Hey der.. i am zee back!.. hmm i did use killbox, but wat i did was that i browsed and found these files and then deleted them
ismaart of me no? heh. ne hows.. heres the report..its quite long!
WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.
If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.
»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP Current Build: Service Pack 2 Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180
»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»
Checking %SystemDrive% folder...
UPX! 08/10/2005 PM 11:44:14 218112 C:\HijackThis.exe
winsync 08/10/2005 PM 11:45:20 6989 C:\hijackthis.log
UPX! 18/10/2005 PM 07:23:54 354 C:\patterns.txt
FSG! 18/10/2005 PM 07:23:54 354 C:\patterns.txt
PEC2 18/10/2005 PM 07:23:54 354 C:\patterns.txt
PECompact2 18/10/2005 PM 07:23:54 354 C:\patterns.txt
Umonitor 18/10/2005 PM 07:23:54 354 C:\patterns.txt
qoologic 18/10/2005 PM 07:23:54 354 C:\patterns.txt
aspack 18/10/2005 PM 07:23:54 354 C:\patterns.txt
PTech 18/10/2005 PM 07:23:54 354 C:\patterns.txt
urllogic 18/10/2005 PM 07:23:54 354 C:\patterns.txt
ad-beh 18/10/2005 PM 07:23:54 354 C:\patterns.txt
ad-behNior.com 18/10/2005 PM 07:23:54 354 C:\patterns.txt
sYVLLSAKY 18/10/2005 PM 07:23:54 354 C:\patterns.txt
_rtneg3 18/10/2005 PM 07:23:54 354 C:\patterns.txt
SAHAgent 18/10/2005 PM 07:23:54 354 C:\patterns.txt
buddy.exe 18/10/2005 PM 07:23:54 354 C:\patterns.txt
ZepMon 18/10/2005 PM 07:23:54 354 C:\patterns.txt
aurora.exe 18/10/2005 PM 07:23:54 354 C:\patterns.txt
;2x(V]@BMD 18/10/2005 PM 07:23:54 354 C:\patterns.txt
Tlji7Mk 18/10/2005 PM 07:23:54 354 C:\patterns.txt
KavSvc 18/10/2005 PM 07:23:54 354 C:\patterns.txt
69.59.186.63 18/10/2005 PM 07:23:54 354 C:\patterns.txt
209.66.67.134 18/10/2005 PM 07:23:54 354 C:\patterns.txt
66.63.167.97 18/10/2005 PM 07:23:54 354 C:\patterns.txt
66.63.167.77 18/10/2005 PM 07:23:54 354 C:\patterns.txt
abetterinternet.com 18/10/2005 PM 07:23:54 354 C:\patterns.txt
8B!7F\(T 18/10/2005 PM 07:23:54 354 C:\patterns.txt
testpopup 18/10/2005 PM 07:23:54 354 C:\patterns.txt
web-nex 18/10/2005 PM 07:23:54 354 C:\patterns.txt
yourkey 18/10/2005 PM 07:23:54 354 C:\patterns.txt
winsync 18/10/2005 PM 07:23:54 354 C:\patterns.txt
rec2_run 18/10/2005 PM 07:23:54 354 C:\patterns.txt
WinShutDown 18/10/2005 PM 07:23:54 354 C:\patterns.txt
ad-w-a-r-e.com 18/10/2005 PM 07:23:54 354 C:\patterns.txt
UPX! 18/10/2005 PM 07:23:56 206336 C:\winpfind.exe
qoologic 18/10/2005 PM 04:41:24 202953 C:\WinPFind.zip
Checking %ProgramFilesDir% folder...
Checking %WinDir% folder...
