ComboFix 09-07-29.04 - My Computer 07/30/2009 22:50.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1594 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\CombFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-906280836-2277474917-2120796318-500
C:\uigxpmv.exe
c:\windows\codec.exe
c:\windows\FONTS\cooecp.tlb
c:\windows\FONTS\logcde.dll
c:\windows\Fonts\mlog
c:\windows\Fonts\services.exe
c:\windows\FONTS\windef.dll
c:\windows\FONTS\windef.Log
c:\windows\FONTS\winpaged.ocx
c:\windows\Install.txt
c:\windows\intcmob.dll
c:\windows\kb913800.exe
c:\windows\system32\6to4v32.dll
c:\windows\system32\certstore.dat
c:\windows\system32\comsa32.sys
c:\windows\system32\drivers\UACdqlpbovoyb.sys
c:\windows\system32\FInstall.sys
c:\windows\system32\Iasv32.dll
c:\windows\system32\mobsyn.exe
c:\windows\system32\msassnz.exe
c:\windows\system32\msbtym.exe
c:\windows\system32\mscdiy.exe
c:\windows\system32\mscdtrwx.exe
c:\windows\system32\mscdymv.exe
c:\windows\system32\mscew.exe
c:\windows\system32\mscfu.exe
c:\windows\system32\mscgra.exe
c:\windows\system32\mscgwc.exe
c:\windows\system32\mschl.exe
c:\windows\system32\mscino.exe
c:\windows\system32\mscit.exe
c:\windows\system32\mscjm.exe
c:\windows\system32\mscmhyen.exe
c:\windows\system32\mscmsqx.exe
c:\windows\system32\mscoc.exe
c:\windows\system32\mscoihqz.exe
c:\windows\system32\mscojdco.exe
c:\windows\system32\mscoxtqc.exe
c:\windows\system32\mscpeh.exe
c:\windows\system32\mscpntuf.exe
c:\windows\system32\mscpz.exe
c:\windows\system32\mscqbkox.exe
c:\windows\system32\mscrv.exe
c:\windows\system32\mscslt.exe
c:\windows\system32\mscsonuj.exe
c:\windows\system32\msctavd.exe
c:\windows\system32\msctcz.exe
c:\windows\system32\msctixl.exe
c:\windows\system32\mscuc.exe
c:\windows\system32\mscvgn.exe
c:\windows\system32\mscwelok.exe
c:\windows\system32\mscwm.exe
c:\windows\system32\mscxlnx.exe
c:\windows\system32\mscymjfk.exe
c:\windows\system32\msczol.exe
c:\windows\system32\msczyr.exe
c:\windows\system32\msdanf.exe
c:\windows\system32\msddpiv.exe
c:\windows\system32\msdep.exe
c:\windows\system32\msdgbbc.exe
c:\windows\system32\msdgf.exe
c:\windows\system32\msdgvhu.exe
c:\windows\system32\msdifsvv.exe
c:\windows\system32\msdjapi.exe
c:\windows\system32\msdjido.exe
c:\windows\system32\msdkpge.exe
c:\windows\system32\msdkz.exe
c:\windows\system32\msdltte.exe
c:\windows\system32\msdlz.exe
c:\windows\system32\msdnn.exe
c:\windows\system32\msdnqy.exe
c:\windows\system32\msdowhlk.exe
c:\windows\system32\msdsavc.exe
c:\windows\system32\msdtfbz.exe
c:\windows\system32\msduhfzj.exe
c:\windows\system32\msdwuv.exe
c:\windows\system32\msdxapzp.exe
c:\windows\system32\msdxyfs.exe
c:\windows\system32\msdznlw.exe
c:\windows\system32\mseasxv.exe
c:\windows\system32\mseaud.exe
c:\windows\system32\msebpg.exe
c:\windows\system32\msecwhq.exe
c:\windows\system32\mseddg.exe
c:\windows\system32\msefjefl.exe
c:\windows\system32\msefjh.exe
c:\windows\system32\msegj.exe
c:\windows\system32\msegt.exe
c:\windows\system32\msehvccs.exe
c:\windows\system32\mseib.exe
c:\windows\system32\msejw.exe
c:\windows\system32\msejyab.exe
c:\windows\system32\msejyqdy.exe
c:\windows\system32\msekx.exe
c:\windows\system32\msekzn.exe
c:\windows\system32\mselecb.exe
c:\windows\system32\mselp.exe
c:\windows\system32\mselu.exe
c:\windows\system32\msembsh.exe
c:\windows\system32\msemmgn.exe
c:\windows\system32\msenrxn.exe
c:\windows\system32\msenwlsc.exe
c:\windows\system32\mseozh.exe
c:\windows\system32\msepu.exe
c:\windows\system32\mserdn.exe
c:\windows\system32\mserf.exe
c:\windows\system32\mserwpdg.exe
c:\windows\system32\mseugo.exe
c:\windows\system32\mseuh.exe
c:\windows\system32\mseunemx.exe
c:\windows\system32\msevflkk.exe
c:\windows\system32\msevgdkp.exe
c:\windows\system32\msevrpty.exe
c:\windows\system32\msevxnms.exe
c:\windows\system32\msewkygl.exe
c:\windows\system32\msexugat.exe
c:\windows\system32\msezfg.exe
c:\windows\system32\msfaqiep.exe
c:\windows\system32\msfbh.exe
c:\windows\system32\msfblqg.exe
c:\windows\system32\msfccugy.exe
c:\windows\system32\msfcf.exe
c:\windows\system32\msfcg.exe
c:\windows\system32\msfcxr.exe
c:\windows\system32\msfdu.exe
c:\windows\system32\msfeddlj.exe
c:\windows\system32\msfej.exe
c:\windows\system32\msfgbq.exe
c:\windows\system32\msfgesrd.exe
c:\windows\system32\msfgxqo.exe
c:\windows\system32\msfhf.exe
c:\windows\system32\msfhq.exe
c:\windows\system32\msfhz.exe
c:\windows\system32\msfin.exe
c:\windows\system32\msfipab.exe
c:\windows\system32\msfjb.exe
c:\windows\system32\msfjch.exe
c:\windows\system32\msfjuh.exe
c:\windows\system32\msfmss.exe
c:\windows\system32\msfmw.exe
c:\windows\system32\msfne.exe
c:\windows\system32\msfnoe.exe
c:\windows\system32\msfouh.exe
c:\windows\system32\msfpgkmw.exe
c:\windows\system32\msfqsd.exe
c:\windows\system32\msfrkpug.exe
c:\windows\system32\msfsktr.exe
c:\windows\system32\msfuab.exe
c:\windows\system32\msfukeu.exe
c:\windows\system32\msfunqk.exe
c:\windows\system32\msfvz.exe
c:\windows\system32\msfwwlqg.exe
c:\windows\system32\msfxcjbv.exe
c:\windows\system32\msfxiehb.exe
c:\windows\system32\msfxjwjs.exe
c:\windows\system32\msfzhbgb.exe
c:\windows\system32\msfzxckb.exe
c:\windows\system32\msfzyvqc.exe
c:\windows\system32\msgaasjy.exe
c:\windows\system32\msgae.exe
c:\windows\system32\msgafk.exe
c:\windows\system32\msgdke.exe
c:\windows\system32\msgecr.exe
c:\windows\system32\msgenjq.exe
c:\windows\system32\msgex.exe
c:\windows\system32\msgfdp.exe
c:\windows\system32\msgff.exe
c:\windows\system32\msggo.exe
c:\windows\system32\msggwx.exe
c:\windows\system32\msghr.exe
c:\windows\system32\msgjkovz.exe
c:\windows\system32\msgkbc.exe
c:\windows\system32\msgkc.exe
c:\windows\system32\msgkra.exe
c:\windows\system32\msglf.exe
c:\windows\system32\msglo.exe
c:\windows\system32\msgno.exe
c:\windows\system32\msgobvqz.exe
c:\windows\system32\msgpuvna.exe
c:\windows\system32\msgqtz.exe
c:\windows\system32\msgrnhd.exe
c:\windows\system32\msgvpo.exe
c:\windows\system32\msgvx.exe
c:\windows\system32\msgwbcd.exe
c:\windows\system32\msgxmg.exe
c:\windows\system32\msgxuhha.exe
c:\windows\system32\msgyg.exe
c:\windows\system32\msgylhb.exe
c:\windows\system32\mshafykz.exe
c:\windows\system32\mshcmr.exe
c:\windows\system32\mshcni.exe
c:\windows\system32\mshgixuk.exe
c:\windows\system32\mshgkcv.exe
c:\windows\system32\mshgw.exe
c:\windows\system32\mshhqdw.exe
c:\windows\system32\mshhra.exe
c:\windows\system32\mshhzk.exe
c:\windows\system32\mshiyr.exe
c:\windows\system32\mshizxr.exe
c:\windows\system32\mshjzf.exe
c:\windows\system32\mshll.exe
c:\windows\system32\mshlnsj.exe
