View Full Version : :oops:Zlob DNSchanger has taken over hii guys please help
sexy_ladii05
2008-08-22, 21:39
hey guys i know i cant do a man job lol but can you help me out for girl like me can firgure it out thank use small words please :)
_______________________________________________________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:37:56, on 17/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: fdkowvbp - {AE7F9E1E-0A21-46C0-91D9-01F9D1ACB887} - (no file)
O4 - HKLM\..\Run: [One view global this] C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW\Third Mapi.exe
O4 - HKLM\..\Run: [AIMWDInstallFilename] C:\Program Files\AIM\AIMWDInstall.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [643d5b23] rundll32.exe "C:\WINDOWS\system32\fwgvlrty.dll",b
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O20 - AppInit_DLLs: ttdewk.dll,vuwofs.dll,jouuki.dll nlrybv.dll
O21 - SSODL: mZUCnvnJwQdJ - {643D5B8D-CE97-F127-8EAA-33AA7BB4B098} - C:\WINDOWS\system32\zgj.dll
O22 - SharedTaskScheduler: Deskscapes - {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
--
End of file - 4633 bytes
sexy_ladii05
2008-08-22, 21:52
hey guys im kinda new here but i was looking up my promblem and people had the same one but i just want say thank you in a adavance i cant wait for someone to help me with my promblem so i can donate some money so people can get more help from you guys cant wait till someone looks at my promblem thanks for your time this forum ROCKs :)
Hi and welcome :)
What makes you think girls can't do computer stuff?
There's lots of ladies here & several other forums that can do anything on a computer.
When you start thinking you can't do stuff cus you're a lady --- that is when you're giving up on life.
And I won't take 'give up' for an answer to anything or "I cant do it cus I'm a girl" for an answer either. :nono:
You do however have a nasty bunch of infections on that machine. :yuck:
Let's see if we can get things back in order -- shall we?
First we need to find out what version of XP you have.
Home or Pro or Media Center?
Right click "my computer" then "properties"
It will tell you in the general tab.
Let me know please.
Then we can continue.
Thanks :)
sexy_ladii05
2008-08-22, 22:18
lol sorry i wont give up just im so frausted thank for relpying
here my information
system:microsoft windows xp
pro
verison 2002
service pack 2
registered to:santa
virus alert!
computer:intel pentium lll processor
449 mhz 256 mb ram
is that what you want and im runnig under safe mode with networking
cause i cant use programs cause virtual low memory thx =]
Thanks :)
I can understand how frustrated this stuff can get.
I was there at one time too.
---------------------
Download this file instead and save it to the desktop:
http://www.microsoft.com/downloads/details.aspx?FamilyId=535D248D-5E10-49B5-B80C-0A0205368124
Do nothing with it yet.
Once you have that file.....
Download Combofix from any of the links below, and save it to your desktop.
Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
Link 3 (http://subs.geekstogo.com/ComboFix.exe)
**Note: It is important that it is saved directly to your desktop**
The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.
Drag the file you downloaded from Microsoft and drop it on top of ComboFix.
Let it run.
Follow prompts from Combofix.
Once installed, you should see a blue screen prompt that says:
The Recovery Console was successfully installed.
Please continue as follows:
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Click Yes to allow ComboFix to continue scanning for malware.
It will reboot the system. Please try to get back to safe mode so it can finish without Norton interfering.
When the tool is finished, it will produce a report for you.
When the report pops up you can close this & reboot back to normal mode.
Please include the following reports for further review, and so we may continue cleansing the system:
C:\ComboFix.txt
--Do not mouseclick combofix's window while it's running. That may cause it to stall
--ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
--Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell me.
--Your internet connection will be terminated while ComboFix runs. Do Not attempt to re-enable it. Should ComboFix terminate prematurely, restart the computer to restore connectivity.
Let me know how the system is running please.
Let me know if you still get memory errors while in normal mode.
We likely will still have work to do.
Thanks :)
sexy_ladii05
2008-08-22, 22:40
:sad::sad: oh my god i dont know whats going on here what im getting for the links you give me
The requested URL /ComboFix.exe was not found on this server.
Apache/2.0.52 (CentOS) Server at subs.geekstogo.com Port 80
The requested URL /downloads/details.aspx was not found on this server.
Apache/2.0.52 (CentOS) Server at www.microsoft.com Port 80
please dont give up on me please
sexy_ladii05
2008-08-22, 22:50
:sad::sad: oh my god i dont know whats going on here what im getting for the links you give me
The requested URL /ComboFix.exe was not found on this server.
Apache/2.0.52 (CentOS) Server at subs.geekstogo.com Port 80
The requested URL /downloads/details.aspx was not found on this server.
Apache/2.0.52 (CentOS) Server at www.microsoft.com Port 80
please dont give up on me please
i have combofix now but not the windows program can you help me =]
Can you get to microsoft site?
How about here?:
http://support.microsoft.com/kb/310994
If you can get there ---- try & download the file for Windows XP Professional Service Pack 2
Thanks
sexy_ladii05
2008-08-22, 23:19
:sad:can you send it on a download link or sumthing i cant get to it when i got combofix it didnt bring me to website just send save or open can you do that to if you getting to annoyed with me im sorryill wait for some to help me i dont want to waste your time =[
That's OK..
You're not wasting my time.
If I didn't have time -- I would have had someone else post. :)
The malware is likely blocking you from getting to Microsoft.
We'll try for it next round.
Go ahead & double click Combofix.exe
Let it do its thing.
Don't click in the combofix window while it is running or it might stall.
When it is done please post the report it gives.
If needed -- go back to safe mode to post if you have trouble getting here in normal mode.
Let me know how things are.
Don't do anything else till I reply back please.
Thanks :)
sexy_ladii05
2008-08-22, 23:30
omg omg please help its saying data error 17 07 2008 check your settings
sexy_ladii05
2008-08-22, 23:42
i think did sumthing cus now running under normal mode and there no virtual memory pop up and i can run sum programs at the same time
Ok :)
Please copy/paste this log in your next reply:
C:\Combofix.txt
Thanks :)
sexy_ladii05
2008-08-23, 00:01
i dont have a log :sad: after combox loads a blue box cums up and says 17 07 08 error please check your settings
please dont give up on me
Is there a log called bug.txt in c:\ ?
If so -- post it please.
sexy_ladii05
2008-08-23, 00:10
i dont get what your saying :sad:
Open My computer then C:\
Look for file called "bug.txt"
If present please cop[y/paste it back here.
It should tell me or the combofix creator what is wrong or where the program went wrong
Can you try that microsoft site again please?
http://www.microsoft.com/downloads/details.aspx?FamilyId=535D248D-5E10-49B5-B80C-0A0205368124
If you can get that file --- go ahead and download it but don't run it.
Just save it to the desktop for now.
Post new Hijackthis log too please.
Thanks :)
sexy_ladii05
2008-08-23, 00:19
agh omg im just a dum blonde :sad: i cant see nothing and that microsft dont work
sexy_ladii05
2008-08-23, 00:22
agh omg im just a dum blonde :sad: i cant see nothing and that microsft dont work
here a new log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:22:29, on 17/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\AIM\AIMWDInstall.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: fdkowvbp - {AE7F9E1E-0A21-46C0-91D9-01F9D1ACB887} - (no file)
O4 - HKLM\..\Run: [One view global this] C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW\Third Mapi.exe
O4 - HKLM\..\Run: [AIMWDInstallFilename] C:\Program Files\AIM\AIMWDInstall.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [643d5b23] rundll32.exe "C:\WINDOWS\system32\fwgvlrty.dll",b
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O21 - SSODL: mZUCnvnJwQdJ - {643D5B8D-CE97-F127-8EAA-33AA7BB4B098} - C:\WINDOWS\system32\zgj.dll
O22 - SharedTaskScheduler: Deskscapes - {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
--
End of file - 4918 bytes
Hey! Watch that dum blonde stuff --- I am blonde too!! :laugh:
Can you get Hijackthis to run?
See if you can get it to run & have it create a new log please.
If it wont -- go back to safe mode with networking and try again please.
Thanks :)
Sorry -- we cross posted. :)
Can you post a uninstall log please?
Start Hijackthis
Click "config" at lower right
Click
misc tools"
Click "open uninstall manager"
Click "save list..."
Save the list someplace handy & post it here.
Thanks :)
sexy_ladii05
2008-08-23, 00:28
lol srry there a new log on top of yuh lol
but here it is again
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:22:29, on 17/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\AIM\AIMWDInstall.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: fdkowvbp - {AE7F9E1E-0A21-46C0-91D9-01F9D1ACB887} - (no file)
O4 - HKLM\..\Run: [One view global this] C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW\Third Mapi.exe
O4 - HKLM\..\Run: [AIMWDInstallFilename] C:\Program Files\AIM\AIMWDInstall.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [643d5b23] rundll32.exe "C:\WINDOWS\system32\fwgvlrty.dll",b
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O21 - SSODL: mZUCnvnJwQdJ - {643D5B8D-CE97-F127-8EAA-33AA7BB4B098} - C:\WINDOWS\system32\zgj.dll
O22 - SharedTaskScheduler: Deskscapes - {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
--
End of file - 4918 bytes
Once you post the uninstall list please do this:
Download Gmer from here:
http://www.gmer.net/gmer.zip
Unzip it to its own folder.
Disconnect from internet & shut down Antivirus to prevent conflicts.
Shut down also any other unneeded apps including any open browser windows.
The less stuff we got running the less chance of false positives in log.
Double click gmer.exe to run it.
Allow driver to install if asked (gmer.sys)
You may get a warning at program start that there is possible rootkit activity and do you want to run scan.
Say OK to run scan.
If no warning, just click "scan".
Let the scan finish.
Once done press "save"
In the new window that pops up, give the log a name and save it someplace handy.
Press save.
Re-enable your antivirus, re-connect to internet & post that log here
Let me know if Gmer gives any problems.
Thanks :)
**
I have to head out for a couple hours. I'll be back tho ok?
Mom needs me for a bit.
sexy_ladii05
2008-08-23, 00:32
i dont think my computer likes me i click save list then the program shuts down should i try 2 run program under safe mde
sexy_ladii05
2008-08-23, 01:04
the second part on the other 1
---- System - GMER 1.0.14 ----
SSDT spvr.sys ZwCreateKey [0xF9A110E0]
SSDT spvr.sys ZwEnumerateKey [0xF9A2FCA2]
SSDT spvr.sys ZwEnumerateValueKey [0xF9A30030]
SSDT spvr.sys ZwOpenKey [0xF9A110C0]
SSDT spvr.sys ZwQueryKey [0xF9A30108]
SSDT spvr.sys ZwQueryValueKey [0xF9A2FF88]
SSDT spvr.sys ZwSetValueKey [0xF9A3019A]
INT 0x3A ? 826E2BF8
INT 0x3E ? 82774BF8
INT 0x3F ? 82774BF8
---- Kernel code sections - GMER 1.0.14 ----
? spvr.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F97AF62C 5 Bytes JMP 826E21D8
---- Kernel IAT/EAT - GMER 1.0.14 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 827792D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F9A42C4C] spvr.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F9A42CA0] spvr.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F9A12040] spvr.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F9A1213C] spvr.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F9A120BE] spvr.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F9A127FC] spvr.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F9A126D2] spvr.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F9A22048] spvr.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 826E22D8
---- Devices - GMER 1.0.14 ----
Device \FileSystem\Fastfat \FatCdrom 827721F8
Device \Driver\usbuhci \Device\USBPDO-0 826E11F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 827751F8
Device \Driver\dmio \Device\DmControl\DmConfig 827751F8
Device \Driver\dmio \Device\DmControl\DmPnP 827751F8
Device \Driver\dmio \Device\DmControl\DmInfo 827751F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 827761F8
Device \Driver\Cdrom \Device\CdRom0 8272F1F8
Device \Driver\Cdrom \Device\CdRom1 8272F1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 827741F8
Device \Driver\atapi \Device\Ide\IdePort0 827741F8
Device \Driver\atapi \Device\Ide\IdePort1 827741F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 827741F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f 827741F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 826391F8
Device \Driver\NetBT \Device\NetbiosSmb 826391F8
Device \Driver\usbuhci \Device\USBFDO-0 826E11F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 826311F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 826311F8
Device \Driver\Ftdisk \Device\FtControl 827761F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{2F13C5B1-BB9C-4EC3-AD9B-C44E0106AD62} 826391F8
Device \FileSystem\Fastfat \Fat 827721F8
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs 823BF1F8
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAB 0xEE 0x03 0xDC ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xDC 0x87 0x4E 0x37 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAB 0xEE 0x03 0xDC ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xDC 0x87 0x4E 0x37 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs ttdewk.dll,vuwofs.dll,jouuki.dll nlrybv.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@LoadAppInit_DLLs 1
Reg HKLM\SOFTWARE\Classes\.7z@ WinRAR
Reg HKLM\SOFTWARE\Classes\.ace@ WinRAR
Reg HKLM\SOFTWARE\Classes\.aim@ .aim
Reg HKLM\SOFTWARE\Classes\.aim@Content Type application/x-aim
Reg HKLM\SOFTWARE\Classes\.amo@ amofile
Reg HKLM\SOFTWARE\Classes\.amo@Content Type application/x-aim+amo
Reg HKLM\SOFTWARE\Classes\.amo@ContentType application/x-amo
Reg HKLM\SOFTWARE\Classes\.arj@ WinRAR
Reg HKLM\SOFTWARE\Classes\.blt@ bltfile
Reg HKLM\SOFTWARE\Classes\.blt@ContentType application/x-blt
Reg HKLM\SOFTWARE\Classes\.bz@ WinRAR
Reg HKLM\SOFTWARE\Classes\.bz2@ WinRAR
Reg HKLM\SOFTWARE\Classes\.cab@ WinRAR
Reg HKLM\SOFTWARE\Classes\.cdf@ ChannelFile
Reg HKLM\SOFTWARE\Classes\.cdf@Content Type application/x-cdf
Reg HKLM\SOFTWARE\Classes\.disabled@ SpybotSD.DisabledFile
Reg HKLM\SOFTWARE\Classes\.eps@Content Type application/postscript
Reg HKLM\SOFTWARE\Classes\.eps\PersistentHandler
Reg HKLM\SOFTWARE\Classes\.eps\PersistentHandler@ {098f2470-bae0-11cd-b579-08002b30bfeb}
Reg HKLM\SOFTWARE\Classes\.gz@ WinRAR
Reg HKLM\SOFTWARE\Classes\.hqx@Content Type application/mac-binhex40
Reg HKLM\SOFTWARE\Classes\.hqx\PersistentHandler
Reg HKLM\SOFTWARE\Classes\.hqx\PersistentHandler@ {098f2470-bae0-11cd-b579-08002b30bfeb}
Reg HKLM\SOFTWARE\Classes\.iso@ WinRAR
Reg HKLM\SOFTWARE\Classes\.jar@ WinRAR
Reg HKLM\SOFTWARE\Classes\.lha@ WinRAR
Reg HKLM\SOFTWARE\Classes\.lzh@ WinRAR
Reg HKLM\SOFTWARE\Classes\.ocp@ AOL.ocpcontrol
Reg HKLM\SOFTWARE\Classes\.ocp@Content Type text/ocp
Reg HKLM\SOFTWARE\Classes\.pic\PersistentHandler
Reg HKLM\SOFTWARE\Classes\.pic\PersistentHandler@ {098f2470-bae0-11cd-b579-08002b30bfeb}
Reg HKLM\SOFTWARE\Classes\.prf@ prffile
Reg HKLM\SOFTWARE\Classes\.prf@Content Type application/pics-rules
Reg HKLM\SOFTWARE\Classes\.r00@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r01@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r02@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r03@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r04@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r05@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r06@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r07@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r08@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r09@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r10@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r11@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r12@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r13@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r14@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r15@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r16@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r17@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r18@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r19@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r20@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r21@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r22@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r23@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r24@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r25@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r26@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r27@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r28@ WinRAR
Reg HKLM\SOFTWARE\Classes\.r29@ WinRAR
Reg HKLM\SOFTWARE\Classes\.rar@ WinRAR
Reg HKLM\SOFTWARE\Classes\.rar\ShellNew
Reg HKLM\SOFTWARE\Classes\.rar\ShellNew@FileName C:\Program Files\WinRAR\rarnew.dat
Reg HKLM\SOFTWARE\Classes\.rev@ WinRAR.REV
Reg HKLM\SOFTWARE\Classes\.sbe@ SpybotSD.SBEFile
Reg HKLM\SOFTWARE\Classes\.sbi@ SpybotSD.SBIFile
Reg HKLM\SOFTWARE\Classes\.sbs@ SpybotSD.SBSFile
Reg HKLM\SOFTWARE\Classes\.tar@ WinRAR
Reg HKLM\SOFTWARE\Classes\.taz@ WinRAR
Reg HKLM\SOFTWARE\Classes\.tbz@ WinRAR
Reg HKLM\SOFTWARE\Classes\.tbz2@ WinRAR
Reg HKLM\SOFTWARE\Classes\.tgz@ WinRAR
Reg HKLM\SOFTWARE\Classes\.tif\PersistentHandler
Reg HKLM\SOFTWARE\Classes\.tif\PersistentHandler@ {098f2470-bae0-11cd-b579-08002b30bfeb}
Reg HKLM\SOFTWARE\Classes\.tiff\PersistentHandler
Reg HKLM\SOFTWARE\Classes\.tiff\PersistentHandler@ {098f2470-bae0-11cd-b579-08002b30bfeb}
Reg HKLM\SOFTWARE\Classes\.tnfo@ SpybotSD.TInfoFile
Reg HKLM\SOFTWARE\Classes\.uti@ SpybotSD.UTIFile
Reg HKLM\SOFTWARE\Classes\.uts@ SpybotSD.UTSFile
Reg HKLM\SOFTWARE\Classes\.uu@ WinRAR
Reg HKLM\SOFTWARE\Classes\.uue@ WinRAR
Reg HKLM\SOFTWARE\Classes\.xml@ xmlfile
Reg HKLM\SOFTWARE\Classes\.xml@Content Type text/xml
Reg HKLM\SOFTWARE\Classes\.xml\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.xml\OpenWithProgIds@Opera.HTML
Reg HKLM\SOFTWARE\Classes\.xsl@ xslfile
Reg HKLM\SOFTWARE\Classes\.xsl@Content Type text/xml
Reg HKLM\SOFTWARE\Classes\.xxe@ WinRAR
Reg HKLM\SOFTWARE\Classes\.z@ WinRAR
Reg HKLM\SOFTWARE\Classes\aAvgAPI.AvgBro@ AvgBro Object
Reg HKLM\SOFTWARE\Classes\aAvgAPI.AvgBro\Clsid
Reg HKLM\SOFTWARE\Classes\aAvgAPI.AvgBro\Clsid@ {18B30EBF-6B58-425E-AC54-831C05D91B5A}
Reg HKLM\SOFTWARE\Classes\ActionBvr.ActionBvr@ ActionBvr Class
Reg HKLM\SOFTWARE\Classes\ActionBvr.ActionBvr\CurVer
Reg HKLM\SOFTWARE\Classes\ActionBvr.ActionBvr\CurVer@ ActionBvr.ActionBvr.1
Reg HKLM\SOFTWARE\Classes\ActionBvr.ActionBvr.1@ ActionBvr Class
Reg HKLM\SOFTWARE\Classes\ActionBvr.ActionBvr.1\CLSID
Reg HKLM\SOFTWARE\Classes\ActionBvr.ActionBvr.1\CLSID@ {58A2E406-8304-11D2-9533-0060b0C3C4F4}
Reg HKLM\SOFTWARE\Classes\ActorBvr.ActorBvr@ ActorBvr Class
Reg HKLM\SOFTWARE\Classes\ActorBvr.ActorBvr\CurVer
Reg HKLM\SOFTWARE\Classes\ActorBvr.ActorBvr\CurVer@ ActorBvr.ActorBvr.1
Reg HKLM\SOFTWARE\Classes\ActorBvr.ActorBvr.1@ ActorBvr Class
Reg HKLM\SOFTWARE\Classes\ActorBvr.ActorBvr.1\CLSID
Reg HKLM\SOFTWARE\Classes\ActorBvr.ActorBvr.1\CLSID@ {6DDE3061-736C-11D2-A5E8-00A0C967A25F}
Reg HKLM\SOFTWARE\Classes\aim@ URL: AOL Instant Messenger Protocol
Reg HKLM\SOFTWARE\Classes\aim@URL Protocol
Reg HKLM\SOFTWARE\Classes\aim\shell
Reg HKLM\SOFTWARE\Classes\aim\shell\open
Reg HKLM\SOFTWARE\Classes\aim\shell\open\command
Reg HKLM\SOFTWARE\Classes\aim\shell\open\command@ "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp %1
Reg HKLM\SOFTWARE\Classes\amofile@ AIM Module Plugin
Reg HKLM\SOFTWARE\Classes\amofile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\amofile\DefaultIcon@ C:\Program Files\AIM6\services\imApp\ver6_8_10_1\resources\en-US\amo.ico
Reg HKLM\SOFTWARE\Classes\amofile\shell
Reg HKLM\SOFTWARE\Classes\amofile\shell\open
Reg HKLM\SOFTWARE\Classes\amofile\shell\open\command
Reg HKLM\SOFTWARE\Classes\amofile\shell\open\command@ "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp "%1"
Reg HKLM\SOFTWARE\Classes\AOL.EEActiveXShim@ EEActiveXShim Class
Reg HKLM\SOFTWARE\Classes\AOL.EEActiveXShim\CLSID
Reg HKLM\SOFTWARE\Classes\AOL.EEActiveXShim\CLSID@ {9DD15EDF-E5A6-46ac-A44F-1D5D52109C8C}
Reg HKLM\SOFTWARE\Classes\AOL.EEActiveXShim\CurVer
Reg HKLM\SOFTWARE\Classes\AOL.EEActiveXShim\CurVer@ AOL.EEActiveXShim.1
Reg HKLM\SOFTWARE\Classes\AOL.EEActiveXShim.1@ EEActiveXShim Class
Reg HKLM\SOFTWARE\Classes\AOL.EEActiveXShim.1\CLSID
Reg HKLM\SOFTWARE\Classes\AOL.EEActiveXShim.1\CLSID@ {9DD15EDF-E5A6-46ac-A44F-1D5D52109C8C}
Reg HKLM\SOFTWARE\Classes\AOL.ocpcontrol@ OcpDocHandler Class
Reg HKLM\SOFTWARE\Classes\AOL.ocpcontrol\CLSID
Reg HKLM\SOFTWARE\Classes\AOL.ocpcontrol\CLSID@ {E3120548-905E-4431-8590-614ABED7F315}
Reg HKLM\SOFTWARE\Classes\AOL.ocpcontrol\CurVer
Reg HKLM\SOFTWARE\Classes\AOL.ocpcontrol\CurVer@ AOL.ocpcontrol.1
Reg HKLM\SOFTWARE\Classes\AOL.ocpcontrol.1@ OcpDocHandler Class
Reg HKLM\SOFTWARE\Classes\AOL.ocpcontrol.1\CLSID
Reg HKLM\SOFTWARE\Classes\AOL.ocpcontrol.1\CLSID@ {E3120548-905E-4431-8590-614ABED7F315}
Reg HKLM\SOFTWARE\Classes\AOLEE.EESvcMgrGate.1@
Reg HKLM\SOFTWARE\Classes\AOLEE.EESvcMgrGate.1\CLSID
Reg HKLM\SOFTWARE\Classes\AOLEE.EESvcMgrGate.1\CLSID@ {10AF3945-2E81-4C59-AF6E-B8B428E34074}
Reg HKLM\SOFTWARE\Classes\AOLSearch.AOLSearchHook@ AOLSearchHook Class
Reg HKLM\SOFTWARE\Classes\AOLSearch.AOLSearchHook\CLSID
Reg HKLM\SOFTWARE\Classes\AOLSearch.AOLSearchHook\CLSID@ {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22}
Reg HKLM\SOFTWARE\Classes\AOLSearch.AOLSearchHook\CurVer
Reg HKLM\SOFTWARE\Classes\AOLSearch.AOLSearchHook\CurVer@ AOLSearch.AOLSearchHook.1
Reg HKLM\SOFTWARE\Classes\AOLSearch.AOLSearchHook.1@ AOLSearchHook Class
Reg HKLM\SOFTWARE\Classes\AOLSearch.AOLSearchHook.1\CLSID
Reg HKLM\SOFTWARE\Classes\AOLSearch.AOLSearchHook.1\CLSID@ {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22}
Reg HKLM\SOFTWARE\Classes\AOLTB.AOLTBSearch@ AOLTBSearch Class
Reg HKLM\SOFTWARE\Classes\AOLTB.AOLTBSearch\CLSID
Reg HKLM\SOFTWARE\Classes\AOLTB.AOLTBSearch\CLSID@ {EA756889-2338-43DB-8F07-D1CA6FB9C90D}
Reg HKLM\SOFTWARE\Classes\AOLTB.AOLTBSearch\CurVer
Reg HKLM\SOFTWARE\Classes\AOLTB.AOLTBSearch\CurVer@ AOLTB.AOLTBSearch.1
Reg HKLM\SOFTWARE\Classes\AOLTB.AOLTBSearch.1@ AOLTBSearch Class
Reg HKLM\SOFTWARE\Classes\AOLTB.AOLTBSearch.1\CLSID
Reg HKLM\SOFTWARE\Classes\AOLTB.AOLTBSearch.1\CLSID@ {EA756889-2338-43DB-8F07-D1CA6FB9C90D}
Reg HKLM\SOFTWARE\Classes\AOLTB.AOLToolBand@ AOLToolBand Class
Reg HKLM\SOFTWARE\Classes\AOLTB.AOLToolBand\CLSID
Reg HKLM\SOFTWARE\Classes\AOLTB.AOLToolBand\CLSID@ {DE9C389F-3316-41A7-809B-AA305ED9D922}
Reg HKLM\SOFTWARE\Classes\AOLTB.AOLToolBand\CurVer
Reg HKLM\SOFTWARE\Classes\AOLTB.AOLToolBand\CurVer@ AOLTB.AOLToolBand.1
Reg HKLM\SOFTWARE\Classes\AOLTB.AOLToolBand.1@ AOLToolBand Class
Reg HKLM\SOFTWARE\Classes\AOLTB.AOLToolBand.1\CLSID
Reg HKLM\SOFTWARE\Classes\AOLTB.AOLToolBand.1\CLSID@ {DE9C389F-3316-41A7-809B-AA305ED9D922}
Reg HKLM\SOFTWARE\Classes\AOLTB.Downloader@ Downloader Class
Reg HKLM\SOFTWARE\Classes\AOLTB.Downloader\CLSID
Reg HKLM\SOFTWARE\Classes\AOLTB.Downloader\CLSID@ {DEE471AA-AD6C-4B87-A0AC-0D3361185523}
Reg HKLM\SOFTWARE\Classes\AOLTB.Downloader\CurVer
Reg HKLM\SOFTWARE\Classes\AOLTB.Downloader\CurVer@ AOLTB.Downloader.1
Reg HKLM\SOFTWARE\Classes\AOLTB.Downloader.1@ Downloader Class
Reg HKLM\SOFTWARE\Classes\AOLTB.Downloader.1\CLSID
Reg HKLM\SOFTWARE\Classes\AOLTB.Downloader.1\CLSID@ {DEE471AA-AD6C-4B87-A0AC-0D3361185523}
Reg HKLM\SOFTWARE\Classes\AOLTB.ToolbarParams@ ToolbarParams Class
Reg HKLM\SOFTWARE\Classes\AOLTB.ToolbarParams\CLSID
Reg HKLM\SOFTWARE\Classes\AOLTB.ToolbarParams\CLSID@ {63610B21-6B0D-46C5-909D-3BD000B9A5A9}
Reg HKLM\SOFTWARE\Classes\AOLTB.ToolbarParams\CurVer
Reg HKLM\SOFTWARE\Classes\AOLTB.ToolbarParams\CurVer@ AOLTB.ToolbarParams.1
Reg HKLM\SOFTWARE\Classes\AOLTB.ToolbarParams.1@ ToolbarParams Class
Reg HKLM\SOFTWARE\Classes\AOLTB.ToolbarParams.1\CLSID
Reg HKLM\SOFTWARE\Classes\AOLTB.ToolbarParams.1\CLSID@ {63610B21-6B0D-46C5-909D-3BD000B9A5A9}
Reg HKLM\SOFTWARE\Classes\AolTbServer.AolToolbarHelper@ AolToolbarHelper Class
Reg HKLM\SOFTWARE\Classes\AolTbServer.AolToolbarHelper\CLSID
Reg HKLM\SOFTWARE\Classes\AolTbServer.AolToolbarHelper\CLSID@ {7DD783A7-DF05-4D9E-AC2E-6A71A0704E1D}
Reg HKLM\SOFTWARE\Classes\AolTbServer.AolToolbarHelper\CurVer
Reg HKLM\SOFTWARE\Classes\AolTbServer.AolToolbarHelper\CurVer@ AolTbServer.AolToolbarHelper.1
Reg HKLM\SOFTWARE\Classes\AolTbServer.AolToolbarHelper.1@ AolToolbarHelper Class
Reg HKLM\SOFTWARE\Classes\AolTbServer.AolToolbarHelper.1\CLSID
Reg HKLM\SOFTWARE\Classes\AolTbServer.AolToolbarHelper.1\CLSID@ {7DD783A7-DF05-4D9E-AC2E-6A71A0704E1D}
Reg HKLM\SOFTWARE\Classes\AS2StubIE.Control@ ActiveScan 2.0 Control Class
Reg HKLM\SOFTWARE\Classes\AS2StubIE.Control\CLSID
Reg HKLM\SOFTWARE\Classes\AS2StubIE.Control\CLSID@ {9cab0a33-96f5-428d-9123-2333f2479aa2}
Reg HKLM\SOFTWARE\Classes\AS2StubIE.Control\CurVer
Reg HKLM\SOFTWARE\Classes\AS2StubIE.Control\CurVer@ AS2StubIE.Control.1
Reg HKLM\SOFTWARE\Classes\AS2StubIE.Control.1@ ActiveScan 2.0 Control Class
Reg HKLM\SOFTWARE\Classes\AS2StubIE.Control.1\CLSID
Reg HKLM\SOFTWARE\Classes\AS2StubIE.Control.1\CLSID@ {9cab0a33-96f5-428d-9123-2333f2479aa2}
Reg HKLM\SOFTWARE\Classes\AS2StubIE.InnerInstaller@ ActiveScan 2.0 InnerInstaller Class
Reg HKLM\SOFTWARE\Classes\AS2StubIE.InnerInstaller\CLSID
Reg HKLM\SOFTWARE\Classes\AS2StubIE.InnerInstaller\CLSID@ {bdc09965-f837-4dbc-8128-03f0cc0a8802}
Reg HKLM\SOFTWARE\Classes\AS2StubIE.InnerInstaller\CurVer
Reg HKLM\SOFTWARE\Classes\AS2StubIE.InnerInstaller\CurVer@ AS2StubIE.InnerInstaller.1
Reg HKLM\SOFTWARE\Classes\AS2StubIE.InnerInstaller.1@ ActiveScan 2.0 InnerInstaller Class
Reg HKLM\SOFTWARE\Classes\AS2StubIE.InnerInstaller.1\CLSID
Reg HKLM\SOFTWARE\Classes\AS2StubIE.InnerInstaller.1\CLSID@ {bdc09965-f837-4dbc-8128-03f0cc0a8802}
Reg HKLM\SOFTWARE\Classes\AS2StubIE.Installer@ ActiveScan 2.0 Installer Class
Reg HKLM\SOFTWARE\Classes\AS2StubIE.Installer\CLSID
Reg HKLM\SOFTWARE\Classes\AS2StubIE.Installer\CLSID@ {2d8ed06d-3c30-438b-96ae-4d110fdc1fb8}
Reg HKLM\SOFTWARE\Classes\AS2StubIE.Installer\CurVer
Reg HKLM\SOFTWARE\Classes\AS2StubIE.Installer\CurVer@ AS2StubIE.Installer.3
Reg HKLM\SOFTWARE\Classes\AS2StubIE.Installer.3@ ActiveScan 2.0 Installer Class
Reg HKLM\SOFTWARE\Classes\AS2StubIE.Installer.3\CLSID
Reg HKLM\SOFTWARE\Classes\AS2StubIE.Installer.3\CLSID@ {2d8ed06d-3c30-438b-96ae-4d110fdc1fb8}
Reg HKLM\SOFTWARE\Classes\AskSBar.SettingsPlugin@ Ask Toolbar Settings Plugin
Reg HKLM\SOFTWARE\Classes\AskSBar.SettingsPlugin\CLSID
Reg HKLM\SOFTWARE\Classes\AskSBar.SettingsPlugin\CLSID@ {F0D4B23B-DA4B-4daf-81E4-DFEE4931A4AA}
Reg HKLM\SOFTWARE\Classes\AskSBar.SettingsPlugin\CurVer
Reg HKLM\SOFTWARE\Classes\AskSBar.SettingsPlugin\CurVer@ AskSBar.SettingsPlugin.1
Reg HKLM\SOFTWARE\Classes\AskSBar.SettingsPlugin.1@ Ask Toolbar Settings Plugin
Reg HKLM\SOFTWARE\Classes\AskSBar.SettingsPlugin.1\CLSID
Reg HKLM\SOFTWARE\Classes\AskSBar.SettingsPlugin.1\CLSID@ {F0D4B23B-DA4B-4daf-81E4-DFEE4931A4AA}
Reg HKLM\SOFTWARE\Classes\AskSBar.ToolbarPlugin@ Ask Toolbar Plugin
Reg HKLM\SOFTWARE\Classes\AskSBar.ToolbarPlugin\CLSID
Reg HKLM\SOFTWARE\Classes\AskSBar.ToolbarPlugin\CLSID@ {B15FD82E-85BC-430d-90CB-65DB1B030510}
Reg HKLM\SOFTWARE\Classes\AskSBar.ToolbarPlugin\CurVer
Reg HKLM\SOFTWARE\Classes\AskSBar.ToolbarPlugin\CurVer@ AskSBar.ToolbarPlugin.1
Reg HKLM\SOFTWARE\Classes\AskSBar.ToolbarPlugin.1@ Ask Toolbar Plugin
Reg HKLM\SOFTWARE\Classes\AskSBar.ToolbarPlugin.1\CLSID
Reg HKLM\SOFTWARE\Classes\AskSBar.ToolbarPlugin.1\CLSID@ {B15FD82E-85BC-430d-90CB-65DB1B030510}
Reg HKLM\SOFTWARE\Classes\AVG.AvgKernel@ Avg Kernel Class
Reg HKLM\SOFTWARE\Classes\AVG.AvgKernel\CLSID
Reg HKLM\SOFTWARE\Classes\AVG.AvgKernel\CLSID@ {41564737-3200-1071-989B-0000E87B4FB1}
Reg HKLM\SOFTWARE\Classes\AVG.AvgKernel\CurVer
Reg HKLM\SOFTWARE\Classes\AVG.AvgKernel\CurVer@ AVG.AvgKernel.7
Reg HKLM\SOFTWARE\Classes\AVG.AvgKernel.7@ Avg Kernel Class
Reg HKLM\SOFTWARE\Classes\AVG.AvgKernel.7\CLSID
Reg HKLM\SOFTWARE\Classes\AVG.AvgKernel.7\CLSID@ {41564737-3200-1071-989B-0000E87B4FB1}
Reg HKLM\SOFTWARE\Classes\AVG.Office@ AVG plugin for the Microsoft Office
Reg HKLM\SOFTWARE\Classes\AVG.Office\CLSID
Reg HKLM\SOFTWARE\Classes\AVG.Office\CLSID@ {04373D9C-5ED8-44f2-BA00-7895D6A5A2DA}
Reg HKLM\SOFTWARE\Classes\AVG.Office\CurVer
Reg HKLM\SOFTWARE\Classes\AVG.Office\CurVer@ AVG.Office.8
Reg HKLM\SOFTWARE\Classes\AVG.Office.8@ AVG plugin for the Microsoft Office
Reg HKLM\SOFTWARE\Classes\AVG.Office.8\CLSID
Reg HKLM\SOFTWARE\Classes\AVG.Office.8\CLSID@ {04373D9C-5ED8-44f2-BA00-7895D6A5A2DA}
Reg HKLM\SOFTWARE\Classes\bltfile@ AIM Buddy List File
Reg HKLM\SOFTWARE\Classes\bltfile\shell
Reg HKLM\SOFTWARE\Classes\bltfile\shell\open
Reg HKLM\SOFTWARE\Classes\bltfile\shell\open\command
Reg HKLM\SOFTWARE\Classes\bltfile\shell\open\command@ "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp "%1"
Reg HKLM\SOFTWARE\Classes\Browse.BrowseWM@ BrowseWM Class
Reg HKLM\SOFTWARE\Classes\Browse.BrowseWM\CLSID
Reg HKLM\SOFTWARE\Classes\Browse.BrowseWM\CLSID@ {8610e1b4-57c3-441b-9821-c81c51c3ac08}
Reg HKLM\SOFTWARE\Classes\Browse.BrowseWM\CurVer
Reg HKLM\SOFTWARE\Classes\Browse.BrowseWM\CurVer@ Browse.BrowseWM.1
Reg HKLM\SOFTWARE\Classes\Browse.BrowseWM.1@ BrowseWM Class
Reg HKLM\SOFTWARE\Classes\Browse.BrowseWM.1\CLSID
Reg HKLM\SOFTWARE\Classes\Browse.BrowseWM.1\CLSID@ {8610e1b4-57c3-441b-9821-c81c51c3ac08}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Attribute@ Attribute Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Attribute\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Attribute\CLSID@ {54BA1E8F-818D-407F-949D-BAE1692C5C18}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Attribute\CurVer
Reg HKLM\SOFTWARE\Classes\CAPICOM.Attribute\CurVer@ CAPICOM.Attribute.1
Reg HKLM\SOFTWARE\Classes\CAPICOM.Attribute.1@ Attribute Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Attribute.1\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Attribute.1\CLSID@ {54BA1E8F-818D-407F-949D-BAE1692C5C18}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificate@ Certificate Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificate\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificate\CLSID@ {9171C115-7DD9-46BA-B1E5-0ED50AFFC1B8}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificate\CurVer
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificate\CurVer@ CAPICOM.Certificate.3
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificate.1@ Certificate Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificate.1\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificate.1\CLSID@ {E38FD381-6404-4041-B5E9-B2739258941F}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificate.2@ Certificate Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificate.2\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificate.2\CLSID@ {E38FD381-6404-4041-B5E9-B2739258941F}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificate.3@ Certificate Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificate.3\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificate.3\CLSID@ {9171C115-7DD9-46BA-B1E5-0ED50AFFC1B8}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates@ Certificates Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates\CLSID@ {3605B612-C3CF-4ab4-A426-2D853391DB2E}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates\CurVer
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates\CurVer@ CAPICOM.Certificates.4
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates.1@ Certificates Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates.1\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates.1\CLSID@ {FBAB033B-CDD0-4C5E-81AB-AEA575CD1338}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates.2@ Certificates Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates.2\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates.2\CLSID@ {FBAB033B-CDD0-4C5E-81AB-AEA575CD1338}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates.3@ Certificates Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates.3\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates.3\CLSID@ {17E3A1C3-EA8A-4970-AF29-7F54610B1D4C}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates.4@ Certificates Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates.4\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Certificates.4\CLSID@ {3605B612-C3CF-4ab4-A426-2D853391DB2E}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Chain@ Chain Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Chain\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Chain\CLSID@ {550C8FFB-4DC0-4756-828C-862E6D0AE74F}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Chain\CurVer
Reg HKLM\SOFTWARE\Classes\CAPICOM.Chain\CurVer@ CAPICOM.Chain.3
Reg HKLM\SOFTWARE\Classes\CAPICOM.Chain.1@ Chain Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Chain.1\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Chain.1\CLSID@ {65104D73-BA60-4160-A95A-4B4782E7AA62}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Chain.2@ Chain Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Chain.2\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Chain.2\CLSID@ {65104D73-BA60-4160-A95A-4B4782E7AA62}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Chain.3@ Chain Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Chain.3\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Chain.3\CLSID@ {550C8FFB-4DC0-4756-828C-862E6D0AE74F}
Reg HKLM\SOFTWARE\Classes\CAPICOM.EncryptedData@ EncryptedData Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.EncryptedData\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.EncryptedData\CLSID@ {A440BD76-CFE1-4D46-AB1F-15F238437A3D}
Reg HKLM\SOFTWARE\Classes\CAPICOM.EncryptedData\CurVer
Reg HKLM\SOFTWARE\Classes\CAPICOM.EncryptedData\CurVer@ CAPICOM.EncryptedData.1
Reg HKLM\SOFTWARE\Classes\CAPICOM.EncryptedData.1@ EncryptedData Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.EncryptedData.1\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.EncryptedData.1\CLSID@ {A440BD76-CFE1-4D46-AB1F-15F238437A3D}
Reg HKLM\SOFTWARE\Classes\CAPICOM.EnvelopedData@ EnvelopedData Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.EnvelopedData\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.EnvelopedData\CLSID@ {F3A12E08-EDE9-4160-8B51-334D982A9AD0}
Reg HKLM\SOFTWARE\Classes\CAPICOM.EnvelopedData\CurVer
Reg HKLM\SOFTWARE\Classes\CAPICOM.EnvelopedData\CurVer@ CAPICOM.EnvelopedData.1
Reg HKLM\SOFTWARE\Classes\CAPICOM.EnvelopedData.1@ EnvelopedData Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.EnvelopedData.1\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.EnvelopedData.1\CLSID@ {F3A12E08-EDE9-4160-8B51-334D982A9AD0}
Reg HKLM\SOFTWARE\Classes\CAPICOM.ExtendedProperty@ ExtendedProperty Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.ExtendedProperty\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.ExtendedProperty\CLSID@ {9E7EA907-5810-4FCA-B817-CD0BBA8496FC}
Reg HKLM\SOFTWARE\Classes\CAPICOM.ExtendedProperty\CurVer
Reg HKLM\SOFTWARE\Classes\CAPICOM.ExtendedProperty\CurVer@ CAPICOM.ExtendedProperty.1
Reg HKLM\SOFTWARE\Classes\CAPICOM.ExtendedProperty.1@ ExtendedProperty Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.ExtendedProperty.1\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.ExtendedProperty.1\CLSID@ {9E7EA907-5810-4FCA-B817-CD0BBA8496FC}
Reg HKLM\SOFTWARE\Classes\CAPICOM.HashedData@ HashedData Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.HashedData\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.HashedData\CLSID@ {CE32ABF6-475D-41F6-BF82-D27F03E3D38B}
Reg HKLM\SOFTWARE\Classes\CAPICOM.HashedData\CurVer
Reg HKLM\SOFTWARE\Classes\CAPICOM.HashedData\CurVer@ CAPICOM.HashedData.1
Reg HKLM\SOFTWARE\Classes\CAPICOM.HashedData.1@ HashedData Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.HashedData.1\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.HashedData.1\CLSID@ {CE32ABF6-475D-41F6-BF82-D27F03E3D38B}
Reg HKLM\SOFTWARE\Classes\CAPICOM.OID@ OID Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.OID\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.OID\CLSID@ {7BF3AC5C-CC84-429A-ACA5-74D916AD6B8C}
Reg HKLM\SOFTWARE\Classes\CAPICOM.OID\CurVer
Reg HKLM\SOFTWARE\Classes\CAPICOM.OID\CurVer@ CAPICOM.OID.1
Reg HKLM\SOFTWARE\Classes\CAPICOM.OID.1@ OID Class
sexy_ladii05
2008-08-23, 01:05
Reg HKLM\SOFTWARE\Classes\CAPICOM.OID.1\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.OID.1\CLSID@ {7BF3AC5C-CC84-429A-ACA5-74D916AD6B8C}
Reg HKLM\SOFTWARE\Classes\CAPICOM.PrivateKey@ PrivateKey Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.PrivateKey\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.PrivateKey\CLSID@ {03ACC284-B757-4B8F-9951-86E600D2CD06}
Reg HKLM\SOFTWARE\Classes\CAPICOM.PrivateKey\CurVer
Reg HKLM\SOFTWARE\Classes\CAPICOM.PrivateKey\CurVer@ CAPICOM.PrivateKey.1
Reg HKLM\SOFTWARE\Classes\CAPICOM.PrivateKey.1@ PrivateKey Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.PrivateKey.1\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.PrivateKey.1\CLSID@ {03ACC284-B757-4B8F-9951-86E600D2CD06}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Settings@ Settings Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Settings\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Settings\CLSID@ {A996E48C-D3DC-4244-89F7-AFA33EC60679}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Settings\CurVer
Reg HKLM\SOFTWARE\Classes\CAPICOM.Settings\CurVer@ CAPICOM.Settings.1
Reg HKLM\SOFTWARE\Classes\CAPICOM.Settings.1@ Settings Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Settings.1\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Settings.1\CLSID@ {A996E48C-D3DC-4244-89F7-AFA33EC60679}
Reg HKLM\SOFTWARE\Classes\CAPICOM.SignedCode@ SignedCode Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.SignedCode\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.SignedCode\CLSID@ {8C3E4934-9FA4-4693-9253-A29A05F99186}
Reg HKLM\SOFTWARE\Classes\CAPICOM.SignedCode\CurVer
Reg HKLM\SOFTWARE\Classes\CAPICOM.SignedCode\CurVer@ CAPICOM.SignedCode.1
Reg HKLM\SOFTWARE\Classes\CAPICOM.SignedCode.1@ SignedCode Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.SignedCode.1\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.SignedCode.1\CLSID@ {8C3E4934-9FA4-4693-9253-A29A05F99186}
Reg HKLM\SOFTWARE\Classes\CAPICOM.SignedData@ SignedData Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.SignedData\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.SignedData\CLSID@ {94AFFFCC-6C05-4814-B123-A941105AA77F}
Reg HKLM\SOFTWARE\Classes\CAPICOM.SignedData\CurVer
Reg HKLM\SOFTWARE\Classes\CAPICOM.SignedData\CurVer@ CAPICOM.SignedData.1
Reg HKLM\SOFTWARE\Classes\CAPICOM.SignedData.1@ SignedData Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.SignedData.1\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.SignedData.1\CLSID@ {94AFFFCC-6C05-4814-B123-A941105AA77F}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Signer@ Signer Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Signer\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Signer\CLSID@ {60A9863A-11FD-4080-850E-A8E184FC3A3C}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Signer\CurVer
Reg HKLM\SOFTWARE\Classes\CAPICOM.Signer\CurVer@ CAPICOM.Signer.2
Reg HKLM\SOFTWARE\Classes\CAPICOM.Signer.1@ Signer Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Signer.1\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Signer.1\CLSID@ {60A9863A-11FD-4080-850E-A8E184FC3A3C}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Signer.2@ Signer Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Signer.2\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Signer.2\CLSID@ {60A9863A-11FD-4080-850E-A8E184FC3A3C}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Store@ Store Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Store\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Store\CLSID@ {91D221C4-0CD4-461C-A728-01D509321556}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Store\CurVer
Reg HKLM\SOFTWARE\Classes\CAPICOM.Store\CurVer@ CAPICOM.Store.3
Reg HKLM\SOFTWARE\Classes\CAPICOM.Store.1@ Store Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Store.1\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Store.1\CLSID@ {78E61E52-0E57-4456-A2F2-517492BCBF8F}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Store.2@ Store Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Store.2\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Store.2\CLSID@ {78E61E52-0E57-4456-A2F2-517492BCBF8F}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Store.3@ Store Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Store.3\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Store.3\CLSID@ {91D221C4-0CD4-461C-A728-01D509321556}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Utilities@ Utilities Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Utilities\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Utilities\CLSID@ {22A85CE1-F011-4231-B9E4-7E7A0438F71B}
Reg HKLM\SOFTWARE\Classes\CAPICOM.Utilities\CurVer
Reg HKLM\SOFTWARE\Classes\CAPICOM.Utilities\CurVer@ CAPICOM.Utilities.1
Reg HKLM\SOFTWARE\Classes\CAPICOM.Utilities.1@ Utilities Class
Reg HKLM\SOFTWARE\Classes\CAPICOM.Utilities.1\CLSID
Reg HKLM\SOFTWARE\Classes\CAPICOM.Utilities.1\CLSID@ {22A85CE1-F011-4231-B9E4-7E7A0438F71B}
Reg HKLM\SOFTWARE\Classes\ChannelFile@ Channel File
Reg HKLM\SOFTWARE\Classes\ChannelFile@FriendlyTypeName @%SystemRoot%\System32\cdfview.dll,-4610
Reg HKLM\SOFTWARE\Classes\ChannelFile\CLSID
Reg HKLM\SOFTWARE\Classes\ChannelFile\CLSID@ {f39a0dc0-9cc8-11d0-a599-00c04fd64433}
Reg HKLM\SOFTWARE\Classes\ChannelFile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\ChannelFile\DefaultIcon@ %1
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell@ Subscribe
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\Edit
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\Edit@ Edit
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\Edit\Command
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\Edit\Command@ notepad.exe %1
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\Explore
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\Explore\Command
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\Explore\Command@ explorer /e,/root,{f39a0dc0-9cc8-11d0-a599-00c04fd64433},%L
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\Open
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\Open\Command
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\Open\Command@ explorer /root,{f39a0dc0-9cc8-11d0-a599-00c04fd64433},%L
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\OpenChannel
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\OpenChannel@ Open Channel
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\OpenChannel\Command
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\OpenChannel\Command@ rundll32 cdfview.dll,OpenChannel %L
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\Subscribe
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\Subscribe@ Make Available Offline
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\Subscribe\Command
Reg HKLM\SOFTWARE\Classes\ChannelFile\Shell\Subscribe\Command@ rundll32 cdfview.dll,Subscribe %L
Reg HKLM\SOFTWARE\Classes\ChannelFile\ShellEx
Reg HKLM\SOFTWARE\Classes\ChannelFile\ShellEx\IconHandler
Reg HKLM\SOFTWARE\Classes\ChannelFile\ShellEx\IconHandler@ {f3ba0dc0-9cc8-11d0-a599-00c04fd64435}
Reg HKLM\SOFTWARE\Classes\ChannelFile\ShellEx\{000214EE-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\ChannelFile\ShellEx\{000214EE-0000-0000-C000-000000000046}@ {f3ba0dc0-9cc8-11d0-a599-00c04fd64435}
Reg HKLM\SOFTWARE\Classes\ChannelFile\ShellEx\{00021500-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\ChannelFile\ShellEx\{00021500-0000-0000-C000-000000000046}@ {f3ba0dc0-9cc8-11d0-a599-00c04fd64435}
Reg HKLM\SOFTWARE\Classes\ChannelFile\ShellEx\{BB2E617C-0920-11d1-9A0B-00C04FC2D6C1}
Reg HKLM\SOFTWARE\Classes\ChannelFile\ShellEx\{BB2E617C-0920-11d1-9A0B-00C04FC2D6C1}@ {f3ba0dc0-9cc8-11d0-a599-00c04fd64435}
Reg HKLM\SOFTWARE\Classes\ChannelFile\ShellFolder
Reg HKLM\SOFTWARE\Classes\ChannelFile\ShellFolder@Attributes 0xA0 0x01 0x00 0xA0
Reg HKLM\SOFTWARE\Classes\ChannelShortcut@ Channel Shortcut
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\CLSID
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\CLSID@ {f3aa0dc0-9cc8-11d0-a599-00c04fd64434}
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\DefaultIcon
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\DefaultIcon@ %1
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\Shell
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\Shell@ Open Channel
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\Shell\OpenChannel
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\Shell\OpenChannel@ Open Channel
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\Shell\OpenChannel\Command
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\Shell\OpenChannel\Command@ rundll32 cdfview.dll,OpenChannel %L
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx\ContextMenuHandlers
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx\ContextMenuHandlers\{f3da0dc0-9cc8-11d0-a599-00c04fd64437}
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx\ContextMenuHandlers\{f3da0dc0-9cc8-11d0-a599-00c04fd64437}@
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx\IconHandler
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx\IconHandler@ {f3ba0dc0-9cc8-11d0-a599-00c04fd64435}
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx\PropertySheetHandlers
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx\PropertySheetHandlers\{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx\PropertySheetHandlers\{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}@
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx\{000214EE-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx\{000214EE-0000-0000-C000-000000000046}@ {f3ba0dc0-9cc8-11d0-a599-00c04fd64435}
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx\{00021500-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx\{00021500-0000-0000-C000-000000000046}@ {f3ba0dc0-9cc8-11d0-a599-00c04fd64435}
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx\{BB2E617C-0920-11d1-9A0B-00C04FC2D6C1}
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx\{BB2E617C-0920-11d1-9A0B-00C04FC2D6C1}@ {f3ba0dc0-9cc8-11d0-a599-00c04fd64435}
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx\{D4029EC0-0920-11d1-9A0B-00C04FC2D6C1}
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellEx\{D4029EC0-0920-11d1-9A0B-00C04FC2D6C1}@ {f3ba0dc0-9cc8-11d0-a599-00c04fd64435}
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellFolder
Reg HKLM\SOFTWARE\Classes\ChannelShortcut\ShellFolder@Attributes 0xA0 0x01 0x00 0xA0
Reg HKLM\SOFTWARE\Classes\CLSID\{B8F872F2-9C89-65E5-014B-0A5F3B70913F}\InprocServer@ ole2disp.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{B8F872F2-9C89-65E5-014B-0A5F3B70913F}\InprocServer32@ oleaut32.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{B8F872F2-9C89-65E5-014B-0A5F3B70913F}\InprocServer32@ThreadingModel Both
Reg HKLM\SOFTWARE\Classes\CLSID\{D025DE9F-3F20-6C9E-268E-CC902C926229}\InprocServer32@ ole32.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{D025DE9F-3F20-6C9E-268E-CC902C926229}\ProgID@ file
Reg HKLM\SOFTWARE\Classes\ColorBvr.ColorBvr@ ColorBvr Class
Reg HKLM\SOFTWARE\Classes\ColorBvr.ColorBvr\CurVer
Reg HKLM\SOFTWARE\Classes\ColorBvr.ColorBvr\CurVer@ ColorBvr.ColorBvr.1
Reg HKLM\SOFTWARE\Classes\ColorBvr.ColorBvr.1@ ColorBvr Class
Reg HKLM\SOFTWARE\Classes\ColorBvr.ColorBvr.1\CLSID
Reg HKLM\SOFTWARE\Classes\ColorBvr.ColorBvr.1\CLSID@ {3845A174-EB30-11D1-9A23-00A0C879FE5F}
Reg HKLM\SOFTWARE\Classes\Content.mbcontent@ mbcontent Class
Reg HKLM\SOFTWARE\Classes\Content.mbcontent\CLSID
Reg HKLM\SOFTWARE\Classes\Content.mbcontent\CLSID@ {52ca3bcf-3b9b-419e-a3d6-5d28c0b0b50c}
Reg HKLM\SOFTWARE\Classes\Content.mbcontent\CurVer
Reg HKLM\SOFTWARE\Classes\Content.mbcontent\CurVer@ Content.mbcontent.1
Reg HKLM\SOFTWARE\Classes\Content.mbcontent.1@ mbcontent Class
Reg HKLM\SOFTWARE\Classes\Content.mbcontent.1\CLSID
Reg HKLM\SOFTWARE\Classes\Content.mbcontent.1\CLSID@ {52ca3bcf-3b9b-419e-a3d6-5d28c0b0b50c}
Reg HKLM\SOFTWARE\Classes\CR.CrBehaviorFactory@ Cr Behavior Factory
Reg HKLM\SOFTWARE\Classes\CR.CrBehaviorFactory\CurVer
Reg HKLM\SOFTWARE\Classes\CR.CrBehaviorFactory\CurVer@ CR.CrBehaviorFactory.1
Reg HKLM\SOFTWARE\Classes\CR.CrBehaviorFactory.1@ Cr Behavior Factory
Reg HKLM\SOFTWARE\Classes\CR.CrBehaviorFactory.1\CLSID
Reg HKLM\SOFTWARE\Classes\CR.CrBehaviorFactory.1\CLSID@ {754FF233-5D4E-11d2-875B-00A0C93C09B3}
Reg HKLM\SOFTWARE\Classes\DAEMON.Tools.Lite@ DAEMON Tools Pro files
Reg HKLM\SOFTWARE\Classes\DAEMON.Tools.Lite\DefaultIcon
Reg HKLM\SOFTWARE\Classes\DAEMON.Tools.Lite\shell
Reg HKLM\SOFTWARE\Classes\DAEMON.Tools.Lite\shell\open
Reg HKLM\SOFTWARE\Classes\DAEMON.Tools.Lite\shell\open\command
