:OTL
MOD - [2012-11-05 11:57:12 | 003,055,976 | ---- | M] () -- C:\Documents and Settings\OEM\Ustawienia lokalne\Dane aplikacji\tuto4pc_pl_1\supt4pc_pl_1.exe
MOD - [2012-11-02 19:59:20 | 002,139,168 | ---- | M] () -- c:\Documents and Settings\All Users\Dane aplikacji\PC Performer Manager\2.4.897.175\{61d8b74e-8d89-46ff-afa6-33382c54ac73}\pcpmngr.dll
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\OEM\USTAWI~1\Temp\sony_ssm.sys --
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\OEM\USTAWI~1\Temp\ewdmaudn.sys -- (ewdmaudn)
IE - HKU\S-1-5-21-606747145-1409082233-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://safesearchr.lavasoft.com/?source ... 50AAC29C31IE - HKU\S-1-5-21-606747145-1409082233-1417001333-1003\..\URLSearchHook: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - No CLSID value found
IE - HKU\S-1-5-21-606747145-1409082233-1417001333-1003\..\SearchScopes\{0574F703-EA47-4D86-9D9D-EF8D158D2556}: "URL" =
http://search.softonic.com/MON00084/tb_v1?q={searchTerms}&SearchSource=4&cc=
IE - HKU\S-1-5-21-606747145-1409082233-1417001333-1003\..\SearchScopes\{CB50EB55-FA7F-4427-9941-CF2E38DB3AF2}: "URL" =
http://websearch.ask.com/redirect?clien ... src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=VX&apn_dtid=YYYYYYFDPL&apn_uid=E1AD37F6-8B9D-472F-9819-0EA0F9861566&apn_sauid=A15736F6-E253-43B8-A08D-3130382A3094
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "blekko"
[2012-03-06 00:58:46 | 000,000,000 | ---D | M] (Softonic Toolbar) -- C:\Documents and Settings\OEM\Dane aplikacji\Mozilla\Firefox\Profiles\k7f77nv8.default\extensions\ffxtlbra@softonic.com
[2012-11-20 00:37:05 | 000,000,000 | ---D | M] (Lavasoft Search Plugin) -- C:\Documents and Settings\OEM\Dane aplikacji\Mozilla\Firefox\Profiles\k7f77nv8.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack
[2012-04-30 17:18:23 | 000,002,571 | ---- | M] () -- C:\Documents and Settings\OEM\Dane aplikacji\Mozilla\Firefox\Profiles\k7f77nv8.default\searchplugins\askcom.xml
[2012-03-06 00:58:29 | 000,002,060 | ---- | M] () -- C:\Documents and Settings\OEM\Dane aplikacji\Mozilla\Firefox\Profiles\k7f77nv8.default\searchplugins\softonic.xml
[2012-11-20 00:37:03 | 000,000,616 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\adawaretb.xml
O3 - HKLM\..\Toolbar: (no name) - {9E131A93-EED7-4BEB-B015-A0ADB30B5646} - No CLSID value found.
O4 - HKLM..\Run: [ROC_roc_ssl_v12] "C:\Program Files\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 File not found
O4 - HKU\S-1-5-21-606747145-1409082233-1417001333-1003..\Run: [RDReminder] C:\Program Files\PC Performer\PCPerformer.exe -rem File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Value error.)
[2012-11-20 00:37:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OEM\Dane aplikacji\blekko
[2012-11-19 18:57:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OEM\Dane aplikacji\PerformerSoft
[2012-11-19 18:57:17 | 000,017,464 | ---- | C] (PerformerSoft LLC) -- C:\WINDOWS\System32\roboot.exe
[2012-11-19 18:57:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Performer Manager
[2012-11-19 18:56:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OEM\Ustawienia lokalne\Dane aplikacji\supt4pc_pl_1
[2012-11-19 18:56:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\supt4pc_pl_1
[2012-11-19 18:56:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OEM\Ustawienia lokalne\Dane aplikacji\tuto4pc_pl_1
[2012-11-06 22:27:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\OEM\Dane aplikacji\blekkotb_019
[2012-04-07 01:31:35 | 003,486,088 | ---- | C] (Ask) -- C:\Program Files\Common Files\ApnToolbarInstaller.exe
[2012-04-07 01:31:35 | 000,143,240 | ---- | C] (Ask.com) -- C:\Program Files\Common Files\ApnStub.exe
[2012-11-19 18:57:29 | 000,000,268 | ---- | M] () -- C:\WINDOWS\tasks\PC Performer_UPDATES.job
[2012-11-19 18:57:29 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\PC Performer_DEFAULT.job
:Commands
[emptytemp]