[FONT=arial][B]:Services
:OTL
[/B][B]SRV - (SoftwareUpd) -- C:\Users\Valeria\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe (SoftwareUpdService)[/B]
[B]SRV - (ServUpdater) -- C:\Users\Valeria\AppData\Local\ServUpdater\ServiceUpd.exe (ServiceUpd)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com[/B]
[B]IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}[/B]
[B]IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW[/B]
[B]IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=137b9494-3f7a-11e1-92a4-001d72fe166d&q={searchTerms}
[/B][B]IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com[/B]
[B]IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com[/B]
[B]IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com[/B]
[B]IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
[/B][B]O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.[/B]
[B]O2 - BHO: (no name) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - No CLSID value found.[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3a539854-6a70-11db-887c-806e6f6e6963}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{745946BB-8EF5-4514-855D-2FCD121E2117}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B][2012/10/19 11.26.28 | 000,000,000 | ---D | C] -- C:\Users\Valeria\AppData\Local\SoftwareUpdater
[/B][B]@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:52B53B17[/B]
[B]@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:CE0A077E[/B]
[B]@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:814B9485[/B]
[B]@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:9E22BBE8[/B]
[B]@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:41099CE9[/B]
[B]@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:35759C73[/B]
[B]@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:CDFF58FE[/B]
[B]@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:ADE16379[/B]
[B]@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:4F636E25[/B]
[B]@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:3064D21D[/B]
[B]@Alternate Data Stream - 120 bytes -> C:\ProgramData\Temp:B623B5B8[/B]
[B]@Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:BB24555F[/B]
[B]@Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:6C5EC3CD[/B]
[B]@Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:D1B5B4F1[/B]
[B]@Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:ABE89FFE[/B]
[B]@Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:3B3A35EC[/B]
[B]@Alternate Data Stream - 106 bytes -> C:\ProgramData\Temp:E1982A23[/B]
[B]@Alternate Data Stream - 103 bytes -> C:\ProgramData\Temp:DCAF903C[/B]
[B]
:Files
ipconfig /flushdns /c[/B]
[B]:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"
:commands
[purity]
[emptytemp]
[RESETHOSTS]
[start explorer]
[CLEARALLRESTOREPOINTS]
[Reboot][/B][/FONT]