:OTL
PRC - [2011-06-12 22:19:09 | 000,344,064 | -HS- | M] (Microsoft Corporation) -- C:\Users\Shimer\AppData\Local\unq.exe
FF - prefs.js..extensions.enabledItems:
[email protected]:3.12.2.16749
[2011-06-12 08:05:40 | 000,000,000 | ---D | M] (Foxit PDF Creator Toolbar) -- C:\Users\Shimer\AppData\Roaming\mozilla\Firefox\Profiles\9zrhh18b.default\extensions\
[email protected] O3:
64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] File not found
O35 - HKU\S-1-5-21-1625244150-408765870-67761525-1000..exefile [open] -- "C:\Users\Shimer\AppData\Local\unq.exe" -a "%1" %* (Microsoft Corporation)
O37 - HKU\S-1-5-21-1625244150-408765870-67761525-1000\...exe [@ = exefile] -- "C:\Users\Shimer\AppData\Local\unq.exe" -a "%1" %* (Microsoft Corporation)
[2011-06-12 22:19:12 | 000,344,064 | -HS- | C] (Microsoft Corporation) -- C:\Users\Shimer\AppData\Local\rwy.exe
[2011-06-12 22:19:09 | 000,344,064 | -HS- | C] (Microsoft Corporation) -- C:\Users\Shimer\AppData\Local\unq.exe
[2011-06-12 22:19:05 | 000,344,064 | -HS- | C] (Microsoft Corporation) -- C:\Users\Shimer\AppData\Local\vxw.exe
[2011-06-13 15:33:57 | 000,011,188 | -HS- | M] () -- C:\Users\Shimer\AppData\Local\55i6emprlt00
[2011-06-12 22:21:19 | 000,011,180 | -HS- | M] () -- C:\ProgramData\55i6emprlt00
:Files
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
C:\Users\Shimer\AppData\Local\Temp*.html
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBAgent"=-
:Commands
[clearallrestorepoints]
[emptytemp]