:OTL SRV - [2011-10-30 12:45:17 | 000,258,048 | ---- | M] () [Auto | Running] – C:\Windows\sysdriver32.exe – (srvsysdriver32) IE - HKU\S-1-5-21-173154198-3789174218-2691514718-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?l=dis&o=15430 IE - HKU\S-1-5-21-173154198-3789174218-2691514718-1000…\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) [2011-10-30 08:35:36 | 000,000,000 | —D | M] (Ask Toolbar) – C:\Users\master\AppData\Roaming\mozilla\Firefox\Profiles\6f4m5p5p.default\extensions\toolbar@ask.com [2011-02-01 19:05:08 | 000,002,333 | ---- | M] () – C:\Users\master\AppData\Roaming\Mozilla\Firefox\Profiles\6f4m5p5p.default\searchplugins\askcom.xml O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) O3:64bit: - HKLM…\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll File not found O3 - HKLM…\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll File not found O3 - HKLM…\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKLM…\Toolbar: (no name) - Locked - No CLSID value found. O4:64bit: - HKLM…\Run: [ASUS WebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe File not found O4:64bit: - HKLM…\Run: [setwallpaper] c:\programdata\SetWallpaper.cmd File not found O4 - HKLM…\Run: [1077765.exe] “C:\Windows\TEMP\1077765.exe” File not found O4 - HKLM…\Run: [1078780.exe] “C:\Users\master\AppData\Local\Temp\1078780.exe” File not found O4 - HKLM…\Run: [1801776.exe] “C:\Users\master\AppData\Local\Temp\1801776.exe” File not found O4 - HKLM…\Run: [516538.exe] “C:\Users\master\AppData\Local\Temp\516538.exe” File not found O4 - HKLM…\Run: [7305195.exe] “C:\Windows\TEMP\7305195.exe” File not found O4 - HKLM…\Run: [sysdriver32.exe] C:\Windows\sysdriver32.exe () O4 - HKLM…\Run: [sysdriver32_.exe] C:\Windows\sysdriver32_.exe () O4 - HKLM…\Run: [tray_ico0] C:\Windows\update.tray-8-0\svchost.exe (Cronosoft) O4 - HKLM…\Run: [tray_ico1] C:\Windows\update.tray-15-0\svchost.exe (Cronosoft) O4 - HKLM…\Run: [tray_ico2] C:\Windows\update.tray-7-0\svchost.exe (Cronosoft) [2011-10-30 12:51:18 | 000,000,000 | —D | C] – C:\Windows\rpcminer [2011-10-30 12:51:18 | 000,000,000 | —D | C] – C:\Windows\phoenix [2011-10-30 12:47:04 | 000,000,000 | -H-D | C] – C:\Windows\update.5.0 [2011-10-30 12:46:07 | 000,000,000 | -H-D | C] – C:\Windows\update.2 [2011-10-30 08:35:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ask.com [2011-10-30 08:06:47 | 000,000,000 | —D | C] – C:\Users\master\AppData\Local\OpenCandy [2011-10-30 08:06:46 | 000,000,000 | —D | C] – C:\Users\master\AppData\Roaming\OpenCandy [2011-10-28 23:47:57 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-7-0-lnk [2011-10-28 23:47:57 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-7-0 [2011-10-28 21:51:23 | 000,000,000 | —D | C] – C:\Windows\ufa [2011-10-28 16:57:12 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-15-0-lnk [2011-10-28 16:57:12 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-15-0 [2011-10-28 16:05:20 | 000,000,000 | —D | C] – C:\Windows\av_ico [2011-10-28 16:03:46 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-8-0-lnk [2011-10-28 16:03:46 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-8-0 [2011-10-30 12:57:20 | 000,000,734 | ---- | M] () – C:\Windows\SysNative\drivers\etc\hîsts [2011-10-30 12:51:17 | 005,589,370 | ---- | M] () – C:\Windows\phoenix.rar [2011-10-30 12:51:17 | 001,075,284 | ---- | M] () – C:\Windows\rpcminer.rar [2011-10-30 12:51:17 | 000,246,272 | ---- | M] () – C:\Windows\unrar.exe [2011-10-30 12:51:17 | 000,182,617 | ---- | M] () – C:\Windows\ufa.rar [2011-10-30 12:47:50 | 000,000,113 | ---- | M] () – C:\Windows\info1 [2011-10-30 12:46:37 | 000,000,000 | ---- | M] () – C:\Windows\loader2.exe_ok [2011-10-30 12:46:21 | 000,904,792 | ---- | M] () – C:\Windows\geoiplist.rar [2011-10-30 12:45:17 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32_.exe [2011-10-30 12:45:17 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32.exe [2011-10-29 21:23:00 | 000,000,910 | ---- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-173154198-3789174218-2691514718-1000Core.job [2011-10-30 10:23:26 | 000,000,932 | ---- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-173154198-3789174218-2691514718-1000UA.job :Reg [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot] “AlternateShell”=“cmd.exe” :Commands [emptytemp] [resethosts]