Code:
:OTL
SRV - (SearchIn1Step Service) -- C:\ProgramData\SearchIn1Step\searchin1172.exe File not found
[2010/07/13 13:03:17 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\ubekolasihi.dll
[2010/07/13 11:01:17 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\ijovohiyesupaho.dll
[2010/07/12 23:44:41 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\epikoziyequ.dll
[2010/07/12 20:20:27 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\enerabulezel.dll
[2010/07/12 16:10:14 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\azopepubitukix.dll
[2010/07/12 14:08:15 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\owebuvog.dll
[2010/07/12 13:03:47 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\ivegoyineba.dll
[2010/07/12 10:32:41 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\ubuyiluyi.dll
[2010/07/11 22:40:03 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\osuyuvas.dll
[2010/07/11 18:24:17 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\eruyaweb.dll
[2010/07/11 16:10:59 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\oditibofepoheba.dll
[2010/07/11 14:47:36 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\enuyiluyirogo.dll
[2010/07/11 13:03:31 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\eyebawut.dll
[2010/07/11 11:08:11 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\opexired.dll
[2010/07/11 00:57:36 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\anofekut.dll
[2010/07/11 00:06:25 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\exovemom.dll
[2010/07/10 21:24:54 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\ufoferoc.dll
[2010/07/10 19:15:23 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\idudugugek.dll
[2010/07/10 16:39:32 | 000,002,738 | ---- | M] () -- C:\Users\Marcus\AppData\Local\uquyabeguyo.dll
[2010/07/10 16:03:11 | 000,000,000 | ---- | M] () -- C:\Users\Marcus\AppData\Local\egedonokecik.dll
[2009/01/27 11:42:19 | 000,030,080 | ---- | C] () -- C:\Windows\System32\drivers\RKHit.sys
@Alternate Data Stream - 177 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:A6DF874E
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]