:OTL SRV - File not found [unknown | Stopped] – -- (MSDTC) SRV - File not found [Auto | Stopped] – C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe – (AntiVirService) SRV - File not found [Auto | Stopped] – C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe – (AntiVirScheduler) SRV - [2010-12-01 21:53:45 | 000,007,168 | ---- | M] () [Auto | Stopped] – C:\Windows\System32\SysPathName.exe – (SysPathName) SRV - [2010-12-01 21:53:24 | 000,036,932 | ---- | M] () [Auto | Stopped] – C:\Windows\System32\sdvvqeytcl.td – (JavaServe) DRV - File not found [File_System | On_Demand | Stopped] – C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys – (avgntflt) DRV - File not found [Kernel | System | Stopped] – C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys – (avgio) FF - prefs.js…browser.search.defaultengine: “Ask.com” FF - prefs.js…browser.search.defaultenginename: “Ask.com” FF - prefs.js…browser.search.order.1: “Ask.com” [2010-11-12 18:05:19 | 000,000,000 | —D | M] – C:\Users\Mateusz\AppData\Roaming\mozilla\Firefox\Profiles\2ncewktp.default\extensions\toolbar@ask.com [2010-05-26 14:18:50 | 000,002,333 | ---- | M] () – C:\Users\Mateusz\AppData\Roaming\Mozilla\FireFox\Profiles\2ncewktp.default\searchplugins\askcom.xml O3 - HKU\S-1-5-21-3867850544-2346939825-3150579051-1000…\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O4 - HKLM…\Run: [avgnt] C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe File not found O4 - HKLM…\Run: [NPSStartup] File not found O4 - HKU\S-1-5-21-3867850544-2346939825-3150579051-1000…\Run: [AdobeBridge] File not found DRV - [2007-03-01 10:34:36 | 000,028,352 | ---- | M] (Avira GmbH) [Kernel | System | Running] – C:\Windows\System32\drivers\ssmdrv.sys – (ssmdrv) MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^vjgvwgvveb.exe - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vjgvwgvveb.exe - () MsConfig - StartUpReg: Adobe Photo Downloader - hkey= - key= - C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe File not found [2010-12-01 21:53:27 | 000,000,000 | —D | C] – C:\Windows\srftcet [2010-12-01 21:53:23 | 000,000,000 | -HSD | C] – C:\VSPS [2010-12-01 21:53:05 | 000,000,000 | —D | C] – C:\Windows\System32\mahaslquas [2010-12-01 21:53:05 | 000,000,000 | —D | C] – C:\Windows\System32\ehfcrrdppt [2010-12-01 21:52:25 | 000,070,920 | ---- | C] (Microsoft Corporation) – C:\Windows\System32\bhoexe.dll [2010-12-03 16:00:09 | 000,000,815 | ---- | M] () – C:\Users\Public\Desktop\Intennet Exploner.lnk [2010-12-03 16:00:09 | 000,000,087 | ---- | M] () – C:\Users\Public\Desktop\ĚÔ±¦ąşÎďA.url [2010-12-03 16:00:09 | 000,000,077 | ---- | M] () – C:\Users\Public\Desktop\Ăâ·ŃµçÓ°C.url [2010-12-03 16:00:09 | 000,000,077 | ---- | M] () – C:\Users\Public\Desktop\¸Ä±äÄăµÄŇ»Éú.url [2010-12-01 21:53:45 | 000,007,168 | ---- | M] () – C:\Windows\System32\SysPathName.exe [2010-12-01 21:53:35 | 000,000,004 | RHS- | M] () – C:\Windows\System32\drivers\etc\hosts [2010-12-01 21:53:24 | 000,036,932 | R— | M] () – C:\Program Files\Common Files\xiiuysr.vm [2010-12-01 21:53:24 | 000,036,932 | R— | M] () – C:\Program Files\Common Files\rileiqk.la [2010-12-01 21:53:24 | 000,036,932 | R— | M] () – C:\Program Files\Common Files\pehsfmt.aw [2010-12-01 21:53:24 | 000,036,932 | R— | M] () – C:\Program Files\Common Files\ncpcauk.zu [2010-12-01 21:53:24 | 000,036,932 | R— | M] () – C:\Program Files\Common Files\ikgiucl.zo [2010-12-01 21:53:24 | 000,036,932 | R— | M] () – C:\Program Files\Common Files\ickuyms.ek [2010-12-01 21:53:24 | 000,036,932 | R— | M] () – C:\Program Files\Common Files\gsbslac.hu [2010-12-01 21:53:24 | 000,036,932 | ---- | M] () – C:\Windows\System32\sdvvqeytcl.td [2010-12-01 21:53:24 | 000,000,342 | ---- | M] () – C:\Windows\System32\SetUp.inf [2010-12-01 21:53:24 | 000,000,089 | ---- | M] () – C:\Windows\run.bat [2010-12-01 21:53:06 | 000,082,801 | ---- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vjgvwgvveb.exe [2010-12-01 21:52:25 | 000,070,920 | ---- | M] (Microsoft Corporation) – C:\Windows\System32\bhoexe.dll [2010-12-01 21:50:46 | 000,001,630 | R— | M] () – C:\Program Files\nowlist.dat [2010-12-01 21:50:15 | 000,018,420 | ---- | M] () – C:\Users\Mateusz\AppData\Roaming\a.exe [2010-09-01 06:14:13 | 000,000,312 | ---- | M] () – C:\Windows\Tasks\At1.job @Alternate Data Stream - 943 bytes -> C:\ProgramData\TEMP:24721E3C :Files C:\Windows\System32\mahaslquas\smss.exe C:\Windows\System32\ehfcrrdppt\explorer.exe RECYCLER /alldrives C:\Program Files\Ask.com :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] :Commands [resethosts] [emptytemp]