c:\windows\system32\mshmhn.exe
c:\windows\system32\mshmyer.exe
c:\windows\system32\mshoe.exe
c:\windows\system32\mshpkrpo.exe
c:\windows\system32\mshrxzjz.exe
c:\windows\system32\mshsdgjn.exe
c:\windows\system32\mshshe.exe
c:\windows\system32\mshssec.exe
c:\windows\system32\mshtgy.exe
c:\windows\system32\mshtkem.exe
c:\windows\system32\mshtuyq.exe
c:\windows\system32\mshudl.exe
c:\windows\system32\mshufyvc.exe
c:\windows\system32\mshvyfg.exe
c:\windows\system32\mshwkd.exe
c:\windows\system32\mshwm.exe
c:\windows\system32\mshxo.exe
c:\windows\system32\mshxytjt.exe
c:\windows\system32\mshydepn.exe
c:\windows\system32\mshzbfnm.exe
c:\windows\system32\mshzct.exe
c:\windows\system32\msiaeon.exe
c:\windows\system32\msicijlj.exe
c:\windows\system32\msiffxrc.exe
c:\windows\system32\msifix.exe
c:\windows\system32\msifwk.exe
c:\windows\system32\msifzde.exe
c:\windows\system32\msiirdh.exe
c:\windows\system32\msikdw.exe
c:\windows\system32\msikgjiw.exe
c:\windows\system32\msils.exe
c:\windows\system32\msiltvbu.exe
c:\windows\system32\msimdc.exe
c:\windows\system32\msimjvm.exe
c:\windows\system32\msimwqmy.exe
c:\windows\system32\msinld.exe
c:\windows\system32\msinnmzs.exe
c:\windows\system32\msipewji.exe
c:\windows\system32\msiplhfz.exe
c:\windows\system32\msiprtfn.exe
c:\windows\system32\msipyizc.exe
c:\windows\system32\msipz.exe
c:\windows\system32\msiqzuu.exe
c:\windows\system32\msird.exe
c:\windows\system32\msiseyjk.exe
c:\windows\system32\msisj.exe
c:\windows\system32\msitng.exe
c:\windows\system32\msivb.exe
c:\windows\system32\msivxws.exe
c:\windows\system32\msiwbwi.exe
c:\windows\system32\msiwugf.exe
c:\windows\system32\msixc.exe
c:\windows\system32\msixfx.exe
c:\windows\system32\msizuv.exe
c:\windows\system32\msjawit.exe
c:\windows\system32\msjbrmk.exe
c:\windows\system32\msjbyxgt.exe
c:\windows\system32\msjcoiv.exe
c:\windows\system32\msjdiuv.exe
c:\windows\system32\msjdq.exe
c:\windows\system32\msjdye.exe
c:\windows\system32\msjek.exe
c:\windows\system32\msjfgyf.exe
c:\windows\system32\msjgev.exe
c:\windows\system32\msjgyjg.exe
c:\windows\system32\msjicsau.exe
c:\windows\system32\msjilqhy.exe
c:\windows\system32\msjinzw.exe
c:\windows\system32\msjivg.exe
c:\windows\system32\msjivgq.exe
c:\windows\system32\msjjn.exe
c:\windows\system32\msjlrzm.exe
c:\windows\system32\msjmizj.exe
c:\windows\system32\msjmle.exe
c:\windows\system32\msjnc.exe
c:\windows\system32\msjnvjsh.exe
c:\windows\system32\msjolh.exe
c:\windows\system32\msjpg.exe
c:\windows\system32\msjps.exe
c:\windows\system32\msjrxu.exe
c:\windows\system32\msjskmm.exe
c:\windows\system32\msjvhwf.exe
c:\windows\system32\msjvlsqd.exe
c:\windows\system32\msjwdtht.exe
c:\windows\system32\msjxaech.exe
c:\windows\system32\msjytrht.exe
c:\windows\system32\msjzj.exe
c:\windows\system32\msjzwnhy.exe
c:\windows\system32\mskbp.exe
c:\windows\system32\mskdgst.exe
c:\windows\system32\mskdlfcf.exe
c:\windows\system32\mskfxkzc.exe
c:\windows\system32\mskgp.exe
c:\windows\system32\mskhgc.exe
c:\windows\system32\mskijpcr.exe
c:\windows\system32\mskjlq.exe
c:\windows\system32\mskjrdml.exe
c:\windows\system32\mskkhvx.exe
c:\windows\system32\mskkjlhv.exe
c:\windows\system32\mskkq.exe
c:\windows\system32\msklgxm.exe
c:\windows\system32\msklua.exe
c:\windows\system32\msklusy.exe
c:\windows\system32\mskma.exe
c:\windows\system32\mskncwm.exe
c:\windows\system32\mskpg.exe
c:\windows\system32\mskpkain.exe
c:\windows\system32\mskqlh.exe
c:\windows\system32\msktmvdf.exe
c:\windows\system32\msktr.exe
c:\windows\system32\mskts.exe
c:\windows\system32\mskttiba.exe
c:\windows\system32\mskuco.exe
c:\windows\system32\mskumbvq.exe
c:\windows\system32\mskwdlim.exe
c:\windows\system32\mskwoc.exe
c:\windows\system32\mskwuy.exe
c:\windows\system32\mskww.exe
c:\windows\system32\mskxhit.exe
c:\windows\system32\mskxlf.exe
c:\windows\system32\mskxlk.exe
c:\windows\system32\mskxtcsh.exe
c:\windows\system32\mskzaj.exe
c:\windows\system32\mskzemqd.exe
c:\windows\system32\mskzpwbb.exe
c:\windows\system32\mslcag.exe
c:\windows\system32\mslcy.exe
c:\windows\system32\msldvd.exe
c:\windows\system32\msletg.exe
c:\windows\system32\mslfdj.exe
c:\windows\system32\mslfj.exe
c:\windows\system32\mslhw.exe
c:\windows\system32\mslhww.exe
c:\windows\system32\mslio.exe
c:\windows\system32\msljc.exe
c:\windows\system32\mslkan.exe
c:\windows\system32\mslmmx.exe
c:\windows\system32\mslmmyg.exe
c:\windows\system32\mslmp.exe
c:\windows\system32\mslns.exe
c:\windows\system32\mslodta.exe
c:\windows\system32\msloj.exe
c:\windows\system32\mslpbgr.exe
c:\windows\system32\mslraeo.exe
c:\windows\system32\mslrgfcc.exe
c:\windows\system32\mslrne.exe
c:\windows\system32\mslrp.exe
c:\windows\system32\mslrxe.exe
c:\windows\system32\mslucqe.exe
c:\windows\system32\msluqn.exe
c:\windows\system32\msluuk.exe
c:\windows\system32\mslvdi.exe
c:\windows\system32\mslxdhd.exe
c:\windows\system32\mslzg.exe
c:\windows\system32\msmacoah.exe
c:\windows\system32\msmagio.exe
c:\windows\system32\msmagnu.exe
c:\windows\system32\msmbea.exe
c:\windows\system32\msmbvqra.exe
c:\windows\system32\msmckv.exe
c:\windows\system32\msmcoqs.exe
c:\windows\system32\msmcq.exe
c:\windows\system32\msmcu.exe
c:\windows\system32\msmedyfq.exe
c:\windows\system32\msmemut.exe
c:\windows\system32\msmftoz.exe
c:\windows\system32\msmhaa.exe
c:\windows\system32\msmhk.exe
c:\windows\system32\msminxd.exe
c:\windows\system32\msmjxznq.exe
c:\windows\system32\msmktixr.exe
c:\windows\system32\msmkxew.exe
c:\windows\system32\msmlwzj.exe
c:\windows\system32\msmlz.exe
c:\windows\system32\msmovruh.exe
c:\windows\system32\msmprznq.exe
c:\windows\system32\msmqjgln.exe
c:\windows\system32\msmru.exe
c:\windows\system32\msmsa.exe
c:\windows\system32\msmscehe.exe
c:\windows\system32\msmsdm.exe
c:\windows\system32\msmskcr.exe
c:\windows\system32\msmtquf.exe
c:\windows\system32\msmuwb.exe
c:\windows\system32\msmwdpk.exe
c:\windows\system32\msmwhh.exe
c:\windows\system32\msmwwdrf.exe
c:\windows\system32\msmxoeab.exe
c:\windows\system32\msmxw.exe
c:\windows\system32\msmxy.exe
c:\windows\system32\msmynr.exe
c:\windows\system32\msmzqwm.exe
c:\windows\system32\msnaq.exe
c:\windows\system32\msnaud.exe
c:\windows\system32\msnbewet.exe
c:\windows\system32\msnbu.exe
c:\windows\system32\msncache.dll
c:\windows\system32\msncjccs.exe
c:\windows\system32\msnczdj.exe
c:\windows\system32\msndloui.exe
c:\windows\system32\msndrui.exe
c:\windows\system32\msnej.exe
c:\windows\system32\msnet.exe
c:\windows\system32\msnfm.exe
c:\windows\system32\msngovql.exe
c:\windows\system32\msnhbds.exe
c:\windows\system32\msniaebo.exe
c:\windows\system32\msnjoiv.exe
