Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

MSN Virus again!


  • This topic is locked This topic is locked

#31
merchantz

merchantz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 28 posts
Here is the hijackthis log. i wasnt sure if you meant with the boxes ticked or unticked.

Unticked -

StartupList report, 20/12/2006, 23:45:04
StartupList version: 1.52.2
Started from : C:\Program Files\Hijackthis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

SpywareTerminator = "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
MSConfig = C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

SUPERAntiSpyware = C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\scrnsave.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Task Scheduler jobs:

AppleSoftwareUpdate.job
Symantec NetDetect.job

--------------------------------------------------

Enumerating Download Program Files:

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\legitcheckcontrol.dll
CODEBASE = http://go.microsoft....k/?linkid=39204

[MsnMessengerSetupDownloadControl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx
CODEBASE = http://messenger.msn...pdownloader.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\macromed\flash\Flash.ocx
CODEBASE = http://fpdownload.ma...ash/swflash.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #4: C:\WINDOWS\system32\wshbth.dll

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll

--------------------------------------------------
End of report, 3,795 bytes
Report generated in 0.141 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

Ticked - StartupList report, 20/12/2006, 23:45:56
StartupList version: 1.52.2
Started from : C:\Program Files\Hijackthis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Oliver Standing\Start Menu\Programs\Startup]
*No files*

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
*No files*

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

SpywareTerminator = "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
MSConfig = C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

SUPERAntiSpyware = C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
*No values found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

--------------------------------------------------

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\WINDOWS\system32\mshta.exe "%1" %*

--------------------------------------------------

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

--------------------------------------------------

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
StubPath = C:\WINDOWS\system32\ieudinit.exe

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

[>{26923b43-4d38-484f-9b9e-de460746276c}]
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

[{4b218e3e-bc98-4770-93d3-2731b9329278}] *
StubPath = %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf

[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe

[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install

--------------------------------------------------

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

--------------------------------------------------

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\scrnsave.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

--------------------------------------------------

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

--------------------------------------------------

Verifying REGEDIT.EXE integrity:

- Regedit.exe found in C:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'

Registry check passed

--------------------------------------------------

Enumerating Browser Helper Objects:

*No BHO's found*

--------------------------------------------------

Enumerating Task Scheduler jobs:

AppleSoftwareUpdate.job
Symantec NetDetect.job

--------------------------------------------------

Enumerating Download Program Files:

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\legitcheckcontrol.dll
CODEBASE = http://go.microsoft....k/?linkid=39204

[Java Plug-in]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
CODEBASE = http://java.sun.com/...indows-i586.cab

[MsnMessengerSetupDownloadControl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx
CODEBASE = http://messenger.msn...pdownloader.cab

[Java Plug-in]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
CODEBASE = http://java.sun.com/...indows-i586.cab

[Java Plug-in]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
CODEBASE = http://java.sun.com/...indows-i586.cab

[Java Plug-in]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
CODEBASE = http://java.sun.com/...indows-i586.cab

[Java Plug-in 1.5.0_06]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
CODEBASE = http://java.sun.com/...indows-i586.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\macromed\flash\Flash.ocx
CODEBASE = http://fpdownload.ma...ash/swflash.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #1: C:\WINDOWS\System32\mswsock.dll
NameSpace #2: C:\WINDOWS\System32\winrnr.dll
NameSpace #3: C:\WINDOWS\System32\mswsock.dll
NameSpace #4: C:\WINDOWS\system32\wshbth.dll
Protocol #1: C:\WINDOWS\system32\mswsock.dll
Protocol #2: C:\WINDOWS\system32\mswsock.dll
Protocol #3: C:\WINDOWS\system32\mswsock.dll
Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
Protocol #6: C:\WINDOWS\system32\mswsock.dll
Protocol #7: C:\WINDOWS\system32\mswsock.dll
Protocol #8: C:\WINDOWS\system32\mswsock.dll
Protocol #9: C:\WINDOWS\system32\mswsock.dll
Protocol #10: C:\WINDOWS\system32\mswsock.dll
Protocol #11: C:\WINDOWS\system32\mswsock.dll
Protocol #12: C:\WINDOWS\system32\mswsock.dll
Protocol #13: C:\WINDOWS\system32\mswsock.dll
Protocol #14: C:\WINDOWS\system32\mswsock.dll
Protocol #15: C:\WINDOWS\system32\mswsock.dll
Protocol #16: C:\WINDOWS\system32\mswsock.dll
Protocol #17: C:\WINDOWS\system32\mswsock.dll
Protocol #18: C:\WINDOWS\system32\mswsock.dll
Protocol #19: C:\WINDOWS\system32\mswsock.dll
Protocol #20: C:\WINDOWS\system32\mswsock.dll
Protocol #21: C:\WINDOWS\system32\mswsock.dll
Protocol #22: C:\WINDOWS\system32\mswsock.dll

--------------------------------------------------

Enumerating Windows NT/2000/XP services

61883 Unit Device: system32\DRIVERS\61883.sys (manual start)
Microsoft ACPI Driver: system32\DRIVERS\ACPI.sys (system)
Microsoft Embedded Controller Driver: system32\DRIVERS\ACPIEC.sys (system)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AEGIS Protocol (IEEE 802.1x) v3.2.0.3: system32\DRIVERS\AegisP.sys (autostart)
AFD: \SystemRoot\System32\drivers\afd.sys (system)
Alerter: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
Alps Pointing-device Filter Driver: system32\DRIVERS\Apfiltr.sys (manual start)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
1394 ARP Client Protocol: system32\DRIVERS\arp1394.sys (manual start)
ASP.NET State Service: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (manual start)
avast! iAVS4 Control Service: "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe" (autostart)
RAS Asynchronous Media Driver: system32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: system32\DRIVERS\atapi.sys (system)
ATM ARP Client Protocol: system32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: system32\DRIVERS\audstub.sys (manual start)
Automatic LiveUpdate Scheduler: "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" (autostart)
avast! Antivirus: "C:\Program Files\Alwil Software\Avast4\ashServ.exe" (autostart)
avast! Mail Scanner: "C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (manual start)
avast! Web Scanner: "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (manual start)
AVC Device: system32\DRIVERS\avc.sys (manual start)
Background Intelligent Transfer Service: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Bluetooth Audio Service: system32\DRIVERS\blueletaudio.sys (manual start)
Computer Browser: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Bluetooth PAN Network Adapter: system32\DRIVERS\btnetdrv.sys (manual start)
Bluetooth USB For Bluetooth Service: System32\Drivers\btcusb.sys (manual start)
Bluetooth Request Block Driver: system32\DRIVERS\BthEnum.sys (manual start)
Bluetooth HID Enumerator: system32\DRIVERS\vbtenum.sys (manual start)
Bluetooth HID Manager Service: System32\Drivers\BTHidMgr.sys (system)
Bluetooth Modem Communications Driver: system32\DRIVERS\bthmodem.sys (manual start)
Bluetooth Device (Personal Area Network): system32\DRIVERS\bthpan.sys (manual start)
Bluetooth Port Driver: System32\Drivers\BTHport.sys (manual start)
Bluetooth Support Service: %SystemRoot%\system32\svchost.exe -k bthsvcs (autostart)
Bluetooth Radio USB Driver: System32\Drivers\BTHUSB.sys (manual start)
Closed Caption Decoder: system32\DRIVERS\CCDECODE.sys (manual start)
CD-ROM Driver: system32\DRIVERS\cdrom.sys (system)
Indexing Service: %SystemRoot%\system32\cisvc.exe (manual start)
ClipBook: %SystemRoot%\system32\clipsrv.exe (disabled)
Microsoft ACPI Control Method Battery Driver: system32\DRIVERS\CmBatt.sys (manual start)
Microsoft Composite Battery Driver: system32\DRIVERS\compbatt.sys (system)
COM+ System Application: C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
d347bus: system32\DRIVERS\d347bus.sys (system)
d347prt: System32\Drivers\d347prt.sys (system)
DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
DHCP Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Disk Driver: system32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
Sony DMI Call service: system32\DRIVERS\DMICall.sys (system)
dmio: System32\drivers\dmio.sys (disabled)
dmload: System32\drivers\dmload.sys (disabled)
Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
Intel® PRO Network Connection Driver: system32\DRIVERS\e100b325.sys (manual start)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINDOWS\system32\svchost.exe -k netsvcs (manual start)
EvtEng: C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (autostart)
Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
FltMgr: system32\DRIVERS\fltMgr.sys (system)
Volume Manager Driver: system32\DRIVERS\ftdisk.sys (system)
GEAR CDRom Filter: SYSTEM32\DRIVERS\GEARAspiWDM.sys (manual start)
gmer: System32\DRIVERS\gmer.sys (manual start)
Generic Packet Classifier: system32\DRIVERS\msgpc.sys (manual start)
Microsoft UAA Bus Driver for High Definition Audio: system32\DRIVERS\HDAudBus.sys (manual start)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Microsoft Bluetooth HID Miniport: system32\DRIVERS\hidbth.sys (manual start)
!!!!: \??\C:\WINDOWS\hide_evr2.sys (manual start)
Human Interface Device Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Microsoft HID Class Driver: system32\DRIVERS\hidusb.sys (manual start)
HSFHWAZL: system32\DRIVERS\HSFHWAZL.sys (manual start)
HSF_DP: system32\DRIVERS\HSF_DP.sys (manual start)
HTTP: System32\Drivers\HTTP.sys (manual start)
HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
i8042 Keyboard and PS/2 Mouse Port Driver: system32\DRIVERS\i8042prt.sys (system)
ialm: system32\DRIVERS\ialmnt5.sys (manual start)
InstallDriver Table Manager: "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe" (manual start)
CD-Burning Filter Driver: system32\DRIVERS\imapi.sys (system)
IMAPI CD-Burning COM Service: C:\WINDOWS\system32\imapi.exe (manual start)
Service for Realtek HD Audio (WDM): system32\drivers\RtkHDAud.sys (manual start)
IntelIde: system32\DRIVERS\intelide.sys (system)
Intel Processor Driver: system32\DRIVERS\intelppm.sys (system)
IPv6 Windows Firewall Driver: system32\DRIVERS\Ip6Fw.sys (manual start)
IP Traffic Filter Driver: system32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: system32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: system32\DRIVERS\ipnat.sys (manual start)
iPod Service: "C:\Program Files\iPod\bin\iPodService.exe" (manual start)
IPSEC driver: system32\DRIVERS\ipsec.sys (system)
IR Enumerator Service: system32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: system32\DRIVERS\isapnp.sys (system)
Intel Wireless Connection Agent Miniport for Win XP: system32\DRIVERS\iwca.sys (manual start)
Keyboard Class Driver: system32\DRIVERS\kbdclass.sys (system)
Keyboard HID Driver: system32\DRIVERS\kbdhid.sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Server: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
LiveUpdate: "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE" (manual start)
TCP/IP NetBIOS Helper: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Machine Debug Manager: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" (autostart)
mdmxsdk: system32\DRIVERS\mdmxsdk.sys (autostart)
Messenger: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
NetMeeting Remote Desktop Sharing: C:\WINDOWS\system32\mnmsrvc.exe (manual start)
Mouse Class Driver: system32\DRIVERS\mouclass.sys (system)
Mouse HID Driver: system32\DRIVERS\mouhid.sys (manual start)
WebDav Client Redirector: system32\DRIVERS\mrxdav.sys (manual start)
MRXSMB: system32\DRIVERS\mrxsmb.sys (system)
Microsoft authenticate service: C:\WINDOWS\system32\msasvc.exe (autostart)
Distributed Transaction Coordinator: C:\WINDOWS\system32\msdtc.exe (manual start)
Microsoft DV Camera and VCR: system32\DRIVERS\msdv.sys (manual start)
Windows Installer: C:\WINDOWS\system32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Microsoft System Management BIOS Driver: system32\DRIVERS\mssmbios.sys (manual start)
Microsoft Streaming Tee/Sink-to-Sink Converter: system32\drivers\MSTEE.sys (manual start)
NABTS/FEC VBI Codec: system32\DRIVERS\NABTSFEC.sys (manual start)
Microsoft TV/Video Connection: system32\DRIVERS\NdisIP.sys (manual start)
Remote Access NDIS TAPI Driver: system32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: system32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: system32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: system32\DRIVERS\netbios.sys (system)
NetBios over Tcpip: system32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (disabled)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
Net Logon: %SystemRoot%\system32\lsass.exe (manual start)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
1394 Net Driver: system32\DRIVERS\nic1394.sys (manual start)
Network Location Awareness (NLA): %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
NT LM Security Support Provider: %SystemRoot%\system32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
nv: system32\DRIVERS\nv4_mini.sys (manual start)
NVIDIA Display Driver Service: %SystemRoot%\system32\nvsvc32.exe (autostart)
IPX Traffic Filter Driver: system32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: system32\DRIVERS\nwlnkfwd.sys (manual start)
Texas Instruments OHCI Compliant IEEE 1394 Host Controller: system32\DRIVERS\ohci1394.sys (system)
Office Source Engine: "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" (manual start)
PCI Bus Driver: system32\DRIVERS\pci.sys (system)
PCIIde: system32\DRIVERS\pciide.sys (system)
Pcmcia: system32\DRIVERS\pcmcia.sys (system)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
IPSEC Services: %SystemRoot%\system32\lsass.exe (autostart)
WAN Miniport (PPTP): system32\DRIVERS\raspptp.sys (manual start)
PrivateDisk: System32\Drivers\PrivateDiskM.sys (system)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
QoS Packet Scheduler: system32\DRIVERS\psched.sys (manual start)
Direct Parallel Link Driver: system32\DRIVERS\ptilink.sys (manual start)
PxHelp20: System32\Drivers\PxHelp20.sys (system)
Remote Access Auto Connection Driver: system32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): system32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: system32\DRIVERS\raspppoe.sys (manual start)
Direct Parallel: system32\DRIVERS\raspti.sys (manual start)
Rdbss: system32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
Remote Desktop Help Session Manager: C:\WINDOWS\system32\sessmgr.exe (manual start)
Digital CD Audio Playback Filter Driver: system32\DRIVERS\redbook.sys (system)
RegSrvc: C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (autostart)
Routing and Remote Access: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
Bluetooth Device (RFCOMM Protocol TDI): system32\DRIVERS\rfcomm.sys (manual start)
Remote Procedure Call (RPC) Locator: %SystemRoot%\system32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\system32\rsvp.exe (manual start)
Spectrum24 Event Monitor: C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (autostart)
WLAN Transport: system32\DRIVERS\s24trans.sys (autostart)
SABProcEnum: \??\C:\Program Files\Mozilla Firefox\SABProcEnum.sys (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
SASDIFSV: \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (system)
SASENUM: \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS (manual start)
SASKUTIL: \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (system)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (manual start)
Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Secdrv: system32\DRIVERS\secdrv.sys (autostart)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Serenum Filter Driver: system32\DRIVERS\serenum.sys (manual start)
StarForce Protection Environment Driver (version 1.x): System32\drivers\sfdrv01.sys (system)
StarForce Protection Helper Driver (version 2.x): System32\drivers\sfhlp02.sys (system)
StarForce Protection Synchronization Driver (version 2.x): System32\drivers\sfsync02.sys (system)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
BDA Slip De-Framer: system32\DRIVERS\SLIP.sys (manual start)
Sony Notebook Control Device: System32\Drivers\SonyNC.sys (manual start)
Sony USB Filter Driver (SONYPVU1): system32\DRIVERS\SONYPVU1.SYS (manual start)
Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
Spyware Terminator Driver 2: \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys (manual start)
Spyware Terminator Realtime Shield Service: C:\PROGRA~1\SPYWAR~1\sp_rsser.exe (autostart)
System Restore Filter Driver: system32\DRIVERS\sr.sys (system)
System Restore Service: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Srv: system32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\system32\svchost.exe -k imgsvc (autostart)
Player Recovery Device Control Driver: System32\Drivers\StMp3Rec.sys (manual start)
BDA IPSink: system32\DRIVERS\StreamIP.sys (manual start)
Software Bus Driver: system32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
MS Software Shadow Copy Provider: C:\WINDOWS\system32\dllhost.exe /Processid:{262C97ED-B2C3-4537-921E-8A1E75E43903} (manual start)
SymWMI Service: "C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe" (autostart)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: system32\DRIVERS\tcpip.sys (system)
Terminal Device Driver: system32\DRIVERS\termdd.sys (system)
Terminal Services: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
tifmsony: system32\drivers\tifmsony.sys (manual start)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Windows User Mode Driver Framework: C:\WINDOWS\system32\wdfmgr.exe (autostart)
Microcode Update Driver: system32\DRIVERS\update.sys (manual start)
Universal Plug and Play Device Host: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
USB Audio Driver (WDM): system32\drivers\usbaudio.sys (manual start)
Microsoft USB Generic Parent Driver: system32\DRIVERS\usbccgp.sys (manual start)
Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: system32\DRIVERS\usbehci.sys (manual start)
Microsoft USB Standard Hub Driver: system32\DRIVERS\usbhub.sys (manual start)
USB Scanner Driver: system32\DRIVERS\usbscan.sys (manual start)
USB Mass Storage Driver: system32\DRIVERS\USBSTOR.SYS (manual start)
Microsoft USB Universal Host Controller Miniport Driver: system32\DRIVERS\usbuhci.sys (manual start)
VAIO Entertainment Aggregation and Control Service: "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe" (manual start)
VAIO Entertainment Task Scheduler: "C:\Program Files\Sony\VAIO Entertainment\VzTaskScheduler.exe" (manual start)
VAIO Entertainment TV Device Arbitration Service: "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe" (manual start)
VAIO Event Service: C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (autostart)
VAIO Media Integrated Server: C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (manual start)
VAIO Media Integrated Server (HTTP): "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP" (manual start)
VAIO Media Integrated Server (UPnP): C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (manual start)
VAIO Cooporated Initialisation: C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe (autostart)
Virtual Serial port driver: system32\DRIVERS\VComm.sys (manual start)
Bluetooth VComm Manager Service: System32\Drivers\VcommMgr.sys (manual start)
VAIO Entertainment UPnP Client Adapter: C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe -RunBySCM (manual start)
VgaSave: \SystemRoot\System32\drivers\vga.sys (system)
Volume Shadow Copy: %SystemRoot%\System32\vssvc.exe (manual start)
VAIO Entertainment Database Service: "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe" (autostart)
VAIO Entertainment File Import Service: C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (autostart)
Intel® PRO/Wireless 2200BG Network Connection Driver for Windows XP: system32\DRIVERS\w29n51.sys (manual start)
Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Remote Access IP ARP Driver: system32\DRIVERS\wanarp.sys (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
WebClient: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
winachsf: system32\DRIVERS\HSF_CNXT.sys (manual start)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WMI Performance Adapter: C:\WINDOWS\system32\wbem\wmiapsrv.exe (manual start)
Windows Socket 2.0 Non-IFS Service Provider Support Environment: \SystemRoot\System32\drivers\ws2ifsl.sys (disabled)
Security Center: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
World Standard Teletext Codec: system32\DRIVERS\WSTCODEC.SYS (manual start)
Automatic Updates: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Network Provisioning Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)


