========== FILES ==========
< reg query HKEY_CLASSES_ROOT\.exe /s /c >
! REG.EXE VERSION 3.0
HKEY_CLASSES_ROOT\.exe
<NO NAME> REG_SZ exefile
I:\Documents and Settings\Administrator\Desktop\cmd.bat deleted successfully.
I:\Documents and Settings\Administrator\Desktop\cmd.txt deleted successfully.
< reg query HKEY_CLASSES_ROOT\exefile /s /c >
! REG.EXE VERSION 3.0
HKEY_CLASSES_ROOT\exefile
<NO NAME> REG_SZ Application
Content Type REG_SZ application/x-msdownload
EditFlags REG_BINARY 38070000
InfoTip REG_SZ prop:FileDescription;Company;FileVersion;Create;Size
TileInfo REG_SZ prop:FileDescription;Company;FileVersion
HKEY_CLASSES_ROOT\exefile\DefaultIcon
<NO NAME> REG_SZ %1
HKEY_CLASSES_ROOT\exefile\shell
HKEY_CLASSES_ROOT\exefile\shell\open
EditFlags REG_BINARY 00000000
HKEY_CLASSES_ROOT\exefile\shell\open\command
<NO NAME> REG_SZ "%1" %*
IsolatedCommand REG_SZ "%1" %*
HKEY_CLASSES_ROOT\exefile\shell\runas
HKEY_CLASSES_ROOT\exefile\shell\runas\command
<NO NAME> REG_SZ "%1" %*
IsolatedCommand REG_SZ "%1" %*
HKEY_CLASSES_ROOT\exefile\shell\start
HKEY_CLASSES_ROOT\exefile\shell\start\command
<NO NAME> REG_SZ "%1" %*
IsolatedCommand REG_SZ "%1" %*
HKEY_CLASSES_ROOT\exefile\shellex
HKEY_CLASSES_ROOT\exefile\shellex\DropHandler
<NO NAME> REG_SZ {86C86720-42A0-1069-A2E8-08002B30309D}
HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers
HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\PEAnalyser
<NO NAME> REG_SZ {09A63660-16F9-11d0-B1DF-004F56001CA7}
HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\PifProps
<NO NAME> REG_SZ {86F19A00-42A0-1069-A2E9-08002B30309D}
HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\ShimLayer Property Page
<NO NAME> REG_SZ {513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}
I:\Documents and Settings\Administrator\Desktop\cmd.bat deleted successfully.
I:\Documents and Settings\Administrator\Desktop\cmd.txt deleted successfully.
< reg query HKEY_CLASSES_ROOT\CLSID\{098f2470-bae0-11cd-b579-08002b30bfeb} /s /c >
! REG.EXE VERSION 3.0
HKEY_CLASSES_ROOT\CLSID\{098f2470-bae0-11cd-b579-08002b30bfeb}
<NO NAME> REG_SZ Null persistent handler
HKEY_CLASSES_ROOT\CLSID\{098f2470-bae0-11cd-b579-08002b30bfeb}\PersistentAddinsRegistered
HKEY_CLASSES_ROOT\CLSID\{098f2470-bae0-11cd-b579-08002b30bfeb}\PersistentAddinsRegistered\{89BCB740-6119-101A-BCB7-00DD010655AF}
<NO NAME> REG_SZ {c3278e90-bea7-11cd-b579-08002b30bfeb}
I:\Documents and Settings\Administrator\Desktop\cmd.bat deleted successfully.
I:\Documents and Settings\Administrator\Desktop\cmd.txt deleted successfully.
< reg query HKEY_CURRENT_USER\Software\Classes\.exe /s /c >
I:\Documents and Settings\Administrator\Desktop\cmd.bat deleted successfully.
I:\Documents and Settings\Administrator\Desktop\cmd.txt deleted successfully.