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAArray@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAArray\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAArray\CLSID@ {D17506C3-6B26-11D0-8914-00C04FC2A0CA}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAArray.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAArray.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAArray.1\CLSID@ {D17506C3-6B26-11D0-8914-00C04FC2A0CA}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABbox2@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABbox2\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABbox2\CLSID@ {C46C1BCE-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABbox2.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABbox2.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABbox2.1\CLSID@ {C46C1BCE-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABbox3@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABbox3\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABbox3\CLSID@ {C46C1BDE-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABbox3.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABbox3.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABbox3.1\CLSID@ {C46C1BDE-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABehavior@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABehavior\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABehavior\CLSID@ {283807B8-2C60-11D0-A31D-00AA00B92C03}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABehavior.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABehavior.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABehavior.1\CLSID@ {283807B8-2C60-11D0-A31D-00AA00B92C03}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABoolean@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABoolean\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABoolean\CLSID@ {C46C1BC1-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABoolean.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABoolean.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DABoolean.1\CLSID@ {C46C1BC1-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DACamera@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DACamera\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DACamera\CLSID@ {C46C1BE2-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DACamera.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DACamera.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DACamera.1\CLSID@ {C46C1BE2-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAColor@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAColor\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAColor\CLSID@ {C46C1BC6-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAColor.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAColor.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAColor.1\CLSID@ {C46C1BC6-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DADashStyle@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DADashStyle\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DADashStyle\CLSID@ {C46C1BF0-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DADashStyle.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DADashStyle.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DADashStyle.1\CLSID@ {C46C1BF0-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAEndStyle@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAEndStyle\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAEndStyle\CLSID@ {C46C1BEC-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAEndStyle.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAEndStyle.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAEndStyle.1\CLSID@ {C46C1BEC-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAEvent@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAEvent\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAEvent\CLSID@ {50B4791F-4731-11D0-8912-00C04FC2A0CA}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAEvent.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAEvent.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAEvent.1\CLSID@ {50B4791F-4731-11D0-8912-00C04FC2A0CA}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAFontStyle@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAFontStyle\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAFontStyle\CLSID@ {25B0F91C-D23D-11D0-9B85-00C04FC2F51D}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAFontStyle.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAFontStyle.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAFontStyle.1\CLSID@ {25B0F91C-D23D-11D0-9B85-00C04FC2F51D}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAGeometry@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAGeometry\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAGeometry\CLSID@ {C46C1BE0-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAGeometry.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAGeometry.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAGeometry.1\CLSID@ {C46C1BE0-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAImage@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAImage\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAImage\CLSID@ {C46C1BD4-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAImage.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAImage.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAImage.1\CLSID@ {C46C1BD4-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAJoinStyle@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAJoinStyle\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAJoinStyle\CLSID@ {C46C1BEE-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAJoinStyle.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAJoinStyle.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAJoinStyle.1\CLSID@ {C46C1BEE-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DALineStyle@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DALineStyle\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DALineStyle\CLSID@ {C46C1BF2-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DALineStyle.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DALineStyle.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DALineStyle.1\CLSID@ {C46C1BF2-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMatte@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMatte\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMatte\CLSID@ {C46C1BD2-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMatte.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMatte.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMatte.1\CLSID@ {C46C1BD2-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMicrophone@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMicrophone\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMicrophone\CLSID@ {C46C1BE6-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMicrophone.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMicrophone.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMicrophone.1\CLSID@ {C46C1BE6-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMontage@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMontage\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMontage\CLSID@ {C46C1BD6-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMontage.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMontage.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAMontage.1\CLSID@ {C46C1BD6-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DANumber@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DANumber\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DANumber\CLSID@ {9CDE7341-3C20-11D0-A330-00AA00B92C03}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DANumber.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DANumber.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DANumber.1\CLSID@ {9CDE7341-3C20-11D0-A330-00AA00B92C03}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPair@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPair\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPair\CLSID@ {C46C1BF4-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPair.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPair.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPair.1\CLSID@ {C46C1BF4-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPath2@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPath2\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPath2\CLSID@ {C46C1BD0-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPath2.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPath2.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPath2.1\CLSID@ {C46C1BD0-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPoint2@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPoint2\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPoint2\CLSID@ {C46C1BC8-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPoint2.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPoint2.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPoint2.1\CLSID@ {C46C1BC8-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPoint3@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPoint3\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPoint3\CLSID@ {C46C1BD8-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPoint3.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPoint3.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAPoint3.1\CLSID@ {C46C1BD8-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DASound@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DASound\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DASound\CLSID@ {C46C1BE4-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DASound.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DASound.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DASound.1\CLSID@ {C46C1BE4-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAStatics@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAStatics\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAStatics\CLSID@ {542FB453-5003-11CF-92A2-00AA00B8A733}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAStatics.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAStatics.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAStatics.1\CLSID@ {542FB453-5003-11CF-92A2-00AA00B8A733}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAString@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAString\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAString\CLSID@ {C46C1BC4-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAString.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAString.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAString.1\CLSID@ {C46C1BC4-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATransform2@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATransform2\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATransform2\CLSID@ {C46C1BCC-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATransform2.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATransform2.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATransform2.1\CLSID@ {C46C1BCC-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATransform3@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATransform3\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATransform3\CLSID@ {C46C1BDC-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATransform3.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATransform3.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATransform3.1\CLSID@ {C46C1BDC-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATuple@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATuple\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATuple\CLSID@ {5DFB2651-9668-11D0-B17B-00C04FC2A0CA}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATuple.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATuple.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DATuple.1\CLSID@ {5DFB2651-9668-11D0-B17B-00C04FC2A0CA}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAUserData@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAUserData\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAUserData\CLSID@ {AF868304-AB0B-11D0-876A-00C04FC29D46}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAUserData.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAUserData.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAUserData.1\CLSID@ {AF868304-AB0B-11D0-876A-00C04FC29D46}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAVector2@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAVector2\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAVector2\CLSID@ {C46C1BCA-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAVector2.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAVector2.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAVector2.1\CLSID@ {C46C1BCA-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAVector3@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAVector3\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAVector3\CLSID@ {C46C1BDA-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAVector3.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAVector3.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAVector3.1\CLSID@ {C46C1BDA-3C52-11D0-9200-848C1D000000}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAView@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAView\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAView\CLSID@ {283807B5-2C60-11D0-A31D-00AA00B92C03}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAView.1@
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAView.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DAView.1\CLSID@ {283807B5-2C60-11D0-A31D-00AA00B92C03}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DirectAnimationIntegratedMediaControl@ Microsoft DirectAnimation Control
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DirectAnimationIntegratedMediaControl\CurVer
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DirectAnimationIntegratedMediaControl\CurVer@ DirectAnimation.DirectAnimationIntegratedMediaControl.1
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DirectAnimationIntegratedMediaControl.1@ Microsoft DirectAnimation Control
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DirectAnimationIntegratedMediaControl.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DirectAnimationIntegratedMediaControl.1\CLSID@ {B6FFC24C-7E13-11D0-9B47-00C04FC2F51D}
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DirectAnimationWindowedIntegratedMediaControl@ Microsoft DirectAnimation Windowed Control
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DirectAnimationWindowedIntegratedMediaControl\CurVer
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DirectAnimationWindowedIntegratedMediaControl\CurVer@ DirectAnimation.DirectAnimationWindowedIntegratedMediaControl.1
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DirectAnimationWindowedIntegratedMediaControl.1@ Microsoft DirectAnimation Windowed Control
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DirectAnimationWindowedIntegratedMediaControl.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectAnimation.DirectAnimationWindowedIntegratedMediaControl.1\CLSID@ {69AD90EF-1C20-11d1-8801-00C04FC29D46}
Reg HKLM\SOFTWARE\Classes\EffectBvr.EffectBvr@ EffectBvr Class
Reg HKLM\SOFTWARE\Classes\EffectBvr.EffectBvr\CurVer
Reg HKLM\SOFTWARE\Classes\EffectBvr.EffectBvr\CurVer@ EffectBvr.EffectBvr.1
Reg HKLM\SOFTWARE\Classes\EffectBvr.EffectBvr.1@ EffectBvr Class
Reg HKLM\SOFTWARE\Classes\EffectBvr.EffectBvr.1\CLSID
Reg HKLM\SOFTWARE\Classes\EffectBvr.EffectBvr.1\CLSID@ {54274112-7A5E-11d2-875F-00A0C93C09B3}
Reg HKLM\SOFTWARE\Classes\fdkowvbp.balq@ fdkowvbp
Reg HKLM\SOFTWARE\Classes\fdkowvbp.balq\CLSID
Reg HKLM\SOFTWARE\Classes\fdkowvbp.balq\CLSID@ {AE7F9E1E-0A21-46C0-91D9-01F9D1ACB887}
Reg HKLM\SOFTWARE\Classes\fdkowvbp.balq\CurVer
Reg HKLM\SOFTWARE\Classes\fdkowvbp.balq\CurVer@ fdkowvbp.1
Reg HKLM\SOFTWARE\Classes\fdkowvbp.ToolBar.1@ fdkowvbp
Reg HKLM\SOFTWARE\Classes\fdkowvbp.ToolBar.1\CLSID
Reg HKLM\SOFTWARE\Classes\fdkowvbp.ToolBar.1\CLSID@ {AE7F9E1E-0A21-46C0-91D9-01F9D1ACB887}
Reg HKLM\SOFTWARE\Classes\gopher@Source Filter {E436EBB6-524F-11CE-9F53-0020AF0BA770}
Reg HKLM\SOFTWARE\Classes\gopher\shell
Reg HKLM\SOFTWARE\Classes\gopher\shell\open
Reg HKLM\SOFTWARE\Classes\gopher\shell\open\command
Reg HKLM\SOFTWARE\Classes\gopher\shell\open\command@ "C:\Program Files\Internet Explorer\iexplore.exe" -nohome
Reg HKLM\SOFTWARE\Classes\isaim.aimlocator@ aimlocator Class
Reg HKLM\SOFTWARE\Classes\isaim.aimlocator\CLSID
Reg HKLM\SOFTWARE\Classes\isaim.aimlocator\CLSID@ {BAEB32D0-732D-11d2-8BF4-0060B0A4A9EA}
Reg HKLM\SOFTWARE\Classes\isaim.aimlocator\CurVer
Reg HKLM\SOFTWARE\Classes\isaim.aimlocator\CurVer@ isaim.aimlocator.1
Reg HKLM\SOFTWARE\Classes\isaim.aimlocator.1@ aimlocator Class
Reg HKLM\SOFTWARE\Classes\isaim.aimlocator.1\CLSID
Reg HKLM\SOFTWARE\Classes\isaim.aimlocator.1\CLSID@ {BAEB32D0-732D-11d2-8BF4-0060B0A4A9EA}
Reg HKLM\SOFTWARE\Classes\JavaPlugin.160_03\CLSID
Reg HKLM\SOFTWARE\Classes\JavaPlugin.160_03\CLSID@ {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
Reg HKLM\SOFTWARE\Classes\LiquidMotion.LMEngine@
Reg HKLM\SOFTWARE\Classes\LiquidMotion.LMEngine\CLSID
Reg HKLM\SOFTWARE\Classes\LiquidMotion.LMEngine\CLSID@ {C533ADF1-0C80-11D1-8C54-00A02468F316}
Reg HKLM\SOFTWARE\Classes\LiquidMotion.LMEngine.1@
Reg HKLM\SOFTWARE\Classes\LiquidMotion.LMEngine.1\CLSID
Reg HKLM\SOFTWARE\Classes\LiquidMotion.LMEngine.1\CLSID@ {C533ADF1-0C80-11D1-8C54-00A02468F316}
Reg HKLM\SOFTWARE\Classes\LM.AutoEffectBvr@ LM Auto Effect Behavior
Reg HKLM\SOFTWARE\Classes\LM.AutoEffectBvr\CurVer
Reg HKLM\SOFTWARE\Classes\LM.AutoEffectBvr\CurVer@ LM.AutoEffectBvr.1
Reg HKLM\SOFTWARE\Classes\LM.AutoEffectBvr.1@ LM Auto Effect Behavior
Reg HKLM\SOFTWARE\Classes\LM.AutoEffectBvr.1\CLSID
Reg HKLM\SOFTWARE\Classes\LM.AutoEffectBvr.1\CLSID@ {BB339A46-7C49-11d2-9BF3-00C04FA34789}
Reg HKLM\SOFTWARE\Classes\LM.LMBehaviorFactory@ LM Behavior Factory
Reg HKLM\SOFTWARE\Classes\LM.LMBehaviorFactory\CurVer
Reg HKLM\SOFTWARE\Classes\LM.LMBehaviorFactory\CurVer@ LM.LMBehaviorFactory.1
Reg HKLM\SOFTWARE\Classes\LM.LMBehaviorFactory.1@ LM Behavior Factory
Reg HKLM\SOFTWARE\Classes\LM.LMBehaviorFactory.1\CLSID
Reg HKLM\SOFTWARE\Classes\LM.LMBehaviorFactory.1\CLSID@ {B1549E58-3894-11D2-BB7F-00A0C999C4C1}
Reg HKLM\SOFTWARE\Classes\LM.LMReader@ LM Runtime Control
Reg HKLM\SOFTWARE\Classes\LM.LMReader\CurVer
Reg HKLM\SOFTWARE\Classes\LM.LMReader\CurVer@ LM.LMReader.1
Reg HKLM\SOFTWARE\Classes\LM.LMReader.1@ LM Runtime Control
Reg HKLM\SOFTWARE\Classes\LM.LMReader.1\CLSID
sexy_ladii05
2008-08-23, 01:06
Reg HKLM\SOFTWARE\Classes\LM.LMReader.1\CLSID@ {183C259A-0480-11d1-87EA-00C04FC29D46}
Reg HKLM\SOFTWARE\Classes\Microsoft.FreeThreadedXMLDOM@ Free Threaded XML DOM Document
Reg HKLM\SOFTWARE\Classes\Microsoft.FreeThreadedXMLDOM\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.FreeThreadedXMLDOM\CLSID@ {2933BF91-7B36-11D2-B20E-00C04F983E60}
Reg HKLM\SOFTWARE\Classes\Microsoft.FreeThreadedXMLDOM\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.FreeThreadedXMLDOM\CurVer@ Microsoft.FreeThreadedXMLDOM.1.0
Reg HKLM\SOFTWARE\Classes\Microsoft.FreeThreadedXMLDOM.1.0@ Free Threaded XML DOM Document
Reg HKLM\SOFTWARE\Classes\Microsoft.FreeThreadedXMLDOM.1.0\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.FreeThreadedXMLDOM.1.0\CLSID@ {2933BF91-7B36-11D2-B20E-00C04F983E60}
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDOM@ XML DOM Document
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDOM\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDOM\CLSID@ {2933BF90-7B36-11D2-B20E-00C04F983E60}
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDOM\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDOM\CurVer@ Microsoft.XMLDOM.1.0
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDOM.1.0@ XML DOM Document
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDOM.1.0\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDOM.1.0\CLSID@ {2933BF90-7B36-11D2-B20E-00C04F983E60}
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDSO@ XML Data Source Object
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDSO\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDSO\CLSID@ {550DDA30-0541-11D2-9CA9-0060B0EC3D39}
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDSO\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDSO\CurVer@ Microsoft.XMLDSO.1.0
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDSO.1.0@ XML Data Source Object
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDSO.1.0\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDSO.1.0\CLSID@ {550DDA30-0541-11D2-9CA9-0060B0EC3D39}
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLHTTP@ XML HTTP Request
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLHTTP\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLHTTP\CLSID@ {ED8C108E-4349-11D2-91A4-00C04F7969E8}
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLHTTP\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLHTTP\CurVer@ Microsoft.XMLHTTP.1.0
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLHTTP.1.0@ XML HTTP Request
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLHTTP.1.0\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLHTTP.1.0\CLSID@ {ED8C108E-4349-11D2-91A4-00C04F7969E8}
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLParser@ XML Parser
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLParser\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLParser\CLSID@ {D2423620-51A0-11D2-9CAF-0060B0EC3D39}
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLParser\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLParser\CurVer@ Microsoft.XMLParser.1.0
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLParser.1.0@ XML Parser
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLParser.1.0\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLParser.1.0\CLSID@ {D2423620-51A0-11D2-9CAF-0060B0EC3D39}
Reg HKLM\SOFTWARE\Classes\MoveBvr.MoveBvr@ MoveBvr Class
Reg HKLM\SOFTWARE\Classes\MoveBvr.MoveBvr\CurVer
Reg HKLM\SOFTWARE\Classes\MoveBvr.MoveBvr\CurVer@ MoveBvr.MoveBvr.1
Reg HKLM\SOFTWARE\Classes\MoveBvr.MoveBvr.1@ MoveBvr Class
Reg HKLM\SOFTWARE\Classes\MoveBvr.MoveBvr.1\CLSID
Reg HKLM\SOFTWARE\Classes\MoveBvr.MoveBvr.1\CLSID@ {C5B86F32-69EE-11d2-875F-00A0C93C09B3}
Reg HKLM\SOFTWARE\Classes\MSIDXS@ Microsoft OLE DB Provider for Indexing Service
Reg HKLM\SOFTWARE\Classes\MSIDXS\Clsid
Reg HKLM\SOFTWARE\Classes\MSIDXS\Clsid@ {F9AE8980-7E52-11d0-8964-00C04FD611D7}
Reg HKLM\SOFTWARE\Classes\MSIDXS ErrorLookup@ Microsoft OLE DB Error Lookup for Indexing Service
Reg HKLM\SOFTWARE\Classes\MSIDXS ErrorLookup\Clsid
Reg HKLM\SOFTWARE\Classes\MSIDXS ErrorLookup\Clsid@ {F9AE8981-7E52-11d0-8964-00C04FD611D7}
Reg HKLM\SOFTWARE\Classes\Msxml@ Msxml
Reg HKLM\SOFTWARE\Classes\Msxml\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml\CLSID@ {CFC399AF-D876-11D0-9C10-00C04FC99C8E}
Reg HKLM\SOFTWARE\Classes\MSXML.DOMDocument@ XML DOM Document
Reg HKLM\SOFTWARE\Classes\MSXML.DOMDocument\CLSID
Reg HKLM\SOFTWARE\Classes\MSXML.DOMDocument\CLSID@ {2933BF90-7B36-11D2-B20E-00C04F983E60}
Reg HKLM\SOFTWARE\Classes\MSXML.DOMDocument\CurVer
Reg HKLM\SOFTWARE\Classes\MSXML.DOMDocument\CurVer@ Microsoft.XMLDOM.1.0
Reg HKLM\SOFTWARE\Classes\MSXML.FreeThreadedDOMDocument@ Free Threaded XML DOM Document
Reg HKLM\SOFTWARE\Classes\MSXML.FreeThreadedDOMDocument\CLSID
Reg HKLM\SOFTWARE\Classes\MSXML.FreeThreadedDOMDocument\CLSID@ {2933BF91-7B36-11D2-B20E-00C04F983E60}
Reg HKLM\SOFTWARE\Classes\MSXML.FreeThreadedDOMDocument\CurVer
Reg HKLM\SOFTWARE\Classes\MSXML.FreeThreadedDOMDocument\CurVer@ Microsoft.FreeThreadedXMLDOM.1.0
Reg HKLM\SOFTWARE\Classes\Msxml2.DOMDocument@ XML DOM Document
Reg HKLM\SOFTWARE\Classes\Msxml2.DOMDocument\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.DOMDocument\CLSID@ {F6D90F11-9C73-11D3-B32E-00C04F990BB4}
Reg HKLM\SOFTWARE\Classes\Msxml2.DOMDocument\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.DOMDocument\CurVer@ Msxml2.DOMDocument.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.DOMDocument.3.0@ XML DOM Document 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.DOMDocument.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.DOMDocument.3.0\CLSID@ {F5078F32-C551-11D3-89B9-0000F81FE221}
Reg HKLM\SOFTWARE\Classes\Msxml2.DSOControl@ XML Data Source Object
Reg HKLM\SOFTWARE\Classes\Msxml2.DSOControl\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.DSOControl\CLSID@ {F6D90F14-9C73-11D3-B32E-00C04F990BB4}
Reg HKLM\SOFTWARE\Classes\Msxml2.DSOControl\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.DSOControl\CurVer@ Msxml2.DSOControl.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.DSOControl.3.0@ XML Data Source Object 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.DSOControl.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.DSOControl.3.0\CLSID@ {F5078F39-C551-11D3-89B9-0000F81FE221}
Reg HKLM\SOFTWARE\Classes\Msxml2.FreeThreadedDOMDocument@ Free Threaded XML DOM Document
Reg HKLM\SOFTWARE\Classes\Msxml2.FreeThreadedDOMDocument\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.FreeThreadedDOMDocument\CLSID@ {F6D90F12-9C73-11D3-B32E-00C04F990BB4}
Reg HKLM\SOFTWARE\Classes\Msxml2.FreeThreadedDOMDocument\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.FreeThreadedDOMDocument\CurVer@ Msxml2.FreeThreadedDOMDocument.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.FreeThreadedDOMDocument.3.0@ Free Threaded XML DOM Document 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.FreeThreadedDOMDocument.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.FreeThreadedDOMDocument.3.0\CLSID@ {F5078F33-C551-11D3-89B9-0000F81FE221}
Reg HKLM\SOFTWARE\Classes\Msxml2.MXXMLWriter@ MXXMLWriter
Reg HKLM\SOFTWARE\Classes\Msxml2.MXXMLWriter\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.MXXMLWriter\CLSID@ {FC220AD8-A72A-4EE8-926E-0B7AD152A020}
Reg HKLM\SOFTWARE\Classes\Msxml2.MXXMLWriter\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.MXXMLWriter\CurVer@ Msxml2.MXXMLWriter.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.MXXMLWriter.3.0@ MXXMLWriter 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.MXXMLWriter.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.MXXMLWriter.3.0\CLSID@ {3D813DFE-6C91-4A4E-8F41-04346A841D9C}
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXAttributes@ SAXAttributes
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXAttributes\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXAttributes\CLSID@ {4DD441AD-526D-4A77-9F1B-9841ED802FB0}
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXAttributes\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXAttributes\CurVer@ Msxml2.SAXAttributes.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXAttributes.3.0@ SAXAttributes 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXAttributes.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXAttributes.3.0\CLSID@ {3E784A01-F3AE-4DC0-9354-9526B9370EBA}
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXXMLReader@ SAX XML Reader
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXXMLReader\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXXMLReader\CLSID@ {079AA557-4A18-424A-8EEE-E39F0A8D41B9}
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXXMLReader\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXXMLReader\CurVer@ Msxml2.SAXXMLReader.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXXMLReader.3.0@ SAX XML Reader 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXXMLReader.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXXMLReader.3.0\CLSID@ {3124C396-FB13-4836-A6AD-1317F1713688}
Reg HKLM\SOFTWARE\Classes\Msxml2.ServerXMLHTTP@ Server XML HTTP
Reg HKLM\SOFTWARE\Classes\Msxml2.ServerXMLHTTP\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.ServerXMLHTTP\CLSID@ {AFBA6B42-5692-48EA-8141-DC517DCF0EF1}
Reg HKLM\SOFTWARE\Classes\Msxml2.ServerXMLHTTP\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.ServerXMLHTTP\CurVer@ Msxml2.ServerXMLHTTP.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.ServerXMLHTTP.3.0@ Server XML HTTP 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.ServerXMLHTTP.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.ServerXMLHTTP.3.0\CLSID@ {AFB40FFD-B609-40A3-9828-F88BBE11E4E3}
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLHTTP@ XML HTTP
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLHTTP\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLHTTP\CLSID@ {F6D90F16-9C73-11D3-B32E-00C04F990BB4}
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLHTTP\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLHTTP\CurVer@ Msxml2.XMLHTTP.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLHTTP.3.0@ XML HTTP 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLHTTP.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLHTTP.3.0\CLSID@ {F5078F35-C551-11D3-89B9-0000F81FE221}
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLParser@ XML Parser
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLParser\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLParser\CLSID@ {F5078F19-C551-11D3-89B9-0000F81FE221}
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLParser\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLParser\CurVer@ Msxml2.XMLParser.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLParser.3.0@ XML Parser 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLParser.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLParser.3.0\CLSID@ {F5078F31-C551-11D3-89B9-0000F81FE221}
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLSchemaCache@ XML Schema Cache
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLSchemaCache\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLSchemaCache\CLSID@ {373984C9-B845-449B-91E7-45AC83036ADE}
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLSchemaCache\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLSchemaCache\CurVer@ Msxml2.XMLSchemaCache.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLSchemaCache.3.0@ XML Schema Cache 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLSchemaCache.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLSchemaCache.3.0\CLSID@ {F5078F34-C551-11D3-89B9-0000F81FE221}
Reg HKLM\SOFTWARE\Classes\Msxml2.XSLTemplate@ XSL Template
Reg HKLM\SOFTWARE\Classes\Msxml2.XSLTemplate\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.XSLTemplate\CLSID@ {2933BF94-7B36-11D2-B20E-00C04F983E60}
Reg HKLM\SOFTWARE\Classes\Msxml2.XSLTemplate\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.XSLTemplate\CurVer@ Msxml2.XSLTemplate.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.XSLTemplate.3.0@ XSL Template 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.XSLTemplate.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.XSLTemplate.3.0\CLSID@ {F5078F36-C551-11D3-89B9-0000F81FE221}
Reg HKLM\SOFTWARE\Classes\NumberBvr.NumberBvr@ NumberBvr Class
Reg HKLM\SOFTWARE\Classes\NumberBvr.NumberBvr\CurVer
Reg HKLM\SOFTWARE\Classes\NumberBvr.NumberBvr\CurVer@ NumberBvr.NumberBvr.1
Reg HKLM\SOFTWARE\Classes\NumberBvr.NumberBvr.1@ NumberBvr Class
Reg HKLM\SOFTWARE\Classes\NumberBvr.NumberBvr.1\CLSID
Reg HKLM\SOFTWARE\Classes\NumberBvr.NumberBvr.1\CLSID@ {ECDB03D2-6E99-11d2-875F-00A0C93C09B3}
Reg HKLM\SOFTWARE\Classes\PathBvr.PathBvr@ PathBvr Class
Reg HKLM\SOFTWARE\Classes\PathBvr.PathBvr\CurVer
Reg HKLM\SOFTWARE\Classes\PathBvr.PathBvr\CurVer@ PathBvr.PathBvr.1
Reg HKLM\SOFTWARE\Classes\PathBvr.PathBvr.1@ PathBvr Class
Reg HKLM\SOFTWARE\Classes\PathBvr.PathBvr.1\CLSID
Reg HKLM\SOFTWARE\Classes\PathBvr.PathBvr.1\CLSID@ {80F49562-6A9A-11d2-875F-00A0C93C09B3}
Reg HKLM\SOFTWARE\Classes\prffile@ Microsoft Office Outlook Profile Settings
Reg HKLM\SOFTWARE\Classes\prffile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\prffile\DefaultIcon@ C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe,6
Reg HKLM\SOFTWARE\Classes\prffile\shell
Reg HKLM\SOFTWARE\Classes\prffile\shell@ Open
Reg HKLM\SOFTWARE\Classes\prffile\shell\Open
Reg HKLM\SOFTWARE\Classes\prffile\shell\Open\command
Reg HKLM\SOFTWARE\Classes\prffile\shell\Open\command@ "C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE" /PromptImportPRF "%1"
Reg HKLM\SOFTWARE\Classes\rar_auto_file@
Reg HKLM\SOFTWARE\Classes\rar_auto_file\shell
Reg HKLM\SOFTWARE\Classes\rar_auto_file\shell\open
Reg HKLM\SOFTWARE\Classes\rar_auto_file\shell\open\command
Reg HKLM\SOFTWARE\Classes\rar_auto_file\shell\open\command@ "C:\Program Files\WinRAR\WinRAR.exe" "%1"
Reg HKLM\SOFTWARE\Classes\RotateBvr.RotateBvr@ RotateBvr Class
Reg HKLM\SOFTWARE\Classes\RotateBvr.RotateBvr\CurVer
Reg HKLM\SOFTWARE\Classes\RotateBvr.RotateBvr\CurVer@ RotateBvr.RotateBvr.1
Reg HKLM\SOFTWARE\Classes\RotateBvr.RotateBvr.1@ RotateBvr Class
Reg HKLM\SOFTWARE\Classes\RotateBvr.RotateBvr.1\CLSID
Reg HKLM\SOFTWARE\Classes\RotateBvr.RotateBvr.1\CLSID@ {027713F2-5FA8-11d2-875B-00A0C93C09B3}
Reg HKLM\SOFTWARE\Classes\ScaleBvr.ScaleBvr@ ScaleBvr Class
Reg HKLM\SOFTWARE\Classes\ScaleBvr.ScaleBvr\CurVer
Reg HKLM\SOFTWARE\Classes\ScaleBvr.ScaleBvr\CurVer@ ScaleBvr.ScaleBvr.1
Reg HKLM\SOFTWARE\Classes\ScaleBvr.ScaleBvr.1@ ScaleBvr Class
Reg HKLM\SOFTWARE\Classes\ScaleBvr.ScaleBvr.1\CLSID
Reg HKLM\SOFTWARE\Classes\ScaleBvr.ScaleBvr.1\CLSID@ {E80353D3-677D-11d2-875E-00A0C93C09B3}
Reg HKLM\SOFTWARE\Classes\SetBvr.SetBvr@ SetBvr Class
Reg HKLM\SOFTWARE\Classes\SetBvr.SetBvr\CurVer
Reg HKLM\SOFTWARE\Classes\SetBvr.SetBvr\CurVer@ SetBvr.SetBvr.1
Reg HKLM\SOFTWARE\Classes\SetBvr.SetBvr.1@ SetBvr Class
Reg HKLM\SOFTWARE\Classes\SetBvr.SetBvr.1\CLSID
Reg HKLM\SOFTWARE\Classes\SetBvr.SetBvr.1\CLSID@ {BA60F742-6F72-11d2-875F-00A0C93C09B3}
Reg HKLM\SOFTWARE\Classes\SpybotSD.DisabledFile@ Disabled startup file
Reg HKLM\SOFTWARE\Classes\SpybotSD.DisabledFile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\SpybotSD.DisabledFile\DefaultIcon@ "C:\Program Files\Spybot - Search & Destroy\blindman.exe",0
Reg HKLM\SOFTWARE\Classes\SpybotSD.DisabledFile\shell
Reg HKLM\SOFTWARE\Classes\SpybotSD.DisabledFile\shell\open
Reg HKLM\SOFTWARE\Classes\SpybotSD.DisabledFile\shell\open\command
Reg HKLM\SOFTWARE\Classes\SpybotSD.DisabledFile\shell\open\command@ "C:\Program Files\Spybot - Search & Destroy\blindman.exe" "%1"
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBEFile@ Spyware exclude file
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBEFile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBEFile\DefaultIcon@ "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe",0
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBEFile\shell
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBEFile\shell\open
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBEFile\shell\open\command
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBEFile\shell\open\command@ "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" "%1"
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBIFile@ Spyware include file
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBIFile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBIFile\DefaultIcon@ "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe",0
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBIFile\shell
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBIFile\shell\open
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBIFile\shell\open\command
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBIFile\shell\open\command@ "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" "%1"
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBSFile@ Spyware supplemental file
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBSFile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBSFile\DefaultIcon@ "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe",0
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBSFile\shell
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBSFile\shell\open
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBSFile\shell\open\command
Reg HKLM\SOFTWARE\Classes\SpybotSD.SBSFile\shell\open\command@ "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" "%1"
Reg HKLM\SOFTWARE\Classes\SpybotSD.TInfoFile@ Internal informations
Reg HKLM\SOFTWARE\Classes\SpybotSD.TInfoFile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\SpybotSD.TInfoFile\DefaultIcon@ "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe",0
Reg HKLM\SOFTWARE\Classes\SpybotSD.TInfoFile\shell
Reg HKLM\SOFTWARE\Classes\SpybotSD.TInfoFile\shell\open
Reg HKLM\SOFTWARE\Classes\SpybotSD.TInfoFile\shell\open\command
Reg HKLM\SOFTWARE\Classes\SpybotSD.TInfoFile\shell\open\command@ "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" "%1"
Reg HKLM\SOFTWARE\Classes\SpybotSD.UTIFile@ Usage tracks include file
Reg HKLM\SOFTWARE\Classes\SpybotSD.UTIFile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\SpybotSD.UTIFile\DefaultIcon@ "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe",0
Reg HKLM\SOFTWARE\Classes\SpybotSD.UTIFile\shell
Reg HKLM\SOFTWARE\Classes\SpybotSD.UTIFile\shell\open
Reg HKLM\SOFTWARE\Classes\SpybotSD.UTIFile\shell\open\command
Reg HKLM\SOFTWARE\Classes\SpybotSD.UTIFile\shell\open\command@ "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" "%1"
Reg HKLM\SOFTWARE\Classes\SpybotSD.UTSFile@ Usage tracks supplemental file
Reg HKLM\SOFTWARE\Classes\SpybotSD.UTSFile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\SpybotSD.UTSFile\DefaultIcon@ "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe",0
Reg HKLM\SOFTWARE\Classes\SpybotSD.UTSFile\shell
Reg HKLM\SOFTWARE\Classes\SpybotSD.UTSFile\shell\open
Reg HKLM\SOFTWARE\Classes\SpybotSD.UTSFile\shell\open\command
Reg HKLM\SOFTWARE\Classes\SpybotSD.UTSFile\shell\open\command@ "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" "%1"
Reg HKLM\SOFTWARE\Classes\SwBroker.SwHelper@ SwHelper Class
Reg HKLM\SOFTWARE\Classes\SwBroker.SwHelper\CLSID
Reg HKLM\SOFTWARE\Classes\SwBroker.SwHelper\CLSID@ {1F3CB77D-D339-49e0-B8E4-FECD6D6F8CB8}
Reg HKLM\SOFTWARE\Classes\SwBroker.SwHelper\CurVer
Reg HKLM\SOFTWARE\Classes\SwBroker.SwHelper\CurVer@ SwBroker.SwHelper.1
Reg HKLM\SOFTWARE\Classes\SwBroker.SwHelper.1@ SwHelper Class
Reg HKLM\SOFTWARE\Classes\SwBroker.SwHelper.1\CLSID
Reg HKLM\SOFTWARE\Classes\SwBroker.SwHelper.1\CLSID@ {1F3CB77D-D339-49e0-B8E4-FECD6D6F8CB8}
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl@ Shockwave ActiveX Control
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl\CLSID
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl\CLSID@ {233C1507-6A77-46A4-9443-F871F945D258}
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl\CurVer
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl\CurVer@ SWCtl.SWCtl.11
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.1@ Shockwave ActiveX Control
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.1\CLSID
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.1\CLSID@ {166B1BCA-3F9C-11CF-8075-444553540000}
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.10.1.1@ Shockwave ActiveX Control
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.10.1.1\CLSID
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.10.1.1\CLSID@ {233C1507-6A77-46A4-9443-F871F945D258}
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.11@ Shockwave ActiveX Control
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.11\CLSID
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.11\CLSID@ {233C1507-6A77-46A4-9443-F871F945D258}
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.7@ Shockwave ActiveX Control
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.7\CLSID
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.7\CLSID@ {166B1BCA-3F9C-11CF-8075-444553540000}
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.8@ Shockwave ActiveX Control
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.8\CLSID
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.8\CLSID@ {166B1BCA-3F9C-11CF-8075-444553540000}
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.8.5@ Shockwave ActiveX Control
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.8.5\CLSID
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.8.5\CLSID@ {166B1BCA-3F9C-11CF-8075-444553540000}
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.8.5.1@ Shockwave ActiveX Control
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.8.5.1\CLSID
Reg HKLM\SOFTWARE\Classes\SWCtl.SWCtl.8.5.1\CLSID@ {166B1BCA-3F9C-11CF-8075-444553540000}
Reg HKLM\SOFTWARE\Classes\Swdir.SwInstallerCtl@ SwInstallerCtl Class
Reg HKLM\SOFTWARE\Classes\Swdir.SwInstallerCtl\CLSID
Reg HKLM\SOFTWARE\Classes\Swdir.SwInstallerCtl\CLSID@ {4DB2E429-B905-479A-9EFF-F7CBD9FD52DE}
Reg HKLM\SOFTWARE\Classes\Swdir.SwInstallerCtl\CurVer
Reg HKLM\SOFTWARE\Classes\Swdir.SwInstallerCtl\CurVer@ Swdir.SwInstallerCtl.1
Reg HKLM\SOFTWARE\Classes\Swdir.SwInstallerCtl.1@ SwInstallerCtl Class
Reg HKLM\SOFTWARE\Classes\Swdir.SwInstallerCtl.1\CLSID
Reg HKLM\SOFTWARE\Classes\Swdir.SwInstallerCtl.1\CLSID@ {4DB2E429-B905-479A-9EFF-F7CBD9FD52DE}
Reg HKLM\SOFTWARE\Classes\SwHelper.SwHelperAttributes@ SwHelperAttributes Class
Reg HKLM\SOFTWARE\Classes\SwHelper.SwHelperAttributes\CLSID
Reg HKLM\SOFTWARE\Classes\SwHelper.SwHelperAttributes\CLSID@ {0103A448-2934-4B3D-A54E-FED761D472E0}
Reg HKLM\SOFTWARE\Classes\SwHelper.SwHelperAttributes\CurVer
Reg HKLM\SOFTWARE\Classes\SwHelper.SwHelperAttributes\CurVer@ SwHelper.SwHelperAttributes.1
Reg HKLM\SOFTWARE\Classes\SwHelper.SwHelperAttributes.1@ SwHelperAttributes Class
Reg HKLM\SOFTWARE\Classes\SwHelper.SwHelperAttributes.1\CLSID
Reg HKLM\SOFTWARE\Classes\SwHelper.SwHelperAttributes.1\CLSID@ {0103A448-2934-4B3D-A54E-FED761D472E0}
Reg HKLM\SOFTWARE\Classes\TIME.MMFactory@
Reg HKLM\SOFTWARE\Classes\TIME.MMFactory\CLSID
Reg HKLM\SOFTWARE\Classes\TIME.MMFactory\CLSID@ {33FDA1EA-80DF-11D2-B263-00A0C90D6111}
Reg HKLM\SOFTWARE\Classes\TIME.MMFactory.1@
Reg HKLM\SOFTWARE\Classes\TIME.MMFactory.1\CLSID
Reg HKLM\SOFTWARE\Classes\TIME.MMFactory.1\CLSID@ {33FDA1EA-80DF-11D2-B263-00A0C90D6111}
Reg HKLM\SOFTWARE\Classes\TIME.TIMEFactory@
Reg HKLM\SOFTWARE\Classes\TIME.TIMEFactory\CLSID
Reg HKLM\SOFTWARE\Classes\TIME.TIMEFactory\CLSID@ {476C391C-3E0D-11D2-B948-00C04FA32195}
Reg HKLM\SOFTWARE\Classes\TIME.TIMEFactory.1@
Reg HKLM\SOFTWARE\Classes\TIME.TIMEFactory.1\CLSID
Reg HKLM\SOFTWARE\Classes\TIME.TIMEFactory.1\CLSID@ {476C391C-3E0D-11D2-B948-00C04FA32195}
Reg HKLM\SOFTWARE\Classes\unagiAx.UnagiAx@ UnagiAx Class
Reg HKLM\SOFTWARE\Classes\unagiAx.UnagiAx\CLSID
Reg HKLM\SOFTWARE\Classes\unagiAx.UnagiAx\CLSID@ {6E704581-CCAE-46D2-9C64-20D724B3624E}
Reg HKLM\SOFTWARE\Classes\unagiAx.UnagiAx\CurVer
Reg HKLM\SOFTWARE\Classes\unagiAx.UnagiAx\CurVer@ unagiAx.UnagiAx.2
Reg HKLM\SOFTWARE\Classes\unagiAx.UnagiAx.2@ UnagiAx Class
Reg HKLM\SOFTWARE\Classes\unagiAx.UnagiAx.2\CLSID
Reg HKLM\SOFTWARE\Classes\unagiAx.UnagiAx.2\CLSID@ {6E704581-CCAE-46D2-9C64-20D724B3624E}
Reg HKLM\SOFTWARE\Classes\unagiAx.UnagiAx.2\Insertable
Reg HKLM\SOFTWARE\Classes\WinRAR@ WinRAR archive
Reg HKLM\SOFTWARE\Classes\WinRAR\DefaultIcon
Reg HKLM\SOFTWARE\Classes\WinRAR\DefaultIcon@ C:\Program Files\WinRAR\WinRAR.exe,0
Reg HKLM\SOFTWARE\Classes\WinRAR\shell
Reg HKLM\SOFTWARE\Classes\WinRAR\shell\open
Reg HKLM\SOFTWARE\Classes\WinRAR\shell\open\command
Reg HKLM\SOFTWARE\Classes\WinRAR\shell\open\command@ "C:\Program Files\WinRAR\WinRAR.exe" "%1"
Reg HKLM\SOFTWARE\Classes\WinRAR\shellex
Reg HKLM\SOFTWARE\Classes\WinRAR\shellex\ContextMenuHandlers
Reg HKLM\SOFTWARE\Classes\WinRAR\shellex\ContextMenuHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
Reg HKLM\SOFTWARE\Classes\WinRAR\shellex\ContextMenuHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}@
Reg HKLM\SOFTWARE\Classes\WinRAR\shellex\DropHandler
Reg HKLM\SOFTWARE\Classes\WinRAR\shellex\DropHandler@ {B41DB860-8EE4-11D2-9906-E49FADC173CA}
Reg HKLM\SOFTWARE\Classes\WinRAR\shellex\PropertySheetHandlers
Reg HKLM\SOFTWARE\Classes\WinRAR\shellex\PropertySheetHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
Reg HKLM\SOFTWARE\Classes\WinRAR\shellex\PropertySheetHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}@
Reg HKLM\SOFTWARE\Classes\WinRAR.REV@ RAR recovery volume
Reg HKLM\SOFTWARE\Classes\WinRAR.REV\DefaultIcon
Reg HKLM\SOFTWARE\Classes\WinRAR.REV\DefaultIcon@ C:\Program Files\WinRAR\WinRAR.exe,1
Reg HKLM\SOFTWARE\Classes\WinRAR.REV\shell
Reg HKLM\SOFTWARE\Classes\WinRAR.REV\shell\open
Reg HKLM\SOFTWARE\Classes\WinRAR.REV\shell\open\command
Reg HKLM\SOFTWARE\Classes\WinRAR.REV\shell\open\command@ "C:\Program Files\WinRAR\WinRAR.exe" "%1"
Reg HKLM\SOFTWARE\Classes\WinRAR.ZIP@ WinRAR ZIP archive
Reg HKLM\SOFTWARE\Classes\WinRAR.ZIP\DefaultIcon
Reg HKLM\SOFTWARE\Classes\WinRAR.ZIP\DefaultIcon@ C:\Program Files\WinRAR\WinRAR.exe,0
Reg HKLM\SOFTWARE\Classes\WinRAR.ZIP\shell
Reg HKLM\SOFTWARE\Classes\WinRAR.ZIP\shell\open
Reg HKLM\SOFTWARE\Classes\WinRAR.ZIP\shell\open\command
Reg HKLM\SOFTWARE\Classes\WinRAR.ZIP\shell\open\command@ "C:\Program Files\WinRAR\WinRAR.exe" "%1"
Reg HKLM\SOFTWARE\Classes\WinRAR.ZIP\shellex
Reg HKLM\SOFTWARE\Classes\WinRAR.ZIP\shellex\ContextMenuHandlers
Reg HKLM\SOFTWARE\Classes\WinRAR.ZIP\shellex\ContextMenuHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
Reg HKLM\SOFTWARE\Classes\WinRAR.ZIP\shellex\ContextMenuHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}@
Reg HKLM\SOFTWARE\Classes\WinRAR.ZIP\shellex\DropHandler
Reg HKLM\SOFTWARE\Classes\WinRAR.ZIP\shellex\DropHandler@ {B41DB860-8EE4-11D2-9906-E49FADC173CA}
Reg HKLM\SOFTWARE\Classes\WinRAR.ZIP\shellex\PropertySheetHandlers
Reg HKLM\SOFTWARE\Classes\WinRAR.ZIP\shellex\PropertySheetHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
Reg HKLM\SOFTWARE\Classes\WinRAR.ZIP\shellex\PropertySheetHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}@
Reg HKLM\SOFTWARE\Classes\XML@ XML Script Engine
Reg HKLM\SOFTWARE\Classes\XML\CLSID
Reg HKLM\SOFTWARE\Classes\XML\CLSID@ {989D1DC0-B162-11D1-B6EC-D27DDCF9A923}
Reg HKLM\SOFTWARE\Classes\XML\OLEScript
Reg HKLM\SOFTWARE\Classes\XML\OLEScript@
Reg HKLM\SOFTWARE\Classes\xmlfile@ XML Document
Reg HKLM\SOFTWARE\Classes\xmlfile@FriendlyTypeName @C:\WINDOWS\system32\msxml3r.dll,-1
Reg HKLM\SOFTWARE\Classes\xmlfile\BrowseInPlace
Reg HKLM\SOFTWARE\Classes\xmlfile\BrowseInPlace@
Reg HKLM\SOFTWARE\Classes\xmlfile\CLSID
Reg HKLM\SOFTWARE\Classes\xmlfile\CLSID@ {48123BC4-99D9-11D1-A6B3-00C04FD91555}
Reg HKLM\SOFTWARE\Classes\xmlfile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\xmlfile\DefaultIcon@ C:\WINDOWS\system32\msxml3.dll,0
Reg HKLM\SOFTWARE\Classes\xmlfile\shell
Reg HKLM\SOFTWARE\Classes\xmlfile\shell\Open
Reg HKLM\SOFTWARE\Classes\xmlfile\shell\Open\command
Reg HKLM\SOFTWARE\Classes\xmlfile\shell\Open\command@ "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome
Reg HKLM\SOFTWARE\Classes\xmlfile\shell\Open\ddeexec
Reg HKLM\SOFTWARE\Classes\xmlfile\shell\Open\ddeexec@ "file:%1",,-1,,,,,
Reg HKLM\SOFTWARE\Classes\xmlfile\shell\Open\ddeexec\application
Reg HKLM\SOFTWARE\Classes\xmlfile\shell\Open\ddeexec\application@ IExplore
Reg HKLM\SOFTWARE\Classes\xmlfile\shell\Open\ddeexec\topic
Reg HKLM\SOFTWARE\Classes\xmlfile\shell\Open\ddeexec\topic@ WWW_OpenURL
Reg HKLM\SOFTWARE\Classes\xslfile@ XSL Stylesheet
Reg HKLM\SOFTWARE\Classes\xslfile@FriendlyTypeName @C:\WINDOWS\system32\msxml3r.dll,-2
Reg HKLM\SOFTWARE\Classes\xslfile\BrowseInPlace
Reg HKLM\SOFTWARE\Classes\xslfile\BrowseInPlace@
Reg HKLM\SOFTWARE\Classes\xslfile\CLSID
Reg HKLM\SOFTWARE\Classes\xslfile\CLSID@ {48123BC4-99D9-11D1-A6B3-00C04FD91555}
Reg HKLM\SOFTWARE\Classes\xslfile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\xslfile\DefaultIcon@ C:\WINDOWS\system32\msxml3.dll,1
Reg HKLM\SOFTWARE\Classes\xslfile\shell
Reg HKLM\SOFTWARE\Classes\xslfile\shell\Open
Reg HKLM\SOFTWARE\Classes\xslfile\shell\Open\command
Reg HKLM\SOFTWARE\Classes\xslfile\shell\Open\command@ "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome
Reg HKLM\SOFTWARE\Classes\xslfile\shell\Open\ddeexec
Reg HKLM\SOFTWARE\Classes\xslfile\shell\Open\ddeexec@ "file:%1",,-1,,,,,
Reg HKLM\SOFTWARE\Classes\xslfile\shell\Open\ddeexec\application
Reg HKLM\SOFTWARE\Classes\xslfile\shell\Open\ddeexec\application@ IExplore
Reg HKLM\SOFTWARE\Classes\xslfile\shell\Open\ddeexec\topic
Reg HKLM\SOFTWARE\Classes\xslfile\shell\Open\ddeexec\topic@ WWW_OpenURL
---- EOF - GMER 1.0.14 ----
sexy_ladii05
2008-08-23, 01:12
HEY I Download windows serivce pack what should i do now
Hey :)
Thanks for the log.
I'm back from Mom's place. :crowned:
If you can avoid it -- pleae wait for a bit before installig service pack.
I don't know how SP3 is gunna work with current problems.
You are still in normal mode so that is good progress & I know combofix did good.
Lets try it agian.
This round should show me what it did last time.
Disable Norton then double click ComboFix again.
OK prompt.
Let it do its thing.
It will likely reboot you again.
When it reboots you & finishes its cleanup it should pop up log.
Please post it.
In the event you have to reboot again to restore internet... log is located here:
C:\combofix.log.
Leme know how things are working.
Don't forget to turn Norton back on.
Thanks :)
sexy_ladii05
2008-08-23, 04:37
why you kkeep saying norton i dont have norton and combofix aint working it just load then a blue box comes up saying date error
sexy_ladii05
2008-08-23, 04:38
can we start over from the begin please
Hi,
can we start over from the begin please
As Keaton_1220 you mean? Or How about John22? Someone else?
OK.
Let's get one thing straight here.
We are all volunteers with real jobs, lives, and we all work in many forums.
And we do it for free.
Lotsa people pay alot of money to have their system cleaned up by a computer shop.
When we see people registering under several names comming from the same place this really ticks us off.
It is a waste of our and victim's time.
We and other forums get literally hundreds of people comming in daily for help with their infected computers.
We only have so many helpers and we are all spread thin.
If we can quit the games --- we can continue with your log.
If you wanna keep playing games I'll close the thread, have ya banned and you can try elsewhere.
Got it??
Shall we play nice & continue?
Double click your clock.
When the date/time box pops up please change the date to today.
Where I am it is August 23 2008 1:30AM
Exact time isn't critical -- just make sure the date is right for now.
I told you about Norton cus I see Norton all over the log.
Did you uninstall it & it only partly uninstall?
We'll hafta finish removing that so you can install an antivirus.
Once done resetting the clock please run Hijackthis again & post the new log.
Thanks!
sexy_ladii05
2008-08-23, 20:47
im sorry those aint my accounts there my dum brother he keep posting stuff all over he only 15 and dum im 26 sorry if i cause you some promblems if you dont wanna help me its ok i just remember when you frist started talking to me you told me not to give up i guess your gonan give up on me but here if you still wanna help me
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:35, on 2008-08-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AIM\AIMWDInstall.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {A596175D-BBC7-476A-A152-FBA652B64505} - C:\WINDOWS\system32\mlJDtrQI.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O4 - HKLM\..\Run: [One view global this] C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW\Third Mapi.exe
O4 - HKLM\..\Run: [AIMWDInstallFilename] C:\Program Files\AIM\AIMWDInstall.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O20 - Winlogon Notify: mlJDtrQI - C:\WINDOWS\SYSTEM32\mlJDtrQI.dll
O21 - SSODL: mZUCnvnJwQdJ - {643D5B8D-CE97-F127-8EAA-33AA7BB4B098} - C:\WINDOWS\system32\zgj.dll
O22 - SharedTaskScheduler: Deskscapes - {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Uninterruptible Power Supply (UPS) - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
--
End of file - 5641 bytes
sexy_ladii05
2008-08-23, 20:49
im sorry those aint my accounts there my dum brother he keep posting stuff all over he only 15 and dum im 26 sorry if i cause you some promblems if you dont wanna help me its ok i just remember when you frist started talking to me you told me not to give up i guess your gonan give up on me but here if you still wanna help me
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:35, on 2008-08-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AIM\AIMWDInstall.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {A596175D-BBC7-476A-A152-FBA652B64505} - C:\WINDOWS\system32\mlJDtrQI.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O4 - HKLM\..\Run: [One view global this] C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW\Third Mapi.exe
O4 - HKLM\..\Run: [AIMWDInstallFilename] C:\Program Files\AIM\AIMWDInstall.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O20 - Winlogon Notify: mlJDtrQI - C:\WINDOWS\SYSTEM32\mlJDtrQI.dll
O21 - SSODL: mZUCnvnJwQdJ - {643D5B8D-CE97-F127-8EAA-33AA7BB4B098} - C:\WINDOWS\system32\zgj.dll
O22 - SharedTaskScheduler: Deskscapes - {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Uninterruptible Power Supply (UPS) - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
--
End of file - 5641 bytes
OK.
Just so you know -- we keep an eye on things like that cus it makes things difficult when someone posts under several accounts with the same logs and ends up involving several helpers when only one should be needed.
It is not fair to others that also need our help or helpers trying to help the same person several times.
nuff said.
-------------------
Now that your date is set correctly --- hit it with Combofix again.
Double click Combofix.exe & let it run.
It will likely reboot you.
When done post these logs:
C:\combofix.txt
New hijackthis log
If I dont reply for a while -- I didnt dissapear -- we are having bad storms where I live.
Thanks
sexy_ladii05
2008-08-23, 21:33
combofix didnt save a log i dont know why
_________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:30, on 2008-08-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AIM\AIMWDInstall.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Opera\opera.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O4 - HKLM\..\Run: [One view global this] C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW\Third Mapi.exe
O4 - HKLM\..\Run: [AIMWDInstallFilename] C:\Program Files\AIM\AIMWDInstall.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [643d5b23] rundll32.exe "C:\WINDOWS\system32\ulgrxkaj.dll",b
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O21 - SSODL: mZUCnvnJwQdJ - {643D5B8D-CE97-F127-8EAA-33AA7BB4B098} - C:\WINDOWS\system32\zgj.dll
O22 - SharedTaskScheduler: Deskscapes - {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Uninterruptible Power Supply (UPS) - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
--
End of file - 5393 bytes
Hi,
Can you get to this site yet?
http://www.microsoft.com/downloads/details.aspx?FamilyId=535D248D-5E10-49B5-B80C-0A0205368124
If you get there --- go ahead and download the file but don't do anything yet.
Just downloadf it and save it to desktop and tell me if you got it.
C:\Combofix.txt
C:\combofix\combofix.txt
C:\combofix\log.txt
C:\bug.txt
C:\qoobox\quarantined files.txt
Any of those files present?
If so --- post them please.
Next I wanna see another scan.
This one is a stand alone virus scanner/cleaner.