SAHAgent 21/07/2005 PM 03:13:32 52224 C:\WINDOWS\2tnoo011.exe
PECompact2 02/10/2005 PM 02:01:36 15988639 C:\WINDOWS\LPT$VPN.869
qoologic 02/10/2005 PM 02:01:36 15988639 C:\WINDOWS\LPT$VPN.869
SAHAgent 02/10/2005 PM 02:01:36 15988639 C:\WINDOWS\LPT$VPN.869
UPX! 03/05/2005 AM 11:44:44 25157 C:\WINDOWS\RMAgentOutput.dll
UPX! 10/01/2005 PM 04:17:24 170053 C:\WINDOWS\tsc.exe
PECompact2 02/10/2005 PM 02:01:36 15988639 C:\WINDOWS\VPTNFILE.869
qoologic 02/10/2005 PM 02:01:36 15988639 C:\WINDOWS\VPTNFILE.869
SAHAgent 02/10/2005 PM 02:01:36 15988639 C:\WINDOWS\VPTNFILE.869
UPX! 18/02/2005 PM 06:40:14 1044560 C:\WINDOWS\vsapi32.dll
aspack 18/02/2005 PM 06:40:14 1044560 C:\WINDOWS\vsapi32.dll
Checking %System% folder...
SAHAgent 30/09/2005 PM 11:40:56 35 C:\WINDOWS\SYSTEM32\2tnoo011.ini
PEC2 18/11/1996 PM 12:00:00 748160 C:\WINDOWS\SYSTEM32\CO2C40EN.DLL
UPX! 17/09/2001 PM 01:20:02 9216 C:\WINDOWS\SYSTEM32\cpuinf32.dll
PEC2 23/08/2001 PM 05:00:00 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
SAHAgent 21/07/2005 PM 03:14:24 30720 C:\WINDOWS\SYSTEM32\hmti6006.exe
SAHAgent 30/09/2005 PM 11:40:56 35 C:\WINDOWS\SYSTEM32\hmti6006.ini
69.59.186.63 18/10/2005 PM 07:22:46 133120 C:\WINDOWS\SYSTEM32\kkeel.dll
209.66.67.134 18/10/2005 PM 07:22:46 133120 C:\WINDOWS\SYSTEM32\kkeel.dll
web-nex 18/10/2005 PM 07:22:46 133120 C:\WINDOWS\SYSTEM32\kkeel.dll
winsync 18/10/2005 PM 07:22:46 133120 C:\WINDOWS\SYSTEM32\kkeel.dll
69.59.186.63 18/10/2005 PM 07:22:46 181760 C:\WINDOWS\SYSTEM32\llrronc.dll
209.66.67.134 18/10/2005 PM 07:22:46 181760 C:\WINDOWS\SYSTEM32\llrronc.dll
web-nex 18/10/2005 PM 07:22:46 181760 C:\WINDOWS\SYSTEM32\llrronc.dll
winsync 18/10/2005 PM 07:22:46 181760 C:\WINDOWS\SYSTEM32\llrronc.dll
UPX! 31/10/2001 AM 11:14:40 30720 C:\WINDOWS\SYSTEM32\mplaa6.dll
UPX! 31/10/2001 AM 11:14:40 30208 C:\WINDOWS\SYSTEM32\mplam6.dll
UPX! 31/10/2001 AM 11:14:40 29184 C:\WINDOWS\SYSTEM32\mplapx.dll
UPX! 31/10/2001 AM 11:14:40 30720 C:\WINDOWS\SYSTEM32\mplaw7.dll
UPX! 31/10/2001 AM 11:14:40 215040 C:\WINDOWS\SYSTEM32\mplva6.dll
UPX! 31/10/2001 AM 11:14:40 203264 C:\WINDOWS\SYSTEM32\mplvm6.dll
UPX! 31/10/2001 AM 11:14:40 245760 C:\WINDOWS\SYSTEM32\mplvpx.dll
UPX! 31/10/2001 AM 11:14:40 211456 C:\WINDOWS\SYSTEM32\mplvw7.dll
aspack 04/08/2004 AM 03:56:38 708096 C:\WINDOWS\SYSTEM32\ntdll.dll
69.59.186.63 30/09/2005 PM 11:12:48 264704 C:\WINDOWS\SYSTEM32\qool3.exe
209.66.67.134 30/09/2005 PM 11:12:48 264704 C:\WINDOWS\SYSTEM32\qool3.exe
66.63.167.97 30/09/2005 PM 11:12:48 264704 C:\WINDOWS\SYSTEM32\qool3.exe
66.63.167.77 30/09/2005 PM 11:12:48 264704 C:\WINDOWS\SYSTEM32\qool3.exe
web-nex 30/09/2005 PM 11:12:48 264704 C:\WINDOWS\SYSTEM32\qool3.exe
winsync 30/09/2005 PM 11:12:48 264704 C:\WINDOWS\SYSTEM32\qool3.exe
rec2_run 30/09/2005 PM 11:12:48 264704 C:\WINDOWS\SYSTEM32\qool3.exe
Umonitor 04/08/2004 AM 03:56:46 657920 C:\WINDOWS\SYSTEM32\rasdlg.dll
SAHAgent 22/07/2005 PM 02:22:16 230400 C:\WINDOWS\SYSTEM32\rsphc5e9.exe
SAHAgent 01/10/2005 AM 10:55:38 3140 C:\WINDOWS\SYSTEM32\rsphc5e9.ini
UPX! 30/09/2005 PM 11:07:10 223232 C:\WINDOWS\SYSTEM32\uci.exe
winsync 23/08/2001 PM 05:00:00 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu
Checking %System%\Drivers folder and sub-folders...
Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts
Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
18/10/2005 PM 07:26:56 S 2048 C:\WINDOWS\bootstat.dat
30/09/2005 PM 11:14:48 S 50688 C:\WINDOWS\NDNuninstall6_38.exe
07/10/2005 PM 07:45:16 S 182272 C:\WINDOWS\NDNuninstall6_90.exe
25/08/2005 PM 07:32:42 H 54156 C:\WINDOWS\QTFont.qfn
18/10/2005 PM 07:14:10 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\0483d65bc374a85b8274f34e5935f6a2\BIT33A.tmp
18/10/2005 PM 07:12:34 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\0895e7ba3074ff06b086171e993094c0\BIT10.tmp
18/10/2005 PM 07:25:06 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\1f9b549b31aa4bd195878a487fdb1652\BIT3.tmp
18/10/2005 PM 07:12:48 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\23c929be5c0510672389df589a274f77\BIT11.tmp
18/10/2005 PM 07:13:08 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\380a38a73a09f3292579c9fb8f25506e\BIT12.tmp
18/10/2005 PM 07:13:58 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\4026cb0febf76a3da2bed800f68f0022\BIT15.tmp
18/10/2005 PM 07:25:22 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\4cb70271437bd595be5bedba46ddc04f\BIT9.tmp
18/10/2005 PM 07:25:14 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\51242e062b4e8600968057f111cf9b54\BIT4.tmp
18/10/2005 PM 07:11:38 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\5407e8c451ddfb412c72afc9f2c13337\BIT8.tmp
18/10/2005 PM 07:10:30 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\6a20958623cd045973c06f6b85b8be34\BIT7.tmp
18/10/2005 PM 07:12:14 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\7210e87e3912d997c94a92cc081e02d4\BITF.tmp
18/10/2005 PM 07:25:02 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\7d081e62713e8f25f8ea1d3688031b5d\BIT2.tmp
18/10/2005 PM 07:12:02 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\810c536d786592e0efb9852931bf1ba6\BITE.tmp
18/10/2005 PM 07:11:04 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\8a9c7d1cb99b6efff1f6b110c55b2ee9\BITC.tmp
18/10/2005 PM 07:14:04 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\8b394b842d9c4e6a28427fae777df59a\BIT339.tmp
18/10/2005 PM 07:24:58 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\8d224a8639d0d3cd94106bd72168312a\BIT1.tmp
18/10/2005 PM 07:13:16 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\981593429475ef0704f5014344a18469\BIT13.tmp
18/10/2005 PM 07:25:32 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\b2d5bf1528590d957dcebbe21530a5a7\BITA.tmp
18/10/2005 PM 07:11:26 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\d37c7e708fc2513c5b94b4befbcaf6e9\BITD.tmp
18/10/2005 PM 07:10:42 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\e6b7d12449da7f5e501f865d71be49c7\BITB.tmp
18/10/2005 PM 07:13:40 H 0 C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\e741c3aa4e1fa87dd7e863074c4e2e43\BIT14.tmp
14/10/2005 PM 05:21:40 HS 8192 C:\WINDOWS\system32\Thumbs.db
18/10/2005 PM 07:26:48 H 8192 C:\WINDOWS\system32\config\default.LOG
18/10/2005 PM 07:27:18 H 1024 C:\WINDOWS\system32\config\SAM.LOG
18/10/2005 PM 07:26:58 H 16384 C:\WINDOWS\system32\config\SECURITY.LOG
18/10/2005 PM 07:27:18 H 65536 C:\WINDOWS\system32\config\software.LOG
18/10/2005 PM 07:27:02 H 892928 C:\WINDOWS\system32\config\system.LOG
30/09/2005 PM 11:28:14 HS 113 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\desktop.ini
30/09/2005 PM 11:28:14 HS 113 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\desktop.ini
30/09/2005 PM 11:28:14 HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\desktop.ini
30/09/2005 PM 11:28:14 HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini
30/09/2005 PM 11:28:14 HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\459I6JE8\desktop.ini
30/09/2005 PM 11:28:14 HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\49WKZR9Y\desktop.ini
30/09/2005 PM 11:28:14 HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\D4IOS0W4\desktop.ini
30/09/2005 PM 11:28:14 HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\TB5HD03E\desktop.ini
18/10/2005 PM 07:25:38 H 6 C:\WINDOWS\Tasks\SA.DAT
14/10/2005 PM 05:20:52 HS 7168 C:\WINDOWS\Web\Thumbs.db
