:Processes Explorer.EXE :OTL PRC - [2009-04-02 12:47:04 | 00,234,888 | ---- | M] () – C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe PRC - [2009-04-02 12:47:02 | 00,464,264 | ---- | M] () – C:\Program Files\AskBarDis\bar\bin\AskService.exe SRV - File not found [Auto | Stopped] – -- (MyWebSearchService) SRV - [2009-04-02 12:47:04 | 00,234,888 | ---- | M] () [Auto | Running] – C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe – (ASKUpgrade) SRV - [2009-04-02 12:47:02 | 00,464,264 | ---- | M] () [Auto | Running] – C:\Program Files\AskBarDis\bar\bin\AskService.exe – (ASKService) IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/home IE - HKCU…\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\4.bin\MWSSRCAS.DLL File not found IE - HKCU…\URLSearchHook: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyBa.dll (Conduit Ltd.) FF - prefs.js…browser.search.defaultenginename: “Search the web (Babylon)” FF - prefs.js…browser.search.defaulturl: “http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch” FF - prefs.js…browser.search.order.1: “Search the web (Babylon)” FF - prefs.js…browser.startup.homepage: “http://search.babylon.com/home” FF - prefs.js…extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.5 FF - prefs.js…extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.1[2009-08-06 12:17:57 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\Barbara\Dane aplikacji\Mozilla\Firefox\Profiles\p75bdvo5.default\extensions{E9A1DEE0-C623-4439-8932-001E7D17607D} [2009-12-03 02:49:15 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\Barbara\Dane aplikacji\Mozilla\Firefox\Profiles\p75bdvo5.default\extensions{0545b830-f0aa-4d7e-8820-50a4629a56fe} [2009-11-13 21:02:37 | 00,001,650 | ---- | M] () – C:\Documents and Settings\Barbara\Dane aplikacji\Mozilla\Firefox\Profiles\p75bdvo5.default\searchplugins\longman-english-dictionary.xml [2009-06-05 11:00:44 | 00,009,941 | ---- | M] () – C:\Documents and Settings\Barbara\Dane aplikacji\Mozilla\Firefox\Profiles\p75bdvo5.default\searchplugins\mywebsearch.xml [2009-12-23 21:21:17 | 00,002,101 | ---- | M] () – C:\Documents and Settings\Barbara\Dane aplikacji\Mozilla\Firefox\Profiles\p75bdvo5.default\searchplugins\qtl.xml [2009-11-13 21:01:53 | 00,000,705 | ---- | M] () – C:\Documents and Settings\Barbara\Dane aplikacji\Mozilla\Firefox\Profiles\p75bdvo5.default\searchplugins\webster.xml O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com) O2 - BHO: (myBabylon English Toolbar) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyBa.dll (Conduit Ltd.) O3 - HKLM…\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com) O3 - HKLM…\Toolbar: (myBabylon English Toolbar) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyBa.dll (Conduit Ltd.) O3 - HKCU…\Toolbar\WebBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - Reg Error: Value error. File not found O3 - HKCU…\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com) O3 - HKCU…\Toolbar\WebBrowser: (myBabylon English Toolbar) - {B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - C:\Program Files\myBabylon_English\tbmyBa.dll (Conduit Ltd.) O4 - HKLM…\Run: [My Web Search Bar] C:\PROGRA~1\MYWEBS~1\bar\4.bin\MWSBAR.DLL File not found O4 - HKLM…\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe File not found O4 - HKLM…\Run: [MyWebSearch Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\M3PLUGIN.DLL File not found O4 - HKLM…\Run: [sysgif32] C:\WINDOWS\Temp~TM10.tmp () O4 - HKCU…\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe File not found O4 - Startup: C:\Documents and Settings\Barbara\Menu Start\Programy\Autostart\siszyd32.exe () O33 - MountPoints2{2aeef827-a5ce-11de-a238-001b77c77909}\Shell\AutoRun\command - “” = E:\2nuk.com – File not found O33 - MountPoints2{2aeef827-a5ce-11de-a238-001b77c77909}\Shell\open\Command - “” = E:\2nuk.com – File not found [2009-12-23 22:19:39 | 00,000,000 | ---- | M] () – C:\WINDOWS\System32\drivers\bzdex.sys [2009-12-23 20:55:33 | 08,638,656 | ---- | M] () – C:\Documents and Settings\Barbara\Pulpit\archives.dat [2009-12-19 15:28:05 | 00,000,116 | ---- | M] () – C:\WINDOWS\System32\fjhdyfhsn.bat [2009-12-19 07:39:01 | 00,006,326 | ---- | M] () – C:\WINDOWS\abucamunumatoyaq.dll [2009-12-19 01:21:24 | 00,000,120 | ---- | M] () – C:\WINDOWS\Fqemijucivici.dat [2009-12-18 16:38:08 | 00,005,109 | ---- | M] () – C:\WINDOWS\emadodexadape.dll [2009-12-18 11:57:56 | 00,005,109 | ---- | M] () – C:\WINDOWS\owalihocimaf.dll [2009-12-18 11:40:45 | 00,005,109 | ---- | M] () – C:\WINDOWS\ewupomuk.dll [2009-12-17 23:50:07 | 00,000,004 | ---- | M] () – C:\Documents and Settings\Barbara\Dane aplikacji\avdrn.dat [2009-12-19 07:39:01 | 00,006,326 | ---- | C] () – C:\WINDOWS\abucamunumatoyaq.dll [2009-12-18 19:20:59 | 00,000,020 | ---- | C] () – C:\Documents and Settings\LocalService\Dane aplikacji\fvgqad.dat [2009-12-18 18:32:48 | 00,704,512 | ---- | C] () – C:\WINDOWS\System32\drivers\bzdex.sys [2009-12-18 16:38:08 | 00,005,109 | ---- | C] () – C:\WINDOWS\emadodexadape.dll [2009-12-18 11:57:55 | 00,005,109 | ---- | C] () – C:\WINDOWS\owalihocimaf.dll [2009-12-18 11:40:44 | 00,005,109 | ---- | C] () – C:\WINDOWS\ewupomuk.dll [2009-12-17 23:53:57 | 00,000,000 | ---- | C] () – C:\WINDOWS\Dyucejohera.bin [2009-12-17 23:53:56 | 00,000,120 | ---- | C] () – C:\WINDOWS\Fqemijucivici.dat [2009-12-17 23:50:18 | 00,000,116 | ---- | C] () – C:\WINDOWS\System32\fjhdyfhsn.bat [2009-12-17 23:50:12 | 00,000,020 | ---- | C] () – C:\Documents and Settings\NetworkService\Dane aplikacji\fvgqad.dat [2009-12-17 23:50:07 | 00,000,004 | ---- | C] () – C:\Documents and Settings\Barbara\Dane aplikacji\avdrn.dat [2009-12-23 22:30:09 | 00,293,376 | ---- | M] () – C:\Documents and Settings\Barbara\Pulpit\77eueluv.exe [2009-12-19 15:28:05 | 00,000,116 | ---- | M] () – C:\WINDOWS\System32\fjhdyfhsn.bat [2009-12-19 07:39:01 | 00,006,326 | ---- | M] () – C:\WINDOWS\abucamunumatoyaq.dll [2009-12-19 01:21:24 | 00,000,120 | ---- | M] () – C:\WINDOWS\Fqemijucivici.dat [2009-12-18 19:21:00 | 00,000,020 | ---- | M] () – C:\Documents and Settings\LocalService\Dane aplikacji\fvgqad.dat [2009-12-18 16:38:08 | 00,005,109 | ---- | M] () – C:\WINDOWS\emadodexadape.dll [2009-12-18 11:57:56 | 00,005,109 | ---- | M] () – C:\WINDOWS\owalihocimaf.dll [2009-12-18 11:40:45 | 00,005,109 | ---- | M] () – C:\WINDOWS\ewupomuk.dll [2009-12-23 22:33:52 | 00,000,000 | ---- | M] () – C:\WINDOWS\System32\drivers\bzdex.sys [2009-12-23 22:30:09 | 00,293,376 | ---- | M] () – C:\Documents and Settings\Barbara\Pulpit\77eueluv.exe [2009-12-19 15:28:05 | 00,000,116 | ---- | M] () – C:\WINDOWS\System32\fjhdyfhsn.bat [2009-12-19 07:39:01 | 00,006,326 | ---- | M] () – C:\WINDOWS\abucamunumatoyaq.dll [2009-12-19 01:21:24 | 00,000,120 | ---- | M] () – C:\WINDOWS\Fqemijucivici.dat [2009-12-18 16:38:08 | 00,005,109 | ---- | M] () – C:\WINDOWS\emadodexadape.dll [2009-12-18 11:57:56 | 00,005,109 | ---- | M] () – C:\WINDOWS\owalihocimaf.dll [2009-12-18 11:40:45 | 00,005,109 | ---- | M] () – C:\WINDOWS\ewupomuk.dll [2009-12-17 23:50:07 | 00,000,004 | ---- | M] () – C:\Documents and Settings\Barbara\Dane aplikacji\avdrn.dat :Services MyWebSearchService ASKUpgrade ASKService :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] :Commands [emptytemp] [Reboot]