:OTL
DRV - File not found [Kernel | On_Demand | Running] -- -- (xpsec)
DRV - File not found [Kernel | On_Demand | Running] -- -- (xcpip)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (fwxoqfog)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (eqgtby2g.sys)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (DNINDIS5)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | System | Stopped] -- -- (Cdaudio)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (catchme)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1&cf=0a6064a8-3719-11e1-8e59-00192136481a
IE - HKLM\..\SearchScopes\{C88640E7-45B9-428F-A0F3-AB65660AD3F6}: "URL" = http://search.myheritage.com?orig=ds&q={searchTerms}
IE - HKU\S-1-5-21-1644491937-776561741-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=stonicpl stagedXpi
IE - HKU\S-1-5-21-1644491937-776561741-839522115-1003\..\SearchScopes,DefaultScope = {0D7562AE-8EF6-416d-A838-AB665251703A}
IE - HKU\S-1-5-21-1644491937-776561741-839522115-1003\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.funmoods.com/?a=stonicpl stagedXpi&s={searchTerms}&f=4
IE - HKU\S-1-5-21-1644491937-776561741-839522115-1003\..\SearchScopes\{BE28C22E-F666-424d-B5FD-125C4AFEE34E}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=0a6064a8-3719-11e1-8e59-00192136481a&q={searchTerms}
IE - HKU\S-1-5-21-1644491937-776561741-839522115-1003\..\SearchScopes\{C88640E7-45B9-428F-A0F3-AB65660AD3F6}: "URL" = http://search.myheritage.com?orig=ds&q={searchTerms}
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..extensions.enabledItems:
DTToolbar@toolbarnet.com:1.0.7.0088
FF - prefs.js..keyword.URL: "http://vshare.toolbarhome.com/search.aspx?srch=ku&q="
[2011-02-24 14:52:34 | 000,000,000 | ---D | M] (vShare) -- C:\Documents and Settings\Kucza\Dane aplikacji\Mozilla\Firefox\Profiles\tsxpbeai.default\extensions\vshare@toolbar
[2009-02-28 20:23:12 | 000,002,921 | ---- | M] () -- C:\Documents and Settings\Kucza\Dane aplikacji\Mozilla\Firefox\Profiles\tsxpbeai.default\searchplugins\daemon-search.xml
[2012-02-09 18:39:15 | 000,001,812 | ---- | M] () -- C:\Documents and Settings\Kucza\Dane aplikacji\Mozilla\Firefox\Profiles\tsxpbeai.default\searchplugins\funmoods.xml
[2009-05-20 23:04:25 | 000,009,941 | ---- | M] () -- C:\Documents and Settings\Kucza\Dane aplikacji\Mozilla\Firefox\Profiles\tsxpbeai.default\searchplugins\mywebsearch.xml
[2012-01-04 21:14:21 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\Kucza\Dane aplikacji\Mozilla\Firefox\Profiles\tsxpbeai.default\searchplugins\startsear.xml
[2011-02-24 14:52:42 | 000,001,592 | ---- | M] () -- C:\Documents and Settings\Kucza\Dane aplikacji\Mozilla\Firefox\Profiles\tsxpbeai.default\searchplugins\web-search.xml
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKU\S-1-5-21-1644491937-776561741-839522115-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
[2012-03-05 12:20:09 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010-07-28 17:37:37 | 000,044,800 | ---- | C] () -- C:\WINDOWS\System32\ini.exe
[2010-07-10 16:05:08 | 000,088,576 | RHS- | C] () -- C:\WINDOWS\System32\nwwksx.dll
[2010-07-10 15:53:57 | 000,046,592 | ---- | C] () -- C:\WINDOWS\System32\redirsm.dll
:Commands
[emptytemp]
[emptyflash]