Code:
:OTL
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
[2011/12/18 14:32:40 | 000,010,486 | -HS- | C] () -- C:\Users\Vivek\AppData\Local\774335p0e210t008t785a0hmt7c3
[2011/11/17 19:38:44 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\3D3D9
[2012/02/18 21:58:44 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\B403D
[2011/11/13 20:40:19 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\d88ffR9hTXqj
[2011/11/13 18:08:58 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\DeeelIIBrzNyxuS
[2011/11/13 18:40:58 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\fpnG4aQH6W7E9Tq
[2011/11/13 18:45:24 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\G1uvS2obFpGaJ
[2011/11/13 18:45:22 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\gYXwkUVelBz
[2011/11/13 18:09:00 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\kS2iDp4HsKf9TqY
[2011/11/13 20:40:19 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\OdEK8gRZ9YwUeIt
[2011/11/13 18:41:00 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\OYCwkIVrlNx0c
[2011/11/13 18:09:07 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\PWJJJdEE8RZqhXk
[2011/11/13 18:45:29 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\VjekIBrzOyA2b3n
[2011/11/13 18:45:29 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\X5aQH6dWKfLgXjC
[2011/11/13 18:45:18 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\yD2onF4pm5Q7E8R
[2011/11/13 18:09:08 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\ZVVVellOBz0cAiv
:Commands
[purity]
[emptytemp]
[emptyjava]
[emptyflash]
[Reboot]