UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.2.0.0 Safari/537.17
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.2.0.0 Safari/537.17
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.2.0.0 Safari/537.17
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.22apple.com/?utm_source=b&ch=sof&uid=TOSHIBAXMK3265GSX_90BHP7D8TXX90BHP7D8T®=1358979112
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.22apple.com/?utm_source=b&ch=sof&uid=TOSHIBAXMK3265GSX_90BHP7D8TXX90BHP7D8T®=1358979112
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.certified-toolbar.com?si=41460&bs=true&tid=3204&q={searchTerms}
IE - HKU\S-1-5-21-3953819830-622224066-1830746929-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.22apple.com/?utm_source=b&ch=sof&uid=TOSHIBAXMK3265GSX_90BHP7D8TXX90BHP7D8T®=1358979112
IE - HKU\S-1-5-21-3953819830-622224066-1830746929-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.22apple.com/?utm_source=b&ch=sof&uid=TOSHIBAXMK3265GSX_90BHP7D8TXX90BHP7D8T®=1358979112
IE - HKU\S-1-5-21-3953819830-622224066-1830746929-1000\..\SearchScopes\{21B5ADB8-009F-4B66-B0BD-DF4EC60973A8}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10267&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AGY&apn_dtid=^YYYYYY^YY^PL&apn_uid=9d3949a3-c41a-44e1-ba8b-23723977eda6&apn_sauid=1DE4046E-2871-4E81-90FA-15008C01674C
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.startup.homepage: "http://search.avira.com/?l=dis&o=APN10267&gct=hp&dc=EU&locale=en_PL"
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2012/11/24 10:22:34 | 000,000,000 | ---D | M] (Certified Toolbar) -- C:\Users\Ania\AppData\Roaming\mozilla\Firefox\Profiles\znn4rebn.default\extensions\{624ad42d-e714-46b4-843e-c7094f740b0f}
[2013/01/23 23:06:39 | 000,002,344 | ---- | M] () -- C:\Users\Ania\AppData\Roaming\mozilla\firefox\profiles\znn4rebn.default\searchplugins\askcom.xml
[2013/01/23 23:11:53 | 000,000,759 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\22apple.xml
[2013/01/18 12:37:45 | 000,003,269 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\Web Search.xml
O2 - BHO: (no name) - {0de094f5-e894-48c7-b16f-338d64674721} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0de094f5-e894-48c7-b16f-338d64674721} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O8:64bit: - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000 File not found
[2012/05/13 12:26:40 | 000,001,074 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3953819830-622224066-1830746929-1000UA.job
[2012/05/13 12:26:36 | 000,001,052 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3953819830-622224066-1830746929-1000Core.job
:Files
[2010/11/21 22:02:45 | 000,002,089 | ---- | C] () -- C:\Users\Ania\AppData\Local\Temp*.html
:Commands
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17
All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKU\S-1-5-21-3953819830-622224066-1830746929-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-21-3953819830-622224066-1830746929-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-3953819830-622224066-1830746929-1000\Software\Microsoft\Internet Explorer\SearchScopes\{21B5ADB8-009F-4B66-B0BD-DF4EC60973A8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21B5ADB8-009F-4B66-B0BD-DF4EC60973A8}\ not found.
Prefs.js: "Ask.com" removed from browser.search.selectedEngine
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: "http://search.avira.com/?l=dis&o=APN10267&gct=hp&dc=EU&locale=en_PL" removed from browser.startup.homepage
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=\ deleted successfully.
C:\Users\Ania\AppData\Roaming\mozilla\Firefox\Profiles\znn4rebn.default\extensions\{624ad42d-e714-46b4-843e-c7094f740b0f}\images folder moved successfully.
C:\Users\Ania\AppData\Roaming\mozilla\Firefox\Profiles\znn4rebn.default\extensions\{624ad42d-e714-46b4-843e-c7094f740b0f}\components folder moved successfully.
C:\Users\Ania\AppData\Roaming\mozilla\Firefox\Profiles\znn4rebn.default\extensions\{624ad42d-e714-46b4-843e-c7094f740b0f}\chrome folder moved successfully.
C:\Users\Ania\AppData\Roaming\mozilla\Firefox\Profiles\znn4rebn.default\extensions\{624ad42d-e714-46b4-843e-c7094f740b0f} folder moved successfully.
File C:\Users\Ania\AppData\Roaming\mozilla\firefox\profiles\znn4rebn.default\searchplugins\askcom.xml not found.
C:\Program Files (x86)\mozilla firefox\searchplugins\22apple.xml moved successfully.
C:\Program Files (x86)\mozilla firefox\searchplugins\Web Search.xml moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0de094f5-e894-48c7-b16f-338d64674721}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0de094f5-e894-48c7-b16f-338d64674721}\ deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{0de094f5-e894-48c7-b16f-338d64674721} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0de094f5-e894-48c7-b16f-338d64674721}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\vProt deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\E&ksportuj do programu Microsoft Excel\ deleted successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3953819830-622224066-1830746929-1000UA.job moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3953819830-622224066-1830746929-1000Core.job moved successfully.
========== FILES ==========
Invalid Switch: 21 22:02:45 | 000,002,089 | ---- | C] () -- C:\Users\Ania\AppData\Local\Temp*.html
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Ania
->Temp folder emptied: 75867760 bytes
->Temporary Internet Files folder emptied: 6418883 bytes
->Java cache emptied: 1 bytes
->FireFox cache emptied: 65798717 bytes
->Google Chrome cache emptied: 370489865 bytes
->Flash cache emptied: 558 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1715692 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 9997345 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36029013 bytes
RecycleBin emptied: 197030969 bytes
Total Files Cleaned = 728.00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 01242013_221724
Files\Folders moved on Reboot...
C:\Users\Ania\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Ania\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0 moved successfully.
C:\Users\Ania\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1 moved successfully.
C:\Users\Ania\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2 moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.2.0.0 Safari/537.17
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.2.0.0 Safari/537.17
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.2.0.0 Safari/537.17
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.2.0.0 Safari/537.17
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17
Zarejestrowani użytkownicy: Bing [Bot]