Checking for CPL files...
03/04/2003 AM 12:17:40 172032 C:\WINDOWS\SYSTEM32\ac3filter.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 68608 C:\WINDOWS\SYSTEM32\access.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 549888 C:\WINDOWS\SYSTEM32\appwiz.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 110592 C:\WINDOWS\SYSTEM32\bthprops.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 135168 C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 80384 C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 155136 C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 358400 C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 129536 C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 380416 C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 68608 C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems, Inc. 03/06/2005 AM 03:52:54 49265 C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation 23/08/2001 PM 05:00:00 187904 C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 618496 C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation 23/08/2001 PM 05:00:00 35840 C:\WINDOWS\SYSTEM32\ncpa.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 25600 C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 257024 C:\WINDOWS\SYSTEM32\nusrmgr.cpl
Microsoft Corporation 23/08/2001 PM 05:00:00 36864 C:\WINDOWS\SYSTEM32\nwc.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 32768 C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 114688 C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc. 23/09/2004 PM 06:57:40 323072 C:\WINDOWS\SYSTEM32\QuickTime.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 298496 C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation 23/08/2001 PM 05:00:00 28160 C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 94208 C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 148480 C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation 03/08/2004 PM 02:03:24 167704 C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 68608 C:\WINDOWS\SYSTEM32\dllcache\access.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 549888 C:\WINDOWS\SYSTEM32\dllcache\appwiz.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 135168 C:\WINDOWS\SYSTEM32\dllcache\desk.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 80384 C:\WINDOWS\SYSTEM32\dllcache\firewall.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 155136 C:\WINDOWS\SYSTEM32\dllcache\hdwwiz.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 358400 C:\WINDOWS\SYSTEM32\dllcache\inetcpl.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 129536 C:\WINDOWS\SYSTEM32\dllcache\intl.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 68608 C:\WINDOWS\SYSTEM32\dllcache\joy.cpl
Microsoft Corporation 23/08/2001 PM 05:00:00 187904 C:\WINDOWS\SYSTEM32\dllcache\main.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 618496 C:\WINDOWS\SYSTEM32\dllcache\mmsys.cpl
Microsoft Corporation 23/08/2001 PM 05:00:00 35840 C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 25600 C:\WINDOWS\SYSTEM32\dllcache\netsetup.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 257024 C:\WINDOWS\SYSTEM32\dllcache\nusrmgr.cpl
Microsoft Corporation 23/08/2001 PM 05:00:00 36864 C:\WINDOWS\SYSTEM32\dllcache\nwc.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 32768 C:\WINDOWS\SYSTEM32\dllcache\odbccp32.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 114688 C:\WINDOWS\SYSTEM32\dllcache\powercfg.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 155648 C:\WINDOWS\SYSTEM32\dllcache\sapi.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 298496 C:\WINDOWS\SYSTEM32\dllcache\sysdm.cpl
Microsoft Corporation 23/08/2001 PM 05:00:00 28160 C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 94208 C:\WINDOWS\SYSTEM32\dllcache\timedate.cpl
Microsoft Corporation 04/08/2004 AM 03:56:58 148480 C:\WINDOWS\SYSTEM32\dllcache\wscui.cpl
Microsoft Corporation 03/08/2004 PM 02:03:24 167704 C:\WINDOWS\SYSTEM32\dllcache\wuaucpl.cpl
»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»
Checking files in %ALLUSERSPROFILE%\Startup folder...
