:OTL
PRC - C:\Users\Public\Documents\AppData\PoApp\PService.e xe (PService)
SRV - (SoftwareUpd) -- C:\Users\George\AppData\Local\SoftwareUpdater\Soft wareUpdService.exe (SoftwareUpdService)
SRV - (PowerOffer Service) -- C:\Users\George\AppData\Local\PosService\Pos.exe (PowerOfferService)
SRV - (ServUpdater) -- C:\Users\George\AppData\Local\ServUpdater\ServiceU pd.exe (ServiceUpd)
IE:
64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" =
http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" =
http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.findeer.com
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.findeer.com
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.findeer.com
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.findeer.com
IE - HKU\S-1-5-21-1129987932-2334857263-2445457253-1001\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" =
http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
[2013/01/07 23:33:14 | 000,002,354 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.8.7.2\bh\Bab ylonToolbar.dll (Babylon BHO)
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.8.7.2\Babylo nToolbarTlbr.dll (Babylon Ltd.)
O4 - HKLM..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher. exe (PLauncher)
[2013/01/03 19:26:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BabylonToolbar
[2013/01/03 19:25:43 | 000,000,000 | ---D | C] -- C:\Users\George\AppData\Roaming\Babylon
[2013/01/03 19:25:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2013/01/03 19:26:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BabylonToolbar
[2013/01/03 19:25:43 | 000,000,000 | ---D | C] -- C:\Users\George\AppData\Roaming\Babylon
[2013/01/03 19:25:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2013/01/03 19:25:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2012/12/10 23:52:47 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\AppData
[2012/12/10 23:52:46 | 000,000,000 | ---D | C] -- C:\Users\George\AppData\Local\PosService
[2013/01/03 19:25:43 | 000,000,000 | ---D | M] -- C:\Users\George\AppData\Roaming\Babylon
:Files
C:\ProgramData\ras_0oed.pad
C:\ProgramData\zak_lo0i7g.pad
C:\Users\George\AppData\Roaming\Uzbad
ipconfig /flushdns /c
:commands
[purity]
[Reboot]