24 Sie 2013, 21:18
25 Sie 2013, 13:08
25 Sie 2013, 14:12
25 Sie 2013, 22:32
26 Sie 2013, 11:08
26 Sie 2013, 11:34
:OTL
[2013-08-19 19:37:48 | 000,000,302 | ---- | C] () -- C:\Windows\tasks\RMSchedule.job
[2013-08-19 19:37:44 | 000,000,302 | ---- | C] () -- C:\Windows\tasks\RMAutoUpdate.job
O8:64bit: - Extra context menu item: Download with FileServe Manager - C:\Program Files (x86)\FileServe Manager\GetUrl.htm File not found
O8:64bit: - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Link to &MidpX - C:\Program Files (x86)\Kwyshell\MidpX\JadInvoker\Extent\jad_wrap.htm File not found
O8:64bit: - Extra context menu item: Pobierz plik wideo w FDM - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm File not found
O8:64bit: - Extra context menu item: Pobierz w FDM - file://C:\Program Files (x86)\Free Download Manager\dllink.htm File not found
O8:64bit: - Extra context menu item: Pobierz wszystkie pliki w FDM - file://C:\Program Files (x86)\Free Download Manager\dlall.htm File not found
O8:64bit: - Extra context menu item: Pobierz zaznaczone pliki w FDM - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm File not found
O8:64bit: - Extra context menu item: Ściągaj z Mipony - file://C:\Program Files (x86)\MiPony\Browser\IEContext.htm File not found
O8 - Extra context menu item: Download with FileServe Manager - C:\Program Files (x86)\FileServe Manager\GetUrl.htm File not found
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Link to &MidpX - C:\Program Files (x86)\Kwyshell\MidpX\JadInvoker\Extent\jad_wrap.htm File not found
O8 - Extra context menu item: Pobierz plik wideo w FDM - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm File not found
O8 - Extra context menu item: Pobierz w FDM - file://C:\Program Files (x86)\Free Download Manager\dllink.htm File not found
O8 - Extra context menu item: Pobierz wszystkie pliki w FDM - file://C:\Program Files (x86)\Free Download Manager\dlall.htm File not found
O8 - Extra context menu item: Pobierz zaznaczone pliki w FDM - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm File not found
O8 - Extra context menu item: Ściągaj z Mipony - file://C:\Program Files (x86)\MiPony\Browser\IEContext.htm File not found
O4 - HKU\S-1-5-21-2914388497-2755535032-3570413230-1000..\Run: [ShowBatteryBar] "C:\Program Files\BatteryBar\ShowBatteryBar.exe" show File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-2914388497-2755535032-3570413230-1000..\Run: [DU Meter] C:\Program Files (x86)\DU Meter\DUMeter.exe File not found
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2914388497-2755535032-3570413230-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-2914388497-2755535032-3570413230-1000\..\Toolbar\WebBrowser: (no name) - {40F5F417-32BB-4296-9446-C1E0094E7D82} - No CLSID value found.
O3 - HKU\S-1-5-21-2914388497-2755535032-3570413230-1000\..\Toolbar\WebBrowser: (no name) - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - No CLSID value found.
[2012-12-03 16:28:14 | 000,002,349 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2013-07-13 16:23:45 | 000,002,120 | ---- | M] () -- C:\Users\Paweł\AppData\Roaming\mozilla\firefox\profiles\4c2cgy2y.default\searchplugins\MyStart.xml
IE - HKU\S-1-5-21-2914388497-2755535032-3570413230-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1124670
IE - HKU\S-1-5-21-2914388497-2755535032-3570413230-1000\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.searchdwebs.info/?l=1&q={searchTerms}&pid=500&r=2013/07/04&hid=3644003010&lg=EN&cc=PL&unqvl=22
IE - HKU\S-1-5-21-2914388497-2755535032-3570413230-1000\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://start.sweetpacks.com/?src=6&q={searchTerms}&st=12&crg=3.5000006.10042&barid={81570062-A600-4A97-A095-A9B2C7E113B2}
IE - HKU\S-1-5-21-2914388497-2755535032-3570413230-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=110824&tt=4912_4&babsrc=SP_ss&mntrId=ba10152c00000000000020cf30315715
IE - HKU\S-1-5-21-2914388497-2755535032-3570413230-1000\..\URLSearchHook: {40f5f417-32bb-4296-9446-c1e0094e7d82} - No CLSID value found
IE - HKU\S-1-5-21-2914388497-2755535032-3570413230-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://search.babylon.com/?affID=121631&babsrc=HP_ss_gin2g&mntrId=BA1000FFDFDA1BEC
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://start.sweetpacks.com/?src=6&q={searchTerms}&st=12&crg=3.5000006.10042&barid={81570062-A600-4A97-A095-A9B2C7E113B2}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1124670
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.searchboxes.info/?l=1&q={searchTerms}&pid=947&r=2013/07/29&hid=2966464569&lg=EN&cc=PL&unqvl=28
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchboxes.info/?pid=947&r=2013/07/29&hid=2966464569&lg=EN&cc=PL&unqvl=28
:Files
C:\Users\Paweł\AppData\Local\Temp*.html
:Commands
[emptytemp]
[resethosts]
26 Sie 2013, 12:24
26 Sie 2013, 14:59