UA: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.31 (KHTML, like Gecko) Chrome/26.0.1410.43 Safari/537.31
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:20.0) Gecko/20100101 Firefox/20.0
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?barid={00583D6B-F848-47EA-9BA4-07B513F1446D}
IE - HKU\S-1-5-21-695095732-1806802702-1764019054-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = pl.v9.com/idg/idg_1332356013_426331
IE - HKU\S-1-5-21-695095732-1806802702-1764019054-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=110819&tt=060612_5_&babsrc=HP_ss&mntrId=20d68ebe00000000000000138f4d2ef5
IE - HKU\S-1-5-21-695095732-1806802702-1764019054-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=110819&tt=060612_5_&babsrc=SP_ss&mntrId=20d68ebe00000000000000138f4d2ef5
IE - HKU\S-1-5-21-695095732-1806802702-1764019054-1001\..\SearchScopes\{C867A5E3-6000-4476-BA3F-329BE267783F}: "URL" = http://start.funmoods.com/results.php?f=4&a=ironto&q={searchTerms}
CHR - Extension: Babylon Toolbar = C:\Users\Paulina\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.11_0\
CHR - Extension: Funmoods = C:\Users\Paulina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\2.1.4_0\
CHR - Extension: SweetIM for Facebook = C:\Users\Paulina\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of
CHR - Extension: SweetIM for Facebook = C:\Users\Paulina\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\
CHR - Extension: Babylon Toolbar = C:\Users\Paulina\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.11_0\
CHR - Extension: Funmoods = C:\Users\Paulina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\2.1.4_0\
CHR - Extension: SweetIM for Facebook = C:\Users\Paulina\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of
CHR - Extension: SweetIM for Facebook = C:\Users\Paulina\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\
O4 - HKU\S-1-5-21-695095732-1806802702-1764019054-1001..\Run: [MSConfig] "C:\Users\Paulina\tbdv.exe" File not found
[2013-04-07 14:55:18 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-695095732-1806802702-1764019054-1001UA.job
[2013-02-07 18:46:06 | 000,114,176 | ---- | C] () -- C:\Users\Paulina\AppData\Roaming\BabMaint.exe
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.31 (KHTML, like Gecko) Chrome/26.0.1410.43 Safari/537.31
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:20.0) Gecko/20100101 Firefox/20.0
UA: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.31 (KHTML, like Gecko) Chrome/26.0.1410.43 Safari/537.31
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:20.0) Gecko/20100101 Firefox/20.0
UA: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.31 (KHTML, like Gecko) Chrome/26.0.1410.43 Safari/537.31
UA: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.31 (KHTML, like Gecko) Chrome/26.0.1410.43 Safari/537.31
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:20.0) Gecko/20100101 Firefox/20.0
UA: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.31 (KHTML, like Gecko) Chrome/26.0.1410.43 Safari/537.31
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:20.0) Gecko/20100101 Firefox/20.0
UA: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.31 (KHTML, like Gecko) Chrome/26.0.1410.43 Safari/537.31
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:20.0) Gecko/20100101 Firefox/20.0
:OTL
[2013-04-07 15:46:03 | 000,000,000 | ---D | C] -- C:\Users\Paulina\Qtrax
[2012-06-26 18:55:25 | 000,000,000 | ---D | M] -- C:\Users\Paulina\AppData\Roaming\Babylon
[2013-02-11 20:39:51 | 000,000,000 | ---D | M] -- C:\Users\Paulina\AppData\Roaming\DealPly
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Media Codec Update Service"=-
"WinampAgent"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"=-
Adobe Reader 8 - Polish
Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników