Code:
:OTL
@Alternate Data Stream - 222 bytes -> C:\ProgramData\Temp:3440EB47
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TempFC5A2B2
[2011/03/07 21:34:23 | 000,001,871 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\i4y12bxe.default\se archplugins\ask.uk.xml
[2009/10/21 19:01:26 | 000,000,866 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\i4y12bxe.default\se archplugins\conduit.xml
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2384137&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.startup.homepage: "http://search.entru.com/?s=1109"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.5
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
[2012/02/02 16:26:42 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2012/02/02 16:21:38 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/02/02 11:28:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 5
[2012/02/02 16:27:19 | 000,025,160 | ---- | M] () -- C:\Windows\SysNative\drivers\hitmanpro36.sys
[2011/07/21 20:01:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\i4y12bxe.default\ex tensions\temp
[2011/03/07 21:34:23 | 000,001,871 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\i4y12bxe.default\se archplugins\ask.uk.xml
[2012/02/10 19:51:00 | 000,001,218 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\i4y12bxe.default\se archplugins\comcast.xml
[2009/10/21 19:01:26 | 000,000,866 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\i4y12bxe.default\se archplugins\conduit.xml
[2012/02/02 14:42:36 | 000,149,456 | ---- | C] (PC Tools) -- C:\Windows\SGDetectionTool.dll0208.old
[2012/02/02 14:42:34 | 002,246,608 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll0208.old
:Commands
[purity]
[emptytemp]
[resethosts]
[CreateRestorePoint]
[Reboot]