:OTL
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=6d026952-33eb-11e1-8d83-001a926e30d7&q={searchTerms}
IE - HKU\S-1-5-21-515967899-2052111302-1801674531-1003\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=SPC2&o=15000&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=PV&apn_dtid=YYYYYYYYPL&apn_uid=23A1A574-152B-40FD-BC91-2A54E7D32A3F&apn_sauid=5B936C25-773E-4E40-BF8A-57B1C0FB7A45
IE - HKU\S-1-5-21-515967899-2052111302-1801674531-1003\..\SearchScopes\{7067852B-58F8-4280-AD2C-EA4869DC94F4}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2832599
IE - HKU\S-1-5-21-515967899-2052111302-1801674531-1003\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=6d026952-33eb-11e1-8d83-001a926e30d7&q={searchTerms}
IE - HKU\S-1-5-21-515967899-2052111302-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "InnoGames Polska Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2832599&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2832599&q="
FF - prefs.js..extensions.enabledItems:
[email protected]:3.3.3.2
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2012-06-08 22:27:48 | 000,000,000 | ---D | M] (InnoGames Polska Community Toolbar) -- C:\Documents and Settings\rb\Dane aplikacji\Mozilla\Firefox\Profiles\0qnqltv9.default\extensions\{14f6a182-4c6f-45ae-9f5a-aa3ccbb1cfa3}
[2012-06-08 22:27:50 | 000,000,000 | ---D | M] (Zynga Community Toolbar) -- C:\Documents and Settings\rb\Dane aplikacji\Mozilla\Firefox\Profiles\0qnqltv9.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011-03-30 12:33:11 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Documents and Settings\rb\Dane aplikacji\Mozilla\Firefox\Profiles\0qnqltv9.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010-08-16 14:49:37 | 000,000,000 | ---D | M] (Streamo.tv) -- C:\Documents and Settings\rb\Dane aplikacji\Mozilla\Firefox\Profiles\0qnqltv9.default\extensions\
[email protected] [2012-05-08 22:26:38 | 000,000,000 | ---D | M] (Sopcast Ask Toolbar) -- C:\Documents and Settings\rb\Dane aplikacji\Mozilla\Firefox\Profiles\0qnqltv9.default\extensions\
[email protected] [2010-11-05 19:50:53 | 000,002,568 | ---- | M] () -- C:\Documents and Settings\rb\Dane aplikacji\Mozilla\Firefox\Profiles\0qnqltv9.default\searchplugins\askcom.xml
[2010-11-25 13:02:52 | 000,000,935 | ---- | M] () -- C:\Documents and Settings\rb\Dane aplikacji\Mozilla\Firefox\Profiles\0qnqltv9.default\searchplugins\conduit.xml
[2011-12-31 22:10:19 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\rb\Dane aplikacji\Mozilla\Firefox\Profiles\0qnqltv9.default\searchplugins\startsear.xml
[2011-10-03 11:14:54 | 000,083,456 | ---- | M] (vShare.tv ) -- C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
FF - prefs.js..extensions.enabledItems:
[email protected]:1.11
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10\_userdata\ggbho.2.dll File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe File not found
O4 - HKU\S-1-5-21-515967899-2052111302-1801674531-1003..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - Startup: C:\Documents and Settings\rb\Menu Start\Programy\Autostart\PowerReg Scheduler V3.exe (Leader Technologies)
[2012-07-10 14:11:01 | 000,000,228 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012-07-09 20:42:01 | 000,000,990 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-515967899-2052111302-1801674531-1003UA.job
[2012-07-07 23:42:01 | 000,000,968 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-515967899-2052111302-1801674531-1003Core.job
[2012-07-10 12:59:02 | 000,000,228 | ---- | M] () -- C:\WINDOWS\Tasks\DriverScanner.job
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=-
"SkyTel"=-
"Alcmtr"=
"JMB36X Configure"=-
"NvMediaCenter"=-
"nwiz"=-
"SSBkgdUpdate"=-
"OpwareSE4"=-
"GrooveMonitor"=-
"NeroFilterCheck"=-
"Freecorder FLV Service"=-
"QuickTime Task"=-
"SunJavaUpdateSched"=-
"Adobe Reader Speed Launcher"=-
"Adobe ARM"=-
"Bonus.SSR.FR11"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu 10"=-
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
"Google Update"=-
"Facebook Update"=-
:Commands
[emptytemp]
[emptyflash]
[clearallrestorepoints]