Code:
:OTL
IE - HKLM\..\SearchScopes\{a5b9c0f5-5616-47cd-a95f-e43b488faccf}: "URL" = http://search.mywebsearch.com/myweb...42443&st=sb&n=77df45da&searchfor={searchTerms}
IE - HKU\S-1-5-21-343818398-1454471165-839522115-1003\..\SearchScopes\{a5b9c0f5-5616-47cd-a95f-e43b488faccf}: "URL" = http://search.mywebsearch.com/myweb...42443&st=sb&n=77df45da&searchfor={searchTerms}
IE - HKU\S-1-5-21-343818398-1454471165-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
O2 - BHO: (no name) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - No CLSID value found.
O2 - BHO: (no name) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - No CLSID value found.
O3 - HKU\S-1-5-21-343818398-1454471165-839522115-1003\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-21-343818398-1454471165-839522115-1003\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444552440000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\tmbp - No CLSID value found
O18 - Protocol\Handler\tmpx - No CLSID value found
[2012/04/10 13:12:24 | 000,000,160 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\-IuyE6EHzNujonPr
[2012/04/10 13:12:24 | 000,000,000 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\-IuyE6EHzNujonP
[2011/12/24 16:06:47 | 000,001,378 | -HS- | C] () -- C:\Documents and Settings\Master Blaster\Local Settings\Application Data\ao46ielr5pg3406gx7357mv8gr7hj2s4
[2011/12/24 16:06:47 | 000,001,378 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\ao46ielr5pg3406gx7357mv8gr7hj2s4
[2011/07/29 05:13:19 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hdty.exe
[2011/07/29 05:13:18 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\qjfs.exe
[2011/07/29 05:13:18 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\icwp.exe
[2011/07/29 05:13:18 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\bfyl.exe
[2011/05/19 01:45:12 | 000,008,512 | -HS- | C] () -- C:\Documents and Settings\Master Blaster\Local Settings\Application Data\405a481v1p73r00sd4854fqwg0637xef60j3i2n5xlhy
[2011/05/19 01:45:12 | 000,008,512 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\405a481v1p73r00sd4854fqwg0637xef60j3i2n5xlhy
[2011/05/08 03:38:26 | 000,014,332 | -HS- | C] () -- C:\Documents and Settings\Master Blaster\Local Settings\Application Data\re15525dl3y7e4hemd3d26i4u6tdmmy
[2011/05/08 03:38:26 | 000,014,332 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\re15525dl3y7e4hemd3d26i4u6tdmmy
[2011/04/18 13:53:36 | 000,013,148 | -HS- | C] () -- C:\Documents and Settings\Master Blaster\Local Settings\Application Data\c7b8l4817jy2c
[2011/04/18 13:53:36 | 000,013,148 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\c7b8l4817jy2c
[2011/04/12 06:48:58 | 000,000,136 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~20176692r
[2011/04/12 06:48:56 | 000,000,104 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\~20176692
[2011/04/12 06:48:48 | 000,000,336 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\20176692
[2011/03/11 06:37:07 | 000,014,506 | -HS- | C] () -- C:\Documents and Settings\Master Blaster\Local Settings\Application Data\2043267982
[2011/03/11 06:37:07 | 000,014,506 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\2043267982
[2011/01/19 17:57:29 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Sqifogomusigego.dat
[2011/01/19 17:57:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Rdife.bin
[2011/01/31 00:40:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iPjHfIb06510
[2011/02/05 12:58:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kCmJhHl06511
[2010/11/03 19:17:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master Blaster\Application Data\Registry Mechanic
:Commands
[purity]
[emptytemp]
[emptyjava]
[emptyflash]
[Reboot]