I'm no computer wizard but I don't think i'm a simpleton either (yet) I hope someone can begin to help me.
Thanks
Kizza*
ArchiveData(auto-quarantine- 2005-04-30 15-08-19.bckp)
Referencefile : SE1R42 28.04.2005
======================================================
MRU LIST
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=MRU FileReference : C:\Documents and Settings\Default\Application Data\microsoft\office\recent\My Webs.LNK
obj[1]=MRU FileReference : C:\Documents and Settings\Default\recent\Desktop.ini
obj[2]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\adobe\acrobat reader\6.0\avgeneral\crecentfiles\c1
obj[3]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\adobe\acrobat reader\6.0\avgeneral\crecentfiles\c2
obj[4]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\adobe\acrobat reader\6.0\avgeneral\crecentfiles\c3
obj[5]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\adobe\acrobat reader\6.0\avgeneral\crecentfiles\c4
obj[6]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\adobe\acrobat reader\6.0\avgeneral\crecentfiles\c5
obj[7]=MRU FileReference : C:\Documents and Settings\Default\Application Data\microsoft\office\recent\photo_albums.LNK
obj[8]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\ahead\cover designer\recent file list
obj[9]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\ahead\nero - burning rom\recent file list
obj[10]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\ahead\nero wave editor\recent file list
obj[11]=MRU RegReference : .DEFAULT\software\macromedia\director\7.0\recentfiles
obj[12]=MRU RegReference : S-1-5-18\software\macromedia\director\7.0\recentfiles
obj[13]=MRU RegReference : S-1-5-19\software\macromedia\director\7.0\recentfiles
obj[14]=MRU RegReference : software\microsoft\direct3d\mostrecentapplication name
obj[15]=MRU RegReference : software\microsoft\direct3d\mostrecentapplication name
obj[16]=MRU RegReference : software\microsoft\directdraw\mostrecentapplication name
obj[17]=MRU RegReference : .DEFAULT\software\microsoft\directinput\mostrecentapplication name
obj[18]=MRU RegReference : S-1-5-18\software\microsoft\directinput\mostrecentapplication name
obj[19]=MRU RegReference : S-1-5-19\software\microsoft\directinput\mostrecentapplication name
obj[20]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\directinput\mostrecentapplication name
obj[21]=MRU RegReference : .DEFAULT\software\microsoft\directinput\mostrecentapplication id
obj[22]=MRU RegReference : S-1-5-18\software\microsoft\directinput\mostrecentapplication id
obj[23]=MRU RegReference : S-1-5-19\software\microsoft\directinput\mostrecentapplication id
obj[24]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\directinput\mostrecentapplication id
obj[25]=MRU RegReference : .DEFAULT\software\microsoft\frontpage defaultsave
obj[26]=MRU RegReference : S-1-5-18\software\microsoft\frontpage defaultsave
obj[27]=MRU RegReference : S-1-5-19\software\microsoft\frontpage defaultsave
obj[28]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\frontpage defaultsave
obj[29]=MRU RegReference : .DEFAULT\software\microsoft\frontpage\editor\insert hyperlink\recently used urls
obj[30]=MRU RegReference : S-1-5-18\software\microsoft\frontpage\editor\insert hyperlink\recently used urls
obj[31]=MRU RegReference : S-1-5-19\software\microsoft\frontpage\editor\insert hyperlink\recently used urls
obj[32]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\frontpage\editor\insert hyperlink\recently used urls
obj[33]=MRU RegReference : .DEFAULT\software\microsoft\frontpage\editor\insert image\recently used urls
obj[34]=MRU RegReference : S-1-5-18\software\microsoft\frontpage\editor\insert image\recently used urls
obj[35]=MRU RegReference : S-1-5-19\software\microsoft\frontpage\editor\insert image\recently used urls
obj[36]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\frontpage\editor\insert image\recently used urls
obj[37]=MRU RegReference : .DEFAULT\software\microsoft\frontpage\explorer\navigation\mrulist
obj[38]=MRU RegReference : S-1-5-18\software\microsoft\frontpage\explorer\navigation\mrulist
obj[39]=MRU RegReference : S-1-5-19\software\microsoft\frontpage\explorer\navigation\mrulist
obj[40]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\frontpage\explorer\navigation\mrulist
obj[41]=MRU RegReference : .DEFAULT\software\microsoft\internet explorer download directory
obj[42]=MRU RegReference : S-1-5-18\software\microsoft\internet explorer download directory
obj[43]=MRU RegReference : S-1-5-19\software\microsoft\internet explorer download directory
obj[44]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\internet explorer download directory
obj[45]=MRU RegReference : .DEFAULT\software\microsoft\internet explorer\main save directory
obj[46]=MRU RegReference : S-1-5-18\software\microsoft\internet explorer\main save directory
obj[47]=MRU RegReference : S-1-5-19\software\microsoft\internet explorer\main save directory
obj[48]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\internet explorer\main save directory
obj[49]=MRU RegReference : .DEFAULT\software\microsoft\internet explorer\typedurls
obj[50]=MRU RegReference : S-1-5-18\software\microsoft\internet explorer\typedurls
obj[51]=MRU RegReference : S-1-5-19\software\microsoft\internet explorer\typedurls
obj[52]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\internet explorer\typedurls
obj[53]=MRU RegReference : software\microsoft\internet explorer\typedurls
obj[54]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\mediaplayer\medialibraryui mllastselectednode
obj[55]=MRU RegReference : .DEFAULT\software\microsoft\mediaplayer\player\recentfilelist
obj[56]=MRU RegReference : S-1-5-18\software\microsoft\mediaplayer\player\recentfilelist
obj[57]=MRU RegReference : S-1-5-19\software\microsoft\mediaplayer\player\recentfilelist
obj[58]=MRU RegReference : .DEFAULT\software\microsoft\mediaplayer\player\settings saveasdir
obj[59]=MRU RegReference : S-1-5-18\software\microsoft\mediaplayer\player\settings saveasdir
obj[60]=MRU RegReference : S-1-5-19\software\microsoft\mediaplayer\player\settings saveasdir
obj[61]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\mediaplayer\player\settings saveasdir
obj[62]=MRU RegReference : .DEFAULT\software\microsoft\mediaplayer\player\settings opendir
obj[63]=MRU RegReference : S-1-5-18\software\microsoft\mediaplayer\player\settings opendir
obj[64]=MRU RegReference : S-1-5-19\software\microsoft\mediaplayer\player\settings opendir
obj[65]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\mediaplayer\player\settings opendir
obj[66]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\mediaplayer\preferences cdrecordpath
obj[67]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\mediaplayer\preferences lastplaylistindex
obj[68]=MRU RegReference : .DEFAULT\software\microsoft\mediaplayer\preferences lastplaylist
obj[69]=MRU RegReference : S-1-5-18\software\microsoft\mediaplayer\preferences lastplaylist
obj[70]=MRU RegReference : S-1-5-19\software\microsoft\mediaplayer\preferences lastplaylist
obj[71]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\mediaplayer\preferences lastplaylist
obj[72]=MRU RegReference : .DEFAULT\software\microsoft\mediaplayer\radio\mrulist
obj[73]=MRU RegReference : S-1-5-18\software\microsoft\mediaplayer\radio\mrulist
obj[74]=MRU RegReference : S-1-5-19\software\microsoft\mediaplayer\radio\mrulist
obj[75]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\mediaplayer\radio\mrulist
obj[76]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\microsoft management console\recent file list
obj[77]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\ntbackup\log files
obj[78]=MRU RegReference : .DEFAULT\software\microsoft\office\8.0\common\open find\microsoft powerpoint\settings\insert picture\file name mru value
obj[79]=MRU RegReference : S-1-5-18\software\microsoft\office\8.0\common\open find\microsoft powerpoint\settings\insert picture\file name mru value
obj[80]=MRU RegReference : S-1-5-19\software\microsoft\office\8.0\common\open find\microsoft powerpoint\settings\insert picture\file name mru value
obj[81]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\office\8.0\common\open find\microsoft powerpoint\settings\insert picture\file name mru value
obj[82]=MRU RegReference : .DEFAULT\software\microsoft\office\8.0\common\open find\microsoft word\settings\open\file name mru value
obj[83]=MRU RegReference : S-1-5-18\software\microsoft\office\8.0\common\open find\microsoft word\settings\open\file name mru value
obj[84]=MRU RegReference : S-1-5-19\software\microsoft\office\8.0\common\open find\microsoft word\settings\open\file name mru value
obj[85]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\office\8.0\common\open find\microsoft word\settings\open\file name mru value
obj[86]=MRU RegReference : .DEFAULT\software\microsoft\office\8.0\common\open find\microsoft word\settings\save as\file name mru value
