This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

winlogon error messages [Closed]

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer (Laptop) seems to be infected with a virus. It has defaulted my homepage to qseach.com, it doesn'nt allow me to run any antivirus programs, does'nt allow me to open Add/Remove Program on my control panel, gives a winlogon error message continuosly whenever I open my internet explorer. can you please suggest how I can get rid of this virus?
Hello and welcome to What The Tech.

I am currently assessing your situation and will be back with a fix for your problem as soon as possible.

Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this, click Options, then click Track this topic. Please select Immediate Email Notification for the topic subscription, then click Proceed.

Please be patient with me during this time.

Meanwhile, please make a reply to this topic to acknowledge that you have read this and is still with me to tackle the problem until the end. If I do not get any response within 3 days, this topic will be closed.
Hello sunoly :),

Welcome to What The Tech. I am Jack&Jill, and I will be helping you out.

Before we go further, there are a few things that I would like to make clear so that we are share the same understanding.
  • Please observe and follow these Terms of Use and the rules in Are you Infected? Getting Started: How To Get Help.
  • Any advice is for your computer only and is taken at your own risk. Fixes sometimes will cause unexpected results, but I will do my best to assist you.
  • Please read the instructions carefully and follow them closely, in the order they are presented to you.
  • If you have any doubts or problems during the fix, please stop and ask.
  • All the tools that I will ask you to download and use are safe. Please allow if prompted by any of your security softwares.
  • Do not use or run any malware cleaning tools without supervision as they may cause more harm if improperly used.
  • Refrain from installing any new programs except those that I request during the fix to prevent interference to my diagnosis of the problem.
  • Lack of malware symptoms does not mean your computer is clean. Stick to this topic until I give the All Clear.
  • If you do not reply within 3 days, this topic will be closed.
If you are agreeable to the above, then everything should go smoothly :) . We may begin.

——————–

Please download DDS from one of the links below and save it to your desktop.

Link 1
Link 2
Link 3

Please disable any script blocker before running DDS.

  • Double click on the dds file and a command window will appear. This is normal.
  • Shortly after, two logs will appear:
    • DDS.txt
    • Attach.txt
  • A window will open instructing you to save and post the logs.
  • Save the logs to a convenient location such as your desktop.
  • Copy the contents of both logs and post them in your next reply.
——————–

Please download aswMBR and save it to your desktop. Click here.
  • Please disable your real time protection of any Antivirus, Antispyware or Antimalware programs temporarily. They will interfere and may cause unexpected results.
  • If you need help to disable your protection programs see here and here.
  • Double click the aswMBR.exe file to run it. If you are asked to download an antivirus software, please allow.
  • Click on the Scan button to start. The program will launch a scan.
  • When done, you will see Scan finished successfully. Please click on Save log and save the file to your desktop.
  • Please post the contents of the log in your next reply.
——————–

Please post back:
1. the DDS logs (DDS.txt and Attach.txt)
2. aswMBR log
Attached is the aswMBR log: aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-11-24 18:56:27 —————————– 18:56:27.953 OS Version: Windows 5.1.2600 Service Pack 3 18:56:27.953 Number of processors: 2 586 0xF06 18:56:27.953 ComputerName: PC100173046818 UserName: Sunita 18:56:29.015 Initialize success 18:57:48.390 AVAST engine download error: 0 18:58:05.859 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 18:58:05.859 Disk 0 Vendor: Size: 0MB BusType: 0 18:58:05.890 Disk 0 MBR read successfully 18:58:05.890 Disk 0 MBR scan 18:58:05.890 Disk 0 unknown MBR code 18:58:05.890 Disk 0 MBR hidden 18:58:05.921 Disk 0 scanning C:\WINDOWS\system32\drivers 18:58:17.984 Service scanning 18:58:19.578 Modules scanning 18:58:33.843 Disk 0 trace - called modules: 18:58:33.843 ntkrnlpa.exe CLASSPNP.SYS disk.sys PCTCore.sys ACPI.sys hal.dll iaStor.sys 18:58:33.859 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x867ee300] 18:58:33.859 3 CLASSPNP.SYS[f76a4fd7] -> nt!IofCallDriver -> [0x867eeae0] 18:58:33.859 5 PCTCore.sys[f7367099] -> nt!IofCallDriver -> \Device\00000091[0x87163a28] 18:58:33.859 7 ACPI.sys[f74fb620] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x86bf0030] 18:58:33.875 Scan finished successfully 18:58:54.500 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Sunita\Desktop\MBR.dat" 18:58:54.500 The log file has been saved successfully to "C:\Documents and Settings\Sunita\Desktop\aswMBR.txt" I wasn't able to run the DDS files as every time I tried to run, I kept getting the winlogon error message.
Hello sunoly :),

Scan with RogueKiller
  • Please download RogueKiller© by Tigzy from one of the links below and save it to your desktop.
    Link 1
    Link 2
  • Allow the download if prompted by your security software and please close all your programs.
  • Double click on RogueKiller.exe to run it. If it does not run, please try a few times.
  • A program window will open. Type 1 for Scan and press Enter when prompted.
  • Once finished, Notepad will open with a log called RKreport.txt, located at the desktop.
  • Please copy and paste the contents of that log in your next reply.
——————–

Please try DDS again and post back the results.

——————–

Please post back:
1. RogueKiller log
2. DDS logs (DDS.txt and Attach.txt)
below is the Roguekiller log, I still am unable to run DDS.



RogueKiller V6.1.10 [11/18/2011] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Sunita [Admin rights]
Mode: Scan – Date : 11/25/2011 22:43:49

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 644 ¤¤¤
[ROGUE ST] HKCU\[…]\Run : 8313836343033373130303133405 (C:\Documents and Settings\Sunita\164796E65735\winlogon.exe) -> FOUND
[ROGUE ST] HKLM\[…]\Run : 8313836343033373130303133405 (C:\Documents and Settings\Sunita\164796E65735\winlogon.exe) -> FOUND
[ROGUE ST] HKUS\S-1-5-21-3999197343-1343777-328208992-1005[…]\Run : 8313836343033373130303133405 (C:\Documents and Settings\Sunita\164796E65735\winlogon.exe) -> FOUND
[HJ NAME] winlogon.exe : C:\Documents and Settings\Sunita\Start Menu\Programs\StartUp\winlogon.exe -> FOUND
[HJ NAME] winlogon.exe : C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlogon.exe -> FOUND
[PROXY FF] 8jtin39r.default\ :0 -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : a2servic.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ackwin32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : acs.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : advxdwin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : agentsvr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : agentw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ahnsd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : alerter.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : alertsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : alogserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : amon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : amon9x.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : anti-trojan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : antigen.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : antivirus.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ants.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : apimonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : aplica32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : apvxdwin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ashWebSv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : atcon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : atguard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : atro55en.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : atupdater.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : atwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : aupdate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : autodown.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : autotrace.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : autoupdate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avcenter.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avconfig.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avconsol.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ave32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avgcc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avgctrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avgemc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avgnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avgserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avgserv9.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avguard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avgw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avkpop.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avkserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avkservice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avkwcl9.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avkwctl9.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avnotify.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avp32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avpcc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avpdos32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avpexec.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avpinst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avpm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avpmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avpnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avptc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avpupd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avrescue.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avscanavshadow.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avsched32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avsynmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avupgsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avwebloader.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avwin95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avwinnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avwsc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avwupd32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avxmonitor9x.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avxmonitornt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avxquar.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avxw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : azonealarm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : bd_professional.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : bidef.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : bidserver.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : bipcp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : bipcpevalsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : bisp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : blackd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : blackice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : boot.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : bootwarn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : borg2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : bs120.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : BullGuard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : callmsi.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ccapp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ccevtmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cclaw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ccpxysvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ccsetmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ccshtdwn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cdp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cfgwiz.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cfiadmin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cfiaudit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cfind.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cfinet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cfinet32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ChromeSetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : clamauto.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : claw95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : claw95cf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : claw95ct.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : clean.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cleaner.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cleaner3.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cleanpc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cmd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cmgrdian.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cmon016.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ComboFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : connectionmonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cpd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cpdclnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cpf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cpf9x206.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cpfnt206.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : csinject.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : csinsm32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : css1631.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ctfmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ctrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cwnb181.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cwntdwmo.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : defalert.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : defscangui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : defwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : deputy.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Diskmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : doors.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : dpf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : drvins32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : drwatson.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : drweb32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : dumphive.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : dv95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : dv95_o.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : dvp95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : dvp95_0.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : earthagent.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ecengine.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ecls.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ecmd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : edi.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : efinet32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : efpeadm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : egui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : EHttpSrv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ekrn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ent.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : esafe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : escanh95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : escanhnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : escanv95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : espwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : etrustcipe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : evpn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ewido.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : exantivirus-cnet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : exit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : expert.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : explored.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : f-agnt95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : f-prot.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : f-prot95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : f-stopw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fa-setup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fact.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fameh32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fast.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fch32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fih32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Filemon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : findviru.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : firewall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : FirewallControlPanel.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : FirewallSettings.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fix-it.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : flowprotector.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fnrb32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fp-win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fp-win_trial.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : FPAVServer.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fprot.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fprot95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : frw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsaa.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsav.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsav32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsav530stbyb.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsav530wtbyb.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsav95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsave32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsgk32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fslaunch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsm32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsma32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsmb32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fssm32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fwenc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fwinstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : gbmenu.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : gbpoll.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : GenericRenosFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : generics.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : gibe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : GoogleToolbarInstaller_download_signed.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : gpedit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : guard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : guarddog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : guardgui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : guardhlp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : hacktracersetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : HelpPane.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : hidec.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : HiJackThis.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : HJTInstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : HostsChk.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : htlog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : hwpe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : iamapp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : iamserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : iamstats.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ibmasn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ibmavsp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : icload95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : icloadnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : icmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : icmoon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : icssuppnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : icsupp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : icsupp95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : icsuppnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : IEDFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : iface.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ifw2000.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : iomon98.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : iparmor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : iris.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : isrv95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : jammer.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : jed.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : jedi.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kav8.0.0.357es.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kavlite40eng.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kavpers40eng.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kavsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kerio-pf-213-en-win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kerio-wrl-421-en-win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kerio-wrp-421-en-win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : killprocesssetup161.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kis8.0.0.506latam.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kpf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kpfw32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ldnetmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ldpro.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ldpromenu.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ldscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : licmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : localnet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : lockdown.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : lockdown2000.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : lookout.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : lsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : luall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : luau.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : lucomserver.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : luinit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : luspt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mbam.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mbamgui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mbamservice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mcagent.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mcmnhdlr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mcshield.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mctool.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mcuimgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mcupdate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mcvsrte.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mcvsshld.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mdll.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mfw2en.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mfweng3.02d30.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mgavrtcl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mgavrte.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mghtml.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mgui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : minilog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : monitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : monsys32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : monsysnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : monwow.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : moolive.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mpfagent.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mpfservice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mpftray.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mrflux.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : MSASCui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : msblast.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : msconfig.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : msinfo32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : msn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mspatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mssmmc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mu0311ad.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mxtask.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : n32scan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : n32scanw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nai_vs_stat.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nav32_loader.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nav80try.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navap.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navapsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navapw32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navauto-protect.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navdx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : naveng.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navengnavex15.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navex15.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navlu32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navrunr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navsched.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navstub.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navw32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navwnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nc2000.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ncinst4.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nd98spst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ndd32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ndntspst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : neomonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : neowatchlog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : netarmor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : netcfg.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : netinfo.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : netmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : netscanpro.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Netscape.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : netspyhunter-1.2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : netstat.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : netutils.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nisserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nisum.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nmain.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nod32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : normist.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : norton_internet_secu_3.0_407.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : notstart.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : npf40_tw_98_nt_me_2k.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : npfmessenger.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nprotect.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : npscheck.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : npssvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nsched32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ntdetect.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ntrtscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ntxconfig.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nupdate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nupgrade.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nvapsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nvarch16.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nvc95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nvlaunch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nvsvc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nwinst4.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nwservice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nwtool16.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : offguard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ogrc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : opera.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Opera_964_int_Setup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ostronet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : outpost.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : outpostinstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : outpostproinstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : padmin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : panixk.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pathping.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pavcl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pavproxy.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pavsched.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pavw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pcc2002s902.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pcc2k_76_1436.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pccclient.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pccguide.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pcciomon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pccmain.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pccntmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pccpfw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pccwin97.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pccwin98.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pcdsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pcfwallicon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pcip10117_0.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pcscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pcscanpdsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : penis32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : periscope.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : persfw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : perswf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pev.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pf2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pfwadmin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ping.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pingscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : platin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pop3trap.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : poproxy.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : popscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : portdetective.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : portmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : portmonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ppinupdt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pptbc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ppvstop.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : prckiller.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Process.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : processmonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : procexp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : procexplorerv1.0.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Procmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : programauditor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : proport.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : protectx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pspf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : purge.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pview.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pview95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : qconsole.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : qserver.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rapapp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rav.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rav7.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rav7win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rav8win32eng.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : realmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : regedit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : regedt32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Regmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rescue.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rescue32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Restart.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : route.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : routemon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rrguard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rshell.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rstrui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rtvscn95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rulaunch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Safari.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : safeweb.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieBITS.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieCrypto.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieDcomLaunch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieRpcSs.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieWUAU.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SbieCtrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SbieSvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sbserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : scan32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : scan95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : scanpm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sched.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : schedapp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : scrscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : scvhosl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sdclt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : serv95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : setupvameeval.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : setup_flowprotector_us.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sgssfw32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sh.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sharedaccess.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : shellspyinstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : shn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : smc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SmitfraudFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sofi.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : spf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sphinx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : spider.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : spysweeper.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : spyxx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SrchSTS.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : srwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ss3edit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : st2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : supftrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : supporter5.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sweep.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sweep95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sweepnet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sweepsrv.sys.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : swnetsup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : swreg.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : swsc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : swxcacls.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : symproxysvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : symtray.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sysdoc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : syshelp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : taskkill.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tasklist.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : taskmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : taskmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : taumon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tauscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tbscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tca.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tcm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tcpsvs32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tds-3.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tds2-98.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tds2-nt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tds2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tfak.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tfak5.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tftpd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tgbob.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : titanin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : titaninxp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tmlisten.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tmntsrv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tracerpt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tracert.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : trjscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : trjsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : trojantrap3.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : UCCLSID.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : UI0Detect.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : undoboot.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : unzip.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : update.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : UserAccountControlSettings.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : VACFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vbcmserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vbcons.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vbust.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vbwin9x.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vbwinntw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vccmserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vcleaner.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vcontrol.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vcsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vet32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vet95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vet98.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vettray.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vfsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vir-help.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : virusmdpersonalfirewall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vmsrvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vnlan300.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vnpc3000.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vpc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vpc42.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vpcmap.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vpfw30s.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vptray.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vscan40.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vscenu6.02d30.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vsched.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vsecomr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vshwin32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vsisetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vsmain.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vsmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vsscan40.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vsstat.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vswin9xe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vswinntse.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vswinperse.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vvstat.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : w32dsm89.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : w9x.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : watchdog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : webscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : webscanx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : webtrap.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : WerFault.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wfindv32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wgfe95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : whoswatchingme.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wimmun32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wingate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : winhlpp32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wink.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : winmgm32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : winppr32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : winrecon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : winroute.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : winservices.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : winsfcm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wmias.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wmiav.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wradmin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wrctrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : WS2Fix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wsbgate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wuauclt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wyvernworksfirewall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : xpf202en.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : xscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zapro.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zapsetup3001.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zatutor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zatutorzauinst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zauinst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zlh.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zonalarm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zonalm2601.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zonealarm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : _avp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : _avp32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : _avpcc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : _avpm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : _findviru.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[HJPOL] HKCU\[…]\Explorer : NoFolderOptions (1) -> FOUND
[HJPOL] HKLM\[…]\Explorer : NoFolderOptions (1) -> FOUND
[HJ] HKLM\[…]\SystemRestore : DisableSR (1) -> FOUND
[HJ] HKLM\[…]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
[HJ] HKLM\[…]\System : EnableLUA (0) -> FOUND
[HJ] HKLM\[…]\Security Center : AntiVirusDisableNotify (1) -> FOUND
[HJ] HKLM\[…]\Security Center : FirewallDisableNotify (1) -> FOUND
[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤
SSDT[50] : NtCreateSection @ 0x805AB3C8 -> HOOKED (\??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys @ 0xF7B8E700)

