O2 - BHO: Helper Class - {850C7964-9320-4055-BE11-7D7B562A6417} - C:\WINDOWS\system32\helper.dll (file missing)
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu27.exe 61A847B5BBF72810358B2B27128065E9C084320161C4661227 A755E9C2933154389A284661A64DB7C8F0287E55E246220D9E 728F80D6664366DB7D5475E744AB97
O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\kernels32.exe
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKLM\..\Run: [clsvxs] cligumim.exe
O4 - HKLM\..\Run: [uiprocs] C:\WINDOWS\system32\clifhysb.exe
O4 - HKLM\..\Run: [newrs32] C:\WINDOWS\system32\edconss.exe
O4 - HKLM\..\Run: [mwini32] C:\WINDOWS\system32\mmswr.exe
O4 - HKLM\..\Run: [msrlink] C:\WINDOWS\system32\rdsruns.exe
O4 - HKCU\..\Run: [Service Pack 1] C:\WINDOWS\system32\vexg6ame4.exe
O4 - HKCU\..\Run: [clsvxs] cligumim.exe
O4 - HKCU\..\Run: [uiprocs] C:\WINDOWS\system32\clifhysb.exe
O4 - HKCU\..\Run: [newrs32] C:\WINDOWS\system32\edconss.exe
O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\luk\LOCALS~1\Temp\winlogon.exe
O4 - HKCU\..\Run: [mwini32] C:\WINDOWS\system32\mmswr.exe
O4 - HKCU\..\Run: [msrlink] C:\WINDOWS\system32\rdsruns.exe
O20 - Winlogon Notify: A3dxq - C:\WINDOWS\system32\a3dx8.dll
O20 - Winlogon Notify: botreg - C:\Documents and Settings\All Users\Документы\Settings\bot.dll (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O20 - Winlogon Notify: psfus - C:\WINDOWS\SYSTEM32\psqlpwd.dll
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O21 - SSODL: CDRecorder036 - {A3BC5E20-0235-1ABF-9CE1-00AA00512036} - C:\WINDOWS\system32\cpdbl32.dll (file missing)
O21 - SSODL: DCOM Server 20509 - {2C1CD3D7-86AC-4068-93BC-A02304B20509} - C:\WINDOWS\system32\wpfcef.dll (file missing)