obj[87]=MRU RegReference : S-1-5-18\software\microsoft\office\8.0\common\open find\microsoft word\settings\save as\file name mru value
obj[88]=MRU RegReference : S-1-5-19\software\microsoft\office\8.0\common\open find\microsoft word\settings\save as\file name mru value
obj[89]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\office\8.0\common\open find\microsoft word\settings\save as\file name mru value
obj[90]=MRU RegReference : .DEFAULT\software\microsoft\office\8.0\excel\recent file list
obj[91]=MRU RegReference : S-1-5-18\software\microsoft\office\8.0\excel\recent file list
obj[92]=MRU RegReference : S-1-5-19\software\microsoft\office\8.0\excel\recent file list
obj[93]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\office\8.0\excel\recent file list
obj[94]=MRU RegReference : .DEFAULT\software\microsoft\office\8.0\powerpoint\recent typeface list
obj[95]=MRU RegReference : S-1-5-18\software\microsoft\office\8.0\powerpoint\recent typeface list
obj[96]=MRU RegReference : S-1-5-19\software\microsoft\office\8.0\powerpoint\recent typeface list
obj[97]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\office\8.0\powerpoint\recent typeface list
obj[98]=MRU RegReference : .DEFAULT\software\microsoft\office\9.0\common\open find\microsoft word\settings\open\file name mru value
obj[99]=MRU RegReference : S-1-5-18\software\microsoft\office\9.0\common\open find\microsoft word\settings\open\file name mru value
obj[100]=MRU RegReference : S-1-5-19\software\microsoft\office\9.0\common\open find\microsoft word\settings\open\file name mru value
obj[101]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\search assistant\acmru\5603
obj[102]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\search assistant\acmru\5604
obj[103]=MRU RegReference : S-1-5-18\software\microsoft\office\9.0\common\open find\microsoft word\settings\save as\file name mru value
obj[104]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\applets\paint\recent file list
obj[105]=MRU RegReference : S-1-5-18\software\microsoft\windows\currentversion\applets\paint\recent file list
obj[106]=MRU RegReference : S-1-5-19\software\microsoft\windows\currentversion\applets\paint\recent file list
obj[107]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\applets\paint\recent file list
obj[108]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\*
obj[109]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\asx
obj[110]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\recentdocs\.log
obj[111]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\bkf
obj[112]=MRU RegReference : .DEFAULT\software\nico mak computing\winzip\filemenu
obj[113]=MRU RegReference : S-1-5-18\software\nico mak computing\winzip\filemenu
obj[114]=MRU RegReference : S-1-5-19\software\nico mak computing\winzip\filemenu
obj[115]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\nico mak computing\winzip\filemenu
obj[116]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\EX_
obj[117]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\fnd
obj[118]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\gif
obj[119]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\htm
obj[120]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\html
obj[121]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\IFO
obj[122]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\INF
obj[123]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\jfif
obj[124]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\jpe
obj[125]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\jpeg
obj[126]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\jpg
obj[127]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\mp3
obj[128]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\mpeg
obj[129]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\mpg
obj[130]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\ncd
obj[131]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\nr3
obj[132]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\nra
obj[133]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\nri
obj[134]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\pdf
obj[135]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\png
obj[136]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\psd
obj[137]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\rar
obj[138]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\vob
obj[139]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\wav
obj[140]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\wmv
obj[141]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\zip
obj[143]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows\currentversion\explorer\findcomputermru
obj[150]=MRU RegReference : S-1-5-19\software\realnetworks\realplayer\6.0\preferences\MostRecentClips3
obj[151]=MRU RegReference : S-1-5-19\software\realnetworks\realplayer\6.0\preferences\MostRecentClips4
obj[152]=MRU RegReference : S-1-5-19\software\realnetworks\realplayer\6.0\preferences\MostRecentClips5
obj[164]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\realnetworks\realplayer\6.0\preferences\MostRecentSkins1
obj[146]=MRU RegReference : .DEFAULT\software\realnetworks\realplayer\6.0\preferences\LastLoginTime
obj[147]=MRU RegReference : S-1-5-18\software\realnetworks\realplayer\6.0\preferences\LastLoginTime
obj[148]=MRU RegReference : S-1-5-19\software\realnetworks\realplayer\6.0\preferences\LastLoginTime
obj[149]=MRU RegReference : S-1-5-19\software\realnetworks\realplayer\6.0\preferences\MostRecentClips2
obj[153]=MRU RegReference : S-1-5-19\software\realnetworks\realplayer\6.0\preferences\MostRecentClips6
obj[154]=MRU RegReference : S-1-5-19\software\realnetworks\realplayer\6.0\preferences\MostRecentClips7
obj[155]=MRU RegReference : S-1-5-19\software\realnetworks\realplayer\6.0\preferences\MostRecentClips8
obj[166]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\realnetworks\realplayer\6.0\preferences\LastLoginTime
obj[196]=MRU RegReference : .DEFAULT\software\microsoft\windows media\wmsdk\general computername
obj[197]=MRU RegReference : S-1-5-18\software\microsoft\windows media\wmsdk\general computername
obj[198]=MRU RegReference : S-1-5-19\software\microsoft\windows media\wmsdk\general computername
obj[199]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\windows media\wmsdk\general computername
obj[200]=MRU RegReference : S-1-5-21-1801674531-1606980848-1060284298-1003\software\winrar\dialogedithistory\extrpath
WIN32.TROJAN.BYTEVERIFY.A
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[131]=Regkey : interface\{22b3b001-82cb-4977-96e2-d55cebadce38}
obj[132]=RegValue : interface\{22b3b001-82cb-4977-96e2-d55cebadce38} ""
obj[138]=Regkey : typelib\{59e961b9-9acf-44fc-9bf5-003470cc2534}
SEARCHMAID
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[133]=Regkey : interface\{835baa68-b5e5-47d5-a18d-2a4e0f5b72d5}
obj[134]=RegValue : interface\{835baa68-b5e5-47d5-a18d-2a4e0f5b72d5} ""
obj[135]=Regkey : interface\{ab2dde8c-cbff-491a-9825-87b8bb4cbfe0}
obj[136]=RegValue : interface\{ab2dde8c-cbff-491a-9825-87b8bb4cbfe0} ""
obj[137]=Regkey : typelib\{42c7653a-5834-45a1-899a-ed0dfa370d21}
obj[156]=Regkey : software\microsoft\windows\currentversion\uninstall\virtual maidvirtual maid
obj[157]=RegValue : software\microsoft\windows\currentversion\uninstall\virtual maidvirtual maid "DisplayName"
obj[158]=RegValue : software\microsoft\windows\currentversion\uninstall\virtual maidvirtual maid "UninstallString"
obj[164]=Regkey : S-1-5-21-1801674531-1606980848-1060284298-1003\software\virtual maid
obj[169]=RegValue : software\microsoft\internet explorer\toolbar "{77B2F8DE-CB3F-4B6B-839B-807DD1ADBA1C}"
obj[182]=RegValue : software\microsoft\windows\currentversion\policies\explorer\run "notepad2.exe"
CRACKSPIDER
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[139]=Regkey : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\internet explorer\extensions\{10954c80-4f0f-11d3-b17c-00c0dfe39736}
obj[140]=RegValue : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\internet explorer\extensions\{10954c80-4f0f-11d3-b17c-00c0dfe39736} "ButtonText"
obj[141]=RegValue : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\internet explorer\extensions\{10954c80-4f0f-11d3-b17c-00c0dfe39736} "MenuText"
obj[142]=RegValue : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\internet explorer\extensions\{10954c80-4f0f-11d3-b17c-00c0dfe39736} "MenuStatusBar"
obj[143]=RegValue : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\internet explorer\extensions\{10954c80-4f0f-11d3-b17c-00c0dfe39736} "ClSid"
obj[144]=RegValue : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\internet explorer\extensions\{10954c80-4f0f-11d3-b17c-00c0dfe39736} "Default Visible"
obj[145]=RegValue : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\internet explorer\extensions\{10954c80-4f0f-11d3-b17c-00c0dfe39736} "Exec"
obj[146]=RegValue : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\internet explorer\extensions\{10954c80-4f0f-11d3-b17c-00c0dfe39736} "HotIcon"
