Code:
:OTL
IE - HKU\.DEFAULT\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No CLSID value found
IE - HKU\S-1-5-18\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No CLSID value found
O2 - BHO: (no name) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No CLSID value found.
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No CLSID value found.
O3 - HKU\S-1-5-21-910154618-685303889-673547498-1018\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-8398-26FADCF27386} - No CLSID value found.
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html File not found
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html File not found
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html File not found
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html File not found
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html File not found
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html File not found
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Gary\Start Menu\Programs\IMVU\Run IMVU.lnk File not found
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/...ndows-i586.cab (Reg Error: Key error.)
[2011/07/26 10:19:57 | 000,012,042 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\vomg3m414lo2n1b8788n21tn0n4xi6
[2011/06/22 01:43:46 | 000,013,162 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\2sj84r4yr1d5210755e
[2009/09/27 00:22:38 | 000,060,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\fsaulwct.sys
[2009/09/27 00:18:25 | 000,060,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\afqfecqu.sys
[2009/09/26 15:57:48 | 000,014,419 | ---- | C] () -- C:\Program Files\Common Files\xebazyvic.dat
[2009/09/26 15:57:49 | 000,016,027 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\rujutupy.com
[2011/01/17 10:40:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\lDgHg06511
[2012/01/22 20:07:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gary\Application Data\PriceGong
[2012/02/04 10:10:00 | 000,000,464 | ---- | M] () -- C:\WINDOWS\Tasks\At25.job
[2012/02/02 20:40:00 | 000,000,464 | ---- | M] () -- C:\WINDOWS\Tasks\At26.job
[2012/02/01 22:20:00 | 000,000,464 | ---- | M] () -- C:\WINDOWS\Tasks\At27.job
[2012/02/05 14:00:00 | 000,000,464 | ---- | M] () -- C:\WINDOWS\Tasks\At28.job
[2012/02/05 14:00:00 | 000,000,464 | ---- | M] () -- C:\WINDOWS\Tasks\At29.job
[2010/12/08 10:34:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gabby catlin\Application Data\PriceGong
:Commands
[purity]
[emptytemp]
[emptyjava]
[emptyflash]
[Reboot]