c:\windows\system32\msnkf.exe
c:\windows\system32\msnkzjyc.exe
c:\windows\system32\msnmb.exe
c:\windows\system32\msnmzc.exe
c:\windows\system32\msnnsmc.exe
c:\windows\system32\msnogi.exe
c:\windows\system32\msnokwr.exe
c:\windows\system32\msnom.exe
c:\windows\system32\msnopm.exe
c:\windows\system32\msnphd.exe
c:\windows\system32\msnplgqk.exe
c:\windows\system32\msnpqbx.exe
c:\windows\system32\msnqhhf.exe
c:\windows\system32\msnrfa.exe
c:\windows\system32\msnrmlan.exe
c:\windows\system32\msnrmn.exe
c:\windows\system32\msnrsq.exe
c:\windows\system32\msnrxtq.exe
c:\windows\system32\msnrxz.exe
c:\windows\system32\msntrirl.exe
c:\windows\system32\msnua.exe
c:\windows\system32\msnvbss.exe
c:\windows\system32\msnvp.exe
c:\windows\system32\msnvriv.exe
c:\windows\system32\msnvva.exe
c:\windows\system32\msnvvu.exe
c:\windows\system32\msnwc.exe
c:\windows\system32\msnwv.exe
c:\windows\system32\msnykimk.exe
c:\windows\system32\msoawz.exe
c:\windows\system32\msobaia.exe
c:\windows\system32\msobksri.exe
c:\windows\system32\msodiigs.exe
c:\windows\system32\msoeqxc.exe
c:\windows\system32\msofjmn.exe
c:\windows\system32\msohsoxu.exe
c:\windows\system32\msojb.exe
c:\windows\system32\msolces.exe
c:\windows\system32\msoleqn.exe
c:\windows\system32\msolg.exe
c:\windows\system32\msomy.exe
c:\windows\system32\msonmq.exe
c:\windows\system32\msoohqy.exe
c:\windows\system32\msopawz.exe
c:\windows\system32\msopxmhi.exe
c:\windows\system32\msopz.exe
c:\windows\system32\msorm.exe
c:\windows\system32\msose.exe
c:\windows\system32\msoss.exe
c:\windows\system32\msotimvc.exe
c:\windows\system32\msovjwj.exe
c:\windows\system32\msown.exe
c:\windows\system32\msoxbw.exe
c:\windows\system32\msoyqzvw.exe
c:\windows\system32\msozakca.exe
c:\windows\system32\msozba.exe
c:\windows\system32\msozmv.exe
c:\windows\system32\msozr.exe
c:\windows\system32\mspak.exe
c:\windows\system32\mspbwo.exe
c:\windows\system32\mspcmi.exe
c:\windows\system32\mspct.exe
c:\windows\system32\mspczldp.exe
c:\windows\system32\mspdamu.exe
c:\windows\system32\mspfw.exe
c:\windows\system32\mspgznok.exe
c:\windows\system32\msphavs.exe
c:\windows\system32\msphd.exe
c:\windows\system32\msphh.exe
c:\windows\system32\msphjubk.exe
c:\windows\system32\msphk.exe
c:\windows\system32\msphlj.exe
c:\windows\system32\msphlq.exe
c:\windows\system32\msphojyk.exe
c:\windows\system32\msphufs.exe
c:\windows\system32\mspjkuc.exe
c:\windows\system32\mspjuhsa.exe
c:\windows\system32\mspkb.exe
c:\windows\system32\mspkr.exe
c:\windows\system32\mspku.exe
c:\windows\system32\mspky.exe
c:\windows\system32\mspmf.exe
c:\windows\system32\mspmmx.exe
c:\windows\system32\mspnanwi.exe
c:\windows\system32\mspozs.exe
c:\windows\system32\msppdjhd.exe
c:\windows\system32\msppm.exe
c:\windows\system32\msppqgzc.exe
c:\windows\system32\mspprc.exe
c:\windows\system32\msppruf.exe
c:\windows\system32\msppxb.exe
c:\windows\system32\mspqhu.exe
c:\windows\system32\mspqiux.exe
c:\windows\system32\mspqlthg.exe
c:\windows\system32\mspqn.exe
c:\windows\system32\msprb.exe
c:\windows\system32\msprex.exe
c:\windows\system32\mspribfe.exe
c:\windows\system32\mspsubu.exe
c:\windows\system32\mspsw.exe
c:\windows\system32\mspubk.exe
c:\windows\system32\mspuiep.exe
c:\windows\system32\mspuk.exe
c:\windows\system32\mspun.exe
c:\windows\system32\mspuwsax.exe
c:\windows\system32\mspvli.exe
c:\windows\system32\mspvmt.exe
c:\windows\system32\mspwc.exe
c:\windows\system32\mspwofky.exe
c:\windows\system32\mspxrw.exe
c:\windows\system32\mspxt.exe
c:\windows\system32\mspyl.exe
c:\windows\system32\mspynsju.exe
c:\windows\system32\mspyqhl.exe
c:\windows\system32\mspyr.exe
c:\windows\system32\mspytark.exe
c:\windows\system32\mspyxur.exe
c:\windows\system32\mspzbwkh.exe
c:\windows\system32\mspzc.exe
c:\windows\system32\mspzfz.exe
c:\windows\system32\mspzht.exe
c:\windows\system32\msqacyb.exe
c:\windows\system32\msqayn.exe
c:\windows\system32\msqaz.exe
c:\windows\system32\msqbfhqi.exe
c:\windows\system32\msqci.exe
c:\windows\system32\msqcnimq.exe
c:\windows\system32\msqcqkf.exe
c:\windows\system32\msqczv.exe
c:\windows\system32\msqdalit.exe
c:\windows\system32\msqdmlh.exe
c:\windows\system32\msqdwre.exe
c:\windows\system32\msqdxau.exe
c:\windows\system32\msqee.exe
c:\windows\system32\msqerrk.exe
c:\windows\system32\msqfjn.exe
c:\windows\system32\msqfn.exe
c:\windows\system32\msqfomd.exe
c:\windows\system32\msqfpa.exe
c:\windows\system32\msqfq.exe
c:\windows\system32\msqfrd.exe
c:\windows\system32\msqfrfh.exe
c:\windows\system32\msqgc.exe
c:\windows\system32\msqgfwlw.exe
c:\windows\system32\msqhpnbn.exe
c:\windows\system32\msqiq.exe
c:\windows\system32\msqizso.exe
c:\windows\system32\msqjqby.exe
c:\windows\system32\msqjxeu.exe
c:\windows\system32\msqkhjxz.exe
c:\windows\system32\msqkoi.exe
c:\windows\system32\msqkpao.exe
c:\windows\system32\msqlacl.exe
c:\windows\system32\msqlh.exe
c:\windows\system32\msqlj.exe
c:\windows\system32\msqlkb.exe
c:\windows\system32\msqmcqt.exe
c:\windows\system32\msqmwrjg.exe
c:\windows\system32\msqnuig.exe
c:\windows\system32\msqnuyo.exe
c:\windows\system32\msqonc.exe
c:\windows\system32\msqpdz.exe
c:\windows\system32\msqpete.exe
c:\windows\system32\msqpmdd.exe
c:\windows\system32\msqpo.exe
c:\windows\system32\msqpxfux.exe
c:\windows\system32\msqqaoy.exe
c:\windows\system32\msqqlfcs.exe
c:\windows\system32\msqqn.exe
c:\windows\system32\msqqrv.exe
c:\windows\system32\msqqzqr.exe
c:\windows\system32\msqrox.exe
c:\windows\system32\msqrsgc.exe
c:\windows\system32\msqrzi.exe
c:\windows\system32\msquav.exe
c:\windows\system32\msquf.exe
c:\windows\system32\msqufds.exe
c:\windows\system32\msqvqtq.exe
c:\windows\system32\msqvt.exe
c:\windows\system32\msqvtlcl.exe
c:\windows\system32\msqwc.exe
c:\windows\system32\msqwegg.exe
c:\windows\system32\msqwpc.exe
c:\windows\system32\msqysixh.exe
c:\windows\system32\msqzhmzb.exe
c:\windows\system32\msqzotjg.exe
c:\windows\system32\msrahxd.exe
c:\windows\system32\msrame.exe
c:\windows\system32\msraot.exe
c:\windows\system32\msrbpotw.exe
c:\windows\system32\msrbvyx.exe
c:\windows\system32\msrcgcpd.exe
c:\windows\system32\msrcrcj.exe
c:\windows\system32\msrcz.exe
c:\windows\system32\msrdqgym.exe
c:\windows\system32\msrenm.exe
c:\windows\system32\msrenoai.exe
c:\windows\system32\msrepxz.exe
c:\windows\system32\msrfjjek.exe
c:\windows\system32\msrfru.exe
c:\windows\system32\msrgb.exe
c:\windows\system32\msrgpc.exe
c:\windows\system32\msrgt.exe
c:\windows\system32\msrgwa.exe
c:\windows\system32\msrgzlk.exe
c:\windows\system32\msrha.exe
c:\windows\system32\msrhesfl.exe
c:\windows\system32\msrhubt.exe
c:\windows\system32\msrhvr.exe
