UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Opera/9.80 (J2ME/MIDP; Opera Mini/6.5.26955/27.1251; U; pl) Presto/2.8.119 Version/11.10
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
:OTL
IE - HKU\S-1-5-21-2025429265-1580818891-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?AF=100482&babsrc=HP_ss&mntrId=80cc3e99000000000000001bfcacf891
IE - HKU\S-1-5-21-2025429265-1580818891-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.1.1:80
FF - prefs.js..browser.search.defaultenginename: "SearchYa!"
FF - prefs.js..browser.search.defaultthis.engineName: " "
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}"
FF - prefs.js..extensions.enabledItems: [email protected]:3.3.3.2
FF - prefs.js..keyword.URL: "http://search.sweetim.com/search.asp?src=2&q="
FF - prefs.js..network.proxy.backup.ftp: "192.168.1.1"
FF - prefs.js..network.proxy.backup.ftp_port: 80
FF - prefs.js..network.proxy.backup.gopher: "192.168.1.1"
FF - prefs.js..network.proxy.backup.gopher_port: 80
FF - prefs.js..network.proxy.backup.socks: "192.168.1.1"
FF - prefs.js..network.proxy.backup.socks_port: 80
FF - prefs.js..network.proxy.backup.ssl: "192.168.1.1"
FF - prefs.js..network.proxy.backup.ssl_port: 80
FF - prefs.js..network.proxy.ftp: "192.168.1.1"
FF - prefs.js..network.proxy.ftp_port: 80
FF - prefs.js..network.proxy.gopher: "192.168.1.1"
FF - prefs.js..network.proxy.gopher_port: 80
FF - prefs.js..network.proxy.http: "192.168.1.1"
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "192.168.1.1"
FF - prefs.js..network.proxy.socks_port: 80
FF - prefs.js..network.proxy.ssl: "192.168.1.1"
FF - prefs.js..network.proxy.ssl_port: 80
FF - prefs.js..network.proxy.type: 0
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q="
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2012-01-21 17:20:00 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011-09-17 16:18:21 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2012-02-09 18:24:56 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\extensions\[email protected]
[2011-05-26 14:10:27 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\extensions\[email protected]
[2012-02-09 19:19:51 | 000,000,000 | ---D | M] (searchya.com) -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\extensions\[email protected]
[2011-05-26 14:10:26 | 000,000,863 | ---- | M] () -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\searchplugins\conduit.xml
[2011-06-10 20:23:47 | 000,002,059 | ---- | M] () -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\searchplugins\daemon-search.xml
[2012-02-09 19:19:34 | 000,001,465 | ---- | M] () -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\searchplugins\searchya.xml
[2011-09-17 16:18:19 | 000,003,915 | ---- | M] () -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\searchplugins\sweetim.xml
[2012-01-24 20:51:02 | 000,002,310 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
O2 - BHO: (no name) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - No CLSID value found.
O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O2 - BHO: (no name) - {EEE6C35C-6118-11DC-9C72-001320C79847} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2025429265-1580818891-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - No CLSID value found.
O3 - HKU\S-1-5-21-2025429265-1580818891-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No CLSID value found.
O3 - HKU\S-1-5-21-2025429265-1580818891-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [TaskTray] File not found
O4 - Startup: C:\Documents and Settings\FLATRON.PC\Menu Start\Programy\Autostart\Spis treści programu OneNote.onetoc2 ()
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (Reg Error: Key error.)
[2012-02-29 15:06:00 | 000,000,466 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{7A2ED286-BC07-441F-97EB-90C10E3F0A7B}.job
[2012-02-29 14:38:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012-02-29 14:37:01 | 000,001,132 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2025429265-1580818891-1417001333-1003UA.job
[2012-02-29 14:26:00 | 000,001,146 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2025429265-1580818891-1417001333-500UA.job
[2012-02-29 13:15:15 | 000,000,462 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{56B21DA0-9D5E-4950-9832-66E36FAF3961}.job
[2012-02-29 07:49:10 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012-02-29 07:49:09 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2025429265-1580818891-1417001333-1003.job
[2012-02-28 17:26:00 | 000,001,094 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2025429265-1580818891-1417001333-500Core1cc13ec489e2e7c.job
[2012-02-28 10:37:10 | 000,001,080 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2025429265-1580818891-1417001333-1003Core.job
[2012-02-27 14:51:01 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2025429265-1580818891-1417001333-1003.job
[2012-02-29 13:15:15 | 000,000,462 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{56B21DA0-9D5E-4950-9832-66E36FAF3961}.job
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=-
"SoundMan"=-
"nwiz"=-
"MSConfig"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=-
"Google Update"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
:OTL
IE - HKU\S-1-5-21-2025429265-1580818891-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?AF=100482&babsrc=HP_ss&mntrId=80cc3e99000000000000001bfcacf891
IE - HKU\S-1-5-21-2025429265-1580818891-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.1.1:80
FF - prefs.js..browser.search.defaultenginename: "SearchYa!"
