:OTL
DRV - File not found [Kernel | Boot | Stopped] -- System32\drivers\qkgxb.sys -- (ayoaqs)
IE - HKLM\..\SearchScopes\{1645A33F-0A96-4315-904E-29E188E7720E}: "URL" = http://startsear.ch/?q={searchTerms}
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "SweetIM Search"
FF - prefs.js..browser.search.defaultthis.engineName: "spesoft"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=937811&ilc=12"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..extensions.enabledAddons:
ffxtlbr@Facemoods.com:1.4.0
FF - prefs.js..extensions.enabledAddons:
info@bflix.info:5.0
FF - prefs.js..extensions.enabledItems:
ffxtlbr@Facemoods.com:1.1.0
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1124670&SearchSource=2&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "Web Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1124670&SearchSource=3&q={searchTerms}"
[2012-05-17 08:22:28 | 000,000,000 | ---D | M] ("Winamp Toolbar") -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2012-08-21 21:34:07 | 000,000,000 | ---D | M] (Spesoft Community Toolbar) -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\extensions\{94817c02-feac-4aa8-99d8-1cb47bf4d4c0}
[2012-08-21 16:18:37 | 000,000,000 | ---D | M] (MyAshampoo Community Toolbar) -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
[2012-03-30 20:00:52 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012-08-21 21:34:08 | 000,000,000 | ---D | M] (ST-Polska Community Toolbar) -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\extensions\{c86eb8a9-ccc2-4b6c-b75d-73576ed591bf}
[2011-11-09 23:51:04 | 000,000,000 | ---D | M] (MediaBar) -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\extensions\{E84D42CA-64EB-11DE-A65F-8C3656D89593}
[2012-08-21 16:18:36 | 000,000,000 | ---D | M] (free-downloads.net Community Toolbar) -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\extensions\{ecdee021-0d17-467f-a1ff-c7a115230949}
[2012-03-17 16:40:35 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\extensions\ffxtlbr@incredibar.com
[2012-09-05 10:47:23 | 000,000,000 | ---D | M] ("Linkury Smartbar") -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\extensions\helperbar@helperbar.com
[2012-03-18 19:43:10 | 000,000,000 | ---D | M] (TheBflix) -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\extensions\info@bflix.info
[2011-08-19 21:03:47 | 000,025,939 | ---- | M] () (No name found) -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\extensions\ffxtlbr@Facemoods.com.xpi
[2011-08-23 21:16:36 | 000,002,333 | ---- | M] () -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\searchplugins\askcom.xml
[2009-07-18 01:02:48 | 000,002,476 | ---- | M] () -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\searchplugins\BearShareWebSearch.xml
[2011-11-30 11:12:45 | 000,000,875 | ---- | M] () -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\searchplugins\conduit.xml
[2009-10-17 12:19:22 | 000,002,399 | ---- | M] () -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\searchplugins\daemon-search.xml
[2012-03-17 16:40:30 | 000,002,203 | ---- | M] () -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\searchplugins\MyStart Search.xml
[2011-05-18 15:06:52 | 000,000,632 | ---- | M] () -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\searchplugins\startsear.xml
[2012-06-10 21:03:35 | 000,004,002 | ---- | M] () -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\searchplugins\sweetim.xml
[2012-09-10 19:20:03 | 000,002,469 | ---- | M] () -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\searchplugins\Web Search.xml
[2009-07-18 01:02:48 | 000,002,476 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\BearShareWebSearch.xml
[2010-03-28 18:56:18 | 000,002,035 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrchFxt.xml
[2011-03-05 14:53:59 | 000,001,196 | ---- | M] () -- C:\Documents and Settings\kasia\Dane aplikacji\Mozilla\Firefox\Profiles\u3n0sbtu.default\searchplugins\winamp-search.xml
O4 - HKLM..\Run: [HF_G_Jul] "C:\Program Files\AVG Secure Search\HF_G_Jul.exe" /DoAction File not found
O4 - HKLM..\Run: [ROC_roc_dec12] "C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 File not found
O4 - HKLM..\Run: [ROC_ROC_JULY_P1] "C:\Program Files\AVG Secure Search\ROC_ROC_JULY_P1.exe" / /PROMPT /CMPID=ROC_JULY_P1 File not found
O4 - HKLM..\Run: [VDownloader] C:\Program Files\VDownloader\VDownloader.exe /silent File not found
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Documents and Settings\kasia\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h File not found
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
[2012-04-19 08:32:44 | 003,623,592 | ---- | C] (Ask) -- C:\Program Files\Common Files\ApnToolbarInstaller.exe
[2012-01-06 15:02:57 | 002,161,160 | ---- | C] (DownVision ) -- C:\Documents and Settings\kasia\Ustawienia lokalne\Dane aplikacji\setup.exe
[2012-04-19 08:32:44 | 000,143,240 | ---- | C] (Ask.com) -- C:\Program Files\Common Files\ApnStub.exe
[2011-03-04 21:16:59 | 000,296,182 | ---- | C] () -- C:\WINDOWS\System32\shimg.dll
@Alternate Data Stream - 196 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:943971F5
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:6B9ADB51
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:5B43B7AD
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:2F8138B7
:Files
C:\Documents and Settings\kasia\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.0_0\BabylonChromePI.dll
C:\Documents and Settings\kasia\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of
C:\Documents and Settings\kasia\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0
C:\Documents and Settings\kasia\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.2.5.32_0
C:\Documents and Settings\kasia\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of
C:\Documents and Settings\kasia\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0
C:\Documents and Settings\kasia\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.2.5.32_0
C:\Documents and Settings\kasia\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\opjkhengjjbmdokikpljnbckmgigndeg\2.2.0.5_0
:Commands
[emptytemp]