c:\windows\system32\msriqte.exe
c:\windows\system32\msriusa.exe
c:\windows\system32\msrjesfs.exe
c:\windows\system32\msrjhcx.exe
c:\windows\system32\msrjp.exe
c:\windows\system32\msrjz.exe
c:\windows\system32\msrket.exe
c:\windows\system32\msrkhop.exe
c:\windows\system32\msrkhwkh.exe
c:\windows\system32\msrkvbg.exe
c:\windows\system32\msrkwph.exe
c:\windows\system32\msrky.exe
c:\windows\system32\msrlarfr.exe
c:\windows\system32\msrlnf.exe
c:\windows\system32\msrlod.exe
c:\windows\system32\msrmm.exe
c:\windows\system32\msrmq.exe
c:\windows\system32\msrnp.exe
c:\windows\system32\msroeit.exe
c:\windows\system32\msrondt.exe
c:\windows\system32\msrpebj.exe
c:\windows\system32\msrpv.exe
c:\windows\system32\msrqc.exe
c:\windows\system32\msrqfkwn.exe
c:\windows\system32\msrqilv.exe
c:\windows\system32\msrqz.exe
c:\windows\system32\msrrgle.exe
c:\windows\system32\msrrjzyt.exe
c:\windows\system32\msrrq.exe
c:\windows\system32\msrsmb.exe
c:\windows\system32\msrsqge.exe
c:\windows\system32\msrtcfk.exe
c:\windows\system32\msrtiyx.exe
c:\windows\system32\msrtsl.exe
c:\windows\system32\msrtyrpu.exe
c:\windows\system32\msruhrwo.exe
c:\windows\system32\msrut.exe
c:\windows\system32\msruwyww.exe
c:\windows\system32\msrvf.exe
c:\windows\system32\msrwmn.exe
c:\windows\system32\msrwq.exe
c:\windows\system32\msrxkci.exe
c:\windows\system32\msrxoirr.exe
c:\windows\system32\msrxuku.exe
c:\windows\system32\msrzyvdz.exe
c:\windows\system32\mssaizx.exe
c:\windows\system32\mssbqkxm.exe
c:\windows\system32\mssbrsud.exe
c:\windows\system32\mssbs.exe
c:\windows\system32\mssbscqx.exe
c:\windows\system32\mssbvsn.exe
c:\windows\system32\mssbxp.exe
c:\windows\system32\mssdhyk.exe
c:\windows\system32\mssdjajx.exe
c:\windows\system32\mssdn.exe
c:\windows\system32\mssehbj.exe
c:\windows\system32\mssetaez.exe
c:\windows\system32\mssfcc.exe
c:\windows\system32\mssffn.exe
c:\windows\system32\mssgp.exe
c:\windows\system32\mssgqdt.exe
c:\windows\system32\msshe.exe
c:\windows\system32\msshk.exe
c:\windows\system32\msshnmu.exe
c:\windows\system32\msshp.exe
c:\windows\system32\msshptlt.exe
c:\windows\system32\msshy.exe
c:\windows\system32\msshyv.exe
c:\windows\system32\mssifb.exe
c:\windows\system32\msskhkoo.exe
c:\windows\system32\msskrrc.exe
c:\windows\system32\msslntmb.exe
c:\windows\system32\mssls.exe
c:\windows\system32\mssmeyla.exe
c:\windows\system32\mssmg.exe
c:\windows\system32\mssnzdru.exe
c:\windows\system32\mssog.exe
c:\windows\system32\mssoukn.exe
c:\windows\system32\mssov.exe
c:\windows\system32\mssox.exe
c:\windows\system32\mssqj.exe
c:\windows\system32\mssqseix.exe
c:\windows\system32\mssqsxk.exe
c:\windows\system32\mssrko.exe
c:\windows\system32\msssgchx.exe
c:\windows\system32\msssyz.exe
c:\windows\system32\msstpws.exe
c:\windows\system32\mssua.exe
c:\windows\system32\mssvcgbh.exe
c:\windows\system32\msswk.exe
c:\windows\system32\msswq.exe
c:\windows\system32\msswxfuq.exe
c:\windows\system32\mssxss.exe
c:\windows\system32\mssyiv.exe
c:\windows\system32\mssyryr.exe
c:\windows\system32\msszk.exe
c:\windows\system32\msszsl.exe
c:\windows\system32\msszztwj.exe
c:\windows\system32\mstalmqq.exe
c:\windows\system32\mstaqc.exe
c:\windows\system32\mstaqg.exe
c:\windows\system32\mstaseqi.exe
c:\windows\system32\mstatqq.exe
c:\windows\system32\mstavhj.exe
c:\windows\system32\mstbel.exe
c:\windows\system32\mstdacm.exe
c:\windows\system32\mstdaqxr.exe
c:\windows\system32\mstdco.exe
c:\windows\system32\mstdczox.exe
c:\windows\system32\mstdjqgs.exe
c:\windows\system32\mstelun.exe
c:\windows\system32\mstemx.exe
c:\windows\system32\mstevfhb.exe
c:\windows\system32\mstfmlk.exe
c:\windows\system32\mstghsh.exe
c:\windows\system32\mstgij.exe
c:\windows\system32\msthiusg.exe
c:\windows\system32\msthnmdj.exe
c:\windows\system32\msthoko.exe
c:\windows\system32\mstipg.exe
c:\windows\system32\mstirvdl.exe
c:\windows\system32\mstissu.exe
c:\windows\system32\mstix.exe
c:\windows\system32\mstjaa.exe
c:\windows\system32\mstjh.exe
c:\windows\system32\mstjmxg.exe
c:\windows\system32\mstjmz.exe
c:\windows\system32\mstjmzcz.exe
c:\windows\system32\mstjo.exe
c:\windows\system32\mstjph.exe
c:\windows\system32\mstjwq.exe
c:\windows\system32\mstjwtsu.exe
c:\windows\system32\mstkgbo.exe
c:\windows\system32\mstkx.exe
c:\windows\system32\mstlc.exe
c:\windows\system32\mstlcr.exe
c:\windows\system32\mstleshv.exe
c:\windows\system32\mstlpir.exe
c:\windows\system32\mstmcqwu.exe
c:\windows\system32\mstmm.exe
c:\windows\system32\mstms.exe
c:\windows\system32\mstmv.exe
c:\windows\system32\mstmydy.exe
c:\windows\system32\mstnhmoo.exe
c:\windows\system32\mstno.exe
c:\windows\system32\mstnxhl.exe
c:\windows\system32\mstoo.exe
c:\windows\system32\mstpdxh.exe
c:\windows\system32\mstqah.exe
c:\windows\system32\mstqd.exe
c:\windows\system32\mstqmvtb.exe
c:\windows\system32\mstqpqyc.exe
c:\windows\system32\mstrn.exe
c:\windows\system32\mstsaqti.exe
c:\windows\system32\mstshz.exe
c:\windows\system32\mstsr.exe
c:\windows\system32\mststq.exe
c:\windows\system32\msttrsc.exe
c:\windows\system32\mstttfcl.exe
c:\windows\system32\mstudth.exe
c:\windows\system32\mstukw.exe
c:\windows\system32\mstwlmv.exe
c:\windows\system32\mstwpa.exe
c:\windows\system32\mstxeebz.exe
c:\windows\system32\mstxmi.exe
c:\windows\system32\mstxo.exe
c:\windows\system32\mstxu.exe
c:\windows\system32\mstyf.exe
c:\windows\system32\mstzau.exe
c:\windows\system32\mstzf.exe
c:\windows\system32\mstzj.exe
c:\windows\system32\mstzm.exe
c:\windows\system32\mstzxvq.exe
c:\windows\system32\mstzykui.exe
c:\windows\system32\msuaed.exe
c:\windows\system32\msuah.exe
c:\windows\system32\msuam.exe
c:\windows\system32\msuaz.exe
c:\windows\system32\msubj.exe
c:\windows\system32\msubwcz.exe
c:\windows\system32\msuby.exe
c:\windows\system32\msubzih.exe
c:\windows\system32\msubzuyk.exe
c:\windows\system32\msuchio.exe
c:\windows\system32\msudfaex.exe
c:\windows\system32\msuduk.exe
c:\windows\system32\msuema.exe
c:\windows\system32\msufc.exe
c:\windows\system32\msufka.exe
c:\windows\system32\msugnmdt.exe
c:\windows\system32\msugpd.exe
c:\windows\system32\msugyybe.exe
c:\windows\system32\msuhbzug.exe
c:\windows\system32\msuhe.exe
c:\windows\system32\msuhtdq.exe
c:\windows\system32\msuhubw.exe
c:\windows\system32\msuiakjb.exe
c:\windows\system32\msuidqep.exe
c:\windows\system32\msuietkd.exe
c:\windows\system32\msuih.exe
c:\windows\system32\msuijezy.exe
c:\windows\system32\msuirdwa.exe
c:\windows\system32\msuizuos.exe
c:\windows\system32\msukb.exe
c:\windows\system32\msukeib.exe
c:\windows\system32\msuky.exe
c:\windows\system32\msukzvia.exe
c:\windows\system32\msuma.exe