08/11/2004 PM 09:05:04 HS 84 C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\desktop.ini
18/10/2005 AM 06:52:44 417792 C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\rrkk.exe
05/10/2005 PM 11:24:10 785 C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Symantec AntiVirus Client (2).lnk
Checking files in %ALLUSERSPROFILE%\Application Data folder...
09/11/2004 AM 01:35:48 HS 62 C:\Documents and Settings\All Users.WINDOWS\Application Data\desktop.ini
Checking files in %USERPROFILE%\Startup folder...
08/11/2004 PM 09:05:04 HS 84 C:\Documents and Settings\Mehreen.USER245\Start Menu\Programs\Startup\desktop.ini
Checking files in %USERPROFILE%\Application Data folder...
09/11/2004 AM 01:35:46 HS 62 C:\Documents and Settings\Mehreen.USER245\Application Data\desktop.ini
24/09/2005 AM 10:24:54 105280 C:\Documents and Settings\Mehreen.USER245\Application Data\GDIPFONTCACHEV1.DAT
»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
SV1 =
acc=ventura5 =
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\LDVPMenu
{BDA77241-42F6-11d0-85E2-00AA001FE28C} = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\mmnnqkyk
{dd56d0cd-0785-4f9e-8097-6ae56ff9bae9} = C:\WINDOWS\system32\kkeel.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin = %SystemRoot%\system32\SHELL32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\LDVPMenu
{BDA77241-42F6-11d0-85E2-00AA001FE28C} = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}
= C:\WINDOWS\system32\wuauclt.dll
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}
PCTools Site Guard = C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B56A7D7D-6927-48C8-A975-17DF180C71AC}
PCTools Browser Monitor = C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = %SystemRoot%\system32\shdocvw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
MenuText = Sun Java Console : C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2D663D1A-8670-49D9-A1A5-4C56B4E14E84}
ButtonText = Spyware Doctor :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9E248641-0E24-4DDB-9A1F-705087832AD6}
MenuText = Java :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}
ButtonText = Yahoo! Messenger : C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
ButtonText = Messenger : C:\Program Files\Messenger\msmsgs.exe
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}
Favorites Band = %SystemRoot%\system32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}
History Band = %SystemRoot%\system32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}
Explorer Band = %SystemRoot%\system32\shdocvw.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\system32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\system32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll
{4E7BD74F-2B8D-469E-8DBC-A42EB79CB428} = COMMUNICATOR : C:\WINDOWS\system32\communicator.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
SunJavaUpdateSched C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
winsync C:\WINDOWS\system32\ddppuz.exe reg_run
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
IMAIL Installed = 1
MAPI Installed = 1
MSFS Installed = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
googletalk "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
msnmsgr "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
ctfmon.exe C:\WINDOWS\system32\ctfmon.exe
Spyware Doctor "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
MSMSGS "C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^rrkk.exe
path C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\rrkk.exe
backup C:\WINDOWS\pss\rrkk.exeCommon Startup
location Common Startup
command C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\rrkk.exe
item rrkk
path C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\rrkk.exe
backup C:\WINDOWS\pss\rrkk.exeCommon Startup
location Common Startup
command C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\rrkk.exe
item rrkk
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Mehreen.USER245^Start Menu^Programs^Startup^Zeno.lnk
path C:\Documents and Settings\Mehreen.USER245\Start Menu\Programs\Startup\Zeno.lnk
backup C:\WINDOWS\pss\Zeno.lnkStartup
location Startup
command C:\WINDOWS\system32\ysysrx6d.exe DO0605
item Zeno
path C:\Documents and Settings\Mehreen.USER245\Start Menu\Programs\Startup\Zeno.lnk
backup C:\WINDOWS\pss\Zeno.lnkStartup
location Startup
command C:\WINDOWS\system32\ysysrx6d.exe DO0605
item Zeno
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Mehreen.USER245^Start Menu^Programs^Startup^Zstart.lnk
path C:\Documents and Settings\Mehreen.USER245\Start Menu\Programs\Startup\Zstart.lnk
backup C:\WINDOWS\pss\Zstart.lnkStartup
location Startup
command C:\WINDOWS\system32\cxdxregt.exe DO0605
item Zstart
path C:\Documents and Settings\Mehreen.USER245\Start Menu\Programs\Startup\Zstart.lnk
backup C:\WINDOWS\pss\Zstart.lnkStartup
location Startup
command C:\WINDOWS\system32\cxdxregt.exe DO0605
item Zstart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\002
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item medgs1
hkey HKLM
command C:\WINDOWS\system32\medgs1.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item medgs1
hkey HKLM
command C:\WINDOWS\system32\medgs1.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\180ClientStubInstall
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item sais
hkey HKCU