Download Dr.Webs CureIt to your desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
Double-click the drweb-cureit.exe file and allow it to run the express scan.
This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
Once the short scan has finished, select the "full system scan"
Click the green arrow > to the right and the scan will begin.
At the first infection, select 'Yes to all' if it asks if you want to cure/move the file.
When the scan has finished, click the "Select all" toggle button (if available) next to the files found
Then click the green cup icon right below and select Move incurable
This will move any infected files to the %userprofile%\DoctorWeb\quarantaine-folder that can't be cured (in case if we need samples).
Then, from the main Dr.Web CureIt menu (top left), click File and choose save report list
Save the report to your desktop. The report will be called DrWeb.csv
Close Dr.Web Cureit and Restart your computer to completely remove any stubborn files in reboot.
Post back with the DrWeb.csv report please.
Thanks :)
sexy_ladii05
2008-08-24, 04:31
nothing works and now my wireless connect that had dns is back should i discontuine using that wireless service?
and just says connect to router and present this
Warning! A Trojan Virus has reconfigured your Network / Internet settings.
The Cox Communications Network Security Team has detected that a change was made to your Network / Internet Connection settings. The change was caused by a Trojan Virus.
Your Next Steps: You can easily restore the settings and Internet access on your own with the instructions below.
To reset the settings yourself:
OSX/MAC users click HERE
Identify the operating system on your computer:
Click the Start button in the taskbar.
Click Control Panel.
Double-click System.
Result: The name of your operation system is listed: it is either Windows 2000, Windows XP or Windows Vista.
Select and follow the instructions below for your operating system. Completing the instructions will reset your Network / Internet (TCP/IP) settings.
Note: If your pop-up blocker is active, you may need to temporarily allow popups to view the links below.
Operating System Instructions
Window 2000
Windows XP
Windows Vista How to: Set Up Windows 2000 for Cox High Speed Internet
How to: Set Up TCP/IP for Windows XP
How to: Set Up TCP/IP for Windows Vista
After completing the instructions, reboot your computer.
Launch your Internet browser to access a webpage.
If you are redirected to this webpage again, then the Trojan Virus is still active on your computer, even though the Internet TCP/IP settings were corrected. Follow the instructions in How to: Trojan / Virus Removal to clean your computer.
All steps complete.
Thank you for using Cox High Speed Internet.
Cox Online Privacy Policy and Related Terms and Agreements
Hi,
What do you mean by "nothing works"?
Did you get that cureit.exe downloaded?
Follow instructions from COX to reset your TCP/IP settings and see if it sticks.
Then......
Before running the scan let's clean out the temporoary folders.
Download ATF Cleaner (http://www.atribune.org/ccount/click.php?id=1)
Double-click ATF-Cleaner.exe to run the program. (If running Vista, right click it and choose "run as administrator)
Click Select All found at the bottom of the list.
Click the Empty Selected button.
If you use Firefox browser, do this also:
Click Firefox at the top and choose Select All from the list.
Click the Empty Selected button.
NOTE : If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser, do this also:
Click Opera at the top and choose Select All from the list.
Click the Empty Selected button.
NOTE : If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
Now download OTScanIT.exe (http://download.bleepingcomputer.com/oldtimer/OTScanIt.exe) to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIT on your desktop.
Note: You must be logged on to the system with an account that has Administrator privileges to run this program.
Close ALL OTHER PROGRAMS.
Open the OTScanIT folder and double-click on OTScanIT.exe to start the program (if you are running on Vista then right-click the program and choose Run as Administrator).
In the Drivers section click on Non-Microsoft.
In the rootkit section click on yes
Under Additional Scans click the checkboxes in front of the following items to select them:
Reg - BotCheck
File - Additional Folder Scans
Do not change any other settings.
Now click the Run Scan button on the toolbar.
Let it run unhindered until it finishes.
When the scan is complete Notepad will open with the report file loaded in it.
Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and Copy/Paste the information back here. I will review it when it comes in. Make sure that the first line is code with brackets around it [] and that the last line is /code with brackets around it [].
If, after posting, the last line is not /code with brackets around it then the log is too big to fit into a single post and you will need to split it into multiple posts or attach it as a file.
Thanks
sexy_ladii05
2008-08-24, 16:28
none of those websites work that you giving me
ComboFix 08-08-21.02 -keaton77 2008-08-23 10:59:05.3 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.66 [GMT -8:00]
Running from: C:\Documents and Settings\keaton77\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\keaton77\Application Data\macromedia\Flash Player\#SharedObjects\FL6QBNRZ\interclick.com
C:\Documents and Settings\keaton77\Application Data\macromedia\Flash Player\#SharedObjects\FL6QBNRZ\interclick.com\ud.sol
C:\Documents and Settings\keaton77\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\keaton77\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\WINDOWS\system32\dynmkuoj.dll
C:\WINDOWS\system32\gtemxe.dll
C:\WINDOWS\system32\jakxrglu.ini
C:\WINDOWS\system32\ulgrxkaj.dll
C:\WINDOWS\system32\VxbaJkkj.ini
C:\WINDOWS\system32\VxbaJkkj.ini2
.
---- Previous Run -------
.
C:\WINDOWS\system32\fmjdoveu.dll
C:\WINDOWS\system32\lvwbnb.dll
C:\WINDOWS\system32\qhoseeiw.dll
C:\WINDOWS\system32\uevodjmf.ini
C:\WINDOWS\system32\VxbaJkkj.ini
C:\WINDOWS\system32\VxbaJkkj.ini2
.
((((((((((((((((((((((((( Files Created from 2008-07-23 to 2008-08-23 )))))))))))))))))))))))))))))))
.
2008-08-23 08:38 . 2008-08-23 08:45 220,176 --a------ C:\WINDOWS\system32\xxyywuRH.dll
2008-08-23 01:35 . 2008-08-23 01:35 323,328 --a------ C:\WINDOWS\system32\jkkJabxV.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-17 05:34 --------- d-----w C:\Documents and Settings\keaton77\Application Data\acccore
2008-07-15 06:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-15 06:31 --------- d-----w C:\Program Files\Trend Micro
2008-07-14 05:07 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-14 05:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-14 01:47 --------- d-----w C:\Program Files\Opera
2008-07-13 18:35 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-07-12 01:04 96,520 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-12 01:04 76,040 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-12 01:04 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-07-01 18:35 94,208 ----a-w C:\WINDOWS\system32\3C.tmp
2008-07-01 18:35 94,208 ----a-w C:\WINDOWS\system32\3A.tmp
2008-07-01 18:35 94,208 ----a-w C:\WINDOWS\system32\38.tmp
2008-07-01 18:35 94,208 ----a-w C:\WINDOWS\system32\37.tmp
2008-07-01 18:35 94,208 ----a-w C:\WINDOWS\system32\36.tmp
2008-07-01 18:35 94,208 ----a-w C:\WINDOWS\system32\35.tmp
2008-07-01 18:35 94,208 ----a-w C:\WINDOWS\system32\34.tmp
2008-07-01 18:35 94,208 ----a-w C:\WINDOWS\system32\2F.tmp
2008-07-01 08:46 94,208 ----a-w C:\WINDOWS\system32\33.tmp
2008-07-01 08:46 94,208 ----a-w C:\WINDOWS\system32\32.tmp
2008-07-01 08:46 94,208 ----a-w C:\WINDOWS\system32\31.tmp
2008-07-01 08:46 94,208 ----a-w C:\WINDOWS\system32\30.tmp
2008-07-01 08:46 94,208 ----a-w C:\WINDOWS\system32\2E.tmp
2008-07-01 08:45 94,208 ----a-w C:\WINDOWS\system32\2D.tmp
2008-07-01 08:45 94,208 ----a-w C:\WINDOWS\system32\2C.tmp
2008-07-01 08:45 94,208 ----a-w C:\WINDOWS\system32\2B.tmp
2008-07-01 08:45 94,208 ----a-w C:\WINDOWS\system32\2A.tmp
2008-07-01 08:45 94,208 ----a-w C:\WINDOWS\system32\29.tmp
2008-07-01 08:45 94,208 ----a-w C:\WINDOWS\system32\28.tmp
2008-07-01 08:45 94,208 ----a-w C:\WINDOWS\system32\27.tmp
2008-07-01 08:45 94,208 ----a-w C:\WINDOWS\system32\26.tmp
2008-07-01 08:44 94,208 ----a-w C:\WINDOWS\system32\25.tmp
2008-07-01 08:44 94,208 ----a-w C:\WINDOWS\system32\23.tmp
2008-07-01 08:44 94,208 ----a-w C:\WINDOWS\system32\22.tmp
2008-07-01 08:44 94,208 ----a-w C:\WINDOWS\system32\21.tmp
2008-07-01 08:44 94,208 ----a-w C:\WINDOWS\system32\20.tmp
2008-07-01 08:15 94,208 ----a-w C:\WINDOWS\system32\7CA.tmp
2008-06-28 03:55 34,688 ------w C:\WINDOWS\system32\mlJDtrQI.dll
2008-06-28 02:26 --------- d-----w C:\Program Files\AIM6
2008-06-27 23:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\acccore
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-06 16:24 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-06-06 16:24 307,200 ------w C:\WINDOWS\Setup1.exe
2007-04-23 22:21 269,824 ----a-w C:\WINDOWS\inf\WG111v3\Vista64\wg111v3.sys
2007-04-23 22:11 224,896 ----a-w C:\WINDOWS\inf\WG111v3\wg111v3.sys
2006-12-15 19:30 98,304 ----a-w C:\WINDOWS\inf\WG111v3\UScanM.exe
2006-12-15 19:30 66,048 ----a-w C:\WINDOWS\inf\WG111v3\EAPPkt.sys
2006-12-15 19:30 315,392 ----a-w C:\WINDOWS\inf\WG111v3\InstallDriver.exe
2006-12-15 19:30 28,672 ----a-w C:\WINDOWS\inf\WG111v3\SetDrv.exe
2006-12-15 19:30 212,992 ----a-w C:\WINDOWS\inf\WG111v3\CopyWHQLDriver.exe
2006-12-15 19:30 20,480 ----a-w C:\WINDOWS\inf\WG111v3\RTWUPath.exe
2006-12-15 19:30 19,968 ----a-w C:\WINDOWS\inf\WG111v3\RTWREFU.EXE
.
------- Sigcheck -------
md5deep: C:\WINDOWS\system32\svchost.exe: error at offset 0: Permission denied
md5deep: C:\WINDOWS\system32\winlogon.exe: error at offset 0: Permission denied
md5deep: C:\WINDOWS\explorer.exe: error at offset 0: Permission denied
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\VCP_TEMP\explorer.exe
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\VCP_SAVE\explorer.exe
2007-06-13 00:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2gdr\explorer.exe
2007-06-13 00:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2qfe\explorer.exe
2002-12-31 12:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
md5deep: C:\WINDOWS\system32\services.exe: error at offset 0: Permission denied
md5deep: C:\WINDOWS\system32\lsass.exe: error at offset 0: Permission denied
md5deep: C:\WINDOWS\system32\spoolsv.exe: error at offset 0: Permission denied
2005-06-10 17:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2002-12-31 13:00 57856 7435b108b935e42ea92ca94f59c8e717 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A596175D-BBC7-476A-A152-FBA652B64505}]
2008-06-27 19:55 34688 --------- C:\WINDOWS\system32\mlJDtrQI.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C9F706D6-B43A-4B64-AAD5-B37B1A749AFE}]
2008-08-23 01:35 323328 --a------ C:\WINDOWS\system32\jkkJabxV.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-06-19 09:51 50528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"One view global this"="C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW\Third Mapi.exe" [2008-08-23 11:54 21544448]
"AIMWDInstallFilename"="C:\Program Files\AIM\AIMWDInstall.exe" [2004-01-12 09:29 102400]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 21:59 115816]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 08:59 124520]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"643d5b23"="C:\WINDOWS\system32\ulgrxkaj.dll" [BU]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v3 Smart Wizard.lnk - C:\Program Files\NETGEAR\WG111v3\WG111v3.exe [2007-09-12 15:14:42 1527808]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{A596175D-BBC7-476A-A152-FBA652B64505}"= "C:\WINDOWS\system32\mlJDtrQI.dll" [2008-06-27 19:55 34688]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"mZUCnvnJwQdJ"= {643D5B8D-CE97-F127-8EAA-33AA7BB4B098} - C:\WINDOWS\system32\zgj.dll [2007-04-16 04:52 32768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJDtrQI]
2008-06-27 19:55 34688 C:\WINDOWS\system32\mlJDtrQI.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=lvwbnb.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= jl_mjpg2.drv
"msacm.fraunhoferacm"= l3codecp.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Spybot - Search & Destroy\\SDShred.exe"=
"C:\\Program Files\\NETGEAR\\WG111v3\\WG111v3.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-11 17:04]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-11 17:04]
R3 ctlsb16;Creative SB16/AWE32/AWE64 Driver (WDM);C:\WINDOWS\system32\drivers\ctlsb16.sys [2004-12-24 11:15]
R3 es1969;ESS 1969 Audio Driver (WDM);C:\WINDOWS\system32\drivers\es1969.sys [2004-12-24 11:15]
R3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys [2004-12-24 11:15]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;C:\WINDOWS\system32\DRIVERS\wg111v3.sys [2007-04-23 14:11]
R3 S3SAVAGE4M;S3SAVAGE4M;C:\WINDOWS\system32\DRIVERS\s3sav4m.sys [2004-12-24 11:16]
S1 SABKUTIL;SABKUTIL;C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys []
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 09:05]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;C:\WINDOWS\system32\drivers\ScreamingBAudio.sys []
S3 USRTI;U.S. Robotics Faxmodem Driver TI;C:\WINDOWS\system32\DRIVERS\USRTI.SYS [2004-12-24 11:16]
.
Contents of the 'Scheduled Tasks' folder
2008-07-03 C:\WINDOWS\Tasks\rpc.job
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe []
2008-08-23 C:\WINDOWS\Tasks\B8EEA5EA89AD5906.job
- c:\docume~1\keaton12\applic~1\defyop~1\that mode mags.exe []
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\keaton77\Application Data\Mozilla\Firefox\Profiles\c9zjcure.default\
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npunagi2.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava11.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava12.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava13.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava14.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava32.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjpi160_03.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npoji610.dll
.
.
------- File Associations (Beta) -------
.
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-23 11:09:24
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\mlJDtrQI.dll
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\jkkJabxV.dll
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSVCHST.EXE
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-08-23 11:22:29 - machine was rebooted [keaton77]
ComboFix-quarantined-files.txt 2008-08-23 19:21:50
ComboFix2.txt 2008-08-23 03:01:08
Pre-Run: 7,908,294,656 bytes free
Post-Run: 7,863,582,720 bytes free
228 --- E O F --- 2008-06-27 21:26:32
Hi Keaton & thanks for the log.
When you say none of the sites work I give you --- what do you mean?
You get "page cannot be displayed" or browser just freezes?
Download the attached cfscript.txt file to your desktop.
Close running programs and temporarily disable your antivirus.
Drag cfscript.txt on top of combofix.exe & drop it.
Let Combofix do its thing.
Post the new C:\combofix.txt when done please.
Let me know how machine is running.
Thanks
sexy_ladii05
2008-08-25, 00:29
i try the cox reset but didnt do anything it comes right back and computer running good so far =]
ComboFix 08-08-21.02 - keaton77 2008-08-23 18:28:46.4 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.127 [GMT -8:00]
Running from: C:\Documents and Settings\keaton77\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\keaton77\Desktop\cfscript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\system32\20.tmp
C:\WINDOWS\system32\21.tmp
C:\WINDOWS\system32\22.tmp
C:\WINDOWS\system32\23.tmp
C:\WINDOWS\system32\25.tmp
C:\WINDOWS\system32\26.tmp
C:\WINDOWS\system32\27.tmp
C:\WINDOWS\system32\28.tmp
C:\WINDOWS\system32\29.tmp
C:\WINDOWS\system32\2A.tmp
C:\WINDOWS\system32\2B.tmp
C:\WINDOWS\system32\2C.tmp
C:\WINDOWS\system32\2D.tmp
C:\WINDOWS\system32\2E.tmp
C:\WINDOWS\system32\2F.tmp
C:\WINDOWS\system32\30.tmp
C:\WINDOWS\system32\31.tmp
C:\WINDOWS\system32\32.tmp
C:\WINDOWS\system32\33.tmp
C:\WINDOWS\system32\34.tmp
C:\WINDOWS\system32\35.tmp
C:\WINDOWS\system32\36.tmp
C:\WINDOWS\system32\37.tmp
C:\WINDOWS\system32\38.tmp
C:\WINDOWS\system32\3A.tmp
C:\WINDOWS\system32\3C.tmp
C:\WINDOWS\system32\7CA.tmp
C:\WINDOWS\system32\jkkJabxV.dll
C:\windows\system32\lvwbnb.dll
C:\WINDOWS\system32\mlJDtrQI.dll
C:\WINDOWS\system32\ulgrxkaj.dll
C:\WINDOWS\system32\xxyywuRH.dll
C:\WINDOWS\system32\zgj.dll
C:\WINDOWS\Tasks\B8EEA5EA89AD5906.job
C:\WINDOWS\Tasks\rpc.job
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW
C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW\face info.exe
C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW\the license.exe
C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW\Third Mapi.exe
C:\WINDOWS\system32\20.tmp
C:\WINDOWS\system32\21.tmp
C:\WINDOWS\system32\22.tmp
C:\WINDOWS\system32\23.tmp
C:\WINDOWS\system32\25.tmp
C:\WINDOWS\system32\26.tmp
C:\WINDOWS\system32\27.tmp
C:\WINDOWS\system32\28.tmp
C:\WINDOWS\system32\29.tmp
C:\WINDOWS\system32\2A.tmp
C:\WINDOWS\system32\2B.tmp
C:\WINDOWS\system32\2C.tmp
C:\WINDOWS\system32\2D.tmp
C:\WINDOWS\system32\2E.tmp
C:\WINDOWS\system32\2F.tmp
C:\WINDOWS\system32\30.tmp
C:\WINDOWS\system32\31.tmp
C:\WINDOWS\system32\32.tmp
C:\WINDOWS\system32\33.tmp
C:\WINDOWS\system32\34.tmp
C:\WINDOWS\system32\35.tmp
C:\WINDOWS\system32\36.tmp
C:\WINDOWS\system32\37.tmp
C:\WINDOWS\system32\38.tmp
C:\WINDOWS\system32\3A.tmp
C:\WINDOWS\system32\3C.tmp
C:\WINDOWS\system32\7CA.tmp
C:\WINDOWS\system32\dpkpvwkm.ini
C:\WINDOWS\system32\erludhrw.dll
C:\WINDOWS\system32\jkkJabxV.dll
C:\WINDOWS\system32\mkwvpkpd.dll
C:\WINDOWS\system32\mlJDtrQI.dll
C:\WINDOWS\system32\VxbaJkkj.ini
C:\WINDOWS\system32\VxbaJkkj.ini2
C:\WINDOWS\system32\xgfvop.dll
C:\WINDOWS\system32\xxyywuRH.dll
C:\WINDOWS\system32\zgj.dll
C:\WINDOWS\Tasks\B8EEA5EA89AD5906.job
C:\WINDOWS\Tasks\rpc.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SABKUTIL
-------\Service_SABKUTIL
((((((((((((((((((((((((( Files Created from 2008-07-24 to 2008-08-24 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-17 05:34 --------- d-----w C:\Documents and Settings\keaton77\Application Data\acccore
2008-07-15 06:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-15 06:31 --------- d-----w C:\Program Files\Trend Micro
2008-07-14 05:07 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-14 05:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-14 01:47 --------- d-----w C:\Program Files\Opera
2008-07-13 18:35 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-07-12 01:04 96,520 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-12 01:04 76,040 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-12 01:04 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-06-28 02:26 --------- d-----w C:\Program Files\AIM6
2008-06-27 23:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\acccore
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-06 16:24 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-06-06 16:24 307,200 ------w C:\WINDOWS\Setup1.exe
2007-04-23 22:21 269,824 ----a-w C:\WINDOWS\inf\WG111v3\Vista64\wg111v3.sys
2007-04-23 22:11 224,896 ----a-w C:\WINDOWS\inf\WG111v3\wg111v3.sys
2006-12-15 19:30 98,304 ----a-w C:\WINDOWS\inf\WG111v3\UScanM.exe
2006-12-15 19:30 66,048 ----a-w C:\WINDOWS\inf\WG111v3\EAPPkt.sys
2006-12-15 19:30 315,392 ----a-w C:\WINDOWS\inf\WG111v3\InstallDriver.exe
2006-12-15 19:30 28,672 ----a-w C:\WINDOWS\inf\WG111v3\SetDrv.exe
2006-12-15 19:30 212,992 ----a-w C:\WINDOWS\inf\WG111v3\CopyWHQLDriver.exe
2006-12-15 19:30 20,480 ----a-w C:\WINDOWS\inf\WG111v3\RTWUPath.exe
2006-12-15 19:30 19,968 ----a-w C:\WINDOWS\inf\WG111v3\RTWREFU.EXE
.
------- Sigcheck -------
2002-12-31 12:00 17408 c9a2fa38b23562f3bb2153b33c95ea8f C:\WINDOWS\system32\svchost.exe
2002-12-31 12:00 506368 e6ffe7a15b04504a8a34d5b950e23f0e C:\WINDOWS\system32\winlogon.exe
2007-06-12 23:23 1035776 19f69b94e52b8d83c6889791dcae304b C:\WINDOWS\explorer.exe
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\VCP_TEMP\explorer.exe
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\VCP_SAVE\explorer.exe
2007-06-13 00:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2gdr\explorer.exe
2007-06-13 00:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2qfe\explorer.exe
2002-12-31 12:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2002-12-31 12:00 110592 cb7a2c2b70518545a022025a92e9a77f C:\WINDOWS\system32\services.exe
2002-12-31 12:00 14848 1a074603db3751a4e77492433afabfca C:\WINDOWS\system32\lsass.exe
2005-06-10 16:53 58880 5305ef86e1dfb4b733438607b74e04d9 C:\WINDOWS\system32\spoolsv.exe
2005-06-10 17:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2002-12-31 13:00 57856 7435b108b935e42ea92ca94f59c8e717 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-06-19 09:51 50528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIMWDInstallFilename"="C:\Program Files\AIM\AIMWDInstall.exe" [2004-01-12 09:29 102400]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 21:59 115816]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 08:59 124520]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v3 Smart Wizard.lnk - C:\Program Files\NETGEAR\WG111v3\WG111v3.exe [2007-09-12 15:14:42 1527808]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= jl_mjpg2.drv
"msacm.fraunhoferacm"= l3codecp.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Spybot - Search & Destroy\\SDShred.exe"=
"C:\\Program Files\\NETGEAR\\WG111v3\\WG111v3.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-11 17:04]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-11 17:04]
R3 ctlsb16;Creative SB16/AWE32/AWE64 Driver (WDM);C:\WINDOWS\system32\drivers\ctlsb16.sys [2004-12-24 11:15]
R3 es1969;ESS 1969 Audio Driver (WDM);C:\WINDOWS\system32\drivers\es1969.sys [2004-12-24 11:15]
R3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys [2004-12-24 11:15]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;C:\WINDOWS\system32\DRIVERS\wg111v3.sys [2007-04-23 14:11]
R3 S3SAVAGE4M;S3SAVAGE4M;C:\WINDOWS\system32\DRIVERS\s3sav4m.sys [2004-12-24 11:16]
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 09:05]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;C:\WINDOWS\system32\drivers\ScreamingBAudio.sys []
S3 USRTI;U.S. Robotics Faxmodem Driver TI;C:\WINDOWS\system32\DRIVERS\USRTI.SYS [2004-12-24 11:16]
.
Contents of the 'Scheduled Tasks' folder
2008-08-24 C:\WINDOWS\Tasks\AC43817194383B35.job
- c:\docume~1\keaton20\applic~1\defyop~1\that mode mags.exe []
2008-07-13 C:\WINDOWS\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe []
2008-08-24 C:\WINDOWS\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe []
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-23 19:24:17
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSVCHST.EXE
C:\WINDOWS\SYSTEM32\MSDTC.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2008-08-23 19:26:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-24 03:26:42
ComboFix3.txt 2008-08-23 03:01:08
ComboFix2.txt 2008-08-23 19:22:38
Pre-Run: 7,672,954,880 bytes free
Post-Run: 7,617,593,344 bytes free
220 --- E O F --- 2008-06-27 21:26:32
sexy_ladii05
2008-08-25, 01:56
OTScanIt logfile created on: 2008-08-23 20:53:34
OTScanIt by OldTimer - Version 1.0.16.2 Folder = C:\Documents and Settings\keaton77\Desktop\OTScanIt
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: | Country: | Language: | Date Format: yyyy-MM-dd
255.48 Mb Total Physical Memory | 116.82 Mb Available Physical Memory | 45.73% Memory free
615.73 Mb Paging File | 395.91 Mb Available in Paging File | 64.30% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.63 Gb Total Space | 7.11 Gb Free Space | 38.18% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KEATON
Current User Name: keaton77
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
[Processes - Non-Microsoft Only]
ccsvchst.exe -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> Symantec Corporation [Ver = 106.2.0.21 | Size = 108648 bytes | Modified Date = 2007-01-09 21:59:32 | Attr = ]
aimwdinstall.exe -> %ProgramFiles%\AIM\AIMWDInstall.exe -> Wild Tangent [Ver = 1.0.0.28 | Size = 102400 bytes | Modified Date = 2004-01-12 09:29:28 | Attr = ]
ccapp.exe -> %CommonProgramFiles%\Symantec Shared\ccApp.exe -> Symantec Corporation [Ver = 106.2.0.21 | Size = 115816 bytes | Modified Date = 2007-01-09 21:59:52 | Attr = ]
jusched.exe -> %ProgramFiles%\Java\jre1.6.0_03\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 2007-09-25 01:11:36 | Attr = ]
aim6.exe -> %ProgramFiles%\AIM6\aim6.exe -> AOL LLC [Ver = 1.4.9.1 | Size = 50528 bytes | Modified Date = 2008-06-19 09:51:32 | Attr = ]
aolload.exe -> %CommonProgramFiles%\AOL\Loader\aolload.exe -> AOL LLC [Ver = 9.3.2.2 | Size = 10800 bytes | Modified Date = 2006-11-03 02:17:28 | Attr = ]
aolsoftware.exe -> %ProgramFiles%\AIM6\aolsoftware.exe -> AOL LLC [Ver = 15.6.1.1 | Size = 41824 bytes | Modified Date = 2007-10-08 13:50:56 | Attr = ]
opera.exe -> %ProgramFiles%\Opera\opera.exe -> Opera Software [Ver = 10081 | Size = 98816 bytes | Modified Date = 2008-06-30 17:59:02 | Attr = ]
otscanit.exe -> %UserProfile%\Desktop\OTScanIt\OTScanIt.exe -> OldTimer Tools [Ver = 1.0.16.2 | Size = 397312 bytes | Modified Date = 2008-07-12 09:29:54 | Attr = ]
[Win32 Services - Non-Microsoft Only]
(AcrSch2Svc) Acronis Scheduler2 Service [Win32_Own | Auto | Stopped] -> -> File not found
(avg8emc) AVG Free8 E-mail Scanner [Win32_Own | Auto | Stopped] -> -> File not found
(avg8wd) AVG Free8 WatchDog [Win32_Own | Auto | Stopped] -> -> File not found
(ccEvtMgr) Symantec Event Manager [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> Symantec Corporation [Ver = 106.2.0.21 | Size = 108648 bytes | Modified Date = 2007-01-09 21:59:32 | Attr = ]
(ccPwdSvc) Symantec Password Validation [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\ccPwdSvc.exe -> Symantec Corporation [Ver = 103.0.3.8 | Size = 79472 bytes | Modified Date = 2004-12-13 15:30:08 | Attr = ]
(ccSetMgr) Symantec Settings Manager [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> Symantec Corporation [Ver = 106.2.0.21 | Size = 108648 bytes | Modified Date = 2007-01-09 21:59:32 | Attr = ]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
(FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> Macrovision Europe Ltd. [Ver = 11.03.005 | Size = 654848 bytes | Modified Date = 2008-05-04 19:53:16 | Attr = ]
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 2005-04-04 00:41:10 | Attr = ]
(UPS) Uninterruptible Power Supply [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\System32\ups.exe -> File not found
[Driver Services - Non-Microsoft Only]
(AegisP) AEGIS Protocol (IEEE 802.1x) v3.4.5.0 [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\AegisP.sys -> Meetinghouse Data Communications [Ver = 3.4.5.0 | Size = 21035 bytes | Modified Date = 2008-03-01 23:06:48 | Attr = ]
(ASPI) Advanced SCSI Programming Interface Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\DRIVERS\ASPI32.sys -> Adaptec [Ver = 4.71 (0002) built by: WinDDK | Size = 16512 bytes | Modified Date = 2002-07-17 09:05:10 | Attr = ]
(AvgLdx86) AVG Free AVI Loader Driver x86 [Kernel | System | Running] -> %SystemRoot%\System32\Drivers\avgldx86.sys -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.116 | Size = 96520 bytes | Modified Date = 2008-07-11 17:04:08 | Attr = ]
(AvgMfx86) AVG Free On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> %SystemRoot%\System32\Drivers\avgmfx86.sys -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.132 | Size = 26824 bytes | Modified Date = 2008-07-11 17:04:06 | Attr = ]
(AvgTdiX) AVG Free8 Network Redirector [Kernel | Auto | Running] -> %SystemRoot%\System32\Drivers\avgtdix.sys -> AVG Technologies CZ, s.r.o. [Ver = 8.0.0.116 | Size = 76040 bytes | Modified Date = 2008-07-11 17:04:08 | Attr = ]
(ctlsb16) Creative SB16/AWE32/AWE64 Driver (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ctlsb16.sys -> Copyright (C) Creative Technology Ltd. 1994-2001 [Ver = 5.1.2501.0 built by: WinDDK | Size = 96256 bytes | Modified Date = 2004-12-24 11:15:52 | Attr = ]
(dmboot) dmboot [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\dmboot.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 799744 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
(dmio) Logical Disk Manager Driver [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\dmio.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 153344 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
(dmload) dmload [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\dmload.sys -> Microsoft Corp., Veritas Software. [Ver = 2600.0.503.0 | Size = 5888 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
(ds1) Yamaha DS1 Audio Driver (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ds1wdm.sys -> Yamaha Corp. [Ver = 5.1.2501.0 built by: WinDDK | Size = 334208 bytes | Modified Date = 2004-12-24 11:15:54 | Attr = ]
(es1969) ESS 1969 Audio Driver (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\es1969.sys -> ESS Technology Inc. [Ver = 5.1.2501.0 built by: WinDDK | Size = 72192 bytes | Modified Date = 2004-12-24 11:15:58 | Attr = ]
(FA312) NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\FA312nd5.sys -> NETGEAR Corp. [Ver = 5.00.119.0 | Size = 16074 bytes | Modified Date = 2004-12-24 11:15:58 | Attr = ]
(GEARAspiWDM) GEAR CDRom Filter [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\GEARAspiWDM.sys -> GEAR Software Inc. [Ver = 2.00.07.03 | Size = 16168 bytes | Modified Date = 2008-01-29 12:01:28 | Attr = ]
(gmer) gmer [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\DRIVERS\gmer.sys -> GMER [Ver = 1, 0, 14, 4401 | Size = 85969 bytes | Modified Date = 2008-07-17 17:46:44 | Attr = ]
(NPPTNT2) NPPTNT2 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\npptNT2.sys -> INCA Internet Co., Ltd. [Ver = 2005, 1, 5, 1 | Size = 4682 bytes | Modified Date = 2004-12-31 16:43:08 | Attr = ]
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ptilink.sys -> Parallel Technologies, Inc. [Ver = 1.10 (XPClient.010817-1148) | Size = 17792 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
(RTL8187B) NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\wg111v3.sys -> Realtek Semiconductor Corporation [Ver = 5.1080.0423.2007 built by: WinDDK | Size = 224896 bytes | Modified Date = 2007-04-23 14:11:54 | Attr = ]
(S3SAVAGE4M) S3SAVAGE4M [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\s3sav4m.sys -> S3 Incorporated [Ver = 5.12.01.8012-8.40.03 built by: ReleasedBinaries | Size = 77824 bytes | Modified Date = 2004-12-24 11:16:14 | Attr = ]
(SABProcEnum) SABProcEnum [Kernel | On_Demand | Stopped] -> %ProgramFiles%\SuperAdBlocker.com\Super Ad Blocker\SABProcEnum.sys -> File not found
(SCREAMINGBDRIVER) Screaming Bee Audio [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\ScreamingBAudio.sys -> File not found
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\secdrv.sys -> Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. [Ver = 4.03.086 | Size = 20480 bytes | Modified Date = 2007-11-13 05:25:54 | Attr = ]
(sptd) sptd [Kernel | Boot | Running] -> %SystemRoot%\System32\Drivers\sptd.sys -> [Ver = | Size = 717296 bytes | Modified Date = 2008-07-13 10:35:30 | Attr = ]
(tifsfilter) Acronis True Image FS Filter [File_System | Auto | Running] -> %SystemRoot%\system32\DRIVERS\tifsfilt.sys -> Acronis [Ver = 4,0,0,469 | Size = 44384 bytes | Modified Date = 2007-12-27 21:30:32 | Attr = ]
(timounter) Acronis True Image Backup Archive Explorer [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\timntr.sys -> Acronis [Ver = 4,0,0,469 | Size = 441760 bytes | Modified Date = 2007-12-27 21:30:32 | Attr = ]
(TPkd) TPkd [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\TPkd.sys -> PACE Anti-Piracy, Inc. [Ver = 5.5.1.2622 | Size = 78648 bytes | Modified Date = 2007-03-13 11:54:38 | Attr = ]
(USRTI) U.S. Robotics Faxmodem Driver TI [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\USRTI.SYS -> U.S. Robotics, Inc. [Ver = 2.60.005 | Size = 765884 bytes | Modified Date = 2004-12-24 11:16:18 | Attr = ]
(wanatw) WAN Miniport (ATW) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\wanatw4.sys -> America Online, Inc. [Ver = 8.3.0.0 | Size = 33588 bytes | Modified Date = 2003-01-10 16:13:04 | Attr = ]
(zntport) NTPort Library Driver [Kernel | Auto | Stopped] -> %SystemRoot%\system32\zntport.sys -> File not found
[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
AIMWDInstallFilename -> %ProgramFiles%\AIM\AIMWDInstall.exe [C:\Program Files\AIM\AIMWDInstall.exe] -> Wild Tangent [Ver = 1.0.0.28 | Size = 102400 bytes | Modified Date = 2004-01-12 09:29:28 | Attr = ]
ccApp -> %CommonProgramFiles%\Symantec Shared\ccApp.exe ["C:\Program Files\Common Files\Symantec Shared\ccApp.exe"] -> Symantec Corporation [Ver = 106.2.0.21 | Size = 115816 bytes | Modified Date = 2007-01-09 21:59:52 | Attr = ]
IPHSend -> %CommonProgramFiles%\AOL\IPHSend\IPHSend.exe [C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe] -> America Online, Inc. [Ver = 1.0.12.1 | Size = 124520 bytes | Modified Date = 2006-02-17 08:59:48 | Attr = ]
SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.6.0_03\bin\jusched.exe [C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 2007-09-25 01:11:36 | Attr = ]
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
Aim6 -> %ProgramFiles%\AIM6\aim6.exe ["C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp] -> AOL LLC [Ver = 1.4.9.1 | Size = 50528 bytes | Modified Date = 2008-06-19 09:51:32 | Attr = ]
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
%AllUsersProfile%\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk -> %ProgramFiles%\NETGEAR\WG111v3\WG111v3.exe -> [Ver = 3, 6, 28, 314 | Size = 1527808 bytes | Modified Date = 2007-09-12 15:14:42 | Attr = ]
< SharedTaskScheduler [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler ->
{EC654325-1273-C2A9-2B7C-45D29BCE68FB} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Deskscapes] -> File not found
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> %SystemRoot%\Explorer.exe -> Microsoft Corporation [Ver = 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234) | Size = 1035776 bytes | Modified Date = 2007-06-12 23:23:08 | Attr = ]
*MultiFile Done* -> ->
*UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit ->
C:\WINDOWS\system32\userinit.exe -> %SystemRoot%\system32\userinit.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 24576 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
*MultiFile Done* -> ->
*UIHost* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost ->
logonui.exe -> %SystemRoot%\system32\logonui.exe -> Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 514560 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
*MultiFile Done* -> ->
*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet ->
rundll32 shell32 -> %SystemRoot%\System32\shell32.dll -> Microsoft Corporation [Ver = 6.00.2900.3241 (xpsp_sp2_qfe.071025-1245) | Size = 8460288 bytes | Modified Date = 2007-10-25 22:34:02 | Attr = ]
Control_RunDLL "sysdm.cpl" -> %SystemRoot%\system32\sysdm.cpl -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 298496 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
*MultiFile Done* -> ->
< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\ForceClassicControlPanel -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 255 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun -> 67108863 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\DisableStatusMessages -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\NoInternetOpenWith -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\DisableRegistryTools -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideLegacyLogonScripts -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideLogoffScripts -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\RunLogonScriptSync -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\RunStartupScriptSync -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideStartupScripts -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
< CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLegacyLogonScripts -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLogoffScripts -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunLogonScriptSync -> 1 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunStartupScriptSync -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideStartupScripts -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
< CDROM Autorun Settings > [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\ -> ->
*DependOnGroup* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\DependOnGroup ->
SCSI miniport -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\ErrorControl -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Group -> SCSI CDROM Class ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Start -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Tag -> 2 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Type -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\DisplayName -> CD-ROM Driver ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\ImagePath -> %SystemRoot%\system32\DRIVERS\cdrom.sys [system32\DRIVERS\cdrom.sys] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 49536 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun -> 1 ->
*AutoRunAlwaysDisable* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRunAlwaysDisable ->
NEC MBR-7 -> -> File not found
NEC MBR-7.4 -> -> File not found
PIONEER CHANGR DRM-1804X -> -> File not found
PIONEER CD-ROM DRM-6324X -> -> File not found
PIONEER CD-ROM DRM-624X -> -> File not found
TORiSAN CD-ROM CDR_C36 -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\0 -> IDE\CdRomSONY_CD-RW__CRX100E_____________________2.0h____\5&35c6ca11&0&0.0.0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\Count -> 2 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\NextInstance -> 2 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\1 -> IDE\CdRomCOMPAQ_CRD-8402B________________________1.03____\30323030302f2f35303120202020202020202020 ->
< HOSTS File > (27 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\Search Bar -> http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html ->
HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home ->
HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\Default_Search_URL -> http://www.google.com/ie ->
HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_CURRENT_USER\: Main\\Start Page -> http://www.myspace.com/ ->
HKEY_CURRENT_USER\: ProxyEnable -> 0 ->
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{53707962-6F74-2D53-2644-206D7942484F} [HKEY_LOCAL_MACHINE] -> %SystemDrive%\PROGRA~1\SPYBOT~1\SDHelper.dll [Spybot-S&D IE Protection] -> Safer Networking Limited [Ver = 1, 6, 0, 12 | Size = 1562448 bytes | Modified Date = 2008-07-07 09:41:58 | Attr = ]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_03\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 501136 bytes | Modified Date = 2007-09-25 01:11:34 | Attr = ]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
{DE9C389F-3316-41A7-809B-AA305ED9D922} [HKEY_LOCAL_MACHINE] -> Reg Error: Value does not exist or could not be read. [AIM Toolbar] -> File not found
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Sun Java Console] -> File not found
{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [] -> File not found
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKEY_LOCAL_MACHINE] -> %SystemDrive%\PROGRA~1\SPYBOT~1\SDHelper.dll [Spybot - Search & Destroy Configuration] -> Safer Networking Limited [Ver = 1, 6, 0, 12 | Size = 1562448 bytes | Modified Date = 2008-07-07 09:41:58 | Attr = ]
CmdMapping: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [] -> File not found
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ ->
Cmdmapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> [Sun Java Console] -> File not found
Cmdmapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKEY_LOCAL_MACHINE] -> %SystemDrive%\PROGRA~1\SPYBOT~1\SDHelper.dll [Spybot - Search & Destroy Configuration] -> Safer Networking Limited [Ver = 1, 6, 0, 12 | Size = 1562448 bytes | Modified Date = 2008-07-07 09:41:58 | Attr = ]
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s ->
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{2F13C5B1-BB9C-4EC3-AD9B-C44E0106AD62} -> (NETGEAR FA311 Fast Ethernet Adapter) ->
{55926E4E-A5FD-411D-8888-C6488604E931} -> (National Semiconductor DP83815-Based PCI Fast Ethernet Adapter) ->
{61F28204-CF85-4972-94C9-E63979446E41} -> () ->
{6CB01287-8D7B-4765-B2ED-F106E6135F55} -> (National Semiconductor DP83815-Based PCI Fast Ethernet Adapter) ->
{85AEDFB2-B3FD-4560-9822-7FD30FC38592} -> (National Semiconductor DP83815-Based PCI Fast Ethernet Adapter) ->
{A3617618-8D43-4025-801E-0DD90445FE87} -> () ->
{B6A51482-DFB4-4BCE-BAC4-02203D846BE0} -> (National Semiconductor DP83815-Based PCI Fast Ethernet Adapter) ->
{C15EC0F9-8DB6-4561-B297-79881B20C086} -> (National Semiconductor DP83815-Based PCI Fast Ethernet Adapter) ->
{C2113DB2-EA82-4A21-AF97-458F9875D957} -> (National Semiconductor DP83815-Based PCI Fast Ethernet Adapter) ->
{DB1AB9CC-51E1-42B2-8240-883504F925EA} -> (NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter) ->
{DFA97C56-DE98-4B40-8784-649FA52F773B} -> (National Semiconductor DP83815-Based PCI Fast Ethernet Adapter) ->
{E5356AE4-DB31-4F53-922E-6EFFC61E001C} -> (NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter) ->
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
msdaipp: [HKEY_LOCAL_MACHINE] -> No CLSID value
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{48DD0448-9209-4F81-9F6D-D83562940134}[HKEY_LOCAL_MACHINE] -> http://lads.myspace.com/upload/MySpaceUploader1006.cab[MySpace Uploader Control] ->
{55027008-315F-4F45-BBC3-8BE119764741}[HKEY_LOCAL_MACHINE] -> http://static.slide.com/uploader/SlideImageUploader.cab[Slide Image Uploader Control] ->
{67DABFBF-D0AB-41FA-9C46-CC0F21721616}[HKEY_LOCAL_MACHINE] -> http://go.divx.com/plugin/DivXBrowserPlugin.cab[Reg Error: Key does not exist or could not be opened.] ->
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}[HKEY_LOCAL_MACHINE] -> http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab[Reg Error: Key does not exist or could not be opened.] ->
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab[Java Plug-in 1.6.0_03] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Reg Error: Key does not exist or could not be opened.] ->
< Module Usage Keys [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader3.ocx\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader3.ocx\\.Owner -> {55027008-315F-4F45-BBC3-8BE119764741} ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader3.ocx\\{55027008-315F-4F45-BBC3-8BE119764741} -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MySpaceUploader.ocx\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MySpaceUploader.ocx\\.Owner -> {48DD0448-9209-4F81-9F6D-D83562940134} ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MySpaceUploader.ocx\\{48DD0448-9209-4F81-9F6D-D83562940134} -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/unicows.dll\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/unicows.dll\\.Owner -> {55027008-315F-4F45-BBC3-8BE119764741} ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/unicows.dll\\{55027008-315F-4F45-BBC3-8BE119764741} -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/unicows.dll\\{48DD0448-9209-4F81-9F6D-D83562940134} -> ->
[Registry - Additional Scans - Non-Microsoft Only]
< BotCheck > -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\DefaultLaunchPermission -> [Binary data over 100 bytes] ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineLaunchRestriction -> [Binary data over 100 bytes] ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineAccessRestriction -> [Binary data over 100 bytes] ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\EnableDCOM -> Y ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{A50398B8-9075-4FBF-A7A1-456BF21937AD} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{AD65A69D-3831-40D7-9629-9B0B50A93843} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{0040D221-54A1-11D1-9DE0-006097042D69} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{2A6D72F1-6E7E-4702-B99C-E40D3DED33C3} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirstRunDisabled -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\\DisableMonitoring -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\\DisableMonitoring -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\\DisableMonitoring -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ -> ->
*Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages ->
msv1_0 -> %SystemRoot%\System32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Bounds -> 0 [binary data] ->
*Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages ->
kerberos -> %SystemRoot%\System32\kerberos.dll -> Microsoft Corporation [Ver = 5.1.2600.2698 (xpsp_sp2_gdr.050614-1522) | Size = 295936 bytes | Modified Date = 2005-06-15 10:49:30 | Attr = ]
msv1_0 -> %SystemRoot%\System32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
schannel -> %SystemRoot%\System32\schannel.dll -> Microsoft Corporation [Ver = 5.1.2600.3126 (xpsp_sp2_gdr.070425-0226) | Size = 144896 bytes | Modified Date = 2007-04-25 03:21:16 | Attr = ]
wdigest -> %SystemRoot%\System32\wdigest.dll -> Microsoft Corporation [Ver = 5.1.2600.2874 (xpsp_sp2_gdr.060323-1516) | Size = 49152 bytes | Modified Date = 2006-03-23 23:37:50 | Attr = ]
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\ImpersonatePrivilegeUpgradeToolHasRun -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\LsaPid -> 584 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\SecureBoot -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\auditbaseobjects -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\crashonauditfail -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\disabledomaincreds -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\everyoneincludesanonymous -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fipsalgorithmpolicy -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\forceguest -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fullprivilegeauditing -> [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\limitblankpassworduse -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\lmcompatibilitylevel -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nodefaultadminowner -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nolmhash -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymous -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymoussam -> 1 ->
*Notification Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Notification Packages ->
scecli -> %SystemRoot%\System32\scecli.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 180224 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\enabledcom -> y ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\ -> ->
*ProviderOrder* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\\ProviderOrder ->
Windows NT Access Provider -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\\ProviderPath -> %SystemRoot%\system32\ntmarta.dll [%SystemRoot%\system32\ntmarta.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 118784 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\System\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\\Pattern -> 30 4A F6 0F C5 59 A6 E8 E2 64 7A 95 28 57 E1 A5 31 61 37 61 36 62 33 35 00 FD 07 00 5D 40 00 00 34 FA 07 00 4E 82 7C 75 20 FA 07 00 40 FD 07 00 4C FD 07 00 E8 D6 73 A9 49 C2 7A DA B9 C8 3E 1A [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\\GrafBlumGroup -> 41 0D FC D6 98 18 FA 13 55 [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\\Lookup -> CB 1F 83 F2 64 F2 [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\SidCache\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\\Auth132 -> %SystemRoot%\System32\IISSUBA.dll [IISSUBA] -> Microsoft Corporation [Ver = 6.0.2600.0 (xpclient.010817-1148) | Size = 9216 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\\ntlmminclientsec -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\\ntlmminserversec -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\\SkewMatrix -> FE 2E 10 F8 10 28 9D C8 5D E0 C7 90 E6 1A 2F 73 [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\\SSOURL -> http://www.passport.com ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\\Time -> E0 AA 6E CA 61 77 C8 01 [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Name -> Digest ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Comment -> Digest SSPI Authentication Package ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Capabilities -> 16464 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\RpcId -> 65535 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Version -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\TokenSize -> 65535 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Time -> 00 40 2B BA 28 B1 C2 01 [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Type -> 49 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Name -> DPA ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Comment -> DPA Security Package ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Capabilities -> 55 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\RpcId -> 17 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Version -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\TokenSize -> 768 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Time -> 00 40 2B BA 28 B1 C2 01 [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Type -> 49 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Name -> MSN ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Comment -> MSN Security Package ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Capabilities -> 55 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\RpcId -> 18 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Version -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\TokenSize -> 768 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Time -> 00 40 2B BA 28 B1 C2 01 [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Type -> 49 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Windows Firewall/Internet Connection Sharing (ICS) ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> %SystemRoot%\System32\svchost.exe [%SystemRoot%\System32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 17408 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 11576 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> %SystemRoot%\System32\ipnathlp.dll [%SystemRoot%\System32\ipnathlp.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 331264 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %SystemRoot%\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\EnableFirewall -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\DoNotAllowExceptions -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\DisableNotifications -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\system32\sessmgr.exe -> %SystemRoot%\system32\sessmgr.exe [C:\WINDOWS\system32\sessmgr.exe:*:Enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Spybot - Search & Destroy\SDShred.exe -> %ProgramFiles%\Spybot - Search & Destroy\SDShred.exe [C:\Program Files\Spybot - Search & Destroy\SDShred.exe:*:Enabled:File Shredder] -> Safer Networking Limited [Ver = 1.0.2.3 | Size = 958976 bytes | Modified Date = 2008-07-07 09:37:40 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\NETGEAR\WG111v3\WG111v3.exe -> %ProgramFiles%\NETGEAR\WG111v3\WG111v3.exe [C:\Program Files\NETGEAR\WG111v3\WG111v3.exe:*:Enabled:NETGEAR WG111v3 Smart Wizard] -> [Ver = 3, 6, 28, 314 | Size = 1527808 bytes | Modified Date = 2007-09-12 15:14:42 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\All -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\0 -> Root\LEGACY_SHAREDACCESS\0000 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> %SystemRoot%\system32\svchost.exe [%systemroot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 17408 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Automatic Updates ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> %SystemRoot%\system32\wuauserv.dll [C:\WINDOWS\system32\wuauserv.dll] -> Microsoft Corporation [Ver = 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158) | Size = 6656 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> [Binary data over 100 bytes] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\0 -> Root\LEGACY_WUAUSERV\0000 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 ->
Reg Error: Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\ not found. -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\Type -> 16 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\Start -> 4 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\ErrorControl -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\ImagePath -> %SystemRoot%\system32\tlntsvr.exe [C:\WINDOWS\system32\tlntsvr.exe] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 73216 bytes | Modified Date = 2002-12-31 12:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\DisplayName -> Telnet ->
*DependOnService* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\DependOnService ->
RPCSS -> %SystemRoot%\System32\RPCSS.dll -> Microsoft Corporation [Ver = 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528) | Size = 397824 bytes | Modified Date = 2005-07-25 21:39:50 | Attr = ]
TCPIP -> -> File not found
NTLMSSP -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\DependOnGroup -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\ObjectName -> LocalSystem ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\Description -> Enables a remote user to log on to this computer and run programs, and supports various TCP/IP Telnet clients, including UNIX-based and Windows-based computers. If this service is stopped, remote user access to programs might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Security\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Security\\Security -> [Binary data over 100 bytes] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\\ProxyEnable -> 0 ->
[Files/Folders - Created Within 30 days]
QooBox -> %SystemDrive%\QooBox -> [Folder | Created Date = 2008-08-22 18:40:13 | Attr = ]
cmdcons -> %SystemDrive%\cmdcons -> [Folder | Created Date = 2008-08-22 18:44:42 | Attr = ]
cmldr -> %SystemDrive%\cmldr -> [Ver = | Size = 260272 bytes | Created Date = 2008-08-22 18:44:43 | Attr = ]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 267964416 bytes | Created Date = 2008-08-23 04:27:30 | Attr = HS]
Boot.bak -> %SystemDrive%\Boot.bak -> [Ver = | Size = 211 bytes | Created Date = 2008-08-22 18:44:46 | Attr = ]
temp -> %SystemRoot%\temp -> [Folder | Created Date = 2008-08-23 19:27:00 | Attr = ]
11 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp ->
swxcacls.exe -> %SystemRoot%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 212480 bytes | Created Date = 2008-08-22 18:42:50 | Attr = ]
swsc.exe -> %SystemRoot%\swsc.exe -> SteelWerX [Ver = 2.0.0.5 | Size = 136704 bytes | Created Date = 2008-08-22 18:42:50 | Attr = ]
fdsv.exe -> %SystemRoot%\fdsv.exe -> Smallfrogs Studio [Ver = 1, 2, 0, 22 | Size = 89504 bytes | Created Date = 2008-08-22 18:42:50 | Attr = ]
sed.exe -> %SystemRoot%\sed.exe -> [Ver = | Size = 98816 bytes | Created Date = 2008-08-22 18:42:50 | Attr = ]
grep.exe -> %SystemRoot%\grep.exe -> [Ver = | Size = 80412 bytes | Created Date = 2008-08-22 18:42:50 | Attr = ]
zip.exe -> %SystemRoot%\zip.exe -> [Ver = | Size = 68096 bytes | Created Date = 2008-08-22 18:42:50 | Attr = ]
VFind.exe -> %SystemRoot%\VFind.exe -> [Ver = | Size = 49152 bytes | Created Date = 2008-08-22 18:42:50 | Attr = ]
swreg.exe -> %SystemRoot%\swreg.exe -> SteelWerX [Ver = 3.0.0.0 | Size = 161792 bytes | Created Date = 2008-08-22 18:42:50 | Attr = ]
Nircmd.exe -> %SystemRoot%\Nircmd.exe -> NirSoft [Ver = 2.10 | Size = 28672 bytes | Created Date = 2008-08-22 18:42:50 | Attr = ]
erdnt -> %SystemRoot%\erdnt -> [Folder | Created Date = 2008-08-22 18:43:29 | Attr = ]
[Files Created - Additional Folder Scans - Non-Microsoft Only]
GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [Ver = | Size = 63272 bytes | Created Date = 2008-08-22 19:30:59 | Attr = ]
Mozilla Firefox.lnk -> %AllUsersProfile%\Desktop\Mozilla Firefox.lnk -> [Ver = | Size = 1506 bytes | Created Date = 2008-08-23 11:45:47 | Attr = ]
jre-6u7-windows-i586-p-iftw.exe -> %UserProfile%\Desktop\jre-6u7-windows-i586-p-iftw.exe -> Sun Microsystems, Inc. [Ver = 6.0.70.6 | Size = 382352 bytes | Created Date = 2008-08-23 07:23:14 | Attr = ]
Photoshop.exe -> %UserProfile%\Desktop\Photoshop.exe -> Adobe Systems, Incorporated [Ver = 10.0 (10.0x20070321 [20070321.m.1480 16:39:00 cutoff; m branch]) | Size = 46348950 bytes | Created Date = 2008-08-23 08:17:06 | Attr = ]
OTScanIt.exe -> %UserProfile%\Desktop\OTScanIt.exe -> [Ver = | Size = 568477 bytes | Created Date = 2008-08-23 20:48:21 | Attr = ]
OTScanIt -> %UserProfile%\Desktop\OTScanIt -> [Folder | Created Date = 2008-08-23 20:48:47 | Attr = ]
ATF-Cleaner.zip -> %UserProfile%\Desktop\ATF-Cleaner.zip -> [Ver = | Size = 47078 bytes | Created Date = 2008-08-23 20:51:48 | Attr = ]
Mozilla Firefox -> %ProgramFiles%\Mozilla Firefox -> [Folder | Created Date = 2008-08-23 11:45:04 | Attr = ]
[Files/Folders - Modified Within 30 days]
QooBox -> %SystemDrive%\QooBox -> [Folder | Modified Date = 2008-08-22 18:40:14 | Attr = ]
cmdcons -> %SystemDrive%\cmdcons -> [Folder | Modified Date = 2008-08-22 18:44:44 | Attr = ]
boot.ini -> %SystemDrive%\boot.ini -> [Ver = | Size = 281 bytes | Modified Date = 2008-08-22 18:44:48 | Attr = RHS]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 267964416 bytes | Modified Date = 2008-08-23 19:22:26 | Attr = HS]
wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [Ver = | Size = 2206 bytes | Modified Date = 2008-08-23 02:08:58 | Attr = ]
temp -> %SystemRoot%\temp -> [Folder | Modified Date = 2008-08-23 19:27:02 | Attr = ]
11 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp ->
system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 246 bytes | Modified Date = 2008-08-23 19:24:10 | Attr = ]
erdnt -> %SystemRoot%\erdnt -> [Folder | Modified Date = 2008-08-22 18:43:30 | Attr = ]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 2008-08-23 19:23:10 | Attr = S]
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 2008-08-23 19:23:20 | Attr = H ]
AC43817194383B35.job -> %SystemRoot%\tasks\AC43817194383B35.job -> [Ver = | Size = 276 bytes | Modified Date = 2008-08-23 20:00:02 | Attr = H ]
RegCure Program Check.job -> %SystemRoot%\tasks\RegCure Program Check.job -> [Ver = | Size = 448 bytes | Modified Date = 2008-08-23 19:23:20 | Attr = ]
C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help -> [Folder | Modified Date = 2007-02-17 12:51:30 | Attr = ]
hhcolreg.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\hhcolreg.dat -> [Ver = | Size = 8516 bytes | Modified Date = 2008-07-13 02:37:48 | Attr = ]
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader -> [Folder | Modified Date = 2007-02-17 20:29:26 | Attr = ]
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [Ver = | Size = 7940 bytes | Modified Date = 2008-08-23 19:24:56 | Attr = ]
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [Ver = | Size = 7940 bytes | Modified Date = 2008-08-23 19:24:56 | Attr = ]
C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA -> [Folder | Modified Date = 2007-02-17 13:00:40 | Attr = ]
opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa11.dat -> [Ver = | Size = 8206 bytes | Modified Date = 2007-02-19 16:05:48 | Attr = ]
C:\Documents and Settings\keaton77\Local Settings\temp\Rar$EX00.499\ -> C:\Documents and Settings\keaton77\Local Settings\temp\Rar$EX00.499\ -> [Folder | Modified Date = 2008-08-23 20:52:14 | Attr = ]
ATF-Cleaner.exe -> C:\Documents and Settings\keaton77\Local Settings\temp\Rar$EX00.499\ATF-Cleaner.exe -> Atribune.org [Ver = 3.00.0002 | Size = 50688 bytes | Modified Date = 2007-09-25 20:54:06 | Attr = ]
[Files Modified - Additional Folder Scans - Non-Microsoft Only]
IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [Ver = | Size = 1958676 bytes | Modified Date = 2008-08-23 13:03:40 | Attr = H ]
GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [Ver = | Size = 63272 bytes | Modified Date = 2008-08-22 19:31:18 | Attr = ]
Mozilla Firefox.lnk -> %AllUsersProfile%\Desktop\Mozilla Firefox.lnk -> [Ver = | Size = 1506 bytes | Modified Date = 2008-08-23 11:45:48 | Attr = ]
jre-6u7-windows-i586-p-iftw.exe -> %UserProfile%\Desktop\jre-6u7-windows-i586-p-iftw.exe -> Sun Microsystems, Inc. [Ver = 6.0.70.6 | Size = 382352 bytes | Modified Date = 2008-08-23 07:23:44 | Attr = ]
OTScanIt.exe -> %UserProfile%\Desktop\OTScanIt.exe -> [Ver = | Size = 568477 bytes | Modified Date = 2008-08-23 20:48:24 | Attr = ]
OTScanIt -> %UserProfile%\Desktop\OTScanIt -> [Folder | Modified Date = 2008-08-23 20:48:48 | Attr = ]
ATF-Cleaner.zip -> %UserProfile%\Desktop\ATF-Cleaner.zip -> [Ver = | Size = 47078 bytes | Modified Date = 2008-08-23 20:51:50 | Attr = ]
[CatchMe Rootkit Scan by GMER]
< Windows folder & sub-folders >
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
< Document and Settings folder & sub folders >
scanning hidden files ...
scan completed successfully
hidden files: 0
< End of report >
Thanks for the logs.