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
184.168.105.79 viabcp.com
184.168.105.79 www.viabcp.com
184.168.105.79 bcpzonasegura.viabcp.com
184.168.105.79 bn.com.pe
184.168.105.79 www.bn.com.pe
184.168.105.79 zonasegura1.bn.com.pe
184.168.105.79 bbvabancocontinental.com
184.168.105.79 www.bbvabancocontinental.com
184.168.105.79 peb1.bbvanetlatam.com
184.168.105.79 www.peb1.bbvanetlatam.com
184.168.105.79 scotiabank.com.pe
184.168.105.79 www.scotiabank.com.pe
184.168.105.79 scotiaenlinea.scotiabank.com.pe
50.2.7.196 pichincha.com
50.2.7.196 www.pichincha.com
124.103.47.148 iniciorapido.info
100.55.123.174 www.iniciorapido.info
89.88.25.213 buscalo.in
91.201.7.78 www.buscalo.in
242.72.3.23 buscafacil.com
[…]


Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
Hello sunoly :),

Did you made any changes to the hosts file yourself before this problem?

RogueKiller in action
  • Please rerun RogueKiller.
  • At the prompt, type 2 for Remove and press Enter.
  • Try a few times if it does not run.
  • Post back the new result.

Check if you can get DDS to run.

——————–

Please post back:
1. RogueKiller log
2. DDS logs (DDS.txt and Attach.txt)
No, I havent made any changes to the Hosts file.
Attached is the roguekiller log. Not able to run DDS still, as when command prompt opens i get the below message

THE COMMAND PROMPT HAS BEEN DISABLED BY YOUR ADMINISTRATOR



RogueKiller V6.1.10 [11/18/2011] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Sunita [Admin rights]
Mode: Scan – Date : 11/25/2011 22:43:49

