:OTL
PRC - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe ()
PRC - C:\Program Files\AskBarDis\bar\bin\AskService.exe ()
SRV - (QueryExplorer Service) -- C:\Documents and Settings\All Users\Application Data\QueryExplorer\queryexplorer119.exe ()
SRV - (ASKUpgrade) -- C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe ()
SRV - (ASKService) -- C:\Program Files\AskBarDis\bar\bin\AskService.exe ()
IE - HKCU\..\URLSearchHook: {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {4daac69c-cba7-45e2-9bc8-1044483d3352} - C:\Program Files\Softonic_France\prxtbSof0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
FF - HKLM\software\mozilla\Firefox\Extensions\\offerboxffx@offerbox.com: C:\Program Files\OfferBox\offerboxffx@offerbox.com [2011/01/26 10:59:47 | 000,000,000 | ---D | M]
[2010/09/12 12:44:32 | 000,000,000 | -H-D | M] (Softonic_France Toolbar) -- C:\Documents and Settings\karine2\Application Data\Mozilla\Firefox\Profiles\7o07vmqb.default\extensions\{364d4e0c-543f-4b85-abe3-19551139da4f}
[2011/04/03 17:36:41 | 000,000,000 | ---D | M] (ResultBar) -- C:\Program Files\Mozilla Firefox\extensions\{34EFA911-B536-4C08-BECE-CD5E55C875B0}
[2008/09/28 15:46:32 | 000,024,683 | ---- | M] (Ask.com) -- C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngin0.dll (Conduit Ltd.)
O2 - BHO: (Jeux- Toolbar) - {3248f342-70c6-418d-a300-b8e925e95556} - C:\Program Files\Jeux-\prxtbJeu2.dll (Conduit Ltd.)
O2 - BHO: (Softonic_France Toolbar) - {4daac69c-cba7-45e2-9bc8-1044483d3352} - C:\Program Files\Softonic_France\prxtbSof0.dll (Conduit Ltd.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
O2 - BHO: (OfferBox) - {FC0D62C2-9640-4AEB-A5D5-CF25DF11FA8C} - C:\Program Files\OfferBox\OfferBoxBHO.dll (Secure Digital Services Limited)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngin0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Jeux- Toolbar) - {3248f342-70c6-418d-a300-b8e925e95556} - C:\Program Files\Jeux-\prxtbJeu2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Softonic_France Toolbar) - {4daac69c-cba7-45e2-9bc8-1044483d3352} - C:\Program Files\Softonic_France\prxtbSof0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngin0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Jeux- Toolbar) - {3248F342-70C6-418D-A300-B8E925E95556} - C:\Program Files\Jeux-\prxtbJeu2.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
O4 - HKCU\..\Run: [A9YA3MI1CF] File not found
O4 - HKCU\..\Run: [cacaoweb] C:\Program Files\cacaoweb\cacaoweb.exe ()
O15 - HKCU\..Trusted Domains: secuser.com ([www] http in Local intranet)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_15)
[2011/04/04 08:57:31 | 000,548,864 | ---- | C] () -- C:\WINDOWS\System32\null0.1989130606307572.exe
[2010/07/30 18:41:32 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\wsbl.dat
[2010/07/30 18:41:32 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\phar_unmip.dat
[2010/07/30 18:41:32 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\phar_histprot.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\ph_white.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\ph_summ.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\ph_black.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pcwords2.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pcwords.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_webproxy.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_video.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_tabloids.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_socialnetworks.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_searchengines.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_regionaltlds.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_pornography.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_onlineshop.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_onlinepay.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_onlinedating.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_news.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_im.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_illegal.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_hate.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_games.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_gambling.dat
[2010/07/30 18:41:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\pc_drugs.dat
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ResultBar"=-
:Commands