Can you get to the drweb site yet?
Download Dr.Webs CureIt to your desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
Double-click the drweb-cureit.exe file and allow it to run the express scan.
This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
Once the short scan has finished, select the "full system scan"
Click the green arrow > to the right and the scan will begin.
At the first infection, select 'Yes to all' if it asks if you want to cure/move the file.
When the scan has finished, click the "Select all" toggle button (if available) next to the files found
Then click the green cup icon right below and select Move incurable
This will move any infected files to the %userprofile%\DoctorWeb\quarantaine-folder that can't be cured (in case if we need samples).
Then, from the main Dr.Web CureIt menu (top left), click File and choose save report list
Save the report to your desktop. The report will be called DrWeb.csv
Close Dr.Web Cureit and Restart your computer to completely remove any stubborn files in reboot.
Post back with the DrWeb.csv report please.
Next:
Open Hijackthis
Click "config"
Click "misc tools"
Click "open uninstall manager"
Click "save list.."
Save the list someplace handy & post contents here.
Thanks.
sexy_ladii05
2008-08-25, 05:17
yea dr webs on full scan right now its half way mark right now ill send to you when its done and my names nicole lol keaton my brother :)
Adobe Flash Player Plugin
Adobe Shockwave Player
AIM 6
America Online (Choose which version to remove)
AOL Uninstaller (Choose which Products to Remove)
Buddy Icon Maker 1.0.0.1
ccCommon
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Java(TM) 6 Update 3
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.0.1)
MSXML 4.0 SP2 (KB936181)
NETGEAR WG111v3 wireless USB 2.0 adapter
Opera 9.51
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Spybot - Search & Destroy
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Windows Installer 3.1 (KB893803)
Windows Media Player Firefox Plugin
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
WinRAR archiver
sexy_ladii05
2008-08-25, 15:07
explorer.exe;c:\windows;Trojan.Starter.384;Cured.;
lsass.exe;c:\windows\system32;Trojan.Starter.384;Cured.;
services.exe;c:\windows\system32;Trojan.Starter.384;Cured.;
spoolsv.exe;c:\windows\system32;Trojan.Starter.384;Cured.;
svchost.exe;c:\windows\system32;Trojan.Starter.384;Cured.;
winlogon.exe;c:\windows\system32;Trojan.Starter.384;Cured.;
distro_SelectRebatesSetup_um1001.exe;C:\WINDOWS;Adware.SAHAgent;Moved.;
kill.exe;C:\WINDOWS\VCP_TEMP;Tool.Prockill;Moved.;
eaxf.exe.vir;C:\QooBox\Quarantine\C\WINDOWS;Trojan.Popuper.7294;Deleted.;
eomb.exe.vir;C:\QooBox\Quarantine\C\WINDOWS;Trojan.Popuper.6637;Deleted.;
Setup.exe.vir;C:\QooBox\Quarantine\C\WINDOWS\Fonts;Trojan.DownLoader.39189;Deleted.;
pskill.exe.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Tool.Prockill;Moved.;
tdssadw.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Packed.612;Deleted.;
tdssl.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Packed.612;Deleted.;
tdssmain.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.DownLoad.3440;Deleted.;
tdsslog.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.DownLoad.3441;Deleted.;
opnmLbCv.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.based.18;Deleted.;
uadekaip.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.based.18;Deleted.;
jouuki.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.based.18;Deleted.;
kjdbmpqy.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.based.18;Deleted.;
nlrybv.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.based.18;Deleted.;
fwgvlrty.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.based.18;Deleted.;
bldirrgo.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.based.18;Deleted.;
dhbole.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.based.18;Deleted.;
20.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
21.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
22.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
23.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
25.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
26.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
27.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
28.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
29.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
2A.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
2B.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
2C.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
2D.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
2E.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
2F.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
30.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
31.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
32.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
33.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
34.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
35.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
36.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
37.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
38.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
3A.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
3C.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
7CA.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.949;Deleted.;
mlJDtrQI.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.448;Deleted.;
setup.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1;Probably BACKDOOR.Trojan;Moved.;
inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_6.0.4.5;Probably BACKDOOR.Trojan;Moved.;
inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_6.0.28.1;Probably BACKDOOR.Trojan;Moved.;
ocpinst.exe\data529;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_6.0.28.1\ocpinst.exe;Probably BACKDOOR.Trojan;;
ocpinst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_6.0.28.1;Archive contains infected objects;Moved.;
setup.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\TRITON_CA_2.2.19.1;Probably BACKDOOR.Trojan;Moved.;
ComboFix.exe\327882R2FWJFW\List-C.bat;C:\Documents and Settings\keaton77\Desktop\ComboFix.exe;Probably BATCH.Virus;;
ComboFix.exe\327882R2FWJFW\psexec.cfexe;C:\Documents and Settings\keaton77\Desktop\ComboFix.exe;Program.PsExec.171;;
ComboFix.exe;C:\Documents and Settings\keaton77\Desktop;Archive contains infected objects;Moved.;
A0000128.bat;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP2;Probably BATCH.Virus;Moved.;
A0000295.bat;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP4;Probably BATCH.Virus;Moved.;
A0000296.EXE;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP4;Program.PsExec.170;Moved.;
A0000314.EXE;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP5;Program.PsExec.170;Moved.;
A0001385.dll;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP7;Trojan.Virtumod.448;Deleted.;
A0001391.bat;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP7;Probably BATCH.Virus;Moved.;
A0001407.EXE;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP7;Program.PsExec.170;Moved.;
A0001459.EXE;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP7;Trojan.Starter.384;Cured.;
A0001460.EXE;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP7;Trojan.Starter.384;Cured.;
A0001461.EXE;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP7;Trojan.Starter.384;Cured.;
A0001462.EXE;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP7;Trojan.Starter.384;Cured.;
A0001463.EXE;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP7;Trojan.Starter.384;Cured.;
A0001464.EXE;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP7;Trojan.Starter.384;Cured.;
A0001468.exe\data529;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP7\A0001468.exe;Probably BACKDOOR.Trojan;;
A0001468.exe;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP7;Archive contains infected objects;Moved.;
A0001479.exe\327882R2FWJFW\List-C.bat;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP7\A0001479.exe;Probably BATCH.Virus;;
A0001479.exe\327882R2FWJFW\psexec.cfexe;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP7\A0001479.exe;Program.PsExec.171;;
A0001479.exe;C:\System Volume Information\_restore{8F6340ED-F2D0-4D17-BBF4-3AC205E3E58B}\RP7;Archive contains infected objects;Moved.;
FILE1740.CHK;C:\FOUND.049;Modification of V2Px.1190;Moved.;
Hi,
Sorry for delay.
Run DrWeb cureit again please using same isntructions as before.
Save log & post it here.
I want to make sure those system files that were previously patched did get cleaned properly. If they did -- this log should be fair short.
Post also new Hijackthis log please.
Thanks :)
sexy_ladii05
2008-08-29, 00:29
kkkkk butbut i think dns changer is back again
Ok.
I'll see what next after I see the new Hijack log and the DrWeb log.
sexy_ladii05
2008-08-31, 03:43
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:33:45, on 29/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {1DC01F38-2C8F-45EF-84A5-8C0D72FA3E3D} - C:\WINDOWS\system32\ddcDvvUL.dll (file missing)
O2 - BHO: {d357bf7c-5aba-7e7b-6a74-dc329cb27823} - {32872bc9-23cd-47a6-b7e7-aba5c7fb753d} - C:\WINDOWS\system32\hbxcra.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {76FE34BE-BD5D-4A35-B131-1F588F2D65FE} - C:\WINDOWS\system32\rqRHaYst.dll (file missing)
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [AIMWDInstallFilename] C:\Program Files\AIM\AIMWDInstall.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [643d5b23] rundll32.exe "C:\WINDOWS\system32\onkjkpqu.dll",b
O4 - HKLM\..\Run: [lphcrpdj0er4j] C:\WINDOWS\system32\lphcrpdj0er4j.exe
O4 - HKLM\..\Run: [{D5-5B-B8-8C-DW}] c:\windows\system32\dwwnw64r.exe DWram03
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\ncntqtdl.exe DWram03
O4 - HKLM\..\RunOnce: [SpybotDeletingA3145] command /c del "C:\WINDOWS\Fonts\'\Tinasoft EasyCafe 2.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9128] cmd /c del "C:\WINDOWS\Fonts\'\Tinasoft EasyCafe 2.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9831] command /c del "C:\WINDOWS\Fonts\'\Speed Math 3.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9341] cmd /c del "C:\WINDOWS\Fonts\'\Speed Math 3.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2516] command /c del "C:\WINDOWS\Fonts\'\Falco Icon Studio 3.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3412] cmd /c del "C:\WINDOWS\Fonts\'\Falco Icon Studio 3.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2961] command /c del "C:\WINDOWS\Fonts\'\FlashFXP 3.3.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8305] cmd /c del "C:\WINDOWS\Fonts\'\FlashFXP 3.3.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA610] command /c del "C:\WINDOWS\Fonts\'\Password Manager Deluxe 3.71.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3811] cmd /c del "C:\WINDOWS\Fonts\'\Etrusoft Quick Screen Capture 3.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2507] command /c del "C:\WINDOWS\Fonts\'\Book Collector Pro 5.4.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC462] cmd /c del "C:\WINDOWS\Fonts\'\Book Collector Pro 5.4.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8749] command /c del "C:\WINDOWS\Fonts\'\Weather Alarm Clock 3.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1409] cmd /c del "C:\WINDOWS\Fonts\'\Weather Alarm Clock 3.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3231] command /c del "C:\WINDOWS\Fonts\'\CyberLink Power2Go 6.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7289] cmd /c del "C:\WINDOWS\Fonts\'\CyberLink Power2Go 6.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1498] command /c del "C:\WINDOWS\Fonts\'\Super Utilities Pro 2008 8.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4338] cmd /c del "C:\WINDOWS\Fonts\'\Super Utilities Pro 2008 8.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3535] command /c del "C:\WINDOWS\Fonts\'\VSO Software CopyToDVD 4.0.14.14.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3373] cmd /c del "C:\WINDOWS\Fonts\'\VSO Software CopyToDVD 4.0.14.14.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2832] command /c del "C:\WINDOWS\Fonts\'\VTC Sony Production Essentials.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8265] cmd /c del "C:\WINDOWS\Fonts\'\VTC Sony Production Essentials.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA682] command /c del "C:\WINDOWS\Fonts\'\R-Wipe amp; Clean 8.0.1459.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7980] cmd /c del "C:\WINDOWS\Fonts\'\R-Wipe amp; Clean 8.0.1459.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6858] command /c del "C:\WINDOWS\Fonts\'\GreenBox Logo Maker 2.0 (Portable).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9986] cmd /c del "C:\WINDOWS\Fonts\'\GreenBox Logo Maker 2.0 (Portable).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2289] command /c del "C:\WINDOWS\Fonts\'\Reaper 2.46.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2672] cmd /c del "C:\WINDOWS\Fonts\'\Reaper 2.46.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7545] command /c del "C:\WINDOWS\Fonts\'\Trojan Remover 6.7.2.254.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6474] cmd /c del "C:\WINDOWS\Fonts\'\Trojan Remover 6.7.2.254.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3284] command /c del "C:\WINDOWS\Fonts\'\Fraps 2.9.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4806] cmd /c del "C:\WINDOWS\Fonts\'\Fraps 2.9.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4063] command /c del "C:\WINDOWS\Fonts\'\Google Earth Pro 4.2.205.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3254] cmd /c del "C:\WINDOWS\Fonts\'\Google Earth Pro 4.2.205.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA38] command /c del "C:\WINDOWS\Fonts\'\GOM Media Player 2.1.9.3754.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9478] cmd /c del "C:\WINDOWS\Fonts\'\GOM Media Player 2.1.9.3754.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2312] command /c del "C:\WINDOWS\Fonts\'\Visual CertExam Suite 1.9.978.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6684] cmd /c del "C:\WINDOWS\Fonts\'\Visual CertExam Suite 1.9.978.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1430] cmd /c del "C:\WINDOWS\Fonts\'\Password Manager Deluxe 3.71.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7225] command /c del "C:\WINDOWS\Fonts\'\All Media Fixer Pro 9.07.2b.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2986] cmd /c del "C:\WINDOWS\Fonts\'\All Media Fixer Pro 9.07.2b.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4917] command /c del "C:\WINDOWS\Fonts\'\Limewire Turbo 5.5.1.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3851] cmd /c del "C:\WINDOWS\Fonts\'\Limewire Turbo 5.5.1.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3133] command /c del "C:\WINDOWS\Fonts\'\Jiffy Gmail Account Creator 1.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1150] cmd /c del "C:\WINDOWS\Fonts\'\Jiffy Gmail Account Creator 1.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6558] command /c del "C:\WINDOWS\Fonts\'\Linkman 7.3.0.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC631] cmd /c del "C:\WINDOWS\Fonts\'\Linkman 7.3.0.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6653] command /c del "C:\WINDOWS\Fonts\'\PageLock Website Copy Protection 7.3.0.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8213] cmd /c del "C:\WINDOWS\Fonts\'\PageLock Website Copy Protection 7.3.0.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3285] command /c del "C:\WINDOWS\Fonts\'\DVD-Cloner 5.50.0.972.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7511] cmd /c del "C:\WINDOWS\Fonts\'\DVD-Cloner 5.50.0.972.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1993] command /c del "C:\WINDOWS\Fonts\'\Revo Uninstaller 1.71 (Portable).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1406] cmd /c del "C:\WINDOWS\Fonts\'\Revo Uninstaller 1.71 (Portable).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4779] command /c del "C:\WINDOWS\Fonts\'\Anonymous Friend 2.9.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC231] cmd /c del "C:\WINDOWS\Fonts\'\Anonymous Friend 2.9.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA508] command /c del "C:\WINDOWS\Fonts\'\AMP Font Viewer 3.81.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1460] cmd /c del "C:\WINDOWS\Fonts\'\AMP Font Viewer 3.81.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3636] command /c del "C:\WINDOWS\Fonts\'\Laptop Battery Doubler 1.2.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6039] cmd /c del "C:\WINDOWS\Fonts\'\Laptop Battery Doubler 1.2.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4541] command /c del "C:\WINDOWS\Fonts\'\XP Tools Pro 8.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6899] cmd /c del "C:\WINDOWS\Fonts\'\XP Tools Pro 8.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA762] command /c del "C:\WINDOWS\Fonts\'\Advanced Registry Optimizer 5.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9631] cmd /c del "C:\WINDOWS\Fonts\'\Advanced Registry Optimizer 5.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2226] command /c del "C:\WINDOWS\Fonts\'\Adobe Photoshop CS3 Portable.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9230] cmd /c del "C:\WINDOWS\Fonts\'\Registry Easy 4.7.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2072] command /c del "C:\WINDOWS\Fonts\'\Rush Hour (1998).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5497] cmd /c del "C:\WINDOWS\Fonts\'\WinRescue XP 1.08.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5874] command /c del "C:\WINDOWS\Fonts\'\Style XP 2008.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5157] cmd /c del "C:\WINDOWS\Fonts\'\Style XP 2008.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3174] command /c del "C:\WINDOWS\Fonts\'\Mouse Robot 1.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC589] cmd /c del "C:\WINDOWS\Fonts\'\Mouse Robot 1.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9147] command /c del "C:\WINDOWS\Fonts\'\PCTools Firewall Plus 4.0.0.45.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4047] cmd /c del "C:\WINDOWS\Fonts\'\PCTools Firewall Plus 4.0.0.45.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1525] command /c del "C:\WINDOWS\Fonts\'\Rapidshare Direct Download 3.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5822] cmd /c del "C:\WINDOWS\Fonts\'\Rapidshare Direct Download 3.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA914] command /c del "C:\WINDOWS\Fonts\'\Nitro PC 2008.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1552] cmd /c del "C:\WINDOWS\Fonts\'\Nitro PC 2008.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2119] command /c del "C:\WINDOWS\Fonts\'\Power Video Converter 1.6.12.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4118] cmd /c del "C:\WINDOWS\Fonts\'\The Promotion 2008 LIMITED DVDRip XviD-AMIABLE.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5326] command /c del "C:\WINDOWS\Fonts\'\Macro Mania 12.4.21.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3280] cmd /c del "C:\WINDOWS\Fonts\'\Macro Mania 12.4.21.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5638] command /c del "C:\WINDOWS\Fonts\'\Noromis PhotoLab 2.20.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1486] cmd /c del "C:\WINDOWS\Fonts\'\Noromis PhotoLab 2.20.zip"
sexy_ladii05
2008-08-31, 03:44
O4 - HKLM\..\RunOnce: [SpybotDeletingA6383] command /c del "C:\WINDOWS\Fonts\'\Backup4All Professional 3.11.304.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1271] cmd /c del "C:\WINDOWS\Fonts\'\Backup4All Professional 3.11.304.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9478] command /c del "C:\WINDOWS\Fonts\'\TaskInfo 8.0.0.260.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2582] cmd /c del "C:\WINDOWS\Fonts\'\TaskInfo 8.0.0.260.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3124] command /c del "C:\WINDOWS\Fonts\'\Flash FXP 3.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5060] cmd /c del "C:\WINDOWS\Fonts\'\Flash FXP 3.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA248] command /c del "C:\WINDOWS\Fonts\'\XYplorer 7.50.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7187] cmd /c del "C:\WINDOWS\Fonts\'\XYplorer 7.50.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8390] command /c del "C:\WINDOWS\Fonts\'\YouTube Get 4.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4272] cmd /c del "C:\WINDOWS\Fonts\'\YouTube Get 4.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9243] command /c del "C:\WINDOWS\Fonts\'\Symantec BootMagic 8.05.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9682] cmd /c del "C:\WINDOWS\Fonts\'\Symantec BootMagic 8.05.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2617] command /c del "C:\WINDOWS\Fonts\'\VSO ConvertXtoDVD 3.2.0.49.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5698] cmd /c del "C:\WINDOWS\Fonts\'\VSO ConvertXtoDVD 3.2.0.49.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA767] command /c del "C:\WINDOWS\Fonts\'\Privacy Eraser Pro 6.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6363] cmd /c del "C:\WINDOWS\Fonts\'\Privacy Eraser Pro 6.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2572] command /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Pro 8.0.015.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC869] cmd /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Pro 8.0.015.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5805] command /c del "C:\WINDOWS\Fonts\'\Driver Magician v.3.28.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC251] cmd /c del "C:\WINDOWS\Fonts\'\System Mechanic Professional 8.0.0.18.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9567] command /c del "C:\WINDOWS\Fonts\'\FTP Explorer 8.8.23.001.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC128] cmd /c del "C:\WINDOWS\Fonts\'\FTP Explorer 8.8.23.001.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2979] command /c del "C:\WINDOWS\Fonts\'\Im Too DVD Ripper 5.0.36.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6762] cmd /c del "C:\WINDOWS\Fonts\'\Im Too DVD Ripper 5.0.36.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5653] command /c del "C:\WINDOWS\Fonts\'\Catch Me If You Can 2002 DVDRip XviD.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9056] cmd /c del "C:\WINDOWS\Fonts\'\Subtitle Processor 7.7.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA706] command /c del "C:\WINDOWS\Fonts\'\Killink CSV 1.12.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1972] cmd /c del "C:\WINDOWS\Fonts\'\Killink CSV 1.12.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2484] command /c del "C:\WINDOWS\Fonts\'\Wash and Go 10.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6596] cmd /c del "C:\WINDOWS\Fonts\'\Wash and Go 10.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA388] command /c del "C:\WINDOWS\Fonts\'\WebcamXP Pro 5.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6161] cmd /c del "C:\WINDOWS\Fonts\'\WebcamXP Pro 5.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6058] command /c del "C:\WINDOWS\Fonts\'\ASA Code Factory 8.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2946] cmd /c del "C:\WINDOWS\Fonts\'\ASA Code Factory 8.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4675] command /c del "C:\WINDOWS\Fonts\'\ASA Data Wizard 8.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1215] cmd /c del "C:\WINDOWS\Fonts\'\ASA Data Wizard 8.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5127] command /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Force Field 1.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2008] cmd /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Force Field 1.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7902] command /c del "C:\WINDOWS\Fonts\'\Super Utilities Pro 8.5 (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6080] cmd /c del "C:\WINDOWS\Fonts\'\Super Utilities Pro 8.5 (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7609] command /c del "C:\WINDOWS\Fonts\'\Orbit Downloader 2.7.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2871] cmd /c del "C:\WINDOWS\Fonts\'\Orbit Downloader 2.7.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7829] command /c del "C:\WINDOWS\Fonts\'\WindowBlinds Enhanced 6.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8963] cmd /c del "C:\WINDOWS\Fonts\'\WindowBlinds Enhanced 6.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8120] command /c del "C:\WINDOWS\Fonts\'\RegDoctor 2.04.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1396] cmd /c del "C:\WINDOWS\Fonts\'\RegDoctor 2.04.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7226] command /c del "C:\WINDOWS\Fonts\'\Registry Repair Wizard 2008 5.06.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3994] cmd /c del "C:\WINDOWS\Fonts\'\Registry Repair Wizard 2008 5.06.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8808] command /c del "C:\WINDOWS\Fonts\'\EasyBoot 5.1.2.586.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9678] cmd /c del "C:\WINDOWS\Fonts\'\EasyBoot 5.1.2.586.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2410] command /c del "C:\WINDOWS\Fonts\'\Ideal Secure 1.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4082] cmd /c del "C:\WINDOWS\Fonts\'\Ideal Secure 1.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4893] command /c del "C:\WINDOWS\Fonts\'\Spamcc 4.7 Pro.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7022] cmd /c del "C:\WINDOWS\Fonts\'\XnView 1.94.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4980] command /c del "C:\WINDOWS\Fonts\'\Winlock Professional 4.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8502] cmd /c del "C:\WINDOWS\Fonts\'\Winlock Professional 4.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9032] command /c del "C:\WINDOWS\Fonts\'\Ninja Surfing Hide IP 1.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9897] cmd /c del "C:\WINDOWS\Fonts\'\Ninja Surfing Hide IP 1.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3582] command /c del "C:\WINDOWS\Fonts\'\Okoker Easy Recorder 4.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6730] cmd /c del "C:\WINDOWS\Fonts\'\Okoker Easy Recorder 4.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4407] command /c del "C:\WINDOWS\Fonts\'\Picture Resize Genius 2.9.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9832] cmd /c del "C:\WINDOWS\Fonts\'\Picture Resize Genius 2.9.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9197] command /c del "C:\WINDOWS\Fonts\'\Operation Mania v1.0.5.55.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5305] cmd /c del "C:\WINDOWS\Fonts\'\Super DVD Creator 9.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1680] command /c del "C:\WINDOWS\Fonts\'\Paragon Partition Manager 9.0 Pro.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9429] cmd /c del "C:\WINDOWS\Fonts\'\MetaProducts Portable Offline Browser v5.1.2820 SR1 Multilingual.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2302] command /c del "C:\WINDOWS\Fonts\'\Auslogics BoostSpeed 4.1.4.133.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4506] cmd /c del "C:\WINDOWS\Fonts\'\Auslogics BoostSpeed 4.1.4.133.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA536] command /c del "C:\WINDOWS\Fonts\'\580 Microsoft Windows Vista Sidebar Gadgets.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2666] cmd /c del "C:\WINDOWS\Fonts\'\580 Microsoft Windows Vista Sidebar Gadgets.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4687] command /c del "C:\WINDOWS\Fonts\'\Vista Manager 1.5.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4452] cmd /c del "C:\WINDOWS\Fonts\'\Vista Manager 1.5.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA161] command /c del "C:\WINDOWS\Fonts\'\AnyDVD amp; AnyDVD HD 6.4.5.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3360] cmd /c del "C:\WINDOWS\Fonts\'\AnyDVD amp; AnyDVD HD 6.4.5.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2610] command /c del "C:\WINDOWS\Fonts\'\Spyware Doctor 5.5.0.212.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9621] cmd /c del "C:\WINDOWS\Fonts\'\Spyware Doctor 5.5.0.212.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7783] command /c del "C:\WINDOWS\Fonts\'\Your Uninstaller! 2008 Pro 6.1.1252.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2686] cmd /c del "C:\WINDOWS\Fonts\'\Your Uninstaller! 2008 Pro 6.1.1252.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4639] command /c del "C:\WINDOWS\Fonts\'\Avast! Antivirus Pro 4.8.1229.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5467] cmd /c del "C:\WINDOWS\Fonts\'\Avast! Antivirus Pro 4.8.1229.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7008] command /c del "C:\WINDOWS\Fonts\'\Photoshop Actions - TextEffects.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3064] cmd /c del "C:\WINDOWS\Fonts\'\Photoshop Actions - TextEffects.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6536] command /c del "C:\WINDOWS\Fonts\'\Kaspersky Internet Security 2009 8.0.0.418.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9639] cmd /c del "C:\WINDOWS\Fonts\'\Kaspersky Internet Security 2009 8.0.0.418.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8535] command /c del "C:\WINDOWS\Fonts\'\Dead Disk Doctor 1.26.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC325] cmd /c del "C:\WINDOWS\Fonts\'\Dead Disk Doctor 1.26.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7429] command /c del "C:\WINDOWS\Fonts\'\MSN Messenger 9.0 Beta (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7199] cmd /c del "C:\WINDOWS\Fonts\'\MSN Messenger 9.0 Beta (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4030] command /c del "C:\WINDOWS\Fonts\'\Daemon Tools Pro Advanced 4.12.220.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8393] cmd /c del "C:\WINDOWS\Fonts\'\Daemon Tools Pro Advanced 4.12.220.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6821] command /c del "C:\WINDOWS\Fonts\'\Driver Genius 2007 Pro 7.1.622.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3863] cmd /c del "C:\WINDOWS\Fonts\'\Driver Genius 2007 Pro 7.1.622.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1131] command /c del "C:\WINDOWS\Fonts\'\Eset NOD32 AntiVirus 3.0.642.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4625] cmd /c del "C:\WINDOWS\Fonts\'\Eset NOD32 AntiVirus 3.0.642.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8867] command /c del "C:\WINDOWS\Fonts\'\Norton Internet Security 2008.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8883] cmd /c del "C:\WINDOWS\Fonts\'\Norton Internet Security 2008.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA179] command /c del "C:\WINDOWS\Fonts\'\Windows Media Player 12.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5119] cmd /c del "C:\WINDOWS\Fonts\'\Windows Media Player 12.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA604] command /c del "C:\WINDOWS\Fonts\'\Kylie Minogue - Sweet Music (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3005] cmd /c del "C:\WINDOWS\Fonts\'\Kylie Minogue - Sweet Music (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8441] command /c del "C:\WINDOWS\Fonts\'\Rapidshare Tools 2008 Collection.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7365] cmd /c del "C:\WINDOWS\Fonts\'\Rapidshare Tools 2008 Collection.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3370] command /c del "C:\WINDOWS\Fonts\'\Pineapple Express (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC793] cmd /c del "C:\WINDOWS\Fonts\'\Pineapple Express (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2058] command /c del "C:\WINDOWS\Fonts\'\Download Accelerator Plus Premium 8.6.1.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7982] cmd /c del "C:\WINDOWS\Fonts\'\Download Accelerator Plus Premium 8.6.1.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1738] command /c del "C:\WINDOWS\Fonts\'\SpeedFan 4.29.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4737] cmd /c del "C:\WINDOWS\Fonts\'\SpeedFan 4.29.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA455] command /c del "C:\WINDOWS\Fonts\'\Elcor Premium Booster 2.8.0.2500.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC872] cmd /c del "C:\WINDOWS\Fonts\'\Elcor Premium Booster 2.8.0.2500.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9022] command /c del "C:\WINDOWS\Fonts\'\Winaso Disk Cleaner 2.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7731] cmd /c del "C:\WINDOWS\Fonts\'\Winaso Disk Cleaner 2.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7864] cmd /c del "C:\WINDOWS\Fonts\'\Spamcc 4.7 Pro.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA268] command /c del "C:\WINDOWS\Fonts\'\Tropic Thunder TS XVID-PreVail.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2913] cmd /c del "C:\WINDOWS\Fonts\'\Tropic Thunder TS XVID-PreVail.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1847] command /c del "C:\WINDOWS\Fonts\'\Pineapple Express TS XviD-OPTiC.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1491] cmd /c del "C:\WINDOWS\Fonts\'\Pineapple Express TS XviD-OPTiC.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4031] command /c del "C:\WINDOWS\Fonts\'\Death Race TELESYNC XviD-OPTiC.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9901] cmd /c del "C:\WINDOWS\Fonts\'\Death Race TELESYNC XviD-OPTiC.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7719] command /c del "C:\WINDOWS\Fonts\'\Flash2X Screensaver Builder 3.0.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1844] cmd /c del "C:\WINDOWS\Fonts\'\Flash2X Screensaver Builder 3.0.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5794] command /c del "C:\WINDOWS\Fonts\'\Photo Frame Show v1.4 Build 154.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8757] cmd /c del "C:\WINDOWS\Fonts\'\Photo Frame Show v1.4 Build 154.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4450] command /c del "C:\WINDOWS\Fonts\'\Flash2X Flash Hunter 3.0.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3503] cmd /c del "C:\WINDOWS\Fonts\'\Flash2X Flash Hunter 3.0.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9180] command /c del "C:\WINDOWS\Fonts\'\Privacy Shield v3.0.79.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6921] cmd /c del "C:\WINDOWS\Fonts\'\Privacy Shield v3.0.79.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5504] command /c del "C:\WINDOWS\Fonts\'\Global Mapper v10.0.10.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3383] cmd /c del "C:\WINDOWS\Fonts\'\Global Mapper v10.0.10.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7717] command /c del "C:\WINDOWS\Fonts\'\Flash2X Wallpaper Maker v1.1.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4465] cmd /c del "C:\WINDOWS\Fonts\'\Flash2X Wallpaper Maker v1.1.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2967] command /c del "C:\WINDOWS\Fonts\'\Okoker Disk Cleaner v4.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6308] cmd /c del "C:\WINDOWS\Fonts\'\Okoker Disk Cleaner v4.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4316] command /c del "C:\WINDOWS\Fonts\'\HARDiNFO 2008 Professional v6.01 build 3180.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1550] cmd /c del "C:\WINDOWS\Fonts\'\HARDiNFO 2008 Professional v6.01 build 3180.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2788] command /c del "C:\WINDOWS\Fonts\'\Oront Burning Kit 2 Premium v2.5.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5045] cmd /c del "C:\WINDOWS\Fonts\'\Oront Burning Kit 2 Premium v2.5.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2188] command /c del "C:\WINDOWS\Fonts\'\FlashFXP v3.7.3 build 1275 BETA.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9781] cmd /c del "C:\WINDOWS\Fonts\'\FlashFXP v3.7.3 build 1275 BETA.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2306] command /c del "C:\WINDOWS\Fonts\'\Chronograph v6.30.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5851] cmd /c del "C:\WINDOWS\Fonts\'\Chronograph v6.30.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1988] command /c del "C:\WINDOWS\Fonts\'\Flash2X EXE Packager 3.0.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8947] cmd /c del "C:\WINDOWS\Fonts\'\Flash2X EXE Packager 3.0.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2048] command /c del "C:\WINDOWS\Fonts\'\CleanMyPC Registry Cleaner v4.10.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1744] cmd /c del "C:\WINDOWS\Fonts\'\CleanMyPC Registry Cleaner v4.10.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9337] command /c del "C:\WINDOWS\Fonts\'\BWMeter v4.1.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3488] cmd /c del "C:\WINDOWS\Fonts\'\BWMeter v4.1.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3003] command /c del "C:\WINDOWS\Fonts\'\CDMenuPro v6.24.00 Business Edition Bilingual.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7947] cmd /c del "C:\WINDOWS\Fonts\'\CDMenuPro v6.24.00 Business Edition Bilingual.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2882] command /c del "C:\WINDOWS\Fonts\'\Download Accelerator Plus 8.7.0.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4531] cmd /c del "C:\WINDOWS\Fonts\'\Download Accelerator Plus 8.7.0.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5129] command /c del "C:\WINDOWS\Fonts\'\Adrosoft AD Stream Recorder v2.6.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3294] cmd /c del "C:\WINDOWS\Fonts\'\Portal RiP.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6271] command /c del "C:\WINDOWS\Fonts\'\DzSoft Perl Editor 5.8.3.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6641] cmd /c del "C:\WINDOWS\Fonts\'\DzSoft Perl Editor 5.8.3.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6722] command /c del "C:\WINDOWS\Fonts\'\Diamond Cut DC7 v7.15.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7926] cmd /c del "C:\WINDOWS\Fonts\'\Diamond Cut DC7 v7.15.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6731] command /c del "C:\WINDOWS\Fonts\'\World In Conflict iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3538] cmd /c del "C:\WINDOWS\Fonts\'\World In Conflict iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6265] command /c del "C:\WINDOWS\Fonts\'\Need For Speed Most Wanted iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2587] cmd /c del "C:\WINDOWS\Fonts\'\Need For Speed Most Wanted iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5597] command /c del "C:\WINDOWS\Fonts\'\Warhammer 40000 plus Dawn Of War plus Soulstorm iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8350] cmd /c del "C:\WINDOWS\Fonts\'\Warhammer 40000 plus Dawn Of War plus Soulstorm iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3863] command /c del "C:\WINDOWS\Fonts\'\Dracula 3 Path Of The Dragon-PROCYON iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7739] cmd /c del "C:\WINDOWS\Fonts\'\Dracula 3 Path Of The Dragon-PROCYON iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4012] command /c del "C:\WINDOWS\Fonts\'\Jazz Jackrabbit 2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9052] cmd /c del "C:\WINDOWS\Fonts\'\Jazz Jackrabbit 2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4939] command /c del "C:\WINDOWS\Fonts\'\Metal Gear Solid 2 - Substance iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6907] cmd /c del "C:\WINDOWS\Fonts\'\Metal Gear Solid 2 - Substance iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1947] command /c del "C:\WINDOWS\Fonts\'\Marvel Super Heroes vs. Capcom X-Men vs. Street Fighter.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7786] cmd /c del "C:\WINDOWS\Fonts\'\Marvel Super Heroes vs. Capcom X-Men vs. Street Fighter.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA901] command /c del "C:\WINDOWS\Fonts\'\Galactic Civilizations II plus Expansions iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8983] cmd /c del "C:\WINDOWS\Fonts\'\Galactic Civilizations II plus Expansions iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9116] command /c del "C:\WINDOWS\Fonts\'\Total Overdose iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5689] cmd /c del "C:\WINDOWS\Fonts\'\Total Overdose iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8954] command /c del "C:\WINDOWS\Fonts\'\Audio-Surf incl. 9 Updates.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6400] cmd /c del "C:\WINDOWS\Fonts\'\Audio-Surf incl. 9 Updates.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA680] command /c del "C:\WINDOWS\Fonts\'\RegCure 1.5.0.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3096] cmd /c del "C:\WINDOWS\Fonts\'\X3 Reunion 2007 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6902] command /c del "C:\WINDOWS\Fonts\'\Registry Clean Expert 4.62.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7628] cmd /c del "C:\WINDOWS\Fonts\'\Star Wars Dark Forces Full iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2596] command /c del "C:\WINDOWS\Fonts\'\Star Wars X-Wing vs. Tie Fighter iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4573] cmd /c del "C:\WINDOWS\Fonts\'\Star Wars X-Wing vs. Tie Fighter iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1069] command /c del "C:\WINDOWS\Fonts\'\LEGO Star Wars IIThe Original Trilogy RiP.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9754] cmd /c del "C:\WINDOWS\Fonts\'\LEGO Star Wars IIThe Original Trilogy RiP.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9709] command /c del "C:\WINDOWS\Fonts\'\The Sims 2 Apartment Life-RELOADED iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1185] cmd /c del "C:\WINDOWS\Fonts\'\The Sims 2 Apartment Life-RELOADED iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2262] command /c del "C:\WINDOWS\Fonts\'\MS flight simulator 2004 plus all Addons iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7230] cmd /c del "C:\WINDOWS\Fonts\'\MS flight simulator 2004 plus all Addons iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1844] command /c del "C:\WINDOWS\Fonts\'\The Witcher iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9979] cmd /c del "C:\WINDOWS\Fonts\'\The Witcher iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1176] command /c del "C:\WINDOWS\Fonts\'\Space Siege iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9988] cmd /c del "C:\WINDOWS\Fonts\'\Space Siege iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6233] command /c del "C:\WINDOWS\Fonts\'\Hunting Unlimited 2009 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6739] cmd /c del "C:\WINDOWS\Fonts\'\Go West A Lucky Luke Adventure 2007 DVDRip XVID-iGNITE.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3118] command /c del "C:\WINDOWS\Fonts\'\Call Of Juarez-RELOADED iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9388] cmd /c del "C:\WINDOWS\Fonts\'\Call Of Juarez-RELOADED iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3889] command /c del "C:\WINDOWS\Fonts\'\The Strangers 2008 DVDRip Xvid.zip"
sexy_ladii05
2008-08-31, 03:45
O4 - HKLM\..\RunOnce: [SpybotDeletingC8444] cmd /c del "C:\WINDOWS\Fonts\'\The Strangers 2008 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4717] command /c del "C:\WINDOWS\Fonts\'\The Bridge on the River Kwai 1957 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9610] cmd /c del "C:\WINDOWS\Fonts\'\The Bridge on the River Kwai 1957 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5257] command /c del "C:\WINDOWS\Fonts\'\Joy Division 2006 FESTiVAL DVDRip XviD-TNAN.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9224] cmd /c del "C:\WINDOWS\Fonts\'\Joy Division 2006 FESTiVAL DVDRip XviD-TNAN.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7039] command /c del "C:\WINDOWS\Fonts\'\Meet The Robinsons 2007 DVDRip XviD-SAiNTS.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8822] cmd /c del "C:\WINDOWS\Fonts\'\Uniblue Spy Eraser 2.0.1.1530.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9046] command /c del "C:\WINDOWS\Fonts\'\Hellboy 2 The Golden Army 2008 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC930] cmd /c del "C:\WINDOWS\Fonts\'\Hellboy 2 The Golden Army 2008 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA615] command /c del "C:\WINDOWS\Fonts\'\Tropic Thunder 2008 TS XviD-KingBen.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6711] cmd /c del "C:\WINDOWS\Fonts\'\Tropic Thunder 2008 TS XviD-KingBen.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2889] command /c del "C:\WINDOWS\Fonts\'\Aladdin 1992 720p HDTV x264-hV.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5175] cmd /c del "C:\WINDOWS\Fonts\'\Aladdin 1992 720p HDTV x264-hV.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8349] command /c del "C:\WINDOWS\Fonts\'\The Matrix Reloaded 2003 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2165] cmd /c del "C:\WINDOWS\Fonts\'\The Matrix Reloaded 2003 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6793] command /c del "C:\WINDOWS\Fonts\'\The Quiet American 2002 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3343] cmd /c del "C:\WINDOWS\Fonts\'\The Quiet American 2002 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7366] command /c del "C:\WINDOWS\Fonts\'\WisdomSoft MotionStudio v4.0.119.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4119] cmd /c del "C:\WINDOWS\Fonts\'\The Fall 2006 LiMiTED NTSC DVDR-BeStDvD.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4872] command /c del "C:\WINDOWS\Fonts\'\Hell Ride 2008 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3911] cmd /c del "C:\WINDOWS\Fonts\'\Hell Ride 2008 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2600] command /c del "C:\WINDOWS\Fonts\'\The Bank Job 2008 DVDRip Xvid-aXXo.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5077] cmd /c del "C:\WINDOWS\Fonts\'\The Bank Job 2008 DVDRip Xvid-aXXo.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9784] command /c del "C:\WINDOWS\Fonts\'\Babylon A.D. DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7343] cmd /c del "C:\WINDOWS\Fonts\'\Babylon A.D. DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8791] command /c del "C:\WINDOWS\Fonts\'\The Invasion 2007 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC613] cmd /c del "C:\WINDOWS\Fonts\'\The Invasion 2007 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1331] command /c del "C:\WINDOWS\Fonts\'\Elegy 2008 LIMITED R5 XviD-COALiTiON.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6391] cmd /c del "C:\WINDOWS\Fonts\'\Elegy 2008 LIMITED R5 XviD-COALiTiON.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6011] command /c del "C:\WINDOWS\Fonts\'\Army Of The Dead 2008 DVDRip XviD-VoMiT.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3523] cmd /c del "C:\WINDOWS\Fonts\'\Army Of The Dead 2008 DVDRip XviD-VoMiT.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6238] command /c del "C:\WINDOWS\Fonts\'\GBTimelapse v2.1.6.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7505] cmd /c del "C:\WINDOWS\Fonts\'\21 DVDRip XviD-FLAiTE.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8348] command /c del "C:\WINDOWS\Fonts\'\Wrong Turn 2003 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC969] cmd /c del "C:\WINDOWS\Fonts\'\Wrong Turn 2003 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA356] command /c del "C:\WINDOWS\Fonts\'\Tombstone 1993 iNT DVDRip XVID-vRs.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9184] cmd /c del "C:\WINDOWS\Fonts\'\Tombstone 1993 iNT DVDRip XVID-vRs.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6405] command /c del "C:\WINDOWS\Fonts\'\Kingdom of Heaven 2005 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1119] cmd /c del "C:\WINDOWS\Fonts\'\Kingdom of Heaven 2005 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5096] command /c del "C:\WINDOWS\Fonts\'\Wrong Turn 2 Dead End 2007 Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3969] cmd /c del "C:\WINDOWS\Fonts\'\Wrong Turn 2 Dead End 2007 Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4454] command /c del "C:\WINDOWS\Fonts\'\The Happening R5 LINE XViD-BaLD.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC800] cmd /c del "C:\WINDOWS\Fonts\'\The Happening R5 LINE XViD-BaLD.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4480] command /c del "C:\WINDOWS\Fonts\'\The Promotion 2008 LIMITED DVDRip XviD-AMIABLE.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9741] command /c del "C:\WINDOWS\Fonts\'\OJOsoft DVD Ripper 2.1.0.0630.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC310] cmd /c del "C:\WINDOWS\Fonts\'\Some Mothers Son 1996.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3007] command /c del "C:\WINDOWS\Fonts\'\Borderland 2007 DVDRip XviD-XanaX.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7974] cmd /c del "C:\WINDOWS\Fonts\'\Borderland 2007 DVDRip XviD-XanaX.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5325] command /c del "C:\WINDOWS\Fonts\'\Pearl Diversion v1.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC459] cmd /c del "C:\WINDOWS\Fonts\'\King Of New York SE 1990 iNTERNAL DVDRip XviD-SAVANNAH.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2761] command /c del "C:\WINDOWS\Fonts\'\The Mummy Tomb of the Dragon Emperor R5 LINE.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4104] cmd /c del "C:\WINDOWS\Fonts\'\The Mummy Tomb of the Dragon Emperor R5 LINE.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7169] command /c del "C:\WINDOWS\Fonts\'\Network Security Protector 2.34.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4130] cmd /c del "C:\WINDOWS\Fonts\'\Network Security Protector 2.34.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA729] command /c del "C:\WINDOWS\Fonts\'\Deamon Tools 4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC120] cmd /c del "C:\WINDOWS\Fonts\'\Serv-U File Server Corporate v7.2.0.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8516] command /c del "C:\WINDOWS\Fonts\'\NCH Swift Sound Switch Plus v1.42 Patch.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8013] cmd /c del "C:\WINDOWS\Fonts\'\NCH Swift Sound Switch Plus v1.42 Patch.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7152] command /c del "C:\WINDOWS\Fonts\'\SQLite Expert Professional v1.7.13.1713.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9235] cmd /c del "C:\WINDOWS\Fonts\'\SQLite Expert Professional v1.7.13.1713.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA295] command /c del "C:\WINDOWS\Fonts\'\Real Spy Monitor v2.86.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC423] cmd /c del "C:\WINDOWS\Fonts\'\Real Spy Monitor v2.86.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4725] command /c del "C:\WINDOWS\Fonts\'\Norton AntiBot v1.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1102] cmd /c del "C:\WINDOWS\Fonts\'\Norton AntiBot v1.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5364] command /c del "C:\WINDOWS\Fonts\'\Runtime GetDataBack for FAT v3.40.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6318] cmd /c del "C:\WINDOWS\Fonts\'\Runtime GetDataBack for FAT v3.40.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6301] command /c del "C:\WINDOWS\Fonts\'\Runtime DiskExplorer for FAT v3.40.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8364] cmd /c del "C:\WINDOWS\Fonts\'\Runtime DiskExplorer for FAT v3.40.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2359] command /c del "C:\WINDOWS\Fonts\'\Danware NetOp Remote Control v9.10.2008197.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8179] cmd /c del "C:\WINDOWS\Fonts\'\Danware NetOp Remote Control v9.10.2008197.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA168] command /c del "C:\WINDOWS\Fonts\'\MindSoft Utilities XP 9.80.2008.20.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3090] cmd /c del "C:\WINDOWS\Fonts\'\MindSoft Utilities XP 9.80.2008.20.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1041] command /c del "C:\WINDOWS\Fonts\'\FoxIt Reader Pro v2.3.3201.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9771] cmd /c del "C:\WINDOWS\Fonts\'\FoxIt Reader Pro v2.3.3201.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1929] command /c del "C:\WINDOWS\Fonts\'\Mjksoft WinSuperKit 6.3.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4743] cmd /c del "C:\WINDOWS\Fonts\'\Mjksoft WinSuperKit 6.3.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1388] command /c del "C:\WINDOWS\Fonts\'\Audio Record Edit Toolbox v10.31.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC838] cmd /c del "C:\WINDOWS\Fonts\'\Audio Record Edit Toolbox v10.31.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2966] command /c del "C:\WINDOWS\Fonts\'\Hancock (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1998] cmd /c del "C:\WINDOWS\Fonts\'\Advanced PC Tweaker 2008 4.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4590] command /c del "C:\WINDOWS\Fonts\'\HttpWatch Professional v5.3.20.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5241] cmd /c del "C:\WINDOWS\Fonts\'\HttpWatch Professional v5.3.20.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7474] command /c del "C:\WINDOWS\Fonts\'\The Attic (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7585] cmd /c del "C:\WINDOWS\Fonts\'\Ashampoo Cover Studio v1.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4858] command /c del "C:\WINDOWS\Fonts\'\Archiver v2.5.3143.16107.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC102] cmd /c del "C:\WINDOWS\Fonts\'\Archiver v2.5.3143.16107.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5920] cmd /c del "C:\WINDOWS\Fonts\'\GBTimelapse v2.1.6.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8158] command /c del "C:\WINDOWS\Fonts\'\Almost Famous 2000 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4122] cmd /c del "C:\WINDOWS\Fonts\'\Beyond Good and EviL iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7764] command /c del "C:\WINDOWS\Fonts\'\Monkey Island III The Curse Of Monkey Island iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5398] cmd /c del "C:\WINDOWS\Fonts\'\Monkey Island III The Curse Of Monkey Island iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6387] command /c del "C:\WINDOWS\Fonts\'\Portal RiP.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3626] command /c del "C:\WINDOWS\Fonts\'\The Godfather The Game RiP.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7150] cmd /c del "C:\WINDOWS\Fonts\'\The Godfather The Game RiP.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7656] command /c del "C:\WINDOWS\Fonts\'\NHL 2008 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6440] cmd /c del "C:\WINDOWS\Fonts\'\NHL 2008 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9206] command /c del "C:\WINDOWS\Fonts\'\Silverfall iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9291] cmd /c del "C:\WINDOWS\Fonts\'\Silverfall iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4499] command /c del "C:\WINDOWS\Fonts\'\Assasins Creed iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2473] cmd /c del "C:\WINDOWS\Fonts\'\Assasins Creed iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8745] command /c del "C:\WINDOWS\Fonts\'\FlatOut Ultimate Carnage-RELOADED iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2148] cmd /c del "C:\WINDOWS\Fonts\'\The Dark Knight 2008 TS Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA962] command /c del "C:\WINDOWS\Fonts\'\Quake 4 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7647] cmd /c del "C:\WINDOWS\Fonts\'\Quake 4 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2860] command /c del "C:\WINDOWS\Fonts\'\BlackSite Area 51 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4173] cmd /c del "C:\WINDOWS\Fonts\'\BlackSite Area 51 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1771] command /c del "C:\WINDOWS\Fonts\'\Space Chimps-SKIDROW iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8602] cmd /c del "C:\WINDOWS\Fonts\'\Space Chimps-SKIDROW iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA535] command /c del "C:\WINDOWS\Fonts\'\Prison Tycoon 3 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8329] cmd /c del "C:\WINDOWS\Fonts\'\Prison Tycoon 3 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3749] command /c del "C:\WINDOWS\Fonts\'\No Limits Coaster Simulator 1.7.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC33] cmd /c del "C:\WINDOWS\Fonts\'\No Limits Coaster Simulator 1.7.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2679] command /c del "C:\WINDOWS\Fonts\'\NBA Live 2008 RiP.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC876] cmd /c del "C:\WINDOWS\Fonts\'\NBA Live 2008 RiP.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3931] command /c del "C:\WINDOWS\Fonts\'\Crash Bandicoot 1,2 and 3 PC iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8406] cmd /c del "C:\WINDOWS\Fonts\'\Crash Bandicoot 1,2 and 3 PC iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7458] command /c del "C:\WINDOWS\Fonts\'\Legend Hand Of God iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9532] cmd /c del "C:\WINDOWS\Fonts\'\Legend Hand Of God iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4023] command /c del "C:\WINDOWS\Fonts\'\Corel DVD Movie Factory Pro 7.00.398.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC995] cmd /c del "C:\WINDOWS\Fonts\'\Crysis 2007-Razor1911 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8197] command /c del "C:\WINDOWS\Fonts\'\UFO Aftermath iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9957] cmd /c del "C:\WINDOWS\Fonts\'\UFO Aftermath iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3573] command /c del "C:\WINDOWS\Fonts\'\Supreme Commander Forged Alliance iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5016] cmd /c del "C:\WINDOWS\Fonts\'\Supreme Commander Forged Alliance iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3762] command /c del "C:\WINDOWS\Fonts\'\Punch! ViaCAD 2D3D 6.0.0.786.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC472] cmd /c del "C:\WINDOWS\Fonts\'\This Is England 2006 LiMiTED DVDRip XviD-DoNE.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5654] command /c del "C:\WINDOWS\Fonts\'\Green Mile 1999 DVDRip XviD.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2710] cmd /c del "C:\WINDOWS\Fonts\'\Bigger Stronger Faster (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7806] command /c del "C:\WINDOWS\Fonts\'\Better luck tomorrow DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4146] cmd /c del "C:\WINDOWS\Fonts\'\Better luck tomorrow DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5870] command /c del "C:\WINDOWS\Fonts\'\Speed Racer 2008 R5 x264.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3881] cmd /c del "C:\WINDOWS\Fonts\'\Speed Racer 2008 R5 x264.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9090] command /c del "C:\WINDOWS\Fonts\'\The Hills Have Eyes 2 DVDRip XviD-DoNE.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC14] cmd /c del "C:\WINDOWS\Fonts\'\The Hills Have Eyes 2 DVDRip XviD-DoNE.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7447] command /c del "C:\WINDOWS\Fonts\'\Dave Chapelle - For What Its Worth 2004 DVDRip XviD.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1555] cmd /c del "C:\WINDOWS\Fonts\'\Dave Chapelle - For What Its Worth 2004 DVDRip XviD.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8971] command /c del "C:\WINDOWS\Fonts\'\Mad Money 2008 DVDRip AC3-FXG.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4281] cmd /c del "C:\WINDOWS\Fonts\'\Mad Money 2008 DVDRip AC3-FXG.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA614] command /c del "C:\WINDOWS\Fonts\'\The Dark Knight 2008 TS Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5868] command /c del "C:\WINDOWS\Fonts\'\Chaos Theory 2007 DVDRip AC3-aXXo.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC996] cmd /c del "C:\WINDOWS\Fonts\'\Chaos Theory 2007 DVDRip AC3-aXXo.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6750] command /c del "C:\WINDOWS\Fonts\'\God Tussi Great Ho 2008 Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8072] cmd /c del "C:\WINDOWS\Fonts\'\God Tussi Great Ho 2008 Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8573] command /c del "C:\WINDOWS\Fonts\'\There Will Be Blood 2007 720p BluRay DTS x264-ESiR.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC421] cmd /c del "C:\WINDOWS\Fonts\'\There Will Be Blood 2007 720p BluRay DTS x264-ESiR.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8631] command /c del "C:\WINDOWS\Fonts\'\Charlie Wilson War DVDRip XviD-DiAMOND.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7244] cmd /c del "C:\WINDOWS\Fonts\'\Charlie Wilson War DVDRip XviD-DiAMOND.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8246] command /c del "C:\WINDOWS\Fonts\'\The Strangers 2008 DVDSCR H264.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4167] cmd /c del "C:\WINDOWS\Fonts\'\The Strangers 2008 DVDSCR H264.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2394] cmd /c del "C:\WINDOWS\Fonts\'\Catch Me If You Can 2002 DVDRip XviD.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7735] command /c del "C:\WINDOWS\Fonts\'\Reno 911 Miami UNRATED DVDRip XviD-DiAMOND.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4178] cmd /c del "C:\WINDOWS\Fonts\'\Reno 911 Miami UNRATED DVDRip XviD-DiAMOND.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9971] cmd /c del "C:\WINDOWS\Fonts\'\Almost Famous 2000 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8271] command /c del "C:\WINDOWS\Fonts\'\The X-Files-Fight the Future 1998 DVDRip Xvid-aXXo.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4251] cmd /c del "C:\WINDOWS\Fonts\'\The X-Files-Fight the Future 1998 DVDRip Xvid-aXXo.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8335] command /c del "C:\WINDOWS\Fonts\'\Go West A Lucky Luke Adventure 2007 DVDRip XVID-iGNITE.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1316] command /c del "C:\WINDOWS\Fonts\'\Sword of the Stranger 300MB MKV X264.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC690] cmd /c del "C:\WINDOWS\Fonts\'\Sword of the Stranger 300MB MKV X264.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9260] command /c del "C:\WINDOWS\Fonts\'\SwirlX3D 1.7.10.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC143] cmd /c del "C:\WINDOWS\Fonts\'\SwirlX3D 1.7.10.zip"
