ok. here is everything that you asked me to do. hope this helps.
MOVEITExplorer killed successfully
LoadLibrary failed for D:\WINDOWS\system32\njbsiwke.dll
D:\WINDOWS\system32\njbsiwke.dll NOT unregistered.
D:\WINDOWS\system32\njbsiwke.dll moved successfully.
D:\bttf.nri moved successfully.
< EmptyTemp >
File delete failed. D:\DOCUME~1\X\LOCALS~1\Temp\WCESLog.log scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
< purity >
Explorer started successfully
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08042008_000356
Files moved on Reboot...
D:\DOCUME~1\X\LOCALS~1\Temp\WCESLog.log moved successfully.
MALWAREBYTESSUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 08/04/2008 at 01:22 AM
Application Version : 4.15.1000
Core Rules Database Version : 3524
Trace Rules Database Version: 1514
Scan type : Complete Scan
Total Scan Time : 01:07:07
Memory items scanned : 339
Memory threats detected : 0
Registry items scanned : 7372
Registry threats detected : 0
File items scanned : 33238
File threats detected : 8
Adware.Tracking Cookie
.media6degrees.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.trafficmp.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.trafficmp.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.trafficmp.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.media6degrees.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.trafficmp.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.trafficmp.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.media6degrees.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
cache.trafficmp.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
cache.trafficmp.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.media6degrees.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.media6degrees.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.atdmt.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.adbrite.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.adbrite.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.adbrite.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
4.adbrite.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.adbrite.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.fastclick.net [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.fastclick.net [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.fastclick.net [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.fastclick.net [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.fastclick.net [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
ad.yieldmanager.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
ad.yieldmanager.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
ad.yieldmanager.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
ad.yieldmanager.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
ad.yieldmanager.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
ad.yieldmanager.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
ad.yieldmanager.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
ad.yieldmanager.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.crackle.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.crackle.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.crackle.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.crackle.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.crackle.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.crackle.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.crackle.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
crackle.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.ehg-groupernetworks.hitbox.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.hitbox.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.hitbox.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.tribalfusion.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.doubleclick.net [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.adopt.euroclick.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.adopt.euroclick.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.adopt.euroclick.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
adopt.euroclick.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.adopt.euroclick.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.adopt.euroclick.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.mediaplex.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.questionmarket.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.questionmarket.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.realmedia.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.realmedia.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.realmedia.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.apmebf.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.advertising.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.advertising.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.advertising.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.advertising.com [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
ads.revsci.net [ D:\Documents and Settings\X\Application Data\Mozilla\Firefox\Profiles\3mqb4zy3.default\cookies.txt ]
.questionmarket.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
ad.yieldmanager.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
ad.yieldmanager.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
ad.yieldmanager.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
ad.yieldmanager.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
