:OTL
SRV - [2010/05/06 17:39:16 | 000,011,776 | ---- | M] () [Auto] -- C:\Windows\System32\mousenh32.exe -- (winbackupdumper-id1906Xv2Ej1zt)
SRV - [2010/05/06 17:39:16 | 000,009,728 | ---- | M] () [Auto] -- C:\Windows\System32\wirepots.exe -- (acrosysbackup_ex06Xv2Ej1zt)
O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (no name) - {2787EA8E-8D87-48AF-88AD-B30246C917AB} - No CLSID value found.
O4 - HKLM..\Run: [Acronis Toolbar Helper] File not found
O4 - HKLM..\Run: [vtuvstsys] C:\Windows\System32\bywuut.dll ()
O4 - HKU\.DEFAULT..\Run: [opmnnnsys] C:\Windows\System32\bywuut.dll ()
O4 - HKU\Administrator_ON_C..\Run: [ddbbyasys] C:\Windows\System32\bywuut.dll ()
O4 - HKU\Administrator_ON_C..\Run: [Desktop Cleanup Wizard] File not found
O4 - HKU\Administrator_ON_C..\Run: [P2kAutostart] File not found
O4 - HKU\Administrator_ON_C..\Run: [winjwws92] C:\Users\Administrator\AppData\Roaming\winjwws92\winjwws93.exe File not found
O4 - HKLM..\RunOnce: [] File not found
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\msdaipp - No CLSID value found
O30 - LSA: Authentication Packages - (bywuut.dll) - C:\Windows\System32\bywuut.dll ()
[2010/05/05 16:39:03 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\winjwws92
[2010/05/17 08:50:30 | 000,089,600 | -H-- | M] () -- C:\Windows\System32\opmlif.dll
[2010/05/06 17:39:16 | 000,037,888 | ---- | M] () -- C:\Windows\System32\wirepots.dll
[2010/05/06 17:39:16 | 000,037,888 | ---- | M] () -- C:\Windows\System32\syspol32.dll
[2010/05/06 17:39:16 | 000,037,888 | ---- | M] () -- C:\Windows\System32\b_syspol32.dll
[2010/05/06 08:44:23 | 000,096,256 | -H-- | M] () -- C:\Windows\System32\rqppqq.dll
[2010/04/05 20:32:22 | 000,000,080 | RHS- | C] () -- C:\Windows\System32\9129AF82DC.dll
[2009/11/02 21:06:03 | 000,000,128 | ---- | C] () -- C:\Windows\System32\_WDYSZYG.sys
:Services
winbackupdumper-id1906Xv2Ej1zt
acrosysbackup_ex06Xv2Ej1zt
:Reg
:Files
C:\Windows\System32\mousenh32.exe
C:\Windows\System32\wirepots.exe
C:\Windows\System32\bywuut.dll
C:\Users\Administrator\AppData\Roaming\winjwws92\winjwws93.exe
:Commands
[purity]
[emptytemp]