Code:
:OTL
SRV - File not found [Auto | Stopped] -- -- (Messenger32)
IE - HKU\.DEFAULT\..\URLSearchHook: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - No CLSID value found
IE - HKU\S-1-5-18\..\URLSearchHook: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - No CLSID value found
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-2578987924-3179448702-1791641027-1007\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-2578987924-3179448702-1791641027-1007\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
[2011/12/30 23:58:58 | 000,013,530 | -HS- | M] () -- C:\Documents and Settings\Benjamin Provost\Local Settings\Application Data\quv20my10cj5tlhuinyj242353h6tak115s14xiosf2
[2011/12/30 23:58:58 | 000,013,530 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\quv20my10cj5tlhuinyj242353h6tak115s14xiosf2
[2011/12/23 13:46:42 | 000,014,268 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\y6jt60i6vx7dac
[2011/12/23 13:46:40 | 000,014,268 | -HS- | M] () -- C:\Documents and Settings\Benjamin Provost\Local Settings\Application Data\y6jt60i6vx7dac
[2011/11/27 01:18:00 | 000,012,948 | -HS- | C] () -- C:\Documents and Settings\Benjamin Provost\Local Settings\Application Data\aoekmg7h0xsk3fhh0kqq1s574o1q
[2011/11/27 01:18:00 | 000,012,948 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\aoekmg7h0xsk3fhh0kqq1s574o1q
[2007/11/17 21:06:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avg7
[2008/01/18 17:47:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/01/18 00:38:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/02/23 08:10:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jeanne Provost\Application Data\Viewpoint
[2009/02/01 00:30:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\TEMP\Application Data\Jetico Personal Firewall
:Commands
[purity]
[emptytemp]
[emptyjava]
[emptyflash]
[Reboot]