Code:
:OTL
IE - HKLM\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\prxtbFre2.dll (Conduit Ltd.)
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
[2008/08/03 18:48:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ngan\AppData\Roaming\mozilla\Extensions
[2012/01/11 13:57:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ngan\AppData\Roaming\mozilla\Firefox\Profiles\pzctg0ec.default\ext ensions
[2012/01/11 13:57:09 | 000,000,000 | ---D | M] (Freecorder Community Toolbar) -- C:\Users\ngan\AppData\Roaming\mozilla\Firefox\Profiles\pzctg0ec.default\ext ensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2011/09/28 13:39:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ngan\AppData\Roaming\mozilla\Firefox\Profiles\pzctg0ec.default\ext ensions\{1392B8D2-5C05-419F-A8F6-B9F15A596612}-TRASH
[2011/11/11 19:28:27 | 000,000,000 | ---D | M] (BFlix Toolbar) -- C:\Users\ngan\AppData\Roaming\mozilla\Firefox\Profiles\pzctg0ec.default\ext ensions\{a6bf16ab-42a1-4bc5-965d-5e407e449aaa}
[2011/11/11 19:28:58 | 000,001,945 | ---- | M] () -- C:\Users\ngan\AppData\Roaming\Mozilla\Firefox\Profiles\pzctg0ec.default\sea rchplugins\bing-zugo.xml
[2012/01/08 23:49:56 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/04 19:21:03 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml.old
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\prxtbFre2.dll (Conduit Ltd.)
O2 - BHO: (BFlix Toolbar) - {a6bf16ab-42a1-4bc5-965d-5e407e449aaa} - C:\Program Files\bflixtoolbar\vmntemplateX.dll ()
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\prxtbFre2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (BFlix Toolbar) - {a6bf16ab-42a1-4bc5-965d-5e407e449aaa} - C:\Program Files\bflixtoolbar\vmntemplateX.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Freecorder Toolbar) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - C:\Program Files\Freecorder\prxtbFre2.dll (Conduit Ltd.)
[2012/01/21 14:18:30 | 000,000,272 | ---- | M] () -- C:\ProgramData\~Bp26Blb39DVrGH
[2012/01/21 14:18:30 | 000,000,168 | ---- | M] () -- C:\ProgramData\~Bp26Blb39DVrGHr
[2012/01/21 00:35:11 | 000,000,440 | ---- | M] () -- C:\ProgramData\Bp26Blb39DVrGH
[2012/01/11 21:57:53 | 000,000,894 | -HS- | M] () -- C:\Users\ngan\AppData\Local\075x22s613657qe7ud702ut
[2012/01/11 21:57:53 | 000,000,894 | -HS- | M] () -- C:\ProgramData\075x22s613657qe7ud702ut
[2012/01/11 21:57:53 | 000,000,894 | -HS- | C] () -- C:\Users\ngan\AppData\Local\075x22s613657qe7ud702ut
[2012/01/11 21:57:53 | 000,000,894 | -HS- | C] () -- C:\ProgramData\075x22s613657qe7ud702ut
[2011/06/13 21:33:12 | 000,000,120 | ---- | C] () -- C:\Users\ngan\AppData\Local\Aqovaripec.dat
[2011/06/13 21:33:12 | 000,000,000 | ---- | C] () -- C:\Users\ngan\AppData\Local\Fbilesicog.bin
2011/05/11 21:53:41 | 000,011,004 | -HS- | C] () -- C:\Users\ngan\AppData\Local\230t17d8r0p00q1761g3mnq4h8r4n7k5w62
[2011/05/11 21:53:41 | 000,011,004 | -HS- | C] () -- C:\ProgramData\230t17d8r0p00q1761g3mnq4h8r4n7k5w62
[2011/05/08 18:10:09 | 000,011,784 | -HS- | C] () -- C:\Users\ngan\AppData\Local\m32esmfe7c4o462rx2yg3t247
[2011/05/08 18:10:09 | 000,011,784 | -HS- | C] () -- C:\ProgramData\m32esmfe7c4o462rx2yg3t247
[2008/02/18 17:31:59 | 000,157,040 | ---- | C] () -- C:\Windows\fdbpinger.exe
[C:\Windows\$NtUninstallKB56859$] -> -> Unknown point type
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMPFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8
helpfile [open] -- Reg Error: Key error.
regfile [merge] -- Reg Error: Key error.
txtfile [edit] -- Reg Error: Key error.
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" =-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" =-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" =-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" =-
"VistaSp2" =-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"bflixtoolbar" =-
"{63A6E9A9-A190-46D4-9430-2DB28654AFD8}" =-
"bflixtoolbar" =-
"Freecorder Toolbar" = Freecorder Toolbar
"Freecorder4.1" =-
:Files
:Commands
[purity]
[emptyjava]
[resethosts]
[CreateRestorePoint]
[Reboot]