c:\windows\system32\msumpn.exe
c:\windows\system32\msumzwid.exe
c:\windows\system32\msunaaa.exe
c:\windows\system32\msunir.exe
c:\windows\system32\msuodmyf.exe
c:\windows\system32\msuoujr.exe
c:\windows\system32\msuoyz.exe
c:\windows\system32\msupft.exe
c:\windows\system32\msupw.exe
c:\windows\system32\msupxj.exe
c:\windows\system32\msupxqge.exe
c:\windows\system32\msupzrj.exe
c:\windows\system32\msuqj.exe
c:\windows\system32\msuqu.exe
c:\windows\system32\msuqx.exe
c:\windows\system32\msurqzs.exe
c:\windows\system32\msurxa.exe
c:\windows\system32\msusasz.exe
c:\windows\system32\msusibv.exe
c:\windows\system32\msutdti.exe
c:\windows\system32\msuuqrh.exe
c:\windows\system32\msuuxul.exe
c:\windows\system32\msuvjaoh.exe
c:\windows\system32\msuvr.exe
c:\windows\system32\msuvzge.exe
c:\windows\system32\msuwcraz.exe
c:\windows\system32\msuwtpl.exe
c:\windows\system32\msuxe.exe
c:\windows\system32\msuxfz.exe
c:\windows\system32\msuxjp.exe
c:\windows\system32\msuxwhw.exe
c:\windows\system32\msuya.exe
c:\windows\system32\msuyejgo.exe
c:\windows\system32\msuylti.exe
c:\windows\system32\msuyms.exe
c:\windows\system32\msuyv.exe
c:\windows\system32\msuzmt.exe
c:\windows\system32\msuzrlp.exe
c:\windows\system32\msuzzxh.exe
c:\windows\system32\msvacshw.exe
c:\windows\system32\msvae.exe
c:\windows\system32\msvai.exe
c:\windows\system32\msvamfe.exe
c:\windows\system32\msvba.exe
c:\windows\system32\msvbgmz.exe
c:\windows\system32\msvbnmwe.exe
c:\windows\system32\msvbx.exe
c:\windows\system32\msvcb.exe
c:\windows\system32\msvcn.exe
c:\windows\system32\msvdnoxr.exe
c:\windows\system32\msvdonq.exe
c:\windows\system32\msvdwf.exe
c:\windows\system32\msveqaln.exe
c:\windows\system32\msvexkx.exe
c:\windows\system32\msvfb.exe
c:\windows\system32\msvfeqh.exe
c:\windows\system32\msvgs.exe
c:\windows\system32\msvhkgwv.exe
c:\windows\system32\msvhldxo.exe
c:\windows\system32\msvhm.exe
c:\windows\system32\msvhqk.exe
c:\windows\system32\msvhtfz.exe
c:\windows\system32\msvib.exe
c:\windows\system32\msviopn.exe
c:\windows\system32\msvje.exe
c:\windows\system32\msvjhl.exe
c:\windows\system32\msvkk.exe
c:\windows\system32\msvkndiz.exe
c:\windows\system32\msvkzqbq.exe
c:\windows\system32\msvlpq.exe
c:\windows\system32\msvlxbx.exe
c:\windows\system32\msvlyn.exe
c:\windows\system32\msvmbnt.exe
c:\windows\system32\msvmco.exe
c:\windows\system32\msvmj.exe
c:\windows\system32\msvnns.exe
c:\windows\system32\msvntxww.exe
c:\windows\system32\msvnzwoc.exe
c:\windows\system32\msvoxwtp.exe
c:\windows\system32\msvpc.exe
c:\windows\system32\msvpf.exe
c:\windows\system32\msvpnh.exe
c:\windows\system32\msvpnyx.exe
c:\windows\system32\msvpocn.exe
c:\windows\system32\msvpr.exe
c:\windows\system32\msvpt.exe
c:\windows\system32\msvpwsa.exe
c:\windows\system32\msvqafnf.exe
c:\windows\system32\msvraz.exe
c:\windows\system32\msvrdo.exe
c:\windows\system32\msvreh.exe
c:\windows\system32\msvrlyv.exe
c:\windows\system32\msvrna.exe
c:\windows\system32\msvrysd.exe
c:\windows\system32\msvsd.exe
c:\windows\system32\msvseotu.exe
c:\windows\system32\msvss.exe
c:\windows\system32\msvstc.exe
c:\windows\system32\msvsw.exe
c:\windows\system32\msvswjp.exe
c:\windows\system32\msvtb.exe
c:\windows\system32\msvtqtie.exe
c:\windows\system32\msvubc.exe
c:\windows\system32\msvuhk.exe
c:\windows\system32\msvuvmb.exe
c:\windows\system32\msvwfv.exe
c:\windows\system32\msvwge.exe
c:\windows\system32\msvwzn.exe
c:\windows\system32\msvxvc.exe
c:\windows\system32\msvys.exe
c:\windows\system32\msvzht.exe
c:\windows\system32\msvzrcus.exe
c:\windows\system32\mswag.exe
c:\windows\system32\mswak.exe
c:\windows\system32\mswbpixb.exe
c:\windows\system32\mswcbcdl.exe
c:\windows\system32\mswcenwb.exe
c:\windows\system32\mswck.exe
c:\windows\system32\mswdef.exe
c:\windows\system32\mswdew.exe
c:\windows\system32\mswds.exe
c:\windows\system32\mswdw.exe
c:\windows\system32\mswemvh.exe
c:\windows\system32\mswerx.exe
c:\windows\system32\mswfs.exe
c:\windows\system32\mswgbxd.exe
c:\windows\system32\mswgkk.exe
c:\windows\system32\mswgs.exe
c:\windows\system32\mswhan.exe
c:\windows\system32\mswhr.exe
c:\windows\system32\mswhx.exe
c:\windows\system32\mswibd.exe
c:\windows\system32\mswimo.exe
c:\windows\system32\mswiymk.exe
c:\windows\system32\mswiyquk.exe
c:\windows\system32\mswjek.exe
c:\windows\system32\mswjkyr.exe
c:\windows\system32\mswjpbzh.exe
c:\windows\system32\mswjso.exe
c:\windows\system32\mswjug.exe
c:\windows\system32\mswjvy.exe
c:\windows\system32\mswkhb.exe
c:\windows\system32\mswkik.exe
c:\windows\system32\mswkl.exe
c:\windows\system32\mswlcsy.exe
c:\windows\system32\mswlhn.exe
c:\windows\system32\mswlioc.exe
c:\windows\system32\mswmt.exe
c:\windows\system32\mswmwxzc.exe
c:\windows\system32\mswngyi.exe
c:\windows\system32\mswnoe.exe
c:\windows\system32\mswnopd.exe
c:\windows\system32\mswnpi.exe
c:\windows\system32\mswnpokd.exe
c:\windows\system32\mswnro.exe
c:\windows\system32\mswnvsn.exe
c:\windows\system32\mswoclo.exe
c:\windows\system32\mswofgr.exe
c:\windows\system32\mswogu.exe
c:\windows\system32\mswox.exe
c:\windows\system32\mswozbd.exe
c:\windows\system32\mswpt.exe
c:\windows\system32\mswqduh.exe
c:\windows\system32\mswqp.exe
c:\windows\system32\mswquv.exe
c:\windows\system32\mswqw.exe
c:\windows\system32\mswrkwa.exe
c:\windows\system32\mswrq.exe
c:\windows\system32\mswsca.exe
c:\windows\system32\mswszgw.exe
c:\windows\system32\mswte.exe
c:\windows\system32\mswtmx.exe
c:\windows\system32\mswtngp.exe
c:\windows\system32\mswubwvi.exe
c:\windows\system32\mswuf.exe
c:\windows\system32\mswurb.exe
c:\windows\system32\mswvmbhq.exe
c:\windows\system32\mswwifq.exe
c:\windows\system32\mswwqvp.exe
c:\windows\system32\mswxe.exe
c:\windows\system32\mswxgmy.exe
c:\windows\system32\mswydr.exe
c:\windows\system32\mswyjw.exe
c:\windows\system32\mswyv.exe
c:\windows\system32\mswyxgnb.exe
c:\windows\system32\mswzywog.exe
c:\windows\system32\msxafut.exe
c:\windows\system32\msxbfovm.exe
c:\windows\system32\msxbgk.exe
c:\windows\system32\msxcoahy.exe
c:\windows\system32\msxct.exe
c:\windows\system32\msxdcj.exe
c:\windows\system32\msxdg.exe
c:\windows\system32\msxdk.exe
c:\windows\system32\msxdpa.exe
c:\windows\system32\msxdry.exe
c:\windows\system32\msxdy.exe
c:\windows\system32\msxega.exe
c:\windows\system32\msxej.exe
c:\windows\system32\msxepytu.exe
c:\windows\system32\msxfijs.exe
c:\windows\system32\msxggd.exe
c:\windows\system32\msxgnp.exe
c:\windows\system32\msxgui.exe
c:\windows\system32\msxgyh.exe
c:\windows\system32\msxhphk.exe
c:\windows\system32\msxhu.exe
c:\windows\system32\msxhzzz.exe
c:\windows\system32\msxia.exe
