Task: {7F154409-5E63-455A-82B4-5C148906C1CC} - System32\Tasks\BartekUpcomingRabelaisianV2 => Rundll32.exe SubstantializingForewomen.dll,main 7 1 <==== UWAGA
HKU\S-1-5-21-1962687598-4095466592-1965337558-1001\...\Run: [Akamai NetSession Interface] => "C:\Users\Bartek\AppData\Local\Akamai\netsession_win.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk [2016-03-25]
HKU\S-1-5-21-1962687598-4095466592-1965337558-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn5dJ8gs0DGDT3GOWsi_8CTz4dPYDWWg8AG1YfBDgeQGTtPwLtRom4Fm0m19SxU_dr9h-Z4KhWIfkmK5woABHoixDS75-9v28DvFh5YQ28FFts5-hQpvPN8KLWvniVL7T1f7I-9lK4PkDsy3Bu7coI9VInZ-GaRRsCjOMjchsdas_ykR0yIhdck,&q={searchTerms}
HKU\S-1-5-21-1962687598-4095466592-1965337558-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn5dJ8gs0DGDT3GOWsi_8CTz4dPYDWWg8AG1YfBDgeQGTtPwLtRom4Fm0m19SxU_dr9h-Z4KhWIfkmK5woABHoixDS75-9v28DvFh5YQ28FFts5-hQpvPN8KLWvniVL7T1f7I-9lK4PkDsy3Bu7coI9VInZ-GaRRsCjOMjchsdas_ykR0yIhdck,&q={searchTerms}
HKU\S-1-5-21-1962687598-4095466592-1965337558-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn5dJ8gs0DGDT3GOWsi_8CTz4dPYDWWg8AG1YfBDgeQGTtPwLtRom4Fm0m19SxU_dr9h-Z4KhWIfkmK5woABHoixDS75-9v28DvFh5YQ28FFts5-hQpvPN8KLWvniVL7T1f7I-9lK4PkDsy3Bu7coI9VInZ-GaRRsCjOMjchsdas_ykR0yIhdck,&q={searchTerms}
SearchScopes: HKLM-x32

ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn5dJ8gs0DGDT3GOWsi_8CTz4dPYDWWg8AG1YfBDgeQGTtPwLtRom4Fm0m19SxU_dr9h-Z4KhWIfkmK5woABHoixDS75-9v28DvFh5YQ28FFts5-hQpvPN8KLWvniVL7T1f7I-9lK4PkDsy3Bu7coI9VInZ-GaRRsCjOMjchsdas_ykR0yIhdck,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1962687598-4095466592-1965337558-1001

DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn5dJ8gs0DGDT3GOWsi_8CTz4dPYDWWg8AG1YfBDgeQGTtPwLtRom4Fm0m19SxU_dr9h-Z4KhWIfkmK5woABHoixDS75-9v28DvFh5YQ28FFts5-hQpvPN8KLWvniVL7T1f7I-9lK4PkDsy3Bu7coI9VInZ-GaRRsCjOMjchsdas_ykR0yIhdck,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1962687598-4095466592-1965337558-1001

{ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn5dJ8gs0DGDT3GOWsi_8CTz4dPYDWWg8AG1YfBDgeQGTtPwLtRom4Fm0m19SxU_dr9h-Z4KhWIfkmK5woABHoixDS75-9v28DvFh5YQ28FFts5-hQpvPN8KLWvniVL7T1f7I-9lK4PkDsy3Bu7coI9VInZ-GaRRsCjOMjchsdas_ykR0yIhdck,&q={searchTerms}
BHO-x32: Native Info

{20ffc3e2-8613-4800-a80c-73ae470177af}

C:\Program Files (x86)\Native Info\Extensions\20ffc3e2-8613-4800-a80c-73ae470177af.dll [2016-02-01] ()
FF Homepage: C:\ProgramData\Quotenamrons\ff.HP
FF NewTab: C:\ProgramData\Quotenamrons\ff.NT
C:\ProgramData\Quotenamrons
FF SearchPlugin: C:\Users\Bartek\AppData\Roaming\Mozilla\Firefox\Profiles\9reqj5xm.default\searchplugins\findit.xml [2016-06-19]
CHR DefaultSearchURL: Profile 1

hxxp://feed.safefinder.biz/?fext=true&publisherid=51218&publisher=extensiondefaultap&st=ed&q={searchTerms}
CHR DefaultSearchKeyword: Profile 1

SafeFinder
R2 backlh; C:\ProgramData\Logic Handler\set.exe [2088448 2016-04-26] () [Brak podpisu cyfrowego]
C:\ProgramData\Logic Handler
EmptyTemp: