Code:
:OTL
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - File not found
[2010/11/05 17:09:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg9
[2010/04/20 15:03:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dave.SHELLEY-7C3A8E9\Application Data\AVG9
[2010/11/05 07:02:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dave.SHELLEY-7C3A8E9\Application Data\Boyv
[2010/11/07 18:01:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dave.SHELLEY-7C3A8E9\Application Data\Koyg
[2010/11/08 15:58:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nicholas\Application Data\AVG10
[2010/04/17 21:15:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nicholas\Application Data\AVG9
[2010/11/04 18:22:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nicholas\Application Data\Eqfu
[2010/11/14 21:37:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nicholas\Application Data\TP
[2010/11/04 10:29:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nicholas\Application Data\Zeuqpo
[2010/11/07 18:13:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Shelley\Application Data\AVG10
[2010/04/16 22:09:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Shelley\Application Data\AVG9
@Alternate Data Stream - 153 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:34BCB6A9
@Alternate Data Stream - 149 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:CE0A077E
@Alternate Data Stream - 149 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:45FE2B4E
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:5EC637CB
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:8B2A99C5
:Commands
[purity]
[emptytemp]
[emptyflash]
[Reboot]