Code:
:Services
:OTL
SRV - (qserver) -- C:\Windows\System32\se44mdfl.dll (Oak Technology Inc.)
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=111...0000219743274e
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?FORM=SOLTDF&PC=SUN1&q={searchTerms}&src=IE-SearchBox
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\2.bin\NPMyWebS.dll File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\m3ffxtbr@mywebsearch.com: C:\Program Files\MyWebSearch\bar\2.bin
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/webgames/popcaploader_v10.cab (PopCapLoader Object)
O33 - MountPoints2\{165822f3-c3f4-11df-a467-00219743274e}\Shell - "" = AutoRun
O33 - MountPoints2\{165822f3-c3f4-11df-a467-00219743274e}\Shell\AutoRun\command - "" = D:\SuperLink.exe
O33 - MountPoints2\{16582345-c3f4-11df-a467-00219743274e}\Shell - "" = AutoRun
O33 - MountPoints2\{16582345-c3f4-11df-a467-00219743274e}\Shell\AutoRun\command - "" = D:\SuperLink.exe
O33 - MountPoints2\{96b200c9-8873-11de-ab76-00219743274e}\Shell\AutoRun\command - "" = D:\Installer.exe
O33 - MountPoints2\{96b20386-8873-11de-ab76-00219743274e}\Shell\AutoRun\command - "" = D:\Installer.exe
NetSvcs: qserver - C:\Windows\System32\se44mdfl.dll (Oak Technology Inc.)
[2012/04/09 11:17:56 | 000,000,000 | ---D | C] -- C:\Program Files\BabylonToolbar
[2012/04/09 11:17:27 | 000,000,000 | ---D | C] -- C:\Users\Belle\AppData\Local\Babylon
[2012/04/09 11:17:24 | 000,000,000 | ---D | C] -- C:\Users\Belle\AppData\Roaming\Babylon
[2012/04/09 11:17:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2012/04/10 12:04:19 | 000,054,272 | ---- | M] () -- C:\Users\Belle\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/09 21:20:20 | 000,000,000 | -HS- | M] () -- C:\Windows\System32\dds_trash_log.cmd
:Files
C:\Windows\System32\se44mdfl.dll
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]