c:\windows\system32\msxitz.exe
c:\windows\system32\msxjgkkk.exe
c:\windows\system32\msxjjv.exe
c:\windows\system32\msxjqwoy.exe
c:\windows\system32\msxjvds.exe
c:\windows\system32\msxkajk.exe
c:\windows\system32\msxkxv.exe
c:\windows\system32\msxlczg.exe
c:\windows\system32\msxldgxp.exe
c:\windows\system32\msxln.exe
c:\windows\system32\msxltj.exe
c:\windows\system32\msxmkdbw.exe
c:\windows\system32\msxmx.exe
c:\windows\system32\msxnat.exe
c:\windows\system32\msxnh.exe
c:\windows\system32\msxnqgsv.exe
c:\windows\system32\msxnrq.exe
c:\windows\system32\msxny.exe
c:\windows\system32\msxobwpd.exe
c:\windows\system32\msxodqf.exe
c:\windows\system32\msxpb.exe
c:\windows\system32\msxpyi.exe
c:\windows\system32\msxpzxwa.exe
c:\windows\system32\msxrlq.exe
c:\windows\system32\msxsfxli.exe
c:\windows\system32\msxsz.exe
c:\windows\system32\msxtfh.exe
c:\windows\system32\msxur.exe
c:\windows\system32\msxusyy.exe
c:\windows\system32\msxvjph.exe
c:\windows\system32\msxvppuv.exe
c:\windows\system32\msxwgdjf.exe
c:\windows\system32\msxwlypm.exe
c:\windows\system32\msxwoc.exe
c:\windows\system32\msxwpez.exe
c:\windows\system32\msxxb.exe
c:\windows\system32\msxxu.exe
c:\windows\system32\msxyafoe.exe
c:\windows\system32\msxyi.exe
c:\windows\system32\msxyohmx.exe
c:\windows\system32\msxywucz.exe
c:\windows\system32\msxyzob.exe
c:\windows\system32\msxzsli.exe
c:\windows\system32\msxzxrj.exe
c:\windows\system32\msxzz.exe
c:\windows\system32\msxzzkcp.exe
c:\windows\system32\msyaabth.exe
c:\windows\system32\msyahlv.exe
c:\windows\system32\msybb.exe
c:\windows\system32\msyblh.exe
c:\windows\system32\msybm.exe
c:\windows\system32\msybmve.exe
c:\windows\system32\msybroox.exe
c:\windows\system32\msybutz.exe
c:\windows\system32\msyckand.exe
c:\windows\system32\msyclno.exe
c:\windows\system32\msyclnvq.exe
c:\windows\system32\msycoxn.exe
c:\windows\system32\msycpvvb.exe
c:\windows\system32\msycrm.exe
c:\windows\system32\msycypdl.exe
c:\windows\system32\msyddbo.exe
c:\windows\system32\msyde.exe
c:\windows\system32\msydrzay.exe
c:\windows\system32\msydxixs.exe
c:\windows\system32\msyebymg.exe
c:\windows\system32\msyedxd.exe
c:\windows\system32\msyfaj.exe
c:\windows\system32\msyfp.exe
c:\windows\system32\msyfqu.exe
c:\windows\system32\msyfvj.exe
c:\windows\system32\msygh.exe
c:\windows\system32\msyglu.exe
c:\windows\system32\msyha.exe
c:\windows\system32\msyharpq.exe
c:\windows\system32\msyhdj.exe
c:\windows\system32\msyhifez.exe
c:\windows\system32\msyiwahf.exe
c:\windows\system32\msyjoicv.exe
c:\windows\system32\msyjsum.exe
c:\windows\system32\msyjsymo.exe
c:\windows\system32\msyjvbf.exe
c:\windows\system32\msyjwr.exe
c:\windows\system32\msyllua.exe
c:\windows\system32\msymn.exe
c:\windows\system32\msynik.exe
c:\windows\system32\msyomifu.exe
c:\windows\system32\msyoskyv.exe
c:\windows\system32\msyotuvi.exe
c:\windows\system32\msypmych.exe
c:\windows\system32\msypozgp.exe
c:\windows\system32\msyppg.exe
c:\windows\system32\msyqgir.exe
c:\windows\system32\msyqi.exe
c:\windows\system32\msyqivz.exe
c:\windows\system32\msyqlel.exe
c:\windows\system32\msyrfi.exe
c:\windows\system32\msyrgi.exe
c:\windows\system32\msyspsn.exe
c:\windows\system32\msytkv.exe
c:\windows\system32\msyuhehw.exe
c:\windows\system32\msyuk.exe
c:\windows\system32\msyum.exe
c:\windows\system32\msyurzp.exe
c:\windows\system32\msyve.exe
c:\windows\system32\msyvg.exe
c:\windows\system32\msyvq.exe
c:\windows\system32\msyvw.exe
c:\windows\system32\msywalg.exe
c:\windows\system32\msywc.exe
c:\windows\system32\msywri.exe
c:\windows\system32\msyxaezo.exe
c:\windows\system32\msyxkzl.exe
c:\windows\system32\msyxpvnu.exe
c:\windows\system32\msyxt.exe
c:\windows\system32\msyxx.exe
c:\windows\system32\msyyf.exe
c:\windows\system32\msyzp.exe
c:\windows\system32\mszaf.exe
c:\windows\system32\mszap.exe
c:\windows\system32\mszbbzoy.exe
c:\windows\system32\mszcc.exe
c:\windows\system32\mszce.exe
c:\windows\system32\mszcm.exe
c:\windows\system32\mszct.exe
c:\windows\system32\mszdbud.exe
c:\windows\system32\mszdkuq.exe
c:\windows\system32\mszdun.exe
c:\windows\system32\mszepzb.exe
c:\windows\system32\mszes.exe
c:\windows\system32\mszetjhj.exe
c:\windows\system32\mszfnl.exe
c:\windows\system32\mszfqng.exe
c:\windows\system32\mszfs.exe
c:\windows\system32\mszgxs.exe
c:\windows\system32\mszhjujx.exe
c:\windows\system32\mszhx.exe
c:\windows\system32\mszhz.exe
c:\windows\system32\mszirrvn.exe
c:\windows\system32\msziuqgf.exe
c:\windows\system32\mszix.exe
c:\windows\system32\mszixxs.exe
c:\windows\system32\mszjhnmt.exe
c:\windows\system32\mszjqcoi.exe
c:\windows\system32\mszkfgwb.exe
c:\windows\system32\mszkie.exe
c:\windows\system32\mszkmcy.exe
c:\windows\system32\mszmeam.exe
c:\windows\system32\mszmvz.exe
c:\windows\system32\msznqpru.exe
c:\windows\system32\msznqq.exe
c:\windows\system32\mszohez.exe
c:\windows\system32\mszohnl.exe
c:\windows\system32\mszonk.exe
c:\windows\system32\mszpg.exe
c:\windows\system32\mszpj.exe
c:\windows\system32\mszpn.exe
c:\windows\system32\mszppavk.exe
c:\windows\system32\mszpsqlt.exe
c:\windows\system32\mszqb.exe
c:\windows\system32\mszqh.exe
c:\windows\system32\mszrovch.exe
c:\windows\system32\mszrpkdu.exe
c:\windows\system32\mszrtnxp.exe
c:\windows\system32\mszsalec.exe
c:\windows\system32\msztpa.exe
c:\windows\system32\mszuijje.exe
c:\windows\system32\mszvrgqp.exe
c:\windows\system32\mszwtds.exe
c:\windows\system32\mszxlq.exe
c:\windows\system32\mszxt.exe
c:\windows\system32\mszxzoe.exe
c:\windows\system32\mszybmu.exe
c:\windows\system32\mszyduxc.exe
c:\windows\system32\mszygi.exe
c:\windows\system32\mszyysv.exe
c:\windows\system32\mszzetp.exe
c:\windows\system32\mszzk.exe
c:\windows\system32\mszzvr.exe
c:\windows\system32\mszzxz.exe
c:\windows\system32\mszzzr.exe
c:\windows\system32\resdll.dll
c:\windows\system32\sopidkc.exe
c:\windows\system32\tmp.reg
c:\windows\system32\UACdmjucqomfi.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACkvyvwnjucs.dll
c:\windows\system32\UACmorxukauiw.dat
c:\windows\system32\UACpadtkslwno.dll
c:\windows\system32\UACrdsmbvyyoi.dll
c:\windows\system32\UACrkrnstkvhp.dll
c:\windows\system32\wiawow32.sys
c:\windows\system32\wiwow64.exe
c:\windows\TEMP\mpj68825.dll
c:\windows\TEMP\mta54283.dll
c:\windows\umeqinoqoyejamiy.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_UACd.sys
——-\Legacy_6TO4
——-\Legacy_IAS
——-\Legacy_MSNCACHE
——-\Legacy_MYWEBSEARCHSERVICE
——-\Legacy_SOPIDKC
——-\Service_6to4
——-\Service_Ias
——-\Service_msncache
——-\Service_MyWebSearchService
——-\Service_sopidkc
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-31 )))))))))))))))))))))))))))))))
.