command "C:\DOCUME~1\MEHREE~1.USE\LOCALS~1\Temp\sais.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item sais
hkey HKCU
command "C:\DOCUME~1\MEHREE~1.USE\LOCALS~1\Temp\sais.exe"
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BluetoothAuthenticationAgent
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item rundll32
hkey HKLM
command rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item rundll32
hkey HKLM
command rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BrowserUpdateSched
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ysysrx6d
hkey HKLM
command C:\WINDOWS\system32\ysysrx6d.exe DO0605
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ysysrx6d
hkey HKLM
command C:\WINDOWS\system32\ysysrx6d.exe DO0605
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\buxo
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item buxo
hkey HKLM
command C:\WINDOWS\system32\rycy\buxo.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item buxo
hkey HKLM
command C:\WINDOWS\system32\rycy\buxo.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CardGate
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CardGate
hkey HKLM
command "C:\Program Files\Softick\CardExport\CardGate.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CardGate
hkey HKLM
command "C:\Program Files\Softick\CardExport\CardGate.exe"
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CAS Client
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item casclient
hkey HKCU
command "C:\Program Files\Cas\Client\casclient.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item casclient
hkey HKCU
command "C:\Program Files\Cas\Client\casclient.exe"
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ccApp
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ccApp
hkey HKLM
command "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ccApp
hkey HKLM
command "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ChoUqTx4
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item iwgebn
hkey HKLM
command C:\WINDOWS\iwgebn.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item iwgebn
hkey HKLM
command C:\WINDOWS\iwgebn.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ctfmon.exe
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ctfmon
hkey HKCU
command C:\WINDOWS\system32\ctfmon.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ctfmon
hkey HKCU
command C:\WINDOWS\system32\ctfmon.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DNS
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item mc-58-12-0000119
hkey HKCU
command C:\Program Files\Common Files\mc-58-12-0000119.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item mc-58-12-0000119
hkey HKCU
command C:\Program Files\Common Files\mc-58-12-0000119.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\exp.exe
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item exp
hkey HKLM
command C:\WINDOWS\system32\exp.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item exp
hkey HKLM
command C:\WINDOWS\system32\exp.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\googletalk
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item googletalk
hkey HKCU
command "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item googletalk
hkey HKCU
command "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GsAds
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item gms2
hkey HKLM
command C:\WINDOWS\system32\gms2.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item gms2
hkey HKLM
command C:\WINDOWS\system32\gms2.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IST Service
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item istsvc
hkey HKLM
command C:\Program Files\ISTsvc\istsvc.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item istsvc
hkey HKLM
command C:\Program Files\ISTsvc\istsvc.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\iTunesHelper
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item iTunesHelper
hkey HKLM
command C:\Program Files\iTunes\iTunesHelper.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item iTunesHelper
hkey HKLM
command C:\Program Files\iTunes\iTunesHelper.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Media Access
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item MediaAccK
hkey HKLM
command C:\Program Files\Media Access\MediaAccK.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item MediaAccK
hkey HKLM
command C:\Program Files\Media Access\MediaAccK.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSMSGS
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item msmsgs
hkey HKCU
command "C:\Program Files\Messenger\msmsgs.exe" /background
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item msmsgs
hkey HKCU
command "C:\Program Files\Messenger\msmsgs.exe" /background
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\msnmsgr
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item msnmsgr
hkey HKCU
command "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item msnmsgr
hkey HKCU
command "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\New.net Startup
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NEWDOT~1
hkey HKLM
command rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NEWDOT~1
hkey HKLM
command rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\opr
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item opr
hkey HKLM
command C:\WINDOWS\system32\opr.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item opr
hkey HKLM
command C:\WINDOWS\system32\opr.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Power Scan
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item powerscan
hkey HKLM
command C:\Program Files\Power Scan\powerscan.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item powerscan
hkey HKLM
command C:\Program Files\Power Scan\powerscan.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PSof1
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item PSof1
hkey HKLM
command C:\WINDOWS\system32\PSof1.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item PSof1
hkey HKLM
command C:\WINDOWS\system32\PSof1.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item qttask
hkey HKLM
command "C:\Program Files\QuickTime\qttask.exe" -atboottime
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item qttask
hkey HKLM
command "C:\Program Files\QuickTime\qttask.exe" -atboottime
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\rsphc5e9
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item rsphc5e9
hkey HKLM
command C:\WINDOWS\system32\rsphc5e9.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item rsphc5e9
hkey HKLM
command C:\WINDOWS\system32\rsphc5e9.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\services32
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item mc-58-12-0000119
hkey HKCU
command C:\Program Files\Common Files\Windows\mc-58-12-0000119.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item mc-58-12-0000119
hkey HKCU
command C:\Program Files\Common Files\Windows\mc-58-12-0000119.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\stb
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item stb
hkey HKLM
command C:\WINDOWS\system32\stb.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item stb
hkey HKLM
command C:\WINDOWS\system32\stb.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SurfAccuracy
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item SAcc
hkey HKLM
command C:\Program Files\SurfAccuracy\SAcc.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item SAcc
hkey HKLM
command C:\Program Files\SurfAccuracy\SAcc.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\System service70
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item pokapoka70
hkey HKLM
command C:\WINDOWS\\\etb\\pokapoka70.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item pokapoka70
hkey HKLM
command C:\WINDOWS\\\etb\\pokapoka70.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TkBellExe
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item realsched
hkey HKLM
command "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item realsched
hkey HKLM
command "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\vptray
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item vptray
hkey HKLM
command C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item vptray
hkey HKLM
command C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\winsync
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ssggdd
hkey HKLM
command C:\WINDOWS\system32\ssggdd.exe reg_run
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ssggdd
hkey HKLM
command C:\WINDOWS\system32\ssggdd.exe reg_run
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinTask driver
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item wintask
hkey HKLM
command C:\WINDOWS\system32\wintask.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item wintask
hkey HKLM
command C:\WINDOWS\system32\wintask.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ZStart
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item wpdxregv
hkey HKLM
command c:\windows\system32\wpdxregv.exe DO0605
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item wpdxregv
hkey HKLM
command c:\windows\system32\wpdxregv.exe DO0605
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item gnotify
hkey HKLM
command C:\Program Files\Google\Gmail Notifier\G001-1.0.24.0\gnotify.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item gnotify
hkey HKLM
command C:\Program Files\Google\Gmail Notifier\G001-1.0.24.0\gnotify.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state
system.ini 0
win.ini 0
bootini 0
services 0
startup 2
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
{0DF44EAA-FF21-4412-828E-260A8728E7F1} =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1
undockwithoutlogon 1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations
LowRiskFileTypes .zip;.rar;.cab;.txt;.exe;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mov;.mp3;.wav
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun 145
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
DisableRegistryTools 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
PostBootReminder {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
CDBurn {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\system32\webcheck.dll
SysTray {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\system32\stobject.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
Shell = Explorer.exe
System =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon
= C:\WINDOWS\system32\NavLogon.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
= wlnotify.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs
»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.4.1 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 18/10/2005 PM 07:40:20