:processes
:OTL
IE - HKCU\..\SearchScopes\{77F2B683-BFE4-4140-A5D5-3004C16E3A8F}: "URL" = http://inet123.ru/?cx=partner-pub-7107628092852806%3Asxiti5-ktqk&cof=FORID%3A10&ie=utf-8&q={searchTerms}&sa=%CF%EE%E8%F1%EA&siteurl=inet123.ru%2F#881
ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} -
SafeBootMin: hitmanpro36 - Reg Error: Value error.
SafeBootMin: hitmanpro36.sys - Reg Error: Value error.
SafeBootMin: HitmanPro36Crusader - Reg Error: Value error.
SafeBootMin: HitmanPro36CrusaderBoot - Reg Error: Value error.
SafeBootNet: hitmanpro36 - Reg Error: Value error.
SafeBootNet: hitmanpro36.sys - Reg Error: Value error.
SafeBootNet: HitmanPro36Crusader - Reg Error: Value error.
SafeBootNet: HitmanPro36CrusaderBoot - Reg Error: Value error.
[2012.07.31 12:34:19 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
@Alternate Data Stream - 165 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07BF512B
DRV - [2012.09.21 23:54:01 | 000,097,440 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SMR311.SYS -- (SMR311)
[2012.09.21 23:54:01 | 000,097,440 | ---- | M] (Symantec Corporation) -- C:\windows\system32\drivers\SMR311.SYS
:Services
:Files
ipconfig /flushdns /c
:Reg
:Commands
[EMPTYTEMP]
[CREATERESTOREPOINT]
[purity]
[start explorer]
[Reboot]