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 644 ¤¤¤
[ROGUE ST] HKCU\[…]\Run : 8313836343033373130303133405 (C:\Documents and Settings\Sunita\164796E65735\winlogon.exe) -> FOUND
[ROGUE ST] HKLM\[…]\Run : 8313836343033373130303133405 (C:\Documents and Settings\Sunita\164796E65735\winlogon.exe) -> FOUND
[ROGUE ST] HKUS\S-1-5-21-3999197343-1343777-328208992-1005[…]\Run : 8313836343033373130303133405 (C:\Documents and Settings\Sunita\164796E65735\winlogon.exe) -> FOUND
[HJ NAME] winlogon.exe : C:\Documents and Settings\Sunita\Start Menu\Programs\StartUp\winlogon.exe -> FOUND
[HJ NAME] winlogon.exe : C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlogon.exe -> FOUND
[PROXY FF] 8jtin39r.default\ :0 -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : a2servic.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ackwin32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : acs.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : advxdwin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : agentsvr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : agentw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ahnsd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : alerter.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : alertsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : alogserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : amon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : amon9x.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : anti-trojan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : antigen.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : antivirus.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ants.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : apimonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : aplica32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : apvxdwin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ashWebSv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : atcon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : atguard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : atro55en.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : atupdater.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : atwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : aupdate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : autodown.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : autotrace.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : autoupdate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avcenter.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avconfig.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avconsol.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ave32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avgcc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avgctrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avgemc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avgnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avgserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avgserv9.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avguard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avgw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avkpop.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avkserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avkservice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avkwcl9.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avkwctl9.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avnotify.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avp32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avpcc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avpdos32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avpexec.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avpinst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avpm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avpmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avpnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avptc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avpupd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avrescue.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avscanavshadow.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avsched32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avsynmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avupgsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avwebloader.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avwin95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avwinnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avwsc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avwupd32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avxmonitor9x.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avxmonitornt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avxquar.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : avxw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : azonealarm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : bd_professional.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : bidef.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : bidserver.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : bipcp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : bipcpevalsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : bisp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : blackd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : blackice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : boot.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : bootwarn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : borg2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : bs120.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : BullGuard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : callmsi.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ccapp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ccevtmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cclaw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ccpxysvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ccsetmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ccshtdwn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cdp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cfgwiz.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cfiadmin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cfiaudit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cfind.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cfinet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cfinet32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ChromeSetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : clamauto.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : claw95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : claw95cf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : claw95ct.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : clean.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cleaner.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cleaner3.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cleanpc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cmd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cmgrdian.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cmon016.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ComboFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : connectionmonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cpd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cpdclnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cpf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cpf9x206.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cpfnt206.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : csinject.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : csinsm32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : css1631.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ctfmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ctrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cwnb181.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : cwntdwmo.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : defalert.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : defscangui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : defwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : deputy.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Diskmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : doors.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : dpf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : drvins32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : drwatson.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : drweb32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : dumphive.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : dv95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : dv95_o.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : dvp95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : dvp95_0.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : earthagent.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ecengine.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ecls.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ecmd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : edi.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : efinet32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : efpeadm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : egui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : EHttpSrv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ekrn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ent.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : esafe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : escanh95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : escanhnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : escanv95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : espwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : etrustcipe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : evpn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ewido.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : exantivirus-cnet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : exit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : expert.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : explored.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : f-agnt95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : f-prot.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : f-prot95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : f-stopw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fa-setup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fact.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fameh32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fast.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fch32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fih32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Filemon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : findviru.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : firewall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : FirewallControlPanel.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : FirewallSettings.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fix-it.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : flowprotector.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fnrb32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fp-win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fp-win_trial.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : FPAVServer.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fprot.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fprot95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : frw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsaa.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsav.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsav32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsav530stbyb.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsav530wtbyb.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsav95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsave32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsgk32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fslaunch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsm32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsma32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fsmb32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fssm32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fwenc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : fwinstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : gbmenu.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : gbpoll.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : GenericRenosFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : generics.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : gibe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : GoogleToolbarInstaller_download_signed.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : gpedit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : guard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : guarddog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : guardgui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : guardhlp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : hacktracersetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : HelpPane.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : hidec.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : HiJackThis.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : HJTInstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : HostsChk.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : htlog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : hwpe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : iamapp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : iamserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : iamstats.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ibmasn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ibmavsp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : icload95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : icloadnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : icmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : icmoon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : icssuppnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : icsupp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : icsupp95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : icsuppnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : IEDFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : iface.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ifw2000.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : iomon98.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : iparmor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : iris.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : isrv95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : jammer.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : jed.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : jedi.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kav8.0.0.357es.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kavlite40eng.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kavpers40eng.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kavsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kerio-pf-213-en-win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kerio-wrl-421-en-win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kerio-wrp-421-en-win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : killprocesssetup161.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kis8.0.0.506latam.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kpf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : kpfw32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ldnetmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ldpro.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ldpromenu.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ldscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : licmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : localnet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : lockdown.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : lockdown2000.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : lookout.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : lsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : luall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : luau.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : lucomserver.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : luinit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : luspt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mbam.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mbamgui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mbamservice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mcagent.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mcmnhdlr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mcshield.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mctool.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mcuimgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mcupdate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mcvsrte.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mcvsshld.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mdll.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mfw2en.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mfweng3.02d30.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mgavrtcl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mgavrte.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mghtml.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mgui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : minilog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : monitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : monsys32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : monsysnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : monwow.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : moolive.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mpfagent.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mpfservice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mpftray.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mrflux.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : MSASCui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : msblast.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : msconfig.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : msinfo32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : msn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mspatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mssmmc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mu0311ad.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : mxtask.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : n32scan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : n32scanw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nai_vs_stat.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nav32_loader.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nav80try.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navap.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navapsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navapw32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navauto-protect.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navdx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : naveng.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navengnavex15.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navex15.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navlu32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navrunr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navsched.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navstub.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navw32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : navwnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nc2000.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ncinst4.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nd98spst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ndd32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ndntspst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : neomonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : neowatchlog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : netarmor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : netcfg.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : netinfo.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : netmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : netscanpro.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Netscape.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : netspyhunter-1.2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : netstat.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : netutils.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nisserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nisum.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nmain.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nod32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : normist.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : norton_internet_secu_3.0_407.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : notstart.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : npf40_tw_98_nt_me_2k.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : npfmessenger.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nprotect.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : npscheck.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : npssvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nsched32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ntdetect.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ntrtscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ntxconfig.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nupdate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nupgrade.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nvapsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nvarch16.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nvc95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nvlaunch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nvsvc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nwinst4.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nwservice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : nwtool16.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : offguard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ogrc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : opera.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Opera_964_int_Setup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ostronet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : outpost.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : outpostinstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : outpostproinstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : padmin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : panixk.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pathping.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pavcl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pavproxy.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pavsched.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pavw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pcc2002s902.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pcc2k_76_1436.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pccclient.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pccguide.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pcciomon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pccmain.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pccntmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pccpfw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pccwin97.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pccwin98.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pcdsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pcfwallicon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pcip10117_0.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pcscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pcscanpdsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : penis32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : periscope.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : persfw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : perswf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pev.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pf2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pfwadmin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ping.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pingscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : platin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pop3trap.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : poproxy.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : popscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : portdetective.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : portmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : portmonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ppinupdt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pptbc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ppvstop.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : prckiller.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Process.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : processmonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : procexp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : procexplorerv1.0.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Procmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : programauditor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : proport.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : protectx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pspf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : purge.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pview.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : pview95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : qconsole.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : qserver.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rapapp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rav.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rav7.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rav7win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rav8win32eng.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : realmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : regedit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : regedt32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Regmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rescue.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rescue32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Restart.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : route.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : routemon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rrguard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rshell.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rstrui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rtvscn95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : rulaunch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : Safari.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : safeweb.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieBITS.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieCrypto.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieDcomLaunch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieRpcSs.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieWUAU.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SbieCtrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SbieSvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sbserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : scan32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : scan95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : scanpm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sched.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : schedapp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : scrscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : scvhosl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sdclt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : serv95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : setupvameeval.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : setup_flowprotector_us.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sgssfw32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sh.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sharedaccess.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : shellspyinstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : shn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : smc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SmitfraudFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sofi.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : spf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sphinx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : spider.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : spysweeper.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : spyxx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : SrchSTS.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : srwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : ss3edit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : st2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : supftrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : supporter5.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sweep.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sweep95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sweepnet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sweepsrv.sys.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : swnetsup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : swreg.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : swsc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : swxcacls.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : symproxysvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : symtray.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : sysdoc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : syshelp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : taskkill.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tasklist.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : taskmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : taskmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : taumon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tauscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tbscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tca.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tcm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tcpsvs32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tds-3.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tds2-98.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tds2-nt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tds2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tfak.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tfak5.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tftpd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tgbob.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : titanin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : titaninxp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tmlisten.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tmntsrv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tracerpt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : tracert.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : trjscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : trjsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : trojantrap3.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : UCCLSID.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : UI0Detect.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : undoboot.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : unzip.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : update.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : UserAccountControlSettings.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : VACFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vbcmserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vbcons.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vbust.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vbwin9x.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vbwinntw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vccmserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vcleaner.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vcontrol.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vcsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vet32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vet95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vet98.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vettray.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vfsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vir-help.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : virusmdpersonalfirewall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vmsrvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vnlan300.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vnpc3000.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vpc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vpc42.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vpcmap.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vpfw30s.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vptray.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vscan40.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vscenu6.02d30.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vsched.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vsecomr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vshwin32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vsisetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vsmain.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vsmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vsscan40.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vsstat.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vswin9xe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vswinntse.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vswinperse.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : vvstat.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : w32dsm89.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : w9x.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : watchdog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : webscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : webscanx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : webtrap.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : WerFault.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wfindv32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wgfe95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : whoswatchingme.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wimmun32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wingate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : winhlpp32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wink.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : winmgm32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : winppr32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : winrecon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : winroute.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : winservices.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : winsfcm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wmias.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wmiav.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wradmin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wrctrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : WS2Fix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wsbgate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wuauclt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : wyvernworksfirewall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : xpf202en.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : xscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zapro.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zapsetup3001.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zatutor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zatutorzauinst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zauinst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zlh.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zonalarm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zonalm2601.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : zonealarm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : _avp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : _avp32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : _avpcc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : _avpm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[IFEO] HKLM\[…]\Image File Execution Options : _findviru.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> FOUND
[HJPOL] HKCU\[…]\Explorer : NoFolderOptions (1) -> FOUND
[HJPOL] HKLM\[…]\Explorer : NoFolderOptions (1) -> FOUND
[HJ] HKLM\[…]\SystemRestore : DisableSR (1) -> FOUND
[HJ] HKLM\[…]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
[HJ] HKLM\[…]\System : EnableLUA (0) -> FOUND
[HJ] HKLM\[…]\Security Center : AntiVirusDisableNotify (1) -> FOUND
[HJ] HKLM\[…]\Security Center : FirewallDisableNotify (1) -> FOUND
[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤
SSDT[50] : NtCreateSection @ 0x805AB3C8 -> HOOKED (\??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys @ 0xF7B8E700)

