Code:
:OTL
IE - HKU\S-1-5-21-1039221757-4152704121-570408990-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
FF - prefs.js..browser.search.defaultenginename: "My Web Search"
FF - prefs.js..keyword.URL: "http://search.mywebsearch.com/myweb...3^us&si=CNu90_qf17ICFURxQgodmgQAmg&searchfor="
[2012/09/27 21:15:03 | 000,009,635 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\bsiu5cbq.default\searchplugins\my-web-search.xml
O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Admin\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll File not found
O3 - HKLM\..\Toolbar: (VideoDownloadConverter) - {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll File not found
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-21-1039221757-4152704121-570408990-1000\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O15 - HKLM\..Trusted Domains: jcatsdefender.com ([caaoc] http in Trusted sites)
O15 - HKLM\..Trusted Domains: jcatsdefender.com ([caaoc] https in Trusted sites)
O15 - HKLM\..Trusted Domains: jcatsdefender.com ([traincaaoc] http in Trusted sites)
O15 - HKLM\..Trusted Domains: jcatsdefender.com ([traincaaoc] https in Trusted sites)
O15 - HKU\S-1-5-21-1039221757-4152704121-570408990-1000\..Trusted Domains: jcatsdefender.com ([caaoc] http in Trusted sites)
O15 - HKU\S-1-5-21-1039221757-4152704121-570408990-1000\..Trusted Domains: jcatsdefender.com ([caaoc] https in Trusted sites)
O15 - HKU\S-1-5-21-1039221757-4152704121-570408990-1000\..Trusted Domains: jcatsdefender.com ([traincaaoc] http in Trusted sites)
O15 - HKU\S-1-5-21-1039221757-4152704121-570408990-1000\..Trusted Domains: jcatsdefender.com ([traincaaoc] https in Trusted sites)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
[2012/10/01 20:58:23 | 000,000,000 | ---D | C] -- C:\FRST
[2012/01/04 20:01:47 | 000,006,160 | -HS- | C] () -- C:\ProgramData\148wl81cw72u12151025pwdnof4e525rjf7uj88446x
[2011/12/29 18:37:11 | 000,013,362 | -HS- | C] () -- C:\ProgramData\qej17wi58ii2gqgfuwhl155625h6ctk508k78epjxu3
[2011/11/17 00:14:10 | 000,000,000 | -HSD | M] -- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\{af8d9e4c-5382-0699-1de2-5974c5427e62}\L
[2011/11/17 00:14:10 | 000,000,000 | -HSD | M] -- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\{af8d9e4c-5382-0699-1de2-5974c5427e62}\U
[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2010/07/27 07:59:11 | 014,162,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2010/07/27 07:03:24 | 012,867,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 18:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/13 18:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 18:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
[2012/04/13 19:09:16 | 000,000,000 | ---D | M] -- C:\Users\Lindsay\AppData\Roaming\AVG10
:Services
:Reg
:Files
:Commands
[purity]
[emptytemp]
[emptyjava]
[emptyflash]
[Reboot]