sexy_ladii05
2008-08-31, 03:47
O4 - HKLM\..\RunOnce: [SpybotDeletingA4324] command /c del "C:\WINDOWS\Fonts\'\Danware NetOp Instruct v5.50.2008126.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5355] cmd /c del "C:\WINDOWS\Fonts\'\Danware NetOp Instruct v5.50.2008126.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4813] command /c del "C:\WINDOWS\Fonts\'\PC Washer 2.0.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6306] cmd /c del "C:\WINDOWS\Fonts\'\PC Washer 2.0.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3400] command /c del "C:\WINDOWS\Fonts\'\Easy CD-DA Extractor Pro v11.9.9 Build 668.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC338] cmd /c del "C:\WINDOWS\Fonts\'\Easy CD-DA Extractor Pro v11.9.9 Build 668.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3776] command /c del "C:\WINDOWS\Fonts\'\Smart Install Maker v5.02.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2891] cmd /c del "C:\WINDOWS\Fonts\'\Smart Install Maker v5.02.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1384] command /c del "C:\WINDOWS\Fonts\'\Agnitum Outpost Security Suite Pro 2009 v6.5.2358.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2463] cmd /c del "C:\WINDOWS\Fonts\'\Agnitum Outpost Security Suite Pro 2009 v6.5.2358.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3193] command /c del "C:\WINDOWS\Fonts\'\CHMEditor v1.2 Build 059.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6959] cmd /c del "C:\WINDOWS\Fonts\'\CHMEditor v1.2 Build 059.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7758] command /c del "C:\WINDOWS\Fonts\'\MetaProducts Portable Offline Browser v5.1.2820 SR1 Multilingual.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA359] command /c del "C:\WINDOWS\Fonts\'\Abyssmedia ScriptCryptor Compiler v2.8.4.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8993] cmd /c del "C:\WINDOWS\Fonts\'\Abyssmedia ScriptCryptor Compiler v2.8.4.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3460] command /c del "C:\WINDOWS\Fonts\'\OnlineEye Pro v2.2.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8178] cmd /c del "C:\WINDOWS\Fonts\'\OnlineEye Pro v2.2.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9187] command /c del "C:\WINDOWS\Fonts\'\Belltech CaptureXT Screen Capture v3.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC138] cmd /c del "C:\WINDOWS\Fonts\'\MetaProducts Offline Explorer Enterprise v5.1.2820 SR1 Multilingual.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8406] command /c del "C:\WINDOWS\Fonts\'\SolidIce KeyClone v1.8k.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7583] cmd /c del "C:\WINDOWS\Fonts\'\SolidIce KeyClone v1.8k.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4807] command /c del "C:\WINDOWS\Fonts\'\CRT v6.1.0.349.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9980] cmd /c del "C:\WINDOWS\Fonts\'\CRT v6.1.0.349.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1411] command /c del "C:\WINDOWS\Fonts\'\SecureFX v6.1.0.349.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1449] cmd /c del "C:\WINDOWS\Fonts\'\SecureFX v6.1.0.349.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4227] command /c del "C:\WINDOWS\Fonts\'\SecureCRT v6.1.0.349.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9064] cmd /c del "C:\WINDOWS\Fonts\'\SecureCRT v6.1.0.349.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9843] command /c del "C:\WINDOWS\Fonts\'\WebcamXP Pro v5.3.2.105.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7724] cmd /c del "C:\WINDOWS\Fonts\'\WebcamXP Pro v5.3.2.105.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1430] command /c del "C:\WINDOWS\Fonts\'\WisdomSoft ScreenHunter Pro v5.0.733.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3759] cmd /c del "C:\WINDOWS\Fonts\'\WisdomSoft ScreenHunter Pro v5.0.733.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6215] command /c del "C:\WINDOWS\Fonts\'\WisdomSoft MotionGIF v4.0.317.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC685] cmd /c del "C:\WINDOWS\Fonts\'\WisdomSoft MotionGIF v4.0.317.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7342] cmd /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Anti Spyware v7.0.483.000.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1048] command /c del "C:\WINDOWS\Fonts\'\WisdomSoft AutoScreenRecorder Pro v3.0.321.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9003] cmd /c del "C:\WINDOWS\Fonts\'\WisdomSoft AutoScreenRecorder Pro v3.0.321.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9912] command /c del "C:\WINDOWS\Fonts\'\EMS SQL Manager 2007 for MySQL 4.4.0.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1818] cmd /c del "C:\WINDOWS\Fonts\'\EMS SQL Manager 2007 for MySQL 4.4.0.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5932] command /c del "C:\WINDOWS\Fonts\'\Jetico BestCrypt Volume Encryption v2.10.02.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8335] cmd /c del "C:\WINDOWS\Fonts\'\Jetico BestCrypt Volume Encryption v2.10.02.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1065] command /c del "C:\WINDOWS\Fonts\'\EximiousSoft GIF Creator v5.58.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6726] cmd /c del "C:\WINDOWS\Fonts\'\EximiousSoft GIF Creator v5.58.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2136] command /c del "C:\WINDOWS\Fonts\'\NovaStor NovaBACKUP Professional v10.0.28605.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4919] cmd /c del "C:\WINDOWS\Fonts\'\NovaStor NovaBACKUP Professional v10.0.28605.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1014] cmd /c del "C:\WINDOWS\Fonts\'\Belltech CaptureXT Screen Capture v3.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6819] command /c del "C:\WINDOWS\Fonts\'\DivlocSoft Actual Search and Replace v2.8.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4844] cmd /c del "C:\WINDOWS\Fonts\'\DivlocSoft Actual Search and Replace v2.8.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6903] command /c del "C:\WINDOWS\Fonts\'\iColorPicker v6.21.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5419] cmd /c del "C:\WINDOWS\Fonts\'\iColorPicker v6.21.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5165] command /c del "C:\WINDOWS\Fonts\'\Backup Key Recovery 1.0.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4158] cmd /c del "C:\WINDOWS\Fonts\'\Backup Key Recovery 1.0.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5509] command /c del "C:\WINDOWS\Fonts\'\Hpmbcalc v4.21.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1767] cmd /c del "C:\WINDOWS\Fonts\'\Hpmbcalc v4.21.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4962] command /c del "C:\WINDOWS\Fonts\'\Lost Planet Extreme Condition Colonies PROPER-ViTALiTY.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7634] cmd /c del "C:\WINDOWS\Fonts\'\Lost Planet Extreme Condition Colonies PROPER-ViTALiTY.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3029] command /c del "C:\WINDOWS\Fonts\'\Metal Gear Solid iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3605] cmd /c del "C:\WINDOWS\Fonts\'\Metal Gear Solid iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7828] command /c del "C:\WINDOWS\Fonts\'\Race Driver GRID Multi 5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2885] cmd /c del "C:\WINDOWS\Fonts\'\Race Driver GRID Multi 5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA10] command /c del "C:\WINDOWS\Fonts\'\Empires Dawn of the Modern World iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC581] cmd /c del "C:\WINDOWS\Fonts\'\Empires Dawn of the Modern World iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9761] command /c del "C:\WINDOWS\Fonts\'\Nuclear Power Plant Simulator.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3483] cmd /c del "C:\WINDOWS\Fonts\'\Nuclear Power Plant Simulator.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6110] command /c del "C:\WINDOWS\Fonts\'\Serious Sam The First Encounter iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4730] cmd /c del "C:\WINDOWS\Fonts\'\Serious Sam The First Encounter iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6353] command /c del "C:\WINDOWS\Fonts\'\Daemon Tools Pro Advanced 4.10.0218.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1300] cmd /c del "C:\WINDOWS\Fonts\'\ConvertXtoDVD 2.2.1.253.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9884] command /c del "C:\WINDOWS\Fonts\'\Dracula Origin-RELOADED iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5990] cmd /c del "C:\WINDOWS\Fonts\'\Dracula Origin-RELOADED iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4047] command /c del "C:\WINDOWS\Fonts\'\The Incredible Hulk-RELOADED iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9720] cmd /c del "C:\WINDOWS\Fonts\'\The Incredible Hulk-RELOADED iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA750] command /c del "C:\WINDOWS\Fonts\'\Devil May Cry 4 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC682] cmd /c del "C:\WINDOWS\Fonts\'\Devil May Cry 4 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3117] command /c del "C:\WINDOWS\Fonts\'\Baby Mama DVDR-DREAMLiGHT.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2993] cmd /c del "C:\WINDOWS\Fonts\'\Baby Mama DVDR-DREAMLiGHT.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9481] command /c del "C:\WINDOWS\Fonts\'\Children of Men 2006 m-HD x264.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2183] cmd /c del "C:\WINDOWS\Fonts\'\Children of Men 2006 m-HD x264.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5741] command /c del "C:\WINDOWS\Fonts\'\Whats Eating Gilbert Grape 1993 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7263] cmd /c del "C:\WINDOWS\Fonts\'\Whats Eating Gilbert Grape 1993 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2729] command /c del "C:\WINDOWS\Fonts\'\Made Of Honor NTSC DVDR-BOW.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6520] cmd /c del "C:\WINDOWS\Fonts\'\Made Of Honor NTSC DVDR-BOW.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1408] command /c del "C:\WINDOWS\Fonts\'\Swimming With Sharks 1994 SE INTERNAL DVDRip XviD.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9109] cmd /c del "C:\WINDOWS\Fonts\'\Swimming With Sharks 1994 SE INTERNAL DVDRip XviD.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1699] command /c del "C:\WINDOWS\Fonts\'\Barbie And The Diamond Castle 2008 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6689] cmd /c del "C:\WINDOWS\Fonts\'\Barbie And The Diamond Castle 2008 DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2904] command /c del "C:\WINDOWS\Fonts\'\Maan Gaye Mughall-E-Azam DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8230] cmd /c del "C:\WINDOWS\Fonts\'\Maan Gaye Mughall-E-Azam DVDRip Xvid.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7672] command /c del "C:\WINDOWS\Fonts\'\Star Wars The Clone Wars TS XviD-COALiTiON.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC49] cmd /c del "C:\WINDOWS\Fonts\'\Star Wars The Clone Wars TS XviD-COALiTiON.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7422] command /c del "C:\WINDOWS\Fonts\'\Half Life 2 The Orange Box iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1459] cmd /c del "C:\WINDOWS\Fonts\'\Half Life 2 The Orange Box iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5693] command /c del "C:\WINDOWS\Fonts\'\Gears Of War-Razor1911 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC123] cmd /c del "C:\WINDOWS\Fonts\'\Gears Of War-Razor1911 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1783] command /c del "C:\WINDOWS\Fonts\'\Sid Meiers Civilization III iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4172] cmd /c del "C:\WINDOWS\Fonts\'\Sid Meiers Civilization III iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6538] command /c del "C:\WINDOWS\Fonts\'\The Settlers VI Rise Of An Empire iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC637] cmd /c del "C:\WINDOWS\Fonts\'\The Settlers VI Rise Of An Empire iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4998] command /c del "C:\WINDOWS\Fonts\'\Hunting Unlimited 2009.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1841] cmd /c del "C:\WINDOWS\Fonts\'\Hunting Unlimited 2009.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1177] command /c del "C:\WINDOWS\Fonts\'\Stubbs The Zombie iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8293] cmd /c del "C:\WINDOWS\Fonts\'\Stubbs The Zombie iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2309] command /c del "C:\WINDOWS\Fonts\'\FarCry iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC873] cmd /c del "C:\WINDOWS\Fonts\'\FarCry iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8932] command /c del "C:\WINDOWS\Fonts\'\Test Drive Unlimited iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9849] cmd /c del "C:\WINDOWS\Fonts\'\Test Drive Unlimited iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4026] command /c del "C:\WINDOWS\Fonts\'\Gothic 3 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1653] cmd /c del "C:\WINDOWS\Fonts\'\Gothic 3 iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8243] command /c del "C:\WINDOWS\Fonts\'\NFS Most Wanted RiP.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5608] cmd /c del "C:\WINDOWS\Fonts\'\NFS Most Wanted RiP.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6348] command /c del "C:\WINDOWS\Fonts\'\Audiosurf iSO plus Updates.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6669] cmd /c del "C:\WINDOWS\Fonts\'\Audiosurf iSO plus Updates.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6303] command /c del "C:\WINDOWS\Fonts\'\Asterix at the Olympic Games iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2632] cmd /c del "C:\WINDOWS\Fonts\'\Asterix at the Olympic Games iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7139] command /c del "C:\WINDOWS\Fonts\'\Viva Pinata-RELOADED iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4979] cmd /c del "C:\WINDOWS\Fonts\'\Viva Pinata-RELOADED iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3479] command /c del "C:\WINDOWS\Fonts\'\GTR Evolution-RELOADED iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1527] cmd /c del "C:\WINDOWS\Fonts\'\GTR Evolution-RELOADED iSO.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5283] command /c del "C:\WINDOWS\Fonts\'\Monopoly Tycoon.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC825] cmd /c del "C:\WINDOWS\Fonts\'\Monopoly Tycoon.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1547] command /c del "C:\WINDOWS\Fonts\'\Risk II.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6610] cmd /c del "C:\WINDOWS\Fonts\'\Risk II.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA338] command /c del "C:\WINDOWS\Fonts\'\Bus Simulator 2008.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3820] cmd /c del "C:\WINDOWS\Fonts\'\Bus Simulator 2008.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4904] command /c del "C:\WINDOWS\Fonts\'\S.T.A.L.K.E.R. Clear Sky 2008 RU.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9101] cmd /c del "C:\WINDOWS\Fonts\'\S.T.A.L.K.E.R. Clear Sky 2008 RU.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2043] command /c del "C:\WINDOWS\Fonts\'\McAfee VirusScan Enterprise v9.0i.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7672] cmd /c del "C:\WINDOWS\Fonts\'\McAfee VirusScan Enterprise v9.0i.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9905] command /c del "C:\WINDOWS\Fonts\'\Eset Nod32 3.0.566.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC710] cmd /c del "C:\WINDOWS\Fonts\'\Eset Nod32 3.0.566.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2842] command /c del "C:\WINDOWS\Fonts\'\Wise RegistryCleaner 3.7.128.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3577] cmd /c del "C:\WINDOWS\Fonts\'\Wise RegistryCleaner 3.7.128.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3340] command /c del "C:\WINDOWS\Fonts\'\ESET NOD32 Antivirus Home Edition 3.0..zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9877] cmd /c del "C:\WINDOWS\Fonts\'\Quick Time Player Pro 7.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6885] command /c del "C:\WINDOWS\Fonts\'\Tube Hunter Ultra v2.3.2756.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8014] cmd /c del "C:\WINDOWS\Fonts\'\Tube Hunter Ultra v2.3.2756.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2191] command /c del "C:\WINDOWS\Fonts\'\FlashGet 1.9.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6829] cmd /c del "C:\WINDOWS\Fonts\'\FlashGet 1.9.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3543] command /c del "C:\WINDOWS\Fonts\'\RegsitryEasy4.7.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4570] cmd /c del "C:\WINDOWS\Fonts\'\ConvertXtoDVD 2.1.19.243.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1887] command /c del "C:\WINDOWS\Fonts\'\Ninja Reflex.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4344] cmd /c del "C:\WINDOWS\Fonts\'\Ninja Reflex.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA214] command /c del "C:\WINDOWS\Fonts\'\Brain Trainer ViTALiTY.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5186] cmd /c del "C:\WINDOWS\Fonts\'\Brain Trainer ViTALiTY.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA434] command /c del "C:\WINDOWS\Fonts\'\Keyboard Music.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8302] cmd /c del "C:\WINDOWS\Fonts\'\Keyboard Music.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9920] command /c del "C:\WINDOWS\Fonts\'\Flobo Hard Disk Repair.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC426] cmd /c del "C:\WINDOWS\Fonts\'\Flobo Hard Disk Repair.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4969] command /c del "C:\WINDOWS\Fonts\'\Okoker Audio Factory.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3043] cmd /c del "C:\WINDOWS\Fonts\'\Okoker Audio Factory.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2573] command /c del "C:\WINDOWS\Fonts\'\Iphone Pc Suite.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7891] cmd /c del "C:\WINDOWS\Fonts\'\Iphone Pc Suite.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8380] command /c del "C:\WINDOWS\Fonts\'\Download Accelerator Plus Premium 8.7.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1317] cmd /c del "C:\WINDOWS\Fonts\'\Download Accelerator Plus Premium 8.7.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2674] command /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Security Suite 8.0.015.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9655] cmd /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Security Suite 8.0.015.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8921] command /c del "C:\WINDOWS\Fonts\'\Amadis FLV to DVD Creator 1.1.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5510] cmd /c del "C:\WINDOWS\Fonts\'\Amadis FLV to DVD Creator 1.1.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3323] command /c del "C:\WINDOWS\Fonts\'\Duplicate File Detector 4.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9796] cmd /c del "C:\WINDOWS\Fonts\'\Duplicate File Detector 4.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5000] command /c del "C:\WINDOWS\Fonts\'\SUPERAntiSpyware Pro 4.20.1046.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1226] cmd /c del "C:\WINDOWS\Fonts\'\SUPERAntiSpyware Pro 4.20.1046.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3615] command /c del "C:\WINDOWS\Fonts\'\Portable Pictomio v1.0.15.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6158] cmd /c del "C:\WINDOWS\Fonts\'\Portable Pictomio v1.0.15.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1184] cmd /c del "C:\WINDOWS\Fonts\'\Punch! ViaCAD 2D3D 6.0.0.786.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5842] command /c del "C:\WINDOWS\Fonts\'\Remograph Remo 3D v1.4.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8124] cmd /c del "C:\WINDOWS\Fonts\'\Remograph Remo 3D v1.4.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9696] command /c del "C:\WINDOWS\Fonts\'\3D PaintBrush v1.0.0.134.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6695] cmd /c del "C:\WINDOWS\Fonts\'\3D PaintBrush v1.0.0.134.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1765] command /c del "C:\WINDOWS\Fonts\'\MobiTNT VirtualCaller 2.00.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1087] cmd /c del "C:\WINDOWS\Fonts\'\MobiTNT VirtualCaller 2.00.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1119] command /c del "C:\WINDOWS\Fonts\'\GoodSync Pro 7.2.9.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9551] cmd /c del "C:\WINDOWS\Fonts\'\OJOsoft DVD Ripper 2.1.0.0630.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1167] command /c del "C:\WINDOWS\Fonts\'\WINCO Alc 2008 Strong 3.2.8.27733.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3767] cmd /c del "C:\WINDOWS\Fonts\'\Crazy Machines.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1631] command /c del "C:\WINDOWS\Fonts\'\ClickyMouse Professional 7.1.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5313] cmd /c del "C:\WINDOWS\Fonts\'\ClickyMouse Professional 7.1.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4114] command /c del "C:\WINDOWS\Fonts\'\BusinessCards MX 3.92.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC942] cmd /c del "C:\WINDOWS\Fonts\'\BusinessCards MX 3.92.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4415] command /c del "C:\WINDOWS\Fonts\'\OJOsoft Total Video Converter 2.1.0.07.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1] cmd /c del "C:\WINDOWS\Fonts\'\OJOsoft Total Video Converter 2.1.0.07.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2417] command /c del "C:\WINDOWS\Fonts\'\Jetico Personal Firewall 2.0.2.6.2296.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8223] cmd /c del "C:\WINDOWS\Fonts\'\Jetico Personal Firewall 2.0.2.6.2296.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6410] command /c del "C:\WINDOWS\Fonts\'\Transfer Your PC Deluxe 2.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6898] cmd /c del "C:\WINDOWS\Fonts\'\Transfer Your PC Deluxe 2.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1570] command /c del "C:\WINDOWS\Fonts\'\Personal Algebra Tutor 8.31.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3648] cmd /c del "C:\WINDOWS\Fonts\'\Personal Algebra Tutor 8.31.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA514] command /c del "C:\WINDOWS\Fonts\'\Mayoko 1.1.3 (Portable).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5422] cmd /c del "C:\WINDOWS\Fonts\'\Mayoko 1.1.3 (Portable).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7646] command /c del "C:\WINDOWS\Fonts\'\Picture Merge Genius 2.7.2 (Portable).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4357] cmd /c del "C:\WINDOWS\Fonts\'\Picture Merge Genius 2.7.2 (Portable).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5763] command /c del "C:\WINDOWS\Fonts\'\Acelogix Ace Optimizer Utilities 4.2.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5266] cmd /c del "C:\WINDOWS\Fonts\'\Acelogix Ace Optimizer Utilities 4.2.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA885] command /c del "C:\WINDOWS\Fonts\'\Windows Live Messenger 9 Build 14.0.39.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9369] cmd /c del "C:\WINDOWS\Fonts\'\Windows Live Messenger 9 Build 14.0.39.zip"
sexy_ladii05
2008-08-31, 03:52
O4 - HKLM\..\RunOnce: [SpybotDeletingA5575] command /c del "C:\WINDOWS\Fonts\'\Acelogix System Tuneup 2.2.0.427.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1327] cmd /c del "C:\WINDOWS\Fonts\'\Acelogix System Tuneup 2.2.0.427.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5048] command /c del "C:\WINDOWS\Fonts\'\Advanced PC Tweaker 2008 4.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4314] command /c del "C:\WINDOWS\Fonts\'\Audio Record Edit Toolbox v10.3.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1470] cmd /c del "C:\WINDOWS\Fonts\'\Portable ConvertXToDVD 3.2.0.50.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA586] command /c del "C:\WINDOWS\Fonts\'\Advanced WindowsCare Professional 2.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6040] cmd /c del "C:\WINDOWS\Fonts\'\Advanced WindowsCare Professional 2.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2603] command /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Pro 8.0.015.000.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4405] cmd /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Pro 8.0.015.000.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3954] command /c del "C:\WINDOWS\Fonts\'\VueScan Pro 8.4.82.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9396] cmd /c del "C:\WINDOWS\Fonts\'\VueScan Pro 8.4.82.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9727] command /c del "C:\WINDOWS\Fonts\'\AoA DVD Ripper 5.19.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7642] cmd /c del "C:\WINDOWS\Fonts\'\AoA DVD Ripper 5.19.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9164] command /c del "C:\WINDOWS\Fonts\'\Business Card Designer Pro 5.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7571] cmd /c del "C:\WINDOWS\Fonts\'\Business Card Designer Pro 5.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4820] command /c del "C:\WINDOWS\Fonts\'\DeskSpace 1.5.4.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4079] cmd /c del "C:\WINDOWS\Fonts\'\DeskSpace 1.5.4.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6837] command /c del "C:\WINDOWS\Fonts\'\Desktop Maestro 3.0.0.830.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC885] cmd /c del "C:\WINDOWS\Fonts\'\Desktop Maestro 3.0.0.830.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3331] command /c del "C:\WINDOWS\Fonts\'\Drive Snapshot 1.39.0.13740.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6141] cmd /c del "C:\WINDOWS\Fonts\'\Drive Snapshot 1.39.0.13740.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6878] command /c del "C:\WINDOWS\Fonts\'\ViewonLog 1.1 Build 131.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6424] cmd /c del "C:\WINDOWS\Fonts\'\ViewonLog 1.1 Build 131.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA164] command /c del "C:\WINDOWS\Fonts\'\KRyLack Password Recovery 2.73.02.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC636] cmd /c del "C:\WINDOWS\Fonts\'\KRyLack Password Recovery 2.73.02.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7401] command /c del "C:\WINDOWS\Fonts\'\Amadis FLV to DVD Creator 3.7.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6601] cmd /c del "C:\WINDOWS\Fonts\'\Amadis FLV to DVD Creator 3.7.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2962] command /c del "C:\WINDOWS\Fonts\'\CDMenuPro Business Edition v6.24.00.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9355] cmd /c del "C:\WINDOWS\Fonts\'\CDMenuPro Business Edition v6.24.00.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5988] command /c del "C:\WINDOWS\Fonts\'\Atomic Alarm Clock v5.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5149] cmd /c del "C:\WINDOWS\Fonts\'\Atomic Alarm Clock v5.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4406] command /c del "C:\WINDOWS\Fonts\'\RegCure v1.5.0.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2322] cmd /c del "C:\WINDOWS\Fonts\'\RegCure v1.5.0.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6827] command /c del "C:\WINDOWS\Fonts\'\PPTminimizer 4.0 (Multilingual).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4889] cmd /c del "C:\WINDOWS\Fonts\'\PPTminimizer 4.0 (Multilingual).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2443] cmd /c del "C:\WINDOWS\Fonts\'\Easy Screen Capture 2.0.4.27.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6642] command /c del "C:\WINDOWS\Fonts\'\Uniblue Registery Booster PowerSuite.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1502] cmd /c del "C:\WINDOWS\Fonts\'\Uniblue Registery Booster PowerSuite.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8545] command /c del "C:\WINDOWS\Fonts\'\Corel Draw X4 Graphic Suite.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7841] cmd /c del "C:\WINDOWS\Fonts\'\Corel Draw X4 Graphic Suite.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6608] command /c del "C:\WINDOWS\Fonts\'\DVDFab Platinum 4055.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8008] cmd /c del "C:\WINDOWS\Fonts\'\DVDFab Platinum 4055.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6919] cmd /c del "C:\WINDOWS\Fonts\'\ESET NOD32 Antivirus Home Edition 3.0..zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9957] command /c del "C:\WINDOWS\Fonts\'\TROJAN REMOVER v6.7.2 Build 2539.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5969] cmd /c del "C:\WINDOWS\Fonts\'\TROJAN REMOVER v6.7.2 Build 2539.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA841] command /c del "C:\WINDOWS\Fonts\'\Core FTP Server v1.0.267.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7662] cmd /c del "C:\WINDOWS\Fonts\'\Core FTP Server v1.0.267.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5064] command /c del "C:\WINDOWS\Fonts\'\Portable ConvertXToDVD 3.2.0.50.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7700] command /c del "C:\WINDOWS\Fonts\'\Norton AntiBot 1.1.838.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4771] cmd /c del "C:\WINDOWS\Fonts\'\Norton AntiBot 1.1.838.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2263] command /c del "C:\WINDOWS\Fonts\'\BitDefender Antivirus 2009 Build 12.0.10 Final.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC967] cmd /c del "C:\WINDOWS\Fonts\'\BitDefender Antivirus 2009 Build 12.0.10 Final.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8620] command /c del "C:\WINDOWS\Fonts\'\Belltech Business Card Designer Pro 5.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6945] cmd /c del "C:\WINDOWS\Fonts\'\Belltech Business Card Designer Pro 5.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2893] command /c del "C:\WINDOWS\Fonts\'\Nokia PC Suite 6.86 Release 4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6971] cmd /c del "C:\WINDOWS\Fonts\'\Nokia PC Suite 6.86 Release 4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4745] command /c del "C:\WINDOWS\Fonts\'\Nero 8.3.2.1 Ultra LITE.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1518] cmd /c del "C:\WINDOWS\Fonts\'\Nero 8.3.2.1 Ultra LITE.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5713] command /c del "C:\WINDOWS\Fonts\'\Nero Vision Express 3.0.1.18.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3995] cmd /c del "C:\WINDOWS\Fonts\'\Nero Vision Express 3.0.1.18.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA692] command /c del "C:\WINDOWS\Fonts\'\Flash2X EXE Packager v3.0.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6572] cmd /c del "C:\WINDOWS\Fonts\'\Nero PhotoShow Deluxe 5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4374] command /c del "C:\WINDOWS\Fonts\'\Mp3 Rocket Pro 5.0.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4337] cmd /c del "C:\WINDOWS\Fonts\'\Mp3 Rocket Pro 5.0.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8324] command /c del "C:\WINDOWS\Fonts\'\MyLanViewer 1.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1974] cmd /c del "C:\WINDOWS\Fonts\'\MyLanViewer 1.4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8685] command /c del "C:\WINDOWS\Fonts\'\Mozilla Firefox 3.0.2 RC2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8884] cmd /c del "C:\WINDOWS\Fonts\'\Mozilla Firefox 3.0.2 RC2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1868] command /c del "C:\WINDOWS\Fonts\'\PdfFactory Professional v3.36.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC140] cmd /c del "C:\WINDOWS\Fonts\'\PdfFactory Professional v3.36.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2744] command /c del "C:\WINDOWS\Fonts\'\Alcohol 120 1.9.7 Build 6221 Final.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1438] cmd /c del "C:\WINDOWS\Fonts\'\Alcohol 120 1.9.7 Build 6221 Final.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7878] command /c del "C:\WINDOWS\Fonts\'\SpeedUpMyPC 2009 v4.0.0.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6348] cmd /c del "C:\WINDOWS\Fonts\'\SpeedUpMyPC 2009 v4.0.0.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6847] command /c del "C:\WINDOWS\Fonts\'\Okoker Internet Accelerator 4.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7632] cmd /c del "C:\WINDOWS\Fonts\'\Okoker Internet Accelerator 4.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8702] command /c del "C:\WINDOWS\Fonts\'\Unlocker 1.8.7.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC512] cmd /c del "C:\WINDOWS\Fonts\'\Unlocker 1.8.7.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9432] command /c del "C:\WINDOWS\Fonts\'\AnyDVD.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6226] cmd /c del "C:\WINDOWS\Fonts\'\AnyDVD.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2405] command /c del "C:\WINDOWS\Fonts\'\Trillian Astra 4.0.0.79.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3431] cmd /c del "C:\WINDOWS\Fonts\'\Trillian Astra 4.0.0.79.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4955] command /c del "C:\WINDOWS\Fonts\'\River Past Video Cleaner Pro v7.6.9.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2011] cmd /c del "C:\WINDOWS\Fonts\'\River Past Video Cleaner Pro v7.6.9.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA411] command /c del "C:\WINDOWS\Fonts\'\Partition Magic 8.05.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC701] cmd /c del "C:\WINDOWS\Fonts\'\Partition Magic 8.05.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1461] cmd /c del "C:\WINDOWS\Fonts\'\Driver Magician v.3.28.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3608] command /c del "C:\WINDOWS\Fonts\'\Winamp 5.541 Built 2165.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8723] cmd /c del "C:\WINDOWS\Fonts\'\Winamp 5.541 Built 2165.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8841] command /c del "C:\WINDOWS\Fonts\'\LimeWire PRO 4.18.6.1 Retail.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1160] cmd /c del "C:\WINDOWS\Fonts\'\LimeWire PRO 4.18.6.1 Retail.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2601] command /c del "C:\WINDOWS\Fonts\'\SpyBot Search and Destroy 1.6.0.30 Final.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6383] cmd /c del "C:\WINDOWS\Fonts\'\SpyBot Search and Destroy 1.6.0.30 Final.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6969] command /c del "C:\WINDOWS\Fonts\'\Portable Mayoko 1.1.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7534] cmd /c del "C:\WINDOWS\Fonts\'\Portable Mayoko 1.1.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6786] command /c del "C:\WINDOWS\Fonts\'\Corel Paint Shop Pro X 10.0.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2743] cmd /c del "C:\WINDOWS\Fonts\'\Corel Paint Shop Pro X 10.0.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1678] command /c del "C:\WINDOWS\Fonts\'\Opera 9.52 Build 10103 Beta.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9931] cmd /c del "C:\WINDOWS\Fonts\'\Opera 9.52 Build 10103 Beta.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3754] command /c del "C:\WINDOWS\Fonts\'\Adobe Flash Player 9.0.47.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7689] cmd /c del "C:\WINDOWS\Fonts\'\Adobe Flash Player 9.0.47.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4542] command /c del "C:\WINDOWS\Fonts\'\CorelDraw Suite X4 complete.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5276] cmd /c del "C:\WINDOWS\Fonts\'\CorelDraw Suite X4 complete.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7413] command /c del "C:\WINDOWS\Fonts\'\GameJackal Pro 3.1.0.4 Beta.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC594] cmd /c del "C:\WINDOWS\Fonts\'\GameJackal Pro 3.1.0.4 Beta.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1271] command /c del "C:\WINDOWS\Fonts\'\FruityLoops Studio Producer Edition XX.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7163] cmd /c del "C:\WINDOWS\Fonts\'\FruityLoops Studio Producer Edition XX.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1344] command /c del "C:\WINDOWS\Fonts\'\Portable System Mechanic Professional.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5683] cmd /c del "C:\WINDOWS\Fonts\'\Portable System Mechanic Professional.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4084] command /c del "C:\WINDOWS\Fonts\'\SUPERAntiSpyware Professional v4.20.10.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5352] cmd /c del "C:\WINDOWS\Fonts\'\SUPERAntiSpyware Professional v4.20.10.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8726] command /c del "C:\WINDOWS\Fonts\'\Super Jigsaw Safari v1.4.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2835] cmd /c del "C:\WINDOWS\Fonts\'\Super Jigsaw Safari v1.4.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8132] command /c del "C:\WINDOWS\Fonts\'\SiteDesigner Technologies 3D FTP v8.0..zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4757] cmd /c del "C:\WINDOWS\Fonts\'\SiteDesigner Technologies 3D FTP v8.0..zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA826] command /c del "C:\WINDOWS\Fonts\'\Registry Booster 2009 v2.1.0.0 WinALL.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9712] cmd /c del "C:\WINDOWS\Fonts\'\Registry Booster 2009 v2.1.0.0 WinALL.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7846] command /c del "C:\WINDOWS\Fonts\'\Mjksoft WinSuperKit v6.3.1 WinAll.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4393] cmd /c del "C:\WINDOWS\Fonts\'\Mjksoft WinSuperKit v6.3.1 WinAll.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3802] command /c del "C:\WINDOWS\Fonts\'\Elecard AVC Plugin v2.3.80625.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3050] cmd /c del "C:\WINDOWS\Fonts\'\Elecard AVC Plugin v2.3.80625.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1454] command /c del "C:\WINDOWS\Fonts\'\ActiveBarcode v5.5.6 Bilingual.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5018] cmd /c del "C:\WINDOWS\Fonts\'\ActiveBarcode v5.5.6 Bilingual.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2254] command /c del "C:\WINDOWS\Fonts\'\Eset Nod32 3.0.672.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1490] command /c del "C:\WINDOWS\Fonts\'\ZoneAlarm AntiVirus v7.0.483.000.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3663] cmd /c del "C:\WINDOWS\Fonts\'\ZoneAlarm AntiVirus v7.0.483.000.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6841] command /c del "C:\WINDOWS\Fonts\'\Zemana Antilogger 1.1.2.416.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5414] cmd /c del "C:\WINDOWS\Fonts\'\Zemana Antilogger 1.1.2.416.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6430] command /c del "C:\WINDOWS\Fonts\'\Proxy Switcher v3.18.0.4990.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2167] cmd /c del "C:\WINDOWS\Fonts\'\Proxy Switcher v3.18.0.4990.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1506] command /c del "C:\WINDOWS\Fonts\'\GreenBox Logo Maker v2.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8156] cmd /c del "C:\WINDOWS\Fonts\'\GreenBox Logo Maker v2.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6120] command /c del "C:\WINDOWS\Fonts\'\CorelDraw Graphics Suite 11.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6549] cmd /c del "C:\WINDOWS\Fonts\'\CorelDraw Graphics Suite 11.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8030] command /c del "C:\WINDOWS\Fonts\'\Game Maker Pro v7.0.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5335] cmd /c del "C:\WINDOWS\Fonts\'\Game Maker Pro v7.0.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8100] command /c del "C:\WINDOWS\Fonts\'\Avant Brower 11.6 Build 20.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4755] cmd /c del "C:\WINDOWS\Fonts\'\Avant Brower 11.6 Build 20.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7209] command /c del "C:\WINDOWS\Fonts\'\RealPlayer v 11.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8174] cmd /c del "C:\WINDOWS\Fonts\'\RealPlayer v 11.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9805] command /c del "C:\WINDOWS\Fonts\'\ConvertXtoDVD 2.1.19.243.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6685] command /c del "C:\WINDOWS\Fonts\'\ConvertXtoDVD 2.2.1.253.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7106] command /c del "C:\WINDOWS\Fonts\'\WinRar 3.70 Final.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5061] cmd /c del "C:\WINDOWS\Fonts\'\Super Mario.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2952] command /c del "C:\WINDOWS\Fonts\'\Satellite Antenna Alignment v.2.38.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4837] cmd /c del "C:\WINDOWS\Fonts\'\Satellite Antenna Alignment v.2.38.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2629] command /c del "C:\WINDOWS\Fonts\'\Nature Illusion Studio v2.60.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6058] cmd /c del "C:\WINDOWS\Fonts\'\Nature Illusion Studio v2.60.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9322] command /c del "C:\WINDOWS\Fonts\'\SpeedCommander 11.62 Build 5000.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1070] cmd /c del "C:\WINDOWS\Fonts\'\SpeedCommander 11.62 Build 5000.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8842] command /c del "C:\WINDOWS\Fonts\'\Arclab Thumb Studio v.1.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1294] cmd /c del "C:\WINDOWS\Fonts\'\Arclab Thumb Studio v.1.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6351] command /c del "C:\WINDOWS\Fonts\'\Hide IP NG 1.32.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9406] cmd /c del "C:\WINDOWS\Fonts\'\Hide IP NG 1.32.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8851] command /c del "C:\WINDOWS\Fonts\'\Flash Learning 02.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4921] cmd /c del "C:\WINDOWS\Fonts\'\Flash Learning 02.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7965] command /c del "C:\WINDOWS\Fonts\'\GetFLV Pro v6.0 Final.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7555] cmd /c del "C:\WINDOWS\Fonts\'\GetFLV Pro v6.0 Final.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6522] command /c del "C:\WINDOWS\Fonts\'\Jetico Personal Firewall v2.0.2.6.2296.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8667] cmd /c del "C:\WINDOWS\Fonts\'\Jetico Personal Firewall v2.0.2.6.2296.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA533] command /c del "C:\WINDOWS\Fonts\'\Personal Algebra Tutor v8.31.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1671] cmd /c del "C:\WINDOWS\Fonts\'\Personal Algebra Tutor v8.31.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2791] command /c del "C:\WINDOWS\Fonts\'\Portable Picture Merge Genius 2.7.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3592] cmd /c del "C:\WINDOWS\Fonts\'\Portable Picture Merge Genius 2.7.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8205] command /c del "C:\WINDOWS\Fonts\'\Screen Grab Pro Deluxe 1.2 Portable.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6453] cmd /c del "C:\WINDOWS\Fonts\'\Screen Grab Pro Deluxe 1.2 Portable.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3182] command /c del "C:\WINDOWS\Fonts\'\Sygate Personal Firewall 5.6.3408 Final.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9932] cmd /c del "C:\WINDOWS\Fonts\'\Sygate Personal Firewall 5.6.3408 Final.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6583] command /c del "C:\WINDOWS\Fonts\'\Bitdefender Total Security 2009.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5206] cmd /c del "C:\WINDOWS\Fonts\'\Wanted (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7840] command /c del "C:\WINDOWS\Fonts\'\Xceed Ultimate Suite 2008 3.2.8373.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9553] cmd /c del "C:\WINDOWS\Fonts\'\Xceed Ultimate Suite 2008 3.2.8373.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3876] command /c del "C:\WINDOWS\Fonts\'\WordWeb Pro v5.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3250] cmd /c del "C:\WINDOWS\Fonts\'\WordWeb Pro v5.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4579] command /c del "C:\WINDOWS\Fonts\'\Music Label 2009 v15.0.1.2003.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5666] cmd /c del "C:\WINDOWS\Fonts\'\Music Label 2009 v15.0.1.2003.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4398] cmd /c del "C:\WINDOWS\Fonts\'\Daemon Tools Pro Advanced 4.10.0218.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8295] cmd /c del "C:\WINDOWS\Fonts\'\Eset Nod32 3.0.672.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4184] command /c del "C:\WINDOWS\Fonts\'\Lavasoft Adaware Pro 2007 7.0.2.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8710] cmd /c del "C:\WINDOWS\Fonts\'\Lavasoft Adaware Pro 2007 7.0.2.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5535] command /c del "C:\WINDOWS\Fonts\'\Banner Maker Pro 7.0.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4300] cmd /c del "C:\WINDOWS\Fonts\'\Banner Maker Pro 7.0.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3725] command /c del "C:\WINDOWS\Fonts\'\Lavasoft Ad-Aware 2007 Pro 7.1.0.8 (Portable).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4424] cmd /c del "C:\WINDOWS\Fonts\'\Lavasoft Ad-Aware 2007 Pro 7.1.0.8 (Portable).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4231] command /c del "C:\WINDOWS\Fonts\'\System Mechanic V7.1.10.7.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3105] cmd /c del "C:\WINDOWS\Fonts\'\System Mechanic V7.1.10.7.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3280] command /c del "C:\WINDOWS\Fonts\'\Cakewalk Guitar Tracks Pro v3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5967] cmd /c del "C:\WINDOWS\Fonts\'\Cakewalk Guitar Tracks Pro v3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9668] command /c del "C:\WINDOWS\Fonts\'\Super Converter 2007.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6273] cmd /c del "C:\WINDOWS\Fonts\'\Super Converter 2007.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6707] command /c del "C:\WINDOWS\Fonts\'\TGTSoft StyleBuilder v2.021000.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC664] cmd /c del "C:\WINDOWS\Fonts\'\Rush Hour (1998).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7868] command /c del "C:\WINDOWS\Fonts\'\Combat Wings Battle of the Pacific.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC902] cmd /c del "C:\WINDOWS\Fonts\'\Combat Wings Battle of the Pacific.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2602] command /c del "C:\WINDOWS\Fonts\'\Deadliest Catch Alaskan Storm.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4538] cmd /c del "C:\WINDOWS\Fonts\'\Deadliest Catch Alaskan Storm.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8530] command /c del "C:\WINDOWS\Fonts\'\Breath of Fire.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3222] cmd /c del "C:\WINDOWS\Fonts\'\Breath of Fire.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7574] command /c del "C:\WINDOWS\Fonts\'\Laptop Battery Doubler 1.2..zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6286] cmd /c del "C:\WINDOWS\Fonts\'\Best Wishes for Tomorrow (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2186] command /c del "C:\WINDOWS\Fonts\'\Sharks Terrors of the Deep Screensaver.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5635] cmd /c del "C:\WINDOWS\Fonts\'\Sharks Terrors of the Deep Screensaver.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA989] command /c del "C:\WINDOWS\Fonts\'\Airscape Transparency.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3764] cmd /c del "C:\WINDOWS\Fonts\'\Airscape Transparency.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4887] command /c del "C:\WINDOWS\Fonts\'\Cleaner (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2145] cmd /c del "C:\WINDOWS\Fonts\'\Cleaner (2008).zip"
sexy_ladii05
2008-08-31, 03:53
O4 - HKLM\..\RunOnce: [SpybotDeletingA4103] command /c del "C:\WINDOWS\Fonts\'\Uniblue Spy Eraser 2.0.1.1530.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA971] command /c del "C:\WINDOWS\Fonts\'\Heroes Wanted (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6418] cmd /c del "C:\WINDOWS\Fonts\'\1Click DVD Copy Pro 3.2.1.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9182] command /c del "C:\WINDOWS\Fonts\'\Power Retouche Pro 8.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7558] cmd /c del "C:\WINDOWS\Fonts\'\Power Retouche Pro 8.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6582] command /c del "C:\WINDOWS\Fonts\'\The Note (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6731] cmd /c del "C:\WINDOWS\Fonts\'\Smart DVD-CD Burner 3.0.104.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8094] command /c del "C:\WINDOWS\Fonts\'\USB Webserver 6 (Portable).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1803] cmd /c del "C:\WINDOWS\Fonts\'\USB Webserver 6 (Portable).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5893] command /c del "C:\WINDOWS\Fonts\'\DVDFab Platinum 5.0.8.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5776] cmd /c del "C:\WINDOWS\Fonts\'\DVDFab Platinum 5.0.8.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA870] command /c del "C:\WINDOWS\Fonts\'\MindSoft Utilities XP 9.80 2008.20.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1009] cmd /c del "C:\WINDOWS\Fonts\'\MindSoft Utilities XP 9.80 2008.20.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9683] command /c del "C:\WINDOWS\Fonts\'\Farsight Calculator 2.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9657] cmd /c del "C:\WINDOWS\Fonts\'\Farsight Calculator 2.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4814] command /c del "C:\WINDOWS\Fonts\'\DownloadStudio 5.0.3.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8487] cmd /c del "C:\WINDOWS\Fonts\'\DownloadStudio 5.0.3.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1288] command /c del "C:\WINDOWS\Fonts\'\Ashampoo WinOptimizer 5.05.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9956] cmd /c del "C:\WINDOWS\Fonts\'\Ashampoo WinOptimizer 5.05.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6397] command /c del "C:\WINDOWS\Fonts\'\Ashampoo Cover Studio 1.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1581] cmd /c del "C:\WINDOWS\Fonts\'\Ashampoo Cover Studio 1.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6842] command /c del "C:\WINDOWS\Fonts\'\Ashampoo Burning Studio 8.03.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7651] cmd /c del "C:\WINDOWS\Fonts\'\Ashampoo Burning Studio 8.03.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8554] command /c del "C:\WINDOWS\Fonts\'\Portable System Mechanic v8.0.0.17.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2758] cmd /c del "C:\WINDOWS\Fonts\'\Portable System Mechanic v8.0.0.17.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1722] cmd /c del "C:\WINDOWS\Fonts\'\Deamon Tools 4.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA688] command /c del "C:\WINDOWS\Fonts\'\Mix Meister Fusion 7.3.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7609] cmd /c del "C:\WINDOWS\Fonts\'\Mix Meister Fusion 7.3.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7885] command /c del "C:\WINDOWS\Fonts\'\3GP Video Convertor 4.22.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6121] cmd /c del "C:\WINDOWS\Fonts\'\3GP Video Convertor 4.22.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5943] command /c del "C:\WINDOWS\Fonts\'\Expression Web 2.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4796] cmd /c del "C:\WINDOWS\Fonts\'\Expression Web 2.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7124] command /c del "C:\WINDOWS\Fonts\'\Speed up my pc 3.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1076] cmd /c del "C:\WINDOWS\Fonts\'\Speed up my pc 3.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA649] command /c del "C:\WINDOWS\Fonts\'\Avg AntiVirus 9.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1944] cmd /c del "C:\WINDOWS\Fonts\'\Avg AntiVirus 9.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3881] command /c del "C:\WINDOWS\Fonts\'\Internet Download Manager 5.15.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3714] cmd /c del "C:\WINDOWS\Fonts\'\Internet Download Manager 5.15.6.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9851] command /c del "C:\WINDOWS\Fonts\'\OnlineEye Pro 2.1.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4807] cmd /c del "C:\WINDOWS\Fonts\'\OnlineEye Pro 2.1.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9325] command /c del "C:\WINDOWS\Fonts\'\onOne PhotoTools 1 Pro.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7682] cmd /c del "C:\WINDOWS\Fonts\'\onOne PhotoTools 1 Pro.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA921] command /c del "C:\WINDOWS\Fonts\'\OO SafeErase 3.0.1308.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2017] cmd /c del "C:\WINDOWS\Fonts\'\OO SafeErase 3.0.1308.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5996] command /c del "C:\WINDOWS\Fonts\'\OO DiskRecovery 4.1.1334.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3316] cmd /c del "C:\WINDOWS\Fonts\'\OO DiskRecovery 4.1.1334.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4291] command /c del "C:\WINDOWS\Fonts\'\Symantec Norton 360 2.0.0.242.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5443] cmd /c del "C:\WINDOWS\Fonts\'\Symantec Norton 360 2.0.0.242.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5937] command /c del "C:\WINDOWS\Fonts\'\Everest Ultimate Edition Beta 4.50.1488.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4319] cmd /c del "C:\WINDOWS\Fonts\'\Everest Ultimate Edition Beta 4.50.1488.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9102] command /c del "C:\WINDOWS\Fonts\'\Atomic Alarm Clock 5.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5365] cmd /c del "C:\WINDOWS\Fonts\'\Atomic Alarm Clock 5.8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1764] command /c del "C:\WINDOWS\Fonts\'\Winter Gold Mine 3D Screensaver 1.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC117] cmd /c del "C:\WINDOWS\Fonts\'\Winter Gold Mine 3D Screensaver 1.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6490] command /c del "C:\WINDOWS\Fonts\'\ConvertXToDVD 3.2.0.50.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1875] cmd /c del "C:\WINDOWS\Fonts\'\ConvertXToDVD 3.2.0.50.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3038] command /c del "C:\WINDOWS\Fonts\'\SlySoft AnyDVD Beta 6.4.6.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7444] cmd /c del "C:\WINDOWS\Fonts\'\SlySoft AnyDVD Beta 6.4.6.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8831] cmd /c del "C:\WINDOWS\Fonts\'\Flash2X EXE Packager v3.0.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC57] cmd /c del "C:\WINDOWS\Fonts\'\Pearl Diversion v1.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9482] cmd /c del "C:\WINDOWS\Fonts\'\Operation Mania v1.0.5.55.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7125] command /c del "C:\WINDOWS\Fonts\'\Handy Backup Professional 6.1.0.1698.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2989] cmd /c del "C:\WINDOWS\Fonts\'\Handy Backup Professional 6.1.0.1698.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5578] command /c del "C:\WINDOWS\Fonts\'\Quad v2.01.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC984] cmd /c del "C:\WINDOWS\Fonts\'\Quad v2.01.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA813] command /c del "C:\WINDOWS\Fonts\'\InfoWorks Technology RegDoctor v2.05.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9538] cmd /c del "C:\WINDOWS\Fonts\'\InfoWorks Technology RegDoctor v2.05.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5333] command /c del "C:\WINDOWS\Fonts\'\Ideal DVD Copy v3.2.0 WinAll.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7063] cmd /c del "C:\WINDOWS\Fonts\'\Ideal DVD Copy v3.2.0 WinAll.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6192] command /c del "C:\WINDOWS\Fonts\'\Auction Auto Bidder v6.1.600.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6071] cmd /c del "C:\WINDOWS\Fonts\'\Auction Auto Bidder v6.1.600.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5521] command /c del "C:\WINDOWS\Fonts\'\Adrosoft Steady Recorder v2.4.5 WinAll.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC218] cmd /c del "C:\WINDOWS\Fonts\'\Adrosoft Steady Recorder v2.4.5 WinAll.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2750] command /c del "C:\WINDOWS\Fonts\'\LimeWire Pro 4.18.6.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1576] cmd /c del "C:\WINDOWS\Fonts\'\LimeWire Pro 4.18.6.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3004] command /c del "C:\WINDOWS\Fonts\'\Diskeeper 2008 Pro Premier 12.0.781.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2136] cmd /c del "C:\WINDOWS\Fonts\'\Diskeeper 2008 Pro Premier 12.0.781.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9531] command /c del "C:\WINDOWS\Fonts\'\Clone DVD 4.01.2516.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8720] cmd /c del "C:\WINDOWS\Fonts\'\Clone DVD 4.01.2516.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9363] command /c del "C:\WINDOWS\Fonts\'\Avira AntiVir Professional 2008 8.1.0.606.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3639] cmd /c del "C:\WINDOWS\Fonts\'\Avira AntiVir Professional 2008 8.1.0.606.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9649] command /c del "C:\WINDOWS\Fonts\'\AVG AntiVirus Pro 8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5787] cmd /c del "C:\WINDOWS\Fonts\'\AVG AntiVirus Pro 8.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7572] command /c del "C:\WINDOWS\Fonts\'\SafeApp Disk Cleaner 1.2.143.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8553] cmd /c del "C:\WINDOWS\Fonts\'\SafeApp Disk Cleaner 1.2.143.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2992] cmd /c del "C:\WINDOWS\Fonts\'\RegCure 1.5.0.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4816] command /c del "C:\WINDOWS\Fonts\'\Steganos Internet Security 2009.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3203] cmd /c del "C:\WINDOWS\Fonts\'\Steganos Internet Security 2009.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA506] command /c del "C:\WINDOWS\Fonts\'\CodeWeavers CrossOver Mac Pro v7.0.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1302] cmd /c del "C:\WINDOWS\Fonts\'\CodeWeavers CrossOver Mac Pro v7.0.2.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5718] command /c del "C:\WINDOWS\Fonts\'\Movie Label 2009 v4.1.1.755.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1511] cmd /c del "C:\WINDOWS\Fonts\'\Movie Label 2009 v4.1.1.755.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7055] command /c del "C:\WINDOWS\Fonts\'\Ashampoo Burning Studio 8 v8.03.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC365] cmd /c del "C:\WINDOWS\Fonts\'\Ashampoo Burning Studio 8 v8.03.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2863] command /c del "C:\WINDOWS\Fonts\'\Ahead Nero v8.3.6.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2514] cmd /c del "C:\WINDOWS\Fonts\'\Ahead Nero v8.3.6.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7276] command /c del "C:\WINDOWS\Fonts\'\Kaspersky Internet Security 2009 8.0.0.454.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC668] cmd /c del "C:\WINDOWS\Fonts\'\Kaspersky Internet Security 2009 8.0.0.454.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3873] command /c del "C:\WINDOWS\Fonts\'\Registry Mechanic 8.0.0.900.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1735] cmd /c del "C:\WINDOWS\Fonts\'\Registry Mechanic 8.0.0.900.