[B]:OTL[/B]
[B]PRC - C:\Users\Public\Documents\AppData\PoApp\PService.exe (PService)[/B]
[B]PRC - C:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe ()[/B]
[B]MOD - C:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe ()[/B]
[B]MOD - C:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.dll ()[/B]
[B]SRV - (SoftwareUpd) -- C:\Users\Marco\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe (SoftwareUpdService)[/B]
[B]SRV - (PowerOffer Service) -- C:\Users\Marco\AppData\Local\PosService\Pos.exe (PowerOfferService)[/B]
[B]SRV - (ServUpdater) -- C:\Users\Marco\AppData\Local\ServUpdater\ServiceUpd.exe (ServiceUpd)[/B]
[B]SRV - (Browser Manager) -- C:\ProgramData\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\mngr.exe ()[/B]
[B]IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com[/B]
[B]IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com[/B]
[B]IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com[/B]
[B]IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com[/B]
[B]IE - HKU\S-1-5-21-1964985950-1455284158-73322723-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.claro-search.com/?affID=114506&tt=4912_7&babsrc=HP_clro&mntrId=d4388d6c0000000000005cac4c019731[/B]
[B]IE - HKU\S-1-5-21-1964985950-1455284158-73322723-1001\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.claro-search.com/?affID=114506&tt=4912_7&babsrc=HP_clro&mntrId=d4388d6c0000000000005cac4c019731[/B]
[B]IE - HKU\S-1-5-21-1964985950-1455284158-73322723-1001\..\SearchScopes\{00CE0DEF-8F01-44A0-91CB-F797E366E70D}: "URL" = http://www.google.it/search?hl=it&q={searchTerms}&meta=[/B]
[B]IE - HKU\S-1-5-21-1964985950-1455284158-73322723-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.claro-search.com/?q={searchTerms}&affID=114506&tt=4912_7&babsrc=SP_clro&mntrId=d4388d6c0000000000005cac4c019731[/B]
[B]IE - HKU\S-1-5-21-1964985950-1455284158-73322723-1001\..\SearchScopes\{3D2BF1FA-6F17-407A-B1FB-AD7FE0211F30}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox[/B]
[B]IE - HKU\S-1-5-21-1964985950-1455284158-73322723-1001\..\SearchScopes\{E169F2B1-1EE1-4E0A-9B73-3BB9F3F10BF4}: "URL" = http://it.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF[/B]
[B]IE - HKU\S-1-5-21-1964985950-1455284158-73322723-1001\..\SearchScopes\{F70FFB3C-701E-43FE-95B2-AD50B2AED90C}: "URL" = http://it.wikipedia.org/wiki/Special:Search?search={searchTerms}[/B]
[B]FF - prefs.js..browser.search.defaultenginename: "Claro Search"[/B]
[B]FF - prefs.js..browser.search.order.1: "Claro Search"[/B]
[B]FF - prefs.js..browser.search.selectedEngine: "Claro Search"[/B]
[B]FF - prefs.js..browser.startup.homepage: "http://www.claro-search.com/?affID=114506&tt=4912_7&babsrc=HP_clro&mntrId=d4388d6c0000000000005cac4c019731"[/B]
[B]FF - prefs.js..extensions.enabledAddons: youtubemp3podcaster@jeremy.d.gregorio.com:2.7.1[/B]
[B]FF - prefs.js..extensions.enabledAddons: {58bd07eb-0ee0-4df0-8121-dc9b693373df}:2.5.911.18[/B]
[B]FF - prefs.js..extensions.enabledAddons: {cb84136f-9c44-433a-9048-c5cd9df1dc16}:4.0.0.1884[/B]
[B]FF - prefs.js..keyword.URL: "http://www.claro-search.com/?affID=114506&tt=4812_1&babsrc=KW_clro&mntrId=d4388d6c0000000000005cac4c019731&q="[/B]
[B]O4 - HKLM..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe (PLauncher)[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1DB18850-5DB9-4488-A62A-D5FCAC4332E6}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{535F1E75-4E6B-448A-9B83-820DA6956661}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{94DCEBA7-7DAC-413B-8F9A-54357D0E1C84}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B]O33 - MountPoints2\{189dd7f5-5fa7-11e1-94e3-b281baaf3ade}\Shell - "" = AutoRun[/B]
[B]O33 - MountPoints2\{189dd7f5-5fa7-11e1-94e3-b281baaf3ade}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL H:\index.html[/B]
[B]O33 - MountPoints2\{6a5db903-78eb-11e1-a174-5cac4c019731}\Shell - "" = AutoRun[/B]
[B]O33 - MountPoints2\{6a5db903-78eb-11e1-a174-5cac4c019731}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a[/B]
[B]O33 - MountPoints2\{dc302d80-8f91-11e1-ab72-ea99b2afabde}\Shell - "" = AutoRun[/B]
[B]O33 - MountPoints2\{dc302d80-8f91-11e1-ab72-ea99b2afabde}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a[/B]
[B]O33 - MountPoints2\F\Shell - "" = AutoRun[/B]
[B]O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a[/B]
[B][2012/12/03 11:49:30 | 000,000,000 | ---D | C] -- C:\Users\Marco\AppData\Roaming\TestApp[/B]
[B][2012/12/03 11:05:14 | 000,000,000 | ---D | C] -- C:\Users\Marco\AppData\Local\PowerOffer[/B]
[B][2012/12/03 11:05:13 | 000,000,000 | ---D | C] -- C:\Users\Marco\AppData\Local\ServUpdater[/B]
[B][2012/12/03 11:05:13 | 000,000,000 | ---D | C] -- C:\Users\Marco\AppData\Local\PosService[/B]
[B][2012/11/28 13:18:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Browser Manager[/B]
[B][2012/11/28 13:17:12 | 000,000,000 | ---D | C] -- C:\ProgramData\IBUpdaterService[/B]
[B][2012/11/28 13:16:36 | 000,000,000 | ---D | C] -- C:\Users\Marco\AppData\Local\SoftwareUpdater[/B]
[B][2012/10/23 16:30:44 | 000,003,488 | ---- | M] () -- C:\Windows\UDB.zip[/B]
[B][2012/10/23 16:30:44 | 000,000,882 | ---- | M] () -- C:\Windows\RegSDImport.xml[/B]
[B][2012/10/23 16:30:44 | 000,000,879 | ---- | M] () -- C:\Windows\RegISSImport.xml[/B]
[B][2012/10/23 16:30:44 | 000,000,131 | ---- | M] () -- C:\Windows\IDB.zip[/B]
[B][2012/12/03 11:05:13 | 000,715,038 | ---- | C] () -- C:\Users\Marco\AppData\Local\unins000.exe[/B]
[B][2012/12/03 11:05:12 | 000,004,067 | ---- | C] () -- C:\Users\Marco\AppData\Local\unins000.dat[/B]
[B][2011/11/29 12:02:57 | 000,000,000 | ---D | M] -- C:\Users\Marco\AppData\Roaming\Babylon[/B]
[B]@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:DFC5A2B2[/B]
[B]@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84[/B]
[B]:Files[/B]
[B]ipconfig /flushdns /c[/B]
[B]netsh int ip reset c:\resetlog.txt /c[/B]
[B]:reg[/B]
[B][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command][/B]
[B]""=""%1" %*" [/B]
[B]:commands[/B]
[B][purity][/B]
[B][emptytemp][/B]
[B][RESETHOSTS][/B]
[B][EMPTYFLASH][/B]
[B][start explorer][/B]
[B][CLEARALLRESTOREPOINTS][/B]
[B][Reboot][/B]