Code:
:OTL
PRC - C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll File not found
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
[2012/03/25 10:11:04 | 000,000,000 | -HSD | C] -- C:\found.000
[2012/03/29 16:59:09 | 000,127,547 | ---- | M] () -- C:\Documents and Settings\TimH\Desktop\setup_av_free.exe
[2012/03/26 19:12:52 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\TimH\Desktop\h94rnms4.exe
[2012/03/23 18:30:56 | 000,000,264 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\~1gKeUlddAhu4pq
[2012/03/23 18:30:56 | 000,000,176 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\~1gKeUlddAhu4pqr
[2012/03/23 18:17:46 | 000,000,853 | ---- | M] () -- C:\Documents and Settings\TimH\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/03/23 18:17:46 | 000,000,835 | ---- | M] () -- C:\Documents and Settings\TimH\Desktop\System Check.lnk
[2012/03/23 18:17:37 | 000,000,336 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\1gKeUlddAhu4pq
[2012/03/15 19:56:46 | 000,488,848 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/03/15 19:56:45 | 000,089,732 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/03/31 11:06:44 | 000,000,853 | ---- | C] () -- C:\Documents and Settings\TimH\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/03/29 16:59:23 | 000,127,547 | ---- | C] () -- C:\Documents and Settings\TimH\Desktop\setup_av_free.exe
[2012/03/26 19:12:52 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\TimH\Desktop\h94rnms4.exe
[2012/03/23 18:30:56 | 000,000,264 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~1gKeUlddAhu4pq
[2012/03/23 18:30:56 | 000,000,176 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~1gKeUlddAhu4pqr
[2012/03/23 18:17:46 | 000,000,835 | ---- | C] () -- C:\Documents and Settings\TimH\Desktop\System Check.lnk
[2012/03/23 18:17:37 | 000,000,336 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\1gKeUlddAhu4pq
[2009/08/30 09:14:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\TimH\Application Data\Viewpoint
[2005/08/16 01:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\Administrator\Local Settings\temp\RarSFX2\h\explorer.exe
[2005/08/16 01:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\Administrator\Local Settings\temp\RarSFX3\h\explorer.exe
[2005/08/16 01:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\Administrator\Local Settings\temp\RarSFX6\h\explorer.exe
[2005/08/16 01:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\Administrator\Local Settings\temp\RarSFX7\h\explorer.exe
[2005/08/16 01:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\TimH\Local Settings\temp\RarSFX1\h\explorer.exe
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"HijackThis"
:Files
C:\Documents and Settings\All Users\Application Data\1gKeUlddAhu4pq.exe
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[emptyflash]
[emptyjava]
[resethosts]
[CreateRestorePoint]
[Reboot]