ad.yieldmanager.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.questionmarket.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.advertising.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.advertising.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.advertising.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.advertising.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.advertising.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.doubleclick.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.adrevolver.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.adrevolver.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.adrevolver.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
media.adrevolver.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.atdmt.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.ads.pointroll.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.ads.pointroll.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.ads.pointroll.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.ads.pointroll.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.ads.pointroll.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.ads.pointroll.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.ads.pointroll.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.tribalfusion.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.insightexpressai.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.insightexpressai.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.insightexpressai.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.insightexpressai.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.insightexpressai.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.insightexpressai.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.dynamic.media.adrevolver.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.dynamic.media.adrevolver.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
ads.nebuadserving.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
ads.nebuadserving.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.zedo.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.zedo.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.zedo.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.zedo.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.zedo.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.revsci.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.revsci.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.revsci.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
ads.revsci.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.usatoday1.112.2o7.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.tacoda.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.tacoda.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.tacoda.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.tacoda.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.tacoda.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
anad.tacoda.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.bs.serving-sys.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.serving-sys.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.serving-sys.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.serving-sys.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.serving-sys.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.serving-sys.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.serving-sys.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.fastclick.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.fastclick.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.fastclick.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.fastclick.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.fastclick.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.media6degrees.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.media6degrees.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.trafficmp.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.trafficmp.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.media6degrees.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.trafficmp.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.trafficmp.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.trafficmp.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.casalemedia.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.casalemedia.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.casalemedia.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.casalemedia.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.casalemedia.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.adbrite.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.stats.adbrite.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.adbrite.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.statcounter.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.statcounter.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.directtrack.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
angleinteractive.directtrack.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.apmebf.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.iacas.adbureau.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.iacas.adbureau.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.iacas.adbureau.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.iacas.adbureau.net [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.atwola.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
.e-2dj6whkiwlcjwcp.stats.esomniture.com [ D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\cookies.txt ]
NotHarmful.Sysinternals Bluescreen Screen Saver
D:\SYSTEM VOLUME INFORMATION\_RESTORE{3AC89F4A-47AA-4C3C-A2BF-C539274C17A0}\RP149\A0024440.SCR
D:\SYSTEM VOLUME INFORMATION\_RESTORE{3AC89F4A-47AA-4C3C-A2BF-C539274C17A0}\RP167\A0036547.SCR
Adware.Vundo/Variant-Gen6
D:\SYSTEM VOLUME INFORMATION\_RESTORE{3AC89F4A-47AA-4C3C-A2BF-C539274C17A0}\RP149\A0025479.DLL
D:\SYSTEM VOLUME INFORMATION\_RESTORE{3AC89F4A-47AA-4C3C-A2BF-C539274C17A0}\RP167\A0036550.DLL
D:\SYSTEM VOLUME INFORMATION\_RESTORE{3AC89F4A-47AA-4C3C-A2BF-C539274C17A0}\RP167\A0036551.DLL
Adware.Vundo Variant