FF - prefs.js..browser.search.defaultthis.engineName: " "
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}"
FF - prefs.js..extensions.enabledItems: [email protected]:3.3.3.2
FF - prefs.js..keyword.URL: "http://search.sweetim.com/search.asp?src=2&q="
FF - prefs.js..network.proxy.backup.ftp: "192.168.1.1"
FF - prefs.js..network.proxy.backup.ftp_port: 80
FF - prefs.js..network.proxy.backup.gopher: "192.168.1.1"
FF - prefs.js..network.proxy.backup.gopher_port: 80
FF - prefs.js..network.proxy.backup.socks: "192.168.1.1"
FF - prefs.js..network.proxy.backup.socks_port: 80
FF - prefs.js..network.proxy.backup.ssl: "192.168.1.1"
FF - prefs.js..network.proxy.backup.ssl_port: 80
FF - prefs.js..network.proxy.ftp: "192.168.1.1"
FF - prefs.js..network.proxy.ftp_port: 80
FF - prefs.js..network.proxy.gopher: "192.168.1.1"
FF - prefs.js..network.proxy.gopher_port: 80
FF - prefs.js..network.proxy.http: "192.168.1.1"
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "192.168.1.1"
FF - prefs.js..network.proxy.socks_port: 80
FF - prefs.js..network.proxy.ssl: "192.168.1.1"
FF - prefs.js..network.proxy.ssl_port: 80
FF - prefs.js..network.proxy.type: 0
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q="
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2012-01-21 17:20:00 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011-09-17 16:18:21 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2012-02-09 18:24:56 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\extensions\[email protected]
[2011-05-26 14:10:27 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\extensions\[email protected]
[2012-02-09 19:19:51 | 000,000,000 | ---D | M] (searchya.com) -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\extensions\[email protected]
[2011-05-26 14:10:26 | 000,000,863 | ---- | M] () -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\searchplugins\conduit.xml
[2011-06-10 20:23:47 | 000,002,059 | ---- | M] () -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\searchplugins\daemon-search.xml
[2012-02-09 19:19:34 | 000,001,465 | ---- | M] () -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\searchplugins\searchya.xml
[2011-09-17 16:18:19 | 000,003,915 | ---- | M] () -- C:\Documents and Settings\Darek\Dane aplikacji\Mozilla\Firefox\Profiles\hbqe5pv5.default\searchplugins\sweetim.xml
[2012-01-24 20:51:02 | 000,002,310 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
O2 - BHO: (no name) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - No CLSID value found.
O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O2 - BHO: (no name) - {EEE6C35C-6118-11DC-9C72-001320C79847} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2025429265-1580818891-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - No CLSID value found.
O3 - HKU\S-1-5-21-2025429265-1580818891-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No CLSID value found.
O3 - HKU\S-1-5-21-2025429265-1580818891-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [TaskTray] File not found
O4 - Startup: C:\Documents and Settings\FLATRON.PC\Menu Start\Programy\Autostart\Spis treści programu OneNote.onetoc2 ()
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (Reg Error: Key error.)
[2012-02-29 15:06:00 | 000,000,466 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{7A2ED286-BC07-441F-97EB-90C10E3F0A7B}.job
[2012-02-29 14:38:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012-02-29 14:37:01 | 000,001,132 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2025429265-1580818891-1417001333-1003UA.job
[2012-02-29 14:26:00 | 000,001,146 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2025429265-1580818891-1417001333-500UA.job
[2012-02-29 13:15:15 | 000,000,462 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{56B21DA0-9D5E-4950-9832-66E36FAF3961}.job
[2012-02-29 07:49:10 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012-02-29 07:49:09 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2025429265-1580818891-1417001333-1003.job
[2012-02-28 17:26:00 | 000,001,094 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2025429265-1580818891-1417001333-500Core1cc13ec489e2e7c.job
[2012-02-28 10:37:10 | 000,001,080 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2025429265-1580818891-1417001333-1003Core.job
[2012-02-27 14:51:01 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2025429265-1580818891-1417001333-1003.job
[2012-02-29 13:15:15 | 000,000,462 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{56B21DA0-9D5E-4950-9832-66E36FAF3961}.job
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
:OTL
O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"8461:TCP"=-
"8462:TCP"=-
Java(TM) 6 Update 30
Java(TM) 6 Update 7
Adobe Reader 8 - Polish
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Opera/9.80 (J2ME/MIDP; Opera Mini/6.5.26955/27.1287; U; pl) Presto/2.8.119 Version/11.10
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0.2) Gecko/20100101 Firefox/10.0.2
UA: Opera/9.80 (J2ME/MIDP; Opera Mini/6.5.26955/27.1287; U; pl) Presto/2.8.119 Version/11.10
Zarejestrowani użytkownicy: Bing [Bot]