--------------------------------------------------

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: *Registry value not found*

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll

--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*No values found*

--------------------------------------------------

End of report, 37,340 bytes
Report generated in 0.109 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

Reqquery Log -


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
AutoRestartShell REG_DWORD 0x1
DefaultDomainName REG_SZ OLLILAPTOP
DefaultUserName REG_SZ Oliver Standing
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ReportBootOk REG_SZ 1
Shell REG_SZ Explorer.exe
ShutdownWithoutLogon REG_SZ 0
System REG_SZ
Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
SfcQuota REG_DWORD 0xffffffff
allocatecdroms REG_SZ 0
allocatedasd REG_SZ 0
allocatefloppies REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0x0
passwordexpirywarning REG_DWORD 0xe
scremoveoption REG_SZ 0
AllowMultipleTSSessions REG_DWORD 0x1
UIHost REG_EXPAND_SZ logonui.exe
LogonType REG_DWORD 0x1
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
SFCDisable REG_DWORD 0x0
WinStationsDisabled REG_SZ 0
HibernationPreviouslyEnabled REG_DWORD 0x1
ShowLogonOptions REG_DWORD 0x0
AltDefaultUserName REG_SZ Oliver Standing
AltDefaultDomainName REG_SZ OLLILAPTOP

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
<NO NAME> REG_SZ Microsoft Disk Quota
NoMachinePolicy REG_DWORD 0x0
NoUserPolicy REG_DWORD 0x1
NoSlowLink REG_DWORD 0x1
NoBackgroundPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1
PerUserLocalSettings REG_DWORD 0x0
RequiresSuccessfulRegistry REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x0
DllName REG_EXPAND_SZ dskquota.dll
ProcessGroupPolicy REG_SZ ProcessGroupPolicy

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}
<NO NAME> REG_SZ Internet Explorer Zonemapping
DllName REG_EXPAND_SZ iedkcs32.dll
ProcessGroupPolicy REG_SZ ProcessGroupPolicyForZoneMap
NoGPOListChanges REG_DWORD 0x1
RequiresSucessfulRegistry REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
ProcessGroupPolicy REG_SZ SceProcessSecurityPolicyGPO
GenerateGroupPolicy REG_SZ SceGenerateGroupPolicy
ExtensionRsopPlanningDebugLevel REG_DWORD 0x1
ProcessGroupPolicyEx REG_SZ SceProcessSecurityPolicyGPOEx
ExtensionDebugLevel REG_DWORD 0x1
DllName REG_EXPAND_SZ scecli.dll
<NO NAME> REG_SZ Security
NoUserPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1
MaxNoGPOListChangesInterval REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx
GenerateGroupPolicy REG_SZ GenerateGroupPolicy
ProcessGroupPolicy REG_SZ ProcessGroupPolicy
DllName REG_EXPAND_SZ iedkcs32.dll
<NO NAME> REG_SZ Internet Explorer Branding
NoSlowLink REG_DWORD 0x1
NoBackgroundPolicy REG_DWORD 0x0
NoGPOListChanges REG_DWORD 0x1
NoMachinePolicy REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}
ProcessGroupPolicy REG_SZ SceProcessEFSRecoveryGPO
DllName REG_EXPAND_SZ scecli.dll
<NO NAME> REG_SZ EFS recovery
NoUserPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1
RequiresSuccessfulRegistry REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}
<NO NAME> REG_SZ Microsoft Offline Files
DllName REG_EXPAND_SZ %SystemRoot%\System32\cscui.dll
EnableAsynchronousProcessing REG_DWORD 0x0
NoBackgroundPolicy REG_DWORD 0x0
NoGPOListChanges REG_DWORD 0x0
NoMachinePolicy REG_DWORD 0x0
NoSlowLink REG_DWORD 0x0
NoUserPolicy REG_DWORD 0x1
PerUserLocalSettings REG_DWORD 0x0
ProcessGroupPolicy REG_SZ ProcessGroupPolicy
RequiresSuccessfulRegistry REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}
<NO NAME> REG_SZ Software Installation
DllName REG_EXPAND_SZ appmgmts.dll
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyObjectsEx
GenerateGroupPolicy REG_SZ GenerateGroupPolicy
NoBackgroundPolicy REG_DWORD 0x0
RequiresSucessfulRegistry REG_DWORD 0x0
NoSlowLink REG_DWORD 0x1
PerUserLocalSettings REG_DWORD 0x1
EventSources REG_MULTI_SZ (Application Management,Application)\0(MsiInstaller,Application)\0\0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon
DllName REG_SZ C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
Logon REG_SZ SABWINLOLogon
Logoff REG_SZ SABWINLOLogoff
Startup REG_SZ SABWINLOStartup
Shutdown REG_SZ SABWINLOShutdown
Asynchronous REG_DWORD 0x0
Impersonate REG_DWORD 0x0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
Asynchronous REG_DWORD 0x0
Impersonate REG_DWORD 0x0
DllName REG_EXPAND_SZ crypt32.dll
Logoff REG_SZ ChainWlxLogoffEvent

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
Asynchronous REG_DWORD 0x0
Impersonate REG_DWORD 0x0
DllName REG_EXPAND_SZ cryptnet.dll
Logoff REG_SZ CryptnetWlxLogoffEvent

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
DLLName REG_SZ cscdll.dll
Logon REG_SZ WinlogonLogonEvent
Logoff REG_SZ WinlogonLogoffEvent
ScreenSaver REG_SZ WinlogonScreenSaverEvent
Startup REG_SZ WinlogonStartupEvent
Shutdown REG_SZ WinlogonShutdownEvent
StartShell REG_SZ WinlogonStartShellEvent
Impersonate REG_DWORD 0x0
Asynchronous REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui
<NO NAME> REG_SZ
DLLName REG_SZ igfxsrvc.dll
Asynchronous REG_DWORD 0x1
Impersonate REG_DWORD 0x1
Unlock REG_SZ WinlogonUnlockEvent

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\IntelWireless
Impersonate REG_DWORD 0x0
Asynchronous REG_DWORD 0x0
Dllname REG_SZ C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
Logon REG_SZ IntelUserLogon
Logoff REG_SZ IntelUserLogoff

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
DLLName REG_SZ wlnotify.dll
Logon REG_SZ SCardStartCertProp
Logoff REG_SZ SCardStopCertProp
Lock REG_SZ SCardSuspendCertProp
Unlock REG_SZ SCardResumeCertProp
Enabled REG_DWORD 0x1
Impersonate REG_DWORD 0x1
Asynchronous REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
Asynchronous REG_DWORD 0x0
DllName REG_EXPAND_SZ wlnotify.dll
Impersonate REG_DWORD 0x0
StartShell REG_SZ SchedStartShell
Logoff REG_SZ SchedEventLogOff

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
Logoff REG_SZ WLEventLogoff
Impersonate REG_DWORD 0x0
Asynchronous REG_DWORD 0x1
DllName REG_EXPAND_SZ sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
DLLName REG_SZ WlNotify.dll
Lock REG_SZ SensLockEvent
Logon REG_SZ SensLogonEvent
Logoff REG_SZ SensLogoffEvent
Safe REG_DWORD 0x1
MaxWait REG_DWORD 0x258
StartScreenSaver REG_SZ SensStartScreenSaverEvent
StopScreenSaver REG_SZ SensStopScreenSaverEvent
Startup REG_SZ SensStartupEvent
Shutdown REG_SZ SensShutdownEvent
StartShell REG_SZ SensStartShellEvent
PostShell REG_SZ SensPostShellEvent
Disconnect REG_SZ SensDisconnectEvent
Reconnect REG_SZ SensReconnectEvent
Unlock REG_SZ SensUnlockEvent
Impersonate REG_DWORD 0x1
Asynchronous REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
Asynchronous REG_DWORD 0x0
DllName REG_EXPAND_SZ wlnotify.dll
Impersonate REG_DWORD 0x0
Logoff REG_SZ TSEventLogoff
Logon REG_SZ TSEventLogon
PostShell REG_SZ TSEventPostShell
Shutdown REG_SZ TSEventShutdown
StartShell REG_SZ TSEventStartShell
Startup REG_SZ TSEventStartup
MaxWait REG_DWORD 0x258
Reconnect REG_SZ TSEventReconnect
Disconnect REG_SZ TSEventDisconnect