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6502] command /c del "C:\WINDOWS\Fonts\'\Wall-E (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1047] cmd /c del "C:\WINDOWS\Fonts\'\Wall-E (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7766] cmd /c del "C:\WINDOWS\Fonts\'\Hancock (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9771] command /c del "C:\WINDOWS\Fonts\'\The Dark Knight (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC560] cmd /c del "C:\WINDOWS\Fonts\'\The Dark Knight (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8916] command /c del "C:\WINDOWS\Fonts\'\Step Brothers (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3649] cmd /c del "C:\WINDOWS\Fonts\'\Step Brothers (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8162] command /c del "C:\WINDOWS\Fonts\'\The Bank Job (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2518] cmd /c del "C:\WINDOWS\Fonts\'\The Bank Job (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2189] command /c del "C:\WINDOWS\Fonts\'\The Love Guru (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5460] cmd /c del "C:\WINDOWS\Fonts\'\The Love Guru (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3972] command /c del "C:\WINDOWS\Fonts\'\Mama Mia (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9786] cmd /c del "C:\WINDOWS\Fonts\'\Mama Mia (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9541] command /c del "C:\WINDOWS\Fonts\'\What Happens In Vegas (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6177] cmd /c del "C:\WINDOWS\Fonts\'\What Happens In Vegas (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2380] command /c del "C:\WINDOWS\Fonts\'\Street Kings (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4103] cmd /c del "C:\WINDOWS\Fonts\'\Street Kings (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6853] command /c del "C:\WINDOWS\Fonts\'\August (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5346] cmd /c del "C:\WINDOWS\Fonts\'\August (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5839] command /c del "C:\WINDOWS\Fonts\'\Vice (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2380] cmd /c del "C:\WINDOWS\Fonts\'\Heroes Wanted (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9385] command /c del "C:\WINDOWS\Fonts\'\Shutter (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3320] cmd /c del "C:\WINDOWS\Fonts\'\Shutter (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2356] command /c del "C:\WINDOWS\Fonts\'\The Eye (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7286] cmd /c del "C:\WINDOWS\Fonts\'\The Eye (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1904] command /c del "C:\WINDOWS\Fonts\'\Pathology (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4397] cmd /c del "C:\WINDOWS\Fonts\'\Pathology (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3397] command /c del "C:\WINDOWS\Fonts\'\Chamatkar (1992) (Hindi).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7871] cmd /c del "C:\WINDOWS\Fonts\'\Chamatkar (1992) (Hindi).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9064] command /c del "C:\WINDOWS\Fonts\'\Made of Honor (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8960] cmd /c del "C:\WINDOWS\Fonts\'\Made of Honor (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1855] command /c del "C:\WINDOWS\Fonts\'\Crash (2004).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5500] cmd /c del "C:\WINDOWS\Fonts\'\Crash (2004).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4840] command /c del "C:\WINDOWS\Fonts\'\Postal (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC455] cmd /c del "C:\WINDOWS\Fonts\'\Postal (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA665] command /c del "C:\WINDOWS\Fonts\'\Speed Racer (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4899] cmd /c del "C:\WINDOWS\Fonts\'\Speed Racer (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2287] command /c del "C:\WINDOWS\Fonts\'\The Forbidden Kingdom (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8477] cmd /c del "C:\WINDOWS\Fonts\'\The Forbidden Kingdom (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8558] command /c del "C:\WINDOWS\Fonts\'\CJ7 (2008) (Cantonese).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2912] cmd /c del "C:\WINDOWS\Fonts\'\CJ7 (2008) (Cantonese).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3905] command /c del "C:\WINDOWS\Fonts\'\The Longshots (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5039] cmd /c del "C:\WINDOWS\Fonts\'\The Longshots (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA148] command /c del "C:\WINDOWS\Fonts\'\Indiana Jones and the Kingdom of the Crystal Skull (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5261] cmd /c del "C:\WINDOWS\Fonts\'\Indiana Jones and the Kingdom of the Crystal Skull (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8627] command /c del "C:\WINDOWS\Fonts\'\SpeedUpMyPC 2009 4.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9875] cmd /c del "C:\WINDOWS\Fonts\'\SpeedUpMyPC 2009 4.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9792] command /c del "C:\WINDOWS\Fonts\'\Easy Screen Capture 2.0.4.27.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9221] command /c del "C:\WINDOWS\Fonts\'\FlashFXP 3.6.0.1240.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8188] cmd /c del "C:\WINDOWS\Fonts\'\FlashFXP 3.6.0.1240.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8053] command /c del "C:\WINDOWS\Fonts\'\Xilisoft DVD Ripper Ultimate 5.0.28.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4641] cmd /c del "C:\WINDOWS\Fonts\'\Xilisoft DVD Ripper Ultimate 5.0.28.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8458] command /c del "C:\WINDOWS\Fonts\'\PCMark Professional 5.1.0.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5859] cmd /c del "C:\WINDOWS\Fonts\'\PCMark Professional 5.1.0.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7180] cmd /c del "C:\WINDOWS\Fonts\'\Corel DVD Movie Factory Pro 7.00.398.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8676] command /c del "C:\WINDOWS\Fonts\'\AntiSpyware Professional 4.20.1046.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6366] cmd /c del "C:\WINDOWS\Fonts\'\AntiSpyware Professional 4.20.1046.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3830] command /c del "C:\WINDOWS\Fonts\'\Spyware Doctor with Antivirus 6.0.0.362.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9967] cmd /c del "C:\WINDOWS\Fonts\'\Spyware Doctor with Antivirus 6.0.0.362.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC911] cmd /c del "C:\WINDOWS\Fonts\'\Registry Clean Expert 4.62.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6258] command /c del "C:\WINDOWS\Fonts\'\Cyberlink PowerDVD Ultra Deluxe 8.0.1531.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7266] cmd /c del "C:\WINDOWS\Fonts\'\Cyberlink PowerDVD Ultra Deluxe 8.0.1531.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7286] command /c del "C:\WINDOWS\Fonts\'\A Nightmare on Elm Street 3 Dream Warriors (1987).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2527] cmd /c del "C:\WINDOWS\Fonts\'\A Nightmare on Elm Street 3 Dream Warriors (1987).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9077] command /c del "C:\WINDOWS\Fonts\'\Afghan Knights (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2214] cmd /c del "C:\WINDOWS\Fonts\'\Afghan Knights (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8404] command /c del "C:\WINDOWS\Fonts\'\Alien Invasion Arizona (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9271] cmd /c del "C:\WINDOWS\Fonts\'\Alien Invasion Arizona (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4677] command /c del "C:\WINDOWS\Fonts\'\The Ruins (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9716] cmd /c del "C:\WINDOWS\Fonts\'\The Ruins (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8356] command /c del "C:\WINDOWS\Fonts\'\Rasputin (1999).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6779] cmd /c del "C:\WINDOWS\Fonts\'\Rasputin (1999).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4275] command /c del "C:\WINDOWS\Fonts\'\The Kingdom (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8100] cmd /c del "C:\WINDOWS\Fonts\'\The Kingdom (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9849] command /c del "C:\WINDOWS\Fonts\'\8 Mile (2002).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9318] cmd /c del "C:\WINDOWS\Fonts\'\8 Mile (2002).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA965] command /c del "C:\WINDOWS\Fonts\'\National Treasure Book of Secrets (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7325] cmd /c del "C:\WINDOWS\Fonts\'\National Treasure Book of Secrets (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4889] command /c del "C:\WINDOWS\Fonts\'\Kung Fu Panda (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6476] cmd /c del "C:\WINDOWS\Fonts\'\Kung Fu Panda (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1212] command /c del "C:\WINDOWS\Fonts\'\Drillbit Taylor (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9484] cmd /c del "C:\WINDOWS\Fonts\'\Drillbit Taylor (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9775] command /c del "C:\WINDOWS\Fonts\'\The Spiderwick Chronicles (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9684] cmd /c del "C:\WINDOWS\Fonts\'\The Spiderwick Chronicles (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7003] command /c del "C:\WINDOWS\Fonts\'\Wanted (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1884] command /c del "C:\WINDOWS\Fonts\'\Redbelt (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2054] cmd /c del "C:\WINDOWS\Fonts\'\Redbelt (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3109] cmd /c del "C:\WINDOWS\Fonts\'\The Attic (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4607] command /c del "C:\WINDOWS\Fonts\'\Faces of Gore 2 (2000).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2765] cmd /c del "C:\WINDOWS\Fonts\'\Faces of Gore 2 (2000).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3258] command /c del "C:\WINDOWS\Fonts\'\Batman Returns (1992).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC93] cmd /c del "C:\WINDOWS\Fonts\'\Batman Returns (1992).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7614] command /c del "C:\WINDOWS\Fonts\'\The Morgue (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC618] cmd /c del "C:\WINDOWS\Fonts\'\The Morgue (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4215] command /c del "C:\WINDOWS\Fonts\'\Felon (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5746] cmd /c del "C:\WINDOWS\Fonts\'\Felon (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5506] command /c del "C:\WINDOWS\Fonts\'\Death Race (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5699] cmd /c del "C:\WINDOWS\Fonts\'\Death Race (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3298] command /c del "C:\WINDOWS\Fonts\'\Stop Loss (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4058] cmd /c del "C:\WINDOWS\Fonts\'\Stop Loss (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1707] cmd /c del "C:\WINDOWS\Fonts\'\The Note (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9499] command /c del "C:\WINDOWS\Fonts\'\Kill Kill Faster Faster (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3013] cmd /c del "C:\WINDOWS\Fonts\'\Kill Kill Faster Faster (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8692] command /c del "C:\WINDOWS\Fonts\'\Taking 5 (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9936] cmd /c del "C:\WINDOWS\Fonts\'\Taking 5 (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1593] command /c del "C:\WINDOWS\Fonts\'\Tortured (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5716] cmd /c del "C:\WINDOWS\Fonts\'\Tortured (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9526] command /c del "C:\WINDOWS\Fonts\'\Diego#039;s Wolf Pup Rescue.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7546] cmd /c del "C:\WINDOWS\Fonts\'\Diego#039;s Wolf Pup Rescue.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7468] command /c del "C:\WINDOWS\Fonts\'\The Spiritual World (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3309] cmd /c del "C:\WINDOWS\Fonts\'\The Spiritual World (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA286] command /c del "C:\WINDOWS\Fonts\'\Flu Bird Horror (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3671] cmd /c del "C:\WINDOWS\Fonts\'\Flu Bird Horror (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9601] command /c del "C:\WINDOWS\Fonts\'\Celine (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9719] cmd /c del "C:\WINDOWS\Fonts\'\Celine (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2376] command /c del "C:\WINDOWS\Fonts\'\Tale 52 (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8765] cmd /c del "C:\WINDOWS\Fonts\'\Tale 52 (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9865] command /c del "C:\WINDOWS\Fonts\'\Elegy (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6093] cmd /c del "C:\WINDOWS\Fonts\'\Elegy (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA933] command /c del "C:\WINDOWS\Fonts\'\Resident Evil Director#039;s Cut (PSX).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC95] cmd /c del "C:\WINDOWS\Fonts\'\Hell Ride (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9816] command /c del "C:\WINDOWS\Fonts\'\Monster Ark (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9511] cmd /c del "C:\WINDOWS\Fonts\'\Monster Ark (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3050] command /c del "C:\WINDOWS\Fonts\'\Cactus (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3803] cmd /c del "C:\WINDOWS\Fonts\'\Cactus (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4518] command /c del "C:\WINDOWS\Fonts\'\Then She Found Me (2007).zip"
sexy_ladii05
2008-08-31, 03:59
O4 - HKLM\..\RunOnce: [SpybotDeletingC4764] cmd /c del "C:\WINDOWS\Fonts\'\Then She Found Me (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1150] command /c del "C:\WINDOWS\Fonts\'\The Promotion (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2264] cmd /c del "C:\WINDOWS\Fonts\'\The Promotion (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2131] command /c del "C:\WINDOWS\Fonts\'\Jump Out Boys (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3393] cmd /c del "C:\WINDOWS\Fonts\'\Jump Out Boys (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2140] command /c del "C:\WINDOWS\Fonts\'\Chronicle of An Escape (2006).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC645] cmd /c del "C:\WINDOWS\Fonts\'\Chronicle of An Escape (2006).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1019] command /c del "C:\WINDOWS\Fonts\'\The Go-Getter (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC758] cmd /c del "C:\WINDOWS\Fonts\'\The Go-Getter (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2351] command /c del "C:\WINDOWS\Fonts\'\Best Wishes for Tomorrow (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2727] command /c del "C:\WINDOWS\Fonts\'\Blood Diamond (2006).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5807] cmd /c del "C:\WINDOWS\Fonts\'\Blood Diamond (2006).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5637] command /c del "C:\WINDOWS\Fonts\'\Be Cool (2005).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4359] cmd /c del "C:\WINDOWS\Fonts\'\Be Cool (2005).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA417] command /c del "C:\WINDOWS\Fonts\'\The Machinist (2004).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6738] cmd /c del "C:\WINDOWS\Fonts\'\The Machinist (2004).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8016] command /c del "C:\WINDOWS\Fonts\'\Willow (1988).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6693] cmd /c del "C:\WINDOWS\Fonts\'\Willow (1988).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5005] command /c del "C:\WINDOWS\Fonts\'\The Shawshank Redemption (1994).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5403] cmd /c del "C:\WINDOWS\Fonts\'\The Shawshank Redemption (1994).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6247] command /c del "C:\WINDOWS\Fonts\'\Scary Movie 4 (2006).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8370] cmd /c del "C:\WINDOWS\Fonts\'\Scary Movie 4 (2006).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5854] command /c del "C:\WINDOWS\Fonts\'\Bigger Stronger Faster (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8257] command /c del "C:\WINDOWS\Fonts\'\Ace Ventura When Nature Calls (1995).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1016] cmd /c del "C:\WINDOWS\Fonts\'\Ace Ventura When Nature Calls (1995).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2282] command /c del "C:\WINDOWS\Fonts\'\Ace Ventura Pet Detective (1994).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5947] cmd /c del "C:\WINDOWS\Fonts\'\Ace Ventura Pet Detective (1994).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9001] command /c del "C:\WINDOWS\Fonts\'\Accepted (2006).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8087] cmd /c del "C:\WINDOWS\Fonts\'\Accepted (2006).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4537] command /c del "C:\WINDOWS\Fonts\'\A Walk to Remember (2002).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6663] cmd /c del "C:\WINDOWS\Fonts\'\A Walk to Remember (2002).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5755] command /c del "C:\WINDOWS\Fonts\'\A Night at the Roxbury (1998).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3635] cmd /c del "C:\WINDOWS\Fonts\'\A Night at the Roxbury (1998).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4869] command /c del "C:\WINDOWS\Fonts\'\Teenape Goes to Camp (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5796] cmd /c del "C:\WINDOWS\Fonts\'\Teenape Goes to Camp (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4167] command /c del "C:\WINDOWS\Fonts\'\Valley of Angels (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8603] cmd /c del "C:\WINDOWS\Fonts\'\Valley of Angels (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7257] command /c del "C:\WINDOWS\Fonts\'\Black Belt (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC31] cmd /c del "C:\WINDOWS\Fonts\'\Black Belt (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2841] command /c del "C:\WINDOWS\Fonts\'\Big Stan (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9812] cmd /c del "C:\WINDOWS\Fonts\'\Big Stan (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4952] command /c del "C:\WINDOWS\Fonts\'\Right Place, Wrong Time (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8649] cmd /c del "C:\WINDOWS\Fonts\'\Right Place, Wrong Time (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8240] command /c del "C:\WINDOWS\Fonts\'\It#039;s A Free World (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3690] cmd /c del "C:\WINDOWS\Fonts\'\It#039;s A Free World (2007).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1665] command /c del "C:\WINDOWS\Fonts\'\Never Forget (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2144] cmd /c del "C:\WINDOWS\Fonts\'\Never Forget (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6038] cmd /c del "C:\WINDOWS\Fonts\'\Resident Evil Director#039;s Cut (PSX).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2272] command /c del "C:\WINDOWS\Fonts\'\Neutopia (Wii).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5922] cmd /c del "C:\WINDOWS\Fonts\'\Neutopia (Wii).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7372] command /c del "C:\WINDOWS\Fonts\'\Hide amp; Secret 2 Cliffhanger Castle.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8101] cmd /c del "C:\WINDOWS\Fonts\'\Hide amp; Secret 2 Cliffhanger Castle.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6658] command /c del "C:\WINDOWS\Fonts\'\Condemned Criminal Origins.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2437] cmd /c del "C:\WINDOWS\Fonts\'\Condemned Criminal Origins.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9871] command /c del "C:\WINDOWS\Fonts\'\Need for Speed - Most Wanted.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3846] cmd /c del "C:\WINDOWS\Fonts\'\Need for Speed - Most Wanted.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5980] command /c del "C:\WINDOWS\Fonts\'\The Chronicles of Riddick - Escape from Butcher Bay.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6872] cmd /c del "C:\WINDOWS\Fonts\'\The Chronicles of Riddick - Escape from Butcher Bay.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA630] command /c del "C:\WINDOWS\Fonts\'\Curse of Montezuma 1.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6239] cmd /c del "C:\WINDOWS\Fonts\'\Curse of Montezuma 1.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2546] command /c del "C:\WINDOWS\Fonts\'\Quake 3 Arena.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6142] cmd /c del "C:\WINDOWS\Fonts\'\Quake 3 Arena.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3403] command /c del "C:\WINDOWS\Fonts\'\Moment of Silence (2004).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2810] cmd /c del "C:\WINDOWS\Fonts\'\Moment of Silence (2004).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA339] command /c del "C:\WINDOWS\Fonts\'\Victoria#039;s Secret Service.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC107] cmd /c del "C:\WINDOWS\Fonts\'\Victoria#039;s Secret Service.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4466] command /c del "C:\WINDOWS\Fonts\'\Pro Evolution Soccer 2008.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC227] cmd /c del "C:\WINDOWS\Fonts\'\Pro Evolution Soccer 2008.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9178] command /c del "C:\WINDOWS\Fonts\'\Super Mario.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1090] command /c del "C:\WINDOWS\Fonts\'\Linewatch (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3371] cmd /c del "C:\WINDOWS\Fonts\'\Linewatch (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4369] command /c del "C:\WINDOWS\Fonts\'\Crazy Machines.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA751] command /c del "C:\WINDOWS\Fonts\'\Enchanted Fairy Friends - Secret of the Fairy Queen.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3421] cmd /c del "C:\WINDOWS\Fonts\'\Enchanted Fairy Friends - Secret of the Fairy Queen.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7475] command /c del "C:\WINDOWS\Fonts\'\Shopping Marathon.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3134] cmd /c del "C:\WINDOWS\Fonts\'\Shopping Marathon.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6628] command /c del "C:\WINDOWS\Fonts\'\Little Shop - Road Trip.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7825] cmd /c del "C:\WINDOWS\Fonts\'\Little Shop - Road Trip.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA310] command /c del "C:\WINDOWS\Fonts\'\WinRAR 3.80 Beta 2 SWO Corporate Edition (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8940] cmd /c del "C:\WINDOWS\Fonts\'\WinRAR 3.80 Beta 2 SWO Corporate Edition (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4412] command /c del "C:\WINDOWS\Fonts\'\SpyEraser 2.0.1.1565.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5962] cmd /c del "C:\WINDOWS\Fonts\'\SpyEraser 2.0.1.1565.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7514] command /c del "C:\WINDOWS\Fonts\'\Aleo Photo Collage Maker 1.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2581] cmd /c del "C:\WINDOWS\Fonts\'\Aleo Photo Collage Maker 1.5.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2621] command /c del "C:\WINDOWS\Fonts\'\OJosoft Total Video Converter 2.1.0.0718.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7123] cmd /c del "C:\WINDOWS\Fonts\'\OJosoft Total Video Converter 2.1.0.0718.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8711] command /c del "C:\WINDOWS\Fonts\'\Wondershare Photo Story Platinum 3.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5659] cmd /c del "C:\WINDOWS\Fonts\'\Wondershare Photo Story Platinum 3.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1468] command /c del "C:\WINDOWS\Fonts\'\Sony Vegas Movie Studio Platinum Edition 9.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC856] cmd /c del "C:\WINDOWS\Fonts\'\Sony Vegas Movie Studio Platinum Edition 9.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6188] command /c del "C:\WINDOWS\Fonts\'\Cyberlink PowerDVD Ultra Deluxe 8.0.2021.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5501] cmd /c del "C:\WINDOWS\Fonts\'\Cyberlink PowerDVD Ultra Deluxe 8.0.2021.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9139] command /c del "C:\WINDOWS\Fonts\'\Driver Detective 6.2.5.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5267] cmd /c del "C:\WINDOWS\Fonts\'\Driver Detective 6.2.5.0.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5807] command /c del "C:\WINDOWS\Fonts\'\Easy CD-DA Extractor Pro 11.5.0.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6289] cmd /c del "C:\WINDOWS\Fonts\'\Easy CD-DA Extractor Pro 11.5.0.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6035] command /c del "C:\WINDOWS\Fonts\'\Avast! 4.8.1195 Pro.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8708] cmd /c del "C:\WINDOWS\Fonts\'\Avast! 4.8.1195 Pro.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5970] command /c del "C:\WINDOWS\Fonts\'\Kaspersky Internet Security 8.0.0.192.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6165] cmd /c del "C:\WINDOWS\Fonts\'\Kaspersky Internet Security 8.0.0.192.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9443] command /c del "C:\WINDOWS\Fonts\'\AVG Anti-Malware 7.5.523.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2213] cmd /c del "C:\WINDOWS\Fonts\'\AVG Anti-Malware 7.5.523.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2535] command /c del "C:\WINDOWS\Fonts\'\USB Disk Security 5.0.0.66.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4895] cmd /c del "C:\WINDOWS\Fonts\'\USB Disk Security 5.0.0.66.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1129] command /c del "C:\WINDOWS\Fonts\'\Privacy Shield 3.0.76.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1066] cmd /c del "C:\WINDOWS\Fonts\'\Privacy Shield 3.0.76.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3890] command /c del "C:\WINDOWS\Fonts\'\TuneUp Utilities 2008 7.0.8007.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1937] cmd /c del "C:\WINDOWS\Fonts\'\TuneUp Utilities 2008 7.0.8007.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA716] command /c del "C:\WINDOWS\Fonts\'\Download Accelerator Plus Premium 8.7.0.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4324] cmd /c del "C:\WINDOWS\Fonts\'\Download Accelerator Plus Premium 8.7.0.3.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3480] command /c del "C:\WINDOWS\Fonts\'\BlackBerry User Tools (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2813] cmd /c del "C:\WINDOWS\Fonts\'\BlackBerry User Tools (2008).zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5698] command /c del "C:\WINDOWS\Fonts\'\CuteFTP Pro 8.3.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5079] cmd /c del "C:\WINDOWS\Fonts\'\CuteFTP Pro 8.3.1.zip"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3461] command /c del "C:\WINDOWS\system32\ddcDvvUL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4793] cmd /c del "C:\WINDOWS\system32\ddcDvvUL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1932] command /c del "C:\WINDOWS\system32\rqRHaYst.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC947] cmd /c del "C:\WINDOWS\system32\rqRHaYst.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1280] command /c del "C:\WINDOWS\system32\idsrffeb.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1510] cmd /c del "C:\WINDOWS\system32\idsrffeb.dll_old"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\RunOnce: [SpybotDeletingB3935] command /c del "C:\WINDOWS\Fonts\'\Tinasoft EasyCafe 2.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6445] cmd /c del "C:\WINDOWS\Fonts\'\Tinasoft EasyCafe 2.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8554] command /c del "C:\WINDOWS\Fonts\'\Speed Math 3.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8891] cmd /c del "C:\WINDOWS\Fonts\'\Speed Math 3.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6184] command /c del "C:\WINDOWS\Fonts\'\KRyLack Password Recovery 2.73.02.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3263] cmd /c del "C:\WINDOWS\Fonts\'\Falco Icon Studio 3.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5825] command /c del "C:\WINDOWS\Fonts\'\FlashFXP 3.3.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1732] cmd /c del "C:\WINDOWS\Fonts\'\FlashFXP 3.3.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8389] command /c del "C:\WINDOWS\Fonts\'\Etrusoft Quick Screen Capture 3.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8228] cmd /c del "C:\WINDOWS\Fonts\'\Etrusoft Quick Screen Capture 3.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9580] command /c del "C:\WINDOWS\Fonts\'\Book Collector Pro 5.4.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5742] cmd /c del "C:\WINDOWS\Fonts\'\Book Collector Pro 5.4.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4770] command /c del "C:\WINDOWS\Fonts\'\Weather Alarm Clock 3.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD895] cmd /c del "C:\WINDOWS\Fonts\'\Weather Alarm Clock 3.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6976] command /c del "C:\WINDOWS\Fonts\'\CyberLink Power2Go 6.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1386] cmd /c del "C:\WINDOWS\Fonts\'\CyberLink Power2Go 6.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB528] command /c del "C:\WINDOWS\Fonts\'\Super Utilities Pro 2008 8.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6707] cmd /c del "C:\WINDOWS\Fonts\'\Super Utilities Pro 2008 8.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4071] command /c del "C:\WINDOWS\Fonts\'\VSO Software CopyToDVD 4.0.14.14.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8614] cmd /c del "C:\WINDOWS\Fonts\'\VSO Software CopyToDVD 4.0.14.14.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1155] command /c del "C:\WINDOWS\Fonts\'\VTC Sony Production Essentials.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7747] cmd /c del "C:\WINDOWS\Fonts\'\VTC Sony Production Essentials.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7304] command /c del "C:\WINDOWS\Fonts\'\R-Wipe amp; Clean 8.0.1459.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8548] cmd /c del "C:\WINDOWS\Fonts\'\R-Wipe amp; Clean 8.0.1459.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9768] command /c del "C:\WINDOWS\Fonts\'\GreenBox Logo Maker 2.0 (Portable).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3439] cmd /c del "C:\WINDOWS\Fonts\'\GreenBox Logo Maker 2.0 (Portable).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2024] command /c del "C:\WINDOWS\Fonts\'\Reaper 2.46.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8363] cmd /c del "C:\WINDOWS\Fonts\'\Style XP 2008.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6003] command /c del "C:\WINDOWS\Fonts\'\Trojan Remover 6.7.2.254.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1390] cmd /c del "C:\WINDOWS\Fonts\'\Trojan Remover 6.7.2.254.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6677] command /c del "C:\WINDOWS\Fonts\'\Fraps 2.9.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD688] cmd /c del "C:\WINDOWS\Fonts\'\DVD-Cloner 5.50.0.972.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4858] command /c del "C:\WINDOWS\Fonts\'\Google Earth Pro 4.2.205.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3773] cmd /c del "C:\WINDOWS\Fonts\'\Google Earth Pro 4.2.205.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5695] command /c del "C:\WINDOWS\Fonts\'\The Quiet American 2002 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1230] cmd /c del "C:\WINDOWS\Fonts\'\GOM Media Player 2.1.9.3754.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1801] command /c del "C:\WINDOWS\Fonts\'\Visual CertExam Suite 1.9.978.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD592] cmd /c del "C:\WINDOWS\Fonts\'\Visual CertExam Suite 1.9.978.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4864] command /c del "C:\WINDOWS\Fonts\'\Warhammer 40000 plus Dawn Of War plus Soulstorm iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9294] cmd /c del "C:\WINDOWS\Fonts\'\Password Manager Deluxe 3.71.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7158] command /c del "C:\WINDOWS\Fonts\'\All Media Fixer Pro 9.07.2b.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD33] cmd /c del "C:\WINDOWS\Fonts\'\All Media Fixer Pro 9.07.2b.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4734] command /c del "C:\WINDOWS\Fonts\'\Limewire Turbo 5.5.1.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8765] cmd /c del "C:\WINDOWS\Fonts\'\Limewire Turbo 5.5.1.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7560] command /c del "C:\WINDOWS\Fonts\'\Jiffy Gmail Account Creator 1.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3329] cmd /c del "C:\WINDOWS\Fonts\'\Jiffy Gmail Account Creator 1.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6210] command /c del "C:\WINDOWS\Fonts\'\Linkman 7.3.0.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9915] cmd /c del "C:\WINDOWS\Fonts\'\Nitro PC 2008.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1899] command /c del "C:\WINDOWS\Fonts\'\PageLock Website Copy Protection 7.3.0.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6399] cmd /c del "C:\WINDOWS\Fonts\'\PageLock Website Copy Protection 7.3.0.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8454] command /c del "C:\WINDOWS\Fonts\'\DVD-Cloner 5.50.0.972.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3674] command /c del "C:\WINDOWS\Fonts\'\Jetico Personal Firewall v2.0.2.6.2296.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3549] cmd /c del "C:\WINDOWS\Fonts\'\Revo Uninstaller 1.71 (Portable).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9142] command /c del "C:\WINDOWS\Fonts\'\Anonymous Friend 2.9.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9060] cmd /c del "C:\WINDOWS\Fonts\'\Anonymous Friend 2.9.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1133] command /c del "C:\WINDOWS\Fonts\'\AMP Font Viewer 3.81.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4398] cmd /c del "C:\WINDOWS\Fonts\'\AMP Font Viewer 3.81.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7483] command /c del "C:\WINDOWS\Fonts\'\Laptop Battery Doubler 1.2.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD286] cmd /c del "C:\WINDOWS\Fonts\'\Laptop Battery Doubler 1.2.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9471] command /c del "C:\WINDOWS\Fonts\'\XP Tools Pro 8.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4674] cmd /c del "C:\WINDOWS\Fonts\'\XP Tools Pro 8.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2359] command /c del "C:\WINDOWS\Fonts\'\Advanced Registry Optimizer 5.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1638] cmd /c del "C:\WINDOWS\Fonts\'\Advanced Registry Optimizer 5.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3919] command /c del "C:\WINDOWS\Fonts\'\Registry Easy 4.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6751] cmd /c del "C:\WINDOWS\Fonts\'\Registry Easy 4.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2783] command /c del "C:\WINDOWS\Fonts\'\WinRescue XP 1.08.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6613] cmd /c del "C:\WINDOWS\Fonts\'\WinRescue XP 1.08.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB362] command /c del "C:\WINDOWS\Fonts\'\Style XP 2008.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5975] command /c del "C:\WINDOWS\Fonts\'\Mouse Robot 1.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8828] cmd /c del "C:\WINDOWS\Fonts\'\Mouse Robot 1.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7491] command /c del "C:\WINDOWS\Fonts\'\PCTools Firewall Plus 4.0.0.45.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1238] cmd /c del "C:\WINDOWS\Fonts\'\PCTools Firewall Plus 4.0.0.45.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4766] command /c del "C:\WINDOWS\Fonts\'\Rapidshare Direct Download 3.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9396] cmd /c del "C:\WINDOWS\Fonts\'\Rapidshare Direct Download 3.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7854] command /c del "C:\WINDOWS\Fonts\'\Nitro PC 2008.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4647] command /c del "C:\WINDOWS\Fonts\'\Power Video Converter 1.6.12.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9533] cmd /c del "C:\WINDOWS\Fonts\'\Power Video Converter 1.6.12.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4020] command /c del "C:\WINDOWS\Fonts\'\Macro Mania 12.4.21.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2429] cmd /c del "C:\WINDOWS\Fonts\'\Macro Mania 12.4.21.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5327] command /c del "C:\WINDOWS\Fonts\'\Asterix at the Olympic Games iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6420] cmd /c del "C:\WINDOWS\Fonts\'\Backup Key Recovery 1.0.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6621] command /c del "C:\WINDOWS\Fonts\'\Backup4All Professional 3.11.304.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4328] cmd /c del "C:\WINDOWS\Fonts\'\Backup4All Professional 3.11.304.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1761] command /c del "C:\WINDOWS\Fonts\'\TaskInfo 8.0.0.260.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD395] cmd /c del "C:\WINDOWS\Fonts\'\TaskInfo 8.0.0.260.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB232] command /c del "C:\WINDOWS\Fonts\'\Flash FXP 3.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5460] cmd /c del "C:\WINDOWS\Fonts\'\Flash FXP 3.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9914] command /c del "C:\WINDOWS\Fonts\'\XYplorer 7.50.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1726] cmd /c del "C:\WINDOWS\Fonts\'\XYplorer 7.50.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1505] command /c del "C:\WINDOWS\Fonts\'\YouTube Get 4.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8845] cmd /c del "C:\WINDOWS\Fonts\'\YouTube Get 4.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB750] command /c del "C:\WINDOWS\Fonts\'\Symantec BootMagic 8.05.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3300] cmd /c del "C:\WINDOWS\Fonts\'\Symantec BootMagic 8.05.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9435] command /c del "C:\WINDOWS\Fonts\'\VSO ConvertXtoDVD 3.2.0.49.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1415] cmd /c del "C:\WINDOWS\Fonts\'\VSO ConvertXtoDVD 3.2.0.49.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1947] command /c del "C:\WINDOWS\Fonts\'\Privacy Eraser Pro 6.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4253] cmd /c del "C:\WINDOWS\Fonts\'\Privacy Eraser Pro 6.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4523] command /c del "C:\WINDOWS\Fonts\'\Rush Hour (1998).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4291] cmd /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Pro 8.0.015.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2900] command /c del "C:\WINDOWS\Fonts\'\System Mechanic Professional 8.0.0.18.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5795] cmd /c del "C:\WINDOWS\Fonts\'\System Mechanic Professional 8.0.0.18.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5651] command /c del "C:\WINDOWS\Fonts\'\FTP Explorer 8.8.23.001.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7877] cmd /c del "C:\WINDOWS\Fonts\'\FTP Explorer 8.8.23.001.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7896] command /c del "C:\WINDOWS\Fonts\'\Im Too DVD Ripper 5.0.36.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2982] cmd /c del "C:\WINDOWS\Fonts\'\Im Too DVD Ripper 5.0.36.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2874] command /c del "C:\WINDOWS\Fonts\'\Subtitle Processor 7.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5884] cmd /c del "C:\WINDOWS\Fonts\'\Subtitle Processor 7.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8921] command /c del "C:\WINDOWS\Fonts\'\Killink CSV 1.12.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7676] cmd /c del "C:\WINDOWS\Fonts\'\Killink CSV 1.12.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5568] command /c del "C:\WINDOWS\Fonts\'\Wash and Go 10.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8269] cmd /c del "C:\WINDOWS\Fonts\'\Wash and Go 10.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6659] command /c del "C:\WINDOWS\Fonts\'\WebcamXP Pro 5.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2914] cmd /c del "C:\WINDOWS\Fonts\'\WebcamXP Pro 5.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5869] command /c del "C:\WINDOWS\Fonts\'\ASA Code Factory 8.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5157] cmd /c del "C:\WINDOWS\Fonts\'\ASA Code Factory 8.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4092] command /c del "C:\WINDOWS\Fonts\'\ASA Data Wizard 8.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9648] cmd /c del "C:\WINDOWS\Fonts\'\ASA Data Wizard 8.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2021] command /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Force Field 1.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8330] cmd /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Force Field 1.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2760] command /c del "C:\WINDOWS\Fonts\'\Super Utilities Pro 8.5 (2008).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD896] cmd /c del "C:\WINDOWS\Fonts\'\Super Utilities Pro 8.5 (2008).zip"
sexy_ladii05
2008-08-31, 04:03
O4 - HKCU\..\RunOnce: [SpybotDeletingB8028] command /c del "C:\WINDOWS\Fonts\'\Orbit Downloader 2.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5973] cmd /c del "C:\WINDOWS\Fonts\'\Orbit Downloader 2.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5291] command /c del "C:\WINDOWS\Fonts\'\WindowBlinds Enhanced 6.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2705] cmd /c del "C:\WINDOWS\Fonts\'\WindowBlinds Enhanced 6.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7658] command /c del "C:\WINDOWS\Fonts\'\RegDoctor 2.04.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5476] cmd /c del "C:\WINDOWS\Fonts\'\RegDoctor 2.04.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6774] command /c del "C:\WINDOWS\Fonts\'\Portable System Mechanic v8.0.0.17.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6507] cmd /c del "C:\WINDOWS\Fonts\'\Registry Repair Wizard 2008 5.06.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1516] command /c del "C:\WINDOWS\Fonts\'\EasyBoot 5.1.2.586.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6417] cmd /c del "C:\WINDOWS\Fonts\'\AnyDVD.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7697] command /c del "C:\WINDOWS\Fonts\'\Ideal Secure 1.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9109] cmd /c del "C:\WINDOWS\Fonts\'\Ideal Secure 1.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5889] command /c del "C:\WINDOWS\Fonts\'\XnView 1.94.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4167] cmd /c del "C:\WINDOWS\Fonts\'\XnView 1.94.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7002] command /c del "C:\WINDOWS\Fonts\'\Winlock Professional 4.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3836] cmd /c del "C:\WINDOWS\Fonts\'\Winlock Professional 4.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8934] command /c del "C:\WINDOWS\Fonts\'\Eset Nod32 3.0.566.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1370] cmd /c del "C:\WINDOWS\Fonts\'\Ninja Surfing Hide IP 1.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9053] command /c del "C:\WINDOWS\Fonts\'\Okoker Easy Recorder 4.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8672] cmd /c del "C:\WINDOWS\Fonts\'\Okoker Easy Recorder 4.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5978] command /c del "C:\WINDOWS\Fonts\'\Picture Resize Genius 2.9.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8975] cmd /c del "C:\WINDOWS\Fonts\'\Picture Resize Genius 2.9.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB377] command /c del "C:\WINDOWS\Fonts\'\Super DVD Creator 9.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7371] cmd /c del "C:\WINDOWS\Fonts\'\Alcohol 120 1.9.7 Build 6221 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9346] command /c del "C:\WINDOWS\Fonts\'\Paragon Partition Manager 9.0 Pro.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1915] cmd /c del "C:\WINDOWS\Fonts\'\Paragon Partition Manager 9.0 Pro.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9229] command /c del "C:\WINDOWS\Fonts\'\Auslogics BoostSpeed 4.1.4.133.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7113] cmd /c del "C:\WINDOWS\Fonts\'\Auslogics BoostSpeed 4.1.4.133.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9844] command /c del "C:\WINDOWS\Fonts\'\580 Microsoft Windows Vista Sidebar Gadgets.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7567] cmd /c del "C:\WINDOWS\Fonts\'\580 Microsoft Windows Vista Sidebar Gadgets.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB472] command /c del "C:\WINDOWS\Fonts\'\Vista Manager 1.5.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8676] cmd /c del "C:\WINDOWS\Fonts\'\Vista Manager 1.5.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8883] command /c del "C:\WINDOWS\Fonts\'\AnyDVD amp; AnyDVD HD 6.4.5.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8246] cmd /c del "C:\WINDOWS\Fonts\'\AnyDVD amp; AnyDVD HD 6.4.5.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2966] command /c del "C:\WINDOWS\Fonts\'\Spyware Doctor 5.5.0.212.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9588] cmd /c del "C:\WINDOWS\Fonts\'\Spyware Doctor 5.5.0.212.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3480] command /c del "C:\WINDOWS\Fonts\'\Your Uninstaller! 2008 Pro 6.1.1252.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6054] cmd /c del "C:\WINDOWS\Fonts\'\Your Uninstaller! 2008 Pro 6.1.1252.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4868] command /c del "C:\WINDOWS\Fonts\'\Avast! Antivirus Pro 4.8.1229.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5720] cmd /c del "C:\WINDOWS\Fonts\'\Avast! Antivirus Pro 4.8.1229.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5509] command /c del "C:\WINDOWS\Fonts\'\Photoshop Actions - TextEffects.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2786] cmd /c del "C:\WINDOWS\Fonts\'\Photoshop Actions - TextEffects.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9640] command /c del "C:\WINDOWS\Fonts\'\Kaspersky Internet Security 2009 8.0.0.418.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9918] cmd /c del "C:\WINDOWS\Fonts\'\Kaspersky Internet Security 2009 8.0.0.418.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3286] command /c del "C:\WINDOWS\Fonts\'\Dead Disk Doctor 1.26.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1722] cmd /c del "C:\WINDOWS\Fonts\'\Dead Disk Doctor 1.26.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB963] command /c del "C:\WINDOWS\Fonts\'\MSN Messenger 9.0 Beta (2008).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8316] cmd /c del "C:\WINDOWS\Fonts\'\MSN Messenger 9.0 Beta (2008).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7449] command /c del "C:\WINDOWS\Fonts\'\Daemon Tools Pro Advanced 4.12.220.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2323] cmd /c del "C:\WINDOWS\Fonts\'\Daemon Tools Pro Advanced 4.12.220.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6855] command /c del "C:\WINDOWS\Fonts\'\GreenBox Logo Maker v2.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD415] cmd /c del "C:\WINDOWS\Fonts\'\Driver Genius 2007 Pro 7.1.622.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4213] command /c del "C:\WINDOWS\Fonts\'\Eset NOD32 AntiVirus 3.0.642.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1198] cmd /c del "C:\WINDOWS\Fonts\'\Eset NOD32 AntiVirus 3.0.642.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1625] command /c del "C:\WINDOWS\Fonts\'\Norton Internet Security 2008.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8663] cmd /c del "C:\WINDOWS\Fonts\'\Norton Internet Security 2008.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3856] command /c del "C:\WINDOWS\Fonts\'\Windows Media Player 12.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8888] cmd /c del "C:\WINDOWS\Fonts\'\Windows Media Player 12.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3753] command /c del "C:\WINDOWS\Fonts\'\Kylie Minogue - Sweet Music (2008).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8044] cmd /c del "C:\WINDOWS\Fonts\'\Kylie Minogue - Sweet Music (2008).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6814] command /c del "C:\WINDOWS\Fonts\'\Rapidshare Tools 2008 Collection.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8528] cmd /c del "C:\WINDOWS\Fonts\'\Vice (2008).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1102] command /c del "C:\WINDOWS\Fonts\'\Pineapple Express (2008).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1886] cmd /c del "C:\WINDOWS\Fonts\'\Pineapple Express (2008).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB757] command /c del "C:\WINDOWS\Fonts\'\Tube Hunter Ultra v2.3.2756.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4121] cmd /c del "C:\WINDOWS\Fonts\'\Download Accelerator Plus Premium 8.6.1.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3691] command /c del "C:\WINDOWS\Fonts\'\SpeedFan 4.29.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2932] cmd /c del "C:\WINDOWS\Fonts\'\SpeedFan 4.29.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB633] command /c del "C:\WINDOWS\Fonts\'\Elcor Premium Booster 2.8.0.2500.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8901] cmd /c del "C:\WINDOWS\Fonts\'\Elcor Premium Booster 2.8.0.2500.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1312] command /c del "C:\WINDOWS\Fonts\'\Winaso Disk Cleaner 2.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9250] cmd /c del "C:\WINDOWS\Fonts\'\Winaso Disk Cleaner 2.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7272] command /c del "C:\WINDOWS\Fonts\'\Spamcc 4.7 Pro.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8087] cmd /c del "C:\WINDOWS\Fonts\'\Spamcc 4.7 Pro.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5575] command /c del "C:\WINDOWS\Fonts\'\Tropic Thunder TS XVID-PreVail.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5449] cmd /c del "C:\WINDOWS\Fonts\'\Tropic Thunder TS XVID-PreVail.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3634] command /c del "C:\WINDOWS\Fonts\'\Pineapple Express TS XviD-OPTiC.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2140] cmd /c del "C:\WINDOWS\Fonts\'\Pineapple Express TS XviD-OPTiC.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9188] command /c del "C:\WINDOWS\Fonts\'\Death Race TELESYNC XviD-OPTiC.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2184] cmd /c del "C:\WINDOWS\Fonts\'\Death Race TELESYNC XviD-OPTiC.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9176] command /c del "C:\WINDOWS\Fonts\'\Flash2X Screensaver Builder 3.0.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD840] cmd /c del "C:\WINDOWS\Fonts\'\Flash2X Screensaver Builder 3.0.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9397] command /c del "C:\WINDOWS\Fonts\'\Photo Frame Show v1.4 Build 154.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4732] cmd /c del "C:\WINDOWS\Fonts\'\Photo Frame Show v1.4 Build 154.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5928] command /c del "C:\WINDOWS\Fonts\'\Iphone Pc Suite.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3208] cmd /c del "C:\WINDOWS\Fonts\'\Flash2X Flash Hunter 3.0.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4558] command /c del "C:\WINDOWS\Fonts\'\Portable ConvertXToDVD 3.2.0.50.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5871] cmd /c del "C:\WINDOWS\Fonts\'\Privacy Shield v3.0.79.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3558] command /c del "C:\WINDOWS\Fonts\'\Global Mapper v10.0.10.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3310] cmd /c del "C:\WINDOWS\Fonts\'\Global Mapper v10.0.10.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB449] command /c del "C:\WINDOWS\Fonts\'\X3 Reunion 2007 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1932] cmd /c del "C:\WINDOWS\Fonts\'\Flash2X Wallpaper Maker v1.1.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1430] command /c del "C:\WINDOWS\Fonts\'\Okoker Disk Cleaner v4.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2147] cmd /c del "C:\WINDOWS\Fonts\'\Okoker Disk Cleaner v4.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4108] command /c del "C:\WINDOWS\Fonts\'\HARDiNFO 2008 Professional v6.01 build 3180.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3585] cmd /c del "C:\WINDOWS\Fonts\'\HARDiNFO 2008 Professional v6.01 build 3180.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2482] command /c del "C:\WINDOWS\Fonts\'\Oront Burning Kit 2 Premium v2.5.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9450] cmd /c del "C:\WINDOWS\Fonts\'\Oront Burning Kit 2 Premium v2.5.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6739] command /c del "C:\WINDOWS\Fonts\'\FlashFXP v3.7.3 build 1275 BETA.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1262] cmd /c del "C:\WINDOWS\Fonts\'\FlashFXP v3.7.3 build 1275 BETA.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8644] command /c del "C:\WINDOWS\Fonts\'\Chronograph v6.30.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9103] cmd /c del "C:\WINDOWS\Fonts\'\Chronograph v6.30.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5012] command /c del "C:\WINDOWS\Fonts\'\Flash2X EXE Packager 3.0.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD809] cmd /c del "C:\WINDOWS\Fonts\'\Wrong Turn 2003 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7944] command /c del "C:\WINDOWS\Fonts\'\CleanMyPC Registry Cleaner v4.10.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2780] cmd /c del "C:\WINDOWS\Fonts\'\CleanMyPC Registry Cleaner v4.10.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9934] command /c del "C:\WINDOWS\Fonts\'\BWMeter v4.1.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8311] cmd /c del "C:\WINDOWS\Fonts\'\BWMeter v4.1.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9975] command /c del "C:\WINDOWS\Fonts\'\CDMenuPro v6.24.00 Business Edition Bilingual.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7885] cmd /c del "C:\WINDOWS\Fonts\'\CDMenuPro v6.24.00 Business Edition Bilingual.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4059] command /c del "C:\WINDOWS\Fonts\'\Download Accelerator Plus 8.7.0.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD179] cmd /c del "C:\WINDOWS\Fonts\'\Download Accelerator Plus 8.7.0.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1329] command /c del "C:\WINDOWS\Fonts\'\Adrosoft AD Stream Recorder v2.6.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4792] cmd /c del "C:\WINDOWS\Fonts\'\Adrosoft AD Stream Recorder v2.6.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7157] command /c del "C:\WINDOWS\Fonts\'\DzSoft Perl Editor 5.8.3.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD721] cmd /c del "C:\WINDOWS\Fonts\'\DzSoft Perl Editor 5.8.3.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4421] command /c del "C:\WINDOWS\Fonts\'\Diamond Cut DC7 v7.15.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6562] cmd /c del "C:\WINDOWS\Fonts\'\Alien Invasion Arizona (2007).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1678] command /c del "C:\WINDOWS\Fonts\'\World In Conflict iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2523] cmd /c del "C:\WINDOWS\Fonts\'\World In Conflict iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4228] command /c del "C:\WINDOWS\Fonts\'\Need For Speed Most Wanted iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3711] cmd /c del "C:\WINDOWS\Fonts\'\Need For Speed Most Wanted iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4042] cmd /c del "C:\WINDOWS\Fonts\'\Warhammer 40000 plus Dawn Of War plus Soulstorm iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7562] command /c del "C:\WINDOWS\Fonts\'\Dracula 3 Path Of The Dragon-PROCYON iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3249] cmd /c del "C:\WINDOWS\Fonts\'\Dracula 3 Path Of The Dragon-PROCYON iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8646] command /c del "C:\WINDOWS\Fonts\'\Jazz Jackrabbit 2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5241] cmd /c del "C:\WINDOWS\Fonts\'\Jazz Jackrabbit 2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3409] command /c del "C:\WINDOWS\Fonts\'\Metal Gear Solid 2 - Substance iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6681] cmd /c del "C:\WINDOWS\Fonts\'\Metal Gear Solid 2 - Substance iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2929] command /c del "C:\WINDOWS\Fonts\'\Marvel Super Heroes vs. Capcom X-Men vs. Street Fighter.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4482] cmd /c del "C:\WINDOWS\Fonts\'\Marvel Super Heroes vs. Capcom X-Men vs. Street Fighter.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3715] command /c del "C:\WINDOWS\Fonts\'\Galactic Civilizations II plus Expansions iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2696] cmd /c del "C:\WINDOWS\Fonts\'\Galactic Civilizations II plus Expansions iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2990] command /c del "C:\WINDOWS\Fonts\'\Total Overdose iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7017] cmd /c del "C:\WINDOWS\Fonts\'\Total Overdose iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2964] command /c del "C:\WINDOWS\Fonts\'\Audio-Surf incl. 9 Updates.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6829] cmd /c del "C:\WINDOWS\Fonts\'\Audio-Surf incl. 9 Updates.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4174] cmd /c del "C:\WINDOWS\Fonts\'\X3 Reunion 2007 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9445] command /c del "C:\WINDOWS\Fonts\'\Star Wars Dark Forces Full iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD258] cmd /c del "C:\WINDOWS\Fonts\'\Star Wars Dark Forces Full iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2823] command /c del "C:\WINDOWS\Fonts\'\Star Wars X-Wing vs. Tie Fighter iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5371] cmd /c del "C:\WINDOWS\Fonts\'\Star Wars X-Wing vs. Tie Fighter iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6118] command /c del "C:\WINDOWS\Fonts\'\LEGO Star Wars IIThe Original Trilogy RiP.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5011] cmd /c del "C:\WINDOWS\Fonts\'\LEGO Star Wars IIThe Original Trilogy RiP.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4526] command /c del "C:\WINDOWS\Fonts\'\The Sims 2 Apartment Life-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8367] cmd /c del "C:\WINDOWS\Fonts\'\The Sims 2 Apartment Life-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB946] command /c del "C:\WINDOWS\Fonts\'\MS flight simulator 2004 plus all Addons iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6651] cmd /c del "C:\WINDOWS\Fonts\'\MS flight simulator 2004 plus all Addons iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB159] command /c del "C:\WINDOWS\Fonts\'\The Witcher iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7259] cmd /c del "C:\WINDOWS\Fonts\'\The Witcher iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2426] command /c del "C:\WINDOWS\Fonts\'\Space Siege iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8809] cmd /c del "C:\WINDOWS\Fonts\'\Space Siege iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1547] command /c del "C:\WINDOWS\Fonts\'\Hunting Unlimited 2009 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5659] cmd /c del "C:\WINDOWS\Fonts\'\Hunting Unlimited 2009 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1893] command /c del "C:\WINDOWS\Fonts\'\Call Of Juarez-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2509] cmd /c del "C:\WINDOWS\Fonts\'\Call Of Juarez-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2271] command /c del "C:\WINDOWS\Fonts\'\The Strangers 2008 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6357] cmd /c del "C:\WINDOWS\Fonts\'\The Strangers 2008 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB608] command /c del "C:\WINDOWS\Fonts\'\The Bridge on the River Kwai 1957 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9675] cmd /c del "C:\WINDOWS\Fonts\'\The Bridge on the River Kwai 1957 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3030] command /c del "C:\WINDOWS\Fonts\'\Joy Division 2006 FESTiVAL DVDRip XviD-TNAN.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2196] cmd /c del "C:\WINDOWS\Fonts\'\Joy Division 2006 FESTiVAL DVDRip XviD-TNAN.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5664] command /c del "C:\WINDOWS\Fonts\'\Meet The Robinsons 2007 DVDRip XviD-SAiNTS.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3856] cmd /c del "C:\WINDOWS\Fonts\'\Meet The Robinsons 2007 DVDRip XviD-SAiNTS.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1431] command /c del "C:\WINDOWS\Fonts\'\Hellboy 2 The Golden Army 2008 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8836] cmd /c del "C:\WINDOWS\Fonts\'\Hellboy 2 The Golden Army 2008 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7273] command /c del "C:\WINDOWS\Fonts\'\Tropic Thunder 2008 TS XviD-KingBen.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8523] cmd /c del "C:\WINDOWS\Fonts\'\Tropic Thunder 2008 TS XviD-KingBen.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5964] command /c del "C:\WINDOWS\Fonts\'\Aladdin 1992 720p HDTV x264-hV.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5368] cmd /c del "C:\WINDOWS\Fonts\'\Aladdin 1992 720p HDTV x264-hV.