:OTL
IE - HKU\S-1-5-21-746137067-1220945662-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?l=dis&o=15183
IE - HKU\S-1-5-21-746137067-1220945662-725345543-1003\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "Softonic-Eng7 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2405280&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..extensions.enabledItems:
toolbar@ask.com:3.9.1.14019
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=PF&o=14778&locale=en_US&apn_uid=7639AFCC-A69F-47BF-9220-04FF1B2E217F&apn_ptnrs=VX&apn_sauid=347DD39A-23A6-4829-92F4-09FDFC270F52&apn_dtid=&&q="
[2011-09-28 18:22:36 | 000,000,000 | ---D | M] (Softonic-Eng7 Community Toolbar) -- C:\Documents and Settings\Rivales\Dane aplikacji\Mozilla\Firefox\Profiles\zjthcvon.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
[2011-10-01 18:27:52 | 000,000,000 | ---D | M] (XfireXO Community Toolbar) -- C:\Documents and Settings\Rivales\Dane aplikacji\Mozilla\Firefox\Profiles\zjthcvon.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
[2010-09-03 19:47:08 | 000,000,000 | ---D | M] (Torbutton) -- C:\Documents and Settings\Rivales\Dane aplikacji\Mozilla\Firefox\Profiles\zjthcvon.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
[2011-04-22 19:34:15 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\Rivales\Dane aplikacji\Mozilla\Firefox\Profiles\zjthcvon.default\extensions\engine@conduit.com
[2011-09-19 18:01:14 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Documents and Settings\Rivales\Dane aplikacji\Mozilla\Firefox\Profiles\zjthcvon.default\extensions\toolbar@ask.com
[2011-10-29 22:17:45 | 000,002,561 | ---- | M] () -- C:\Documents and Settings\Rivales\Dane aplikacji\Mozilla\Firefox\Profiles\zjthcvon.default\searchplugins\askcom.xml
[2010-03-16 11:33:24 | 000,000,929 | ---- | M] () -- C:\Documents and Settings\Rivales\Dane aplikacji\Mozilla\Firefox\Profiles\zjthcvon.default\searchplugins\conduit.xml
[2011-05-21 18:01:37 | 000,002,048 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
[2010-03-30 22:04:29 | 002,131,336 | ---- | C] (Ask.com ) -- C:\Program Files\Common Files\AskToolbarInstaller.exe
[2011-10-29 22:15:47 | 000,000,268 | ---- | M] () -- C:\WINDOWS\tasks\RegistryBooster.job
[2011-10-29 22:15:47 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\SpeedUpMyPC.job
[2011-10-29 22:01:00 | 000,000,238 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011-05-21 21:32:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rivales\Dane aplikacji\facemoods.com
:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1039:TCP"=-
"5000:UDP"=-
:Commands
[resethosts]
[emptytemp]
[emptyflash]