Okay, here goes
Have no idea what I'm doing, just obeying dutifully
Thank you!
by the way, when I went to restart out of safemode both times it said the program Sample was not responding and to end it now. Don't know if that means anything. Also, before doing this I ran Spyware doctor and it found the following. If it means nothing, forgive the space on the page. Spyware Doctor says it was removed afterwards.
Trojan.Downloader.CashDeluxe C:\WINDOWS\System32\cdromdrv32.dll Elevated
Trojan.Downloader.CashDeluxe C:\WINDOWS\system32\cwklgqvx.exe Elevated
Trojan.Downloader.CashDeluxe C:\WINDOWS\System32\user_32.dll Elevated
Trojan.Downloader.CashDeluxe HKCR\a_inc_module.class1 Elevated
Trojan.Downloader.CashDeluxe HKCR\a_inc_module.class1## Elevated
Trojan.Downloader.CashDeluxe HKCR\a_inc_module.class1\Clsid Elevated
Trojan.Downloader.CashDeluxe HKCR\a_inc_module.class1\Clsid## Elevated
Trojan.Downloader.CashDeluxe HKCR\cdromdrv32.shell_plugin Elevated
Trojan.Downloader.CashDeluxe HKCR\cdromdrv32.shell_plugin## Elevated
Trojan.Downloader.CashDeluxe HKCR\cdromdrv32.shell_plugin\Clsid Elevated
Trojan.Downloader.CashDeluxe HKCR\cdromdrv32.shell_plugin\Clsid## Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA} Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}## Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\Implemented Categories Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\Implemented Categories## Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502} Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}## Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\InprocServer32 Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\InprocServer32## Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\InprocServer32##ThreadingModel Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\ProgID Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\ProgID## Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\Programmable Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\Programmable## Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\TypeLib Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\TypeLib## Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\VERSION Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\VERSION## Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C} Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}## Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\Implemented Categories Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\Implemented Categories## Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502} Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}## Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\InprocServer32 Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\InprocServer32## Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\InprocServer32##ThreadingModel Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\ProgID Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\ProgID## Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\Programmable Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\Programmable## Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\TypeLib Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\TypeLib## Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\VERSION Elevated
Trojan.Downloader.CashDeluxe HKCR\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\VERSION## Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{61391E50-5236-494A-BAE2-282F6C520C65} Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{61391E50-5236-494A-BAE2-282F6C520C65}## Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{61391E50-5236-494A-BAE2-282F6C520C65}\ProxyStubClsid Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{61391E50-5236-494A-BAE2-282F6C520C65}\ProxyStubClsid## Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{61391E50-5236-494A-BAE2-282F6C520C65}\ProxyStubClsid32 Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{61391E50-5236-494A-BAE2-282F6C520C65}\ProxyStubClsid32## Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{61391E50-5236-494A-BAE2-282F6C520C65}\TypeLib Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{61391E50-5236-494A-BAE2-282F6C520C65}\TypeLib## Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{61391E50-5236-494A-BAE2-282F6C520C65}\TypeLib##Version Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{8144C535-F34D-47BC-9013-A7C05AA8F12C} Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{8144C535-F34D-47BC-9013-A7C05AA8F12C}## Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{8144C535-F34D-47BC-9013-A7C05AA8F12C}\ProxyStubClsid Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{8144C535-F34D-47BC-9013-A7C05AA8F12C}\ProxyStubClsid## Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{8144C535-F34D-47BC-9013-A7C05AA8F12C}\ProxyStubClsid32 Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{8144C535-F34D-47BC-9013-A7C05AA8F12C}\ProxyStubClsid32## Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{8144C535-F34D-47BC-9013-A7C05AA8F12C}\TypeLib Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{8144C535-F34D-47BC-9013-A7C05AA8F12C}\TypeLib## Elevated