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\VESWinlogon
Asynchronous REG_DWORD 0x1
Impersonate REG_DWORD 0x0
Startup REG_SZ EventStartup
DllName REG_EXPAND_SZ VESWinlogon.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon
Logon REG_SZ WLEventLogon
Logoff REG_SZ WLEventLogoff
Startup REG_SZ WLEventStartup
Shutdown REG_SZ WLEventShutdown
StartScreenSaver REG_SZ WLEventStartScreenSaver
StopScreenSaver REG_SZ WLEventStopScreenSaver
Lock REG_SZ WLEventLock
Unlock REG_SZ WLEventUnlock
StartShell REG_SZ WLEventStartShell
PostShell REG_SZ WLEventPostShell
Disconnect REG_SZ WLEventDisconnect
Reconnect REG_SZ WLEventReconnect
Impersonate REG_DWORD 0x1
Asynchronous REG_DWORD 0x0
SafeMode REG_DWORD 0x1
MaxWait REG_DWORD 0xffffffff
DllName REG_EXPAND_SZ WgaLogon.dll
Event REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings
Data REG_BINARY 01000000D08C9DDF0115D1118C7A00C04FC297EB010000005F04023829F27542BB7A277863D6AE9104000000040000005300000003660000A800000010000000940B9499DE96D6B3A05770ADD783D08B0000000004800000A000000010000000137DD5158E8992A09BAD5F6182108E4B080600000D49DD281AEAFAA781313334716595184654A5103B57F9E1A8EEE725AA6B8E8B179C30BCDACA8F39180839E53603EE21A98959ABEB0F67B295CC813B675626613F6355511F7C619641EF947BFEDC09DA25DDA3577AB7FB5D055343134A048F780B2D6775A7AE8ACE702D0F5C982056503CA194B8F931683D561E61EA93EEF4E9F8CF9F966B07DADCA7A46212FEBB107A27D705BEA3AE60E6CEA798599D3B859F104495F24EA063E911E1AF4DE19E3EE9BA75FD4783CCD3D9AF80C936A64104F93A51F71FB5CF4C5366FA2ABAC0F99A070D27C73FE25959114571106D3A12100EBCC4ACE434AAB88FF72F96E830FEA7B7BB5DFD3A9F9CA69DE5D910533F3E3816C63047E772B325898E7D954AC379E2993CEC470D9FF0CFCDEFC07C8A35AAB56B0EC744E68375DDD4855E57A3C35235C3B7EC01E33EE80D12E3E3D7BD06BF29156F2E91F5F91F4B204D2BA0512EA153F536C7D218B6D57F6FFB5869C3E25B3A5465C485FA92D85BBE4208D3EB723E880BDEC02F6983CD40519595E0E8C8E3528F6D2207B149CC6EB647A6441912A7E6CC0FE3F1EBF9612C98C65C9279D4A07D0CE6CF1227900E2D8A6C60FA4CE42977AD242F4600DF32510127AA3F38F6D6EDBF377BB9DF2EF2A3D70E1FA0F7D305A56A59F210AA23E6B787F22C71456ACE0B495463129496478E6261C457D0AE5BF6E5A7429AF996E7965A6180D58E6D3E43A291DBC0D4B74B264AB8F0B1EB315B998B34FCDF182A90B009CF2FE72517A1A3F5BB834E0E94F70692AFADBD033572D80EC5207C026BFCA91E3E65455B66C71FF9ADAA002F1052F283E0F391133B6CA90FBB837E469A90DDC0B49D5AA597F6B09938C40EA235B8117C41AB8696F8E26AB1778486B345037A8B4ECBE8842FD0196A97940106A0587843EC80053AD77A2411FD04004D1BB40DA9794E23574CBF80079A7872D4516512AD5E4FEA50FFE16F43182FA0D8C7695C563F5E31D796604A284A967DBCE059AFF5B490B74A371BDED3C54E6566815404E2EDE4FCF9D3CF45089C1050BA2CBCCE80788DFDFB082683A4CB9299D74C449C0D853CC438C526514862A3C2A6D
  • 0

Advertisements


#32
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Hi, merchantz :whistling:

The Rootkit Trojan still in the system.

Please download the Killbox by Option^Explicit.

Note: In the event you already have Killbox, this is a new version that I need you to download.
  • Save it to your desktop.
Run Killbox.exe. Paste the following location into Killbox. Checkmark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click YES and it will reboot.

C:\WINDOWS\hide_evr2.sys

If the computer does not restart by itself, manually restart he computer.

The regquery I need to see, is the one on Post 30. Download that one and overwrite the previous one.

Post the log of the new regquery fle and produce again a startup list with both boxes ticked.
  • 0

#33
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Hi, merchantz :whistling:

Try this also:
  • Please double-click Killbox.exe to run it.
  • Select:
    • Delete on Reboot
    • then Click on the All Files button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\cc.exe
    C:\WINDOWS\system32\qsetup.exe
    C:\WINDOWS\system32\mi.exe
    C:\WINDOWS\system32\tel.exe
    C:\WINDOWS\system32\install.exe
    C:\WINDOWS\system32\msasvc.exe
    C:\WINDOWS\hide_evr2.sys
    C:\Documents and Settings\Oliver Standing\qsetup.exe
    C:\Documents and Settings\Oliver Standing\tel.exe
    C:\Documents and Settings\Oliver Standing\cc.exe
    C:\Documents and Settings\Oliver Standing\jes.exe
    C:\Documents and Settings\Oliver Standing\mi.exe
    C:\Documents and Settings\Oliver Standing\ost.exe
    C:\Documents and Settings\Oliver Standing\telebos.exe


  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
  • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

Keep me posted.
  • 0

#34
merchantz

merchantz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 28 posts
hijack this startlog with both boxes ticked.

StartupList report, 21/12/2006, 18:35:47
StartupList version: 1.52.2
Started from : C:\Program Files\Hijackthis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Oliver Standing\Start Menu\Programs\Startup]
*No files*

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
*No files*

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

SpywareTerminator = "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
MSConfig = C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

SUPERAntiSpyware = C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
*No values found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

--------------------------------------------------

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\WINDOWS\system32\mshta.exe "%1" %*

--------------------------------------------------

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

--------------------------------------------------

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
StubPath = C:\WINDOWS\system32\ieudinit.exe

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

[>{26923b43-4d38-484f-9b9e-de460746276c}]
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

[{4b218e3e-bc98-4770-93d3-2731b9329278}] *
StubPath = %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf

[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe

[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install

--------------------------------------------------

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

--------------------------------------------------

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\scrnsave.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

--------------------------------------------------

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

--------------------------------------------------

Verifying REGEDIT.EXE integrity:

- Regedit.exe found in C:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'

Registry check passed

--------------------------------------------------

Enumerating Browser Helper Objects:

*No BHO's found*

--------------------------------------------------

Enumerating Task Scheduler jobs:

AppleSoftwareUpdate.job
Symantec NetDetect.job

--------------------------------------------------

Enumerating Download Program Files:

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\legitcheckcontrol.dll
CODEBASE = http://go.microsoft....k/?linkid=39204

[Java Plug-in]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
CODEBASE = http://java.sun.com/...indows-i586.cab

[MsnMessengerSetupDownloadControl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx
CODEBASE = http://messenger.msn...pdownloader.cab

[Java Plug-in]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
CODEBASE = http://java.sun.com/...indows-i586.cab

[Java Plug-in]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
CODEBASE = http://java.sun.com/...indows-i586.cab

[Java Plug-in]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
CODEBASE = http://java.sun.com/...indows-i586.cab

[Java Plug-in 1.5.0_06]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
CODEBASE = http://java.sun.com/...indows-i586.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\macromed\flash\Flash.ocx
CODEBASE = http://fpdownload.ma...ash/swflash.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #1: C:\WINDOWS\System32\mswsock.dll
NameSpace #2: C:\WINDOWS\System32\winrnr.dll
NameSpace #3: C:\WINDOWS\System32\mswsock.dll
NameSpace #4: C:\WINDOWS\system32\wshbth.dll
Protocol #1: C:\WINDOWS\system32\mswsock.dll
Protocol #2: C:\WINDOWS\system32\mswsock.dll
Protocol #3: C:\WINDOWS\system32\mswsock.dll
Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
Protocol #6: C:\WINDOWS\system32\mswsock.dll
Protocol #7: C:\WINDOWS\system32\mswsock.dll
Protocol #8: C:\WINDOWS\system32\mswsock.dll
Protocol #9: C:\WINDOWS\system32\mswsock.dll
Protocol #10: C:\WINDOWS\system32\mswsock.dll
Protocol #11: C:\WINDOWS\system32\mswsock.dll
Protocol #12: C:\WINDOWS\system32\mswsock.dll
Protocol #13: C:\WINDOWS\system32\mswsock.dll
Protocol #14: C:\WINDOWS\system32\mswsock.dll
Protocol #15: C:\WINDOWS\system32\mswsock.dll
Protocol #16: C:\WINDOWS\system32\mswsock.dll
Protocol #17: C:\WINDOWS\system32\mswsock.dll
Protocol #18: C:\WINDOWS\system32\mswsock.dll
Protocol #19: C:\WINDOWS\system32\mswsock.dll
Protocol #20: C:\WINDOWS\system32\mswsock.dll
Protocol #21: C:\WINDOWS\system32\mswsock.dll
Protocol #22: C:\WINDOWS\system32\mswsock.dll

