:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.findeer.com[2012/06/09 15:34:10 | 000,000,000 | ---D | M] (Lavasoft Search Plugin) -- C:\Users\claudio\AppData\Roaming\mozilla\Firefox\Profiles\mku6vfwe.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack
[2011/12/03 18:11:14 | 000,330,316 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\personas@christopher.beard.xpi
[2012/09/21 16:33:25 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\0324adea3b6ec02af09ea4ae9424591b_expire
[2012/10/04 18:11:49 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\251a01e6e21370e33021658d316cc1a2_expire
[2012/10/03 19:21:39 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\292124057d00cb0fa73db6b90d079658_expire
[2012/08/12 18:05:56 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\2e74403c227112bec523796d5a77d77e_expire
[2012/10/04 18:11:48 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\35c5ead7c694459d2b46d88482247348_expire
[2012/08/28 17:03:12 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\4ad053d40dfa5cab7948e9251df6e3d9_expire
[2012/09/02 06:41:05 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\4b0e98311420d21d03c4ea36a788d6d7_expire
[2012/09/29 07:29:30 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\4d3d10bd28ff623813254a49b26be41f_expire
[2012/09/04 18:12:26 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\61e2ae11ba3d1cbe8887ea80f192e299_expire
[2012/08/13 07:16:20 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\6a549303124ba1b3ba81874e45b5f516_expire
[2012/10/04 18:11:47 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\79fb7d8c9c120c501ff74f2666f1ed76_expire
[2012/07/25 05:59:55 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\7acafe2d3e4c14a116bde4e028813ba7_expire
[2012/08/24 17:18:38 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\7cf04ffc65c19302872f4c23faa25a61_expire
[2012/08/27 16:41:37 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\b5bc7084382de95cb69790e5d10db338_expire
[2012/09/09 19:16:47 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\bc8dad417f8f0fb33406e79ccd806c7f_expire
[2012/10/03 19:21:44 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\be618ea2f4f463a305fc75d122f2d990_expire
[2012/10/04 18:11:48 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\c4f56b1faa9ea9bb7789728409bfc21f_expire
[2012/10/03 19:21:42 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\c5538e5049ca9b04ad62d9a930947369_expire
[2012/09/10 18:02:07 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\c695615035b25c404dbe6372f2672432_expire
[2012/08/18 17:59:01 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\c920ba477ab4d054bcdfe1b9fc1c6e58_expire
[2012/08/18 17:59:00 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\cbb69a449d3e39b3a3781ffb1d7fa52b_expire
[2012/09/04 18:12:26 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\cf48148729d10f9b8d2ad3b687ebfb80_expire
[2012/09/17 17:36:01 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\d12f0f1c68a3d6a58fdb249c5dbfb676_expire
[2012/08/26 16:26:26 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\d83bb387de1d7c4401815e133de06c6b_expire
[2012/07/25 05:59:55 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\da13d216564eb3ba7e1d2c6dcfa74204_expire
[2012/08/21 17:23:36 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\dc6668d28979688b1e2066d1dcaef0f6_expire
[2012/09/20 16:54:35 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\e02b35320e5111f1b626466c13c70a0a_expire
[2012/08/26 06:17:46 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\e7215b147326809c45f6cf0952274624_expire
[2012/10/03 19:21:41 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\e919434ec29526b28593c426e4264271_expire
[2012/09/10 18:02:05 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\eb04bdda55e3827d8df8b5e1afac83a2_expire
[2012/10/03 19:21:43 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\ece71b71690fad200cbed95871ef4bb2_expire
[2012/10/03 19:21:40 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\ee1ab4cb8e86769e288abaa46407a623_expire
[2012/10/03 19:21:41 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\ef8b53537a5678ed1fcb65662c69bced_expire
[2012/10/03 19:21:42 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\f03527c67e08602d2e4c18ae7867300d_expire
[2012/09/29 07:29:29 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\fa74672918974682c82b8d91dfbe0d6b_expire
[2012/09/29 07:29:29 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\ff4d692d5e7cccbc4b3e9ef4062b1c6f_expire
[2012/07/22 21:29:07 | 000,001,867 | ---- | M] () -- C:\Users\claudio\AppData\Roaming\mozilla\firefox\profiles\mku6vfwe.default\searchplugins\findeer.xml
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [] File not found
[2012/10/02 15:29:01 | 000,002,710 | ---- | M] () -- C:\Users\claudio\Documents\cc_20121002_152857.reg
[2012/10/02 15:14:27 | 000,002,138 | ---- | M] () -- C:\Users\claudio\Documents\cc_20121002_151425.reg
[2012/10/02 15:14:15 | 000,005,496 | ---- | M] () -- C:\Users\claudio\Documents\cc_20121002_151411.reg
[2012/10/01 18:24:36 | 000,000,448 | ---- | M] () -- C:\Users\claudio\Documents\cc_20121001_182432.reg
[2012/09/30 14:37:18 | 000,000,448 | ---- | M] () -- C:\Users\claudio\Documents\cc_20120930_143715.reg
[2012/09/30 10:12:24 | 000,000,758 | ---- | M] () -- C:\Users\claudio\Documents\cc_20120930_101216.reg
[2012/09/15 12:19:58 | 000,001,064 | ---- | M] () -- C:\Users\claudio\Documents\cc_20120915_121955.reg
[2012/09/15 12:15:10 | 000,007,286 | ---- | M] () -- C:\Users\claudio\Documents\cc_20120915_121505.reg
[2012/06/10 21:41:53 | 000,000,000 | ---D | M] -- C:\Users\claudio\AppData\Roaming\Ad-Aware Antivirus
[2012/07/22 21:57:18 | 000,000,000 | ---D | M] -- C:\Users\claudio\AppData\Roaming\Iminent
@Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:4116B5AB
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:981884E7
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:52DBE86F
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:81F83028
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:5D458568
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:029E021F
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:9FD757A9
:Files
ipconfig /flushdns /c
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"
:commands
[purity]
[emptytemp]
[RESETHOSTS]
[start explorer]
[CLEARALLRESTOREPOINTS]
[Reboot]