:OTL PRC - [2011-08-21 20:25:12 | 000,355,840 | ---- | M] () – C:\Windows\update.5.0\svchost.exe PRC - [2011-08-21 20:25:12 | 000,355,840 | ---- | M] () – C:\Windows\update.5.0\svchost.exe PRC - [2011-08-21 19:58:33 | 000,232,960 | ---- | M] () – C:\Windows\l1rezerv.exe PRC - [2011-08-21 19:54:48 | 000,634,880 | ---- | M] () – C:\Windows\update.2\svchost.exe PRC - [2011-08-21 19:54:48 | 000,634,880 | ---- | M] () – C:\Windows\update.2\svchost.exe PRC - [2011-08-21 19:53:22 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32_.exe PRC - [2011-08-21 19:53:22 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32.exe PRC - [2011-08-21 19:52:48 | 001,213,440 | -H-- | M] () – C:\Windows\update.tray-7-0\svchost.exe PRC - [2011-08-21 19:52:48 | 001,213,440 | -H-- | M] () – C:\Windows\update.1\svchost.exe MOD - [2011-08-21 19:58:33 | 000,232,960 | ---- | M] () – C:\Windows\l1rezerv.exe MOD - [2011-08-21 19:53:22 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32_.exe MOD - [2011-08-21 19:53:22 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32.exe MOD - [2011-08-21 19:52:48 | 001,213,440 | -H-- | M] () – C:\Windows\update.tray-7-0\svchost.exe SRV - File not found [Auto | Stopped] – -- (ddservice) SRV - [2011-08-21 20:25:12 | 000,355,840 | ---- | M] () [Auto | Running] – C:\Windows\update.5.0\svchost.exe – (srvbtcclient) SRV - [2011-08-21 19:54:48 | 000,634,880 | ---- | M] () [Auto | Running] – C:\Windows\update.2\svchost.exe – (srviecheck) SRV - [2011-08-21 19:53:22 | 000,258,048 | ---- | M] () [Auto | Running] – C:\Windows\sysdriver32.exe – (srvsysdriver32) SRV - [2011-08-21 19:52:48 | 001,213,440 | -H-- | M] () [Auto | Running] – C:\Windows\update.1\svchost.exe – (wxpdrivers) IE - HKLM…\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.) IE - HKLM…\URLSearchHook: {c86eb8a9-ccc2-4b6c-b75d-73576ed591bf} - C:\Program Files\Softonic-Polska\tbSoft.dll (Conduit Ltd.) IE - HKCU…\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.) IE - HKCU…\URLSearchHook: {c86eb8a9-ccc2-4b6c-b75d-73576ed591bf} - C:\Program Files\Softonic-Polska\tbSoft.dll (Conduit Ltd.) FF - prefs.js…browser.search.defaulturl: “http://search.conduit.com/ResultsExt.aspx?ctid=CT2530240&SearchSource=3&q={searchTerms}” FF - prefs.js…browser.startup.homepage: “http://www.mydtzone.com/startpage|http://www.daemon-search.com/startpage|http://search.conduit.com/?ctid=CT2786678&SearchSource=13” FF - prefs.js…keyword.URL: “http://search.conduit.com/ResultsExt.aspx?ctid=CT2530240&SearchSource=2&q=” [2011-06-15 15:11:18 | 000,000,000 | —D | M] (“DAEMON Tools Toolbar”) – C:\Users\Pavilion\AppData\Roaming\mozilla\Firefox\Profiles\9k8gf8ha.default\extensions\DTToolbar@toolbarnet.com [2011-05-29 11:27:01 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\Pavilion\AppData\Roaming\mozilla\Firefox\Profiles\9k8gf8ha.default\extensions\engine@conduit.com [2011-05-25 16:53:16 | 000,000,933 | ---- | M] () – C:\Users\Pavilion\AppData\Roaming\Mozilla\Firefox\Profiles\9k8gf8ha.default\searchplugins\conduit.xml O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - File not found O2 - BHO: (Softonic-Polska Toolbar) - {c86eb8a9-ccc2-4b6c-b75d-73576ed591bf} - C:\Program Files\Softonic-Polska\tbSoft.dll (Conduit Ltd.) O3 - HKLM…\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O3 - HKLM…\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKLM…\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - File not found O3 - HKLM…\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.) O3 - HKLM…\Toolbar: (Softonic-Polska Toolbar) - {c86eb8a9-ccc2-4b6c-b75d-73576ed591bf} - C:\Program Files\Softonic-Polska\tbSoft.dll (Conduit Ltd.) O3 - HKCU…\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKCU…\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.) O3 - HKCU…\Toolbar\WebBrowser: (Softonic-Polska Toolbar) - {C86EB8A9-CCC2-4B6C-B75D-73576ED591BF} - C:\Program Files\Softonic-Polska\tbSoft.dll (Conduit Ltd.) O4 - HKLM…\Run: [1818828.exe] C:\Windows\Temp\1818828.exe () O4 - HKLM…\Run: [3025165.exe] C:\Windows\Temp\3025165.exe () O4 - HKLM…\Run: [4404976.exe] C:\Windows\Temp\4404976.exe () O4 - HKLM…\Run: [4590738.exe] C:\Users\Pavilion\AppData\Local\Temp\4590738.exe () O4 - HKLM…\Run: [7343558.exe] C:\Users\Pavilion\AppData\Local\Temp\7343558.exe () O4 - HKLM…\Run: [871850-loader2.exe] C:\Windows\Temp\871850-loader2.exe () O4 - HKLM…\Run: [avast] File not found O4 - HKLM…\Run: [l1rezerv.exe] C:\Windows\l1rezerv.exe () O4 - HKLM…\Run: [sysdriver32.exe] C:\Windows\sysdriver32.exe () O4 - HKLM…\Run: [sysdriver32_.exe] C:\Windows\sysdriver32_.exe () O4 - HKLM…\Run: [tray_ico] File not found O4 - HKLM…\Run: [tray_ico0] C:\Windows\update.tray-7-0\svchost.exe () O4 - HKLM…\Run: [tray_ico1] File not found O4 - HKLM…\Run: [tray_ico2] File not found O4 - HKLM…\Run: [tray_ico3] File not found O4 - HKLM…\Run: [tray_ico4] File not found O4 - HKLM…\Run: [wxpdrv] C:\Windows\services32.exe () [2011-08-21 20:02:32 | 000,000,000 | —D | C] – C:\Windows\av_ico [2011-08-21 20:01:17 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-7-0-lnk [2011-08-21 20:01:17 | 000,000,000 | -H-D | C] – C:\Windows\update.tray-7-0 [2011-08-21 19:56:51 | 000,000,000 | —D | C] – C:\Windows\ufa [2011-08-21 19:56:51 | 000,000,000 | —D | C] – C:\Windows\rpcminer [2011-08-21 19:56:51 | 000,000,000 | —D | C] – C:\Windows\phoenix [2011-08-21 19:54:49 | 000,000,000 | -H-D | C] – C:\Windows\update.2 [2011-08-21 19:54:07 | 000,000,000 | -H-D | C] – C:\Windows\update.5.0 [2011-08-21 19:53:05 | 000,000,000 | -H-D | C] – C:\Windows\update.1 [2011-08-21 20:27:46 | 000,000,734 | ---- | M] () – C:\Windows\System32\drivers\etc\hîsts [2011-08-21 20:25:13 | 000,000,177 | ---- | M] () – C:\Windows\info1 [2011-08-21 19:58:33 | 000,232,960 | ---- | M] () – C:\Windows\l1rezerv.exe [2011-08-21 19:56:50 | 005,589,370 | ---- | M] () – C:\Windows\phoenix.rar [2011-08-21 19:56:50 | 001,075,284 | ---- | M] () – C:\Windows\rpcminer.rar [2011-08-21 19:56:50 | 000,246,272 | ---- | M] () – C:\Windows\unrar.exe [2011-08-21 19:56:50 | 000,182,617 | ---- | M] () – C:\Windows\ufa.rar [2011-08-21 19:56:29 | 000,904,792 | ---- | M] () – C:\Windows\geoiplist.rar [2011-08-21 19:53:53 | 000,000,000 | ---- | M] () – C:\Windows\loader2.exe_ok [2011-08-21 19:53:22 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32_.exe [2011-08-21 19:53:22 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32.exe [2011-08-21 19:52:48 | 001,213,440 | ---- | M] () – C:\Windows\services32.exe [2011-08-21 19:55:42 | 004,636,907 | ---- | C] () – C:\Windows\geoiplist :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] :Commands [CLEARALLRESTOREPOINTS] [RESETHOSTS] [emptytemp]