[B]:OTL
PRC - C:\ComboFix\CF3964.3XE ()
PRC - C:\Users\Public\Documents\AppData\PoApp\PService.exe (PService)
PRC - C:\Programmi\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe ()
[/B][B]MOD - C:\Users\bac\AppData\Local\Temp\catchme.dll ()[/B]
[B]MOD - C:\ComboFix\CF3964.3XE ()
[/B][B]MOD - C:\Programmi\AVG Secure Search\vprot.exe ()[/B]
[B]MOD - C:\Programmi\Common Files\AVG Secure Search\DNTInstaller\13.2.0\avgdttbx.dll ()[/B]
[B]MOD - C:\Programmi\Common Files\AVG Secure Search\SiteSafetyInstaller\13.2.0\SiteSafety.dll ()
[/B][B]SRV - (SoftwareUpd) -- C:\Users\bac\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe (SoftwareUpdService)[/B]
[B]SRV - (PowerOffer Service) -- C:\Users\bac\AppData\Local\PosService\Pos.exe (PowerOfferService)[/B]
[B]SRV - (ServUpdater) -- C:\Users\bac\AppData\Local\ServUpdater\ServiceUpd.exe (ServiceUpd)
SRV - (vToolbarUpdater13.2.0) -- C:\Programmi\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe ()
O4 - HKLM..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe (PLauncher)
[/B][B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0684B3F3-6F42-4051-B9A5-63F709031D94}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{08AE7275-A1D2-4B5F-BA99-0D1018E83CED}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{371125F9-3CEE-4082-BFB9-5AB012390200}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{447DA4E9-A778-4076-9A8E-2612FF9406CF}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A01F6C8C-F7D4-49FB-B458-AFFF52CB6B43}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A3BB1B5E-4E77-4A5E-B4F6-699EAA9B9203}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B36AFCA7-3A57-469F-9656-3563DBCE4D40}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CA970207-130C-4DA2-9FEF-A44B3717C0F4}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{e29ac6c2-7037-11de-816d-806e6f6e6963}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B]O33 - MountPoints2\{229835e1-daf8-11e0-8b30-1c7508e58933}\Shell - "" = AutoRun[/B]
[B]O33 - MountPoints2\{229835e1-daf8-11e0-8b30-1c7508e58933}\Shell\AutoRun\command - "" = D:\AutoRun.exe[/B]
[B]O33 - MountPoints2\{448f362f-d7ed-11e0-91d6-1c7508e58933}\Shell - "" = AutoRun[/B]
[B]O33 - MountPoints2\{448f362f-d7ed-11e0-91d6-1c7508e58933}\Shell\AutoRun\command - "" = D:\AutoRun.exe[/B]
[B]O33 - MountPoints2\{50d9d199-fe5e-11e0-934f-68a3c40b6ce4}\Shell - "" = AutoRun[/B]
[B]O33 - MountPoints2\{50d9d199-fe5e-11e0-934f-68a3c40b6ce4}\Shell\AutoRun\command - "" = D:\setup_vmb_lite.exe /checkApplicationPresence[/B]
[B]O33 - MountPoints2\{50d9d1de-fe5e-11e0-934f-1c7508e58933}\Shell - "" = AutoRun[/B]
[B]O33 - MountPoints2\{50d9d1de-fe5e-11e0-934f-1c7508e58933}\Shell\AutoRun\command - "" = D:\setup_vmb_lite.exe /checkApplicationPresence[/B]
[B]O33 - MountPoints2\{672684b3-291d-11e2-9d60-72a3c40b6ce4}\Shell - "" = AutoRun[/B]
[B]O33 - MountPoints2\{672684b3-291d-11e2-9d60-72a3c40b6ce4}\Shell\AutoRun\command - "" = D:\LaunchU3.exe -a[/B]
[B]O33 - MountPoints2\{7cef5395-d586-11e0-8c6b-1c7508e58933}\Shell - "" = AutoRun[/B]
[B]O33 - MountPoints2\{7cef5395-d586-11e0-8c6b-1c7508e58933}\Shell\AutoRun\command - "" = D:\AutoRun.exe[/B]
[B]O33 - MountPoints2\{95580ffa-02fc-11e1-91eb-1c7508e58933}\Shell - "" = AutoRun[/B]
[B]O33 - MountPoints2\{95580ffa-02fc-11e1-91eb-1c7508e58933}\Shell\AutoRun\command - "" = D:\AutoRun.exe[/B]
[B]O33 - MountPoints2\{ddd019be-0f07-11e1-baff-1c7508e58933}\Shell - "" = AutoRun[/B]
[B]O33 - MountPoints2\{ddd019be-0f07-11e1-baff-1c7508e58933}\Shell\AutoRun\command - "" = D:\AutoRun.exe[/B]
[B]O33 - MountPoints2\{e52c9189-f95e-11e0-ab87-68a3c40b6ce4}\Shell - "" = AutoRun[/B]
[B]O33 - MountPoints2\{e52c9189-f95e-11e0-ab87-68a3c40b6ce4}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a[/B]
[B]O33 - MountPoints2\{fd8cf768-d607-11e0-909f-806e6f6e6963}\Shell - "" = AutoRun[/B]
[B]O33 - MountPoints2\{fd8cf768-d607-11e0-909f-806e6f6e6963}\Shell\AutoRun\command - "" = D:\AutoRun.exe[/B]
[B]O33 - MountPoints2\D\Shell - "" = AutoRun[/B]
[B]O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\LaunchU3.exe -a
:Files
C:\Users\bac\AppData\Local\PosService
C:\Users\bac\AppData\Local\PowerOffer
C:\Users\bac\AppData\Local\ServUpdater
C:\Users\Public\Documents\AppData\PoApp
C:\Users\bac\AppData\Local\Lollipop
C:\Users\bac\AppData\Roaming\EmoticoonsToolbar
C:\Users\bac\AppData\Local\SoftwareUpdater
C:\Users\bac\AppData\Local\unins000.exe
C:\Users\bac\AppData\Local\unins000.dat
[/B][B]ipconfig /flushdns /c[/B]
[B]netsh int ip reset c:\resetlog.txt /c[/B]
[B]:reg[/B]
[B][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command][/B]
[B]""=""%1" %*" [/B]
[B]:commands[/B]
[B][purity][/B]
[B][emptytemp][/B]
[B][RESETHOSTS][/B]
[B][EMPTYFLASH][/B]
[B][CLEARALLRESTOREPOINTS][/B]
[B][Reboot][/B]