UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
rdpclip
RtHDVCpl
TCrdMain
Toshiba Registration
Toshiba TEMPRO
TosSENotify
Adobe ARM
GrooveMonitor
USB3MON
Toshiba Places Icon Utility.lnk
Microsoft Windows
Internet Explorer
Microsoft Windows
ALLUpdate
TOPI.EXE
\Microsoft\Windows Defender\MP Scheduled Scan
\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
\Microsoft\Windows\NetTrace\GatherNetworkInfo
\{C0371A51-4D61-4704-91F0-56191AEE2CD7}
Microsoft Office Groove Audit Service
NAUpdate
odserv
ose
WinDefend
:OTL
DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.5&ts=1377758386538&tguid=62606-6533-1377758386538-411A39635EBDA81E0448B00AC673A32C&st=chrome&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.5&ts=1377758386538&tguid=62606-6533-1377758386538-411A39635EBDA81E0448B00AC673A32C&st=chrome&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.5&ts=1377758386538&tguid=62606-6533-1377758386538-411A39635EBDA81E0448B00AC673A32C&st=chrome&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.5&ts=1377758386538&tguid=62606-6533-1377758386538-411A39635EBDA81E0448B00AC673A32C&st=chrome&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.5&ts=1377758386538&tguid=62606-6533-1377758386538-411A39635EBDA81E0448B00AC673A32C&st=chrome&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.5&ts=1377758386538&tguid=62606-6533-1377758386538-411A39635EBDA81E0448B00AC673A32C&st=chrome&q=
IE - HKLM\..\SearchScopes\{FE8315A5-E2BC-40D8-81C5-50C3CDE59459}: "URL" = http://search.certified-toolbar.com?si=62606&st=bs&tid=6533&ver=4.5&ts=1377758386538&tguid=62606-6533-1377758386538-411A39635EBDA81E0448B00AC673A32C&q={searchTerms}
IE - HKU\S-1-5-21-3798194511-2015093275-3936282910-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www2.delta-search.com/?babsrc=HP_ss&mntrId=0E2F446D570522C8&affID=121564&tt=288013_icon&tsp=4988
IE - HKU\S-1-5-21-3798194511-2015093275-3936282910-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.5&ts=1377758386538&tguid=62606-6533-1377758386538-411A39635EBDA81E0448B00AC673A32C&st=chrome&q=
IE - HKU\S-1-5-21-3798194511-2015093275-3936282910-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.5&ts=1377758386538&tguid=62606-6533-1377758386538-411A39635EBDA81E0448B00AC673A32C&st=chrome&q=
IE - HKU\S-1-5-21-3798194511-2015093275-3936282910-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.5&ts=1377758386538&tguid=62606-6533-1377758386538-411A39635EBDA81E0448B00AC673A32C&st=chrome&q=
IE - HKU\S-1-5-21-3798194511-2015093275-3936282910-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.5&ts=1377758386538&tguid=62606-6533-1377758386538-411A39635EBDA81E0448B00AC673A32C&st=chrome&q=
IE - HKU\S-1-5-21-3798194511-2015093275-3936282910-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.5&ts=1377758386538&tguid=62606-6533-1377758386538-411A39635EBDA81E0448B00AC673A32C&st=chrome&q=
IE - HKU\S-1-5-21-3798194511-2015093275-3936282910-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.5&ts=1377758386538&tguid=62606-6533-1377758386538-411A39635EBDA81E0448B00AC673A32C&st=chrome&q=
IE - HKU\S-1-5-21-3798194511-2015093275-3936282910-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=0E2F446D570522C8&affID=121564&tt=288013_icon&tsp=4988
IE - HKU\S-1-5-21-3798194511-2015093275-3936282910-1000\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://www.mystart.com/results.php?pr=vmn&id=toolbarcleaner&v=1_1_1_4&ent=ch_4802&q={searchTerms}
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-3798194511-2015093275-3936282910-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4:64bit: - HKLM..\Run: [] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O8:64bit: - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 File not found
[2013-08-28 20:39:00 | 000,000,000 | ---D | M] -- C:\Users\POL Office\AppData\Roaming\Babylon
[2013-08-29 07:28:12 | 000,000,000 | ---D | M] -- C:\Users\POL Office\AppData\Roaming\DVDVideoSoft
:Files
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
:Commands
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36
Zarejestrowani użytkownicy: Bing [Bot]