Code:
:OTL
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKCU\..Trusted Domains: onmycam.com ([]* is out of zone range - 6)
O15 - HKCU\..Trusted Domains: onmycam.net ([]* is out of zone range - 6)
O15 - HKCU\..Trusted Domains: onmycam.org ([]* is out of zone range - 6)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/downlo...8f/wvc1dmo.cab (Reg Error: Value error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
[2010/12/12 06:12:43 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\YSUKXVESZ
[2010/12/03 06:32:14 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\Ÿ9Ÿ9
[2009/09/25 11:41:17 | 000,019,408 | ---- | C] () -- C:\Documents and Settings\Jim\Application Data\ebic.dat
[2009/09/25 11:41:17 | 000,018,393 | ---- | C] () -- C:\Documents and Settings\Jim\Application Data\cuvumowaxu.exe
[2009/09/25 11:41:17 | 000,018,001 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ijodyfigu.pif
[2009/09/25 11:41:17 | 000,017,324 | ---- | C] () -- C:\Documents and Settings\Jim\Application Data\umoxywumol.vbs
[2009/09/25 11:41:16 | 000,015,309 | ---- | C] () -- C:\Documents and Settings\Jim\Local Settings\Application Data\guvotozaze.com
[2009/09/25 11:41:16 | 000,014,141 | ---- | C] () -- C:\Documents and Settings\Jim\Application Data\natarogaje.inf
[2009/09/25 11:41:16 | 000,010,845 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\afacynaj.bin
[2009/09/25 11:41:15 | 000,019,301 | ---- | C] () -- C:\Documents and Settings\Jim\Local Settings\Application Data\tunonyhyd.dll
[2009/09/25 11:41:15 | 000,018,206 | ---- | C] () -- C:\Program Files\Common Files\iluqovag._dl
[2009/09/25 11:41:15 | 000,010,829 | ---- | C] () -- C:\Program Files\Common Files\timybidu.inf
[2009/09/25 11:06:11 | 000,019,556 | ---- | C] () -- C:\Documents and Settings\Jim\Local Settings\Application Data\esyset.lib
[2009/09/25 11:06:10 | 000,015,392 | ---- | C] () -- C:\Documents and Settings\Jim\Local Settings\Application Data\gaty.ban
[2009/09/25 11:06:10 | 000,013,547 | ---- | C] () -- C:\Documents and Settings\Jim\Local Settings\Application Data\ywurob.vbs
[2009/09/25 10:24:46 | 000,016,084 | ---- | C] () -- C:\Documents and Settings\Jim\Application Data\rematuzej.db
[2009/09/25 10:24:46 | 000,015,230 | ---- | C] () -- C:\Documents and Settings\Jim\Local Settings\Application Data\hagehe.scr
[2009/09/25 10:24:46 | 000,013,862 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\bogufapo.exe
[2009/09/25 10:24:45 | 000,018,807 | ---- | C] () -- C:\Documents and Settings\Jim\Local Settings\Application Data\mylegany.lib
[2009/09/25 10:24:45 | 000,013,878 | ---- | C] () -- C:\Documents and Settings\Jim\Application Data\cerufuku._sy
[2009/09/25 10:24:45 | 000,012,801 | ---- | C] () -- C:\Documents and Settings\Jim\Application Data\atik.lib
[2009/09/25 10:24:45 | 000,011,125 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\farib.com
[2009/09/25 10:24:45 | 000,010,428 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\awitygos.ban
[2009/09/25 10:24:44 | 000,015,630 | ---- | C] () -- C:\Documents and Settings\Jim\Local Settings\Application Data\jypy.sys
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2CA54532
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
:Services
:Reg
:Files
D:\Program Files\Common Files\Real\Toolbar\RealBar.dll
:Commands
[purity]
[emptytemp]
[emptyflash]
[Reboot]