[B]:OTL
PRC - C:\Users\Public\Documents\AppData\PoApp\PService.exe (PService)
SRV - (SoftwareUpd) -- C:\Users\Laura\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe (SoftwareUpdService)
SRV - (PowerOffer Service) -- C:\Users\Laura\AppData\Local\PosService\Pos.exe (PowerOfferService)
SRV - (ServUpdater) -- C:\Users\Laura\AppData\Local\ServUpdater\ServiceUpd.exe (ServiceUpd)
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://search.chatzum.com/?q={searchTerms}
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [URL="http://search.findeer.com"]Search[/URL]
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [URL="http://search.findeer.com"]Search[/URL]
IE - HKU\S-1-5-21-157529117-3945794094-1926780886-1001\..\SearchScopes\{0474A27F-CAF8-487F-A71C-9FDDD9EE576E}: "URL" = http://rover.ebay.com/rover/1/724-42445-16445-8/4?satitle={searchTerms}
IE - HKU\S-1-5-21-157529117-3945794094-1926780886-1001\..\SearchScopes\{66BD6455-F79D-4591-BAB7-4B594746EC9F}: "URL" = http://www.zinio.com/search/index.jsp?s={searchTerms}&rf=sonyie8search
IE - HKU\S-1-5-21-157529117-3945794094-1926780886-1001\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://search.chatzum.com/?q={searchTerms}
IE - HKU\S-1-5-21-157529117-3945794094-1926780886-1001\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://search.chatzum.com/?q={SearchTerms}
IE - HKU\S-1-5-21-157529117-3945794094-1926780886-1001\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-157529117-3945794094-1926780886-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [URL="http://search.fbdownloader.com/?channel=sfit202fbdgy11"]fbDownloader Search[/URL]
O4 - HKLM..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe (PLauncher)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{16BD4E42-8E31-4BD3-BF4E-4113F40CEB2F}: NameServer = 176.31.229.24,176.31.229.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2472CA45-E689-4833-9476-2BF208E87CD7}: NameServer = 176.31.229.24,176.31.229.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}: NameServer = 176.31.229.24,176.31.229.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{927587AB-1894-493E-8E72-6063314BF69A}: NameServer = 176.31.229.24,176.31.229.25
[2012/11/11 14:45:30 | 000,000,000 | ---D | C] -- C:\VCS35_TMP
[2012/10/23 13:29:59 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/10/23 13:29:32 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/10/23 13:28:39 | 005,009,347 | R--- | C] (Swearware) -- C:\Users\Laura\Desktop\ComboFix.exe
[2012/07/13 19:25:15 | 000,004,069 | ---- | C] () -- C:\Users\Laura\AppData\Local\unins000.dat
[2012/05/06 17:18:08 | 000,008,704 | ---- | C] () -- C:\Users\Laura\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/23 20:58:28 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2011/11/25 14:34:35 | 000,002,119 | ---- | C] () -- C:\Windows\SysWow64\McOEMAppRules.dat
@[URL="http://www.tomshw.it/forum/member.php?u=102884"]alt[/URL]ernate Data Stream - 146 bytes -> C:\ProgramData\Temp:E8BE05FA
@[URL="http://www.tomshw.it/forum/member.php?u=102884"]alt[/URL]ernate Data Stream - 136 bytes -> C:\ProgramData\Temp:42DC4246
:Files
ipconfig /flushdns /c
netsh int ip reset c:\resetlog.txt /c
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"
:commands
[purity]
[emptytemp]
[RESETHOSTS]
[EMPTYFLASH]
[start explorer]
[CLEARALLRESTOREPOINTS]
[Reboot][/B]