Rogue Killer log
RogueKiller V6.1.10 [11/18/2011] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Sunita [Admin rights]
Mode: Remove – Date : 11/26/2011 21:34:27
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 643 ¤¤¤
[ROGUE ST] HKCU\[…]\Run : 8313836343033373130303133405 (C:\Documents and Settings\Sunita\164796E65735\winlogon.exe) -> DELETED
[ROGUE ST] HKLM\[…]\Run : 8313836343033373130303133405 (C:\Documents and Settings\Sunita\164796E65735\winlogon.exe) -> DELETED
[HJ NAME] winlogon.exe : C:\Documents and Settings\Sunita\Start Menu\Programs\StartUp\winlogon.exe -> DELETED
[HJ NAME] winlogon.exe : C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlogon.exe -> DELETED
[PROXY FF] 8jtin39r.default\ :0 -> NOT REMOVED, USE PROXYFIX
[IFEO] HKLM\[…]\Image File Execution Options : a2servic.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ackwin32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : acs.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : advxdwin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : agentsvr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : agentw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ahnsd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : alerter.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : alertsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : alogserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : amon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : amon9x.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : anti-trojan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : antigen.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : antivirus.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ants.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : apimonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : aplica32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : apvxdwin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ashWebSv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : atcon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : atguard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : atro55en.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : atupdater.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : atwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : aupdate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : autodown.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : autotrace.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : autoupdate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avcenter.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avconfig.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avconsol.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ave32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avgcc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avgctrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avgemc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avgnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avgserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avgserv9.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avguard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avgw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avkpop.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avkserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avkservice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avkwcl9.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avkwctl9.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avnotify.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avp32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avpcc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avpdos32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avpexec.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avpinst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avpm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avpmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avpnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avptc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avpupd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avrescue.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avscanavshadow.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avsched32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avsynmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avupgsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avwebloader.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avwin95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avwinnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avwsc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avwupd32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avxmonitor9x.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avxmonitornt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avxquar.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : avxw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : azonealarm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : bd_professional.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : bidef.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : bidserver.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : bipcp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : bipcpevalsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : bisp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : blackd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : blackice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : boot.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : bootwarn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : borg2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : bs120.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : BullGuard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : callmsi.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ccapp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ccevtmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cclaw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ccpxysvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ccsetmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ccshtdwn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cdp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cfgwiz.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cfiadmin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cfiaudit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cfind.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cfinet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cfinet32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ChromeSetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : clamauto.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : claw95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : claw95cf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : claw95ct.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : clean.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cleaner.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cleaner3.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cleanpc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cmd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cmgrdian.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cmon016.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ComboFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : connectionmonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cpd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cpdclnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cpf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cpf9x206.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cpfnt206.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : csinject.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : csinsm32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : css1631.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ctfmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ctrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cwnb181.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : cwntdwmo.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : defalert.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : defscangui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : defwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : deputy.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Diskmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : doors.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : dpf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : drvins32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : drwatson.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : drweb32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : dumphive.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : dv95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : dv95_o.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : dvp95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : dvp95_0.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : earthagent.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ecengine.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ecls.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ecmd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : edi.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : efinet32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : efpeadm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : egui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : EHttpSrv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ekrn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ent.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : esafe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : escanh95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : escanhnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : escanv95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : espwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : etrustcipe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : evpn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ewido.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : exantivirus-cnet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : exit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : expert.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : explored.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : f-agnt95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : f-prot.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : f-prot95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : f-stopw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fa-setup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fact.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fameh32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fast.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fch32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fih32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Filemon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : findviru.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : firewall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : FirewallControlPanel.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : FirewallSettings.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fix-it.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : flowprotector.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fnrb32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fp-win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fp-win_trial.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : FPAVServer.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fprot.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fprot95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : frw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsaa.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsav.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsav32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsav530stbyb.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsav530wtbyb.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsav95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsave32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsgk32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fslaunch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsm32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsma32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fsmb32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fssm32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fwenc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : fwinstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : gbmenu.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : gbpoll.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : GenericRenosFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : generics.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : gibe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : GoogleToolbarInstaller_download_signed.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : gpedit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : guard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : guarddog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : guardgui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : guardhlp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : hacktracersetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : HelpPane.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : hidec.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : HiJackThis.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : HJTInstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : HostsChk.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : htlog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : hwpe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : iamapp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : iamserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : iamstats.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ibmasn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ibmavsp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : icload95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : icloadnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : icmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : icmoon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : icssuppnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : icsupp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : icsupp95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : icsuppnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : IEDFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : iface.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ifw2000.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : iomon98.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : iparmor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : iris.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : isrv95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : jammer.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : jed.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : jedi.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kav8.0.0.357es.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kavlite40eng.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kavpers40eng.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kavsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kerio-pf-213-en-win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kerio-wrl-421-en-win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kerio-wrp-421-en-win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : killprocesssetup161.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kis8.0.0.506latam.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kpf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : kpfw32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ldnetmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ldpro.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ldpromenu.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ldscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : licmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : localnet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : lockdown.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : lockdown2000.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : lookout.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : lsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : luall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : luau.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : lucomserver.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : luinit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : luspt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mbam.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mbamgui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mbamservice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mcagent.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mcmnhdlr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mcshield.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mctool.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mcuimgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mcupdate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mcvsrte.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mcvsshld.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mdll.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mfw2en.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mfweng3.02d30.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mgavrtcl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mgavrte.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mghtml.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mgui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : minilog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : monitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : monsys32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : monsysnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : monwow.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : moolive.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mpfagent.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mpfservice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mpftray.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mrflux.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : MSASCui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : msblast.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : msconfig.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : msinfo32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : msn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mspatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mssmmc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mu0311ad.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : mxtask.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : n32scan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : n32scanw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nai_vs_stat.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nav32_loader.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nav80try.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navap.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navapsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navapw32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navauto-protect.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navdx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : naveng.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navengnavex15.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navex15.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navlu32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navrunr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navsched.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navstub.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navw32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : navwnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nc2000.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ncinst4.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nd98spst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ndd32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ndntspst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : neomonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : neowatchlog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : netarmor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : netcfg.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : netinfo.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : netmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : netscanpro.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Netscape.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : netspyhunter-1.2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : netstat.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : netutils.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nisserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nisum.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nmain.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nod32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : normist.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : norton_internet_secu_3.0_407.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : notstart.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : npf40_tw_98_nt_me_2k.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : npfmessenger.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nprotect.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : npscheck.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : npssvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nsched32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ntdetect.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ntrtscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ntxconfig.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nupdate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nupgrade.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nvapsvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nvarch16.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nvc95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nvlaunch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nvsvc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nwinst4.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nwservice.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : nwtool16.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : offguard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ogrc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : opera.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Opera_964_int_Setup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ostronet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : outpost.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : outpostinstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : outpostproinstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : padmin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : panixk.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pathping.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pavcl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pavproxy.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pavsched.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pavw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pcc2002s902.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pcc2k_76_1436.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pccclient.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pccguide.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pcciomon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pccmain.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pccntmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pccpfw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pccwin97.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pccwin98.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pcdsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pcfwallicon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pcip10117_0.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pcscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pcscanpdsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : penis32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : periscope.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : persfw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : perswf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pev.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pf2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pfwadmin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ping.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pingscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : platin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pop3trap.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : poproxy.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : popscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : portdetective.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : portmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : portmonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ppinupdt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pptbc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ppvstop.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : prckiller.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Process.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : processmonitor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : procexp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : procexplorerv1.0.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Procmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : programauditor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : proport.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : protectx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pspf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : purge.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pview.