:OTL PRC - [2011-11-08 10:23:49 | 000,038,408 | ---- | M] (MyWebSearch.com) – C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE PRC - [2011-11-08 10:23:48 | 000,034,336 | ---- | M] (MyWebSearch.com) – C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE SRV - [2011-11-08 10:23:50 | 000,034,320 | ---- | M] (MyWebSearch.com) [Auto | Stopped] – C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE – (MyWebSearchService) IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=imb IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=stonicpl&s={searchTerms}&f=4 IE - HKLM…\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKLM…\SearchScopes{56256A51-B582-467e-B8D4-7786EDA79AE0}: “URL” = http://search.mywebsearch.com/mywebsear … searchfor={searchTerms} IE - HKLM…\SearchScopes{EEE6C360-6118-11DC-9C72-001320C79847}: “URL” = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=4.0002002 IE - HKU\S-1-5-21-1606980848-1078145449-854245398-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=imb IE - HKU\S-1-5-21-1606980848-1078145449-854245398-1002…\SearchScopes,DefaultScope = {56256A51-B582-467e-B8D4-7786EDA79AE0} IE - HKU\S-1-5-21-1606980848-1078145449-854245398-1002…\SearchScopes{0D7562AE-8EF6-416d-A838-AB665251703A}: “URL” = http://start.facemoods.com/?a=stonicpl&s={searchTerms}&f=4 IE - HKU\S-1-5-21-1606980848-1078145449-854245398-1002…\SearchScopes{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: “URL” = http://search.babylon.com/?q={searchTerms}&AF=108603&babsrc=SP_ss&mntrId=dcbb4ec9000000000000000e2e473c85 IE - HKU\S-1-5-21-1606980848-1078145449-854245398-1002…\SearchScopes{56256A51-B582-467e-B8D4-7786EDA79AE0}: “URL” = http://search.mywebsearch.com/mywebsear … searchfor={searchTerms} IE - HKU\S-1-5-21-1606980848-1078145449-854245398-1002…\SearchScopes{EEE6C360-6118-11DC-9C72-001320C79847}: “URL” = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=4.0002002 FF - prefs.js…browser.search.defaultenginename: “SweetIM Search” FF - prefs.js…browser.search.selectedEngine: “SweetIM Search” FF - prefs.js…browser.startup.homepage: “http://www.v9.com/?utm_source=b&utm_medium=imb” FF - prefs.js…keyword.URL: “http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=GRxdm324YYPL&ptb=zvq.Z7RK_l2RHoOe9cEZ4w&ind=2011110809&ptnrS=GRxdm324YYPL&si=4263&n=77df1d99&psa=&st=kwd&searchfor=” FF - prefs.js…sweetim.toolbar.previous.browser.search.defaultenginename: "Google " FF - prefs.js…sweetim.toolbar.previous.browser.search.defaulturl: “” FF - prefs.js…sweetim.toolbar.previous.browser.search.selectedEngine: “Google” FF - HKLM\Software\MozillaPlugins@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\1.bin\NPMyWebS.dll (MyWebSearch.com) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\m3ffxtbr@mywebsearch.com: C:\Program Files\MyWebSearch\bar\1.bin [2011-11-08 10:24:00 | 000,000,000 | —D | M] [2011-11-08 17:12:22 | 000,000,000 | —D | M] (Babylon) – C:\Documents and Settings\WTK\Dane aplikacji\Mozilla\Firefox\Profiles\ndzl7e1i.default\extensions\ffxtlbr@babylon.com [2012-01-26 09:42:57 | 000,000,000 | —D | M] (Facemoods) – C:\Documents and Settings\WTK\Dane aplikacji\Mozilla\Firefox\Profiles\ndzl7e1i.default\extensions\ffxtlbr@Facemoods.com [2011-11-08 10:24:00 | 000,000,000 | —D | M] (My Web Search) – C:\Documents and Settings\WTK\Dane aplikacji\Mozilla\Firefox\Profiles\ndzl7e1i.default\extensions\m3ffxtbr@mywebsearch.com [2012-02-29 17:03:24 | 000,000,000 | —D | M] (@@toolbarname@@) – C:\Documents and Settings\WTK\Dane aplikacji\Mozilla\Firefox\Profiles\ndzl7e1i.default\extensions\toolbar@ask.com [2011-11-08 18:01:27 | 000,009,965 | ---- | M] () – C:\Documents and Settings\WTK\Dane aplikacji\Mozilla\Firefox\Profiles\ndzl7e1i.default\searchplugins\mywebsearch.xml [2012-05-12 23:08:12 | 000,003,934 | ---- | M] () – C:\Documents and