obj[147]=RegValue : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\internet explorer\extensions\{10954c80-4f0f-11d3-b17c-00c0dfe39736} "Icon"
obj[247]=File : C:\WINDOWS\crcspider.ico
2020SEARCH
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[148]=Regkey : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\internet explorer\menuext\&rsdn search
obj[149]=RegValue : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\internet explorer\menuext\&rsdn search ""
obj[150]=RegValue : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\internet explorer\menuext\&rsdn search "Contexts"
obj[161]=Regkey : S-1-5-21-1801674531-1606980848-1060284298-1003\\software\microsoft\internet explorer\menuext\&rsdn search
obj[162]=RegValue : S-1-5-21-1801674531-1606980848-1060284298-1003\\software\microsoft\internet explorer\menuext\&rsdn search ""
obj[163]=RegValue : S-1-5-21-1801674531-1606980848-1060284298-1003\\software\microsoft\internet explorer\menuext\&rsdn search "Contexts"
ALTNETBDE
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[151]=Regkey : software\classes\interface\{ad5bc1f0-72d8-44b3-8e3d-8e8fecce43fb}
obj[152]=RegValue : software\classes\interface\{ad5bc1f0-72d8-44b3-8e3d-8e8fecce43fb} ""
WIN32.DOWNLOADER
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[153]=Regkey : software\microsoft\code store database\distribution units\{11111111-1111-1111-1111-111111111157}
obj[154]=RegValue : software\microsoft\code store database\distribution units\{11111111-1111-1111-1111-111111111157} "SystemComponent"
obj[155]=RegValue : software\microsoft\code store database\distribution units\{11111111-1111-1111-1111-111111111157} "Installer"
SECURITY IGUARD
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[159]=Regkey : software\rex-services
obj[160]=RegValue : software\rex-services "MGuid"
obj[183]=Folder : C:\Documents and Settings\Default\Application Data\Rex-Services
ALEXA
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[165]=RegValue : .DEFAULT\software\microsoft\internet explorer\extensions\cmdmapping "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
obj[166]=RegValue : S-1-5-18\software\microsoft\internet explorer\extensions\cmdmapping "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
obj[167]=RegValue : S-1-5-19\software\microsoft\internet explorer\extensions\cmdmapping "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
obj[168]=RegValue : S-1-5-21-1801674531-1606980848-1060284298-1003\software\microsoft\internet explorer\extensions\cmdmapping "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[170]=RegData : software\microsoft\windows nt\currentversion\winlogon "Shell"
POSSIBLE BROWSER HIJACK ATTEMPT
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[171]=RegData : S-1-5-19\Software\Microsoft\Internet Explorer\Main "Search Page"
obj[172]=RegData : S-1-5-19\Software\Microsoft\Internet Explorer\Main "Search Bar"
obj[173]=RegData : S-1-5-19\Software\Microsoft\Internet Explorer\Search "SearchAssistant"
obj[174]=RegData : S-1-5-19\Software\Microsoft\Internet Explorer "SearchURL"
obj[175]=RegData : S-1-5-19\Software\Microsoft\Internet Explorer\SearchURL "SearchURL"
obj[176]=RegData : S-1-5-21-1801674531-1606980848-1060284298-1003\Software\Microsoft\Internet Explorer "SearchURL"
obj[185]=File : C:\Documents and Settings\Default\Favorites\Poker.url
obj[186]=File : C:\Documents and Settings\Default\Favorites\Black Jack Online.url
obj[187]=File : C:\Documents and Settings\Default\Favorites\Online Gambling.url
obj[188]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy.url
obj[189]=File : C:\Documents and Settings\Default\Favorites\Spyware Removal.url
obj[190]=File : C:\Documents and Settings\Default\Favorites\Network Security.url
obj[191]=File : C:\Documents and Settings\Default\Favorites\Anti Spam.url
obj[192]=File : C:\Documents and Settings\Default\Favorites\Online Dating.url
obj[193]=File : C:\Documents and Settings\Default\Favorites\Sexual Life\Photo Personal.url
obj[194]=File : C:\Documents and Settings\Default\Favorites\Sexual Life\Escorts.url
obj[195]=File : C:\Documents and Settings\Default\Favorites\Sexual Life\Single Girls.url
obj[196]=File : C:\Documents and Settings\Default\Favorites\Sexual Life\Swinger Clubs.url
obj[197]=File : C:\Documents and Settings\Default\Favorites\Sexual Life\Adult Dating.url
obj[198]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Online Pharmacy.url
