:Processes Explorer.EXE :Services Sukoku Service :OTL IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://search.bearshare.com [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/ FF - prefs.js…browser.search.defaultenginename: “BearShare Web Search” FF - prefs.js…browser.search.order.1: “BearShare Web Search” FF - prefs.js…extensions.enabledItems: {0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC}:2.0.0.1050 FF - prefs.js…extensions.enabledItems: {2224E955-00E9-4613-A844-CE69FCCAAE91}:3.8.1.4690 FF - prefs.js…keyword.URL: “http://search.bearshare.com/webResults.html?src=ffb&q=” FF - HKLM\software\mozilla\Firefox\Extensions\{2224E955-00E9-4613-A844-CE69FCCAAE91}: C:\Program Files\Internet Saving Optimizer\3.8.1.4690\FF [2009-09-12 09:10:50 | 00,000,000 | —D | M] FF - HKLM\software\mozilla\Firefox\Extensions\{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC}: C:\Program Files\Media Access Startup\2.0.0.1050\FF [2009-09-12 09:11:02 | 00,000,000 | —D | M] [2009-07-18 01:02:48 | 00,002,476 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\BearShareWebSearch.xml [2009-09-29 17:29:28 | 00,002,381 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\sukoku119.xml O2 - BHO: (Media Access Startup) - {25B8D58C-B0CB-46b0-BA64-05B3804E4E86} - C:\Program Files\Media Access Startup\2.0.0.1050\HPIEAddOn.dll () O2 - BHO: (NP Helper Class) - {35B8D58C-B0CB-46b0-BA64-05B3804E4E86} - C:\Program Files\Internet Saving Optimizer\3.8.1.4690\NPIEAddOn.dll () O2 - BHO: (Smart-Shopper) - {4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E} - C:\Program Files\Smart-Shopper\Bin\2.6.43\Smrt-Shpr.dll (SmartShopper Networks) O2 - BHO: (UrlHelper Class) - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\BearShare\BearShareIEHelper.dll () O3 - HKLM…\Toolbar: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare) O3 - HKCU…\Toolbar\WebBrowser: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare) [2009-09-12 08:48:00 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\032C [2009-09-14 15:15:16 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\101A5 [2009-09-20 19:41:17 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\113C8 [2009-09-18 16:32:23 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\17177 [2009-09-18 18:30:24 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\18129 [2009-09-16 18:24:26 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\1AF [2009-09-13 15:59:27 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\1B2EE [2009-09-20 15:47:32 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\203B9 [2009-09-15 16:10:02 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\21D5 [2009-09-17 16:29:35 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\2335B [2009-09-16 15:37:38 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\26EA [2009-09-14 19:35:39 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\2735B [2009-09-11 20:59:46 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\2E148 [2009-09-17 13:51:47 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\2F1F [2009-09-11 15:45:48 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\30186 [2009-09-13 13:11:48 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\30271 [2009-10-11 10:28:49 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\31148 [2009-09-17 16:23:54 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\36128 [2009-09-16 07:16:54 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\36273 [2009-09-14 20:12:55 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\37119 [2009-09-13 07:56:56 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\3837A [2009-09-19 11:19:58 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\3A1C5 [2009-09-21 08:05:59 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\3B5D [2009-09-13 14:28:04 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\42A0 [2009-09-21 14:07:05 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\52EE [2009-09-20 10:49:06 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\638A [2009-09-18 16:13:07 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\7251 [2009-09-13 08:03:07 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\77D [2009-09-19 08:30:08 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\83A9 [2009-09-19 12:05:10 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\A1F4 [2009-09-13 22:17:10 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\A33D [2009-09-21 14:34:12 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\C157 [2009-09-14 21:15:13 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\D8C [2009-09-12 12:54:14 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\E5D [2009-09-12 09:09:38 | 00,000,000 | —D | C] – C:\Documents and Settings\Home\Ustawienia lokalne\Dane aplikacji\DoubleD [2009-09-12 09:12:14 | 00,000,000 | —D | C] – C:\Documents and Settings\Home\Ustawienia lokalne\Dane aplikacji\Internet Saving Optimizer [2009-09-12 09:11:02 | 00,000,000 | —D | C] – C:\Documents and Settings\Home\Ustawienia lokalne\Dane aplikacji\Media Access Startup [2009-09-12 09:10:00 | 00,000,000 | —D | C] – C:\Program Files\DoubleD [2009-09-12 09:10:49 | 00,000,000 | —D | C] – C:\Program Files\Internet Saving Optimizer [2009-09-12 09:11:01 | 00,000,000 | —D | C] – C:\Program Files\Media Access Startup :Commands [emptytemp] [start explorer]