Code:
:OTL
SRV - File not found [Auto | Stopped] -- -- (RoxLiveShare9)
SRV - File not found [On_Demand | Stopped] -- -- (McSysmon)
SRV - File not found [Unknown | Stopped] -- -- (McShield)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:51636
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:51636
O3 - HKU\S-1-5-21-1004747553-854733563-2513261659-1007\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-1004747553-854733563-2513261659-1007\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-appf?lic=NFVXV1UtV0JEWEMtVllGTjMtUURKTUgtNDJBT0EtSzZIVTk"&"inst=NzctNzIyNDA yMDA5LVNUMTJGT0krMS1ERFQrMC1FVUxBKzEtU1QxMkZBUFArMQ"&"prod=90"&"ver=2012.0. 1796"&"mid=5188a9f4d2a647d1a4bad153e62412d6-f43308e76f07837a7ea13e9f5929462580b6ee3d File not found
O8 - Extra context menu item: &AIM Toolbar Search - Reg Error: Value error. File not found
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Key error.)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll File not found
[2011/09/08 17:57:01 | 000,001,180 | -HS- | M] () -- C:\Documents and Settings\LT BABY\Local Settings\Application Data\o63enu3yd4f2q
[2011/09/08 17:57:01 | 000,001,180 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\o63enu3yd4f2q
[2009/01/11 13:03:28 | 000,011,168 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\widijeve
[2011/02/11 19:04:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\391C5
[2011/09/14 10:18:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2009/07/26 18:10:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\bazoveza
[2009/05/09 16:26:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\befuvanu
[2009/05/09 16:26:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\bewihafe
[2009/07/26 18:10:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\bofofevu
[2009/07/26 18:10:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\dapavama
[2009/07/26 18:10:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\darunuwe
[2009/05/09 16:27:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\darususi
[2009/07/26 18:10:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\denufudu
[2009/07/26 18:10:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\donojawi
[2009/07/26 18:10:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\fedeyipu
[2009/07/26 18:10:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\fenobeko
[2009/07/26 18:10:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\firugoti
[2009/05/22 00:06:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\fivipute
[2009/05/09 16:27:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\fosadite
[2009/05/09 16:27:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\fusigoka
[2009/07/26 18:10:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\fuzowezo
[2009/07/26 18:10:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\garazuha
[2009/05/09 16:28:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\geligehu
[2009/05/09 16:28:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\gihoyojo
[2009/05/09 16:28:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\gohifodi
[2009/05/09 11:20:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\gomuzidi
[2009/07/26 18:10:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\guhiziho
[2009/05/09 16:29:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\hekazezi
[2009/05/21 00:06:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\hekeyapi
[2009/07/26 18:10:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\hivunote
[2009/05/09 16:29:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\hutikovu
[2009/05/09 16:29:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\janifedu
[2009/05/09 16:29:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\javinete
[2009/07/26 18:10:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\jefaduku
[2009/07/26 18:10:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\jezemimu
[2009/05/09 16:30:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\jomotewa
[2009/07/26 18:10:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\juposeno
[2009/05/09 16:30:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\jutizowi
[2009/05/09 11:24:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kewevuro
[2009/05/09 16:30:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kewowupa
[2009/05/09 16:30:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kimuremo
[2009/05/22 00:06:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kivigoru
[2009/07/26 18:10:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kiyajeru
[2009/05/09 16:31:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kubidima
[2009/05/09 16:31:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kujonuva
[2009/05/09 16:31:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kuvimulo
[2009/07/26 18:10:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\lepekisu
[2009/07/26 18:10:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\lezaromo
[2009/05/09 16:31:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\litikusi
[2009/07/26 18:10:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\malaruwo
[2009/05/09 16:31:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\matizava
[2011/09/10 23:29:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\mJ21101PpGeC21101
[2009/05/24 18:32:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\muhoyawa
[2009/07/26 18:11:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\namiviko
[2009/05/09 16:31:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\nawonane
[2009/07/26 18:11:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\netojeke
[2009/05/09 16:31:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\nevorefa
[2009/05/09 16:32:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\nifodiyu
[2009/05/09 16:32:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\nijetiyi
[2009/05/09 16:32:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\nimidiki
[2009/07/26 18:11:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\norefose
[2009/05/09 11:24:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\novusina
[2009/06/11 21:12:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\nutuhunu
[2009/05/16 20:11:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\nuwuzeku
[2009/06/09 23:38:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\papororo
[2009/07/26 18:11:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\patayaru
[2009/05/09 16:32:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\pawovuda
[2009/05/09 16:32:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\peheliba
[2009/05/09 16:33:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\pehirema
[2009/05/09 16:33:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\peroruvo
[2009/07/26 18:11:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\pogewaso
[2009/05/09 16:33:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\rakedega
[2009/07/26 18:11:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ramuzovi
[2009/06/11 21:12:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ravezula
[2009/07/26 18:11:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ravufuge
[2009/05/09 16:33:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\resemuzu
[2009/05/09 16:33:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\robejaku
[2009/05/09 16:33:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ruhegozi
[2009/07/26 18:11:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\satukivu
[2009/05/09 11:24:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\sihosido
[2009/07/26 18:11:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\siwelehu
[2009/05/09 16:34:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\sohibesi
[2009/06/07 08:52:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\sugemeha
[2009/05/09 16:34:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tevaziva
[2011/09/11 00:10:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tiwedihu
[2009/05/09 16:35:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tomavita
[2009/06/06 09:26:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\toyoyavi
[2009/05/09 16:35:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vegozadi
[2011/09/10 23:39:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/09/11 00:10:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vonibusa
[2009/05/09 16:35:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vozafiwu
[2011/09/10 23:29:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vumehijo
[2009/06/08 01:30:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vuzofafu
[2009/06/09 00:09:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wamejawe
[2009/05/09 16:35:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wazuloro
[2011/09/11 00:10:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wekavube
[2009/05/28 23:01:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wenihubi
[2009/05/09 16:36:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wepejapu
[2009/05/24 18:32:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wolizapa
[2009/05/09 16:36:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wotuzapi
[2009/05/18 23:00:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wuduzuli
[2009/05/09 16:36:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wuniferi
[2011/09/11 00:10:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wuyojogi
[2009/05/09 16:37:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\yabohoyu
[2009/05/09 16:37:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\yinerodu
[2011/09/11 00:10:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\yubihimo
[2009/05/09 16:37:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\yujawohu
[2009/05/09 11:24:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\yupabuse
[2011/09/10 18:57:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\zapujevu
[2009/05/09 16:37:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\zarebeba
[2009/06/11 23:03:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\zuhuyaba
[2009/05/09 16:37:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\zujopuhe
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
:Commands
[purity]
[emptytemp]
[emptyflash]
[Reboot]