Trojan.Downloader.CashDeluxe HKCR\Interface\{8144C535-F34D-47BC-9013-A7C05AA8F12C}\TypeLib##Version Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{6AB0337F-F523-4073-AFBF-0947B331955E} Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{6AB0337F-F523-4073-AFBF-0947B331955E}## Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{6AB0337F-F523-4073-AFBF-0947B331955E}\1.0 Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{6AB0337F-F523-4073-AFBF-0947B331955E}\1.0## Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{6AB0337F-F523-4073-AFBF-0947B331955E}\1.0 Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{6AB0337F-F523-4073-AFBF-0947B331955E}\1.0## Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{6AB0337F-F523-4073-AFBF-0947B331955E}\1.0\win32 Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{6AB0337F-F523-4073-AFBF-0947B331955E}\1.0\win32## Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{6AB0337F-F523-4073-AFBF-0947B331955E}\1.0\FLAGS Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{6AB0337F-F523-4073-AFBF-0947B331955E}\1.0\FLAGS## Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{6AB0337F-F523-4073-AFBF-0947B331955E}\1.0\HELPDIR Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{6AB0337F-F523-4073-AFBF-0947B331955E}\1.0\HELPDIR## Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{9A0673DB-7BD7-43D6-8FA2-C93FE0B996EB} Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{9A0673DB-7BD7-43D6-8FA2-C93FE0B996EB}## Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{9A0673DB-7BD7-43D6-8FA2-C93FE0B996EB}\1.0 Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{9A0673DB-7BD7-43D6-8FA2-C93FE0B996EB}\1.0## Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{9A0673DB-7BD7-43D6-8FA2-C93FE0B996EB}\1.0 Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{9A0673DB-7BD7-43D6-8FA2-C93FE0B996EB}\1.0## Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{9A0673DB-7BD7-43D6-8FA2-C93FE0B996EB}\1.0\win32 Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{9A0673DB-7BD7-43D6-8FA2-C93FE0B996EB}\1.0\win32## Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{9A0673DB-7BD7-43D6-8FA2-C93FE0B996EB}\1.0\FLAGS Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{9A0673DB-7BD7-43D6-8FA2-C93FE0B996EB}\1.0\FLAGS## Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{9A0673DB-7BD7-43D6-8FA2-C93FE0B996EB}\1.0\HELPDIR Elevated
Trojan.Downloader.CashDeluxe HKCR\TypeLib\{9A0673DB-7BD7-43D6-8FA2-C93FE0B996EB}\1.0\HELPDIR## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA} Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\Implemented Categories Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\Implemented Categories## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502} Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\InprocServer32 Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\InprocServer32## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\InprocServer32##ThreadingModel Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\ProgID Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\ProgID## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\Programmable Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\Programmable## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\TypeLib Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\TypeLib## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\VERSION Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{0D708714-CF29-488B-98BE-24D1B96230AA}\VERSION## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C} Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\Implemented Categories Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\Implemented Categories## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502} Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\InprocServer32 Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\InprocServer32## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\InprocServer32##ThreadingModel Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\ProgID Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\ProgID## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\Programmable Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\Programmable## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\TypeLib Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\TypeLib## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\VERSION Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Classes\CLSID\{6CFD19FA-D47A-4C1D-8044-33235651387C}\VERSION## Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0D708714-CF29-488B-98BE-24D1B96230AA} Elevated
Trojan.Downloader.CashDeluxe HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0D708714-CF29-488B-98BE-24D1B96230AA}##
Also, a few weeks back we had a wicked virus that I can't remember the name of, Brave something or something that starts with Brav. We had to do a complete reformat and reinstall of the OS. Norton hogs everything and the vendor that makes our software we use for work, which is Case Catalyst says we needed to disable it because it interferes with realtime writing from our steno machines to the computer. We run Spyware doctor and Norton regularly, but it's always infected. Just a background if any of that helps.
Okay, now for the stuff you ACTUALLY wanted!
-Stephanie
************************* Rustock.b-fix -- By ejvindh *************************
Sun 03/18/2007 21:43:44.84
No Rustock.b-rootkits found
******************************* End of Logfile ********************************
Adobe Flash Player 9 ActiveX
AppCore
Apple Software Update
ATI Control Panel
ATI Display Driver
AV
BCM V.92 56K Modem
Broadcom Gigabit Integrated Controller
caseCATalyst4
ccCommon
Dell ResourceCD
HijackThis 1.99.1
Intel® PROSet
Internet Worm Protection
iTunes
LiveUpdate 3.1 (Symantec Corporation)
Microsoft Office Standard Edition 2003
Microsoft Office XP Small Business
Norton AntiVirus
Norton AntiVirus (Symantec Corporation)
Norton AntiVirus Help
Norton AntiVirus Parent MSI
Norton AntiVirus SYMLT MSI
Norton Protection Center
O2Micro Smartcard Driver
QuickTime
Samsung ML-1740 Series
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB920683)
SigmaTel AC97 Audio Drivers
SPBBC 32bit
Spyware Doctor 4.0
Symantec
SymNet
Update for Windows XP (KB835409)
Update for Windows XP (KB898461)
Update for Windows XP (KB908531)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB842773
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB911567
Windows XP Hotfix - KB918899
SmitFraudFix v2.150
Scan done at 21:53:28.48, Sun 03/18/2007
Run from C:\Documents and Settings\Rafael\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Rafael
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Rafael\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Rafael\FAVORI~1
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32
»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End