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
184.168.105.79 viabcp.com
184.168.105.79 www.viabcp.com
184.168.105.79 bcpzonasegura.viabcp.com
184.168.105.79 bn.com.pe
184.168.105.79 www.bn.com.pe
184.168.105.79 zonasegura1.bn.com.pe
184.168.105.79 bbvabancocontinental.com
184.168.105.79 www.bbvabancocontinental.com
184.168.105.79 peb1.bbvanetlatam.com
184.168.105.79 www.peb1.bbvanetlatam.com
184.168.105.79 scotiabank.com.pe
184.168.105.79 www.scotiabank.com.pe
184.168.105.79 scotiaenlinea.scotiabank.com.pe
50.2.7.196 pichincha.com
50.2.7.196 www.pichincha.com
124.103.47.148 iniciorapido.info
100.55.123.174 www.iniciorapido.info
89.88.25.213 buscalo.in
91.201.7.78 www.buscalo.in
242.72.3.23 buscafacil.com
[…]


Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
Hello sunoly :),

The second RogueKiller log you posted is the same as the previous one. Could you please provide the latest one?

——————–

Please download ComboFix from one of the links below and save it to your desktop.

Link 1
Link 2

Do not mouse click on ComboFix while it is running. That may cause it to stall. ComboFix is a powerful tool and must not be used without supervision.

Install Recovery Console and run ComboFix
  • Please disable your real time protection of any Antivirus, Antispyware or Antimalware programs temporarily when running ComboFix. They will interfere and may cause unexpected results.
  • If you need help to disable your protection programs see here and here.
  • Double click on ComboFix.exe and follow the prompts. Please run it in Normal Mode.
  • As part of its process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. You will be asked to install it if it is not present in your computer. Click Yes to proceed.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    Note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, click on Yes to continue scanning for malware.
  • When finished, a log will be produced as C:\ComboFix.txt. Please post this log in your next reply.
  • If you lose Internet connection after running ComboFix, right click on the network icon at the system tray and select Repair, or you can reboot the computer.
  • Enable back your security softwares as soon as you completed the ComboFix steps.
A detailed step by step tutorial to run ComboFix can be found here if you need help.

——————–

Please post back:
1. the correct RogueKiller log
2. ComboFix log
Rogue Killer log

RogueKiller V6.1.10 [11/18/2011] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Sunita [Admin rights]
Mode: Remove – Date : 11/26/2011 21:34:27