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8127] command /c del "C:\WINDOWS\Fonts\'\The Matrix Reloaded 2003 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3037] cmd /c del "C:\WINDOWS\Fonts\'\The Matrix Reloaded 2003 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8619] cmd /c del "C:\WINDOWS\Fonts\'\The Quiet American 2002 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6879] command /c del "C:\WINDOWS\Fonts\'\The Fall 2006 LiMiTED NTSC DVDR-BeStDvD.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8024] cmd /c del "C:\WINDOWS\Fonts\'\The Fall 2006 LiMiTED NTSC DVDR-BeStDvD.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4483] command /c del "C:\WINDOWS\Fonts\'\Hell Ride 2008 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD358] cmd /c del "C:\WINDOWS\Fonts\'\Hell Ride 2008 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8146] command /c del "C:\WINDOWS\Fonts\'\The Bank Job 2008 DVDRip Xvid-aXXo.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4132] cmd /c del "C:\WINDOWS\Fonts\'\The Bank Job 2008 DVDRip Xvid-aXXo.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4141] command /c del "C:\WINDOWS\Fonts\'\Babylon A.D. DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6538] cmd /c del "C:\WINDOWS\Fonts\'\Babylon A.D. DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5666] command /c del "C:\WINDOWS\Fonts\'\The Invasion 2007 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2005] cmd /c del "C:\WINDOWS\Fonts\'\The Invasion 2007 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2009] command /c del "C:\WINDOWS\Fonts\'\Elegy 2008 LIMITED R5 XviD-COALiTiON.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD511] cmd /c del "C:\WINDOWS\Fonts\'\Elegy 2008 LIMITED R5 XviD-COALiTiON.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9163] command /c del "C:\WINDOWS\Fonts\'\Army Of The Dead 2008 DVDRip XviD-VoMiT.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5920] cmd /c del "C:\WINDOWS\Fonts\'\Army Of The Dead 2008 DVDRip XviD-VoMiT.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5977] command /c del "C:\WINDOWS\Fonts\'\21 DVDRip XviD-FLAiTE.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD456] cmd /c del "C:\WINDOWS\Fonts\'\21 DVDRip XviD-FLAiTE.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7815] command /c del "C:\WINDOWS\Fonts\'\Wrong Turn 2003 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6157] command /c del "C:\WINDOWS\Fonts\'\Tombstone 1993 iNT DVDRip XVID-vRs.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1865] cmd /c del "C:\WINDOWS\Fonts\'\Tombstone 1993 iNT DVDRip XVID-vRs.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3959] command /c del "C:\WINDOWS\Fonts\'\Kingdom of Heaven 2005 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9338] cmd /c del "C:\WINDOWS\Fonts\'\Kingdom of Heaven 2005 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4720] command /c del "C:\WINDOWS\Fonts\'\Wrong Turn 2 Dead End 2007 Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3966] cmd /c del "C:\WINDOWS\Fonts\'\Wrong Turn 2 Dead End 2007 Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4225] command /c del "C:\WINDOWS\Fonts\'\The Happening R5 LINE XViD-BaLD.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8358] cmd /c del "C:\WINDOWS\Fonts\'\The Happening R5 LINE XViD-BaLD.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6994] command /c del "C:\WINDOWS\Fonts\'\The Promotion 2008 LIMITED DVDRip XviD-AMIABLE.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6219] cmd /c del "C:\WINDOWS\Fonts\'\The Promotion 2008 LIMITED DVDRip XviD-AMIABLE.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8469] command /c del "C:\WINDOWS\Fonts\'\Some Mothers Son 1996.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3478] cmd /c del "C:\WINDOWS\Fonts\'\Some Mothers Son 1996.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9262] command /c del "C:\WINDOWS\Fonts\'\Borderland 2007 DVDRip XviD-XanaX.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7346] cmd /c del "C:\WINDOWS\Fonts\'\Borderland 2007 DVDRip XviD-XanaX.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB89] command /c del "C:\WINDOWS\Fonts\'\King Of New York SE 1990 iNTERNAL DVDRip XviD-SAVANNAH.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4817] cmd /c del "C:\WINDOWS\Fonts\'\King Of New York SE 1990 iNTERNAL DVDRip XviD-SAVANNAH.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4067] command /c del "C:\WINDOWS\Fonts\'\The Mummy Tomb of the Dragon Emperor R5 LINE.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD583] cmd /c del "C:\WINDOWS\Fonts\'\The Mummy Tomb of the Dragon Emperor R5 LINE.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7857] command /c del "C:\WINDOWS\Fonts\'\Network Security Protector 2.34.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD192] cmd /c del "C:\WINDOWS\Fonts\'\Network Security Protector 2.34.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6657] command /c del "C:\WINDOWS\Fonts\'\FlashGet 1.9.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5044] cmd /c del "C:\WINDOWS\Fonts\'\Serv-U File Server Corporate v7.2.0.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3734] command /c del "C:\WINDOWS\Fonts\'\NCH Swift Sound Switch Plus v1.42 Patch.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1062] cmd /c del "C:\WINDOWS\Fonts\'\NCH Swift Sound Switch Plus v1.42 Patch.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5225] command /c del "C:\WINDOWS\Fonts\'\SQLite Expert Professional v1.7.13.1713.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2119] cmd /c del "C:\WINDOWS\Fonts\'\SQLite Expert Professional v1.7.13.1713.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5086] command /c del "C:\WINDOWS\Fonts\'\Real Spy Monitor v2.86.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD679] cmd /c del "C:\WINDOWS\Fonts\'\Real Spy Monitor v2.86.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2377] command /c del "C:\WINDOWS\Fonts\'\Norton AntiBot v1.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD316] cmd /c del "C:\WINDOWS\Fonts\'\Norton AntiBot v1.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8341] command /c del "C:\WINDOWS\Fonts\'\Runtime GetDataBack for FAT v3.40.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3557] cmd /c del "C:\WINDOWS\Fonts\'\Runtime GetDataBack for FAT v3.40.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB871] command /c del "C:\WINDOWS\Fonts\'\Runtime DiskExplorer for FAT v3.40.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4220] cmd /c del "C:\WINDOWS\Fonts\'\Runtime DiskExplorer for FAT v3.40.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7576] command /c del "C:\WINDOWS\Fonts\'\Danware NetOp Remote Control v9.10.2008197.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8237] cmd /c del "C:\WINDOWS\Fonts\'\Danware NetOp Remote Control v9.10.2008197.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9207] command /c del "C:\WINDOWS\Fonts\'\MindSoft Utilities XP 9.80.2008.20.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD698] cmd /c del "C:\WINDOWS\Fonts\'\MindSoft Utilities XP 9.80.2008.20.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3123] command /c del "C:\WINDOWS\Fonts\'\FoxIt Reader Pro v2.3.3201.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8945] cmd /c del "C:\WINDOWS\Fonts\'\FoxIt Reader Pro v2.3.3201.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9147] command /c del "C:\WINDOWS\Fonts\'\Mjksoft WinSuperKit 6.3.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2639] cmd /c del "C:\WINDOWS\Fonts\'\Mjksoft WinSuperKit 6.3.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9244] command /c del "C:\WINDOWS\Fonts\'\Audio Record Edit Toolbox v10.31.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1727] cmd /c del "C:\WINDOWS\Fonts\'\Audio Record Edit Toolbox v10.31.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5793] command /c del "C:\WINDOWS\Fonts\'\BetterJPEG 2.0.0.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5251] cmd /c del "C:\WINDOWS\Fonts\'\BetterJPEG 2.0.0.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9566] command /c del "C:\WINDOWS\Fonts\'\HttpWatch Professional v5.3.20.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1418] cmd /c del "C:\WINDOWS\Fonts\'\HttpWatch Professional v5.3.20.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7905] command /c del "C:\WINDOWS\Fonts\'\Ashampoo Cover Studio v1.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4104] cmd /c del "C:\WINDOWS\Fonts\'\Ashampoo Cover Studio v1.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8902] command /c del "C:\WINDOWS\Fonts\'\Archiver v2.5.3143.16107.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD154] cmd /c del "C:\WINDOWS\Fonts\'\Archiver v2.5.3143.16107.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5275] command /c del "C:\WINDOWS\Fonts\'\GBTimelapse v2.1.6.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4364] cmd /c del "C:\WINDOWS\Fonts\'\GBTimelapse v2.1.6.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9861] command /c del "C:\WINDOWS\Fonts\'\Beyond Good and EviL iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5966] cmd /c del "C:\WINDOWS\Fonts\'\Beyond Good and EviL iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB364] command /c del "C:\WINDOWS\Fonts\'\Monkey Island III The Curse Of Monkey Island iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD580] cmd /c del "C:\WINDOWS\Fonts\'\Monkey Island III The Curse Of Monkey Island iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3086] command /c del "C:\WINDOWS\Fonts\'\Portal RiP.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5257] cmd /c del "C:\WINDOWS\Fonts\'\Portal RiP.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5295] command /c del "C:\WINDOWS\Fonts\'\The Godfather The Game RiP.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4887] cmd /c del "C:\WINDOWS\Fonts\'\The Godfather The Game RiP.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9661] command /c del "C:\WINDOWS\Fonts\'\NHL 2008 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5437] cmd /c del "C:\WINDOWS\Fonts\'\NHL 2008 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4015] command /c del "C:\WINDOWS\Fonts\'\Silverfall iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7947] cmd /c del "C:\WINDOWS\Fonts\'\Silverfall iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4427] command /c del "C:\WINDOWS\Fonts\'\Assasins Creed iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8870] cmd /c del "C:\WINDOWS\Fonts\'\Assasins Creed iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1391] command /c del "C:\WINDOWS\Fonts\'\FlatOut Ultimate Carnage-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4977] cmd /c del "C:\WINDOWS\Fonts\'\FlatOut Ultimate Carnage-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3774] command /c del "C:\WINDOWS\Fonts\'\Quake 4 iSO.zip"
sexy_ladii05
2008-08-31, 04:04
O4 - HKCU\..\RunOnce: [SpybotDeletingD769] cmd /c del "C:\WINDOWS\Fonts\'\Quake 4 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3132] command /c del "C:\WINDOWS\Fonts\'\BlackSite Area 51 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1679] cmd /c del "C:\WINDOWS\Fonts\'\BlackSite Area 51 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2078] command /c del "C:\WINDOWS\Fonts\'\Space Chimps-SKIDROW iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8481] cmd /c del "C:\WINDOWS\Fonts\'\Space Chimps-SKIDROW iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2981] command /c del "C:\WINDOWS\Fonts\'\Prison Tycoon 3 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4655] cmd /c del "C:\WINDOWS\Fonts\'\Prison Tycoon 3 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4094] command /c del "C:\WINDOWS\Fonts\'\No Limits Coaster Simulator 1.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3475] cmd /c del "C:\WINDOWS\Fonts\'\No Limits Coaster Simulator 1.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9234] command /c del "C:\WINDOWS\Fonts\'\NBA Live 2008 RiP.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9347] cmd /c del "C:\WINDOWS\Fonts\'\NBA Live 2008 RiP.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3760] command /c del "C:\WINDOWS\Fonts\'\Crash Bandicoot 1,2 and 3 PC iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1998] cmd /c del "C:\WINDOWS\Fonts\'\Crash Bandicoot 1,2 and 3 PC iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1529] command /c del "C:\WINDOWS\Fonts\'\Legend Hand Of God iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4513] cmd /c del "C:\WINDOWS\Fonts\'\Legend Hand Of God iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3699] command /c del "C:\WINDOWS\Fonts\'\Crysis 2007-Razor1911 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4330] cmd /c del "C:\WINDOWS\Fonts\'\Crysis 2007-Razor1911 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1609] command /c del "C:\WINDOWS\Fonts\'\UFO Aftermath iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9703] cmd /c del "C:\WINDOWS\Fonts\'\UFO Aftermath iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4721] command /c del "C:\WINDOWS\Fonts\'\Supreme Commander Forged Alliance iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4196] cmd /c del "C:\WINDOWS\Fonts\'\Supreme Commander Forged Alliance iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3452] command /c del "C:\WINDOWS\Fonts\'\This Is England 2006 LiMiTED DVDRip XviD-DoNE.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2418] cmd /c del "C:\WINDOWS\Fonts\'\SpyEraser 2.0.1.1565.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1313] command /c del "C:\WINDOWS\Fonts\'\Green Mile 1999 DVDRip XviD.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7892] cmd /c del "C:\WINDOWS\Fonts\'\Green Mile 1999 DVDRip XviD.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1225] command /c del "C:\WINDOWS\Fonts\'\Better luck tomorrow DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7533] cmd /c del "C:\WINDOWS\Fonts\'\Better luck tomorrow DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4633] command /c del "C:\WINDOWS\Fonts\'\Speed Racer 2008 R5 x264.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8467] cmd /c del "C:\WINDOWS\Fonts\'\Driver Magician v.3.28.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2371] command /c del "C:\WINDOWS\Fonts\'\The Hills Have Eyes 2 DVDRip XviD-DoNE.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2589] cmd /c del "C:\WINDOWS\Fonts\'\The Hills Have Eyes 2 DVDRip XviD-DoNE.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2169] command /c del "C:\WINDOWS\Fonts\'\Dave Chapelle - For What Its Worth 2004 DVDRip XviD.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5402] cmd /c del "C:\WINDOWS\Fonts\'\Dave Chapelle - For What Its Worth 2004 DVDRip XviD.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9089] command /c del "C:\WINDOWS\Fonts\'\Mad Money 2008 DVDRip AC3-FXG.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD389] cmd /c del "C:\WINDOWS\Fonts\'\Devil May Cry 4 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7757] command /c del "C:\WINDOWS\Fonts\'\The Dark Knight 2008 TS Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3637] cmd /c del "C:\WINDOWS\Fonts\'\The Dark Knight 2008 TS Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5367] command /c del "C:\WINDOWS\Fonts\'\Chaos Theory 2007 DVDRip AC3-aXXo.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9857] cmd /c del "C:\WINDOWS\Fonts\'\Okoker Internet Accelerator 4.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3355] command /c del "C:\WINDOWS\Fonts\'\God Tussi Great Ho 2008 Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9616] cmd /c del "C:\WINDOWS\Fonts\'\God Tussi Great Ho 2008 Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4408] command /c del "C:\WINDOWS\Fonts\'\There Will Be Blood 2007 720p BluRay DTS x264-ESiR.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6288] cmd /c del "C:\WINDOWS\Fonts\'\There Will Be Blood 2007 720p BluRay DTS x264-ESiR.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1408] command /c del "C:\WINDOWS\Fonts\'\Charlie Wilson War DVDRip XviD-DiAMOND.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5919] cmd /c del "C:\WINDOWS\Fonts\'\August (2008).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB209] command /c del "C:\WINDOWS\Fonts\'\The Strangers 2008 DVDSCR H264.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6537] cmd /c del "C:\WINDOWS\Fonts\'\The Strangers 2008 DVDSCR H264.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3148] command /c del "C:\WINDOWS\Fonts\'\Catch Me If You Can 2002 DVDRip XviD.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2940] cmd /c del "C:\WINDOWS\Fonts\'\Catch Me If You Can 2002 DVDRip XviD.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4966] command /c del "C:\WINDOWS\Fonts\'\Reno 911 Miami UNRATED DVDRip XviD-DiAMOND.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1033] cmd /c del "C:\WINDOWS\Fonts\'\Reno 911 Miami UNRATED DVDRip XviD-DiAMOND.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9384] command /c del "C:\WINDOWS\Fonts\'\Almost Famous 2000 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9513] cmd /c del "C:\WINDOWS\Fonts\'\Almost Famous 2000 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5828] command /c del "C:\WINDOWS\Fonts\'\The X-Files-Fight the Future 1998 DVDRip Xvid-aXXo.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9494] cmd /c del "C:\WINDOWS\Fonts\'\The X-Files-Fight the Future 1998 DVDRip Xvid-aXXo.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB258] command /c del "C:\WINDOWS\Fonts\'\Go West A Lucky Luke Adventure 2007 DVDRip XVID-iGNITE.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2519] cmd /c del "C:\WINDOWS\Fonts\'\Go West A Lucky Luke Adventure 2007 DVDRip XVID-iGNITE.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB498] command /c del "C:\WINDOWS\Fonts\'\Sword of the Stranger 300MB MKV X264.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8916] cmd /c del "C:\WINDOWS\Fonts\'\Sword of the Stranger 300MB MKV X264.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2795] command /c del "C:\WINDOWS\Fonts\'\SwirlX3D 1.7.10.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1442] cmd /c del "C:\WINDOWS\Fonts\'\SwirlX3D 1.7.10.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3238] command /c del "C:\WINDOWS\Fonts\'\Danware NetOp Instruct v5.50.2008126.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6949] cmd /c del "C:\WINDOWS\Fonts\'\Danware NetOp Instruct v5.50.2008126.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7820] command /c del "C:\WINDOWS\Fonts\'\PC Washer 2.0.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6113] cmd /c del "C:\WINDOWS\Fonts\'\PC Washer 2.0.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9457] command /c del "C:\WINDOWS\Fonts\'\Easy CD-DA Extractor Pro v11.9.9 Build 668.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9726] cmd /c del "C:\WINDOWS\Fonts\'\Easy CD-DA Extractor Pro v11.9.9 Build 668.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4120] command /c del "C:\WINDOWS\Fonts\'\Smart Install Maker v5.02.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5295] cmd /c del "C:\WINDOWS\Fonts\'\Smart Install Maker v5.02.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7738] command /c del "C:\WINDOWS\Fonts\'\Agnitum Outpost Security Suite Pro 2009 v6.5.2358.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3571] cmd /c del "C:\WINDOWS\Fonts\'\Agnitum Outpost Security Suite Pro 2009 v6.5.2358.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9667] command /c del "C:\WINDOWS\Fonts\'\CHMEditor v1.2 Build 059.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2348] cmd /c del "C:\WINDOWS\Fonts\'\CHMEditor v1.2 Build 059.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1598] command /c del "C:\WINDOWS\Fonts\'\MetaProducts Portable Offline Browser v5.1.2820 SR1 Multilingual.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD266] cmd /c del "C:\WINDOWS\Fonts\'\MetaProducts Portable Offline Browser v5.1.2820 SR1 Multilingual.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB173] command /c del "C:\WINDOWS\Fonts\'\Abyssmedia ScriptCryptor Compiler v2.8.4.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD757] cmd /c del "C:\WINDOWS\Fonts\'\Abyssmedia ScriptCryptor Compiler v2.8.4.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1569] command /c del "C:\WINDOWS\Fonts\'\OnlineEye Pro v2.2.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1369] cmd /c del "C:\WINDOWS\Fonts\'\OnlineEye Pro v2.2.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5915] command /c del "C:\WINDOWS\Fonts\'\MetaProducts Offline Explorer Enterprise v5.1.2820 SR1 Multilingual.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5814] cmd /c del "C:\WINDOWS\Fonts\'\MetaProducts Offline Explorer Enterprise v5.1.2820 SR1 Multilingual.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6923] command /c del "C:\WINDOWS\Fonts\'\SolidIce KeyClone v1.8k.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6679] cmd /c del "C:\WINDOWS\Fonts\'\SolidIce KeyClone v1.8k.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8794] command /c del "C:\WINDOWS\Fonts\'\CRT v6.1.0.349.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4997] cmd /c del "C:\WINDOWS\Fonts\'\CRT v6.1.0.349.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5518] command /c del "C:\WINDOWS\Fonts\'\SecureFX v6.1.0.349.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3170] cmd /c del "C:\WINDOWS\Fonts\'\SecureFX v6.1.0.349.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1869] command /c del "C:\WINDOWS\Fonts\'\SecureCRT v6.1.0.349.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5593] cmd /c del "C:\WINDOWS\Fonts\'\SecureCRT v6.1.0.349.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4115] command /c del "C:\WINDOWS\Fonts\'\WebcamXP Pro v5.3.2.105.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4116] cmd /c del "C:\WINDOWS\Fonts\'\WebcamXP Pro v5.3.2.105.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7225] command /c del "C:\WINDOWS\Fonts\'\WisdomSoft ScreenHunter Pro v5.0.733.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7190] cmd /c del "C:\WINDOWS\Fonts\'\WisdomSoft ScreenHunter Pro v5.0.733.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1526] command /c del "C:\WINDOWS\Fonts\'\WisdomSoft MotionGIF v4.0.317.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6671] cmd /c del "C:\WINDOWS\Fonts\'\WisdomSoft MotionGIF v4.0.317.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8667] command /c del "C:\WINDOWS\Fonts\'\WisdomSoft MotionStudio v4.0.119.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9849] cmd /c del "C:\WINDOWS\Fonts\'\WisdomSoft MotionStudio v4.0.119.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5769] command /c del "C:\WINDOWS\Fonts\'\WisdomSoft AutoScreenRecorder Pro v3.0.321.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2337] cmd /c del "C:\WINDOWS\Fonts\'\WisdomSoft AutoScreenRecorder Pro v3.0.321.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5045] command /c del "C:\WINDOWS\Fonts\'\EMS SQL Manager 2007 for MySQL 4.4.0.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4265] cmd /c del "C:\WINDOWS\Fonts\'\EMS SQL Manager 2007 for MySQL 4.4.0.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1807] command /c del "C:\WINDOWS\Fonts\'\Jetico BestCrypt Volume Encryption v2.10.02.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2375] cmd /c del "C:\WINDOWS\Fonts\'\Jetico BestCrypt Volume Encryption v2.10.02.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2284] command /c del "C:\WINDOWS\Fonts\'\EximiousSoft GIF Creator v5.58.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9105] cmd /c del "C:\WINDOWS\Fonts\'\EximiousSoft GIF Creator v5.58.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5948] command /c del "C:\WINDOWS\Fonts\'\NovaStor NovaBACKUP Professional v10.0.28605.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3610] cmd /c del "C:\WINDOWS\Fonts\'\NovaStor NovaBACKUP Professional v10.0.28605.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9029] command /c del "C:\WINDOWS\Fonts\'\Belltech CaptureXT Screen Capture v3.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2782] cmd /c del "C:\WINDOWS\Fonts\'\Belltech CaptureXT Screen Capture v3.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB526] command /c del "C:\WINDOWS\Fonts\'\DivlocSoft Actual Search and Replace v2.8.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4455] cmd /c del "C:\WINDOWS\Fonts\'\DivlocSoft Actual Search and Replace v2.8.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9100] command /c del "C:\WINDOWS\Fonts\'\iColorPicker v6.21.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8064] cmd /c del "C:\WINDOWS\Fonts\'\iColorPicker v6.21.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5573] command /c del "C:\WINDOWS\Fonts\'\Backup Key Recovery 1.0.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8913] command /c del "C:\WINDOWS\Fonts\'\Hpmbcalc v4.21.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5524] cmd /c del "C:\WINDOWS\Fonts\'\Hpmbcalc v4.21.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2475] command /c del "C:\WINDOWS\Fonts\'\Lost Planet Extreme Condition Colonies PROPER-ViTALiTY.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8052] cmd /c del "C:\WINDOWS\Fonts\'\Lost Planet Extreme Condition Colonies PROPER-ViTALiTY.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2939] command /c del "C:\WINDOWS\Fonts\'\Neutopia (Wii).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3667] cmd /c del "C:\WINDOWS\Fonts\'\Metal Gear Solid iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4310] command /c del "C:\WINDOWS\Fonts\'\Race Driver GRID Multi 5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7471] cmd /c del "C:\WINDOWS\Fonts\'\Race Driver GRID Multi 5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6641] command /c del "C:\WINDOWS\Fonts\'\Empires Dawn of the Modern World iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5798] cmd /c del "C:\WINDOWS\Fonts\'\Empires Dawn of the Modern World iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3201] command /c del "C:\WINDOWS\Fonts\'\Nuclear Power Plant Simulator.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1177] cmd /c del "C:\WINDOWS\Fonts\'\Nuclear Power Plant Simulator.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB310] command /c del "C:\WINDOWS\Fonts\'\Serious Sam The First Encounter iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD388] cmd /c del "C:\WINDOWS\Fonts\'\Serious Sam The First Encounter iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5053] command /c del "C:\WINDOWS\Fonts\'\WarCraft III-Frozen Throne iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6067] cmd /c del "C:\WINDOWS\Fonts\'\WarCraft III-Frozen Throne iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6288] command /c del "C:\WINDOWS\Fonts\'\Dracula Origin-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5170] cmd /c del "C:\WINDOWS\Fonts\'\Dracula Origin-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7105] command /c del "C:\WINDOWS\Fonts\'\The Incredible Hulk-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2700] cmd /c del "C:\WINDOWS\Fonts\'\The Incredible Hulk-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2634] command /c del "C:\WINDOWS\Fonts\'\Devil May Cry 4 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8156] command /c del "C:\WINDOWS\Fonts\'\Baby Mama DVDR-DREAMLiGHT.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1745] cmd /c del "C:\WINDOWS\Fonts\'\Baby Mama DVDR-DREAMLiGHT.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9490] command /c del "C:\WINDOWS\Fonts\'\Children of Men 2006 m-HD x264.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD109] cmd /c del "C:\WINDOWS\Fonts\'\Children of Men 2006 m-HD x264.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2402] command /c del "C:\WINDOWS\Fonts\'\Whats Eating Gilbert Grape 1993 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD315] cmd /c del "C:\WINDOWS\Fonts\'\Whats Eating Gilbert Grape 1993 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3045] command /c del "C:\WINDOWS\Fonts\'\Made Of Honor NTSC DVDR-BOW.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7031] cmd /c del "C:\WINDOWS\Fonts\'\Made Of Honor NTSC DVDR-BOW.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2214] command /c del "C:\WINDOWS\Fonts\'\Swimming With Sharks 1994 SE INTERNAL DVDRip XviD.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8012] cmd /c del "C:\WINDOWS\Fonts\'\Swimming With Sharks 1994 SE INTERNAL DVDRip XviD.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2428] command /c del "C:\WINDOWS\Fonts\'\Barbie And The Diamond Castle 2008 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7062] cmd /c del "C:\WINDOWS\Fonts\'\Barbie And The Diamond Castle 2008 DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1172] command /c del "C:\WINDOWS\Fonts\'\Maan Gaye Mughall-E-Azam DVDRip Xvid.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5016] cmd /c del "C:\WINDOWS\Fonts\'\CodeWeavers CrossOver Mac Pro v7.0.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6051] command /c del "C:\WINDOWS\Fonts\'\Star Wars The Clone Wars TS XviD-COALiTiON.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7388] cmd /c del "C:\WINDOWS\Fonts\'\Star Wars The Clone Wars TS XviD-COALiTiON.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9168] command /c del "C:\WINDOWS\Fonts\'\Half Life 2 The Orange Box iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8464] cmd /c del "C:\WINDOWS\Fonts\'\Half Life 2 The Orange Box iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2158] command /c del "C:\WINDOWS\Fonts\'\Gears Of War-Razor1911 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD563] cmd /c del "C:\WINDOWS\Fonts\'\Gears Of War-Razor1911 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3287] command /c del "C:\WINDOWS\Fonts\'\Sid Meiers Civilization III iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD329] cmd /c del "C:\WINDOWS\Fonts\'\Sid Meiers Civilization III iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5078] command /c del "C:\WINDOWS\Fonts\'\The Settlers VI Rise Of An Empire iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2383] cmd /c del "C:\WINDOWS\Fonts\'\The Settlers VI Rise Of An Empire iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7541] command /c del "C:\WINDOWS\Fonts\'\Hunting Unlimited 2009.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD663] cmd /c del "C:\WINDOWS\Fonts\'\Hunting Unlimited 2009.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5762] command /c del "C:\WINDOWS\Fonts\'\Stubbs The Zombie iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8244] cmd /c del "C:\WINDOWS\Fonts\'\Stubbs The Zombie iSO.zip"
sexy_ladii05
2008-08-31, 04:06
O4 - HKCU\..\RunOnce: [SpybotDeletingB3694] command /c del "C:\WINDOWS\Fonts\'\FarCry iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1107] cmd /c del "C:\WINDOWS\Fonts\'\FarCry iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7983] command /c del "C:\WINDOWS\Fonts\'\Test Drive Unlimited iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1882] cmd /c del "C:\WINDOWS\Fonts\'\Test Drive Unlimited iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5290] command /c del "C:\WINDOWS\Fonts\'\Gothic 3 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD282] cmd /c del "C:\WINDOWS\Fonts\'\Deamon Tools 4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7035] command /c del "C:\WINDOWS\Fonts\'\PCMark Professional 5.1.0.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8339] cmd /c del "C:\WINDOWS\Fonts\'\NFS Most Wanted RiP.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8741] command /c del "C:\WINDOWS\Fonts\'\Audiosurf iSO plus Updates.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1850] cmd /c del "C:\WINDOWS\Fonts\'\Audiosurf iSO plus Updates.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4268] cmd /c del "C:\WINDOWS\Fonts\'\Asterix at the Olympic Games iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6442] command /c del "C:\WINDOWS\Fonts\'\Viva Pinata-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7812] cmd /c del "C:\WINDOWS\Fonts\'\Viva Pinata-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5173] command /c del "C:\WINDOWS\Fonts\'\GTR Evolution-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3687] cmd /c del "C:\WINDOWS\Fonts\'\GTR Evolution-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5066] command /c del "C:\WINDOWS\Fonts\'\Monopoly Tycoon.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1708] cmd /c del "C:\WINDOWS\Fonts\'\Monopoly Tycoon.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB554] command /c del "C:\WINDOWS\Fonts\'\Risk II.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2372] cmd /c del "C:\WINDOWS\Fonts\'\Risk II.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5566] command /c del "C:\WINDOWS\Fonts\'\Bus Simulator 2008.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3498] cmd /c del "C:\WINDOWS\Fonts\'\Bus Simulator 2008.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8360] command /c del "C:\WINDOWS\Fonts\'\S.T.A.L.K.E.R. Clear Sky 2008 RU.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8939] cmd /c del "C:\WINDOWS\Fonts\'\S.T.A.L.K.E.R. Clear Sky 2008 RU.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB339] command /c del "C:\WINDOWS\Fonts\'\McAfee VirusScan Enterprise v9.0i.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3925] cmd /c del "C:\WINDOWS\Fonts\'\McAfee VirusScan Enterprise v9.0i.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD106] cmd /c del "C:\WINDOWS\Fonts\'\Eset Nod32 3.0.566.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6058] command /c del "C:\WINDOWS\Fonts\'\Wise RegistryCleaner 3.7.128.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1005] cmd /c del "C:\WINDOWS\Fonts\'\Wise RegistryCleaner 3.7.128.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1081] command /c del "C:\WINDOWS\Fonts\'\Quick Time Player Pro 7.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8486] cmd /c del "C:\WINDOWS\Fonts\'\Quick Time Player Pro 7.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5444] cmd /c del "C:\WINDOWS\Fonts\'\Tube Hunter Ultra v2.3.2756.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5981] cmd /c del "C:\WINDOWS\Fonts\'\FlashGet 1.9.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5371] command /c del "C:\WINDOWS\Fonts\'\RegsitryEasy4.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4995] cmd /c del "C:\WINDOWS\Fonts\'\RegsitryEasy4.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3164] command /c del "C:\WINDOWS\Fonts\'\Ninja Reflex.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7598] cmd /c del "C:\WINDOWS\Fonts\'\Ninja Reflex.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7433] command /c del "C:\WINDOWS\Fonts\'\Brain Trainer ViTALiTY.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1035] cmd /c del "C:\WINDOWS\Fonts\'\Brain Trainer ViTALiTY.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2619] command /c del "C:\WINDOWS\Fonts\'\Keyboard Music.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6292] cmd /c del "C:\WINDOWS\Fonts\'\Keyboard Music.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6439] command /c del "C:\WINDOWS\Fonts\'\Flobo Hard Disk Repair.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2376] cmd /c del "C:\WINDOWS\Fonts\'\Flobo Hard Disk Repair.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB468] command /c del "C:\WINDOWS\Fonts\'\Okoker Audio Factory.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD611] cmd /c del "C:\WINDOWS\Fonts\'\Okoker Audio Factory.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6899] cmd /c del "C:\WINDOWS\Fonts\'\Iphone Pc Suite.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9769] command /c del "C:\WINDOWS\Fonts\'\Download Accelerator Plus Premium 8.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6013] cmd /c del "C:\WINDOWS\Fonts\'\Download Accelerator Plus Premium 8.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB412] command /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Security Suite 8.0.015.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9605] cmd /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Security Suite 8.0.015.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4591] command /c del "C:\WINDOWS\Fonts\'\Amadis FLV to DVD Creator 1.1.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4959] cmd /c del "C:\WINDOWS\Fonts\'\Amadis FLV to DVD Creator 1.1.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2821] command /c del "C:\WINDOWS\Fonts\'\Duplicate File Detector 4.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2176] cmd /c del "C:\WINDOWS\Fonts\'\Duplicate File Detector 4.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8393] command /c del "C:\WINDOWS\Fonts\'\SUPERAntiSpyware Pro 4.20.1046.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7801] cmd /c del "C:\WINDOWS\Fonts\'\SUPERAntiSpyware Pro 4.20.1046.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5524] command /c del "C:\WINDOWS\Fonts\'\ClickyMouse Professional 7.1.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6393] cmd /c del "C:\WINDOWS\Fonts\'\Portable Pictomio v1.0.15.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9525] command /c del "C:\WINDOWS\Fonts\'\Punch! ViaCAD 2D3D 6.0.0.786.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5098] cmd /c del "C:\WINDOWS\Fonts\'\Punch! ViaCAD 2D3D 6.0.0.786.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7821] command /c del "C:\WINDOWS\Fonts\'\Remograph Remo 3D v1.4.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4425] cmd /c del "C:\WINDOWS\Fonts\'\Remograph Remo 3D v1.4.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1070] command /c del "C:\WINDOWS\Fonts\'\3D PaintBrush v1.0.0.134.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8610] cmd /c del "C:\WINDOWS\Fonts\'\3D PaintBrush v1.0.0.134.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4979] command /c del "C:\WINDOWS\Fonts\'\MobiTNT VirtualCaller 2.00.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD13] cmd /c del "C:\WINDOWS\Fonts\'\MobiTNT VirtualCaller 2.00.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8892] command /c del "C:\WINDOWS\Fonts\'\GoodSync Pro 7.2.9.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2702] cmd /c del "C:\WINDOWS\Fonts\'\GoodSync Pro 7.2.9.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6668] command /c del "C:\WINDOWS\Fonts\'\WINCO Alc 2008 Strong 3.2.8.27733.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8670] cmd /c del "C:\WINDOWS\Fonts\'\WINCO Alc 2008 Strong 3.2.8.27733.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8159] cmd /c del "C:\WINDOWS\Fonts\'\ClickyMouse Professional 7.1.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4907] command /c del "C:\WINDOWS\Fonts\'\BusinessCards MX 3.92.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9266] cmd /c del "C:\WINDOWS\Fonts\'\BusinessCards MX 3.92.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9917] command /c del "C:\WINDOWS\Fonts\'\OJOsoft Total Video Converter 2.1.0.07.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2099] cmd /c del "C:\WINDOWS\Fonts\'\OJOsoft Total Video Converter 2.1.0.07.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6918] command /c del "C:\WINDOWS\Fonts\'\Jetico Personal Firewall 2.0.2.6.2296.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3066] cmd /c del "C:\WINDOWS\Fonts\'\Jetico Personal Firewall 2.0.2.6.2296.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4047] command /c del "C:\WINDOWS\Fonts\'\Transfer Your PC Deluxe 2.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7626] cmd /c del "C:\WINDOWS\Fonts\'\Transfer Your PC Deluxe 2.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6745] command /c del "C:\WINDOWS\Fonts\'\Personal Algebra Tutor 8.31.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3977] cmd /c del "C:\WINDOWS\Fonts\'\Personal Algebra Tutor 8.31.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5157] command /c del "C:\WINDOWS\Fonts\'\Mayoko 1.1.3 (Portable).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2737] cmd /c del "C:\WINDOWS\Fonts\'\Mayoko 1.1.3 (Portable).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7828] command /c del "C:\WINDOWS\Fonts\'\Picture Merge Genius 2.7.2 (Portable).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD406] cmd /c del "C:\WINDOWS\Fonts\'\Picture Merge Genius 2.7.2 (Portable).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2084] command /c del "C:\WINDOWS\Fonts\'\Acelogix Ace Optimizer Utilities 4.2.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4534] cmd /c del "C:\WINDOWS\Fonts\'\Acelogix Ace Optimizer Utilities 4.2.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6902] command /c del "C:\WINDOWS\Fonts\'\Windows Live Messenger 9 Build 14.0.39.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9957] cmd /c del "C:\WINDOWS\Fonts\'\Windows Live Messenger 9 Build 14.0.39.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB592] command /c del "C:\WINDOWS\Fonts\'\Acelogix System Tuneup 2.2.0.427.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6308] cmd /c del "C:\WINDOWS\Fonts\'\Acelogix System Tuneup 2.2.0.427.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3557] command /c del "C:\WINDOWS\Fonts\'\Advanced PC Tweaker 2008 4.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3129] cmd /c del "C:\WINDOWS\Fonts\'\Advanced PC Tweaker 2008 4.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3277] command /c del "C:\WINDOWS\Fonts\'\Audio Record Edit Toolbox v10.3.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1898] cmd /c del "C:\WINDOWS\Fonts\'\Audio Record Edit Toolbox v10.3.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6046] command /c del "C:\WINDOWS\Fonts\'\Advanced WindowsCare Professional 2.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9296] cmd /c del "C:\WINDOWS\Fonts\'\Advanced WindowsCare Professional 2.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6955] command /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Pro 8.0.015.000.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3784] cmd /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Pro 8.0.015.000.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9642] command /c del "C:\WINDOWS\Fonts\'\VueScan Pro 8.4.82.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1013] cmd /c del "C:\WINDOWS\Fonts\'\VueScan Pro 8.4.82.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1302] command /c del "C:\WINDOWS\Fonts\'\AoA DVD Ripper 5.19.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6842] cmd /c del "C:\WINDOWS\Fonts\'\AoA DVD Ripper 5.19.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8872] command /c del "C:\WINDOWS\Fonts\'\Business Card Designer Pro 5.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD69] cmd /c del "C:\WINDOWS\Fonts\'\Business Card Designer Pro 5.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3196] command /c del "C:\WINDOWS\Fonts\'\DeskSpace 1.5.4.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5405] cmd /c del "C:\WINDOWS\Fonts\'\DeskSpace 1.5.4.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7341] command /c del "C:\WINDOWS\Fonts\'\Desktop Maestro 3.0.0.830.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3723] cmd /c del "C:\WINDOWS\Fonts\'\Desktop Maestro 3.0.0.830.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1050] command /c del "C:\WINDOWS\Fonts\'\Drive Snapshot 1.39.0.13740.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1235] cmd /c del "C:\WINDOWS\Fonts\'\Drive Snapshot 1.39.0.13740.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2555] command /c del "C:\WINDOWS\Fonts\'\ViewonLog 1.1 Build 131.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8475] cmd /c del "C:\WINDOWS\Fonts\'\ViewonLog 1.1 Build 131.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5148] cmd /c del "C:\WINDOWS\Fonts\'\KRyLack Password Recovery 2.73.02.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3003] command /c del "C:\WINDOWS\Fonts\'\Amadis FLV to DVD Creator 3.7.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2844] cmd /c del "C:\WINDOWS\Fonts\'\Amadis FLV to DVD Creator 3.7.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7759] command /c del "C:\WINDOWS\Fonts\'\CDMenuPro Business Edition v6.24.00.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD55] cmd /c del "C:\WINDOWS\Fonts\'\CDMenuPro Business Edition v6.24.00.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5880] command /c del "C:\WINDOWS\Fonts\'\Atomic Alarm Clock v5.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6145] cmd /c del "C:\WINDOWS\Fonts\'\Atomic Alarm Clock v5.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5560] command /c del "C:\WINDOWS\Fonts\'\RegCure v1.5.0.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2539] cmd /c del "C:\WINDOWS\Fonts\'\RegCure v1.5.0.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6581] command /c del "C:\WINDOWS\Fonts\'\PPTminimizer 4.0 (Multilingual).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4639] cmd /c del "C:\WINDOWS\Fonts\'\PPTminimizer 4.0 (Multilingual).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4521] command /c del "C:\WINDOWS\Fonts\'\Wanted (2008).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9757] cmd /c del "C:\WINDOWS\Fonts\'\Adobe Photoshop CS3 Portable.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3421] command /c del "C:\WINDOWS\Fonts\'\Uniblue Registery Booster PowerSuite.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5180] cmd /c del "C:\WINDOWS\Fonts\'\Uniblue Registery Booster PowerSuite.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3947] command /c del "C:\WINDOWS\Fonts\'\Corel Draw X4 Graphic Suite.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8617] cmd /c del "C:\WINDOWS\Fonts\'\Corel Draw X4 Graphic Suite.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1854] command /c del "C:\WINDOWS\Fonts\'\DVDFab Platinum 4055.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD973] cmd /c del "C:\WINDOWS\Fonts\'\DVDFab Platinum 4055.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6885] command /c del "C:\WINDOWS\Fonts\'\ESET NOD32 Antivirus Home Edition 3.0..zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6252] cmd /c del "C:\WINDOWS\Fonts\'\ESET NOD32 Antivirus Home Edition 3.0..zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8820] command /c del "C:\WINDOWS\Fonts\'\OnlineEye Pro 2.1.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9154] cmd /c del "C:\WINDOWS\Fonts\'\TROJAN REMOVER v6.7.2 Build 2539.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2264] command /c del "C:\WINDOWS\Fonts\'\Core FTP Server v1.0.267.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1686] cmd /c del "C:\WINDOWS\Fonts\'\Core FTP Server v1.0.267.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9618] cmd /c del "C:\WINDOWS\Fonts\'\Portable ConvertXToDVD 3.2.0.50.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6060] command /c del "C:\WINDOWS\Fonts\'\Norton AntiBot 1.1.838.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3569] cmd /c del "C:\WINDOWS\Fonts\'\Norton AntiBot 1.1.838.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7878] command /c del "C:\WINDOWS\Fonts\'\BitDefender Antivirus 2009 Build 12.0.10 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD459] cmd /c del "C:\WINDOWS\Fonts\'\BitDefender Antivirus 2009 Build 12.0.10 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5792] command /c del "C:\WINDOWS\Fonts\'\Belltech Business Card Designer Pro 5.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3658] cmd /c del "C:\WINDOWS\Fonts\'\Belltech Business Card Designer Pro 5.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6241] command /c del "C:\WINDOWS\Fonts\'\Nokia PC Suite 6.86 Release 4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6977] cmd /c del "C:\WINDOWS\Fonts\'\Nokia PC Suite 6.86 Release 4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4752] command /c del "C:\WINDOWS\Fonts\'\Nero 8.3.2.1 Ultra LITE.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3459] cmd /c del "C:\WINDOWS\Fonts\'\Nero 8.3.2.1 Ultra LITE.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9526] command /c del "C:\WINDOWS\Fonts\'\Nero Vision Express 3.0.1.18.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6028] cmd /c del "C:\WINDOWS\Fonts\'\Nero Vision Express 3.0.1.18.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2504] command /c del "C:\WINDOWS\Fonts\'\Nero PhotoShow Deluxe 5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3771] cmd /c del "C:\WINDOWS\Fonts\'\Nero PhotoShow Deluxe 5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5858] command /c del "C:\WINDOWS\Fonts\'\Mp3 Rocket Pro 5.0.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1334] cmd /c del "C:\WINDOWS\Fonts\'\Mp3 Rocket Pro 5.0.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7736] command /c del "C:\WINDOWS\Fonts\'\MyLanViewer 1.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3873] cmd /c del "C:\WINDOWS\Fonts\'\MyLanViewer 1.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2101] command /c del "C:\WINDOWS\Fonts\'\Mozilla Firefox 3.0.2 RC2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2698] cmd /c del "C:\WINDOWS\Fonts\'\Mozilla Firefox 3.0.2 RC2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7676] command /c del "C:\WINDOWS\Fonts\'\PdfFactory Professional v3.36.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6351] cmd /c del "C:\WINDOWS\Fonts\'\PdfFactory Professional v3.36.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7048] command /c del "C:\WINDOWS\Fonts\'\Alcohol 120 1.9.7 Build 6221 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9143] command /c del "C:\WINDOWS\Fonts\'\SpeedUpMyPC 2009 v4.0.0.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3207] cmd /c del "C:\WINDOWS\Fonts\'\SpeedUpMyPC 2009 v4.0.0.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9660] command /c del "C:\WINDOWS\Fonts\'\Okoker Internet Accelerator 4.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2867] command /c del "C:\WINDOWS\Fonts\'\Unlocker 1.8.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6824] cmd /c del "C:\WINDOWS\Fonts\'\Unlocker 1.8.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7599] command /c del "C:\WINDOWS\Fonts\'\AnyDVD.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9686] command /c del "C:\WINDOWS\Fonts\'\Trillian Astra 4.0.0.79.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7148] cmd /c del "C:\WINDOWS\Fonts\'\Trillian Astra 4.0.0.79.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6730] command /c del "C:\WINDOWS\Fonts\'\River Past Video Cleaner Pro v7.6.9.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8788] cmd /c del "C:\WINDOWS\Fonts\'\River Past Video Cleaner Pro v7.6.9.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6622] command /c del "C:\WINDOWS\Fonts\'\Mama Mia (2008).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6622] cmd /c del "C:\WINDOWS\Fonts\'\Partition Magic 8.05.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2706] command /c del "C:\WINDOWS\Fonts\'\Driver Magician v.3.28.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4130] command /c del "C:\WINDOWS\Fonts\'\Winamp 5.541 Built 2165.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6072] cmd /c del "C:\WINDOWS\Fonts\'\Winamp 5.541 Built 2165.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7708] command /c del "C:\WINDOWS\Fonts\'\LimeWire PRO 4.18.6.1 Retail.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8353] cmd /c del "C:\WINDOWS\Fonts\'\LimeWire PRO 4.18.6.1 Retail.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1946] command /c del "C:\WINDOWS\Fonts\'\SpyBot Search and Destroy 1.6.0.30 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1315] cmd /c del "C:\WINDOWS\Fonts\'\SpyBot Search and Destroy 1.6.0.30 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5608] command /c del "C:\WINDOWS\Fonts\'\Portable Mayoko 1.1.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2447] cmd /c del "C:\WINDOWS\Fonts\'\Portable Mayoko 1.1.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6250] command /c del "C:\WINDOWS\Fonts\'\Corel Paint Shop Pro X 10.0.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9509] cmd /c del "C:\WINDOWS\Fonts\'\Corel Paint Shop Pro X 10.0.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9413] command /c del "C:\WINDOWS\Fonts\'\Opera 9.52 Build 10103 Beta.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6701] cmd /c del "C:\WINDOWS\Fonts\'\Enchanted Fairy Friends - Secret of the Fairy Queen.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8841] command /c del "C:\WINDOWS\Fonts\'\Adobe Flash Player 9.0.47.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5393] cmd /c del "C:\WINDOWS\Fonts\'\Adobe Flash Player 9.0.47.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8510] command /c del "C:\WINDOWS\Fonts\'\CorelDraw Suite X4 complete.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2507] cmd /c del "C:\WINDOWS\Fonts\'\CorelDraw Suite X4 complete.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2134] command /c del "C:\WINDOWS\Fonts\'\GameJackal Pro 3.1.0.4 Beta.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4360] cmd /c del "C:\WINDOWS\Fonts\'\GameJackal Pro 3.1.0.4 Beta.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3474] command /c del "C:\WINDOWS\Fonts\'\FruityLoops Studio Producer Edition XX.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9694] cmd /c del "C:\WINDOWS\Fonts\'\FruityLoops Studio Producer Edition XX.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6995] command /c del "C:\WINDOWS\Fonts\'\Portable System Mechanic Professional.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2538] cmd /c del "C:\WINDOWS\Fonts\'\Portable System Mechanic Professional.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9450] command /c del "C:\WINDOWS\Fonts\'\SUPERAntiSpyware Professional v4.20.10.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3404] cmd /c del "C:\WINDOWS\Fonts\'\SUPERAntiSpyware Professional v4.20.10.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2580] command /c del "C:\WINDOWS\Fonts\'\Super Jigsaw Safari v1.4.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8750] cmd /c del "C:\WINDOWS\Fonts\'\Super Jigsaw Safari v1.4.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7974] command /c del "C:\WINDOWS\Fonts\'\SiteDesigner Technologies 3D FTP v8.0..zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3780] cmd /c del "C:\WINDOWS\Fonts\'\SiteDesigner Technologies 3D FTP v8.0..zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6849] command /c del "C:\WINDOWS\Fonts\'\Registry Booster 2009 v2.1.0.0 WinALL.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1692] cmd /c del "C:\WINDOWS\Fonts\'\Registry Booster 2009 v2.1.0.0 WinALL.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1178] command /c del "C:\WINDOWS\Fonts\'\Mjksoft WinSuperKit v6.3.1 WinAll.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9771] cmd /c del "C:\WINDOWS\Fonts\'\Mjksoft WinSuperKit v6.3.1 WinAll.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9614] command /c del "C:\WINDOWS\Fonts\'\Elecard AVC Plugin v2.3.80625.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8889] cmd /c del "C:\WINDOWS\Fonts\'\Elecard AVC Plugin v2.3.80625.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5283] command /c del "C:\WINDOWS\Fonts\'\ActiveBarcode v5.5.6 Bilingual.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9753] cmd /c del "C:\WINDOWS\Fonts\'\ActiveBarcode v5.5.6 Bilingual.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2710] command /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Anti Spyware v7.0.483.000.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7552] cmd /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Anti Spyware v7.0.483.000.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8731] command /c del "C:\WINDOWS\Fonts\'\ZoneAlarm AntiVirus v7.0.483.000.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2845] cmd /c del "C:\WINDOWS\Fonts\'\ZoneAlarm AntiVirus v7.0.483.000.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3882] command /c del "C:\WINDOWS\Fonts\'\Zemana Antilogger 1.1.2.416.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6607] cmd /c del "C:\WINDOWS\Fonts\'\Zemana Antilogger 1.1.2.416.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3707] command /c del "C:\WINDOWS\Fonts\'\Proxy Switcher v3.18.0.4990.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7225] cmd /c del "C:\WINDOWS\Fonts\'\Proxy Switcher v3.18.0.4990.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2928] cmd /c del "C:\WINDOWS\Fonts\'\GreenBox Logo Maker v2.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1247] command /c del "C:\WINDOWS\Fonts\'\CorelDraw Graphics Suite 11.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3675] cmd /c del "C:\WINDOWS\Fonts\'\CorelDraw Graphics Suite 11.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1944] command /c del "C:\WINDOWS\Fonts\'\Game Maker Pro v7.0.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1953] cmd /c del "C:\WINDOWS\Fonts\'\Game Maker Pro v7.0.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1196] command /c del "C:\WINDOWS\Fonts\'\Avant Brower 11.6 Build 20.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2986] cmd /c del "C:\WINDOWS\Fonts\'\Avant Brower 11.6 Build 20.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6236] command /c del "C:\WINDOWS\Fonts\'\RealPlayer v 11.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4948] cmd /c del "C:\WINDOWS\Fonts\'\RealPlayer v 11.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7093] command /c del "C:\WINDOWS\Fonts\'\ConvertXtoDVD 2.1.19.243.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8622] cmd /c del "C:\WINDOWS\Fonts\'\ConvertXtoDVD 2.1.19.243.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3695] command /c del "C:\WINDOWS\Fonts\'\ConvertXtoDVD 2.2.1.253.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6869] cmd /c del "C:\WINDOWS\Fonts\'\ConvertXtoDVD 2.2.1.253.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7470] command /c del "C:\WINDOWS\Fonts\'\WinRar 3.70 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD411] cmd /c del "C:\WINDOWS\Fonts\'\WinRar 3.70 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1461] command /c del "C:\WINDOWS\Fonts\'\Satellite Antenna Alignment v.2.38.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5906] cmd /c del "C:\WINDOWS\Fonts\'\Satellite Antenna Alignment v.2.38.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1446] command /c del "C:\WINDOWS\Fonts\'\Nature Illusion Studio v2.60.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9928] cmd /c del "C:\WINDOWS\Fonts\'\Nature Illusion Studio v2.60.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4498] command /c del "C:\WINDOWS\Fonts\'\SpeedCommander 11.62 Build 5000.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2926] cmd /c del "C:\WINDOWS\Fonts\'\SpeedCommander 11.62 Build 5000.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6225] command /c del "C:\WINDOWS\Fonts\'\Arclab Thumb Studio v.1.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4162] cmd /c del "C:\WINDOWS\Fonts\'\Arclab Thumb Studio v.1.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1555] command /c del "C:\WINDOWS\Fonts\'\Hide IP NG 1.32.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4721] cmd /c del "C:\WINDOWS\Fonts\'\Hide IP NG 1.32.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB705] command /c del "C:\WINDOWS\Fonts\'\Flash Learning 02.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8662] cmd /c del "C:\WINDOWS\Fonts\'\Flash Learning 02.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1201] command /c del "C:\WINDOWS\Fonts\'\GetFLV Pro v6.0 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7780] cmd /c del "C:\WINDOWS\Fonts\'\GetFLV Pro v6.0 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3737] cmd /c del "C:\WINDOWS\Fonts\'\Jetico Personal Firewall v2.0.2.6.2296.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3] command /c del "C:\WINDOWS\Fonts\'\Personal Algebra Tutor v8.31.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2821] cmd /c del "C:\WINDOWS\Fonts\'\Personal Algebra Tutor v8.31.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8504] command /c del "C:\WINDOWS\Fonts\'\Portable Picture Merge Genius 2.7.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8862] cmd /c del "C:\WINDOWS\Fonts\'\Portable Picture Merge Genius 2.7.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5829] command /c del "C:\WINDOWS\Fonts\'\Screen Grab Pro Deluxe 1.2 Portable.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6690] cmd /c del "C:\WINDOWS\Fonts\'\Screen Grab Pro Deluxe 1.2 Portable.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB861] command /c del "C:\WINDOWS\Fonts\'\Sygate Personal Firewall 5.6.3408 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3623] cmd /c del "C:\WINDOWS\Fonts\'\Sygate Personal Firewall 5.6.3408 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1659] command /c del "C:\WINDOWS\Fonts\'\Bitdefender Total Security 2009.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5419] cmd /c del "C:\WINDOWS\Fonts\'\Bitdefender Total Security 2009.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9821] command /c del "C:\WINDOWS\Fonts\'\Xceed Ultimate Suite 2008 3.2.8373.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD733] cmd /c del "C:\WINDOWS\Fonts\'\Xceed Ultimate Suite 2008 3.2.8373.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1865] command /c del "C:\WINDOWS\Fonts\'\WordWeb Pro v5.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2367] cmd /c del "C:\WINDOWS\Fonts\'\WordWeb Pro v5.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9283] command /c del "C:\WINDOWS\Fonts\'\Music Label 2009 v15.0.1.2003.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2490] cmd /c del "C:\WINDOWS\Fonts\'\Music Label 2009 v15.0.1.2003.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB289] command /c del "C:\WINDOWS\Fonts\'\Daemon Tools Pro Advanced 4.10.0218.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4870] cmd /c del "C:\WINDOWS\Fonts\'\Daemon Tools Pro Advanced 4.10.0218.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8957] command /c del "C:\WINDOWS\Fonts\'\Eset Nod32 3.0.672.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5816] cmd /c del "C:\WINDOWS\Fonts\'\Eset Nod32 3.0.672.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7016] command /c del "C:\WINDOWS\Fonts\'\Lavasoft Adaware Pro 2007 7.0.2.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1310] cmd /c del "C:\WINDOWS\Fonts\'\Lavasoft Adaware Pro 2007 7.0.2.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1739] command /c del "C:\WINDOWS\Fonts\'\Banner Maker Pro 7.0.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4911] cmd /c del "C:\WINDOWS\Fonts\'\Banner Maker Pro 7.0.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3121] command /c del "C:\WINDOWS\Fonts\'\Lavasoft Ad-Aware 2007 Pro 7.1.0.8 (Portable).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9340] cmd /c del "C:\WINDOWS\Fonts\'\Lavasoft Ad-Aware 2007 Pro 7.1.0.8 (Portable).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4994] command /c del "C:\WINDOWS\Fonts\'\System Mechanic V7.1.10.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9794] cmd /c del "C:\WINDOWS\Fonts\'\System Mechanic V7.1.10.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6193] command /c del "C:\WINDOWS\Fonts\'\Cakewalk Guitar Tracks Pro v3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6456] cmd /c del "C:\WINDOWS\Fonts\'\Cakewalk Guitar Tracks Pro v3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB100] command /c del "C:\WINDOWS\Fonts\'\Super Converter 2007.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6487] cmd /c del "C:\WINDOWS\Fonts\'\Super Converter 2007.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2335] command /c del "C:\WINDOWS\Fonts\'\TGTSoft StyleBuilder v2.021000.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2188] cmd /c del "C:\WINDOWS\Fonts\'\TGTSoft StyleBuilder v2.021000.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB398] command /c del "C:\WINDOWS\Fonts\'\Combat Wings Battle of the Pacific.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1085] cmd /c del "C:\WINDOWS\Fonts\'\Combat Wings Battle of the Pacific.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB755] command /c del "C:\WINDOWS\Fonts\'\Deadliest Catch Alaskan Storm.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3177] cmd /c del "C:\WINDOWS\Fonts\'\Deadliest Catch Alaskan Storm.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3855] command /c del "C:\WINDOWS\Fonts\'\Breath of Fire.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6896] cmd /c del "C:\WINDOWS\Fonts\'\Breath of Fire.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB855] command /c del "C:\WINDOWS\Fonts\'\Laptop Battery Doubler 1.2..zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3290] cmd /c del "C:\WINDOWS\Fonts\'\Laptop Battery Doubler 1.2..zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3652] command /c del "C:\WINDOWS\Fonts\'\Sharks Terrors of the Deep Screensaver.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2834] cmd /c del "C:\WINDOWS\Fonts\'\Sharks Terrors of the Deep Screensaver.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB804] command /c del "C:\WINDOWS\Fonts\'\Airscape Transparency.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8718] cmd /c del "C:\WINDOWS\Fonts\'\Airscape Transparency.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1291] command /c del "C:\WINDOWS\Fonts\'\Cleaner (2008).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7658] cmd /c del "C:\WINDOWS\Fonts\'\Cleaner (2008).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2726] command /c del "C:\WINDOWS\Fonts\'\Uniblue Spy Eraser 2.0.1.1530.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7197] cmd /c del "C:\WINDOWS\Fonts\'\Uniblue Spy Eraser 2.0.1.1530.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1] command /c del "C:\WINDOWS\Fonts\'\1Click DVD Copy Pro 3.2.1.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6545] cmd /c del "C:\WINDOWS\Fonts\'\1Click DVD Copy Pro 3.2.1.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9739] command /c del "C:\WINDOWS\Fonts\'\Power Retouche Pro 8.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9556] cmd /c del "C:\WINDOWS\Fonts\'\Power Retouche Pro 8.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2112] command /c del "C:\WINDOWS\Fonts\'\Smart DVD-CD Burner 3.0.104.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1755] cmd /c del "C:\WINDOWS\Fonts\'\Smart DVD-CD Burner 3.0.104.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4032] command /c del "C:\WINDOWS\Fonts\'\USB Webserver 6 (Portable).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD320] cmd /c del "C:\WINDOWS\Fonts\'\USB Webserver 6 (Portable).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8067] command /c del "C:\WINDOWS\Fonts\'\DVDFab Platinum 5.0.8.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9633] cmd /c del "C:\WINDOWS\Fonts\'\DVDFab Platinum 5.0.8.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1341] command /c del "C:\WINDOWS\Fonts\'\MindSoft Utilities XP 9.80 2008.20.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2207] cmd /c del "C:\WINDOWS\Fonts\'\MindSoft Utilities XP 9.80 2008.20.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8561] command /c del "C:\WINDOWS\Fonts\'\Farsight Calculator 2.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2077] cmd /c del "C:\WINDOWS\Fonts\'\Farsight Calculator 2.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2022] command /c del "C:\WINDOWS\Fonts\'\DownloadStudio 5.0.3.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6358] cmd /c del "C:\WINDOWS\Fonts\'\DownloadStudio 5.0.3.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9568] command /c del "C:\WINDOWS\Fonts\'\Ashampoo WinOptimizer 5.05.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4111] cmd /c del "C:\WINDOWS\Fonts\'\Ashampoo WinOptimizer 5.05.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5483] command /c del "C:\WINDOWS\Fonts\'\Ashampoo Cover Studio 1.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8607] cmd /c del "C:\WINDOWS\Fonts\'\Ashampoo Cover Studio 1.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3109] command /c del "C:\WINDOWS\Fonts\'\Ashampoo Burning Studio 8.03.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5736] cmd /c del "C:\WINDOWS\Fonts\'\Ashampoo Burning Studio 8.03.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9083] cmd /c del "C:\WINDOWS\Fonts\'\Portable System Mechanic v8.0.0.17.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8175] command /c del "C:\WINDOWS\Fonts\'\Deamon Tools 4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB793] command /c del "C:\WINDOWS\Fonts\'\Mix Meister Fusion 7.3.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9572] cmd /c del "C:\WINDOWS\Fonts\'\Mix Meister Fusion 7.3.2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1282] command /c del "C:\WINDOWS\Fonts\'\3GP Video Convertor 4.22.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD225] cmd /c del "C:\WINDOWS\Fonts