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : pview95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : qconsole.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : qserver.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rapapp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rav.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rav7.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rav7win.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rav8win32eng.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : realmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : regedit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : regedt32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Regmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rescue.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rescue32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Restart.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : route.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : routemon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rrguard.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rshell.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rstrui.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rtvscn95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : rulaunch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : Safari.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : safeweb.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieBITS.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieCrypto.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieDcomLaunch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieRpcSs.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SandboxieWUAU.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SbieCtrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SbieSvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sbserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : scan32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : scan95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : scanpm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sched.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : schedapp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : scrscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : scvhosl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sdclt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : serv95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : setupvameeval.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : setup_flowprotector_us.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sgssfw32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sh.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sharedaccess.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : shellspyinstall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : shn.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : smc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SmitfraudFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sofi.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : spf.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sphinx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : spider.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : spysweeper.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : spyxx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : SrchSTS.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : srwatch.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : ss3edit.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : st2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : supftrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : supporter5.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sweep.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sweep95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sweepnet.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sweepsrv.sys.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : swnetsup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : swreg.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : swsc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : swxcacls.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : symproxysvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : symtray.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : sysdoc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : syshelp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : taskkill.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tasklist.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : taskmgr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : taskmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : taumon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tauscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tbscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tca.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tcm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tcpsvs32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tds-3.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tds2-98.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tds2-nt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tds2.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tfak.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tfak5.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tftpd.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tgbob.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : titanin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : titaninxp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tmlisten.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tmntsrv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tracerpt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : tracert.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : trjscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : trjsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : trojantrap3.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : UCCLSID.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : UI0Detect.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : undoboot.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : unzip.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : update.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : UserAccountControlSettings.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : VACFix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vbcmserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vbcons.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vbust.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vbwin9x.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vbwinntw.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vccmserv.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vcleaner.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vcontrol.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vcsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vet32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vet95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vet98.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vettray.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vfsetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vir-help.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : virusmdpersonalfirewall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vmsrvc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vnlan300.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vnpc3000.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vpc32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vpc42.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vpcmap.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vpfw30s.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vptray.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vscan40.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vscenu6.02d30.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vsched.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vsecomr.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vshwin32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vsisetup.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vsmain.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vsmon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vsscan40.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vsstat.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vswin9xe.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vswinntse.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vswinperse.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : vvstat.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : w32dsm89.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : w9x.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : watchdog.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : webscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : webscanx.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : webtrap.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : WerFault.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wfindv32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wgfe95.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : whoswatchingme.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wimmun32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wingate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : winhlpp32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wink.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : winmgm32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : winppr32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : winrecon.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : winroute.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : winservices.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : winsfcm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wmias.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wmiav.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wnt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wradmin.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wrctrl.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : WS2Fix.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wsbgate.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wuauclt.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : wyvernworksfirewall.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : xpf202en.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : xscan.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zapro.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zapsetup3001.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zatutor.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zatutorzauinst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zauinst.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zlh.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zonalarm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zonalm2601.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : zonealarm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : _avp.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : _avp32.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : _avpcc.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : _avpm.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[IFEO] HKLM\[…]\Image File Execution Options : _findviru.exe ("C:\Documents and Settings\Sunita\164796E65735\winlogon.exe") -> DELETED
[HJPOL] HKCU\[…]\Explorer : NoFolderOptions (1) -> DELETED
[HJPOL] HKLM\[…]\Explorer : NoFolderOptions (1) -> DELETED
[HJ] HKLM\[…]\SystemRestore : DisableSR (1) -> REPLACED (0)
[HJ] HKLM\[…]\System : ConsentPromptBehaviorAdmin (0) -> REPLACED (2)
[HJ] HKLM\[…]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[…]\Security Center : AntiVirusDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[…]\Security Center : FirewallDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
184.168.105.79 viabcp.com
184.168.105.79 www.viabcp.com
184.168.105.79 bcpzonasegura.viabcp.com
184.168.105.79 bn.com.pe
184.168.105.79 www.bn.com.pe
184.168.105.79 zonasegura1.bn.com.pe
184.168.105.79 bbvabancocontinental.com
184.168.105.79 www.bbvabancocontinental.com
184.168.105.79 peb1.bbvanetlatam.com
184.168.105.79 www.peb1.bbvanetlatam.com
184.168.105.79 scotiabank.com.pe
184.168.105.79 www.scotiabank.com.pe
184.168.105.79 scotiaenlinea.scotiabank.com.pe
50.2.7.196 pichincha.com
50.2.7.196 www.pichincha.com
124.103.47.148 iniciorapido.info
100.55.123.174 www.iniciorapido.info
89.88.25.213 buscalo.in
91.201.7.78 www.buscalo.in
242.72.3.23 buscafacil.com
[…]
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
Combofix log
ComboFix 11-11-28.02 - Sunita 11/27/2011 21:40:40.1.2 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Resident AV is active
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Sunita\Application Data\PriceGong
c:\documents and settings\Sunita\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Sunita\Application Data\PriceGong\Data\z.xml
c:\documents and settings\Sunita\WINDOWS
c:\windows\CSC\d6
c:\windows\kb913800.exe
D:\Autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2011-10-27 to 2011-11-27 )))))))))))))))))))))))))))))))
.
.
2011-12-18 11:52 . 2010-09-08 00:23 114432 —-a-r- c:\windows\system32\drivers\ewusbnet.sys
2011-12-18 11:52 . 2009-10-12 04:21 100736 —-a-w- c:\windows\system32\drivers\ewusbdev.sys
2011-12-18 11:52 . 2007-08-08 17:13 24448 —-a-w- c:\windows\system32\drivers\ewdcsc.sys
2011-12-18 11:51 . 2011-12-18 11:51 ——– d—–w- c:\program files\Tata Photon+
2011-11-27 10:26 . 2011-11-27 10:26 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{9E495A9D-6C54-4C2C-8960-2DF18EF3BDFB}\offreg.dll
2011-11-26 11:05 . 2011-10-07 03:48 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{9E495A9D-6C54-4C2C-8960-2DF18EF3BDFB}\mpengine.dll
2011-11-25 11:41 . 2011-11-26 10:35 111872 —-a-w- c:\windows\system32\drivers\TrueSight.sys
2011-11-22 12:16 . 2011-11-22 12:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-22 12:05 . 2011-11-26 10:23 ——– d—–w- c:\documents and settings\Sunita\Application Data\Systweak
2011-11-22 12:05 . 2011-07-07 02:26 17280 —-a-w- c:\windows\system32\roboot.exe
2011-11-20 11:50 . 2011-11-26 10:24 ——– d—–w- C:\sh4ldr
2011-11-20 11:50 . 2011-11-20 11:50 ——– d—–w- c:\program files\Enigma Software Group
2011-11-20 11:50 . 2011-11-26 10:24 ——– d—–w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP
2011-11-20 11:50 . 2011-11-20 11:50 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2011-11-20 08:56 . 2011-11-26 10:27 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2011-11-16 08:12 . 2011-11-16 08:12 ——– d-sha-r- c:\documents and settings\Sunita\164796E65735
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-10 14:22 . 2006-03-16 04:00 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 03:48 . 2008-06-16 11:17 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-09-28 07:06 . 2006-03-16 04:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 00:41 . 2008-07-29 09:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 00:41 . 2006-03-16 04:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 00:41 . 2006-03-16 04:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20 . 2006-03-16 04:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2007-12-09 11:05 . 2007-12-09 11:05 6026816 —-a-w- c:\program files\Firefox Setup 2.0.0.11.exe
2008-08-16 06:42 . 2008-08-16 06:42 13112 —-a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2008-08-16 06:42 . 2008-08-16 06:42 70456 —-a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2008-08-16 06:42 . 2008-08-16 06:42 91448 —-a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2008-08-16 06:42 . 2008-08-16 06:42 20800 —-a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2008-08-16 06:43 . 2008-08-16 06:43 206136 —-a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2008-08-16 06:42 . 2008-08-16 06:42 31032 —-a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2008-08-16 06:42 . 2008-08-16 06:42 40248 —-a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2008-05-20 21:41 . 2008-05-20 21:41 479232 —-a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll
2008-05-20 21:41 . 2008-05-20 21:41 548864 —-a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll
2008-05-20 21:41 . 2008-05-20 21:41 626688 —-a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll
2008-06-05 02:58 . 2008-06-05 02:58 648504 —-a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2008-08-16 06:42 . 2008-08-16 06:42 23864 —-a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2011-04-14 16:26 . 2011-05-20 01:02 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\prxtbBit2.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
2011-05-09 09:49 176936 —-a-w- c:\program files\BitTorrentBar\prxtbBit2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\prxtbBit2.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{88C7F2AA-F93F-432C-8F0E-B7D85967A527}"= "c:\program files\BitTorrentBar\prxtbBit2.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-02 68856]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 57344]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-20 7581696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-07-20 86016]
"nwiz"="nwiz.exe" [2006-07-20 1519616]
"MsmqIntCert"="mqrt.dll" [2008-04-14 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 61952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-17 794713]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-19 102400]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-06-19 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-03-15 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2006-03-15 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2006-03-15 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-03-15 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-03-15 455168]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-03 413696]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2006-05-16 40960]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-08 155648]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-06-30 1447168]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-18 198160]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"BCSSync"="c:\program files\Microsoft Office\Microsoft Office Professional edition 2003\Office14\BCSSync.exe" [2010-03-13 91520]
"MobileBroadband"="c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2010-09-08 272384]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-02-27 519584]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiSpyWareDisableNotify"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\english\\setup.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Microsoft Office\\Microsoft Office Professional edition 2003\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Microsoft Office Professional edition 2003\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Microsoft Office Professional edition 2003\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Documents and Settings\\Sunita\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Documents and Settings\\Sunita\\164796E65735\\winlogon.exe"=
.
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-13 135664]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-07-07 195336]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2010-09-08 114432]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-13 135664]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-10-12 100736]
R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [2010-09-08 100736]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Microsoft Office Professional edition 2003\Office14\GROOVE.EXE [2011-06-12 31125880]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 TrueSight;TrueSight;c:\windows\system32\drivers\TrueSight.sys [2011-11-26 111872]
S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [2011-06-15 249648]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-20 468224]
S2 VmbService;Vodafone Mobile Broadband Service;c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2010-09-08 8704]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-13 11:43]
.
2011-11-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-13 11:43]
.
2011-11-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3999197343-1343777-328208992-1005Core.job
- c:\documents and settings\Sunita\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-28 11:11]
.
2011-11-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3999197343-1343777-328208992-1005UA.job
- c:\documents and settings\Sunita\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-28 11:11]
.
2011-11-27 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 09:20]
.
2011-11-26 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 06:04]
.
2011-11-27 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 06:04]
.
.
——- Supplementary Scan ——-
.
uLocal Page = hxxp://jo4y770w7vsy4e5.directorio-w.com
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://vz2k046v98318q8.directorio-w.com
mLocal Page = hxxp://vlz87cz398s45eq.directorio-w.com
mStart Page = hxxp://9x496t0ibe1q002.directorio-w.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_AU&c=64&bd=pavilion&pf=laptop
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~4\MICROS~1\Office14\ONBttnIE.dll/105
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\Sunita\Application Data\Mozilla\Firefox\Profiles\8jtin39r.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://1ef5156153z3xd4.directorio-w.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - prefs.js: network.proxy.type - 1
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS REMOVED - - - -
.
Notify-NavLogon - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-11-27 22:00
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????L?@? ???xc??????`?@?????L?@
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 5.1.2600
.
CreateFile("\\.\PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!
.
**************************************************************************
.
Completion time: 2011-11-27 22:04:56
ComboFix-quarantined-files.txt 2011-11-27 11:04
.
Pre-Run: 38,468,833,280 bytes free
Post-Run: 47,502,811,136 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /fastdetect /NoExecute=OptOut
.
- - End Of File - - DA2FB650E8E7218E06C786D7F5FC5404