:OTL IE - HKU\S-1-5-21-2052111302-261903793-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=113480 … 1a4d7d2367 FF - prefs.js…browser.search.defaultenginename: “Search the web (Babylon)” FF - prefs.js…browser.search.order.1: “Search the web (Babylon)” FF - prefs.js…browser.startup.homepage: “http://search.babylon.com/?affID=113480&babsrc=HP_ss&mntrId=c40e2777000000000000001a4d7d2367” FF - prefs.js…keyword.URL: “http://search.babylon.com/?affID=113480&babsrc=KW_ss&mntrId=c40e2777000000000000001a4d7d2367&q=” [2012-06-01 18:48:01 | 000,000,000 | —D | M] (KMP Media Toolbar) – E:\Documents and Settings\Admin\Dane aplikacji\Mozilla\Firefox\Profiles\o8df593g.default\extensions{daf5b34c-1aa3-4c33-ae24-766a370635d2} [2012-06-01 17:55:47 | 000,000,000 | —D | M] (KMPlayer Toolbar) – E:\Documents and Settings\Admin\Dane aplikacji\Mozilla\Firefox\Profiles\o8df593g.default\extensions\toolbar@ask.com [2012-06-01 18:53:52 | 000,002,313 | ---- | M] () – E:\Program Files\mozilla firefox\searchplugins\babylon.xml O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (KMPlayer Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - E:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O2 - BHO: (KMP Media Toolbar) - {daf5b34c-1aa3-4c33-ae24-766a370635d2} - E:\Program Files\kmpmediatoolbar\searchresultsDx.dll (Ask.com) O3 - HKLM…\Toolbar: (KMPlayer Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - E:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKLM…\Toolbar: (KMP Media Toolbar) - {daf5b34c-1aa3-4c33-ae24-766a370635d2} - E:\Program Files\kmpmediatoolbar\searchresultsDx.dll (Ask.com) O3 - HKU\S-1-5-21-2052111302-261903793-682003330-1003…\Toolbar\WebBrowser: (KMPlayer Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - E:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O4 - HKLM…\Run: [] File not found O4 - HKLM…\Run: [ApnUpdater] E:\Program Files\Ask.com\Updater\Updater.exe (Ask) [2012-06-01 18:54:18 | 000,000,000 | —D | C] – E:\Documents and Settings\Admin\Dane aplikacji\BabylonToolbar [2012-06-01 18:54:11 | 000,000,000 | —D | C] – E:\Program Files\BabylonToolbar [2012-06-01 18:53:33 | 000,000,000 | —D | C] – E:\Documents and Settings\All Users\Dane aplikacji\Babylon [2012-06-01 18:53:33 | 000,000,000 | —D | C] – E:\Documents and Settings\Admin\Dane aplikacji\Babylon [2012-06-01 18:48:00 | 000,000,000 | —D | C] – E:\Documents and Settings\Admin\Dane aplikacji\kmpmediatoolbar [2012-06-01 17:55:45 | 000,000,000 | —D | C] – E:\Program Files\Ask.com [2012-06-01 17:55:44 | 000,000,000 | —D | C] – E:\Documents and Settings\Admin\Ustawienia lokalne\Dane aplikacji\AskToolbar [2012-06-01 18:47:54 | 000,000,000 | —D | C] – E:\Program Files\kmpmediatoolbar [2012-06-03 17:55:00 | 000,000,234 | ---- | M] () – E:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job [2012-06-03 16:29:58 | 000,000,148 | ---- | M] () – E:\Documents and Settings\Admin\Video.lnk [2012-06-03 16:29:58 | 000,000,148 | ---- | M] () – E:\Documents and Settings\Admin\Pictures.lnk [2012-06-03 16:29:58 | 000,000,148 | ---- | M] () – E:\Documents and Settings\Admin\Passwords.lnk [2012-06-03 16:29:58 | 000,000,148 | ---- | M] () – E:\Documents and Settings\Admin\New Folder.lnk [2012-06-03 16:29:58 | 000,000,148 | ---- | M] () – E:\Documents and Settings\Admin\Music.lnk [2012-06-03 16:29:58 | 000,000,148 | ---- | M] () – E:\Documents and Settings\Admin\Documents.lnk [2012-06-01 18:54:12 | 000,000,237 | ---- | M] () – E:\user.js [2012-06-03 16:29:58 | 000,049,152 | RHS- | C] () – E:\Documents and Settings\Admin\fuefue.scr [2012-06-03 16:44:46 | 000,044,748 | -H-- | M] () – E:\WINDOWS\System32\xb877153.dl_ [2012-06-03 16:44:46 | 000,044,748 | -H-- | M] () – E:\WINDOWS\System32\rh702732.dl_ [2012-06-03 16:08:33 | 000,044,748 | -H-- | C] () – E:\WINDOWS\System32\nc877153.dl_ [2012-06-03 00:33:46 | 000,044,748 | -H-- | C] () – E:\WINDOWS\System32\ad877153.dl_ [2012-06-02 10:15:28 | 000,081,920 | ---- | C] () – E:\WINDOWS\System32\xb877153.dll [2012-06-02 10:15:28 | 000,044,748 | -H-- | C] () – E:\WINDOWS\System32\xb877153.dl_ [2012-06-02 10:15:27 | 000,044,748 | -H-- | C] () – E:\WINDOWS\System32\wb877153.dl_ [2012-06-01 21:35:40 | 000,044,748 | -H-- | C] () – E:\WINDOWS\System32\vb877153.dl_ [2012-06-01 21:28:01 | 000,081,920 | ---- | C] () – E:\WINDOWS\System32\rh702732.dll [2012-06-01 21:28:01 | 000,044,748 | -H-- | C] () – E:\WINDOWS\System32\rh702732.dl_ :Files del “\?\E:\Documents and Settings\Admin\autorun.inf” /c :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] :Commands [emptytemp]