< reg query HKEY_CURRENT_USER\Software\Classes\exefile /s /c >
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Classes\exefile
<NO NAME> REG_SZ Application
Content Type REG_SZ application/x-msdownload
EditFlags REG_BINARY 38070000
TileInfo REG_SZ prop:FileDescription;Company;FileVersion
InfoTip REG_SZ prop:FileDescription;Company;FileVersion;Create;Size
HKEY_CURRENT_USER\Software\Classes\exefile\DefaultIcon
<NO NAME> REG_SZ %1
HKEY_CURRENT_USER\Software\Classes\exefile\shell
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open
EditFlags REG_BINARY 00000000
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command
<NO NAME> REG_SZ "%1" %*
IsolatedCommand REG_SZ "%1" %*
HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas
HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command
<NO NAME> REG_SZ "%1" %*
IsolatedCommand REG_SZ "%1" %*
HKEY_CURRENT_USER\Software\Classes\exefile\shell\start
HKEY_CURRENT_USER\Software\Classes\exefile\shell\start\command
<NO NAME> REG_SZ "%1" %*
IsolatedCommand REG_SZ "%1" %*
I:\Documents and Settings\Administrator\Desktop\cmd.bat deleted successfully.
I:\Documents and Settings\Administrator\Desktop\cmd.txt deleted successfully.
< reg query HKEY_CURRENT_USER\Software\Classes\CLSID\{098f2470-bae0-11cd-b579-08002b30bfeb} /s /c >
I:\Documents and Settings\Administrator\Desktop\cmd.bat deleted successfully.
I:\Documents and Settings\Administrator\Desktop\cmd.txt deleted successfully.
< reg query HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe /s /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe
<NO NAME> REG_SZ exefile
I:\Documents and Settings\Administrator\Desktop\cmd.bat deleted successfully.
I:\Documents and Settings\Administrator\Desktop\cmd.txt deleted successfully.
< reg query HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile /s /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile
<NO NAME> REG_SZ Application
EditFlags REG_BINARY 38070000
TileInfo REG_SZ prop:FileDescription;Company;FileVersion
InfoTip REG_SZ prop:FileDescription;Company;FileVersion;Create;Size
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\DefaultIcon
<NO NAME> REG_SZ %1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open
EditFlags REG_BINARY 00000000
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command
<NO NAME> REG_SZ "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\runas
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\runas\command
<NO NAME> REG_SZ "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shellex\DropHandler
<NO NAME> REG_SZ {86C86720-42A0-1069-A2E8-08002B30309D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shellex\PropertySheetHandlers\PEAnalyser
<NO NAME> REG_SZ {09A63660-16F9-11d0-B1DF-004F56001CA7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shellex\PropertySheetHandlers\PifProps
<NO NAME> REG_SZ {86F19A00-42A0-1069-A2E9-08002B30309D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shellex\PropertySheetHandlers\ShimLayer Property Page
<NO NAME> REG_SZ {513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}
I:\Documents and Settings\Administrator\Desktop\cmd.bat deleted successfully.
I:\Documents and Settings\Administrator\Desktop\cmd.txt deleted successfully.
< reg query HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{098f2470-bae0-11cd-b579-08002b30bfeb} /s /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{098f2470-bae0-11cd-b579-08002b30bfeb}
<NO NAME> REG_SZ Null persistent handler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{098f2470-bae0-11cd-b579-08002b30bfeb}\PersistentAddinsRegistered
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{098f2470-bae0-11cd-b579-08002b30bfeb}\PersistentAddinsRegistered\{89BCB740-6119-101A-BCB7-00DD010655AF}
<NO NAME> REG_SZ {c3278e90-bea7-11cd-b579-08002b30bfeb}
I:\Documents and Settings\Administrator\Desktop\cmd.bat deleted successfully.
I:\Documents and Settings\Administrator\Desktop\cmd.txt deleted successfully.
OTL by OldTimer - Version 3.2.31.0 log created on 11212011_145624