Code:
:OTL
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
@Alternate Data Stream - 85 bytes -> C:\ProgramData:$SS_DESCRIPTOR_SVXWVBPTSVBVVFN4TF1R VLNVCL1XYRVBHV9TJVHVVPVVVVVVVJVV
@Alternate Data Stream - 85 bytes -> C:\ProgramData:$SS_DESCRIPTOR_SVXWV4PVSVVVV8N4TF1R VDNVCLPT4WP9HVM8G6XVFGVXVF5VVJVP
@Alternate Data Stream - 64 bytes -> C:\Users\Admin\Desktop\The.Illusionist[2006]DvDrip[Eng]-aXXo.mp4:TOC.WMV
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:EAB1AD1B
@Alternate Data Stream - 151 bytes -> C:\ProgramData\TEMP:8C443193
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:51387F29
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:7A0A894A
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:726A7C8D
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:41C283B2
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:3965C4E8
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:B310C233
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:550179F5
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:B8EA2C49
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:F854B030
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:A42A9F39
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:9B750A13
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:77846FFE
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:B84EF836
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:956EC010
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:5925E400
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:700B8E2E
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:6CC1CB6D
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:5E3FBF9D
:Services
:Reg
:Files
:Commands
[purity]
[emptytemp]
[emptyflash]
[Reboot]