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 643 ¤¤¤
[ROGUE ST] HKCU\[…]\Run : 8313836343033373130303133405 (C:\Documents and Settings\Sunita\164796E65735\winlogon.exe) -> DELETED
[ROGUE ST] HKLM\[…]\Run : 8313836343033373130303133405 (C:\Documents and Settings\Sunita\164796E65735\winlogon.exe) -> DELETED
[HJ NAME] winlogon.exe : C:\Documents and Settings\Sunita\Start Menu\Programs\StartUp\winlogon.exe -> DELETED
[HJ NAME] winlogon.exe : C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlogon.exe -> DELETED
[PROXY FF] 8jtin39r.default\ :0 -> NOT REMOVED, USE PROXYFIX
[IFEO] HKLM\[…]\Image File Execution Options : a2servic.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ackwin32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : acs.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : advxdwin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : agentsvr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : agentw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ahnsd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : alerter.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : alertsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : alogserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : amon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : amon9x.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : anti-trojan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : antigen.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : antivirus.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ants.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : apimonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : aplica32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : apvxdwin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ashWebSv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : atcon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : atguard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : atro55en.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : atupdater.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : atwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : aupdate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : autodown.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : autotrace.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : autoupdate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avcenter.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avconfig.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avconsol.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ave32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avgcc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avgctrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avgemc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avgnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avgserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avgserv9.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avguard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avgw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avkpop.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avkserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avkservice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avkwcl9.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avkwctl9.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avnotify.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avp32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avpcc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avpdos32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avpexec.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avpinst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avpm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avpmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avpnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avptc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avpupd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avrescue.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avscanavshadow.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avsched32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avsynmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avupgsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avwebloader.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avwin95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avwinnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avwsc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avwupd32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avxmonitor9x.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avxmonitornt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avxquar.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avxw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : azonealarm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : bd_professional.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : bidef.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : bidserver.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : bipcp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : bipcpevalsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : bisp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : blackd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : blackice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : boot.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : bootwarn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : borg2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : bs120.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : BullGuard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : callmsi.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ccapp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ccevtmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cclaw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ccpxysvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ccsetmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ccshtdwn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cdp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cfgwiz.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cfiadmin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cfiaudit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cfind.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cfinet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cfinet32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ChromeSetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : clamauto.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : claw95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : claw95cf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : claw95ct.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : clean.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cleaner.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cleaner3.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cleanpc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cmd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cmgrdian.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cmon016.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ComboFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : connectionmonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cpd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cpdclnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cpf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cpf9x206.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cpfnt206.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : csinject.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : csinsm32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : css1631.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ctfmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ctrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cwnb181.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cwntdwmo.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : defalert.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : defscangui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : defwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : deputy.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Diskmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : doors.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : dpf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : drvins32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : drwatson.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : drweb32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : dumphive.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : dv95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : dv95_o.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : dvp95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : dvp95_0.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : earthagent.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ecengine.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ecls.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ecmd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : edi.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : efinet32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : efpeadm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : egui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : EHttpSrv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ekrn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ent.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : esafe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : escanh95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : escanhnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : escanv95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : espwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : etrustcipe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : evpn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ewido.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : exantivirus-cnet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : exit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : expert.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : explored.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : f-agnt95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : f-prot.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : f-prot95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : f-stopw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fa-setup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fact.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fameh32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fast.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fch32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fih32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Filemon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : findviru.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : firewall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : FirewallControlPanel.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : FirewallSettings.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fix-it.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : flowprotector.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fnrb32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fp-win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fp-win_trial.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : FPAVServer.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fprot.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fprot95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : frw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsaa.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsav.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsav32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsav530stbyb.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsav530wtbyb.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsav95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsave32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsgk32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fslaunch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsm32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsma32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsmb32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fssm32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fwenc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fwinstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : gbmenu.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : gbpoll.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : GenericRenosFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : generics.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : gibe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : GoogleToolbarInstaller_download_signed.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : gpedit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : guard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : guarddog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : guardgui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : guardhlp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : hacktracersetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : HelpPane.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : hidec.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : HiJackThis.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : HJTInstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : HostsChk.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : htlog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : hwpe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : iamapp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : iamserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : iamstats.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ibmasn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ibmavsp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : icload95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : icloadnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : icmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : icmoon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : icssuppnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : icsupp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : icsupp95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : icsuppnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : IEDFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : iface.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ifw2000.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : iomon98.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : iparmor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : iris.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : isrv95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : jammer.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : jed.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : jedi.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kav8.0.0.357es.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kavlite40eng.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kavpers40eng.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kavsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kerio-pf-213-en-win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kerio-wrl-421-en-win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kerio-wrp-421-en-win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : killprocesssetup161.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kis8.0.0.506latam.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kpf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kpfw32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ldnetmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ldpro.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ldpromenu.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ldscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : licmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : localnet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : lockdown.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : lockdown2000.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : lookout.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : lsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : luall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : luau.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : lucomserver.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : luinit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : luspt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mbam.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mbamgui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mbamservice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mcagent.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mcmnhdlr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mcshield.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mctool.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mcuimgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mcupdate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mcvsrte.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mcvsshld.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mdll.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mfw2en.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mfweng3.02d30.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mgavrtcl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mgavrte.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mghtml.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mgui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : minilog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : monitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : monsys32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : monsysnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : monwow.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : moolive.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mpfagent.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mpfservice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mpftray.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mrflux.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : MSASCui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : msblast.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : msconfig.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : msinfo32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : msn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mspatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mssmmc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mu0311ad.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mxtask.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : n32scan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : n32scanw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nai_vs_stat.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nav32_loader.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nav80try.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navap.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navapsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navapw32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navauto-protect.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navdx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : naveng.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navengnavex15.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navex15.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navlu32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navrunr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navsched.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navstub.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navw32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navwnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nc2000.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ncinst4.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nd98spst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ndd32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ndntspst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : neomonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : neowatchlog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : netarmor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : netcfg.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : netinfo.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : netmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : netscanpro.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Netscape.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : netspyhunter-1.2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : netstat.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : netutils.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nisserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nisum.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nmain.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nod32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : normist.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : norton_internet_secu_3.0_407.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : notstart.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : npf40_tw_98_nt_me_2k.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : npfmessenger.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nprotect.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : npscheck.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : npssvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nsched32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ntdetect.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ntrtscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ntxconfig.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nupdate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nupgrade.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nvapsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nvarch16.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nvc95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nvlaunch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nvsvc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nwinst4.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nwservice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nwtool16.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : offguard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ogrc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : opera.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Opera_964_int_Setup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ostronet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : outpost.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : outpostinstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : outpostproinstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : padmin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : panixk.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pathping.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pavcl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pavproxy.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pavsched.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pavw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pcc2002s902.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pcc2k_76_1436.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pccclient.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pccguide.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pcciomon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pccmain.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pccntmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pccpfw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pccwin97.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pccwin98.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pcdsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pcfwallicon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pcip10117_0.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pcscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pcscanpdsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : penis32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : periscope.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : persfw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : perswf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pev.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pf2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pfwadmin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ping.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pingscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : platin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pop3trap.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : poproxy.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : popscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : portdetective.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : portmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : portmonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ppinupdt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pptbc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ppvstop.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : prckiller.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Process.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : processmonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : procexp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : procexplorerv1.0.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Procmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : programauditor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : proport.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : protectx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pspf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : purge.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pview.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pview95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : qconsole.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : qserver.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rapapp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rav.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rav7.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rav7win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rav8win32eng.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : realmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : regedit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : regedt32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Regmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rescue.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rescue32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Restart.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : route.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : routemon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rrguard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rshell.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rstrui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rtvscn95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rulaunch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Safari.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : safeweb.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieBITS.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieCrypto.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieDcomLaunch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieRpcSs.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieWUAU.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SbieCtrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SbieSvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sbserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : scan32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : scan95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : scanpm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sched.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : schedapp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : scrscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : scvhosl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sdclt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : serv95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : setupvameeval.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : setup_flowprotector_us.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sgssfw32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sh.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sharedaccess.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : shellspyinstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : shn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : smc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SmitfraudFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sofi.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : spf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sphinx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : spider.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : spysweeper.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : spyxx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SrchSTS.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : srwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ss3edit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : st2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : supftrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : supporter5.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sweep.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sweep95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sweepnet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sweepsrv.sys.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : swnetsup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : swreg.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : swsc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : swxcacls.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : symproxysvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : symtray.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sysdoc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : syshelp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : taskkill.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tasklist.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : taskmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : taskmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : taumon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tauscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tbscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tca.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tcm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tcpsvs32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tds-3.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tds2-98.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tds2-nt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tds2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tfak.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tfak5.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tftpd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tgbob.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : titanin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : titaninxp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tmlisten.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tmntsrv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tracerpt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tracert.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : trjscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : trjsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : trojantrap3.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : UCCLSID.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : UI0Detect.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : undoboot.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : unzip.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : update.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : UserAccountControlSettings.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : VACFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vbcmserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vbcons.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vbust.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vbwin9x.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vbwinntw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vccmserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vcleaner.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vcontrol.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vcsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vet32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vet95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vet98.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vettray.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vfsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vir-help.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : virusmdpersonalfirewall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vmsrvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vnlan300.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vnpc3000.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vpc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vpc42.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vpcmap.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vpfw30s.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vptray.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vscan40.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vscenu6.02d30.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vsched.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vsecomr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vshwin32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vsisetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vsmain.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vsmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vsscan40.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vsstat.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vswin9xe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vswinntse.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vswinperse.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vvstat.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : w32dsm89.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : w9x.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : watchdog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : webscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : webscanx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : webtrap.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : WerFault.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wfindv32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wgfe95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : whoswatchingme.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wimmun32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wingate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : winhlpp32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wink.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : winmgm32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : winppr32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : winrecon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : winroute.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : winservices.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : winsfcm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wmias.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wmiav.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wradmin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wrctrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : WS2Fix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wsbgate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wuauclt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wyvernworksfirewall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : xpf202en.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : xscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zapro.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zapsetup3001.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zatutor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zatutorzauinst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zauinst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zlh.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zonalarm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zonalm2601.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zonealarm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : _avp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : _avp32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : _avpcc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : _avpm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : _findviru.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[HJPOL] HKCU\[…]\Explorer : NoFolderOptions (1) -> DELETED
[HJPOL] HKLM\[…]\Explorer : NoFolderOptions (1) -> DELETED
[HJ] HKLM\[…]\SystemRestore : DisableSR (1) -> REPLACED (0)
[HJ] HKLM\[…]\System : ConsentPromptBehaviorAdmin (0) -> REPLACED (2)
[HJ] HKLM\[…]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[…]\Security Center : AntiVirusDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[…]\Security Center : FirewallDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
184.168.105.79 viabcp.com
184.168.105.79 www.viabcp.com
184.168.105.79 bcpzonasegura.viabcp.com
184.168.105.79 bn.com.pe
184.168.105.79 www.bn.com.pe
184.168.105.79 zonasegura1.bn.com.pe
184.168.105.79 bbvabancocontinental.com
184.168.105.79 www.bbvabancocontinental.com
184.168.105.79 peb1.bbvanetlatam.com
184.168.105.79 www.peb1.bbvanetlatam.com
184.168.105.79 scotiabank.com.pe
184.168.105.79 www.scotiabank.com.pe
184.168.105.79 scotiaenlinea.scotiabank.com.pe
50.2.7.196 pichincha.com
50.2.7.196 www.pichincha.com
124.103.47.148 iniciorapido.info
100.55.123.174 www.iniciorapido.info
89.88.25.213 buscalo.in
91.201.7.78 www.buscalo.in
242.72.3.23 buscafacil.com
[…]


Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

Combofix log

ComboFix 11-11-28.02 - Sunita 11/27/2011 21:40:40.1.2 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Resident AV is active
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Sunita\Application Data\PriceGong
c:\documents and settings\Sunita\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\z.xml
c:\documents and settings\Sunita\WINDOWS
c:\windows\CSC\d6
c:\windows\kb913800.exe
D:\Autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2011-10-27 to 2011-11-27 )))))))))))))))))))))))))))))))
.
.
2011-12-18 11:52 . 2010-09-08 00:23 114432 —-a-r- c:\windows\system32\drivers\ewusbnet.sys
2011-12-18 11:52 . 2009-10-12 04:21 100736 —-a-w- c:\windows\system32\drivers\ewusbdev.sys
2011-12-18 11:52 . 2007-08-08 17:13 24448 —-a-w- c:\windows\system32\drivers\ewdcsc.sys
2011-12-18 11:51 . 2011-12-18 11:51 ——– d—–w- c:\program files\Tata Photon+
2011-11-27 10:26 . 2011-11-27 10:26 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{9E495A9D-6C54-4C2C-8960-2DF18EF3BDFB}\offreg.dll
2011-11-26 11:05 . 2011-10-07 03:48 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{9E495A9D-6C54-4C2C-8960-2DF18EF3BDFB}\mpengine.dll
2011-11-25 11:41 . 2011-11-26 10:35 111872 —-a-w- c:\windows\system32\drivers\TrueSight.sys
2011-11-22 12:16 . 2011-11-22 12:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-22 12:05 . 2011-11-26 10:23 ——– d—–w- c:\documents and settings\Sunita\Application Data\Systweak
2011-11-22 12:05 . 2011-07-07 02:26 17280 —-a-w- c:\windows\system32\roboot.exe
2011-11-20 11:50 . 2011-11-26 10:24 ——– d—–w- C:\sh4ldr
2011-11-20 11:50 . 2011-11-20 11:50 ——– d—–w- c:\program files\Enigma Software Group
2011-11-20 11:50 . 2011-11-26 10:24 ——– d—–w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP
2011-11-20 11:50 . 2011-11-20 11:50 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2011-11-20 08:56 . 2011-11-26 10:27 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2011-11-16 08:12 . 2011-11-16 08:12 ——– d-sha-r- c:\documents and settings\Sunita\164796E65735
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-10 14:22 . 2006-03-16 04:00 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 03:48 . 2008-06-16 11:17 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-09-28 07:06 . 2006-03-16 04:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 00:41 . 2008-07-29 09:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 00:41 . 2006-03-16 04:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 00:41 . 2006-03-16 04:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20 . 2006-03-16 04:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2007-12-09 11:05 . 2007-12-09 11:05 6026816 —-a-w- c:\program files\Firefox Setup 2.0.0.11.exe
2008-08-16 06:42 . 2008-08-16 06:42 13112 —-a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2008-08-16 06:42 . 2008-08-16 06:42 70456 —-a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2008-08-16 06:42 . 2008-08-16 06:42 91448 —-a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2008-08-16 06:42 . 2008-08-16 06:42 20800 —-a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2008-08-16 06:43 . 2008-08-16 06:43 206136 —-a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2008-08-16 06:42 . 2008-08-16 06:42 31032 —-a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2008-08-16 06:42 . 2008-08-16 06:42 40248 —-a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2008-05-20 21:41 . 2008-05-20 21:41 479232 —-a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll
2008-05-20 21:41 . 2008-05-20 21:41 548864 —-a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll
2008-05-20 21:41 . 2008-05-20 21:41 626688 —-a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll
2008-06-05 02:58 . 2008-06-05 02:58 648504 —-a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2008-08-16 06:42 . 2008-08-16 06:42 23864 —-a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2011-04-14 16:26 . 2011-05-20 01:02 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\prxtbBit2.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
2011-05-09 09:49 176936 —-a-w- c:\program files\BitTorrentBar\prxtbBit2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\prxtbBit2.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{88C7F2AA-F93F-432C-8F0E-B7D85967A527}"= "c:\program files\BitTorrentBar\prxtbBit2.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-02 68856]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 57344]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-20 7581696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-07-20 86016]
"nwiz"="nwiz.exe" [2006-07-20 1519616]
"MsmqIntCert"="mqrt.dll" [2008-04-14 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 61952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-17 794713]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-19 102400]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-06-19 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-03-15 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2006-03-15 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2006-03-15 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-03-15 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-03-15 455168]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-03 413696]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2006-05-16 40960]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-08 155648]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-06-30 1447168]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-18 198160]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"BCSSync"="c:\program files\Microsoft Office\Microsoft Office Professional edition 2003\Office14\BCSSync.exe" [2010-03-13 91520]
"MobileBroadband"="c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2010-09-08 272384]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-02-27 519584]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiSpyWareDisableNotify"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\english\\setup.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Microsoft Office\\Microsoft Office Professional edition 2003\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Microsoft Office Professional edition 2003\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Microsoft Office Professional edition 2003\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Documents and Settings\\Sunita\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Documents and Settings\\Sunita\\164796E65735\\winlogon.exe"=
.
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-13 135664]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-07-07 195336]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2010-09-08 114432]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-13 135664]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-10-12 100736]
R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [2010-09-08 100736]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Microsoft Office Professional edition 2003\Office14\GROOVE.EXE [2011-06-12 31125880]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 TrueSight;TrueSight;c:\windows\system32\drivers\TrueSight.sys [2011-11-26 111872]
S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [2011-06-15 249648]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-20 468224]
S2 VmbService;Vodafone Mobile Broadband Service;c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2010-09-08 8704]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-13 11:43]
.
2011-11-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-13 11:43]
.
2011-11-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3999197343-1343777-328208992-1005Core.job
- c:\documents and settings\Sunita\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-28 11:11]
.
2011-11-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3999197343-1343777-328208992-1005UA.job
- c:\documents and settings\Sunita\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-28 11:11]
.
2011-11-27 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 09:20]
.
2011-11-26 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 06:04]
.
2011-11-27 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 06:04]
.
.
——- Supplementary Scan ——-
.
uLocal Page = hxxp://jo4y770w7vsy4e5.directorio-w.com
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://vz2k046v98318q8.directorio-w.com
mLocal Page = hxxp://vlz87cz398s45eq.directorio-w.com
mStart Page = hxxp://9x496t0ibe1q002.directorio-w.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_AU&c=64&bd=pavilion&pf=laptop
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~4\MICROS~1\Office14\ONBttnIE.dll/105
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\Sunita\Application Data\Mozilla\Firefox\Profiles\8jtin39r.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://1ef5156153z3xd4.directorio-w.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - prefs.js: network.proxy.type - 1
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS REMOVED - - - -
.
Notify-NavLogon - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-27 22:00
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????L?@? ???xc??????`?@?????L?@
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600
.
CreateFile("\\.\PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!
.
**************************************************************************
.
Completion time: 2011-11-27 22:04:56
ComboFix-quarantined-files.txt 2011-11-27 11:04
.
Pre-Run: 38,468,833,280 bytes free
Post-Run: 47,502,811,136 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /fastdetect /NoExecute=OptOut
.
- - End Of File - - DA2FB650E8E7218E06C786D7F5FC5404
Hello sunoly :),

Is this your personal computer?