--------------------------------------------------

Enumerating Windows NT/2000/XP services

61883 Unit Device: system32\DRIVERS\61883.sys (manual start)
Microsoft ACPI Driver: system32\DRIVERS\ACPI.sys (system)
Microsoft Embedded Controller Driver: system32\DRIVERS\ACPIEC.sys (system)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AEGIS Protocol (IEEE 802.1x) v3.2.0.3: system32\DRIVERS\AegisP.sys (autostart)
AFD: \SystemRoot\System32\drivers\afd.sys (system)
Alerter: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
Alps Pointing-device Filter Driver: system32\DRIVERS\Apfiltr.sys (manual start)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
1394 ARP Client Protocol: system32\DRIVERS\arp1394.sys (manual start)
ASP.NET State Service: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (manual start)
avast! iAVS4 Control Service: "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe" (autostart)
RAS Asynchronous Media Driver: system32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: system32\DRIVERS\atapi.sys (system)
ATM ARP Client Protocol: system32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: system32\DRIVERS\audstub.sys (manual start)
Automatic LiveUpdate Scheduler: "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" (autostart)
avast! Antivirus: "C:\Program Files\Alwil Software\Avast4\ashServ.exe" (autostart)
avast! Mail Scanner: "C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (manual start)
avast! Web Scanner: "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (manual start)
AVC Device: system32\DRIVERS\avc.sys (manual start)
Background Intelligent Transfer Service: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Bluetooth Audio Service: system32\DRIVERS\blueletaudio.sys (manual start)
Computer Browser: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Bluetooth PAN Network Adapter: system32\DRIVERS\btnetdrv.sys (manual start)
Bluetooth USB For Bluetooth Service: System32\Drivers\btcusb.sys (manual start)
Bluetooth Request Block Driver: system32\DRIVERS\BthEnum.sys (manual start)
Bluetooth HID Enumerator: system32\DRIVERS\vbtenum.sys (manual start)
Bluetooth HID Manager Service: System32\Drivers\BTHidMgr.sys (system)
Bluetooth Modem Communications Driver: system32\DRIVERS\bthmodem.sys (manual start)
Bluetooth Device (Personal Area Network): system32\DRIVERS\bthpan.sys (manual start)
Bluetooth Port Driver: System32\Drivers\BTHport.sys (manual start)
Bluetooth Support Service: %SystemRoot%\system32\svchost.exe -k bthsvcs (autostart)
Bluetooth Radio USB Driver: System32\Drivers\BTHUSB.sys (manual start)
Closed Caption Decoder: system32\DRIVERS\CCDECODE.sys (manual start)
CD-ROM Driver: system32\DRIVERS\cdrom.sys (system)
Indexing Service: %SystemRoot%\system32\cisvc.exe (manual start)
ClipBook: %SystemRoot%\system32\clipsrv.exe (disabled)
Microsoft ACPI Control Method Battery Driver: system32\DRIVERS\CmBatt.sys (manual start)
Microsoft Composite Battery Driver: system32\DRIVERS\compbatt.sys (system)
COM+ System Application: C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
d347bus: system32\DRIVERS\d347bus.sys (system)
d347prt: System32\Drivers\d347prt.sys (system)
DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
DHCP Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Disk Driver: system32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
Sony DMI Call service: system32\DRIVERS\DMICall.sys (system)
dmio: System32\drivers\dmio.sys (disabled)
dmload: System32\drivers\dmload.sys (disabled)
Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
Intel® PRO Network Connection Driver: system32\DRIVERS\e100b325.sys (manual start)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINDOWS\system32\svchost.exe -k netsvcs (manual start)
EvtEng: C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (autostart)
Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
FltMgr: system32\DRIVERS\fltMgr.sys (system)
Volume Manager Driver: system32\DRIVERS\ftdisk.sys (system)
GEAR CDRom Filter: SYSTEM32\DRIVERS\GEARAspiWDM.sys (manual start)
gmer: System32\DRIVERS\gmer.sys (manual start)
Generic Packet Classifier: system32\DRIVERS\msgpc.sys (manual start)
Microsoft UAA Bus Driver for High Definition Audio: system32\DRIVERS\HDAudBus.sys (manual start)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Microsoft Bluetooth HID Miniport: system32\DRIVERS\hidbth.sys (manual start)
!!!!: \??\C:\WINDOWS\hide_evr2.sys (manual start)
Human Interface Device Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Microsoft HID Class Driver: system32\DRIVERS\hidusb.sys (manual start)
HSFHWAZL: system32\DRIVERS\HSFHWAZL.sys (manual start)
HSF_DP: system32\DRIVERS\HSF_DP.sys (manual start)
HTTP: System32\Drivers\HTTP.sys (manual start)
HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
i8042 Keyboard and PS/2 Mouse Port Driver: system32\DRIVERS\i8042prt.sys (system)
ialm: system32\DRIVERS\ialmnt5.sys (manual start)
InstallDriver Table Manager: "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe" (manual start)
CD-Burning Filter Driver: system32\DRIVERS\imapi.sys (system)
IMAPI CD-Burning COM Service: C:\WINDOWS\system32\imapi.exe (manual start)
Service for Realtek HD Audio (WDM): system32\drivers\RtkHDAud.sys (manual start)
IntelIde: system32\DRIVERS\intelide.sys (system)
Intel Processor Driver: system32\DRIVERS\intelppm.sys (system)
IPv6 Windows Firewall Driver: system32\DRIVERS\Ip6Fw.sys (manual start)
IP Traffic Filter Driver: system32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: system32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: system32\DRIVERS\ipnat.sys (manual start)
iPod Service: "C:\Program Files\iPod\bin\iPodService.exe" (manual start)
IPSEC driver: system32\DRIVERS\ipsec.sys (system)
IR Enumerator Service: system32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: system32\DRIVERS\isapnp.sys (system)
Intel Wireless Connection Agent Miniport for Win XP: system32\DRIVERS\iwca.sys (manual start)
Keyboard Class Driver: system32\DRIVERS\kbdclass.sys (system)
Keyboard HID Driver: system32\DRIVERS\kbdhid.sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Server: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
LiveUpdate: "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE" (manual start)
TCP/IP NetBIOS Helper: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Machine Debug Manager: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" (autostart)
mdmxsdk: system32\DRIVERS\mdmxsdk.sys (autostart)
Messenger: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
NetMeeting Remote Desktop Sharing: C:\WINDOWS\system32\mnmsrvc.exe (manual start)
Mouse Class Driver: system32\DRIVERS\mouclass.sys (system)
Mouse HID Driver: system32\DRIVERS\mouhid.sys (manual start)
WebDav Client Redirector: system32\DRIVERS\mrxdav.sys (manual start)
MRXSMB: system32\DRIVERS\mrxsmb.sys (system)
Microsoft authenticate service: C:\WINDOWS\system32\msasvc.exe (autostart)
Distributed Transaction Coordinator: C:\WINDOWS\system32\msdtc.exe (manual start)
Microsoft DV Camera and VCR: system32\DRIVERS\msdv.sys (manual start)
Windows Installer: C:\WINDOWS\system32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Microsoft System Management BIOS Driver: system32\DRIVERS\mssmbios.sys (manual start)
Microsoft Streaming Tee/Sink-to-Sink Converter: system32\drivers\MSTEE.sys (manual start)
NABTS/FEC VBI Codec: system32\DRIVERS\NABTSFEC.sys (manual start)
Microsoft TV/Video Connection: system32\DRIVERS\NdisIP.sys (manual start)
Remote Access NDIS TAPI Driver: system32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: system32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: system32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: system32\DRIVERS\netbios.sys (system)
NetBios over Tcpip: system32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (disabled)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
Net Logon: %SystemRoot%\system32\lsass.exe (manual start)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
1394 Net Driver: system32\DRIVERS\nic1394.sys (manual start)
Network Location Awareness (NLA): %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
NT LM Security Support Provider: %SystemRoot%\system32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
nv: system32\DRIVERS\nv4_mini.sys (manual start)
NVIDIA Display Driver Service: %SystemRoot%\system32\nvsvc32.exe (autostart)
IPX Traffic Filter Driver: system32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: system32\DRIVERS\nwlnkfwd.sys (manual start)
Texas Instruments OHCI Compliant IEEE 1394 Host Controller: system32\DRIVERS\ohci1394.sys (system)
Office Source Engine: "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" (manual start)
PCI Bus Driver: system32\DRIVERS\pci.sys (system)
PCIIde: system32\DRIVERS\pciide.sys (system)
Pcmcia: system32\DRIVERS\pcmcia.sys (system)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
IPSEC Services: %SystemRoot%\system32\lsass.exe (autostart)
WAN Miniport (PPTP): system32\DRIVERS\raspptp.sys (manual start)
PrivateDisk: System32\Drivers\PrivateDiskM.sys (system)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
QoS Packet Scheduler: system32\DRIVERS\psched.sys (manual start)
Direct Parallel Link Driver: system32\DRIVERS\ptilink.sys (manual start)
PxHelp20: System32\Drivers\PxHelp20.sys (system)
Remote Access Auto Connection Driver: system32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): system32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: system32\DRIVERS\raspppoe.sys (manual start)
Direct Parallel: system32\DRIVERS\raspti.sys (manual start)
Rdbss: system32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
Remote Desktop Help Session Manager: C:\WINDOWS\system32\sessmgr.exe (manual start)
Digital CD Audio Playback Filter Driver: system32\DRIVERS\redbook.sys (system)
RegSrvc: C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (autostart)
Routing and Remote Access: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
Bluetooth Device (RFCOMM Protocol TDI): system32\DRIVERS\rfcomm.sys (manual start)
Remote Procedure Call (RPC) Locator: %SystemRoot%\system32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\system32\rsvp.exe (manual start)
Spectrum24 Event Monitor: C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (autostart)
WLAN Transport: system32\DRIVERS\s24trans.sys (autostart)
SABProcEnum: \??\C:\Program Files\Mozilla Firefox\SABProcEnum.sys (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
SASDIFSV: \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (system)
SASENUM: \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS (manual start)
SASKUTIL: \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (system)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (manual start)
Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Secdrv: system32\DRIVERS\secdrv.sys (autostart)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Serenum Filter Driver: system32\DRIVERS\serenum.sys (manual start)
StarForce Protection Environment Driver (version 1.x): System32\drivers\sfdrv01.sys (system)
StarForce Protection Helper Driver (version 2.x): System32\drivers\sfhlp02.sys (system)
StarForce Protection Synchronization Driver (version 2.x): System32\drivers\sfsync02.sys (system)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
BDA Slip De-Framer: system32\DRIVERS\SLIP.sys (manual start)
Sony Notebook Control Device: System32\Drivers\SonyNC.sys (manual start)
Sony USB Filter Driver (SONYPVU1): system32\DRIVERS\SONYPVU1.SYS (manual start)
Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
Spyware Terminator Driver 2: \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys (manual start)
Spyware Terminator Realtime Shield Service: C:\PROGRA~1\SPYWAR~1\sp_rsser.exe (autostart)
System Restore Filter Driver: system32\DRIVERS\sr.sys (system)
System Restore Service: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Srv: system32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\system32\svchost.exe -k imgsvc (autostart)
Player Recovery Device Control Driver: System32\Drivers\StMp3Rec.sys (manual start)
BDA IPSink: system32\DRIVERS\StreamIP.sys (manual start)
Software Bus Driver: system32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
MS Software Shadow Copy Provider: C:\WINDOWS\system32\dllhost.exe /Processid:{262C97ED-B2C3-4537-921E-8A1E75E43903} (manual start)
SymWMI Service: "C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe" (autostart)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: system32\DRIVERS\tcpip.sys (system)
Terminal Device Driver: system32\DRIVERS\termdd.sys (system)
Terminal Services: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
tifmsony: system32\drivers\tifmsony.sys (manual start)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Windows User Mode Driver Framework: C:\WINDOWS\system32\wdfmgr.exe (autostart)
Microcode Update Driver: system32\DRIVERS\update.sys (manual start)
Universal Plug and Play Device Host: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
USB Audio Driver (WDM): system32\drivers\usbaudio.sys (manual start)
Microsoft USB Generic Parent Driver: system32\DRIVERS\usbccgp.sys (manual start)
Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: system32\DRIVERS\usbehci.sys (manual start)
Microsoft USB Standard Hub Driver: system32\DRIVERS\usbhub.sys (manual start)
USB Scanner Driver: system32\DRIVERS\usbscan.sys (manual start)
USB Mass Storage Driver: system32\DRIVERS\USBSTOR.SYS (manual start)
Microsoft USB Universal Host Controller Miniport Driver: system32\DRIVERS\usbuhci.sys (manual start)
VAIO Entertainment Aggregation and Control Service: "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe" (manual start)
VAIO Entertainment Task Scheduler: "C:\Program Files\Sony\VAIO Entertainment\VzTaskScheduler.exe" (manual start)
VAIO Entertainment TV Device Arbitration Service: "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe" (manual start)
VAIO Event Service: C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (autostart)
VAIO Media Integrated Server: C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (manual start)
VAIO Media Integrated Server (HTTP): "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP" (manual start)
VAIO Media Integrated Server (UPnP): C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (manual start)
VAIO Cooporated Initialisation: C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe (autostart)
Virtual Serial port driver: system32\DRIVERS\VComm.sys (manual start)
Bluetooth VComm Manager Service: System32\Drivers\VcommMgr.sys (manual start)
VAIO Entertainment UPnP Client Adapter: C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe -RunBySCM (manual start)
VgaSave: \SystemRoot\System32\drivers\vga.sys (system)
Volume Shadow Copy: %SystemRoot%\System32\vssvc.exe (manual start)
VAIO Entertainment Database Service: "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe" (autostart)
VAIO Entertainment File Import Service: C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (autostart)
Intel® PRO/Wireless 2200BG Network Connection Driver for Windows XP: system32\DRIVERS\w29n51.sys (manual start)
Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Remote Access IP ARP Driver: system32\DRIVERS\wanarp.sys (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
WebClient: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
winachsf: system32\DRIVERS\HSF_CNXT.sys (manual start)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WMI Performance Adapter: C:\WINDOWS\system32\wbem\wmiapsrv.exe (manual start)
Windows Socket 2.0 Non-IFS Service Provider Support Environment: \SystemRoot\System32\drivers\ws2ifsl.sys (disabled)
Security Center: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
World Standard Teletext Codec: system32\DRIVERS\WSTCODEC.SYS (manual start)
Automatic Updates: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Network Provisioning Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)


--------------------------------------------------

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: *Registry value not found*

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll

--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*No values found*

--------------------------------------------------

End of report, 37,340 bytes
Report generated in 0.203 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

regkey


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\.NET CLR Data

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\.NET CLR Data\Performance
Open REG_SZ OpenPerformanceData
Collect REG_SZ CollectPerformanceData
Close REG_SZ ClosePerformanceData
Library REG_SZ netfxperf.dll
Counter Types REG_BINARY 3600350035003300360000003600350035003300360000003600350035003300360000003600350035003300360000003600350035003300360000003600350035003300360000000000
Counter Names REG_BINARY 530071006C0043006C00690065006E0074003A002000430075007200720065006E00740020002300200070006F006F006C0065006400200061006E00640020006E006F006E0070006F006F006C0065006400200063006F006E006E0065006300740069006F006E0073000000530071006C0043006C00690065006E0074003A002000430075007200720065006E00740020002300200070006F006F006C0065006400200063006F006E006E0065006300740069006F006E0073000000530071006C0043006C00690065006E0074003A002000430075007200720065006E00740020002300200063006F006E006E0065006300740069006F006E00200070006F006F006C0073000000530071006C0043006C00690065006E0074003A0020005000650061006B0020002300200070006F006F006C0065006400200063006F006E006E0065006300740069006F006E0073000000530071006C0043006C00690065006E0074003A00200054006F00740061006C002000230020006600610069006C0065006400200063006F006E006E0065006300740073000000530071006C0043006C00690065006E0074003A00200054006F00740061006C002000230020006600610069006C0065006400200063006F006D006D0061006E006400730000000000
Last Counter REG_DWORD 0xac2
Last Help REG_DWORD 0xac3
First Counter REG_DWORD 0xab6
First Help REG_DWORD 0xab7
Object List REG_SZ 2742
WbemAdapFileSignature REG_BINARY 31FB4B337DD09BDF99429D7DBB5FDD48
WbemAdapFileTime REG_BINARY 006D1A330CD9C201
WbemAdapFileSize REG_DWORD 0x8000
WbemAdapStatus REG_DWORD 0xffffffff

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\.NET CLR Networking

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\.NET CLR Networking\Performance
Open REG_SZ OpenPerformanceData
Collect REG_SZ CollectPerformanceData
Close REG_SZ ClosePerformanceData
Library REG_SZ netfxperf.dll
Counter Types REG_BINARY 3600350035003300360000003600350037003900320000003600350037003900320000003600350035003300360000003600350035003300360000000000
Counter Names REG_BINARY 43006F006E006E0065006300740069006F006E0073002000450073007400610062006C00690073006800650064000000420079007400650073002000520065006300650069007600650064000000420079007400650073002000530065006E007400000044006100740061006700720061006D007300200052006500630065006900760065006400000044006100740061006700720061006D0073002000530065006E00740000000000
Last Counter REG_DWORD 0xace
Last Help REG_DWORD 0xacf
First Counter REG_DWORD 0xac4
First Help REG_DWORD 0xac5
Object List REG_SZ 2756 2756 2756 2756 2756 2756 2756 2756 2756 2756 2756 2756 2756 2756 2756 2756 2756 2756 2756 2756 2756
WbemAdapFileSignature REG_BINARY 31FB4B337DD09BDF99429D7DBB5FDD48
WbemAdapFileTime REG_BINARY 006D1A330CD9C201
WbemAdapFileSize REG_DWORD 0x8000
WbemAdapStatus REG_DWORD 0xffffffff

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\.NETFramework

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\.NETFramework\Performance
Close REG_SZ CloseCtrs
Collect REG_SZ CollectCtrs
Open REG_SZ OpenCtrs
Library REG_SZ mscoree.dll
Last Counter REG_DWORD 0xb7e
Last Help REG_DWORD 0xb7f
First Counter REG_DWORD 0xad0
First Help REG_DWORD 0xad1
WbemAdapFileSignature REG_BINARY 8C54138D0271ED4E9C16D8534FF707E4
WbemAdapFileTime REG_BINARY 008D40C2F969C401
WbemAdapFileSize REG_DWORD 0x26000
WbemAdapStatus REG_DWORD 0x0

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\61883
Type REG_DWORD 0x1
Start REG_DWORD 0x3
ErrorControl REG_DWORD 0x1
ImagePath REG_EXPAND_SZ system32\DRIVERS\61883.sys
DisplayName REG_SZ 61883 Unit Device

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\61883\Security
Security REG_BINARY 01001480900000009C000000140000003000000002001C000100000002801400FF010F00010100000000000100000000020060000400000000001400FD01020001010000000000051200000000001800FF010F0001020000000000052000000020020000000014008D01020001010000000000050B00000000001800FD01020001020000000000052000000023020000010100000000000512000000010100000000000512000000

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\Aavmker4
DisplayName REG_SZ avast! Asynchronous Virus Monitor
ErrorControl REG_DWORD 0x1
Type REG_DWORD 0x1
Start REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\Aavmker4\Enum
0 REG_SZ Root\LEGACY_AAVMKER4\0000
Count REG_DWORD 0x1
NextInstance REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\Abiosdsk
ErrorControl REG_DWORD 0x0
Group REG_SZ Primary disk
Start REG_DWORD 0x4
Tag REG_DWORD 0x3
Type REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\abp480n5
ErrorControl REG_DWORD 0x1
Group REG_SZ SCSI miniport
Start REG_DWORD 0x4
Tag REG_DWORD 0x38
Type REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\abp480n5\Parameters

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\abp480n5\Parameters\PnpInterface
5 REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\ACPI
ErrorControl REG_DWORD 0x1
Group REG_SZ Boot Bus Extender
Start REG_DWORD 0x0
Tag REG_DWORD 0x1
Type REG_DWORD 0x1
DisplayName REG_SZ Microsoft ACPI Driver
ImagePath REG_EXPAND_SZ system32\DRIVERS\ACPI.sys

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\ACPI\Parameters
AMLIMaxCTObjs REG_BINARY 0D000000

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\ACPI\Parameters\WakeUp
FixedEventMask REG_BINARY 2001
FixedEventStatus REG_BINARY 0004
GenericEventMask REG_BINARY 00000020
GenericEventStatus REG_BINARY 00007ECE

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\ACPI\Enum
0 REG_SZ ACPI_HAL\PNP0C08\0
Count REG_DWORD 0x1
NextInstance REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\ACPIEC
ErrorControl REG_DWORD 0x1
Group REG_SZ System Bus Extender
Start REG_DWORD 0x0
Tag REG_DWORD 0x6
Type REG_DWORD 0x1
DisplayName REG_SZ Microsoft Embedded Controller Driver
ImagePath REG_EXPAND_SZ system32\DRIVERS\ACPIEC.sys

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\ACPIEC\Enum
0 REG_SZ ACPI\PNP0C09\4&121dce69&0
Count REG_DWORD 0x1
NextInstance REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\adpu160m
ErrorControl REG_DWORD 0x1
Group REG_SZ SCSI miniport
Start REG_DWORD 0x4
Tag REG_DWORD 0x3c
Type REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\adpu160m\Parameters

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\adpu160m\Parameters\PnpInterface
5 REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\aec
Type REG_DWORD 0x1
Start REG_DWORD 0x3
ErrorControl REG_DWORD 0x1
ImagePath REG_EXPAND_SZ system32\drivers\aec.sys
DisplayName REG_SZ Microsoft Kernel Acoustic Echo Canceller

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\aec\Security
Security REG_BINARY 01001480900000009C000000140000003000000002001C000100000002801400FF010F00010100000000000100000000020060000400000000001400FD01020001010000000000051200000000001800FF010F0001020000000000052000000020020000000014008D01020001010000000000050B00000000001800FD01020001020000000000052000000023020000010100000000000512000000010100000000000512000000

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\AegisP
Type REG_DWORD 0x1
Start REG_DWORD 0x2
ErrorControl REG_DWORD 0x1
Tag REG_DWORD 0xb
ImagePath REG_EXPAND_SZ system32\DRIVERS\AegisP.sys
DisplayName REG_SZ AEGIS Protocol (IEEE 802.1x) v3.2.0.3
Group REG_SZ PNP_TDI
Description REG_SZ AEGIS Protocol (IEEE 802.1x) v3.2.0.3

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\AegisP\Linkage
Bind REG_MULTI_SZ \Device\{1AACB47D-D92F-4A68-BB60-634ECE16AD7D}\0\Device\s24trans_{1AACB47D-D92F-4A68-BB60-634ECE16AD7D}\0\0
Route REG_MULTI_SZ "{1AACB47D-D92F-4A68-BB60-634ECE16AD7D}"\0"s24trans" "{1AACB47D-D92F-4A68-BB60-634ECE16AD7D}"\0\0
Export REG_MULTI_SZ \Device\AegisP_{1AACB47D-D92F-4A68-BB60-634ECE16AD7D}\0\Device\AegisP_s24trans_{1AACB47D-D92F-4A68-BB60-634ECE16AD7D}\0\0

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\AegisP\Security
Security REG_BINARY 01001480900000009C000000140000003000000002001C000100000002801400FF010F00010100000000000100000000020060000400000000001400FD01020001010000000000051200000000001800FF010F0001020000000000052000000020020000000014008D01020001010000000000050B00000000001800FD01020001020000000000052000000023020000010100000000000512000000010100000000000512000000

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\AegisP\Enum
0 REG_SZ Root\LEGACY_AEGISP\0000
Count REG_DWORD 0x1
NextInstance REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\AFD
DisplayName REG_SZ AFD
Description REG_SZ AFD Networking Support Environment
Group REG_SZ TDI
ImagePath REG_SZ \SystemRoot\System32\drivers\afd.sys
Start REG_DWORD 0x1
Type REG_DWORD 0x1
ErrorControl REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\AFD\Parameters

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\AFD\Security
Security REG_BINARY 01001480900000009C000000140000003000000002001C000100000002801400FF010F00010100000000000100000000020060000400000000001400FD01020001010000000000051200000000001800FF010F0001020000000000052000000020020000000014008D01020001010000000000050B00000000001800FD01020001020000000000052000000023020000010100000000000512000000010100000000000512000000

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\AFD\Enum
0 REG_SZ Root\LEGACY_AFD\0000
Count REG_DWORD 0x1
NextInstance REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\Aha154x
ErrorControl REG_DWORD 0x1
Group REG_SZ SCSI miniport
Start REG_DWORD 0x4
Tag REG_DWORD 0x6
Type REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\Aha154x\Parameters
LegacyAdapterDetection REG_DWORD 0x0

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\Aha154x\Parameters\PnpInterface
1 REG_DWORD 0x1
3 REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\aic78u2
ErrorControl REG_DWORD 0x1
Group REG_SZ SCSI miniport
Start REG_DWORD 0x4
Tag REG_DWORD 0x34
Type REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\aic78u2\Parameters

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\aic78u2\Parameters\PnpInterface
5 REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\aic78xx
ErrorControl REG_DWORD 0x1
Group REG_SZ SCSI miniport
Start REG_DWORD 0x4
Tag REG_DWORD 0x1e
Type REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\aic78xx\Parameters

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\aic78xx\Parameters\PnpInterface
5 REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\Alerter
Type REG_DWORD 0x20
Start REG_DWORD 0x2
ErrorControl REG_DWORD 0x1
ImagePath REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k LocalService
DisplayName REG_SZ Alerter
DependOnService REG_MULTI_SZ LanmanWorkstation\0\0
DependOnGroup REG_MULTI_SZ \0
ObjectName REG_SZ NT AUTHORITY\LocalService
Description REG_SZ Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start.

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\Alerter\Parameters
AlertNames REG_MULTI_SZ \0
ServiceDll REG_EXPAND_SZ %SystemRoot%\system32\alrsvc.dll

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\Alerter\Security
Security REG_BINARY 01001480900000009C000000140000003000000002001C000100000002801400FF010F00010100000000000100000000020060000400000000001400FD01020001010000000000051200000000001800FF010F0001020000000000052000000020020000000014008D01020001010000000000050B00000000001800FD01020001020000000000052000000023020000010100000000000512000000010100000000000512000000

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\Alerter\Enum
0 REG_SZ Root\LEGACY_ALERTER\0000
Count REG_DWORD 0x1
NextInstance REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\ALG
Description REG_SZ Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Windows Firewall.
Type REG_DWORD 0x10
Start REG_DWORD 0x3
ErrorControl REG_DWORD 0x1
ImagePath REG_EXPAND_SZ %SystemRoot%\System32\alg.exe
DisplayName REG_SZ Application Layer Gateway Service
ObjectName REG_SZ NT AUTHORITY\LocalService

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\ALG\Security
Security REG_BINARY 01001480900000009C000000140000003000000002001C000100000002801400FF010F00010100000000000100000000020060000400000000001400FD01020001010000000000051200000000001800FF010F0001020000000000052000000020020000000014008D01020001010000000000050B00000000001800FD01020001020000000000052000000023020000010100000000000512000000010100000000000512000000

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\ALG\Enum
0 REG_SZ Root\LEGACY_ALG\0000
Count REG_DWORD 0x1
NextInstance REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\AliIde
ErrorControl REG_DWORD 0x1
Group REG_SZ System Bus Extender
Start REG_DWORD 0x4
Tag REG_DWORD 0x4
Type REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\amsint
ErrorControl REG_DWORD 0x1
Group REG_SZ SCSI miniport
Start REG_DWORD 0x4
Tag REG_DWORD 0x24
Type REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\amsint\Parameters

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\amsint\Parameters\PnpInterface
5 REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\ApfiltrService
Type REG_DWORD 0x1
Start REG_DWORD 0x3
ErrorControl REG_DWORD 0x0
Tag REG_DWORD 0x4
ImagePath REG_EXPAND_SZ system32\DRIVERS\Apfiltr.sys
DisplayName REG_SZ Alps Pointing-device Filter Driver
Group REG_SZ Pointer Port

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\ApfiltrService\Security
Security REG_BINARY 01001480900000009C000000140000003000000002001C000100000002801400FF010F00010100000000000100000000020060000400000000001400FD01020001010000000000051200000000001800FF010F0001020000000000052000000020020000000014008D01020001010000000000050B00000000001800FD01020001020000000000052000000023020000010100000000000512000000010100000000000512000000

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\ApfiltrService\Enum
0 REG_SZ ACPI\SNY9001\4&121dce69&0
Count REG_DWORD 0x1
NextInstance REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\currentControlSet\Services\AppMgmt
Description REG_SZ Provides software installation services such as Assign, Publish, and Remove.
DisplayName REG_SZ Application Management
ErrorControl REG_DWORD 0x1
ImagePath REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
Obj
  • 0

#35
merchantz

merchantz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 28 posts
it starts in normal mode! However it rebooted to the blue warning screen after around 10 mins.
  • 0

#36
merchantz

merchantz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 28 posts
The message you referred to did appear - ' PendingFileRenameOperations prompt'. For both the single file delete and the multiple file one. I was not able to paste the multiple filepaths and see them though?

And windows opened with the 'system configuration utility' box open too.
  • 0

#37
merchantz

merchantz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 28 posts
Right, it has not rebooted this time (fingers crossed). I did a scan with spyware terminator and it zapped one trojan. Here is the report.


Spyware Terminator Version: 1.7.0.899
Start time: 21/12/2006 18:59:41
System: Windows XP
User: Admin

Processes Scan
C:\WINDOWS\SYSTEM32\WINLOGON.EXE [Microsoft Corporation] C:\PROGRAM FILES\SUPERANTISPYWARE\SASWINLO.DLL [SUPERAntiSpyware.com], C:\WINDOWS\SYSTEM32\VESWINLOGON.DLL [Sony Corporation], C:\PROGRAM FILES\INTEL\WIRELESS\BIN\LGNOTIFY.DLL [Intel Corporation],
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\EVTENG.EXE [Intel Corporation] PSREGAPI.DLL [Intel Corporation], TRACEAPI.DLL [Intel Corporation],
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\S24EVMON.EXE [Intel Corporation ] TRACEAPI.DLL, PSREGAPI.DLL,
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE [Microsoft Corporation] C:\WINDOWS\SYSTEM32\ADOBEPDF.DLL [Adobe Systems Incorporated.], C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\DISTILLR\ADISTRES.DLL [Adobe Systems Incorporated.],
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE [Empty] C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWCMNS.DLL [ALWIL Software], C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWCMNOS.DLL [ALWIL Software], C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWCMNB.DLL [ALWIL Software],
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\ALUSCHEDULERSVC.EXE [Symantec Corporation]
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE [Empty] C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWAUX.DLL [ALWIL Software], ASWCMNB.DLL, ASWCMNOS.DLL, C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWENGIN.DLL [ALWIL Software], C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWSCAN.DLL [ALWIL Software], ASWCMNS.DLL, C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHBASE.DLL [ALWIL Software], C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHTASK.DLL [ALWIL Software], C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWINTEG.DLL [ALWIL Software], C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWIDLE.DLL [ALWIL Software], C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\AAVM4H.DLL [ALWIL Software], C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ENGLISH\BASE.DLL [ALWIL Software], UNACEV2.DLL [Empty], C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\AHRESMAI.DLL [ALWIL Software], C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\AHRESMES.DLL [ALWIL Software], C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\AHRESNS.DLL [ALWIL Software], C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\AHRESOUT.DLL [ALWIL Software], C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\AHRESP2P.DLL [ALWIL Software], C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\AHRESSTD.DLL [ALWIL Software], C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\AHRESWS.DLL [ALWIL Software], C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSSQLT.DLL [ALWIL Software],
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\REGSRVC.EXE [Intel Corporation]
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\ZCFGSVC.EXE [Intel Corporation] PFMGRAPI.DLL [Intel Corporation], TRACEAPI.DLL, PSREGAPI.DLL, MUROCAPI.DLL [Intel Corporation], S24MUDLL.DLL [Intel Corporation], C1XSTNGS.DLL [Intel Corporation], C:\PROGRAM FILES\INTEL\WIRELESS\BIN\LIBEAY32.DLL [Empty], LSAWRAPI.DLL [Intel Corporation], C:\PROGRAM FILES\INTEL\WIRELESS\BIN\D8021XPS.DLL [Empty],
C:\WINDOWS\EXPLORER.EXE [Microsoft Corporation] C:\PROGRAM FILES\ITUNES\ITUNESMINIPLAYER.DLL [Apple Computer, Inc.], C:\PROGRAM FILES\ITUNES\ITUNESMINIPLAYER.RESOURCES\EN.LPROJ\ITUNESMINIPLAYERLOCALIZED.DLL [Apple Computer, Inc.], C:\PROGRAM FILES\ITUNES\ITUNESMINIPLAYER.RESOURCES\ITUNESMINIPLAYER.DLL [Apple Computer, Inc.],
C:\Program Files\Intel\Wireless\Bin\1XConfig.exe [Intel] C:\Program Files\Intel\Wireless\Bin\IntelAE5.dll [Meetinghouse Data Communications], TraceAPI.dll, PsRegApi.dll, D8021XPS.DLL,
C:\PROGRAM FILES\SONY\VAIO EVENT SERVICE\VESMGR.EXE [Sony Corporation] VESSUEVENT.DLL [Sony Corporation], C:\PROGRAM FILES\SONY\VAIO EVENT SERVICE\VESBASEPS.DLL [Empty], SNYUTILS.DLL [Sony Corporation], SXBIOS.DLL [Sony Corporation], VESWNDMSG.DLL [Sony Corporation], VESTRANSFORM.DLL [Sony Corporation], VESWNDMSGHOOK.DLL [Sony Corporation], VESPOWERMGR.DLL [Sony Corporation], VESSEMIPNP.DLL [Sony Corporation], VESSUPERFORM.DLL [Sony Corporation], VESVIDEO.DLL [Sony Corporation], VESPERFORM.DLL [Sony Corporation], VESHKWNDCOMMON.DLL [Sony Corporation], C:\WINDOWS\SYSTEM32\IGFXEXPS.DLL [Intel Corporation],
C:\WINDOWS\SYSTEM32\IGFXEXT.EXE [Intel Corporation] HCCUTILS.DLL [Intel Corporation], IGFXSRVC.DLL [Intel Corporation], IGFXDEV.DLL [Intel Corporation], IGFXEXPS.DLL,
C:\PROGRAM FILES\COMMON FILES\SONY SHARED\VAIO ENTERTAINMENT PLATFORM\VCSW\VCSW.EXE [Sony Corporation] SONYUPPC.DLL [Sony Corporation], UPNPCTRL.DLL [Sony Corporation], VCSWEXEPS.DLL [Sony Corporation],
C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE [SUPERAntiSpyware.com] C:\PROGRAM FILES\SUPERANTISPYWARE\DEUPX.DLL [SuperAntiSpyware.com], C:\PROGRAM FILES\SUPERANTISPYWARE\SASSEH.DLL [SuperAdBlocker.com],
C:\PROGRAM FILES\COMMON FILES\SONY SHARED\VAIO ENTERTAINMENT PLATFORM\VZCDB\VZCDBSVC.EXE [Sony Corporation] VZCDBVCDS.DLL [Sony Corporation], VZCDBSSDB.DLL [Sony Corporation], VZCDBLOCALDB.DLL [Sony Corporation], VCSWEXEPS.DLL, VZCDBSVCPS.DLL [Sony Corporation], METALLIC.DLL [Sony Corporation],
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SECURITY CENTER\SYMWSC.EXE [Symantec Corporation] WSCHLPR.DLL [Symantec Corporation], PCCLN-FW.DLL [Symantec Corporation], SSCWMIAV.DLL [Symantec Corporation], SSCWMIFW.DLL [Symantec Corporation], MCAFEEAV.DLL [Symantec Corporation], MCAFEEFW.DLL [Symantec Corporation], ETRST-AV.DLL [Symantec Corporation], ETRST-FW.DLL [Symantec Corporation], PCCLN-AV.DLL [Symantec Corporation], ZONE-FW.DLL [Symantec Corporation], SSCIWP.DLL [Symantec Corporation], SSCNIS56.DLL [Symantec Corporation], SSCNIS7.DLL [Symantec Corporation], SSCNAV.DLL [Symantec Corporation], SSC-ICF.DLL [Symantec Corporation], SSC-WU.DLL [Symantec Corporation],
C:\PROGRAM FILES\COMMON FILES\SONY SHARED\VAIO ENTERTAINMENT PLATFORM\VZCDB\VZFW.EXE [Sony Corporation] VZFWIMPORT.DLL [Sony Corporation], VZCDB.DLL [Sony Corporation], VZCDBSVCPS.DLL, VZCS.DLL [Sony Corporation],
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE [ALWIL Software] ASHUINT.DLL [ALWIL Software], ASHBASE.DLL, ASWCMNOS.DLL, ASWCMNB.DLL, ASWCMNS.DLL, C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\XT1922.DLL [Codejock Software], AAVM4H.DLL, ASHTASK.DLL, ASWAUX.DLL, AHRESMAI.DLL, BASE.DLL, ASWENGIN.DLL, ASWSCAN.DLL, LANG.DLL [ALWIL Software], LANGMAI.DLL [ALWIL Software],
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE [ALWIL Software] ASHBASE.DLL, ASWCMNOS.DLL, ASWCMNB.DLL, ASWCMNS.DLL, AAVM4H.DLL, ASHTASK.DLL, ASWAUX.DLL, BASE.DLL, ASHWSFTR.DLL [ALWIL Software], ASWSCAN.DLL, AhResWS.dll, ASWENGIN.DLL,
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SECURITY CENTER\SYMSCUI.EXE [Symantec Corporation] SYMSCWB.DLL [Symantec Corporation], WSCHLPR.DLL,
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE [Mozilla Corporation] C:\PROGRAM FILES\MOZILLA FIREFOX\JS3250.DLL [Netscape Communications Corporation], C:\PROGRAM FILES\MOZILLA FIREFOX\NSPR4.DLL [Netscape Communications Corporation], C:\PROGRAM FILES\MOZILLA FIREFOX\XPCOM_CORE.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\PLC4.DLL [Netscape Communications Corporation], C:\PROGRAM FILES\MOZILLA FIREFOX\PLDS4.DLL [Netscape Communications Corporation], C:\PROGRAM FILES\MOZILLA FIREFOX\SMIME3.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\NSS3.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\SOFTOKN3.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\SSL3.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\XPCOM_COMPAT.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS\MYSPELL.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS\JAR50.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\[email protected]\COMPONENTS\QFASERVICES.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\[email protected]\COMPONENTS\FULLSOFT.DLL [Full Circle Software, Inc.], C:\DOCUMENTS [Empty], C:\PROGRAM FILES\MOZILLA FIREFOX\XPCOM.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\FREEBL3.DLL [Mozilla Foundation], C:\Program Files\Mozilla Firefox\nssckbi.dll [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS\SPELLCHK.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS\NPSWF32.DLL [Empty],
C:\Program Files\Spyware Terminator\SPYWARETERMINATOR.EXE [Crawler.com]
C:\Program Files\Spyware Terminator\SPYWARETERMINATORSHIELD.EXE [Crawler.com]
C:\Program Files\Spyware Terminator\sp_rsser.exe [Crawler.com]

Startup Scan

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"SUPERAntiSpyware" = "C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE" [ SUPERAntiSpyware.com ]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"SpywareTerminator" = "C:\Program Files\Spyware Terminator\SPYWARETERMINATORSHIELD.EXE" [ Crawler.com ]
"MSConfig" = "C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\MSCONFIG.EXE" [ Microsoft Corporation ]
"NvCplDaemon" = "C:\WINDOWS\SYSTEM32\NVCPL.DLL" [ NVIDIA Corporation ]

Toolbars Scan
DiskView {6A882320-BDD0-4ff4-BE3A-D8BAF82668E9} C:\Program Files\Vyooh\DiskView\VizBar.dll [file not found]
Yahoo! Toolbar {EF99BD32-C1FB-11D2-892F-0090271D4F88} C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL [Yahoo! Inc.]

Explorer Bars Scan
Shell Search Band {21569614-B795-46B1-85F4-E737A8DC09AD} C:\WINDOWS\SYSTEM32\BROWSEUI.DLL [Microsoft Corporation]

BHO Scan
Shell Search Band {21569614-B795-46B1-85F4-E737A8DC09AD} C:\WINDOWS\SYSTEM32\BROWSEUI.DLL [Microsoft Corporation]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [file not found]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} [file not found]
{e2e2dd38-d088-4134-82b7-f2ba38496583} [file not found]
{FB5F1910-F110-11d2-BB9E-00C04F795683} [file not found]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
{42071714-76d4-11d1-8b24-00a0c9068ff3} = Display Panning CPL Extension (deskpan.dll) [file not found]
{764BF0E1-F219-11ce-972D-00AA00A14F56} = Shell extensions for file compression () [file not found]
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} = Encryption Context Menu () [file not found]
{88895560-9AA2-1069-930E-00AA0030EBC8} = HyperTerminal Icon Ext (C:\WINDOWS\system32\hticons.dll) [file not found]
{A70C977A-BF00-412C-90B7-034C51DA2439} = NvCpl DesktopContext Class (C:\WINDOWS\SYSTEM32\NVCPL.DLL) [NVIDIA Corporation]
{FFB699E0-306A-11d3-8BD1-00104B6F7516} = Play on my TV helper (C:\WINDOWS\SYSTEM32\NVCPL.DLL) [NVIDIA Corporation]
{0DF44EAA-FF21-4412-828E-260A8728E7F1} = Taskbar and Start Menu () [file not found]
{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} = Autoplay for SlideShow (C:\WINDOWS\SYSTEM32\SHIMGVW.DLL) [Microsoft Corporation]
{7A9D77BD-5403-11d2-8785-2E0420524153} = User Accounts () [file not found]
{640167b4-59b0-47a6-b335-a6b3c0695aea} = Portable Media Devices (C:\WINDOWS\SYSTEM32\AUDIODEV.DLL) [Microsoft Corporation]
{cc86590a-b60a-48e6-996b-41d25ed39a1e} = Portable Media Devices Menu (C:\WINDOWS\SYSTEM32\AUDIODEV.DLL) [Microsoft Corporation]
{ED58A35B-B554-42AF-A26C-6F3D424200D3} = Sony Power Management Extensiond (C:\PROGRAM FILES\SONY\VAIO POWER MANAGEMENT\SPMPANEL.DLL) [Sony Corporation]
{F6A51CCC-6AA6-46ad-B726-97466F0A38BF} = SafeGuard® PrivateDisk extension (C:\PROGRAM FILES\UTIMACO\SAFEGUARD PRIVATEDISK\PDSHELL.DLL) [Utimaco Safeware AG]
{DEE12703-6333-4D4E-8F34-738C4DCC2E04} = RecordNow! SendToExt (C:\PROGRAM FILES\SONIC\RECORDNOW!\SHLEXT.DLL) [Empty]
{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} = Adobe.Acrobat.ContextMenu (C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\ACROBAT ELEMENTS\CONTEXTMENU.DLL) [Adobe Systems Inc.]
{e57ce731-33e8-4c51-8354-bb4de9d215d1} = Universal Plug and Play Devices () [file not found]
{32020A01-506E-484D-A2A8-BE3CF17601C3} = AlcoholShellEx () [file not found]
{00020D75-0000-0000-C000-000000000046} = Microsoft Office Outlook Desktop Icon Handler (C:\Program Files\Microsoft Office\OFFICE11\MLSHEXT.DLL) [Microsoft Corporation]
{0006F045-0000-0000-C000-000000000046} = Microsoft Office Outlook Custom Icon Handler (C:\Program Files\Microsoft Office\OFFICE11\OLKFSTUB.DLL) [Microsoft Corporation]
{42042206-2D85-11D3-8CFF-005004838597} = Microsoft Office HTML Icon Handler (C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL) [Microsoft Corporation]
{8FF88D21-7BD0-11D1-BFB7-00AA00262A11} = WinAce Archiver 2.6 Context Menu Shell Extension (C:\PROGRAM FILES\WINACE\ARCEXT.DLL) [e-merge GmbH]
{8FF88D25-7BD0-11D1-BFB7-00AA00262A11} = WinAce Archiver 2.6 DragDrop Shell Extension (C:\PROGRAM FILES\WINACE\ARCEXT.DLL) [e-merge GmbH]
{8FF88D27-7BD0-11D1-BFB7-00AA00262A11} = WinAce Archiver 2.6 Context Menu Shell Extension (C:\PROGRAM FILES\WINACE\ARCEXT.DLL) [e-merge GmbH]
{8FF88D23-7BD0-11D1-BFB7-00AA00262A11} = WinAce Archiver 2.6 Property Sheet Shell Extension (C:\PROGRAM FILES\WINACE\ARCEXT.DLL) [e-merge GmbH]
{21569614-B795-46b1-85F4-E737A8DC09AD} = Shell Search Band (C:\WINDOWS\SYSTEM32\BROWSEUI.DLL) [Microsoft Corporation]
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} = Shell Extensions for RealOne Player (C:\PROGRAM FILES\REAL\REALPLAYER\RPSHELL.DLL) [RealNetworks, Inc.]
{472083B0-C522-11CF-8763-00608CC02F24} = avast (C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSHELL.DLL) [ALWIL Software]
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} = iTunes (C:\PROGRAM FILES\ITUNES\ITUNESMINIPLAYER.DLL) [Apple Computer, Inc.]
{BD88A479-9623-4897-8546-BC62B9628F44} = SPTHandler (C:\PROGRAM FILES\SPYWARE TERMINATOR\SPTCONTMENU.DLL) [Crawler.com]

