[B]:OTL[/B]
[B]PRC - C:\Users\Public\Documents\AppData\PoApp\PService.exe (PService)[/B]
[B]PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe ()[/B]
[B]SRV - (vToolbarUpdater13.2.0) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe ()[/B]
[B]SRV - (SoftwareUpd) -- C:\Users\Hurto\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe (SoftwareUpdService)[/B]
[B]SRV - (ServUpdater) -- C:\Users\Hurto\AppData\Local\ServUpdater\ServiceUpd.exe (ServiceUpd)[/B]
[B]IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [URL="http://search.findeer.com"]Search[/URL][/B]
[B]IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [URL="http://search.findeer.com"]Search[/URL][/B]
[B]IE - HKU\S-1-5-21-3869779913-2830439072-1351645438-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [URL]https://mail.hpcds.com/[/URL][/B]
[B]O4 - HKLM..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe (PLauncher)[/B]
[B]O4 - HKLM..\Run: [ROC_ROC_JULY_P1] "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_JULY_P1.exe" / /PROMPT /CMPID=ROC_JULY_P1 File not found[/B]
[B]O4 - HKLM..\Run: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 File not found[/B]
[B]O4 - HKLM..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" File not found[/B]
[B][2012/12/01 10:36:26 | 000,208,216 | ---- | C] (Kaspersky Lab, GERT) -- C:\Windows\SysNative\drivers\63271553.sys[/B]
[B][2012/11/25 09:48:02 | 000,000,000 | ---D | C] -- C:\Users\Hurto\AppData\Local\PowerOffer[/B]
[B][2012/11/25 09:48:01 | 000,000,000 | ---D | C] -- C:\Users\Hurto\AppData\Local\ServUpdater[/B]
[B][2012/11/25 09:48:01 | 000,000,000 | ---D | C] -- C:\Users\Hurto\AppData\Local\PosService[/B]
[B][2012/11/24 09:09:02 | 000,000,000 | ---D | C] -- C:\Users\Hurto\AppData\Local\SoftwareUpdater[/B]
[B][2012/10/29 12:09:28 | 000,200,704 | ---- | M] ( (c) MusicCity) -- C:\Windows\SysWow64\muzwmts.dll[/B]
[B][2012/10/29 12:09:28 | 000,172,032 | ---- | M] (Musiccity Co.Ltd.) -- C:\Windows\SysWow64\muzapp.exe[/B]
[B][2012/10/29 12:09:28 | 000,030,568 | ---- | M] () -- C:\Windows\MusiccityDownload.exe[/B]
[B][2012/10/29 12:09:26 | 000,024,576 | ---- | M] ((주)마크애니) -- C:\Windows\SysWow64\MASetupCleaner.exe[/B]
[B][2012/11/28 19:22:13 | 000,485,282 | RHS- | C] () -- C:\JSLUE[/B]
[B][2012/11/25 09:48:00 | 000,004,067 | ---- | C] () -- C:\Users\Hurto\AppData\Local\unins000.dat[/B]
[B][2012/11/30 19:04:02 | 000,000,266 | ---- | C] () -- C:\Windows\tasks\AutoKMS.job[/B]
[B]@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:CB0AACC9[/B]
[B]:Files[/B]
[B]ipconfig /flushdns /c[/B]
[B]netsh int ip reset c:\resetlog.txt /c[/B]
[B]:reg[/B]
[B][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command][/B]
[B]""=""%1" %*" [/B]
[B]:commands[/B]
[B][purity][/B]
[B][emptytemp][/B]
[B][RESETHOSTS][/B]
[B][EMPTYFLASH][/B]
[B][start explorer][/B]
[B][CLEARALLRESTOREPOINTS][/B]
[B][Reboot][/B]