D:\SYSTEM VOLUME INFORMATION\_RESTORE{3AC89F4A-47AA-4C3C-A2BF-C539274C17A0}\RP160\A0032512.DLL
D:\SYSTEM VOLUME INFORMATION\_RESTORE{3AC89F4A-47AA-4C3C-A2BF-C539274C17A0}\RP167\A0036548.DLL
D:\SYSTEM VOLUME INFORMATION\_RESTORE{3AC89F4A-47AA-4C3C-A2BF-C539274C17A0}\RP167\A0036552.DLL
DSSDeckard's System Scanner v20071014.68
Run by X on 2008-08-04 10:41:15
Computer is in Normal Mode.
--------------------------------------------------------------------------------
System Drive D: has 0.61 GiB (less than 15%) free.-- HijackThis (run as X.exe) ---------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:41, on 8/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20583)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
D:\WINDOWS\system32\UStorSrv.exe
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\PROGRA~1\MI3AA1~1\rapimgr.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\system32\wuauclt.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\mozilla.org\Mozilla\mozilla.exe
D:\Documents and Settings\X\Desktop\dss.exe
D:\PROGRA~1\TRENDM~1\HIJACK~1\X.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
N3 - Netscape 7: user_pref("browser.search.defaultengine", "
http://www.google.com/"); (D:\Documents and Settings\X\Application Data\Mozilla\Profiles\default\ctvirtnn.slt\prefs.js)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AnyDVD] D:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVP] "D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [IE7-10] rundll32 advpack.dll,LaunchINFSectionEx NR_IE7en.inf,AfterUserStart,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - D:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - D:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PacificPoker - {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - D:\PROGRA~1\PACIFI~1\pacificpoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: MANSION - {CD03D14B-0EF6-4f5a-BB81-1ECAFFC676AF} - D:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: MANSION - {CD03D14B-0EF6-4f5a-BB81-1ECAFFC676AF} - D:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - D:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - D:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} -
http://appdirectory....sharingctrl.cabO16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) -
http://support.f-sec...m/ols/fscax.cabO16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} -
http://messenger.zon...oF.cab31267.cabO16 - DPF: {EEC9DBCC-04AD-4A1B-BEA7-C6DAD9515D5A} -
http://asp.mathxl.co.../EconPlayer.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{A3C7BD06-C7A9-4EB6-8C88-A3D1FF6526AE}: NameServer =
O17 - HKLM\System\CS3\Services\Tcpip\..\{A3C7BD06-C7A9-4EB6-8C88-A3D1FF6526AE}: NameServer =
O17 - HKLM\System\CS4\Services\Tcpip\..\{A3C7BD06-C7A9-4EB6-8C88-A3D1FF6526AE}: NameServer =
O17 - HKLM\System\CS5\Services\Tcpip\..\{A3C7BD06-C7A9-4EB6-8C88-A3D1FF6526AE}: NameServer =
O17 - HKLM\System\CS6\Services\Tcpip\..\{A3C7BD06-C7A9-4EB6-8C88-A3D1FF6526AE}: NameServer =
O17 - HKLM\System\CS7\Services\Tcpip\..\{A3C7BD06-C7A9-4EB6-8C88-A3D1FF6526AE}: NameServer =
O17 - HKLM\System\CS8\Services\Tcpip\..\{A3C7BD06-C7A9-4EB6-8C88-A3D1FF6526AE}: NameServer =
O17 - HKLM\System\CS9\Services\Tcpip\..\{A3C7BD06-C7A9-4EB6-8C88-A3D1FF6526AE}: NameServer =
O17 - HKLM\System\CS10\Services\Tcpip\..\{A3C7BD06-C7A9-4EB6-8C88-A3D1FF6526AE}: NameServer =
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - D:\Program Files\WinPcap\rpcapd.exe
O23 - Service: UStorage Server Service - OTi - D:\WINDOWS\system32\UStorSrv.exe
--
End of file - 9277 bytes
-- Files created between 2008-07-04 and 2008-08-04 -----------------------------
2008-07-31 10:24:43 96559 --a------ D:\WINDOWS\system32\drivers\klin.dat
2008-07-31 10:24:43 87855 --a------ D:\WINDOWS\system32\drivers\klick.dat
2008-07-31 10:14:27 507936 --ahs---- D:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-31 10:14:27 2964000 --ahs---- D:\WINDOWS\system32\drivers\fidbox.dat
2008-07-29 20:54:57 0 d--h----- D:\WINDOWS\$hf_mig$
2008-07-27 11:12:19 0 d-------- D:\Program Files\Elaborate Bytes
2008-07-27 11:08:48 0 d-------- D:\WINDOWS\system32\SoftwareDistribution
2008-07-27 11:01:02 0 d-------- D:\Program Files\SlySoft
2008-07-26 21:48:37 0 d-------- D:\Program Files\Pocket Tanks Deluxe
2008-07-22 18:39:49 0 d-------- D:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-22 18:39:37 0 d-------- D:\Program Files\SUPERAntiSpyware
2008-07-22 18:39:37 0 d-------- D:\Documents and Settings\X\Application Data\SUPERAntiSpyware.com
2008-07-21 19:28:41 0 d-------- D:\Documents and Settings\X\Application Data\Malwarebytes
2008-07-21 19:28:38 0 d-------- D:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-21 19:28:37 0 d-------- D:\Program Files\Malwarebytes' Anti-Malware
2008-07-16 16:20:45 38160 --a------ D:\WINDOWS\system32\LMRTREND.dll <Not Verified; Microsoft Corporation; Microsoft® Windows Operating System>
2008-07-16 16:20:44 182032 --a------ D:\WINDOWS\system32\dxtmsft3.dll <Not Verified; Microsoft Corporation; Microsoft® Windows Operating System>
2008-07-16 16:20:41 63488 --a------ D:\WINDOWS\system32\unam4ie.exe <Not Verified; Microsoft Corporation; DirectShow>
2008-07-16 16:20:39 10240 --a------ D:\WINDOWS\system32\vidx16.dll
2008-07-16 16:20:39 194320 --a------ D:\WINDOWS\system32\qcut.dll <Not Verified; Microsoft Corporation; DirectShow>
2008-07-16 16:20:38 4608 --a------ D:\WINDOWS\system32\w95inf32.dll <Not Verified; Microsoft Corporation; Microsoft® Plus! for Windows® 95>
2008-07-16 16:20:38 2272 --a------ D:\WINDOWS\system32\w95inf16.dll <Not Verified; Microsoft Corporation; Microsoft® Plus! for Windows® 95>
2008-07-16 16:20:24 0 d-------- D:\Program Files\Auralog
2008-07-16 15:54:23 68096 --a------ D:\WINDOWS\zip.exe
2008-07-16 15:54:23 49152 --a------ D:\WINDOWS\VFind.exe
