UA: Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.57 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
UA: Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.57 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
UA: Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.57 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
UA: Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.57 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
UA: Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.57 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\BOENKA~1\AppData\Local\Temp\GPU-Z.sys -- (GPU-Z)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard)
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
IE - HKU\.DEFAULT\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
IE - HKU\S-1-5-18\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
IE - HKU\S-1-5-21-4043554830-416964004-2373153037-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_Prot
IE - HKU\S-1-5-21-4043554830-416964004-2373153037-1000\..\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - No CLSID value found
IE - HKU\S-1-5-21-4043554830-416964004-2373153037-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=F2FE00235A678754&affID=123627&tsp=4937
IE - HKU\S-1-5-21-4043554830-416964004-2373153037-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=^U3&apn_dtid=^OSJ000^YY^PL&apn_uid=55018499-FDB0-4A1F-B8F1-FCE8DE9C330F&apn_sauid=FB115B91-4E9A-4710-AD40-7C7138CA5595
IE - HKU\S-1-5-21-4043554830-416964004-2373153037-1000\..\SearchScopes\{5B291E6C-9A74-4034-971B-A4B007A0B315}: "URL" = http://radiobar.toolbarhome.com/search.aspx?q={searchTerms}&srch=dsp
IE - HKU\S-1-5-21-4043554830-416964004-2373153037-1000\..\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA74C8}: "URL" = http://www.searchqu.com/web?src=ieb&q={SearchTerms}
IE - HKU\S-1-5-21-4043554830-416964004-2373153037-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
FF - prefs.js..browser.search.defaultenginename: "Ask.com Search"
F - prefs.js..browser.search.order.1: "Ask.com Search"
FF - prefs.js..browser.search.selectedEngine: "Ask.com Search"
FF - prefs.js..browser.startup.homepage: "http://search.babylon.com/?affID=110000&tt=050412_30b&babsrc=HP_ss&mntrId=f2fe27e800000000000000235a678754"
FF - prefs.js..extensions.enabledAddons: [email protected]:1.1.9
FF - prefs.js..browser.search.defaultengine: "Ask.com Search"
[2012-04-16 16:58:58 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Bożenka\AppData\Roaming\mozilla\Firefox\Profiles\i1s3qn24.default\extensions\[email protected]
[2013-07-08 17:49:44 | 000,000,000 | ---D | M] (Delta Toolbar) -- C:\Users\Bożenka\AppData\Roaming\mozilla\Firefox\Profiles\i1s3qn24.default\extensions\[email protected]
[2013-03-22 22:53:42 | 000,000,000 | ---D | M] (Browse22Save) -- C:\Users\Bożenka\AppData\Roaming\mozilla\Firefox\Profiles\i1s3qn24.default\extensions\[email protected]
[2013-03-05 17:56:35 | 000,000,000 | ---D | M] (Browwse2SavEE) -- C:\Users\Bożenka\AppData\Roaming\mozilla\Firefox\Profiles\i1s3qn24.default\extensions\[email protected]
[2012-04-16 16:58:58 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Bożenka\AppData\Roaming\mozilla\Firefox\Profiles\i1s3qn24.default\extensions\[email protected]
[2013-07-08 17:49:44 | 000,000,000 | ---D | M] (Delta Toolbar) -- C:\Users\Bożenka\AppData\Roaming\mozilla\Firefox\Profiles\i1s3qn24.default\extensions\[email protected]
[2013-03-22 22:53:42 | 000,000,000 | ---D | M] (Browse22Save) -- C:\Users\Bożenka\AppData\Roaming\mozilla\Firefox\Profiles\i1s3qn24.default\extensions\[email protected]
[2013-03-05 17:56:35 | 000,000,000 | ---D | M] (Browwse2SavEE) -- C:\Users\Bożenka\AppData\Roaming\mozilla\Firefox\Profiles\i1s3qn24.default\extensions\[email protected]
[2013-06-07 13:37:10 | 000,002,308 | ---- | M] () -- C:\Users\Bożenka\AppData\Roaming\mozilla\firefox\profiles\i1s3qn24.default\searchplugins\askcom.xml
[2013-06-23 17:35:29 | 000,002,306 | ---- | M] () -- C:\Users\Bożenka\AppData\Roaming\mozilla\firefox\profiles\i1s3qn24.default\searchplugins\askcomsearch.xml
[2013-07-08 20:18:59 | 000,006,505 | ---- | M] () -- C:\Users\Bożenka\AppData\Roaming\mozilla\firefox\profiles\i1s3qn24.default\searchplugins\babylon.xml
[2013-07-08 20:18:59 | 000,006,505 | ---- | M] () -- C:\Users\Bożenka\AppData\Roaming\mozilla\firefox\profiles\i1s3qn24.default\searchplugins\BrowserDefender.xml
[2013-07-08 20:19:16 | 000,001,294 | ---- | M] () -- C:\Users\Bożenka\AppData\Roaming\mozilla\firefox\profiles\i1s3qn24.default\searchplugins\delta.xml
[2012-04-16 16:41:33 | 000,002,353 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
CHR - Extension: Browwse2SavEE = C:\Users\Bożenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnhaeeedhjdjcaeaphiiopoficpnhadp\1\
CHR - Extension: Browse22Save = C:\Users\Bożenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\obkjbehdiolojflnkhmjcpbboflfpgbn\1\
O3 - HKLM\..\Toolbar: (no name) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - No CLSID value found.
O3 - HKU\S-1-5-21-4043554830-416964004-2373153037-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-4043554830-416964004-2373153037-1000\..\Toolbar\WebBrowser: (no name) - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - No CLSID value found.
O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files\Mobogenie\DaemonProcess.exe File not found
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
[2013-11-25 13:54:32 | 000,000,000 | ---D | M] -- C:\Users\Bożenka\AppData\Roaming\Babylon
[2010-01-24 12:37:45 | 000,000,000 | ---D | M] -- C:\Users\Bożenka\AppData\Roaming\Bandoo
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=-
"EgisTecLiveUpdate"=-
"Adobe Reader Speed Launcher"=-
"WinampAgent"=-
"Skytel"=-
"UnlockerAssistant"=-
:Files
c:\users\Bożenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.57 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.57 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\BOENKA~1\AppData\Local\Temp\catchme.sys -- (catchme)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_Prot
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - No CLSID value found.
[2013-11-25 20:42:21 | 000,000,000 | -HSD | C] -- C:\Users\Bożenka\AppData\Roaming\.#
[2013-11-25 20:35:34 | 000,000,000 | ---D | C] -- C:\Users\Bożenka\AppData\Local\_
[2013-11-23 20:00:19 | 000,000,000 | ---D | C] -- C:\temp
[2013-11-24 15:01:07 | 000,001,612 | ---- | M] () -- C:\Users\Bożenka\Desktop\Wyczyść rejestr za darmo!.lnk
UA: Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.57 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:25.0) Gecko/20100101 Firefox/25.0
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników