Code:
:OTL
IE - HKU\S-1-5-21-515583346-2551849537-2618369934-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
[2012/01/10 00:48:36 | 000,366,080 | ---- | C] (Корпорация Майкрософт) -- C:\Users\Pat\Documents\UNffbK0.exe
[2012/01/10 00:48:35 | 000,366,080 | ---- | C] (Корпорация Майкрософт) -- C:\Users\Pat\Documents\7265t.exe
[2012/01/10 21:19:29 | 000,005,684 | -HS- | M] () -- C:\Users\Pat\AppData\Local\270g64m584464es2vt180fx
[2012/01/10 21:19:29 | 000,005,684 | -HS- | M] () -- C:\ProgramData\270g64m584464es2vt180fx
[2012/01/10 14:50:48 | 000,003,726 | -HS- | M] () -- C:\Users\Pat\AppData\Local\21juy61aha1224gursi88rlkuu5mp68jeb6v60s3u11qst
[2012/01/10 14:50:48 | 000,003,726 | -HS- | M] () -- C:\ProgramData\21juy61aha1224gursi88rlkuu5mp68jeb6v60s3u11qst
[2012/01/04 18:41:46 | 000,001,436 | -HS- | M] () -- C:\Users\Pat\AppData\Local\fwy56et66vp5ilixbfij237357o4lri438t60pygsu2
[2012/01/03 12:57:19 | 000,013,122 | -HS- | M] () -- C:\Users\Pat\AppData\Local\683yv44bq84a35103446etiitt8s666uxy1tx21778a
[2012/01/03 12:57:19 | 000,013,122 | -HS- | M] () -- C:\ProgramData\683yv44bq84a35103446etiitt8s666uxy1tx21778a
[2011/12/26 15:25:10 | 000,002,428 | -HS- | M] () -- C:\Users\Pat\AppData\Local\qc33xffd0ua6634ib5532kj7jn1xl3h8
[2011/12/26 15:25:10 | 000,002,428 | -HS- | M] () -- C:\ProgramData\qc33xffd0ua6634ib5532kj7jn1xl3h8
[2011/12/21 20:09:13 | 000,001,458 | -HS- | M] () -- C:\Users\Pat\AppData\Local\173138t3d060c562n640q3bog0x4
[2011/12/20 23:19:46 | 000,006,010 | -HS- | M] () -- C:\Users\Pat\AppData\Local\7on2n11ogr7n42xgcdo0677of141lpw05x6b
[2011/12/20 23:19:46 | 000,006,010 | -HS- | M] () -- C:\ProgramData\7on2n11ogr7n42xgcdo0677of141lpw05x6b
[2011/12/17 01:35:43 | 000,011,428 | -HS- | M] () -- C:\Users\Pat\AppData\Local\o4go10t2ew7ikk
[2011/12/17 01:35:43 | 000,011,428 | -HS- | M] () -- C:\ProgramData\o4go10t2ew7ikk
[2011/12/14 23:18:38 | 000,012,062 | -HS- | M] () -- C:\Users\Pat\AppData\Local\213812u3u364p503o070g4clh2y7
[2011/12/14 23:18:38 | 000,012,062 | -HS- | M] () -- C:\ProgramData\213812u3u364p503o070g4clh2y7
[2011/12/14 21:01:25 | 000,001,582 | -HS- | M] () -- C:\Users\Pat\AppData\Local\wrtxqe4s5omf0cvp3ugj1w488u8g
[2012/01/10 21:15:28 | 000,005,684 | -HS- | C] () -- C:\Users\Pat\AppData\Local\270g64m584464es2vt180fx
[2012/01/10 21:15:28 | 000,005,684 | -HS- | C] () -- C:\ProgramData\270g64m584464es2vt180fx
[2012/01/10 00:48:34 | 000,003,726 | -HS- | C] () -- C:\ProgramData\21juy61aha1224gursi88rlkuu5mp68jeb6v60s3u11qst
[2012/01/10 00:48:33 | 000,003,726 | -HS- | C] () -- C:\Users\Pat\AppData\Local\21juy61aha1224gursi88rlkuu5mp68jeb6v60s3u11qst
[2012/01/04 18:31:50 | 000,001,436 | -HS- | C] () -- C:\Users\Pat\AppData\Local\fwy56et66vp5ilixbfij237357o4lri438t60pygsu2
[2012/01/03 12:43:47 | 000,013,122 | -HS- | C] () -- C:\Users\Pat\AppData\Local\683yv44bq84a35103446etiitt8s666uxy1tx21778a
[2012/01/03 12:43:47 | 000,013,122 | -HS- | C] () -- C:\ProgramData\683yv44bq84a35103446etiitt8s666uxy1tx21778a
[2011/12/26 15:20:39 | 000,002,428 | -HS- | C] () -- C:\Users\Pat\AppData\Local\qc33xffd0ua6634ib5532kj7jn1xl3h8
[2011/12/26 15:20:39 | 000,002,428 | -HS- | C] () -- C:\ProgramData\qc33xffd0ua6634ib5532kj7jn1xl3h8
[2011/12/21 20:08:57 | 000,001,458 | -HS- | C] () -- C:\Users\Pat\AppData\Local\173138t3d060c562n640q3bog0x4
[2011/12/20 23:17:05 | 000,006,010 | -HS- | C] () -- C:\Users\Pat\AppData\Local\7on2n11ogr7n42xgcdo0677of141lpw05x6b
[2011/12/20 23:17:05 | 000,006,010 | -HS- | C] () -- C:\ProgramData\7on2n11ogr7n42xgcdo0677of141lpw05x6b
[2011/12/16 10:43:23 | 000,011,428 | -HS- | C] () -- C:\Users\Pat\AppData\Local\o4go10t2ew7ikk
[2011/12/16 10:43:23 | 000,011,428 | -HS- | C] () -- C:\ProgramData\o4go10t2ew7ikk
[2011/12/14 23:03:40 | 000,012,062 | -HS- | C] () -- C:\Users\Pat\AppData\Local\213812u3u364p503o070g4clh2y7
[2011/12/14 23:03:40 | 000,012,062 | -HS- | C] () -- C:\ProgramData\213812u3u364p503o070g4clh2y7
[2011/12/14 20:56:32 | 000,001,582 | -HS- | C] () -- C:\Users\Pat\AppData\Local\wrtxqe4s5omf0cvp3ugj1w488u8g
[2011/12/11 20:20:42 | 000,009,344 | -HS- | C] () -- C:\Users\Pat\AppData\Local\2y30ou3s74e850
[2011/12/11 20:20:42 | 000,009,344 | -HS- | C] () -- C:\ProgramData\2y30ou3s74e850
[2011/12/10 22:23:41 | 000,009,764 | -HS- | C] () -- C:\Users\Pat\AppData\Local\781282f4y341m488x727r1iou1f7
[2011/12/10 22:23:41 | 000,009,764 | -HS- | C] () -- C:\ProgramData\781282f4y341m488x727r1iou1f7
[2011/12/10 14:39:51 | 000,011,314 | -HS- | C] () -- C:\Users\Pat\AppData\Local\cupibp5b3wqn8vij3aox8y410e1b
[2011/12/10 14:39:51 | 000,011,314 | -HS- | C] () -- C:\ProgramData\cupibp5b3wqn8vij3aox8y410e1b
@Alternate Data Stream - 190 bytes -> C:\ProgramData\TEMP:8E5EA40F
:Commands
[purity]
[emptytemp]
[emptyjava]
[emptyflash]
[Reboot]