obj[199]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Adipex.url
obj[200]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Alprazolam.url
obj[201]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Ambien.url
obj[202]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Carisoprodol.url
obj[203]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Celebrex.url
obj[204]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Cipro.url
obj[205]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Clonazepam.url
obj[206]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Codeine.url
obj[207]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Diazepam.url
obj[208]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Hydrocodone.url
obj[209]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Lipitor.url
obj[210]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Lorazepam.url
obj[211]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Lorcet.url
obj[212]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Lortab.url
obj[213]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Norco.url
obj[214]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Paxil.url
obj[215]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Prozac.url
obj[216]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Ritalin.url
obj[217]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Steroids.url
obj[218]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Ultram.url
obj[219]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Valium.url
obj[220]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Viagra.url
obj[221]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Vicodin.url
obj[222]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Xanax.url
obj[223]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Zithromax.url
obj[224]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Zoloft.url
obj[225]=File : C:\Documents and Settings\Default\Favorites\Online Pharmacy\Zyban.url
obj[226]=File : C:\Documents and Settings\Default\Favorites\Internet\Spyware.url
obj[227]=File : C:\Documents and Settings\Default\Favorites\Internet\Spyware Remover.url
obj[228]=File : C:\Documents and Settings\Default\Favorites\Internet\Network Security.url
obj[229]=File : C:\Documents and Settings\Default\Favorites\Internet\Anti Spam Filters.url
obj[230]=File : C:\Documents and Settings\Default\Favorites\Internet\Antivirus.url
obj[231]=File : C:\Documents and Settings\Default\Favorites\Internet\Web Site Design.url
obj[232]=File : C:\Documents and Settings\Default\Favorites\Online Gambling\Online Casino.url
obj[233]=File : C:\Documents and Settings\Default\Favorites\Online Gambling\Online Gambling.url
obj[234]=File : C:\Documents and Settings\Default\Favorites\Online Gambling\Wagering.url
obj[235]=File : C:\Documents and Settings\Default\Favorites\Online Gambling\Online Poker.url
obj[236]=File : C:\Documents and Settings\Default\Favorites\Online Gambling\Black Jack.url
obj[237]=File : C:\Documents and Settings\Default\Favorites\Online Gambling\Online Slot Machines.url
obj[238]=File : C:\Documents and Settings\Default\Favorites\Online Gambling\Online Roulette.url
obj[239]=File : C:\Documents and Settings\Default\Favorites\Online Gambling\Sport Betting.url
obj[240]=File : C:\Documents and Settings\Default\Favorites\Online Gambling\Craps.url
obj[241]=File : C:\Documents and Settings\Default\Favorites\Online Gambling\Baccarat.url
obj[242]=File : C:\Documents and Settings\Default\Favorites\Online Gambling\Horse Racing.url
obj[243]=File : C:\Documents and Settings\Default\Favorites\Online Gambling\Black Jack Tips.url
obj[244]=File : C:\Documents and Settings\Default\Favorites\Online Gambling\Free Chips.url
obj[245]=File : C:\Documents and Settings\Default\Favorites\Online Gambling\Lottery.url
obj[246]=File : C:\Documents and Settings\Default\Favorites\Online Gambling\Bingo.url
TRACKING COOKIE
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[177]=IECache Entry : C:\Documents and Settings\Default\Cookies\default@mediaplex[1].txt
obj[178]=IECache Entry : C:\Documents and Settings\Default\Cookies\default@bluestreak[1].txt
obj[179]=IECache Entry : C:\Documents and Settings\Default\Cookies\default@atdmt[1].txt
obj[180]=IECache Entry : C:\Documents and Settings\Default\Cookies\[email protected][2].txt
obj[181]=IECache Entry : C:\Documents and Settings\Default\Cookies\default@doubleclick[1].txt
CYDOOR
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[184]=File : C:\WINDOWS\TEMP\_ad1A5.dll