

UA: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
UA: Opera/9.80 (Windows NT 5.1; U; pl) Presto/2.10.229 Version/11.60
UA: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
UA: Opera/9.80 (Windows NT 5.1; U; pl) Presto/2.10.229 Version/11.60
UA: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
UA: Opera/9.80 (Windows NT 5.1; U; pl) Presto/2.10.229 Version/11.60
UA: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
:OTL
FF - prefs.js..extensions.enabledItems: [email protected]:1.2.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.5
[2012-01-07 22:24:42 | 000,000,000 | ---D | M] (Browser Companion Helper) -- C:\Documents and Settings\xxxxx\Dane aplikacji\Mozilla\Firefox\Profiles\wdpx4vzv.default\extensions\[email protected]
O15 - HKU\S-1-5-21-2485243083-2988513709-3248651416-1005\..Trusted Domains: bossa.pl ([www] https in Trusted sites)
O15 - HKU\S-1-5-21-2485243083-2988513709-3248651416-1005\..Trusted Domains: google.pl ([groups] https in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.3.1/jinstall-131_03-win.cab (Java Plug-in 1.3.1_03)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
:Files
C:\FOUND.*
C:\Documents and Settings\xxxxx\Dane aplikacji\AVG2012
C:\$AVG
C:\Documents and Settings\All Users\Dane aplikacji\AVG2012
C:\Program Files\AVG
C:\Documents and Settings\xxxxx\Pulpit\cc_20120113_222633.reg
C:\Documents and Settings\xxxxx\Pulpit\cc_20120112_203525.reg
C:\Documents and Settings\xxxxx\Pulpit\cc_20120110_222728.reg
C:\Program Files\hijackthis.zip
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Browser companion helper"=-
"HControl"=-
[HKEY_USERS\S-1-5-21-2485243083-2988513709-3248651416-1005\Software\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Opera/9.80 (Windows NT 5.1; U; pl) Presto/2.10.229 Version/11.60
UA: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
UA: Opera/9.80 (Windows NT 5.1; U; pl) Presto/2.10.229 Version/11.60
UA: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
UA: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; BTRS122327; GTB7.2; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0) Gecko/20100101 Firefox/10.0
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = pl.v9.com/ins/ins_1326573469_179460
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = pl.v9.com/ins/ins_1326573469_179460
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.asus.com
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.asus.com
IE - HKU\S-1-5-21-2485243083-2988513709-3248651416-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.asus.com
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
[2012-01-14 21:37:54 | 000,002,415 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\v9.xml
[2012-01-14 22:29:08 | 000,002,310 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
:Files
C:\Program Files\Google\Update
C:\FOUND.*
C:\WINDOWS\tasks\*.job
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0) Gecko/20100101 Firefox/10.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:10.0) Gecko/20100101 Firefox/10.0
:OTL
IE - HKU\S-1-5-21-2485243083-2988513709-3248651416-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = pl.v9.com/ins/ins_1326573469_179460
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
O3 - HKU\S-1-5-21-2485243083-2988513709-3248651416-1005\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
:Services
gupdate
gupdatem
:Commands
[clearallrestorepoints]
[emptytemp]
Zarejestrowani użytkownicy: Google [Bot]