2009-07-31 05:21 . 2009-07-31 05:21 3285 —-a-w- c:\windows\owexujesazuku.dll
2009-07-31 04:52 . 2009-07-31 04:53 ——– d-s—w- C:\Combo-Fix
2009-07-31 04:21 . 2009-07-31 04:21 3269 —-a-w- c:\windows\ijipahal.dll
2009-07-31 03:16 . 2009-07-31 03:16 3269 —-a-w- c:\windows\udegupiditem.dll
2009-07-31 01:10 . 2009-07-31 01:10 3285 —-a-w- c:\windows\ifatupekamos.dll
2009-07-30 23:04 . 2009-07-30 23:04 3277 —-a-w- c:\windows\izuhadajakucuraq.dll
2009-07-30 21:29 . 2009-07-30 21:29 3269 —-a-w- c:\windows\agodahig.dll
2009-07-30 21:01 . 2009-07-30 21:01 3277 —-a-w- c:\windows\eciwesoz.dll
2009-07-30 20:21 . 2009-07-30 20:21 3269 —-a-w- c:\windows\ojuvegubelix.dll
2009-07-30 18:13 . 2009-07-30 18:13 3285 —-a-w- c:\windows\efosaxoga.dll
2009-07-30 17:27 . 2009-07-30 17:27 3269 —-a-w- c:\windows\itomapesepe.dll
2009-07-30 17:04 . 2009-07-30 17:04 3277 —-a-w- c:\windows\eyobuhuwonez.dll
2009-07-30 16:21 . 2009-07-30 16:21 3277 —-a-w- c:\windows\ijoxovab.dll
2009-07-30 15:22 . 2009-07-30 15:22 3269 —-a-w- c:\windows\afayayiyohuyaga.dll
2009-07-30 06:39 . 2009-07-30 06:39 3277 —-a-w- c:\windows\oruxezoyipo.dll
2009-07-30 06:29 . 2009-07-30 06:29 3293 —-a-w- c:\windows\aluwuhuq.dll
2009-07-30 06:22 . 2009-07-30 06:22 3269 —-a-w- c:\windows\ugubojebuqagetey.dll
2009-07-30 04:16 . 2009-07-30 04:16 3285 —-a-w- c:\windows\uyefuheli.dll
2009-07-30 03:36 . 2009-07-30 03:36 3285 —-a-w- c:\windows\edayetas.dll
2009-07-29 22:15 . 2009-07-29 22:15 3277 —-a-w- c:\windows\ocopuveb.dll
2009-07-29 21:24 . 2009-07-29 21:24 3277 —-a-w- c:\windows\exasufol.dll
2009-07-29 20:44 . 2009-07-29 20:44 3293 —-a-w- c:\windows\etadohugili.dll
2009-07-29 18:06 . 2009-07-29 18:06 3277 —-a-w- c:\windows\icuqilaquvacax.dll
2009-07-29 17:31 . 2009-07-29 17:31 3165 —-a-w- c:\windows\ewowofehoc.dll
2009-07-29 17:01 . 2009-07-29 17:01 3293 —-a-w- c:\windows\obebebaguwimu.dll
2009-07-29 16:26 . 2009-07-29 16:26 3269 —-a-w- c:\windows\awawoluw.dll
2009-07-29 07:59 . 2009-07-29 07:59 3277 —-a-w- c:\windows\afiyodege.dll
2009-07-29 07:03 . 2009-07-29 07:03 3293 —-a-w- c:\windows\afiyacik.dll
2009-07-29 06:50 . 2009-07-29 06:50 3293 —-a-w- c:\windows\ohajijohapuh.dll
2009-07-29 06:30 . 2009-07-29 06:30 3301 —-a-w- c:\windows\owiquqis.dll
2009-07-29 06:10 . 2009-07-29 06:10 3285 —-a-w- c:\windows\axipilid.dll
2009-07-29 05:20 . 2009-07-29 05:20 3269 —-a-w- c:\windows\iwekudat.dll
2009-07-29 04:36 . 2009-07-29 04:36 3309 —-a-w- c:\windows\ogadopumamajux.dll
2009-07-29 04:20 . 2009-07-29 04:20 3285 —-a-w- c:\windows\oridojodoh.dll
2009-07-29 03:56 . 2009-07-29 03:56 3261 —-a-w- c:\windows\ihofiwupuc.dll
2009-07-29 03:26 . 2009-07-29 03:26 3285 —-a-w- c:\windows\ixibizebuf.dll
2009-07-29 00:47 . 2009-07-29 00:47 3269 —-a-w- c:\windows\ededibotaxar.dll
2009-07-29 00:37 . 2009-07-29 00:37 3277 —-a-w- c:\windows\uqugafekute.dll
2009-07-28 23:56 . 2009-07-28 23:56 3285 —-a-w- c:\windows\otamuyosamav.dll
2009-07-28 23:06 . 2009-07-28 23:06 3301 —-a-w- c:\windows\abewaruyumogavim.dll
2009-07-28 22:22 . 2009-07-28 22:22 3261 —-a-w- c:\windows\imecuxiq.dll
2009-07-28 21:43 . 2009-07-28 21:43 3293 —-a-w- c:\windows\awufuwejatazaleb.dll
2009-07-28 19:37 . 2009-07-28 19:37 3293 —-a-w- c:\windows\edibufisawanulam.dll
2009-07-28 18:33 . 2009-07-28 18:33 3269 —-a-w- c:\windows\exovadazaderirif.dll
2009-07-28 16:27 . 2009-07-28 16:27 3285 —-a-w- c:\windows\upisavadebib.dll
2009-07-28 15:37 . 2009-07-28 15:37 3293 —-a-w- c:\windows\obaferab.dll
2009-07-28 15:31 . 2009-07-28 15:31 152576 —-a-w- c:\documents and settings\My Computer\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-07-28 07:38 . 2009-07-28 07:38 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple Computer
2009-07-28 07:38 . 2009-07-28 07:38 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2009-07-28 07:01 . 2009-07-28 07:01 3309 —-a-w- c:\windows\ojozehobiq.dll
2009-07-28 06:43 . 2009-07-28 06:43 3269 —-a-w- c:\windows\ahobimon.dll
2009-07-28 05:52 . 2009-07-28 05:52 3277 —-a-w- c:\windows\ohibopitucigenog.dll
2009-07-28 05:29 . 2009-07-28 05:29 ——– d—–w- C:\_OTM
2009-07-28 05:16 . 2009-07-28 05:16 3277 —-a-w- c:\windows\exacikotadoq.dll
2009-07-28 04:55 . 2009-07-28 04:55 3261 —-a-w- c:\windows\ocubicitaqun.dll
2009-07-28 03:04 . 2009-07-28 03:04 3285 —-a-w- c:\windows\esumobelisuz.dll
2009-07-28 01:57 . 2009-07-28 01:56 102664 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2009-07-28 01:55 . 2009-07-28 02:03 ——– d—–w- c:\documents and settings\My Computer\.housecall6.6
2009-07-28 01:52 . 2009-07-28 01:52 3301 —-a-w- c:\windows\exeqobacagayus.dll
2009-07-28 01:37 . 2009-07-28 01:37 3293 —-a-w- c:\windows\uwohinal.dll
2009-07-28 01:32 . 1998-03-26 23:25 12800 —-a-w- c:\windows\system\Wing32.dll
2009-07-28 01:32 . 1996-02-14 22:01 92208 —-a-w- c:\windows\system32\Wing.dll
2009-07-28 01:31 . 2009-07-28 01:31 ——– d—–w- c:\program files\Enigma Software Group
2009-07-28 01:27 . 2009-07-28 01:27 3269 —-a-w- c:\windows\ojibexuyiru.dll
2009-07-28 00:56 . 2009-07-28 00:56 3293 —-a-w- c:\windows\uforatiqefa.dll
2009-07-28 00:22 . 2009-07-28 00:22 3269 —-a-w- c:\windows\inugohewat.dll
2009-07-27 23:41 . 2009-07-27 23:41 552 —-a-w- c:\windows\system32\d3d8caps.dat
2009-07-27 23:28 . 2009-07-27 23:28 ——– d—–w- C:\VundoFix Backups
2009-07-27 23:10 . 2009-07-27 23:10 3293 —-a-w- c:\windows\izabevaxitig.dll
2009-07-27 22:50 . 2009-07-27 22:50 3285 —-a-w- c:\windows\ufugohew.dll
2009-07-27 22:21 . 2009-07-27 22:21 3285 —-a-w- c:\windows\eraducenafidaco.dll
2009-07-27 21:39 . 2009-07-28 05:28 4 —-a-w- c:\windows\system32\bincd32.dat
2009-07-27 21:22 . 2009-07-31 04:25 120 —-a-w- c:\windows\Ctuwihuvuwox.dat
2009-07-27 21:18 . 2009-07-27 21:18 31232 —-a-w- c:\windows\system32\wingenocx.dll
2009-07-27 21:15 . 2009-07-27 21:15 ——– d—–w- c:\documents and settings\My Computer\Local Settings\Application Data\{AF00CE25-C84A-4B91-95A8-107F77DCF9EE}
2009-07-27 21:03 . 2009-07-27 21:05 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\14357344
2009-07-27 21:03 . 2009-07-28 00:29 64 —-a-w- c:\windows\ppp4.dat
2009-07-27 21:03 . 2009-07-28 00:29 3 —-a-w- c:\windows\ppp3.dat
2009-07-27 21:03 . 2009-07-27 21:03 36 —-a-w- c:\windows\system32\sysnet.dat
2009-07-27 21:03 . 2009-07-27 21:03 45056 —-a-w- C:\uynrr.exe
2009-07-27 00:48 . 2009-07-27 00:48 ——– d—–w- c:\documents and settings\My Computer\Application Data\Jane s Hotel
2009-07-27 00:48 . 2009-07-27 00:48 ——– d—–w- c:\program files\Realore
2009-07-17 07:14 . 2009-07-17 07:14 ——– d—–w- c:\program files\MSECache
2009-07-02 05:56 . 2009-07-02 05:56 ——– d—–w- c:\program files\XCOM Terror from the Deep
2009-07-02 05:55 . 2009-07-02 05:55 ——– d—–w- C:\CWE
2009-07-02 05:45 . 2009-07-02 05:56 ——– d—–w- c:\documents and settings\My Computer\Application Data\GetRightToGo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-28 15:52 . 2009-03-24 04:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-28 15:32 . 2008-10-30 08:31 ——– d—–w- c:\program files\Java
2009-07-28 15:26 . 2008-09-19 21:10 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\avg8
2009-07-27 04:00 . 2008-10-25 22:17 ——– d—a-w- c:\docume~1\ALLUSE~1\APPLIC~1\TEMP
2009-07-26 16:02 . 2008-09-19 21:10 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-24 00:33 . 2008-11-27 22:10 ——– d—–w- c:\documents and settings\My Computer\Application Data\Azureus
2009-07-24 00:30 . 2008-12-11 01:57 ——– d—–w- c:\program files\Mango Earth
2009-07-22 10:00 . 2009-06-27 05:18 ——– d—–w- c:\program files\Microsoft Silverlight
2009-07-20 06:11 . 2008-11-27 22:10 ——– d—–w- c:\program files\Mininova-Vuze
2009-07-17 23:20 . 2006-06-19 04:25 57328 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-17 06:59 . 2008-10-25 17:12 ——– d—–w- c:\program files\Microsoft Works
2009-07-16 22:57 . 2008-10-19 05:54 ——– d—–w- c:\program files\Common Files\Adobe
2009-07-13 20:36 . 2009-03-24 04:15 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 20:36 . 2009-03-24 04:15 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-12 23:02 . 2008-09-19 19:31 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-12 23:02 . 2008-11-18 03:15 513 —-a-w- c:\windows\EReg515.dat
2009-07-12 23:01 . 2008-11-18 03:14 ——– d—–w- c:\program files\Disney Interactive
2009-07-11 22:13 . 2008-10-30 08:32 ——– d—–w- c:\program files\freecol
2009-07-09 23:19 . 2008-11-27 23:18 ——– d—–w- c:\program files\Puppy Luv