Settings\WTK\Dane aplikacji\Mozilla\Firefox\Profiles\ndzl7e1i.default\searchplugins\sweetim.xml [2012-01-01 17:01:31 | 000,002,310 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml [2012-01-26 09:44:25 | 000,002,051 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml [2012-05-12 23:21:50 | 000,000,429 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\v9.xml CHR - default_search_provider: search_url = http://start.facemoods.com/?a=stonicpl&s={searchTerms}&f=4 O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com) O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com) O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO) O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll (facemoods.com BHO) O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKLM…\Toolbar: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com) O3 - HKLM…\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.) O3 - HKLM…\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll (facemoods.com) O3 - HKLM…\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKU\S-1-5-21-1606980848-1078145449-854245398-1002…\Toolbar\WebBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com) O4 - HKLM…\Run: [facemoods] C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe (facemoods.com) O4 - HKLM…\Run: [My Web Search Bar Search Scope Monitor] C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (MyWebSearch.com) O4 - HKLM…\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com) O4 - HKLM…\Run: [sweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.) O4 - HKLM…\Run: [TaskTray] File not found O4 - HKLM…\Run: [WinampAgent] “C:\Program Files\Winamp\winampa.exe” File not found O4 - HKU.DEFAULT…\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe File not found O4 - HKU\S-1-5-18…\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe File not found O4 - HKU\S-1-5-20…\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe File not found O4 - HKU\S-1-5-21-1606980848-1078145449-854245398-1002…\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com) O4 - HKU.DEFAULT…\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found O4 - HKU\S-1-5-18…\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found O4 - HKU\S-1-5-20…\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredi … 2011110809 File not found O27 - HKLM IFEO\notepad.exe: Debugger - C:\WINDOWS\system32\Notepad2.exe () [2012-05-13 20:59:07 | 000,001,124 | ---- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1606980848-1078145449-854245398-1002UA.job [2012-05-13 19:37:21 | 000,000,994 | ---- | M] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1606980848-1078145449-854245398-1002UA.job [2012-05-13 15:18:08 | 000,000,260 | ---- | M] () – C:\WINDOWS\tasks\RegClean Pro_DEFAULT.job [2012-05-12 23:52:33 | 000,000,268 | ---- | M] () – C:\WINDOWS\tasks\RegClean Pro_UPDATES.job [2012-05-12 22:37:01 | 000,000,972 | ---- | M] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1606980848-1078145449-854245398-1002Core.job [2012-05-12 16:59:01 | 000,001,072 | ---- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1606980848-1078145449-854245398-1002Core.job [2012-05-11 21:22:28 | 000,000,284 | ---- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2011-11-08 17:12:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\Babylon [2012-05-12 23:07:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\SweetIM [2011-11-08 17:12:13 | 000,000,000 | —D | M] – C:\Documents and Settings\WTK\Dane aplikacji\Babylon [2011-12-07 21:44:20 | 000,000,000 | —D | M] – C:\Documents and Settings\WTK\Dane aplikacji\BabylonToolbar [2012-01-26 11:59:56 | 000,000,000 | —D | M] – C:\Documents and Settings\WTK\Dane aplikacji\facemoods.com :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] :Commands [RESETHOSTS] [emptytemp]