RAS
:OTL
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - File not found [On_Demand | Stopped] -- -- (ACDaemon)
IE - HKU\S-1-5-21-1645522239-1500820517-725345543-1004\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
FF - prefs.
js..browser.search.defau ltenginename: %µ£Yoog Search%µ£
FF - prefs.
js..browser.search.defau lturl: %µ£
http://www6.yoog.com/search.php?q=%µ£
FF - prefs.
js..browser.search.selec tedEngine: %µ£Yoog Search%µ£
FF - prefs.
js..keyword.URL: %µ£
http://www6.searchonthego.net/search.php?q=%µ£
FF - user.
js..browser.search.select edEngine: %µ£Yoog Search%µ£
FF - user.
js..keyword.URL: %µ£
http://www6.searchonthego.net/search.php?q=%µ£
FF - HKLM\Software\MozillaPlugins\y axmpb@yahoo.com/YahooActiveXPluginBridge;versi on=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.d ll File not found
O2 - BHO: (no name) - {64F56FC1-1272-44CD-BA6E-39723696E350} - No CLSID value found.
O2 - BHO: (no name) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - No CLSID value found.
O3 - HKU\S-1-5-21-1645522239-1500820517-725345543-1004\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [EoEngine] File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O33 - MountPoints2\{3115adc2-fcdc-11dc-97f8-0018f38111a7}\Shell - %µ£%µ£ = AutoRun
O33 - MountPoints2\{3115adc2-fcdc-11dc-97f8-0018f38111a7}\Shell\AutoRun\co mmand - %µ£%µ£ = F:\LaunchU3.exe
O33 - MountPoints2\{3115adc3-fcdc-11dc-97f8-0018f38111a7}\Shell - %µ£%µ£ = AutoRun
O33 - MountPoints2\{3115adc3-fcdc-11dc-97f8-0018f38111a7}\Shell\Auto\comma nd - %µ£%µ£ = auto.exe
O33 - MountPoints2\{3115adc3-fcdc-11dc-97f8-0018f38111a7}\Shell\AutoRun\co mmand - %µ£%µ£ = C:\WINDOWS\system32\RunDLL32.E XE Shell32.DLL,ShellExec_RunDLL auto.exe
O33 - MountPoints2\{3115adc3-fcdc-11dc-97f8-0018f38111a7}\Shell\explore\Co mmand - %µ£%µ£ = oufddh.exe
O33 - MountPoints2\{3115adc3-fcdc-11dc-97f8-0018f38111a7}\Shell\open\Comma nd - %µ£%µ£ = oufddh.exe
O33 - MountPoints2\{f46413b4-508a-11df-9e04-0018f38111a7}\Shell - %µ£%µ£ = AutoRun
O33 - MountPoints2\{f46413b4-508a-11df-9e04-0018f38111a7}\Shell\AutoRun\co mmand - %µ£%µ£ = %µ£F:\WD SmartWare.exe%µ£ autoplay=true
O33 - MountPoints2\{f4c9c3b6-f04e-11e0-a15b-0018f38111a7}\Shell - %µ£%µ£ = AutoRun
O33 - MountPoints2\{f4c9c3b6-f04e-11e0-a15b-0018f38111a7}\Shell\AutoRun\co mmand - %µ£%µ£ = F:\USBAutoRun.exe
[2011/11/18 13:29:22 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011/11/15 20:21:19 | 000,000,000 | ---D | C] -- C:\Qoobox
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2011/11/15 20:34:41 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/11/15 20:34:41 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/11/12 15:48:17 | 000,000,296 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~Rh4Kag9p4zfvNn
[2011/11/12 15:48:17 | 000,000,224 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~Rh4Kag9p4zfvNnr
[2011/11/12 15:42:04 | 000,000,456 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Rh4Kag9p4zfvNn
[2008/12/19 08:42:01 | 001,824,618 | ---- | C] () -- C:\Documents and Settings\chauvet\Local Settings\Application Data\cywmgkg_navfx.dat
[2008/12/19 08:40:18 | 000,310,159 | ---- | C] () -- C:\Documents and Settings\chauvet\Local Settings\Application Data\cywmgkg_nav.dat
[2008/12/19 08:40:18 | 000,005,150 | ---- | C] () -- C:\Documents and Settings\chauvet\Local Settings\Application Data\cywmgkg.dat
[2008/12/19 08:40:18 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\chauvet\Local Settings\Application Data\cywmgkg_navps.dat
[2008/12/04 12:40:45 | 000,047,686 | ---- | C] () -- C:\WINDOWS\System32\ouoromsmml ycfejvv.exe
[2008/10/01 18:27:06 | 000,280,584 | ---- | C] () -- C:\Documents and Settings\chauvet\Local Settings\Application Data\eyqaymc_nav.dat
[2008/10/01 18:27:06 | 000,009,376 | ---- | C] () -- C:\Documents and Settings\chauvet\Local Settings\Application Data\eyqaymc.dat
[2008/10/01 18:27:06 | 000,003,777 | ---- | C] () -- C:\Documents and Settings\chauvet\Local Settings\Application Data\eyqaymc_navps.dat
[2008/08/22 20:54:47 | 000,000,086 | ---- | C] () -- C:\WINDOWS\System32\netwbix32. dll
[2008/04/15 14:14:59 | 000,411,487 | ---- | C] () -- C:\Documents and Settings\chauvet\Local Settings\Application Data\ambwefmkxh_nav.dat
[2008/04/15 14:14:59 | 000,011,839 | ---- | C] () -- C:\Documents and Settings\chauvet\Local Settings\Application Data\ambwefmkxh.dat
[2008/04/15 14:14:59 | 000,001,868 | ---- | C] () -- C:\Documents and Settings\chauvet\Local Settings\Application Data\ambwefmkxh_navps.dat
[2006/03/29 07:43:38 | 000,042,496 | ---- | C] () -- C:\WINDOWS\System32\ALZZip.BIN
[2006/03/29 07:43:36 | 000,062,464 | ---- | C] () -- C:\WINDOWS\System32\ALZALZ.BIN
:Files
ipconfig /flushdns /c
C:\WINDOWS\tasks\*.job
attrib -H c:\*.* /s /d /c
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\*.sqm
:Commands
[emptytemp]
[CREATERESTOREPOINT]