ComboFix 14-02-24.02 - Marcin 2014-02-27 20:02:44.1.2 - x64 Microsoft Windows 8 6.2.9200.0.1250.48.1045.18.3674.1997 [GMT 1:00] Uruchomiony z: C:\Users\Marcin\Downloads\ComboFix.exe AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) C:\END C:\Program Files (x86)\Smileys We Love Toolbar for IE\adXLoader.dll C:\Program Files (x86)\Speed Test 127\ScRIpthost.dll C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default\bProtectorPreferences C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage ((((((((((((((((((((((((( Pliki utworzone od 2014-01-27 do 2014-02-27 ))))))))))))))))))))))))))))))) 2014-02-27 19:17:06 . 2014-02-27 19:17:06 -------- d-----w- C:\Users\Default\AppData\Local\temp 2014-02-05 19:03:51 . 2014-02-05 19:03:51 -------- d-----w- C:\Users\Marcin\AppData\Roaming\1H1Q 2014-02-05 18:39:16 . 2014-02-05 18:39:16 -------- d-----w- C:\Users\Marcin\AppData\Roaming\FoxTab 2014-02-05 18:39:04 . 2014-02-05 18:39:08 -------- d-----w- C:\Program Files (x86)\Foxtab . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{fe063412-bea4-4d76-8ed3-183be6220d17}] 2013-08-21 17:36:54 100336 ----a-w- C:\Program Files (x86)\BonanzaDeals\BonanzaDealsIE.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "UpdateChecker"="C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\UpdateCheckerApp.exe" [2013-08-25 21:44:26 7168] "uTorrent"="C:\Users\Marcin\AppData\Roaming\uTorrent\uTorrent.exe" [2014-01-24 16:37:25 905296] "NextLive"="C:\Users\Marcin\AppData\Roaming\newnext.me\nengine.dll" [2014-01-25 23:40:10 1283584] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-08-06 11:30:40 642216] "CLVirtualDrive"="C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" [2012-07-26 11:04:09 491320] "RemoteControl10"="C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2012-03-28 16:34:30 91432] "HP Quick Launch"="C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2012-07-09 11:40:02 580512] "Adobe Creative Cloud"="C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2013-10-17 17:54:44 2237328] "mobilegeni daemon"="C:\Program Files (x86)\Mobogenie\DaemonProcess.exe" [2014-01-28 18:09:12 775872] C:\Users\Marcin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ MyPC Backup.lnk - C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe [2013-9-19 1953320] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\ simplicheck.lnk - C:\Program Files (x86)\simplitec\simplicheck\simplicheck.exe -timer [2012-10-22 2936168] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "EnableUIADesktopToggle"= 0 (0x0) "EnableCursorSuppression"= 1 (0x1) "ConsentPromptBehaviorUser"= 3 (0x3) "DisableCAD"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) R2 bonanzadealslive;UsA‚uga BonanzaDealsLive (bonanzadealslive);C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe;C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [x] R2 PLAY ONLINE. RunOuc;PLAY ONLINE. OUC;C:\Program Files (x86)\PLAY ONLINE\UpdateDog\ouc.exe;C:\Program Files (x86)\PLAY ONLINE\UpdateDog\ouc.exe [x] R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [x] R3 ATHDFU;Qualcomm Atheros Valkyrie USB BootROM;C:\Windows\System32\Drivers\AthDfu.sys;C:\Windows\SYSNATIVE\Drivers\AthDfu.sys [x] R3 bonanzadealslivem;UsA‚uga BonanzaDealsLive (bonanzadealslivem);C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe;C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [x] R3 BthLEEnum;Sterownik funkcji Bluetooth Low Energy;C:\Windows\system32\DRIVERS\BthLEEnum.sys;C:\Windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\system32\DRIVERS\ssudbus.sys;C:\Windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;C:\Windows\system32\DRIVERS\ew_hwusbdev.sys;C:\Windows\SYSNATIVE\DRIVERS\ew_hwusbdev.sys [x] R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [x] R3 huawei_cdcecm;huawei_cdcecm;C:\Windows\system32\DRIVERS\ew_jucdcecm.sys;C:\Windows\SYSNATIVE\DRIVERS\ew_jucdcecm.sys [x] R3 iaStorA;iaStorA;C:\Windows\System32\drivers\iaStorA.sys;C:\Windows\SYSNATIVE\drivers\iaStorA.sys [x] R3 lehidmini;Bluetooth Low Energy Hid Device;C:\Windows\System32\drivers\leath_hid.sys;C:\Windows\SYSNATIVE\drivers\leath_hid.sys [x] R3 SmbDrv;SmbDrv;C:\Windows\System32\drivers\Smb_driver_AMDASF.sys;C:\Windows\SYSNATIVE\drivers\Smb_driver_AMDASF.sys [x] R3 SmbDrvI;SmbDrvI;C:\Windows\System32\drivers\Smb_driver_Intel.sys;C:\Windows\SYSNATIVE\drivers\Smb_driver_Intel.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\system32\DRIVERS\ssudmdm.sys;C:\Windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R4 BitGuard;BitGuard;C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe;C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [x] S0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys;C:\Windows\SYSNATIVE\drivers\amd_sata.sys [x] S0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys;C:\Windows\SYSNATIVE\drivers\amd_xata.sys [x] S1 CLVirtualDrive;CLVirtualDrive;C:\Windows\system32\DRIVERS\CLVirtualDrive.sys;C:\Windows\SYSNATIVE\DRIVERS\CLVirtualDrive.sys [x] S2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [x] S2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe;C:\Windows\SYSNATIVE\atiesrxx.exe [x] S2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x] S2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\adminservice.exe;C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [x] S2 BackupStack;Computer Backup (MyPC Backup);C:\Program Files (x86)\MyPC Backup\BackupStack.exe;C:\Program Files (x86)\MyPC Backup\BackupStack.exe [x] S2 Fabs;FABS - Helping agent for MAGIX media database;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [x] S2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x] S2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [x] S2 HWDeviceService64.exe;HWDeviceService64.exe;C:\ProgramData\DatacardService\HWDeviceService64.exe;C:\ProgramData\DatacardService\HWDeviceService64.exe [x] S2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x] S2 ZAtheros Bt&Wlan Coex Agent;ZAtheros Bt&Wlan Coex Agent;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x] S3 AthBTPort;Qualcomm Atheros Virtual Bluetooth Class;C:\Windows\system32\DRIVERS\btath_flt.sys;C:\Windows\SYSNATIVE\DRIVERS\btath_flt.sys [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW86.sys;C:\Windows\SYSNATIVE\drivers\AtihdW86.sys [x] S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\system32\drivers\btath_a2dp.sys;C:\Windows\SYSNATIVE\drivers\btath_a2dp.sys [x] S3 btath_avdt;Qualcomm Atheros Bluetooth AVDT Service;C:\Windows\system32\drivers\btath_avdt.sys;C:\Windows\SYSNATIVE\drivers\btath_avdt.sys [x] S3 BTATH_BUS;Qualcomm Atheros Bluetooth Bus;C:\Windows\System32\drivers\btath_bus.sys;C:\Windows\SYSNATIVE\drivers\btath_bus.sys [x] S3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\System32\drivers\btath_hcrp.sys;C:\Windows\SYSNATIVE\drivers\btath_hcrp.sys [x] S3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\system32\DRIVERS\btath_lwflt.sys;C:\Windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x] S3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\System32\drivers\btath_rcp.sys;C:\Windows\SYSNATIVE\drivers\btath_rcp.sys [x] S3 BtFilter;BtFilter;C:\Windows\system32\DRIVERS\btfilter.sys;C:\Windows\SYSNATIVE\DRIVERS\btfilter.sys [x] S3 ew_usbenumfilter;huawei_CompositeFilter;C:\Windows\System32\drivers\ew_usbenumfilter.sys;C:\Windows\SYSNATIVE\drivers\ew_usbenumfilter.sys [x] S3 