:OTL
PRC - [2004-08-03 23:44:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q=IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q= IE - HKU\S-1-5-21-602162358-1383384898-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.ask.com/?o=13928&l=dis IE - HKU\S-1-5-21-602162358-1383384898-839522115-1003\..\URLSearchHook: {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll ()
FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..keyword.URL: "http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p="
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKU\S-1-5-21-602162358-1383384898-839522115-1003\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKLM..\Run: [MSN] C:\Windows\svrse.exe File not found
O4 - HKU\S-1-5-21-602162358-1383384898-839522115-1003..\Run: [amva] C:\WINDOWS\System32\amvo.exe File not found
O4 - HKU\S-1-5-21-602162358-1383384898-839522115-1003..\Run: [cdoosoft] C:\DOCUME~1\x\USTAWI~1\Temp\herss.exe File not found
O28 - HKLM ShellExecuteHooks: {BB4C402F-882A-4526-8C08-51278EA437C1} - C:\WINDOWS\System32\e8main0.dll File not found
O32 - AutoRun File - [2009-08-06 00:44:32 | 00,000,063 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-08-06 00:44:32 | 00,000,063 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{02701082-3264-11dd-a380-0013d4da1e76}\Shell\AutoRun\command - "" = H:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe -- File not found
O33 - MountPoints2\{02701082-3264-11dd-a380-0013d4da1e76}\Shell\open\command - "" = H:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe -- File not found
O33 - MountPoints2\{41cb7d05-2583-11dd-93fa-806d6172696f}\Shell\AutoRun\command - "" = 22yj2fy1.exe
O33 - MountPoints2\{41cb7d05-2583-11dd-93fa-806d6172696f}\Shell\open\Command - "" = 22yj2fy1.exe
O33 - MountPoints2\{41cb7d07-2583-11dd-93fa-806d6172696f}\Shell\AutoRun\command - "" = 22yj2fy1.exe
O33 - MountPoints2\{41cb7d07-2583-11dd-93fa-806d6172696f}\Shell\open\Command - "" = 22yj2fy1.exe
O33 - MountPoints2\{5bf15a8c-2ca7-11dd-a374-0013d4da1e76}\Shell\AutoRun\command - "" = G:\x.com -- File not found
O33 - MountPoints2\{5bf15a8c-2ca7-11dd-a374-0013d4da1e76}\Shell\explore\Command - "" = G:\x.com -- File not found
O33 - MountPoints2\{5bf15a8c-2ca7-11dd-a374-0013d4da1e76}\Shell\open\Command - "" = G:\x.com -- File not found
O33 - MountPoints2\{7b45239f-29c6-11dd-a36b-0013d4da1e76}\Shell\AutoRun\command - "" = dwvo.cmd
O33 - MountPoints2\{7b45239f-29c6-11dd-a36b-0013d4da1e76}\Shell\explore\Command - "" = dwvo.cmd
O33 - MountPoints2\{7b45239f-29c6-11dd-a36b-0013d4da1e76}\Shell\open\Command - "" = dwvo.cmd
O33 - MountPoints2\{88a04e08-3490-11dd-a386-0013d4da1e76}\Shell\AutoRun\command - "" = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{88a04e08-3490-11dd-a386-0013d4da1e76}\Shell\open\command - "" = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{8e1f6f9b-3d8b-11dd-a396-0013d4da1e76}\Shell\AutoRun\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{8e1f6f9b-3d8b-11dd-a396-0013d4da1e76}\Shell\open\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{a23ade55-46ab-11de-a3ee-0013d4da1e76}\Shell\AutoRun\command - "" = l61yyp.exe
O33 - MountPoints2\{a23ade55-46ab-11de-a3ee-0013d4da1e76}\Shell\open\Command - "" = l61yyp.exe
O33 - MountPoints2\{d9604bfc-461d-11de-a3ed-0013d4da1e76}\Shell - "" = AutoRun
O33 - MountPoints2\{eb1348d5-2741-11dd-8ff6-0013d4da1e76}\Shell\AutoRun\command - "" = H:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe -- File not found
O33 - MountPoints2\{eb1348d5-2741-11dd-8ff6-0013d4da1e76}\Shell\open\command - "" = H:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe -- File not found
:Files
C:\Program Files\AskSearch
C:\Program Files\AskBarDis
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Acrobat Assistant.lnk
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\AutoCAD Startup Accelerator.lnk
C:\RECYCLER
D:\RECYCLER
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeVersionCue"=-
"Alcmtr"=-
"HP Software Update"=-
"NeroFilterCheck"=-
"nwiz"=-
"QuickTime Task"=-
"RTHDCPL"=-
"SkyTel"=-
"WinampAgent"=-
:Commands
[emptytemp]
[start explorer]