:OTL PRC - [2011/08/22 00:11:28 | 000,232,960 | ---- | M] () – C:\Windows\l1rezerv.exe PRC - [2011/08/22 00:06:28 | 000,273,920 | ---- | M] () – C:\Windows\update.3\svchost.exe PRC - [2011/08/22 00:06:28 | 000,273,920 | ---- | M] () – C:\Windows\update.3\svchost.exe PRC - [2011/08/22 00:06:28 | 000,273,920 | ---- | M] () – C:\Windows\update.3\svchost.exe PRC - [2011/08/22 00:06:28 | 000,273,920 | ---- | M] () – C:\Windows\update.3\svchost.exe PRC - [2011/08/22 00:02:53 | 000,355,840 | ---- | M] () – C:\Windows\update.5.0\svchost.exe PRC - [2011/08/22 00:02:53 | 000,355,840 | ---- | M] () – C:\Windows\update.5.0\svchost.exe PRC - [2011/08/22 00:02:53 | 000,355,840 | ---- | M] () – C:\Windows\update.5.0\svchost.exe PRC - [2011/08/22 00:02:53 | 000,355,840 | ---- | M] () – C:\Windows\update.5.0\svchost.exe PRC - [2011/08/22 00:02:53 | 000,355,840 | ---- | M] () – C:\Windows\update.5.0\svchost.exe PRC - [2011/08/22 00:02:53 | 000,355,840 | ---- | M] () – C:\Windows\update.5.0\svchost.exe PRC - [2011/08/22 00:02:53 | 000,355,840 | ---- | M] () – C:\Windows\update.5.0\svchost.exe PRC - [2011/08/22 00:02:53 | 000,355,840 | ---- | M] () – C:\Windows\update.5.0\svchost.exe PRC - [2011/08/21 23:58:36 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32_.exe PRC - [2011/08/21 23:58:36 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32.exe MOD - [2011/08/22 00:11:28 | 000,232,960 | ---- | M] () – C:\Windows\l1rezerv.exe MOD - [2011/08/22 00:06:28 | 000,273,920 | ---- | M] () – C:\Windows\update.3\svchost.exe MOD - [2011/08/21 23:58:36 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32_.exe MOD - [2011/08/21 23:58:36 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32.exe SRV - [2011/08/21 23:58:36 | 000,258,048 | ---- | M] () [Auto | Running] – C:\Windows\sysdriver32.exe – (srvsysdriver32) O3 - HKLM…\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O4 - HKLM…\Run: [1200204.exe] File not found O4 - HKLM…\Run: [2046375.exe] File not found O4 - HKLM…\Run: [6896728.exe] File not found O4 - HKLM…\Run: [7191153.exe] File not found O4 - HKLM…\Run: [l1rezerv.exe] C:\Windows\l1rezerv.exe () O4 - HKLM…\Run: [sysdriver32.exe] C:\Windows\sysdriver32.exe () O4 - HKLM…\Run: [sysdriver32_.exe] C:\Windows\sysdriver32_.exe () O4 - HKLM…\Run: [systemup] C:\Windows\systemup.exe () O4 - HKLM…\Run: [w_distrib.exe] C:\Windows\update.3\svchost.exe () O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - File not found O31 - SafeBoot: AlternateShell - services32.exe [2011/08/22 00:58:01 | 000,000,000 | —D | C] – C:\Windows\rpcminer [2011/08/22 00:58:01 | 000,000,000 | —D | C] – C:\Windows\phoenix [2011/08/22 00:13:56 | 000,000,000 | —D | C] – C:\Windows\system64 [2011/08/22 00:06:29 | 000,000,000 | -H-D | C] – C:\Windows\update.3 [2011/08/22 00:04:15 | 000,000,000 | -H-D | C] – C:\Windows\update.2 [2011/08/22 00:02:54 | 000,000,000 | -H-D | C] – C:\Windows\update.5.0 [2011/08/22 00:58:00 | 005,589,370 | ---- | M] () – C:\Windows\phoenix.rar [2011/08/22 00:58:00 | 001,075,284 | ---- | M] () – C:\Windows\rpcminer.rar [2011/08/22 00:58:00 | 000,246,272 | ---- | M] () – C:\Windows\unrar.exe [2011/08/22 00:58:00 | 000,182,617 | ---- | M] () – C:\Windows\ufa.rar [2011/08/22 00:15:01 | 000,000,223 | ---- | M] () – C:\Windows\info1 [2011/08/22 00:11:28 | 000,232,960 | ---- | M] () – C:\Windows\l1rezerv.exe [2011/08/22 00:04:40 | 000,000,734 | ---- | M] () – C:\Windows\SysNative\drivers\etc\hîsts [2011/08/22 00:01:18 | 000,000,000 | ---- | M] () – C:\Windows\loader2.exe_ok [2011/08/22 00:01:14 | 000,904,792 | ---- | M] () – C:\Windows\geoiplist.rar [2011/08/22 00:00:46 | 000,139,776 | ---- | M] () – C:\Windows\systemup.exe [2011/08/21 23:58:36 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32_.exe [2011/08/21 23:58:36 | 000,258,048 | ---- | M] () – C:\Windows\sysdriver32.exe [2011/08/22 00:01:16 | 004,636,907 | ---- | C] () – C:\Windows\geoiplist :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] “C:\Windows\update.tray-10-0\svchost.exe”=- “C:\Windows\update.1\svchost.exe”=- “C:\Windows\update.tray-10-0-lnk\svchost.exe”=- “C:\Windows\update.2\svchost.exe”=- “C:\Windows\update.3\svchost.exe”=- “C:\Windows\update.tray-10-0\svchost.exe”=- “C:\Windows\update.1\svchost.exe”=- “C:\Windows\update.tray-10-0-lnk\svchost.exe”=- “C:\Windows\update.2\svchost.exe”=- “C:\Windows\update.3\svchost.exe”=- :Commands [CLEARALLRESTOREPOINTS] [RESETHOSTS] [emptytemp]