:OTL
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3015261
[2013/04/10 18:21:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Luigi\AppData\Roaming\Mozilla\Firefox\Profiles\ykry9tvv.default\extensions\anttoolbar@ant.com
[2013/05/08 19:58:40 | 000,534,214 | ---- | M] () (No name found) -- C:\Users\Luigi\AppData\Roaming\Mozilla\Firefox\Profiles\12vq7hij.default-1365583746560\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
O3 - HKLM\..\Toolbar: (no name) - {3ce45c4f-bfff-4988-9a3c-a75c1f491319} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
[2013/04/17 00:58:53 | 000,000,000 | ---D | C] -- C:\Users\Luigi\AppData\Roaming\Kariiw
[2013/04/17 00:58:53 | 000,000,000 | ---D | C] -- C:\Users\Luigi\AppData\Roaming\Asiv
[2013/04/14 18:56:22 | 000,000,000 | ---D | C] -- C:\Users\Luigi\AppData\Roaming\Hizy
[2013/05/08 21:03:22 | 000,016,384 | ---- | M] () -- C:\Users\Luigi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/05/08 18:19:32 | 000,722,318 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2013/05/08 18:19:32 | 000,146,218 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2013/05/08 20:49:36 | 000,016,384 | ---- | C] () -- C:\Users\Luigi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/21 21:11:01 | 000,009,610 | -HS- | C] () -- C:\Users\Luigi\AppData\Local\tbfiuj2vtf1c6k5p5fm0tk3a5hlb1vq80f648vyqr7qcvu
[2011/12/21 21:11:01 | 000,009,610 | -HS- | C] () -- C:\ProgramData\tbfiuj2vtf1c6k5p5fm0tk3a5hlb1vq80f648vyqr7qcvu
[2011/09/28 16:44:14 | 000,179,271 | ---- | C] () -- C:\windows\System32\xlive.dll.cat
[2011/07/05 22:32:11 | 000,000,016 | ---- | C] () -- C:\windows\System32\asdict.dat
[2013/05/06 22:56:52 | 000,002,048 | -HS- | M] () -- C:\$RECYCLE.BIN\S-1-5-18\$8bb065065cc2cc421dff94194c86a39a\@
[2013/04/30 21:09:32 | 000,000,000 | -HSD | M] -- C:\$RECYCLE.BIN\S-1-5-18\$8bb065065cc2cc421dff94194c86a39a\L
[2013/05/07 23:16:29 | 000,000,000 | -HSD | M] -- C:\$RECYCLE.BIN\S-1-5-18\$8bb065065cc2cc421dff94194c86a39a\U
[2009/07/14 14:12:31 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
[2011/08/11 09:47:51 | 000,000,000 | ---- | M] ()(C:\windows\System32\?????) -- C:\windows\System32\獷楬汢捯污
[2011/08/11 09:47:51 | 000,000,000 | ---- | C] ()(C:\windows\System32\?????) -- C:\windows\System32\獷楬汢捯污
:commands
[emptytemp]
[reboot]