2009-07-02 05:20 . 2008-10-18 08:04 43520 —-a-w- c:\windows\system32\CmdLineExt03.dll
2009-06-29 17:52 . 2009-06-29 17:52 297 —-a-w- c:\windows\EReg072.dat
2009-06-29 17:51 . 2009-06-29 17:51 ——– d—–w- c:\program files\Firaxis Games
2009-06-29 16:12 . 2006-06-17 09:23 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2008-09-19 17:42 78336 ——w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2008-09-19 17:42 17408 ——w- c:\windows\system32\corpol.dll
2009-06-27 17:48 . 2009-06-27 17:47 ——– d—–w- c:\program files\Canon
2009-06-27 17:46 . 2009-06-27 17:46 ——– d—–w- c:\program files\Common Files\Canon
2009-06-19 15:59 . 2008-09-19 21:10 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-18 23:11 . 2009-06-12 16:58 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\AVG Security Toolbar
2009-06-18 01:08 . 2008-11-07 17:45 ——– d—–w- c:\program files\The Learning Company
2009-06-16 14:36 . 2006-06-17 09:23 119808 ——w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2006-06-17 09:23 81920 ——w- c:\windows\system32\fontsub.dll
2009-06-13 03:37 . 2009-06-13 03:35 ——– d—–w- c:\documents and settings\My Computer\Application Data\Move Networks
2009-06-12 19:51 . 2009-06-12 19:51 ——– d—–w- c:\documents and settings\My Computer\Application Data\DivX
2009-06-12 19:50 . 2008-11-28 16:01 10684866 —-a-w- c:\documents and settings\My Computer\Application Data\Azureus\plugins\azump\mplayer.exe
2009-06-12 19:50 . 2009-06-12 19:50 ——– d—–w- c:\program files\DivX
2009-06-12 19:50 . 2009-06-12 19:49 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-06-12 19:48 . 2008-11-27 22:09 ——– d—–w- c:\program files\Vuze
2009-06-12 16:58 . 2009-06-12 16:58 ——– d—–w- c:\documents and settings\LocalService\Application Data\AVGTOOLBAR
2009-06-11 20:47 . 2009-06-11 20:47 ——– d—–w- c:\program files\Coupons
2009-06-07 06:22 . 2008-09-19 21:10 ——– d—–w- c:\documents and settings\My Computer\Application Data\AVGTOOLBAR
2009-06-07 06:16 . 2009-06-01 06:49 ——– d—–w- c:\program files\Windows Media Connect 2
2009-06-05 21:08 . 2008-10-26 23:03 ——– d—–w- c:\program files\Hasbro Interactive
2009-06-03 19:09 . 2006-06-17 09:23 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-06-01 16:01 . 2009-04-27 20:23 ——– d—–w- c:\documents and settings\My Computer\Application Data\ZoomBrowser EX
2009-06-01 15:56 . 2009-06-01 15:56 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\ZoomBrowser
2009-05-19 17:03 . 2008-09-19 21:10 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-05-19 17:03 . 2008-09-19 21:10 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-07 15:32 . 2008-09-19 17:43 345600 ——w- c:\windows\system32\localspl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-26 17:36 1008896 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]
2009-07-20 06:12 2215960 —-a-w- c:\program files\Mininova-Vuze\tbMin0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{d51d388b-f5dc-471a-a1ce-5e2d671091c0}"= "c:\program files\Mininova-Vuze\tbMin0.dll" [2009-07-20 2215960]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]
[HKEY_CLASSES_ROOT\clsid\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D51D388B-F5DC-471A-A1CE-5E2D671091C0}"= "c:\program files\Mininova-Vuze\tbMin0.dll" [2009-07-20 2215960]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]
[HKEY_CLASSES_ROOT\clsid\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-25 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-25 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-25 114688]
"IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" [2006-12-06 9138176]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-10 153136]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-12-22 67752]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"SetDefPrt"="c:\program files\Brother\Brmfl04a\BrStDvPt.exe" [2004-05-25 49152]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 851968]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"MSxmlHpr"="c:\windows\system32\msxm192z.dll" [2004-08-18 28672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
c:\documents and settings\My Computer\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2009-1-10 225280]
PowerReg Scheduler.exe [2009-3-31 189952]
c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
ImageMixer 3 SE Camera Monitor for SD.lnk - c:\program files\PIXELA\ImageMixer 3 SE for SD\CameraMonitor.exe [2009-5-31 253952]
Status Monitor.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2008-10-30 815104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-19 17:03 11952 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Adobe\\Photoshop Elements 5.0\\AdobePhotoshopElementsMediaServer.exe"=
"c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization 4 Gold\\Civilization4.exe"=
"c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization 4 Gold\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization 4 Gold\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization 4 Gold\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\old harddrive (G)\\old program files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Netscape\\Netscape\\Netscp.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Infogrames Interactive\\Civilization III\\CIV3PTW\\Civilization3X.exe"=
"c:\\Documents and Settings\\My Computer\\Desktop\\games\\Steam\\steamapps\\common\\spaceempiresv\\SE5\\SE5.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1583:TCP"= 1583:TCP:Pervasive DBEngine
"3351:TCP"= 3351:TCP:Pervasive DBEngine
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/19/2008 2:10 PM 335752]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/19/2008 2:10 PM 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [9/19/2008 2:15 PM 907032]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/19/2008 2:15 PM 298776]
S3 gAGP440p;gAGP440p;\??\c:\docume~1\MYCOMP~1\LOCALS~1\Temp\gAGP440p.sys –> c:\docume~1\MYCOMP~1\LOCALS~1\Temp\gAGP440p.sys [?]
S3 MOSUMAC;USB-Ethernet Driver;c:\windows\system32\drivers\MOSUMAC.SYS [9/19/2008 12:16 PM 40448]
S3 WPEServ;soft Xpansion Print2Document;c:\program files\Common Files\WPE\wpeserv.exe [9/19/2008 2:06 PM 323584]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-*{d51d388b-f5dc-471a-a1ce-5e2d671091c0} - (no file)
HKLM-Run-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL
HKLM-Run-Jgovixejower - c:\windows\umeqinoqoyejamiy.dll
HKLM-Run-SigmatelSysTrayApp - sttray.exe
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: &Search;
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{722FE9B2-6895-42D9-9984-F4CB26616023} - {722FE9B2-6895-42D9-9984-F4CB26616023} - c:\program files\Cosmi\Perfect PDF Creator\pdfshell.dll
FF - ProfilePath - c:\docume~1\MYCOMP~1\APPLIC~1\Mozilla\Firefox\Profiles\uor6kyr0.default\
FF - prefs.js: browser.startup.homepage - hxxp://lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\My Computer\Application Data\Mozilla\Firefox\Profiles\uor6kyr0.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\old harddrive (g)\old program files\Mozilla Firefox\plugins\NPcol305.dll
FF - plugin: c:\old harddrive (g)\old program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\old harddrive (g)\old program files\Mozilla Firefox\plugins\NPMyWebS.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
FF - HiddenExtension: XUL Cache: {AF00CE25-C84A-4B91-95A8-107F77DCF9EE} - c:\documents and settings\My Computer\Local Settings\Application Data\{AF00CE25-C84A-4B91-95A8-107F77DCF9EE}
—- FIREFOX POLICIES —-
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\old harddrive (g)\old program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-30 23:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(3628)
c:\windows\system32\WININET.dll
c:\windows\system32\msxm192z.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\brss01a.exe
c:\program files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\Brmfrmps.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\ehome\mcrdsvc.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
c:\program files\AVG\AVG8\avgtray.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-07-31 23:21 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-31 06:21
Pre-Run: 166,902,882,304 bytes free
Post-Run: 166,891,724,800 bytes free
1612 — E O F — 2009-07-30 15:15