Code:
:OTL
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TempFC5A2B2
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2384137&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.startup.homepage: "http://search.entru.com/?s=1109"
[2011/07/21 19:57:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2011/07/21 19:57:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/02/02 15:54:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\i4y12bxe.default\ex tensions
[2011/07/21 20:01:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\i4y12bxe.default\ex tensions\temp
[2011/03/07 21:34:23 | 000,001,871 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\i4y12bxe.default\se archplugins\ask.uk.xml
[2012/02/02 17:37:40 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
() (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I4Y12BXE.DEFAULT\EX TENSIONS\{04514A2C-A3AB-4F47-8688-55F911B0FE75}.XPI
() (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I4Y12BXE.DEFAULT\EX TENSIONS\{1280606B-2510-4FE0-97EF-9B5A22EAFE30}.XPI
() (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I4Y12BXE.DEFAULT\EX TENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
() (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I4Y12BXE.DEFAULT\EX TENSIONS\{20A82645-C095-46ED-80E3-08825760534B}.XPI
() (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I4Y12BXE.DEFAULT\EX TENSIONS\{39952C40-5197-11DA-8CD6-0800200C9A66}.XPI
() (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I4Y12BXE.DEFAULT\EX TENSIONS\{5E594888-3E8E-47DA-B2C6-B0B545112F84}.XPI
() (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I4Y12BXE.DEFAULT\EX TENSIONS\{6E84150A-D526-41F1-A480-A67D3FED910D}.XPI
() (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I4Y12BXE.DEFAULT\EX TENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I4Y12BXE.DEFAULT\EX TENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I4Y12BXE.DEFAULT\EX TENSIONS\{D618933B-9EB4-1C04-949D-0F9B1A39EBB9}.XPI
() (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I4Y12BXE.DEFAULT\EX TENSIONS\{DC572301-7619-498C-A57D-39143191B318}.XPI
() (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I4Y12BXE.DEFAULT\EX TENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I4Y12BXE.DEFAULT\EX TENSIONS\PERSONAS@CHRISTOPHER.BEARD.XPI
() (No name found) -- C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I4Y12BXE.DEFAULT\EX TENSIONS\SKIPSCREEN@SKIPSCREEN.XPI
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
[2012/02/02 18:39:36 | 000,000,000 | ---D | C] -- C:\ProgramData\RegAce
[2012/02/02 18:39:17 | 000,000,000 | ---D | C] -- C:\Windows\RegAce
[2012/02/02 17:22:28 | 000,799,880 | ---- | C] (Crawler.com ) -- C:\Users\Owner\Desktop\SpywareTerminatorSetup.exe
[2012/02/02 16:26:42 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2012/02/02 16:21:38 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/02/07 17:28:24 | 000,013,472 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/07 17:28:24 | 000,013,472 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/07 17:25:21 | 000,798,720 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/02/07 17:25:21 | 000,675,098 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/02/07 17:25:21 | 000,126,088 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
:Files
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[emptyflash]
[emptyjava]
[resethosts]
[CreateRestorePoint]
[Reboot]