Winlogon Notify Scan
!SASWinLogon = C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (C:\PROGRAM FILES\SUPERANTISPYWARE\SASWINLO.DLL) [SUPERAntiSpyware.com]
igfxcui = igfxsrvc.dll (C:\WINDOWS\system32\IGFXSRVC.DLL) [Intel Corporation]
IntelWireless = C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (C:\PROGRAM FILES\INTEL\WIRELESS\BIN\LGNOTIFY.DLL) [Intel Corporation]
VESWinlogon = VESWinlogon.dll (C:\WINDOWS\system32\VESWINLOGON.DLL) [Sony Corporation]
WgaLogon = WgaLogon.dll (C:\WINDOWS\system32\WGALOGON.DLL) [Microsoft Corporation]

Services Scan
"AegisP" = C:\WINDOWS\SYSTEM32\DRIVERS\AEGISP.SYS [Meetinghouse Data Communications]
"ApfiltrService" = C:\WINDOWS\SYSTEM32\DRIVERS\APFILTR.SYS [Alps Electric Co., Ltd.]
"aswUpdSv" = C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE [Empty]
"Automatic LiveUpdate Scheduler" = C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\ALUSCHEDULERSVC.EXE [Symantec Corporation]
"avast! Antivirus" = C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE [Empty]
"avast! Mail Scanner" = C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE [ALWIL Software]
"avast! Web Scanner" = C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE [ALWIL Software]
"BlueletAudio" = system32\DRIVERS\blueletaudio.sys [file not found]
"BT" = system32\DRIVERS\btnetdrv.sys [file not found]
"Btcsrusb" = System32\Drivers\btcusb.sys [file not found]
"BTHidEnum" = system32\DRIVERS\vbtenum.sys [file not found]
"BTHidMgr" = System32\Drivers\BTHidMgr.sys [file not found]
"d347bus" = C:\WINDOWS\SYSTEM32\DRIVERS\D347BUS.SYS [Empty]
"d347prt" = C:\WINDOWS\SYSTEM32\DRIVERS\D347PRT.SYS [Empty]
"dmboot" = C:\WINDOWS\SYSTEM32\DRIVERS\DMBOOT.SYS [Microsoft Corp., Veritas Software]
"DMICall" = C:\WINDOWS\SYSTEM32\DRIVERS\DMICALL.SYS [Sony Corporation]
"dmio" = C:\WINDOWS\SYSTEM32\DRIVERS\DMIO.SYS [Microsoft Corp., Veritas Software]
"dmload" = C:\WINDOWS\SYSTEM32\DRIVERS\DMLOAD.SYS [Microsoft Corp., Veritas Software.]
"E100B" = C:\WINDOWS\SYSTEM32\DRIVERS\E100B325.SYS [Intel Corporation]
"EvtEng" = C:\PROGRAM FILES\INTEL\WIRELESS\BIN\EVTENG.EXE [Intel Corporation]
"FileObjInfo" = C:\DOCUMENTS [Empty]
"GEARAspiWDM" = C:\WINDOWS\SYSTEM32\DRIVERS\GEARASPIWDM.SYS [GEAR Software Inc.]
"gmer" = C:\WINDOWS\SYSTEM32\DRIVERS\GMER.SYS [GMER]
"HDAudBus" = C:\WINDOWS\SYSTEM32\DRIVERS\HDAUDBUS.SYS [Windows ® Server 2003 DDK provider]
"hide_evr2" = C:\WINDOWS\hide_evr2.sys [file not found]
"HSFHWAZL" = C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWAZL.SYS [Conexant Systems, Inc.]
"HSF_DP" = C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.SYS [Conexant Systems, Inc.]
"ialm" = C:\WINDOWS\SYSTEM32\DRIVERS\IALMNT5.SYS [Intel Corporation]
"IDriverT" = C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\DRIVER\11\INTEL 32\IDRIVERT.EXE [Macrovision Corporation]
"IntcAzAudAddService" = C:\WINDOWS\SYSTEM32\DRIVERS\RTKHDAUD.SYS [Realtek Semiconductor Corp.]
"iPod Service" = C:\PROGRAM FILES\IPOD\BIN\IPODSERVICE.EXE [Apple Computer, Inc.]
"IWCA" = C:\WINDOWS\SYSTEM32\DRIVERS\IWCA.SYS [Intel Corporation]
"LiveUpdate" = C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE [Symantec Corporation]
"mdmxsdk" = C:\WINDOWS\SYSTEM32\DRIVERS\MDMXSDK.SYS [Conexant]
"MsaSvc" = C:\WINDOWS\system32\msasvc.exe [file not found]
"nv" = C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS [NVIDIA Corporation]
"NVSvc" = C:\WINDOWS\SYSTEM32\NVSVC32.EXE [NVIDIA Corporation]
"PrivateDisk" = C:\WINDOWS\SYSTEM32\DRIVERS\PRIVATEDISKM.SYS [Utimaco Safeware AG]
"Ptilink" = C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS [Parallel Technologies, Inc.]
"PxHelp20" = C:\WINDOWS\SYSTEM32\DRIVERS\PXHELP20.SYS [Sonic Solutions]
"RegSrvc" = C:\PROGRAM FILES\INTEL\WIRELESS\BIN\REGSRVC.EXE [Intel Corporation]
"S24EventMonitor" = C:\PROGRAM FILES\INTEL\WIRELESS\BIN\S24EVMON.EXE [Intel Corporation ]
"s24trans" = C:\WINDOWS\SYSTEM32\DRIVERS\S24TRANS.SYS [Intel Corporation]
"SABProcEnum" = C:\Program Files\Mozilla Firefox\SABProcEnum.sys [file not found]
"SASDIFSV" = C:\PROGRAM FILES\SUPERANTISPYWARE\SASDIFSV.SYS [Empty]
"SASENUM" = C:\PROGRAM FILES\SUPERANTISPYWARE\SASENUM.SYS [SuperAdBlocker, Inc.]
"SASKUTIL" = C:\PROGRAM FILES\SUPERANTISPYWARE\SASKUTIL.SYS [Empty]
"Secdrv" = C:\WINDOWS\SYSTEM32\DRIVERS\SECDRV.SYS [Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.]
"sfdrv01" = C:\WINDOWS\SYSTEM32\DRIVERS\SFDRV01.SYS [Protection Technology]
"sfhlp02" = C:\WINDOWS\SYSTEM32\DRIVERS\SFHLP02.SYS [Protection Technology]
"sfsync02" = C:\WINDOWS\SYSTEM32\DRIVERS\SFSYNC02.SYS [Protection Technology]
"SNC" = C:\WINDOWS\SYSTEM32\DRIVERS\SONYNC.SYS [Sony Corporation]
"SONYPVU1" = C:\WINDOWS\SYSTEM32\DRIVERS\SONYPVU1.SYS [Sony Corporation]
"sp_rsdrv2" = C:\WINDOWS\SYSTEM32\DRIVERS\SP_RSDRV2.SYS [Empty]
"sp_rssrv" = C:\Program Files\Spyware Terminator\sp_rsser.exe [Crawler.com]
"StMp3Rec" = C:\WINDOWS\SYSTEM32\DRIVERS\STMP3REC.SYS [Generic]
"SymWSC" = C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SECURITY CENTER\SYMWSC.EXE [Symantec Corporation]
"tifmsony" = C:\WINDOWS\SYSTEM32\DRIVERS\TIFMSONY.SYS [Texas Instruments]
"VAIO Entertainment Aggregation and Control Service" = C:\PROGRAM FILES\COMMON FILES\SONY SHARED\VAIO ENTERTAINMENT\VZRS\VZRS.EXE [Sony Corporation]
"VAIO Entertainment Task Scheduler" = C:\PROGRAM FILES\SONY\VAIO ENTERTAINMENT\VZTASKSCHEDULER.EXE [Sony Corporation]
"VAIO Entertainment TV Device Arbitration Service" = C:\PROGRAM FILES\COMMON FILES\SONY SHARED\VAIO ENTERTAINMENT PLATFORM\VZCS\VZHARDWARERESOURCEMANAGER\VZHARDWARERESOURCEMANAGER.EXE [Sony Corporation]
"VAIO Event Service" = C:\PROGRAM FILES\SONY\VAIO EVENT SERVICE\VESMGR.EXE [Sony Corporation]
"VAIOMediaPlatform-IntegratedServer-AppServer" = C:\PROGRAM FILES\SONY\VAIO MEDIA INTEGRATED SERVER\VMISRV.EXE [Sony Corporation]
"VAIOMediaPlatform-IntegratedServer-HTTP" = C:\PROGRAM FILES\SONY\VAIO MEDIA INTEGRATED SERVER\PLATFORM\SV_HTTPD.EXE [Sony Corporation]
"VAIOMediaPlatform-IntegratedServer-UPnP" = C:\PROGRAM FILES\SONY\VAIO MEDIA INTEGRATED SERVER\PLATFORM\UPNPFRAMEWORK.EXE [Sony Corporation]
"VAIOMediaPlatform-Mobile-Gateway" = C:\PROGRAM FILES\SONY\VAIO MEDIA INTEGRATED SERVER\PLATFORM\VMGATEWAY.EXE [Sony Corporation]
"VCI" = C:\PROGRAM FILES\SONY\VAIO COOPERATED INITIALISATION\VCI_SVC.EXE [Sony Corporation]
"VComm" = system32\DRIVERS\VComm.sys [file not found]
"VcommMgr" = System32\Drivers\VcommMgr.sys [file not found]
"Vcsw" = C:\PROGRAM FILES\COMMON FILES\SONY SHARED\VAIO ENTERTAINMENT PLATFORM\VCSW\VCSW.EXE [Sony Corporation]
"VzCdbSvc" = C:\PROGRAM FILES\COMMON FILES\SONY SHARED\VAIO ENTERTAINMENT PLATFORM\VZCDB\VZCDBSVC.EXE [Sony Corporation]
"VzFw" = C:\PROGRAM FILES\COMMON FILES\SONY SHARED\VAIO ENTERTAINMENT PLATFORM\VZCDB\VZFW.EXE [Sony Corporation]
"w29n51" = C:\WINDOWS\SYSTEM32\DRIVERS\W29N51.SYS [Intel® Corporation]
"winachsf" = C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.SYS [Conexant Systems, Inc.]

Protocol Filters Scan
Class Install Handler = {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} (C:\WINDOWS\SYSTEM32\URLMON.DLL) [Microsoft Corporation]
text/xml = {807553E5-5146-11D5-A672-00B0D022E945} (C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\OFFICE11\MSOXMLMF.DLL) [Microsoft Corporation]

Hosts Scan
LOCALHOST mapping = 1

IE Scan
IERESET.INF missing START_PAGE_URL="http://www.microsoft...r=6&ar=msnhome" or START_PAGE_URL="http://www.msn.com"
  • 0

#38
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Hi, merchantz :whistling:

It appears the Rootkit was deleted. Lets delete its entries in the registry:

Go to Start->Run, type CMD and click Ok. The MSDOS window will be displayed. At the prompt type the following and press Enter after each line:

SC Stop hide_evr2
SC Delete hide_evr2
SC Stop MsaSvc
SC Delete MsaSvc
Exit


Click here to download Dr.Web CureIt and save it to your desktop.
  • Doubleclick the drweb-cureit.exe file and allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found:
    Posted Image
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    Posted Image
  • This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
Please run the F-Secure Online Scanner

Note: This Scanner is for Internet Explorer Only!
  • Follow the Instruction Here for installation.
  • Accept the License Agreement.
  • Once the ActiveX installs,Click Full System Scan
  • Once the download completes,the scan will begin automatically.
  • The scan will take some time to finish,so please be patient.
  • When the scan completes, click the Automatic cleaning (recommended) button.
  • Click the Show Report button and Copy&Paste the entire report in your next reply
Please download the Sophos Anti-Rootkit Scanner and save it to your desktop.

You will need to enter your name, e-mail address and location in order to access the download page.
  • Once you have downloaded the file, double click the sarsfx icon
  • Review the licence agreement and click on the Accept button
  • The scanner will prompt you to extract the files to C:\SOPHTEMP - DO NOT change this location, simply click the Install button
  • Once the files have been extracted; using Windows Explorer, navigate to C:\SOPHTEMP and double click on the blue shield icon called sargui
  • Ensure that there are checkmarks next to Running processes, Windows registry and Local hard drives, then click Start scan
  • Allow the program to scan your computer - please be patient as it may take some time
  • Once the scan has completed a window will pop-up with the results of the scan - click OK to this
  • In the main window, you will see each of the entries found by the scan (if any)
    • If the scanner generated any warning messages, please click on each warning and copy and paste the text of it into this thread for me to review
    • Once you have posted any warning messages here, you can close the scanner and wait for me to get back to you
  • If you have not had any warnings, any entries which can be cleaned up by the scanner will have a box with a green checkmark in it next to the entry
  • To clean up these entries click on the Clean up checked items button
  • If you accidentally check a file NOT recommended for clean up, you will get a warning message and if necessary can re-select the entries you want to clean up
  • Once you have cleaned the selected files, you will be prompted to re-boot your computer - please do so
  • When you have re-booted, please post a fresh HijackThis log into this thread and tell me how your computer is running now
Post the contents of the log from Dr.Web CureIt you saved previously, the F-Secure Online Scanner log and a fresh Hijackthis log ran in Normal Mode[/B]. Use multiple replies if needed.
  • 0

#39
merchantz

merchantz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 28 posts
wow thanks for the great response!

