:OTL O4 - HKCU..\Run: [1970697885] C:\Users\Rufty\AppData\Local\vwu.exe () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1207475069-2375867297-3514939225-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present [2011/08/01 13:13:51 | 000,010,544 | -HS- | M] () -- C:\ProgramData\2b20g13747uujl32et1554se2m073 [2011/08/01 13:13:50 | 000,010,544 | -HS- | M] () -- C:\Users\Rufty\AppData\Local\2b20g13747uujl32et1554se2m073 :Reg [HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command] @="C:\Program Files\Internet Explorer\iexplore.exe" :Files ipconfig /flushdns /c :Commands [purity] [resethosts] [emptytemp] [EMPTYFLASH] [CREATERESTOREPOINT] [Reboot]