Code:
:OTL
SRV - File not found [Auto | Stopped] -- -- (0215001222663327mcinstcleanup) McAfee Application Installer Cleanup (0215001222663327)
O2 - BHO: (no name) - {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - No CLSID value found.
O4 - HKU\S-1-5-21-187182159-18414740-2408625527-1006..\Run: [Uniblue RegistryBooster 2009] File not found
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - File not found
O15 - HKU\S-1-5-21-187182159-18414740-2408625527-1006\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} http://www.gogobox.com.tw/neo.fld/GNowStarter.cab (Reg Error: Key error.)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/sof...iveXPlugin.cab (Reg Error: Key error.)
[5 C:\Documents and Settings\RAMON LAT\My Documents\*.tmp files -> C:\Documents and Settings\RAMON LAT\My Documents\*.tmp -> ]
[2008/03/06 19:35:34 | 000,000,000 | -HS- | C] () -- C:\Documents and Settings\RAMON LAT\Application Data\0047d0a9f6.dat
[2005/12/04 10:26:00 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\msbb.exe.temp
[2005/07/31 15:17:50 | 000,131,024 | ---- | C] () -- C:\WINDOWS\System32\5qihi5nl.dat
[2005/07/31 15:17:50 | 000,047,880 | ---- | C] () -- C:\WINDOWS\System32\k7pk1h9r.dat
[2005/07/31 15:17:50 | 000,004,728 | ---- | C] () -- C:\WINDOWS\System32\4k0ngtr1.dat
[2005/07/31 15:17:50 | 000,002,714 | ---- | C] () -- C:\WINDOWS\System32\3desel0c.dat
[2005/07/31 15:17:50 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\j07qv9e6.dat
[2005/07/31 15:17:45 | 000,003,514 | ---- | C] () -- C:\WINDOWS\System32\9vuihjuq.ini
[2005/07/31 15:17:45 | 000,000,035 | ---- | C] () -- C:\WINDOWS\System32\g6vhm81m.ini
[2007/02/08 23:18:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/06/21 18:47:20 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\~0
[2009/05/21 18:46:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\RAMON LAT\Application Data\Uniblue
@Alternate Data Stream - 500 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2C595FF3
:Services
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" =-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" =-
:Files
:Commands
[purity]
[emptytemp]
[emptyflash]
[Reboot]