I'm unfortunately away from my computer for about 10 days but i will implement as soon as i get back, and let you know the result.

Thanks again.
  • 0

#40
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Happy Holidays! :whistling: :blink:
  • 0

Advertisements


#41
merchantz

merchantz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 28 posts
The Sophos scan came up with an error saying that a process could not start in safe mode. (Error: Could not initialize kernel driver memsweep.sys. Please restart and try again.) Otherwise it found lots of hidden regestry keys which could not be selected for modification. Otherwise it had one hidden file called c:/windows/system32/lzx32.sys which was not checked but can be.


The F-Secure scan i could not navigate to the 'accept' button because the window was smaller because it was running in safe mode.

Here is the Dr Web report which went fine!

namn.exe;C:\;Trojan.PWS.Pape;Deleted.;
textbox[1].mp3;C:\Documents and Settings\Oliver Standing\Local Settings\Temporary Internet Files\Content.IE5\36ZHHLZZ;Trojan.Spambot;Deleted.;
textbox[1].mp3;C:\Documents and Settings\Oliver Standing\Local Settings\Temporary Internet Files\Content.IE5\E3OFUXKL;Trojan.Spambot;Deleted.;
textbox[1].mp3;C:\Documents and Settings\Oliver Standing\Local Settings\Temporary Internet Files\Content.IE5\M1YLAT2B;Trojan.Spambot;Deleted.;
textbox[2].mp3;C:\Documents and Settings\Oliver Standing\Local Settings\Temporary Internet Files\Content.IE5\M1YLAT2B;Trojan.Spambot;Deleted.;
textbox[1].mp3;C:\Documents and Settings\Oliver Standing\Local Settings\Temporary Internet Files\Content.IE5\ORS7705S;Trojan.Spambot;Deleted.;
MiniBugTransporter.dll;C:\Program Files\Common Files\Real\WeatherBug;Adware.Minibug;Incurable.Moved.;
UnInstall.exe;C:\Program Files\Common Files\{34A58EF0-0574-1033-0116-05111220002c};Adware.Macfa;Incurable.Moved.;
Bar888.dll;C:\Program Files\Common Files\{34A58EF0-0575-1033-0116-05111220002c};Adware.Macfa;Incurable.Moved.;
UnInstall.exe;C:\Program Files\Common Files\{34A58EF0-0575-1033-0116-05111220002c};Adware.Macfa;Incurable.Moved.;
system.dll;C:\Program Files\Common Files\{54A58EF0-0574-1033-0116-05111220002c};Adware.Macfa;Incurable.Moved.;
system.dll;C:\Program Files\Common Files\{54A58EF0-0575-1033-0116-05111220002c};Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc1;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc1;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc10;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc10;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc11;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc11;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc12;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc12;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc13;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc13;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc14;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc14;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc15;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc15;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc16;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc16;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc17;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc17;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc18;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc18;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc19;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc19;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc2;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc2;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc20;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc20;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc21;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc21;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc22;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc22;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc23;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc23;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc3;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc3;Adware.Macfa;Incurable.Moved.;
system.dll;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc4;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc4;Adware.Macfa;Incurable.Moved.;
Update.exe;C:\RECYCLER\S-1-5-21-3705841881-1901854557-909247424-1005\Dc5;Adware.Macfa;Incurable.Moved.;
A0034580.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP417;Adware.IWantSearch;Incurable.Moved.;
A0034582.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP417;Trojan.Spambot;Deleted.;
A0034828.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Trojan.Spambot;Deleted.;
A0034846.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035725.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Trojan.PWS.Pape;Deleted.;
A0035726.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035732.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035733.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Trojan.Spambot;Deleted.;
A0035756.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Trojan.DownLoader.15690;Deleted.;
A0035757.exe\data001;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419\A0035757.exe;Trojan.PWS.Snap;;
A0035757.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Archive contains infected objects;Moved.;
A0035763.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035765.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035767.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035769.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035771.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035773.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035791.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035793.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035809.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035811.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035813.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035815.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035817.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035819.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035821.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035823.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035825.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035827.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035829.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035831.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035833.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035835.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035837.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035839.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035841.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035843.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035845.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035847.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035849.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035851.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035853.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035855.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035857.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035859.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035861.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035863.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035865.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035867.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035869.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035871.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035873.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035875.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035877.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035879.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035881.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035883.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035885.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035887.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035889.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035891.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035893.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035895.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035897.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035899.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035901.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035903.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035905.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035907.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035909.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035911.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035913.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035915.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035917.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035919.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035921.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035923.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035925.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035927.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035929.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035931.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035933.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035935.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035937.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035939.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035941.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035942.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035943.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035944.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035945.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035946.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035947.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035948.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035949.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035951.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035952.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035953.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035954.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035955.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035956.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035957.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035958.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035959.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035960.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035961.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035962.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035963.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035964.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035965.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035967.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035968.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035969.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035970.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035971.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035972.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035973.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035974.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035975.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035976.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035977.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035978.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035979.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035980.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035981.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035983.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035985.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035986.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035987.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035988.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035989.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035991.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0035992.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035993.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035994.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035995.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035996.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035997.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035998.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0035999.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036000.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036001.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036002.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036003.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036004.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036005.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036006.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036007.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036009.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036010.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036011.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036012.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036013.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036014.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036015.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036016.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036017.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036018.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036019.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036020.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036021.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036023.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036024.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036025.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036026.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036027.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036028.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036029.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036030.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036031.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036032.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036033.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036035.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036036.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036037.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036038.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036039.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036040.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036041.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036042.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036043.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036045.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036046.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036047.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036048.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036049.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036050.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036051.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036052.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036053.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036054.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036055.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036056.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036057.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036058.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036059.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036060.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036061.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036062.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036063.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036064.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036065.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036066.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036067.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036068.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036069.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036070.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036071.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036072.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036073.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036074.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036075.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036076.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036077.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036078.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036079.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036080.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036081.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036082.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036083.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036084.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036085.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036086.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036087.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036088.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036089.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036090.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036091.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036092.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036093.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036094.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036095.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036096.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036097.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.Macfa;Incurable.Moved.;
A0036099.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036101.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036103.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036105.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036107.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036109.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036111.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036113.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036115.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036117.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036119.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036121.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036123.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036125.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036127.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036129.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036131.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036133.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036135.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036137.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036139.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036141.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036143.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036145.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036147.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036149.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036151.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036153.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036155.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036157.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036159.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036161.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036163.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036165.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036167.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036169.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036171.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036173.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036175.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036177.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036179.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036181.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036183.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036185.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036187.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036189.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036191.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036193.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036195.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036197.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036199.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036201.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036203.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036205.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036207.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036209.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036211.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036213.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036215.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036217.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036219.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036221.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036223.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036225.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036227.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036229.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036231.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036233.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036235.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036237.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036239.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036241.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036243.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036245.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036247.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036249.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036251.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036253.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036255.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036257.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036259.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036261.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036263.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036265.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036267.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036269.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036271.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036273.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036275.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036277.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036279.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036281.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036283.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036285.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036287.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036289.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036291.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036293.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036295.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036297.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036299.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036301.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036303.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036305.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036307.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036309.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036311.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036313.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036315.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036317.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036319.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036321.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036323.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036325.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036327.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036329.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036331.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036333.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036335.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036337.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036339.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036341.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036343.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Adware.IWantSearch;Incurable.Moved.;
A0036378.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP419;Trojan.Spambot;Deleted.;
A0036388.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP420;Trojan.Spambot;Deleted.;
A0036495.sys;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP420;Trojan.NtRootKit.168;Deleted.;
A0036498.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Trojan.Spambot;Deleted.;
A0036499.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Adware.Macfa;Incurable.Moved.;
A0036501.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Trojan.Spambot;Deleted.;
A0037371.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Adware.Macfa;Incurable.Moved.;
A0037373.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Adware.Macfa;Incurable.Moved.;
A0037374.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Adware.Macfa;Incurable.Moved.;
A0037385.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Trojan.Spambot;Deleted.;
A0037386.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Adware.Macfa;Incurable.Moved.;
A0038365.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Adware.Macfa;Incurable.Moved.;
A0038376.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Trojan.Spambot;Deleted.;
A0038377.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Adware.Macfa;Incurable.Moved.;
A0039376.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Trojan.Spambot;Deleted.;
A0039378.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Adware.Macfa;Incurable.Moved.;
A0039379.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Trojan.Spambot;Deleted.;
A0040390.exe\data001;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421\A0040390.exe;Trojan.PWS.Snap;;
A0040390.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Archive contains infected objects;Moved.;
A0040400.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Trojan.Spambot;Deleted.;
A0041392.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Adware.Macfa;Incurable.Moved.;
A0041394.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Trojan.Spambot;Deleted.;
A0041397.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Trojan.Spambot;Deleted.;
A0041399.exe\data001;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421\A0041399.exe;Trojan.PWS.Snap;;
A0041399.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Archive contains infected objects;Moved.;
A0041402.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Trojan.PWS.Pape;Deleted.;
A0041403.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Adware.Macfa;Incurable.Moved.;
A0041489.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Adware.Macfa;Incurable.Moved.;
A0041492.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Trojan.Spambot;Deleted.;
A0041494.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Trojan.Starter.112;Deleted.;
A0041496.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Trojan.Spambot;Deleted.;
A0041497.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Adware.Macfa;Incurable.Moved.;
A0041499.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Adware.Macfa;Incurable.Moved.;
A0041500.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Trojan.Spambot;Deleted.;
A0046534.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Adware.Macfa;Incurable.Moved.;
A0046535.exe;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Adware.Macfa;Incurable.Moved.;
A0046536.dll;C:\System Volume Information\_restore{B01E8ED6-95B5-4381-A1C4-8341C4F8B2E9}\RP421;Adware.Macfa;Incurable.Mo

Edited by merchantz, 02 January 2007 - 04:36 PM.

  • 0

#42
merchantz

merchantz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 28 posts
In normal mode the blue warning crash screen comes up after a couple of minutes so i cant run hijackthis in it! Here is a report from safe mode.

Cheers

Logfile of HijackThis v1.99.1
Scan saved at 22:40:23, on 02/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com/en/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://vcl.vaio.sony...eu/PforVAIO.htm
O3 - Toolbar: DiskView - {6A882320-BDD0-4ff4-BE3A-D8BAF82668E9} - C:\Program Files\Vyooh\DiskView\VizBar.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\VAIO Entertainment\VzTaskScheduler.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
  • 0

#43
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Hi, merchantz :whistling:

Welcome back.

Lets try this fix. Usually must be done in Normal Mode.

Download Rustbfix from one of these locations:

http://www.uploads.e...et/rustbfix.exe
http://uploads.ejvin...om/Rustbfix.exe

...and save it to your desktop.

Double click on rustbfix.exe to run the tool. If a Rustock.b-infection is found, you will shortly hereafter be asked to reboot the computer. The reboot will probably take quite a while, and perhaps 2 reboots will be needed. But this will happen automatically. After the reboot 2 logfiles will open (%root%\avenger.txt & %root%\rustbfix\pelog.txt). Post the content of these logfiles along with a new HijackThis log.
  • 0

#44
merchantz

merchantz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 28 posts
Right i did that but could only do it from safe mode. When it rebooted a window came up called system32 or something and said 'cannot find cd' so i pressed cancel. I am now in normal mode

Reports-

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\uwvixcfp

*******************

Script file located at: \??\C:\WINDOWS\rlksdxxq.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Driver PE386 unloaded successfully.
Program C:\Rustbfix\2run.bat successfully set up to run once on reboot.

Completed script processing.

*******************

Finished! Terminate.


--------------------


************************* Rustock.b-fix -- By ejvindh *************************
03/01/2007 18:19:45.42

******************* Pre-run Status of system *******************

Rootkit driver PE386 is found. Starting the unload-procedure....

Rustock.b-ADS attached to the System32-folder:
No streams found.

Looking for Rustock.b-files in the System32-folder:
system32\lzx32.sys FOUND!
attempting to delete lzx32.sys from system32-folder


******************* Post-run Status of system *******************

Rustock.b-driver on the system: NONE!

Rustock.b-ADS attached to the System32-folder:
No System32-ADS found.

Looking for Rustock.b-files in the System32-folder:
No Rustock.b-files found in system32


******************************* End of Logfile ********************************

-----------

Hijackthis

Logfile of HijackThis v1.99.1
Scan saved at 18:25:41, on 03/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\NOTEPAD.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\SoftwareDistribution\Download\Install\Windows-KB890830-V1.23-delta.exe
d:\5f9c0255ef1cb039852c5d92365b078b\mrtstub.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com/en/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://vcl.vaio.sony...eu/PforVAIO.htm
O3 - Toolbar: DiskView - {6A882320-BDD0-4ff4-BE3A-D8BAF82668E9} - C:\Program Files\Vyooh\DiskView\VizBar.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\PROGRA~1\SPYWAR~1\sp_rsser.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\VAIO Entertainment\VzTaskScheduler.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
  • 0

#45
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Hi, merchantz :whistling:

You have succesfully removed the rootkit.

The log looks clear. How is the computer doing?
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP