:processes
:OTL
IE - HKU\S-1-5-21-4011912087-3930819905-3012435978-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/web/{searchTerms}?babsrc=SP_ss&affID=100888&mntrId=8866d79f000000000000889ffa500489
[2011.10.27 12:48:30 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\DNS\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\ffxtlbr@babylon.com
O3 - HKLM\..\Toolbar: (Reg Error: Value error.) - Locked - Reg Error: Value error. File not found
O4 - HKLM..\Run: [] File not found
MsConfig:64bit - StartUpReg: [b]VKSaver[/b] - hkey= - key= - C:\ProgramData\VKSaver\VKSaver.exe (AudioVkontakte.ru)
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:5D7E5A8F
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:CDFF58FE
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:93EB7685
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:4D066AD2
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:E36F5B57
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:E1F04E8D
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:0B9176C0
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:798A3728
:Services
:Files
C:\ProgramData\VKSaver\
autorun.inf /alldrives
recycler /alldrives
netsh winsock reset catalog /c
netsh winsock reset /c
netsh int ipv4 reset reset.log /c
netsh int ipv6 reset reset.log /c
ipconfig /flushdns /c
ipconfig /release /c
ipconfig /renew /c
ipconfig /all /c
:Reg
:Commands
[EMPTYJAVA]
[EMPTYFLASH]
[EMPTYTEMP]
[RESETHOSTS]
[purity]
[start explorer]
[Reboot]