2008-07-16 15:54:23 212480 --a------ D:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-07-16 15:54:23 136704 --a------ D:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-07-16 15:54:23 161792 --a------ D:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-07-16 15:54:23 98816 --a------ D:\WINDOWS\sed.exe
2008-07-16 15:54:23 80412 --a------ D:\WINDOWS\grep.exe
2008-07-16 15:54:23 89504 --a------ D:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-07-16 15:50:30 0 d-------- D:\WINDOWS\setup.pss
2008-07-16 15:50:15 0 d-------- D:\WINDOWS\setupupd
2008-07-16 14:17:13 0 d-------- D:\WINDOWS\ERUNT
2008-07-14 17:45:46 0 d-------- D:\Program Files\Trend Micro
-- Find3M Report ---------------------------------------------------------------
2008-08-02 11:12:17 0 d-------- D:\Program Files\Common Files
2008-07-31 10:14:40 0 d-------- D:\Program Files\Kaspersky Lab
2008-07-22 18:39:10 0 d-------- D:\Program Files\Common Files\Wise Installation Wizard
2008-07-16 20:20:52 0 d-------- D:\Program Files\Uniblue
2008-07-16 19:23:11 0 d-------- D:\Program Files\Microsoft ActiveSync
2008-07-05 21:37:09 0 d-------- D:\Program Files\Beat It
2008-06-23 16:21:16 0 d-------- D:\Documents and Settings\X\Application Data\Vso
2008-06-08 22:27:46 0 d-------- D:\Program Files\Absolute Poker
2008-06-05 16:13:56 0 d-------- D:\Documents and Settings\X\Application Data\Uniblue
2008-06-05 16:12:52 0 d-------- D:\Program Files\XBC
2008-06-05 16:08:23 0 d-------- D:\Program Files\Binaryfish
2008-06-05 15:46:25 0 d-------- D:\Program Files\MagicDisc
2008-05-09 23:55:57 2508 --a------ D:\Documents and Settings\X\Application Data\$_hpcst$.hpc
2008-05-04 13:11:21 33 --a------ D:\Documents and Settings\X\Application Data\install.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnyDVD"="D:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [07/27/2008 10:42]
"TkBellExe"="D:\Program Files\Common Files\Real\Update_OB\realsched.exe" [05/13/2006 22:47]
"AVP"="D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 18:21]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [08/03/2004 21:56]
"SUPERAntiSpyware"="D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [05/28/2008 10:33]
"H/PC Connection Agent"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe" [06/20/2006 22:36]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"ShowDeskFix"=regsvr32 /s /n /i:u shell32
"IE7-10"=rundll32 advpack.dll,LaunchINFSectionEx NR_IE7en.inf,AfterUserStart,,4,N
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= D:\Program Files\SUPERAntiSpyware\SASSEH.DLL [05/13/2008 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
D:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 13:41 294912 D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winim83.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winyd50.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=D:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^ghmec.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
backup=D:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=D:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^VoiceCenter.lnk]
backup=D:\WINDOWS\pss\VoiceCenter.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^X^Start Menu^Programs^Startup^MagicDisc.lnk]
path=D:\Documents and Settings\X\Start Menu\Programs\Startup\MagicDisc.lnk
backup=D:\WINDOWS\pss\MagicDisc.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^X^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
backup=D:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^X^Start Menu^Programs^Startup^Registration Heroes of Might & Magic 5.LNK]
backup=D:\WINDOWS\pss\Registration Heroes of Might & Magic 5.LNKStartup
e
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\+,-./0123456789:;<=exe]
!"#$%&'()*+,-./0123456789:;<=exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\3456789:;<=>?@ABCDEexe]
()*+,-./0123456789:;<=>?@ABCDEexe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\3456789:;<=>?@ABCDEFGexe]
()*+,-./0123456789:;<=>?@ABCDEFGexe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
"D:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrowserUpdateSched]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
D:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
"D:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"D:\Program Files\D-Tools\daemon.exe" -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
"D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JavaCore]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kav]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"D:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
D:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
D:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"D:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyhunter Security Suite]
"D:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpyEraser]
"D:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Messenger"=2 (0x2)
"navapsvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccEvtMgr"=2 (0x2)
"iPodService"=3 (0x3)
"ccPwdSvc"=3 (0x3)
"Symantec Core LC"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=2 (0x2)
"SBService"=2 (0x2)
"SAVScan"=3 (0x3)
"NPFMntor"=2 (0x2)
"Pml Driver HPZ12"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)
"Network Monitor"=2 (0x2)
"MDM"=2 (0x2)
"cmdService"=2 (0x2)
"ATI Smart"=2 (0x2)
"antivirwebservice"=2 (0x2)
"AntiVirService"=2 (0x2)
"AntiVirScheduler"=2 (0x2)
"AntiVirMailService"=2 (0x2)
"AntiVirFirewallService"=2 (0x2)
"Alerter"=3 (0x3)
"SQLAgent$SONY_MEDIAMGR"=3 (0x3)
"ose"=3 (0x3)
"AVEService"=2 (0x2)
"AudioSrv"=2 (0x2)
"StarWindServiceAE"=2 (0x2)
"sdCoreService"=2 (0x2)
"sdAuxService"=2 (0x2)
"AVP"=2 (0x2)
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
"WLSetupSvc"=3 (0x3)
"WebrootSpySweeperService"=2 (0x2)
"WebClient"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17bbc147-e0fa-11dc-b293-00112fde776c}]
AutoRun\command- M:\LaunchU3.exe -a
-- End of Deckard's System Scanner: finished at 2008-08-04 10:41:49 ------------