huawei_cdcacm;huawei_cdcacm;C:\Windows\system32\DRIVERS\ew_jucdcacm.sys;C:\Windows\SYSNATIVE\DRIVERS\ew_jucdcacm.sys [x] S3 huawei_enumerator;huawei_enumerator;C:\Windows\System32\drivers\ew_jubusenum.sys;C:\Windows\SYSNATIVE\drivers\ew_jubusenum.sys [x] S3 huawei_ext_ctrl;huawei_ext_ctrl;C:\Windows\System32\drivers\ew_juextctrl.sys;C:\Windows\SYSNATIVE\drivers\ew_juextctrl.sys [x] S3 huawei_wwanecm;huawei_wwanecm;C:\Windows\system32\DRIVERS\ew_juwwanecm.sys;C:\Windows\SYSNATIVE\DRIVERS\ew_juwwanecm.sys [x] S3 RSP2STOR;Realtek PCIE CardReader Driver - P2;C:\Windows\system32\DRIVERS\RtsP2Stor.sys;C:\Windows\SYSNATIVE\DRIVERS\RtsP2Stor.sys [x] S3 RTL8168;Realtek 8168 NT Driver;C:\Windows\system32\DRIVERS\Rt630x64.sys;C:\Windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [x] S3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\DRIVERS\usbfilter.sys;C:\Windows\SYSNATIVE\DRIVERS\usbfilter.sys [x] S3 WirelessButtonDriver;HP Wireless Button Driver Service;C:\Windows\System32\drivers\WirelessButtonDriver64.sys;C:\Windows\SYSNATIVE\drivers\WirelessButtonDriver64.sys [x] S3 WUDFWpdComp;WUDFWpdComp;C:\Windows\system32\DRIVERS\WUDFRd.sys;C:\Windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x] S3 WUDFWpdMtp;WUDFWpdMtp;C:\Windows\system32\DRIVERS\WUDFRd.sys;C:\Windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x] [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] apphost REG_MULTI_SZ apphostsvc iissvcs REG_MULTI_SZ w3svc was [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-02-22 09:13:32 1150280 ----a-w- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\Installer\chrmstp.exe Zawartość folderu 'Zaplanowane zadania' 2014-02-27 C:\Windows\Tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-17 13:48:59 . 2014-02-20 18:59:49] 2014-02-25 C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job - C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-12-23 19:40:24 . 2013-12-23 19:40:14] 2014-02-27 C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job - C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-12-23 19:40:24 . 2013-12-23 19:40:14] 2014-02-23 C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-24 08:44:25 . 2013-01-24 08:44:24] 2014-02-27 C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-24 08:44:25 . 2013-01-24 08:44:24] 2014-02-23 C:\Windows\Tasks\PC Performer_DEFAULT.job - C:\Program Files (x86)\PC Performer\PCPerformer.exe [2014-01-20 11:05:36 . 2013-06-19 13:58:22] 2014-01-21 C:\Windows\Tasks\PC Performer_UPDATES.job - C:\Program Files (x86)\PC Performer\PCPerformer.exe [2014-01-20 11:05:36 . 2013-06-19 13:58:22] --------- X64 Entries ----------- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1] @="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}" [HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}] 2013-10-16 17:02:12 3358064 ----a-w- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2] @="{853B7E05-C47D-4985-909A-D0DC5C6D7303}" [HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}] 2013-10-16 17:02:12 3358064 ----a-w- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3] @="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}" [HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}] 2013-10-16 17:02:12 3358064 ----a-w- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-06-12 21:42:02 6548112] "BtPreLoad"="C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe" [2012-08-07 16:15:48 65152] "AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-09-25 02:45:54 472984] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\PROGRA~3\BitGuard\271832~1.68\{C16C1~1\loader.dll ------- Skan uzupełniający ------- uStart Page = hxxp://www2.delta-search.com/?babsrc=HP_ss&mntrId=D6CC582C80139263&affID=123627&tsp=5003 uLocal Page = C:\Windows\system32\blank.htm mLocal Page = C:\Windows\SysWOW64\blank.htm IE: {{07BA1DA9-F501-4796-8728-74D1B91A6CD5} - C:\Program Files (x86)\PokerStars.EU\PokerStarsUpdate.exe TCP: Interfaces\{08508FE6-8165-40A2-95EE-ACE4460BDD98}: NameServer = 89.108.202.20 89.108.195.20 TCP: Interfaces\{09F5BEB4-4577-4BAD-A9D5-133240004B1D}: NameServer = 89.108.195.20 89.108.202.20 TCP: Interfaces\{43E46B34-D5C4-46AE-9BC0-650ED3CB80BB}: NameServer = 89.108.202.21 89.108.195.21 TCP: Interfaces\{4792D987-69E7-4A36-B84D-473457C9C99D}: NameServer = 89.108.195.20 89.108.202.20 TCP: Interfaces\{717623AB-EF26-4181-B172-E56376D15CD1}: NameServer = 89.108.195.20 89.108.202.20 TCP: Interfaces\{D6C6BE3B-3F75-442B-A42D-1E1A4297715C}: NameServer = 89.108.202.21 89.108.195.21 FF - ProfilePath - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\9zgmfx2h.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&CUI=UN12348900371566119&UM=1&SearchSource=3&q={searchTerms} FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1750559&CUI=UN12348900371566119&UM=1&SearchSource=13 FF - user.js: extensions.delta.tlbrSrchUrl - FF - user.js: extensions.delta.id - d6cc1fb500000000000012689d9ba93e FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} FF - user.js: extensions.delta.instlDay - 15864 FF - user.js: extensions.delta.vrsn - 1.8.21.5 FF - user.js: extensions.delta.vrsni - 1.8.21.5 FF - user.js: extensions.delta.vrsnTs - 1.8.21.510:55:22 FF - user.js: extensions.delta.prtnrId - delta FF - user.js: extensions.delta.prdct - delta FF - user.js: extensions.delta.aflt - babsst FF - user.js: extensions.delta.smplGrp - none FF - user.js: extensions.delta.tlbrId - base FF - user.js: extensions.delta.instlRef - sst FF - user.js: extensions.delta.dfltLng - en FF - user.js: extensions.delta.excTlbr - false FF - user.js: extensions.delta.ffxUnstlRst - true FF - user.js: extensions.delta.admin - false FF - user.js: extensions.delta_i.babTrack - affID=121562 FF - user.js: extensions.delta_i.babExt - FF - user.js: extensions.delta_i.srcExt - ss FF - user.js: extensions.delta.autoRvrt - false FF - user.js: extensions.delta.rvrt - false FF - user.js: extensions.delta.newTab - false FF - user.js: extensions.irspeeddial.aflt - fxtb103 FF - user.js: extensions.irspeeddial.instlRef - FF - user.js: extensions.irspeeddial.cr - 530549640 FF - user.js: extensions.irspeeddial.cd - 2XzuyEtN2Y1L1QzuyDzztB0CzztDtCtAzytByCtAtC0F0ByDtN0D0Tzu0CyByCyBtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1Czu1G2Z1S - - - - USUNIĘTO PUSTE WPISY - - - - BHO-{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} - C:\Program Files (x86)\Speed Test 127\ScriptHost.dll BHO-{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775} - C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader.dll Toolbar-{CF0F43AB-9C23-4D7B-8040-201B82844854} - C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader.dll Wow6432Node-HKCU-Run-Pokki - %LOCALAPPDATA%\Pokki\Engine\Launcher.dll Wow6432Node-HKLM-Run-TrayServer - C:\Program Files (x86)\MAGIX\Video_deluxe_17_Premium_Version_para_descargar\TrayServer_es.exe HKLM-Run-SynTPEnh - C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-Speed Test 4354 - C:\Program Files (x86)\Speed Test 4354\uninst.exe AddRemove-{B8019B54-F9BE-490A-9619-6D06F18F129F} - C:\Program Files (x86)\InstallShield Installation Information\{B8019B54-F9BE-490A-9619-6D06F18F129F}\setup.exe AddRemove-1540585613.portal.qtrax.com - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\Silverlight.Configuration.exe AddRemove-William Hill CASINO CLUB - C:\Casino\William Hill CASINO CLUB\_SetupCasino_c1a647_pl.exe