End of file - 269382 bytes
sexy_ladii05
2008-08-31, 04:09
O4 - HKCU\..\RunOnce: [SpybotDeletingB3694] command /c del "C:\WINDOWS\Fonts\'\FarCry iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1107] cmd /c del "C:\WINDOWS\Fonts\'\FarCry iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7983] command /c del "C:\WINDOWS\Fonts\'\Test Drive Unlimited iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1882] cmd /c del "C:\WINDOWS\Fonts\'\Test Drive Unlimited iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5290] command /c del "C:\WINDOWS\Fonts\'\Gothic 3 iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD282] cmd /c del "C:\WINDOWS\Fonts\'\Deamon Tools 4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7035] command /c del "C:\WINDOWS\Fonts\'\PCMark Professional 5.1.0.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8339] cmd /c del "C:\WINDOWS\Fonts\'\NFS Most Wanted RiP.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8741] command /c del "C:\WINDOWS\Fonts\'\Audiosurf iSO plus Updates.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1850] cmd /c del "C:\WINDOWS\Fonts\'\Audiosurf iSO plus Updates.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4268] cmd /c del "C:\WINDOWS\Fonts\'\Asterix at the Olympic Games iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6442] command /c del "C:\WINDOWS\Fonts\'\Viva Pinata-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7812] cmd /c del "C:\WINDOWS\Fonts\'\Viva Pinata-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5173] command /c del "C:\WINDOWS\Fonts\'\GTR Evolution-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3687] cmd /c del "C:\WINDOWS\Fonts\'\GTR Evolution-RELOADED iSO.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5066] command /c del "C:\WINDOWS\Fonts\'\Monopoly Tycoon.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1708] cmd /c del "C:\WINDOWS\Fonts\'\Monopoly Tycoon.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB554] command /c del "C:\WINDOWS\Fonts\'\Risk II.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2372] cmd /c del "C:\WINDOWS\Fonts\'\Risk II.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5566] command /c del "C:\WINDOWS\Fonts\'\Bus Simulator 2008.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3498] cmd /c del "C:\WINDOWS\Fonts\'\Bus Simulator 2008.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8360] command /c del "C:\WINDOWS\Fonts\'\S.T.A.L.K.E.R. Clear Sky 2008 RU.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8939] cmd /c del "C:\WINDOWS\Fonts\'\S.T.A.L.K.E.R. Clear Sky 2008 RU.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB339] command /c del "C:\WINDOWS\Fonts\'\McAfee VirusScan Enterprise v9.0i.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3925] cmd /c del "C:\WINDOWS\Fonts\'\McAfee VirusScan Enterprise v9.0i.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD106] cmd /c del "C:\WINDOWS\Fonts\'\Eset Nod32 3.0.566.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6058] command /c del "C:\WINDOWS\Fonts\'\Wise RegistryCleaner 3.7.128.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1005] cmd /c del "C:\WINDOWS\Fonts\'\Wise RegistryCleaner 3.7.128.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1081] command /c del "C:\WINDOWS\Fonts\'\Quick Time Player Pro 7.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8486] cmd /c del "C:\WINDOWS\Fonts\'\Quick Time Player Pro 7.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5444] cmd /c del "C:\WINDOWS\Fonts\'\Tube Hunter Ultra v2.3.2756.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5981] cmd /c del "C:\WINDOWS\Fonts\'\FlashGet 1.9.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5371] command /c del "C:\WINDOWS\Fonts\'\RegsitryEasy4.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4995] cmd /c del "C:\WINDOWS\Fonts\'\RegsitryEasy4.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3164] command /c del "C:\WINDOWS\Fonts\'\Ninja Reflex.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7598] cmd /c del "C:\WINDOWS\Fonts\'\Ninja Reflex.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7433] command /c del "C:\WINDOWS\Fonts\'\Brain Trainer ViTALiTY.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1035] cmd /c del "C:\WINDOWS\Fonts\'\Brain Trainer ViTALiTY.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2619] command /c del "C:\WINDOWS\Fonts\'\Keyboard Music.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6292] cmd /c del "C:\WINDOWS\Fonts\'\Keyboard Music.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6439] command /c del "C:\WINDOWS\Fonts\'\Flobo Hard Disk Repair.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2376] cmd /c del "C:\WINDOWS\Fonts\'\Flobo Hard Disk Repair.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB468] command /c del "C:\WINDOWS\Fonts\'\Okoker Audio Factory.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD611] cmd /c del "C:\WINDOWS\Fonts\'\Okoker Audio Factory.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6899] cmd /c del "C:\WINDOWS\Fonts\'\Iphone Pc Suite.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9769] command /c del "C:\WINDOWS\Fonts\'\Download Accelerator Plus Premium 8.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6013] cmd /c del "C:\WINDOWS\Fonts\'\Download Accelerator Plus Premium 8.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB412] command /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Security Suite 8.0.015.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9605] cmd /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Security Suite 8.0.015.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4591] command /c del "C:\WINDOWS\Fonts\'\Amadis FLV to DVD Creator 1.1.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4959] cmd /c del "C:\WINDOWS\Fonts\'\Amadis FLV to DVD Creator 1.1.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2821] command /c del "C:\WINDOWS\Fonts\'\Duplicate File Detector 4.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2176] cmd /c del "C:\WINDOWS\Fonts\'\Duplicate File Detector 4.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8393] command /c del "C:\WINDOWS\Fonts\'\SUPERAntiSpyware Pro 4.20.1046.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7801] cmd /c del "C:\WINDOWS\Fonts\'\SUPERAntiSpyware Pro 4.20.1046.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5524] command /c del "C:\WINDOWS\Fonts\'\ClickyMouse Professional 7.1.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6393] cmd /c del "C:\WINDOWS\Fonts\'\Portable Pictomio v1.0.15.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9525] command /c del "C:\WINDOWS\Fonts\'\Punch! ViaCAD 2D3D 6.0.0.786.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5098] cmd /c del "C:\WINDOWS\Fonts\'\Punch! ViaCAD 2D3D 6.0.0.786.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7821] command /c del "C:\WINDOWS\Fonts\'\Remograph Remo 3D v1.4.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4425] cmd /c del "C:\WINDOWS\Fonts\'\Remograph Remo 3D v1.4.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1070] command /c del "C:\WINDOWS\Fonts\'\3D PaintBrush v1.0.0.134.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8610] cmd /c del "C:\WINDOWS\Fonts\'\3D PaintBrush v1.0.0.134.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4979] command /c del "C:\WINDOWS\Fonts\'\MobiTNT VirtualCaller 2.00.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD13] cmd /c del "C:\WINDOWS\Fonts\'\MobiTNT VirtualCaller 2.00.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8892] command /c del "C:\WINDOWS\Fonts\'\GoodSync Pro 7.2.9.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2702] cmd /c del "C:\WINDOWS\Fonts\'\GoodSync Pro 7.2.9.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6668] command /c del "C:\WINDOWS\Fonts\'\WINCO Alc 2008 Strong 3.2.8.27733.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8670] cmd /c del "C:\WINDOWS\Fonts\'\WINCO Alc 2008 Strong 3.2.8.27733.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8159] cmd /c del "C:\WINDOWS\Fonts\'\ClickyMouse Professional 7.1.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4907] command /c del "C:\WINDOWS\Fonts\'\BusinessCards MX 3.92.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9266] cmd /c del "C:\WINDOWS\Fonts\'\BusinessCards MX 3.92.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9917] command /c del "C:\WINDOWS\Fonts\'\OJOsoft Total Video Converter 2.1.0.07.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2099] cmd /c del "C:\WINDOWS\Fonts\'\OJOsoft Total Video Converter 2.1.0.07.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6918] command /c del "C:\WINDOWS\Fonts\'\Jetico Personal Firewall 2.0.2.6.2296.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3066] cmd /c del "C:\WINDOWS\Fonts\'\Jetico Personal Firewall 2.0.2.6.2296.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4047] command /c del "C:\WINDOWS\Fonts\'\Transfer Your PC Deluxe 2.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7626] cmd /c del "C:\WINDOWS\Fonts\'\Transfer Your PC Deluxe 2.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6745] command /c del "C:\WINDOWS\Fonts\'\Personal Algebra Tutor 8.31.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3977] cmd /c del "C:\WINDOWS\Fonts\'\Personal Algebra Tutor 8.31.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5157] command /c del "C:\WINDOWS\Fonts\'\Mayoko 1.1.3 (Portable).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2737] cmd /c del "C:\WINDOWS\Fonts\'\Mayoko 1.1.3 (Portable).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7828] command /c del "C:\WINDOWS\Fonts\'\Picture Merge Genius 2.7.2 (Portable).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD406] cmd /c del "C:\WINDOWS\Fonts\'\Picture Merge Genius 2.7.2 (Portable).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2084] command /c del "C:\WINDOWS\Fonts\'\Acelogix Ace Optimizer Utilities 4.2.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4534] cmd /c del "C:\WINDOWS\Fonts\'\Acelogix Ace Optimizer Utilities 4.2.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6902] command /c del "C:\WINDOWS\Fonts\'\Windows Live Messenger 9 Build 14.0.39.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9957] cmd /c del "C:\WINDOWS\Fonts\'\Windows Live Messenger 9 Build 14.0.39.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB592] command /c del "C:\WINDOWS\Fonts\'\Acelogix System Tuneup 2.2.0.427.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6308] cmd /c del "C:\WINDOWS\Fonts\'\Acelogix System Tuneup 2.2.0.427.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3557] command /c del "C:\WINDOWS\Fonts\'\Advanced PC Tweaker 2008 4.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3129] cmd /c del "C:\WINDOWS\Fonts\'\Advanced PC Tweaker 2008 4.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3277] command /c del "C:\WINDOWS\Fonts\'\Audio Record Edit Toolbox v10.3.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1898] cmd /c del "C:\WINDOWS\Fonts\'\Audio Record Edit Toolbox v10.3.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6046] command /c del "C:\WINDOWS\Fonts\'\Advanced WindowsCare Professional 2.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9296] cmd /c del "C:\WINDOWS\Fonts\'\Advanced WindowsCare Professional 2.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6955] command /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Pro 8.0.015.000.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3784] cmd /c del "C:\WINDOWS\Fonts\'\ZoneAlarm Pro 8.0.015.000.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9642] command /c del "C:\WINDOWS\Fonts\'\VueScan Pro 8.4.82.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1013] cmd /c del "C:\WINDOWS\Fonts\'\VueScan Pro 8.4.82.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1302] command /c del "C:\WINDOWS\Fonts\'\AoA DVD Ripper 5.19.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6842] cmd /c del "C:\WINDOWS\Fonts\'\AoA DVD Ripper 5.19.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8872] command /c del "C:\WINDOWS\Fonts\'\Business Card Designer Pro 5.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD69] cmd /c del "C:\WINDOWS\Fonts\'\Business Card Designer Pro 5.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3196] command /c del "C:\WINDOWS\Fonts\'\DeskSpace 1.5.4.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5405] cmd /c del "C:\WINDOWS\Fonts\'\DeskSpace 1.5.4.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7341] command /c del "C:\WINDOWS\Fonts\'\Desktop Maestro 3.0.0.830.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3723] cmd /c del "C:\WINDOWS\Fonts\'\Desktop Maestro 3.0.0.830.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1050] command /c del "C:\WINDOWS\Fonts\'\Drive Snapshot 1.39.0.13740.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1235] cmd /c del "C:\WINDOWS\Fonts\'\Drive Snapshot 1.39.0.13740.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2555] command /c del "C:\WINDOWS\Fonts\'\ViewonLog 1.1 Build 131.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8475] cmd /c del "C:\WINDOWS\Fonts\'\ViewonLog 1.1 Build 131.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5148] cmd /c del "C:\WINDOWS\Fonts\'\KRyLack Password Recovery 2.73.02.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3003] command /c del "C:\WINDOWS\Fonts\'\Amadis FLV to DVD Creator 3.7.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2844] cmd /c del "C:\WINDOWS\Fonts\'\Amadis FLV to DVD Creator 3.7.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7759] command /c del "C:\WINDOWS\Fonts\'\CDMenuPro Business Edition v6.24.00.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD55] cmd /c del "C:\WINDOWS\Fonts\'\CDMenuPro Business Edition v6.24.00.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5880] command /c del "C:\WINDOWS\Fonts\'\Atomic Alarm Clock v5.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6145] cmd /c del "C:\WINDOWS\Fonts\'\Atomic Alarm Clock v5.8.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5560] command /c del "C:\WINDOWS\Fonts\'\RegCure v1.5.0.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2539] cmd /c del "C:\WINDOWS\Fonts\'\RegCure v1.5.0.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6581] command /c del "C:\WINDOWS\Fonts\'\PPTminimizer 4.0 (Multilingual).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4639] cmd /c del "C:\WINDOWS\Fonts\'\PPTminimizer 4.0 (Multilingual).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4521] command /c del "C:\WINDOWS\Fonts\'\Wanted (2008).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9757] cmd /c del "C:\WINDOWS\Fonts\'\Adobe Photoshop CS3 Portable.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3421] command /c del "C:\WINDOWS\Fonts\'\Uniblue Registery Booster PowerSuite.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5180] cmd /c del "C:\WINDOWS\Fonts\'\Uniblue Registery Booster PowerSuite.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3947] command /c del "C:\WINDOWS\Fonts\'\Corel Draw X4 Graphic Suite.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8617] cmd /c del "C:\WINDOWS\Fonts\'\Corel Draw X4 Graphic Suite.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1854] command /c del "C:\WINDOWS\Fonts\'\DVDFab Platinum 4055.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD973] cmd /c del "C:\WINDOWS\Fonts\'\DVDFab Platinum 4055.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6885] command /c del "C:\WINDOWS\Fonts\'\ESET NOD32 Antivirus Home Edition 3.0..zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6252] cmd /c del "C:\WINDOWS\Fonts\'\ESET NOD32 Antivirus Home Edition 3.0..zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8820] command /c del "C:\WINDOWS\Fonts\'\OnlineEye Pro 2.1.5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9154] cmd /c del "C:\WINDOWS\Fonts\'\TROJAN REMOVER v6.7.2 Build 2539.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2264] command /c del "C:\WINDOWS\Fonts\'\Core FTP Server v1.0.267.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1686] cmd /c del "C:\WINDOWS\Fonts\'\Core FTP Server v1.0.267.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9618] cmd /c del "C:\WINDOWS\Fonts\'\Portable ConvertXToDVD 3.2.0.50.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6060] command /c del "C:\WINDOWS\Fonts\'\Norton AntiBot 1.1.838.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3569] cmd /c del "C:\WINDOWS\Fonts\'\Norton AntiBot 1.1.838.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7878] command /c del "C:\WINDOWS\Fonts\'\BitDefender Antivirus 2009 Build 12.0.10 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD459] cmd /c del "C:\WINDOWS\Fonts\'\BitDefender Antivirus 2009 Build 12.0.10 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5792] command /c del "C:\WINDOWS\Fonts\'\Belltech Business Card Designer Pro 5.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3658] cmd /c del "C:\WINDOWS\Fonts\'\Belltech Business Card Designer Pro 5.1.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6241] command /c del "C:\WINDOWS\Fonts\'\Nokia PC Suite 6.86 Release 4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6977] cmd /c del "C:\WINDOWS\Fonts\'\Nokia PC Suite 6.86 Release 4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4752] command /c del "C:\WINDOWS\Fonts\'\Nero 8.3.2.1 Ultra LITE.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3459] cmd /c del "C:\WINDOWS\Fonts\'\Nero 8.3.2.1 Ultra LITE.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9526] command /c del "C:\WINDOWS\Fonts\'\Nero Vision Express 3.0.1.18.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6028] cmd /c del "C:\WINDOWS\Fonts\'\Nero Vision Express 3.0.1.18.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2504] command /c del "C:\WINDOWS\Fonts\'\Nero PhotoShow Deluxe 5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3771] cmd /c del "C:\WINDOWS\Fonts\'\Nero PhotoShow Deluxe 5.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5858] command /c del "C:\WINDOWS\Fonts\'\Mp3 Rocket Pro 5.0.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1334] cmd /c del "C:\WINDOWS\Fonts\'\Mp3 Rocket Pro 5.0.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7736] command /c del "C:\WINDOWS\Fonts\'\MyLanViewer 1.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3873] cmd /c del "C:\WINDOWS\Fonts\'\MyLanViewer 1.4.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2101] command /c del "C:\WINDOWS\Fonts\'\Mozilla Firefox 3.0.2 RC2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2698] cmd /c del "C:\WINDOWS\Fonts\'\Mozilla Firefox 3.0.2 RC2.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7676] command /c del "C:\WINDOWS\Fonts\'\PdfFactory Professional v3.36.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6351] cmd /c del "C:\WINDOWS\Fonts\'\PdfFactory Professional v3.36.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7048] command /c del "C:\WINDOWS\Fonts\'\Alcohol 120 1.9.7 Build 6221 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9143] command /c del "C:\WINDOWS\Fonts\'\SpeedUpMyPC 2009 v4.0.0.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3207] cmd /c del "C:\WINDOWS\Fonts\'\SpeedUpMyPC 2009 v4.0.0.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9660] command /c del "C:\WINDOWS\Fonts\'\Okoker Internet Accelerator 4.6.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2867] command /c del "C:\WINDOWS\Fonts\'\Unlocker 1.8.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6824] cmd /c del "C:\WINDOWS\Fonts\'\Unlocker 1.8.7.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7599] command /c del "C:\WINDOWS\Fonts\'\AnyDVD.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9686] command /c del "C:\WINDOWS\Fonts\'\Trillian Astra 4.0.0.79.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7148] cmd /c del "C:\WINDOWS\Fonts\'\Trillian Astra 4.0.0.79.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6730] command /c del "C:\WINDOWS\Fonts\'\River Past Video Cleaner Pro v7.6.9.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8788] cmd /c del "C:\WINDOWS\Fonts\'\River Past Video Cleaner Pro v7.6.9.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6622] command /c del "C:\WINDOWS\Fonts\'\Mama Mia (2008).zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6622] cmd /c del "C:\WINDOWS\Fonts\'\Partition Magic 8.05.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2706] command /c del "C:\WINDOWS\Fonts\'\Driver Magician v.3.28.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4130] command /c del "C:\WINDOWS\Fonts\'\Winamp 5.541 Built 2165.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6072] cmd /c del "C:\WINDOWS\Fonts\'\Winamp 5.541 Built 2165.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7708] command /c del "C:\WINDOWS\Fonts\'\LimeWire PRO 4.18.6.1 Retail.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8353] cmd /c del "C:\WINDOWS\Fonts\'\LimeWire PRO 4.18.6.1 Retail.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1946] command /c del "C:\WINDOWS\Fonts\'\SpyBot Search and Destroy 1.6.0.30 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1315] cmd /c del "C:\WINDOWS\Fonts\'\SpyBot Search and Destroy 1.6.0.30 Final.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5608] command /c del "C:\WINDOWS\Fonts\'\Portable Mayoko 1.1.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2447] cmd /c del "C:\WINDOWS\Fonts\'\Portable Mayoko 1.1.3.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6250] command /c del "C:\WINDOWS\Fonts\'\Corel Paint Shop Pro X 10.0.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9509] cmd /c del "C:\WINDOWS\Fonts\'\Corel Paint Shop Pro X 10.0.0.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9413] command /c del "C:\WINDOWS\Fonts\'\Opera 9.52 Build 10103 Beta.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6701] cmd /c del "C:\WINDOWS\Fonts\'\Enchanted Fairy Friends - Secret of the Fairy Queen.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8841] command /c del "C:\WINDOWS\Fonts\'\Adobe Flash Player 9.0.47.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5393] cmd /c del "C:\WINDOWS\Fonts\'\Adobe Flash Player 9.0.47.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8510] command /c del "C:\WINDOWS\Fonts\'\CorelDraw Suite X4 complete.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2507] cmd /c del "C:\WINDOWS\Fonts\'\CorelDraw Suite X4 complete.zip"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2134] command /c del "C:\WINDOWS
sexy_ladii05
2008-08-31, 04:11
all done the last post is double posted dont mind it and now i got this fake desktop screen please help sorry for the lateness =]
sexy_ladii05
2008-08-31, 04:23
my computer getting worst please help please
OK....
What are you guys doing over there??
Now you have password stealing trojans bundled with a worm that is gunna take over the hard drive & fill it up. :eek:
You better not be downloading cracks & keygens.... that is the only place I see where this junk comes from.
That log is HUGE!! :lip:
Can you zip it and attach it to your next reply please.
Gimme a few min to do next fix..
Don't reboot yet cus spybot has a billion files to nuke & its prolly gunna crash trying.
Hang on a few ok?
sexy_ladii05
2008-08-31, 04:27
agh i already roobet omg no i havent download keygen i been using limewire buti thought giving me promblems so i detle it omg i dont want nothing happen on my computer my college exams on here agh please help how do i zip it??
Well somebody downloaded/ran a keygen or crack.
Limewire has to be one of the most dangerous p2p programs out there.
Almost everything on their networks is infected with some sorta junk.
Ok...
Since you rebooted I need you to make a new Hijackthis log.
If it is huge like the other one please do this:
Right click the new Hijackthis log you made> send to> "compressed (zipped) folder"
Attach the file called Hijackthis.zip.
Check this too please.
Open Spybot
Click "recovery"
If there is a TON of junk there --- right click in list window> select all> delete all selected.
I'll let ya know what next when I see the hijackthis log.
Thanks :)
You said you uninstalled Limewire.
You have any other p2p programs installed?
If so -- please uninstall them.
Right now you are spreading that nasty worm to other p2p users.
See this info page for clarification:
http://forums.spybot.info/showpost.php?p=218503&postcount=4
If they will not uninstall -- let me know & I'll help you remove it.
Thanks :)
sexy_ladii05
2008-08-31, 05:28
i dont know if i did it right but here it is =]
sexy_ladii05
2008-08-31, 05:29
and i already detle limewire is it still on my computer??
and i already detle limewire is it still on my computer??
I dunno yet. If it is we'll remove it.
I shall see it in next log.
We are getting to the point where things are getting difficult.
If you don't watch what the heck you guys are doing over there --- you will end up having to format!
Very often these keygens and cracks come with file infecting viruses which basically means a hosed system. :spider:
Right now you have no antivirus so you are at high risk.
And if you guys have a network these infections could very well be on the other systems as well meaning entire network may be infected.
These things are not funny.
You have worms that are trying to steal your passwords, your system could very well be being used as a spambot sending email spam to everyone on the planet (which also means your ISP may stop your internet services for spamming)
Your system could also be being used to attack other machines. (again if ISP sees this they can cut your services)
I have attached a file called fix.zip
Please download this & save it to your desktop.
Right click it> extract all> follow wizard to extract files.
Open Fix folder and double click "fix.reg"
Answer yes when it asks if you want to add contents to registry.
Should get success message.
Delete fix folder when done.
Next download new copy of ComboFix from here:
http://subs.geekstogo.com/ComboFix.exe
Save it to desktop & let it overwrite old one.
Double click it and let it run.
Follow instructions given.
Do not click inside combofix window or app will freeze.
Post the new ComboFix.txt along with a new Hijackthis log.
Then stick around cus I will have further instructions.
Thanks
sexy_ladii05
2008-08-31, 06:07
I dont see no attach file =[ im sorry if this getting diffucult i didnt mean for this to happen
Sorry -- I forgot to attach it :|
Try now please.
sexy_ladii05
2008-08-31, 17:00
ComboFix 08-08-30.03 - kkooo 2008-08-29 21:45:07.5 - FAT32x86
Running from: C:\Documents and Settings\kkooo\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\kkooo\Application Data\macromedia\Flash Player\#SharedObjects\JDU9UDDQ\static.youku.com
C:\Documents and Settings\kkooo\Application Data\macromedia\Flash Player\#SharedObjects\JDU9UDDQ\static.youku.com\v1.0.0318\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\kkooo\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com
C:\Documents and Settings\kkooo\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com\settings.sol
C:\Documents and Settings\kkooo\Cookies\kkooo@aniscartujo[2].txt
C:\Documents and Settings\kkooo\Start Menu\Programs\Startup\Deewoo.lnk
C:\Documents and Settings\kkooo\Start Menu\Programs\Startup\DW_Start.lnk
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\BM670e68bf.txt
C:\WINDOWS\faceback.exe
C:\WINDOWS\Fonts\Setup.exe
C:\WINDOWS\system32\acxkhylp.exe
C:\WINDOWS\system32\blphcrpdj0er4j.scr
C:\WINDOWS\system32\dwwnw64r.exe
C:\WINDOWS\system32\hbxcra.dll
C:\WINDOWS\system32\liurgvwc.dll
C:\WINDOWS\system32\lphcrpdj0er4j.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mjbnsxkj.exe
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\onkjkpqu.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\phcrpdj0er4j.bmp
C:\WINDOWS\system32\qoMfedCu.dll
C:\WINDOWS\system32\rnypfpxd.dll
C:\WINDOWS\system32\rqRHyxyY.dll
C:\WINDOWS\system32\swmwrt.dll
C:\WINDOWS\system32\tsYaHRqr.ini
C:\WINDOWS\system32\tsYaHRqr.ini2
C:\WINDOWS\system32\uqpkjkno.ini
C:\WINDOWS\system32\winpfz33.sys
C:\WINDOWS\system32\yjrcjmer.dll
C:\WINDOWS\system32\zxdnt3d.cfg
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMDSERVICE
-------\Legacy_NETWORK_MONITOR
-------\Legacy_TNIDRIVER
-------\Service_TnIDriver
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-30 )))))))))))))))))))))))))))))))
.
2008-08-29 09:56 . 2008-08-29 09:56 <DIR> d-------- C:\WINDOWS\system32\unknown
2008-08-29 06:21 . 2008-08-29 06:21 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-08-29 02:05 . 2008-08-29 02:05 <DIR> d--hs---- C:\WINDOWS\U2FudGE
2008-08-29 02:05 . 2008-08-29 02:05 548,928 --a------ C:\WINDOWS\system32\ncntqtdl.exe
2008-08-29 02:05 . 2008-08-29 02:05 153,444 --a------ C:\WINDOWS\system32\g59.exe
2008-08-29 02:04 . 2008-08-29 02:04 <DIR> d-------- C:\WINDOWS\system32\wTR02
2008-08-29 02:04 . 2008-08-29 02:04 <DIR> d-------- C:\WINDOWS\system32\towl
2008-08-29 02:04 . 2008-08-29 02:04 <DIR> d-------- C:\WINDOWS\system32\tec
2008-08-29 02:04 . 2008-08-29 02:04 <DIR> d-------- C:\WINDOWS\system32\dbl
2008-08-29 02:04 . 2008-08-29 02:04 <DIR> d-------- C:\WINDOWS\system32\bdir
2008-08-29 02:04 . 2008-08-29 02:04 <DIR> d-------- C:\Temp\dax41
2008-08-29 02:04 . 2008-08-29 02:04 <DIR> d-------- C:\Temp
2008-08-29 02:01 . 2008-08-29 02:01 <DIR> d--hs---- C:\FOUND.000
2008-08-28 21:49 . 2008-08-28 21:49 <DIR> d-------- C:\Documents and Settings\kkooo\Application Data\LimeWire
2008-08-28 12:47 . 2008-08-28 12:47 <DIR> d-------- C:\Program Files\AIM Search
2008-08-28 12:46 . 2008-08-28 12:46 <DIR> d-------- C:\Program Files\Viewpoint
2008-08-28 05:09 . 2008-08-28 05:09 51,436 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-08-28 03:32 . 2008-08-28 03:32 <DIR> d-------- C:\Program Files\Safari
2008-08-28 03:23 . 2008-08-28 03:24 <DIR> d-------- C:\Program Files\QuickTime
2008-08-28 03:20 . 2008-08-28 03:20 <DIR> d-------- C:\Program Files\Apple Software Update
2008-08-27 08:26 . 2008-08-28 08:27 758 ---hs---- C:\WINDOWS\system32\wdpdjaaj.ini
2008-08-27 08:26 . 2008-08-27 08:26 0 --a------ C:\WINDOWS\BM670e68bf.xml
2008-08-27 05:58 . 2008-08-27 05:58 <DIR> d-------- C:\Documents and Settings\kkooo\Application Data\imo.im
2008-08-27 05:28 . 2008-08-27 05:28 <DIR> d-------- C:\Documents and Settings\kkooo\DoctorWeb
2008-08-27 00:07 . 2008-08-27 00:07 <DIR> d-------- C:\Documents and Settings\kkooo\Application Data\Thinstall
2008-08-26 12:29 . 2008-08-26 12:29 <DIR> d-------- C:\Program Files\AOL Search
2008-08-26 12:28 . 2008-08-26 12:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-08-26 06:35 . 2008-08-26 06:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Software
2008-08-26 01:52 . 2004-05-13 17:32 276,480 --a------ C:\WINDOWS\system32\slbcsp.dll
2008-08-26 01:52 . 2004-05-13 17:27 171,008 --a------ C:\WINDOWS\system32\sccsccp.dll
2008-08-26 01:52 . 2004-05-13 17:27 169,984 --a------ C:\WINDOWS\system32\sccbase.dll
2008-08-26 01:52 . 2004-05-13 17:33 89,600 --a------ C:\WINDOWS\system32\slbiop.dll
2008-08-26 01:52 . 2004-05-13 17:33 14,848 --a------ C:\WINDOWS\system32\slbrccsp.dll
2008-08-25 20:33 . 2008-08-25 20:33 <DIR> d-------- C:\Documents and Settings\kkooo\Application Data\Apple Computer
2008-08-25 20:32 . 2008-08-25 20:32 <DIR> d-------- C:\Documents and Settings\kkooo
2008-08-25 05:26 . 2008-08-25 05:26 <DIR> d-------- C:\Program Files\Bonjour
2008-08-25 05:21 . 2008-08-25 05:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-07-17 17:46 . 2008-08-26 01:15 250 --a------ C:\WINDOWS\gmer.ini
2008-07-15 13:42 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-14 22:38 . 2008-07-14 22:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-14 22:31 . 2008-07-14 22:31 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-13 21:07 . 2008-07-13 21:07 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-13 21:07 . 2008-07-13 21:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-13 17:47 . 2008-07-13 17:47 <DIR> d-------- C:\Program Files\Opera
2008-07-13 17:44 . 2008-07-13 17:44 262,144 --a------ C:\Documents and Settings\KEATON~3
2008-07-13 17:44 . 2008-07-13 17:44 262,144 --a------ C:\Documents and Settings\KEATON~1
2008-07-13 12:34 . 2008-07-13 12:34 262,144 --a------ C:\Documents and Settings\KEF90A~3.KEA
2008-07-13 12:34 . 2008-07-13 12:34 262,144 --a------ C:\Documents and Settings\keaton1
2008-07-13 10:35 . 2008-07-13 10:35 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-07-13 01:52 . 2008-07-13 01:52 <DIR> d-------- C:\Documents and Settings\Default User
2008-07-11 23:31 . 2008-07-11 23:31 262,144 --a------ C:\Documents and Settings\KEF90A~2.KEA
2008-07-11 23:30 . 2008-07-11 23:30 <DIR> d-------- C:\Documents and Settings\Administrator
2008-07-11 18:47 . 2008-07-15 17:30 4,298 ---hs---- C:\WINDOWS\system32\uvphrjcr.ini
2008-07-11 17:39 . 2008-07-11 17:39 262,144 --a------ C:\Documents and Settings\KEF90A~1.KEA
2008-07-11 17:39 . 2008-07-11 17:39 262,144 --a------ C:\Documents and Settings\AD59A3~1
2008-07-11 17:22 . 2008-07-11 17:34 262,144 --a------ C:\Documents and Settings\KEATON~4.KEA
2008-07-11 17:22 . 2008-07-11 17:34 262,144 --a------ C:\Documents and Settings\ADMINI~4
2008-07-11 17:04 . 2008-07-11 17:04 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-11 17:04 . 2008-07-11 17:04 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-11 17:04 . 2008-07-11 17:04 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-11 17:04 . 2008-07-11 17:04 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-11 16:56 . 2008-07-11 17:06 8,192 --a------ C:\Documents and Settings\KEATON~3.KEA
2008-07-11 16:56 . 2008-07-11 17:06 8,192 --a------ C:\Documents and Settings\ADMINI~3
2008-07-11 14:29 . 2008-07-11 14:29 262,144 --a------ C:\Documents and Settings\KEATON~2.KEA
2008-07-11 14:29 . 2008-07-11 14:29 262,144 --a------ C:\Documents and Settings\ADMINI~2
2008-07-11 11:44 . 2008-07-11 12:19 262,144 --a------ C:\Documents and Settings\ADMINI~1
2008-07-11 11:44 . 2008-07-11 17:06 8,192 --a------ C:\Documents and Settings\T_REX
2008-07-11 11:44 . 2008-07-11 17:06 8,192 --a------ C:\Documents and Settings\BLAHBLAH
2008-07-11 11:44 . 2008-07-11 17:06 8,192 --a------ C:\Documents and Settings\blah13
2008-07-11 11:43 . 2008-07-11 12:19 262,144 --a------ C:\Documents and Settings\KEATON~1.KEA
2008-07-11 11:43 . 2008-07-11 17:06 8,192 --a------ C:\Documents and Settings\KEATON20
2008-07-11 11:43 . 2008-07-11 17:06 8,192 --a------ C:\Documents and Settings\keaton
2008-07-11 11:43 . 2008-07-11 17:06 8,192 --a------ C:\Documents and Settings\every1
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-29 18:09 2,036,227 ----a-w C:\Program Files\zia01476
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-06 16:24 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-06-06 16:24 307,200 ------w C:\WINDOWS\Setup1.exe
2008-05-15 19:58 403,794 ----a-w C:\WINDOWS\469.exe
2008-05-14 05:45 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-05-08 12:28 202,752 ------w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-04-23 22:21 269,824 ----a-w C:\WINDOWS\inf\WG111v3\Vista64\wg111v3.sys
2007-04-23 22:11 224,896 ----a-w C:\WINDOWS\inf\WG111v3\wg111v3.sys
2006-12-15 19:30 98,304 ----a-w C:\WINDOWS\inf\WG111v3\UScanM.exe
2006-12-15 19:30 66,048 ----a-w C:\WINDOWS\inf\WG111v3\EAPPkt.sys
2006-12-15 19:30 315,392 ----a-w C:\WINDOWS\inf\WG111v3\InstallDriver.exe
2006-12-15 19:30 28,672 ----a-w C:\WINDOWS\inf\WG111v3\SetDrv.exe
2006-12-15 19:30 212,992 ----a-w C:\WINDOWS\inf\WG111v3\CopyWHQLDriver.exe
2006-12-15 19:30 20,480 ----a-w C:\WINDOWS\inf\WG111v3\RTWUPath.exe
2006-12-15 19:30 19,968 ----a-w C:\WINDOWS\inf\WG111v3\RTWREFU.EXE
2005-08-03 00:46 187,904 --sha-r C:\WINDOWS\U2FudGE\asappsrv.dll
2005-08-03 00:58 293,888 --sha-r C:\WINDOWS\U2FudGE\command.exe
2005-07-30 00:24 472 --sha-r C:\WINDOWS\U2FudGE\oZIRx3H.vbs
.
------- Sigcheck -------
2002-12-31 12:00 17408 41fbc74ad30ec94ccb5e381adff97801 C:\WINDOWS\system32\svchost.exe
2002-12-31 12:00 506368 57fe5ee5e09a64592c68aa4b0e006db9 C:\WINDOWS\system32\winlogon.exe
2007-06-12 23:23 1035776 3fbd51a7602a6b620be096b72e7a7a27 C:\WINDOWS\explorer.exe
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\VCP_TEMP\explorer.exe
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\VCP_SAVE\explorer.exe
2007-06-13 00:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2gdr\explorer.exe
2007-06-13 00:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2qfe\explorer.exe
2002-12-31 12:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2002-12-31 12:00 110592 207939da390a3cef38fdf89cf5f42277 C:\WINDOWS\system32\services.exe
2002-12-31 12:00 14848 d2d425dcd5a37199666e21b826f52fee C:\WINDOWS\system32\lsass.exe
2005-06-10 16:53 58880 d519475810eb24a5cbb31bcc45e19622 C:\WINDOWS\system32\spoolsv.exe
2005-06-10 17:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2002-12-31 13:00 57856 7435b108b935e42ea92ca94f59c8e717 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 08:59 124520]
"AIMWDInstallFilename"="C:\Program Files\AIM\AIMWDInstall.exe" [2004-01-12 09:29 102400]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= jl_mjpg2.drv
"msacm.fraunhoferacm"= l3codecp.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Spybot - Search & Destroy\\SDShred.exe"=
"C:\\Program Files\\NETGEAR\\WG111v3\\WG111v3.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\1214617059\\ee\\aolsoftware.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"86:TCP"= 86:TCP:BroadCam Web Server
R2 avg8emc;AVG Free8 E-mail Scanner;C:\WINDOWS\system32\DRIVERS\avg8emc.syS []
R2 avg8wd;AVG Free8 WatchDog;C:\WINDOWS\system32\DRIVERS\avg8wd.syS []
R3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 09:05]
R3 JL2005;JL2005A Toy Camera;C:\WINDOWS\system32\DRIVERS\JL2005.syS []
R3 SCREAMINGBDRIVER;Screaming Bee Audio;C:\WINDOWS\system32\drivers\ScreamingBAudio.sys []
R3 USRTI;U.S. Robotics Faxmodem Driver TI;C:\WINDOWS\system32\DRIVERS\USRTI.SYS [2004-12-24 11:16]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-07-11 17:04]
S2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-07-11 17:04]
S2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 13:38]
S3 ctlsb16;Creative SB16/AWE32/AWE64 Driver (WDM);C:\WINDOWS\system32\drivers\ctlsb16.sys [2004-12-24 11:15]
S3 es1969;ESS 1969 Audio Driver (WDM);C:\WINDOWS\system32\drivers\es1969.sys [2004-12-24 11:15]
S3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys [2004-12-24 11:15]
S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;C:\WINDOWS\system32\DRIVERS\wg111v3.sys [2007-04-23 14:11]
S3 S3SAVAGE4M;S3SAVAGE4M;C:\WINDOWS\system32\DRIVERS\s3sav4m.sys [2004-12-24 11:16]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-HookURL - (no file)
URLSearchHooks-Rank - (no file)
URLSearchHooks-HookURL - (no file)
URLSearchHooks-Rank - (no file)
BHO-{76FE34BE-BD5D-4A35-B131-1F588F2D65FE} - C:\WINDOWS\system32\rqRHaYst.dll
HKLM-Run-643d5b23 - C:\WINDOWS\system32\onkjkpqu.dll
HKLM-Run-lphcrpdj0er4j - C:\WINDOWS\system32\lphcrpdj0er4j.exe
HKLM-Run-{D5-5B-B8-8C-DW} - C:\windows\system32\dwwnw64r.exe
Notify-ddcDvvUL - ddcDvvUL.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\kkooo\Application Data\Mozilla\Firefox\Profiles\gzajy2e7.default\
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npqtplugin8.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava11.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava12.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava13.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava14.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava32.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjpi160_03.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npoji610.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-29 21:53:02
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\SYSTEM32\MSDTC.EXE
C:\PROGRAM FILES\BONJOUR\MDNSRESPONDER.EXE
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\WINDOWS\SYSTEM32\MQSVC.EXE
C:\WINDOWS\SYSTEM32\WSCNTFY.EXE
C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-08-29 21:57:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-30 05:57:02
Pre-Run: 5,701,074,944 bytes free
Post-Run: 5,743,083,520 bytes free
266 --- E O F --- 2008-06-27 21:26:32
sexy_ladii05
2008-08-31, 17:02
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:01, on 2008-08-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\AIM\AIMWDInstall.exe
C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [AIMWDInstallFilename] C:\Program Files\AIM\AIMWDInstall.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O22 - SharedTaskScheduler: Deskscapes - {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - (no file)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: Uninterruptible Power Supply (UPS) - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 4311 bytes
Hi,
I really hate to have to say this but it does not look like we are making any progress.
Due to the nature of current infections ranging from bots, file patchers (yes some of your system files appear to be patched), password stealers, name changers and a seemingly endless incomming source of malware I truly think at this point in time it would be safest to back up your data you want to keep & format the machine & start out fresh.
At least this way you have a better chance of a clean install and knowing that the system will be safe to use.
We could go on for weeks and all the while your personal info is being plastered all over the "underground" for sale and we'll never know if we got it all removed.
I really think format is the only option at this point.
I can post some help links to safely do your re-install & some safety advise to help you stay clean if you like.
Regards,
Blender
sexy_ladii05
2008-08-31, 23:25
well my wirelss software get detled??
When you format --- everything gets deleted.
Everything.
Good stuff, Windows, Viruses, all of it.
That is why I tell you to back up your important stuff before you do anything.
Burn it to CD or whatever but you will need to back it up someplace OTHER THAN the drive you have windows installed on.
And before you put your backups back on system or use them --- you will need to scan it with antivirus to make sure you didn't back up infections.
You will need your XP install CD, Your drivers CD, and your software CD that came with the computer.
If you installed other hardware after buying the PC then you will need the Driver/software CD for it too.
If no CDs... then you will need to use the recovery partition on your computer to restore it back to factory settings.
Usually F11 at bootup to access the recovery partition.
sexy_ladii05
2008-09-01, 20:37
agh i dont have any of those things =[ :sad:
Please download this tool from Microsoft.
http://go.microsoft.com/fwlink/?linkid=52012
Double click on MGADiag.exe to run it.
Click Continue.
The program will run. It takes a while to finish the diagnosis, please be patient.
Once done, click on Copy.
Open Notepad and paste the contents in. Save this file and post it in your next reply, along with a new HijackThis log
sexy_ladii05
2008-09-01, 22:39
what is that for?? i cant reformat my computer cause once i do i can get back online
That tool doesn't format the computer lol.
It is just to check the genuine status of it.
What do you mean you can't get online if you format?
Don't you have the driver for your wireless on a cd or something?
If you don't --- download the wireless driver/software & burn it to CD or something.
sexy_ladii05
2008-09-03, 22:41
how do i do that?? cant i just make a cd imagie of it wont still work an iso
What??
I do not know what you mean about the iso.
Do you have the driver CD for your wireless device or not?
If not --- go to the manufacturer's site who created it, download the file & burn it to a CD so you will have it.
If you need ISO burning software this one is free & really easy to use.
http://www.snapfiles.com/get/burncdcc.html
Download that> unzip it.
Once unzipped, double click "burncdcc.exe"
Point it to the ISO you just downloaded or want to burn.
Click "start" to burn the CD.
It will ask you to insert CD.
You can have it automatically eject the CD.
sexy_ladii05
2008-09-06, 05:51
this dll dont work
regsvr32 jscript.dll
regsvr32 vbscript.dll
and i get this error when trying to start up a program
error cannot start aim (0x80040154).(im-0001)
please help
Hi,
Any other programs doing that error besides AIM?
Please do what I asked here:
http://forums.spybot.info/showpost.php?p=230373&postcount=78
Also upload that aim.exe to this site & tell me what the results are:
http://www.virustotal.com/en/indexf.html
C:\Program Files\AIM\aim.exe
Thanks :)
sexy_ladii05
2008-09-08, 05:42
Diagnostic Report (1.7.0095.0):
-----------------------------------------
WGA Data-->
Validation Status: Blocked VLK
Validation Code: 3
Online Validation Code: N/A
Cached Validation Code: N/A
Windows Product Key: *****-*****-RFGRH-X8RTX-2PWMJ
Windows Product Key Hash: Cf+b5qnrxwaN5Dd9AEjaKAXcPE0=
Windows Product ID: 55274-648-2358111-23233
Windows Product ID Type: 1
Windows License Type: Volume
Windows OS version: 5.1.2600.2.00010100.2.0.pro
CSVLK Server: N/A
CSVLK PID: N/A
ID: {EFF6BDC1-4E1A-430E-8A0E-2B4F096C6D63}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.7.59.1
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-171-1_70AFE6BE-1223-800401f3_70AFE6BE-116-800401f3_63BB5E84-433-800401f3_E2AD56EA-235-800401f3_16E0B333-89-800401f3
Resolution Status: N/A
WgaER Data-->
ThreatID(s): N/A
Version: N/A
WGA Notifications Data-->
Cached Result: N/A, hr = 0x800401f3
File Exists: Yes
Version: 1.7.18.7
WgaTray.exe Signed By: Microsoft
WgaLogon.dll Signed By: Microsoft
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGATray.exe Signed By: Microsoft
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-604-645_025D1FF3-171-1
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Default Browser: C:\Program Files\Opera\Opera.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
File Mismatch: C:\WINDOWS\system32\winlogon.exe[5.1.2600.2180]
File Mismatch: C:\WINDOWS\system32\syssetup.dll[5.1.2600.2180]
Other data-->
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:01, on 2008-09-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\kkooo\Local Settings\Application Data\Opera\Opera\profile\cache4\temporary_download\MGADiag.exe
C:\Documents and Settings\kkooo\Local Settings\Application Data\Opera\Opera\profile\cache4\temporary_download\MGADiag.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O22 - SharedTaskScheduler: Deskscapes - {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - (no file)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
--
End of file - 4059 bytes
sexy_ladii05
2008-09-08, 06:00
Diagnostic Report (1.7.0095.0):
-----------------------------------------
WGA Data-->
Validation Status: Blocked VLK
Validation Code: 3
Online Validation Code: N/A
Cached Validation Code: N/A
Windows Product Key: *****-*****-RFGRH-X8RTX-2PWMJ
Windows Product Key Hash: Cf+b5qnrxwaN5Dd9AEjaKAXcPE0=
Windows Product ID: 55274-648-2358111-23233
Windows Product ID Type: 1
Windows License Type: Volume
Windows OS version: 5.1.2600.2.00010100.2.0.pro
CSVLK Server: N/A
CSVLK PID: N/A
ID: {EFF6BDC1-4E1A-430E-8A0E-2B4F096C6D63}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.7.59.1
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-171-1_70AFE6BE-1223-800401f3_70AFE6BE-116-800401f3_63BB5E84-433-800401f3_E2AD56EA-235-800401f3_16E0B333-89-800401f3
Resolution Status: N/A
WgaER Data-->
ThreatID(s): N/A
Version: N/A
WGA Notifications Data-->
Cached Result: N/A, hr = 0x800401f3
File Exists: Yes
Version: 1.7.18.7
WgaTray.exe Signed By: Microsoft
WgaLogon.dll Signed By: Microsoft
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGATray.exe Signed By: Microsoft
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-604-645_025D1FF3-171-1
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Default Browser: C:\Program Files\Opera\Opera.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
File Mismatch: C:\WINDOWS\system32\winlogon.exe[5.1.2600.2180]
File Mismatch: C:\WINDOWS\system32\syssetup.dll[5.1.2600.2180]
Other data-->
Diagnostic Report (1.7.0095.0):
-----------------------------------------
WGA Data-->
Validation Status: Blocked VLK
Validation Code: 3
Online Validation Code: N/A
Cached Validation Code: N/A
Windows Product Key: *****-*****-RFGRH-X8RTX-2PWMJ
Windows Product Key Hash: Cf+b5qnrxwaN5Dd9AEjaKAXcPE0=
Windows Product ID: 55274-648-2358111-23233
Windows Product ID Type: 1
Windows License Type: Volume
Windows OS version: 5.1.2600.2.00010100.2.0.pro
CSVLK Server: N/A
CSVLK PID: N/A
ID: {EFF6BDC1-4E1A-430E-8A0E-2B4F096C6D63}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.7.59.1
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-171-1_70AFE6BE-1223-800401f3_70AFE6BE-116-800401f3_63BB5E84-433-800401f3_E2AD56EA-235-800401f3_16E0B333-89-800401f3
Resolution Status: N/A
WgaER Data-->
ThreatID(s): N/A
Version: N/A
WGA Notifications Data-->
Cached Result: N/A, hr = 0x800401f3
File Exists: Yes
Version: 1.7.18.7
WgaTray.exe Signed By: Microsoft
WgaLogon.dll Signed By: Microsoft
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGATray.exe Signed By: Microsoft
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-604-645_025D1FF3-171-1
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Default Browser: C:\Program Files\Opera\Opera.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
File Mismatch: C:\WINDOWS\system32\winlogon.exe[5.1.2600.2180]
File Mismatch: C:\WINDOWS\system32\syssetup.dll[5.1.2600.2180]
Other data-->
Diagnostic Report (1.7.0095.0):
-----------------------------------------
WGA Data-->
Validation Status: Blocked VLK
Validation Code: 3
Online Validation Code: N/A
Cached Validation Code: N/A
Windows Product Key: *****-*****-RFGRH-X8RTX-2PWMJ
Windows Product Key Hash: Cf+b5qnrxwaN5Dd9AEjaKAXcPE0=
Windows Product ID: 55274-648-2358111-23233
Windows Product ID Type: 1
Windows License Type: Volume
Windows OS version: 5.1.2600.2.00010100.2.0.pro
CSVLK Server: N/A
CSVLK PID: N/A
ID: {EFF6BDC1-4E1A-430E-8A0E-2B4F096C6D63}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.7.59.1
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-171-1_70AFE6BE-1223-800401f3_70AFE6BE-116-800401f3_63BB5E84-433-800401f3_E2AD56EA-235-800401f3_16E0B333-89-800401f3
Resolution Status: N/A
WgaER Data-->
ThreatID(s): N/A
Version: N/A
WGA Notifications Data-->
Cached Result: N/A, hr = 0x800401f3
File Exists: Yes
Version: 1.7.18.7
WgaTray.exe Signed By: Microsoft
WgaLogon.dll Signed By: Microsoft
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGATray.exe Signed By: Microsoft
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-604-645_025D1FF3-171-1
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Default Browser: C:\Program Files\Opera\Opera.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
File Mismatch: C:\WINDOWS\system32\winlogon.exe[5.1.2600.2180]
File Mismatch: C:\WINDOWS\system32\syssetup.dll[5.1.2600.2180]
Other data-->
Diagnostic Report (1.7.0095.0):
-----------------------------------------
WGA Data-->
Validation Status: Blocked VLK
Validation Code: 3
Online Validation Code: N/A
Cached Validation Code: N/A
Windows Product Key: *****-*****-RFGRH-X8RTX-2PWMJ
Windows Product Key Hash: Cf+b5qnrxwaN5Dd9AEjaKAXcPE0=
Windows Product ID: 55274-648-2358111-23233
Windows Product ID Type: 1
Windows License Type: Volume
Windows OS version: 5.1.2600.2.00010100.2.0.pro
CSVLK Server: N/A
CSVLK PID: N/A
ID: {EFF6BDC1-4E1A-430E-8A0E-2B4F096C6D63}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.7.59.1
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-171-1_70AFE6BE-1223-800401f3_70AFE6BE-116-800401f3_63BB5E84-433-800401f3_E2AD56EA-235-800401f3_16E0B333-89-800401f3
Resolution Status: N/A
WgaER Data-->
ThreatID(s): N/A
Version: N/A
WGA Notifications Data-->
Cached Result: N/A, hr = 0x800401f3
File Exists: Yes
Version: 1.7.18.7
WgaTray.exe Signed By: Microsoft
WgaLogon.dll Signed By: Microsoft
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGATray.exe Signed By: Microsoft
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-604-645_025D1FF3-171-1
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Default Browser: C:\Program Files\Opera\Opera.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
File Mismatch: C:\WINDOWS\system32\winlogon.exe[5.1.2600.2180]
File Mismatch: C:\WINDOWS\system32\syssetup.dll[5.1.2600.2180]
Other data-->
Hi,
Thanks for the logs.
Unfortunately I cannot help you any further.
I cannot put myself at risk for "aiding and abetting a crime"
It appears your Product key has been blocked because it is a "volume licence key"
VLK's are generally only available to corperations -- not private people.
WGA Data-->
Validation Status: Blocked VLK
Please see this post for more info:
http://forums.spybot.info/showpost.php?p=25290&postcount=4
I highly suggest you get yourself a valid copy of windows so you can keep up with the needed updates that prevent most exploits that lead to infections.
Because your PK is blocked you cannot get the needed updates and MS support when issues do arrise.
Get yourself a valid copy of windows so you can format/re-install properly and be sure of a clean system.
Thanks for understanding.
Blender