——————–

Remove P2P software
  • IMPORTANT: I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

    BitTorrent
    BitTorrentBar


  • Our policy as pointed out in the Terms of Use:

    We will not support or allow the discussion of any peer to peer (P2P) applications, except for their removal.

  • Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
  • Go to Control Panel > Add/Remove Programs and uninstall the P2P program(s) listed above (in red).
  • Please remove them before we continue with fixing your computer.

Check a registry key
  • Go to Start > Run…. Copy and paste the following text into the white box:
    cmd /c reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" /s >> "%userprofile%\desktop\query.txt"
  • Click OK.
  • Post the contents of query.txt as attachment. It is found on your desktop.
——————–

Check for additional security risks
  • Please download CKScanner© by askey127 and save to your desktop. Click here.
  • Double click on CKScanner.exe and click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File. You will be prompted, click OK.
  • Post the contents of ckfiles.txt in your reply, it is located on your desktop.
  • Please run the program only once.
——————–

Validate Windows
  • Please download MGADiag.exe from Microsoft and save it to a convenient location. Click here.
  • Double click on MGADiag.exe to run it.
  • Click Continue.
  • The program will run. It takes a while to finish the diagnosis, please be patient.
  • Once done, click on Copy.
  • Open Notepad and paste the contents in. Save this file and post it in your next reply.
——————–

Please post back:
1. the answer to my question
2. query.txt
3. CKScanner log
4. MGADiag result
1) yes it is, how does that matter. I have removed Bit torrent files 2)Attached 3) CK Scanner results CKScanner - Additional Security Risks - These are not necessarily bad c:\documents and settings\sunita\my documents\games\crack.bat c:\documents and settings\sunita\my documents\games\crack.zip c:\program files\oberon media\bejeweled 2 deluxe\sounds\firecrackle.ogg c:\program files\oberon media\jewel quest\audio\st_win3_crackle.ogg c:\program files\oberon media\magic match\data\sounds\ice_crack.ogg scanner sequence 3.EM.11.BCNADK —– EOF —– 4)MGADiag Diagnostic Report (1.9.0027.0): —————————————– Windows Validation Data–> Validation Status: Genuine Validation Code: 0 Cached Validation Code: N/A Windows Product Key: *****-*****-9TCCK-JPCBM-B2FQ8 Windows Product Key Hash: B/IohRcCzV6LJrex8WpCdnxgTvg= Windows Product ID: 76487-OEM-2211906-00803 Windows Product ID Type: 2 Windows License Type: OEM SLP Windows OS version: 5.1.2600.2.00010100.3.0.med ID: {855DA039-3734-4F25-BDDB-9EA5CEB2ADF2}(3) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: Registered, 1.8.31.0 Signed By: Microsoft Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: 025D1FF3-230-1 Resolution Status: N/A Vista WgaER Data–> ThreatID(s): N/A Version: N/A Windows XP Notifications Data–> Cached Result: 0 File Exists: Yes Version: 1.8.31.0 WgaTray.exe Signed By: Microsoft WgaLogon.dll Signed By: Microsoft OGA Notifications Data–> Cached Result: 109 Version: 1.7.105.35 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: Microsoft OGA Data–> Office Status: 109 N/A OGA Version: Registered, 2.0.48.0 Signed By: Microsoft Office Diagnostics: B4D0AA8B-604-645_025D1FF3-230-1 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) Default Browser: C:\Program Files\Internet Explorer\iexplore.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data–> Other data–> Office Details: {855DA039-3734-4F25-BDDB-9EA5CEB2ADF2}1.9.0027.05.1.2600.2.00010100.3.0.medx32*****-*****-*****-*****-B2FQ876487-OEM-2211906-008032S-1-5-21-3999197343-1343777-328208992Hewlett-PackardHP Pavilion dv6000 (RE128PA#ABG) Hewlett-PackardF.12 20061219000000.000000+000Compaq,Hewlett,Hewlett,Compaq1CCE3FDF0184606A04090409AUS Eastern Standard Time(GMT+10:00)02HP109 Licensing Data–> N/A Windows Activation Technologies–> N/A HWID Data–> N/A OEM Activation 1.0 Data–> BIOS string matches: yes Marker string from BIOS: BEE0:Compaq Computer Corporation|147FE:Compaq Computer Corporation|147FE:Compaq Computer Corporation|BEE0:Hewlett-Packard Company|1481A:Hewlett-Packard Company Marker string from OEMBIOS.DAT: Compaq,Hewlett,Hewlett,Compaq OEM Activation 2.0 Data–> N/A

Attachments:

Hello sunoly :), Thank you for the logs. The approach to deal to non personal computers is different from what we are going through :). What are these files? c:\documents and settings\sunita\my documents\games\crack.bat c:\documents and settings\sunita\my documents\games\crack.zip They are putting on the red light for me to move on. If they are illegal, please delete them in order for me to continue. There are still a couple of things we need to clean up before we are done. Repeat the CKScanner step again and post back the result after you have deleted them.
CKScanner - Additional Security Risks - These are not necessarily bad c:\program files\oberon media\bejeweled 2 deluxe\sounds\firecrackle.ogg c:\program files\oberon media\jewel quest\audio\st_win3_crackle.ogg c:\program files\oberon media\magic match\data\sounds\ice_crack.ogg scanner sequence 3.AB.11.AQAATV —– EOF —– The computer works better now.
Hello sunoly :),

Thanks for removing those files and glad to hear things are better now.

Do an online scan with ESET Online Scanner.
Please be patient as scanning will take quite some time. If you have problem running the scan, you might want to disable any real time protection that you have.
  • Click here to go to ESET Online Scanner page.
  • Click on Run ESET Online Scanner. A new window will open.
    For FireFox user, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • After reading through the Terms of Use, check YES, I accept the Terms of Use and click Start to begin scan.
  • You will be prompted to install an ActiveX Control from ESET. Please install.
  • At the Computer scan settings section, uncheck (untick) Remove found threats. <– Important, do not remove anything yet.
  • Then, check Scan archives.
  • Now, click on Advanced settings and make sure all these are checked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Click on Scan to proceed.
  • When done, the scan result will be shown. Look for C:\Program Files\ESET\ESET Online Scanner\log.txt and open the file.
  • Post the contents in your reply.
If the contents of log.txt do not reflect what is shown in the result window, click on List of found threats, then Export to text file…, save a file and post that instead.

——————–

Please post back:
1. ESET result

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI