This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Hijackthis Log

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has recently been having problems. I frequently get a blue screen even when running some basic applications. I also cant get rid of this thing called Mirar. any help would be greatly appreciated. and here is the log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:06:09, on 12/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Avast4\ashDisp.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {0347C33E-8762-4905-BF09-768834316C61} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: (no name) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - (no file)
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file)
O3 - Toolbar: Mirar - {CF9C3686-E61C-433A-864A-E04DD590B578} - (no file)
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\RunOnce: [gi400296855] "C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\gi44HUHQ.exe" /resume:"C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\3644HOGV" /exename:"C:\a Torrents folder\New Folder\SpyHunter Security Suite v3.7.19 [h33t]-MasterUploader\SpyHunter Security Suite v3.7.19 [h33t]-MasterUploader\Setup\spyhunterS.exe"
O4 - HKUS\S-1-5-18\..\Run: [vxvjeppy.exe] C:\WINDOWS\vxvjeppy.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [jrfyvaod.exe] C:\WINDOWS\jrfyvaod.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [vxvjeppy.exe] C:\WINDOWS\vxvjeppy.exe (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Download with Go!Zilla - file://C:\Program Files\Go!Zilla\download-with-gozilla.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.antimalwareguard.com
O15 - Trusted Zone: *.antispyexpert.com
O15 - Trusted Zone: *.avsystemcare.com
O15 - Trusted Zone: *.gomyhit.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.onerateld.com
O15 - Trusted Zone: *.safetydownload.com
O15 - Trusted Zone: *.spyguardpro.com
O15 - Trusted Zone: *.storageguardsoft.com
O15 - Trusted Zone: *.trustedantivirus.com
O15 - Trusted Zone: *.virusremover2008.com
O15 - Trusted Zone: *.virusschlacht.com
O15 - Trusted Zone: *.amaena.com (HKLM)
O15 - Trusted Zone: *.avsystemcare.com (HKLM)
O15 - Trusted Zone: *.onerateld.com (HKLM)
O15 - Trusted Zone: *.safetydownload.com (HKLM)
O15 - Trusted Zone: *.trustedantivirus.com (HKLM)
O15 - Trusted Zone: *.virusschlacht.com (HKLM)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} -
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} (Java Plug-in 1.4.2_03) -
O20 - AppInit_DLLs: ctsgwt.dll
O20 - Winlogon Notify: rwachyx - rwachyx32.dll (file missing)
O23 - Service: Amazon Unbox Video Service (ADVService) - Amazon.com - C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)
O24 - Desktop Component 0: (no name) - http://sportsbybrooks.com/sbbgig1426.jpg

–
End of file - 9284 bytes
hello

Download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.
  • Open the OTScanIt2 folder and double-click on OTScanIt.exe to start the program. Make sure you close all other programs and don't use the PC while the scan runs.
  • Under File Age at the top, change it from 30 days to 90 days
  • Under Additional Scans check the boxes beside Reg - ColumnHandlers, Reg - Desktop Components, Reg - Disabled MS Config Items, Reg - File Associations, Reg - NetSvcs, Reg - Protocol Filters, Reg - Protocol Handlers, Reg - SafeBoot Minimal, Reg - SafeBoot Network, Reg - Session Manager Settings, Reg - Winsock2 Catalogs, File - Lop Check, File - Purity Scan, Files - Signature Check, and Evnt - EventViewer Logs ( Last 10 Errors).
  • Under Rootkit Search change it to Yes
  • Under the Custom Scans box at the bottom left paste the following in

    %systemroot%\Prefetch\*.* /s
    %systemroot%\system32\drivers\*.dat
    %systemroot%\Temp\bca4e2da.$$$
    %systemroot%\Temp\ed47fa.$
    %systemroot%\Temp\fa56d7ec.$$$
    %systemroot%\Temp\*.$$$
    %systemroot%\System32\antiwpa.dll
    %SYSTEMDRIVE%\*.epk
    %systemroot%\*.epk
    %systemroot%\system32\*.epk
    %systemroot%\system32\bb*.dat
    %systemroot%\system32\cookie*.dat
    %systemroot%\system32\kaxs.dat
    %systemroot%\system32\ps*.dat
    %systemroot%\system32\*32.sys
    %systemroot%\*.dr
    %SYSTEMDRIVE%\*.dr
    %systemroot%\system32\*.dr
    %systemroot%\system32\nods32.dll
    %systemroot%\*.res
    %SYSTEMDRIVE%\*.res
    %systemroot%\system32\*.res
    %systemroot%\system32\sockins32.dll
    %systemroot%\system32\Spool\*.*
    %systemroot%\system32\Spool\*.exe
    %systemroot%\system32\Spool\*.rar /s
    %systemroot%\system32\Spool\*.zip /s
    %systemroot%\system32\Spool\*.dat /s
    %ProgramFiles%\MSN Messenger\*.zip
    %ProgramFiles%\MSN Messenger\*.exe
    %ProgramFiles%\MSN Messenger\*.rar
    %PROGRAMFILES%\*crack*.
    %PROGRAMFILES%\*keygen*.
    %SYSTEMDRIVE%\*crack*.
    %SYSTEMDRIVE%\*keygen*.
    %SYSTEMDRIVE%\*.zip
    %SYSTEMDRIVE%\*.rar
    %SYSTEMDRIVE%\*.exe
    %SYSTEMDRIVE%\*.dll
    %systemroot%\*.zip
    %systemroot%\*.rar
    %systemroot%\system32\*.zip
    %systemroot%\system32\*.rar
    %PROGRAMFILES%\*.zip
    %PROGRAMFILES%\*.rar
    %PROGRAMFILES%\*.exe
    %PROGRAMFILES%\*.dll
    %DESKTOP%\*.zip
    %DESKTOP%\*.rar
    %DESKTOP%\*.exe
    %DESKTOP%\*crack*.
    %DESKTOP%\*keygen*.
    %PROGRAMFILES%\Common Files\*.*
    %PROGRAMFILES%\Common Files\*bak*.
    %systemroot%\SYSTEM32\*bak*.
    %PROGRAMFILES%\*bak*.
    %systemroot%\ime\imjp8_1\*bak*.
    %PROGRAMFILES%\QuickTime\*bak*.
    %PROGRAMFILES%\Viewpoint\Viewpoint Manager\*bak*.
    %PROGRAMFILES%\Analog Devices\Core\*bak*.
    %SYSTEMDRIVE%\hp\KBD\*bak*.
    %PROGRAMFILES%\Adobe\Photoshop Album Starter Edition\3.2\Apps\*bak*.
    %PROGRAMFILES%\BillP Studios\WinPatrol\*bak*.
    %PROGRAMFILES%\BroadJump\Client Foundation\*bak*.
    %PROGRAMFILES%\Common Files\Real\Update_OB\*bak*.
    %PROGRAMFILES%\Common Files\Sonic\Update Manager\*bak*.
    %PROGRAMFILES%\\Google\GoogleToolbarNotifier\*bak*.
    %PROGRAMFILES%\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\*bak*.
    %PROGRAMFILES%\Yahoo!\Messenger\*bak*.
    %USERNAME%\*.zip
    %USERNAME%\*.rar
    %USERNAME%\*.exe
    %USERPROFILE%\*.zip
    %USERPROFILE%\*.rar
    %USERPROFILE%\*.exe
    %ALLUSERSPROFILE%\*.zip
    %ALLUSERSPROFILE%\*.rar
    %ALLUSERSPROFILE%\*.exe
    %APPDATA%\*.zip
    %APPDATA%\*.rar
    %APPDATA%\*.exe
    %ALLUSERSSTARTMENU%\*.zip
    %ALLUSERSSTARTMENU%\*.rar
    %ALLUSERSSTARTMENU%\*.exe
    %ALLUSERSSTARTUP%\*.zip
    %ALLUSERSSTARTUP%\*.rar
    %ALLUSERSSTARTUP%\*.exe
    %ALLUSERSPROGRAMS%\*.zip
    %ALLUSERSPROGRAMS%\*.rar
    %ALLUSERSPROGRAMS%\*.exe
    %ALLUSERSAPPDATA%\*.zip
    %ALLUSERSAPPDATA%\*.rar
    %ALLUSERSAPPDATA%\*.exe
    %APPDATA%\*.zip
    %APPDATA%\*.rar
    %APPDATA%\*.exe
    %APPDATA%\*.dat
    %APPDATA%\*.dll
    %QUICKLAUNCH%\*.zip
    %QUICKLAUNCH%\*.rar
    %QUICKLAUNCH%\*.exe
    %STARTUP%\*.zip
    %STARTUP%\*.rar
    %STARTUP%\*.exe
    %STARTMENU%\*.zip
    %STARTMENU%\*.rar
    %STARTMENU%\*.exe
    %MYDOCUMENTS%\*.zip
    %MYDOCUMENTS%\*.rar
    %MYDOCUMENTS%\*.exe
    %MYDOCUMENTS%\*crack*.
    %MYDOCUMENTS%\*keygen*.
    %PROGRAMFILES%\Mozilla Firefox\plugins\*.*
    %PROGRAMFILES%\Internet Explorer\*.*
    %PROGRAMFILES%\Internet Explorer\PLUGINS\*.*
    %PROGRAMFILES%\Mozilla Firefox\*.zip /s
    %PROGRAMFILES%\Mozilla Firefox\*.rar /s
    %PROGRAMFILES%\Mozilla Firefox\*.exe /s
    %PROGRAMFILES%\Internet Explorer\*.zip /s
    %PROGRAMFILES%\Internet Explorer\*.rar /s
    %PROGRAMFILES%\Internet Explorer\*.exe /s
    %SYSTEMDRIVE%\*.dat
    %SYSTEMDRIVE%\*.sys
    %SYSTEMROOT%\*.dat
    %SYSTEMROOT%\*.sys
    %systemroot%\system32\drivers\*.exe /s
    %systemroot%\system32\drivers\*.zip /s
    %systemroot%\system32\drivers\*.rar /s
    %systemroot%\system\*.exe /s
    %systemroot%\system\*.zip /s
    %systemroot%\system\*.rar /s
    %systemroot%\AppPatch\*.exe /s
    %systemroot%\AppPatch\*.zip /s
    %systemroot%\AppPatch\*.rar /s
    %systemroot%\Cache\*.*
    %systemroot%\Downloaded Program Files\*.*
    %systemroot%\Fonts\*.exe /s
    %systemroot%\Fonts\*.zip /s
    %systemroot%\Fonts\*.rar /s
    %systemroot%\Fonts\*.dll /s
    %systemroot%\Help\*.exe /s
    %systemroot%\Help\*.zip /s
    %systemroot%\Help\*.rar /s
    %systemroot%\Tasks\*.*
    %APPDATA%\*.sys
    %APPDATA%\Google\*.*
    %systemroot%\system32\serauth1.dll
    %systemroot%\system32\serauth2.dll
    %systemroot%\system32\sysaudio.sys
    %PROGRAMFILES%\*TinyProxy*.
    HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla|extensions /rs
    %systemroot%\system32\inf\*.exe /s
    %systemroot%\system32\inf\*.zip /s
    %systemroot%\system32\inf\*.rar /s
    %systemroot%\system32\inf\*.dll /s
    %PROGRAMFILES%\Bitlord\Downloads\*.zip /s
    %PROGRAMFILES%\Bitlord\Downloads\*.rar /s
    %PROGRAMFILES%\Bitlord\Downloads\*.exe /s
    %PROGRAMFILES%\Bitlord\Downloads\*crack*.
    %PROGRAMFILES%\Bitlord\Downloads\*keygen*.
    %PROGRAMFILES%\eMule\Incoming\*.zip /s
    %PROGRAMFILES%\eMule\Incoming\*.rar /s
    %PROGRAMFILES%\eMule\Incoming\*.exe /s
    %PROGRAMFILES%\eMule\Incoming\*crack*.
    %PROGRAMFILES%\eMule\Incoming\*keygen*.
    %ProgramFiles%\Bittorent\downloads\*.zip /s
    %ProgramFiles%\Bittorent\downloads\*.exe /s
    %ProgramFiles%\Bittorent\downloads\*.rar /s
    %PROGRAMFILES%\Bittorent\Downloads\*crack*.
    %PROGRAMFILES%\Bittorent\Downloads\*keygen*.
    %ProgramFiles%\Bearshare\Shared\*.zip /s
    %ProgramFiles%\Bearshare\Shared\*.exe /s
    %ProgramFiles%\Bearshare\Shared\*.rar /s
    %ProgramFiles%\Bearshare\Shared\*crack*.
    %ProgramFiles%\Bearshare\Shared\*keygen*.
    %ProgramFiles%\Morpheus\My Shared Folder\*.zip /s
    %ProgramFiles%\Morpheus\My Shared Folder\*.exe /s
    %ProgramFiles%\Morpheus\My Shared Folder\*.rar /s
    %ProgramFiles%\Morpheus\My Shared Folder\*crack*.
    %ProgramFiles%\Morpheus\My Shared Folder\*keygen*.
    %ProgramFiles%\uTorrent\Downloads\*.zip /s
    %ProgramFiles%\uTorrent\Downloads\*.exe /s
    %ProgramFiles%\uTorrent\Downloads\*.rar /s
    %ProgramFiles%\uTorrent\Downloads\*crack*.
    %ProgramFiles%\uTorrent\Downloads\*keygen*.
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*.zip /s
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*.exe /s
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*.rar /s
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*crack*.
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*keygen*.
    %ProgramFiles%\Kazaa\My Shared Folder\*.zip /s
    %ProgramFiles%\Kazaa\My Shared Folder\*.exe /s
    %ProgramFiles%\Kazaa\My Shared Folder\*.rar /s
    %ProgramFiles%\Kazaa\My Shared Folder\*crack*.
    %ProgramFiles%\Kazaa\My Shared Folder\*keygen*.
    %ProgramFiles%\Icq\Shared Files\*.zip /s
    %ProgramFiles%\Icq\Shared Files\*.exe /s
    %ProgramFiles%\Icq\Shared Files\*.rar /s
    %ProgramFiles%\Icq\Shared Files\*crack*.
    %ProgramFiles%\Icq\Shared Files\*keygen*.
    %ProgramFiles%\Direct Connect\Received Files\*.zip /s
    %ProgramFiles%\Direct Connect\Received Files\*.exe /s
    %ProgramFiles%\Direct Connect\Received Files\*.rar /s
    %ProgramFiles%\Direct Connect\Received Files\*crack*.
    %ProgramFiles%\Direct Connect\Received Files\*keygen*.
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.zip
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.rar
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.exe
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*crack*.
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*keygen*.
    %APPDATA%\Opera\Opera\profile\widgets\*.*
    %PROGRAMFILES%\Opera\program\plugins\*.* /s
    %APPDATA%\Opera\Opera\profile\toolbar\*.* /s




  • Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and post the information back here in an attachment. I will review it when it comes in. The last line is < End of Report >, so make sure that is the last line in the attached report.


Make sure you attach the report in your reply. If it is too big to upload, then zip the text file and upload it that way
hello

Start OTScanIt2. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Unregister Dlls]
[Win32 Services - Safe List]
YY -> (Viewpoint Manager Service) Viewpoint Manager Service [Win32_Own | Auto | Stopped] ->
[Registry - Safe List]
< Internet Explorer Settings [HKEY_CURRENT_USER\] > ->
YN -> HKEY_CURRENT_USER\: URLSearchHooks\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {02478D38-C3F9-4efb-9B51-7695ECA05670} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {0347C33E-8762-4905-BF09-768834316C61} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {31FF080D-12A3-439A-A2EF-4BA95A3148E8} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {9ECB9560-04F9-4bbc-943D-298DDF1699E1} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {B56A7D7D-6927-48C8-A975-17DF180C71AC} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {BDF3E430-B101-42AD-A544-FADC6B084872} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
YN -> "{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> "{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> "{CF9C3686-E61C-433A-864A-E04DD590B578}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Mirar]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> ShellBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\"{4982D40A-C53B-4615-B15B-B5B5E98D167C}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\"{4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\"{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\"{CF9C3686-E61C-433A-864A-E04DD590B578}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Mirar]
YN -> WebBrowser\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "KernelFaultCheck" -> [%systemroot%\system32\dumprep 0 -k]
YN -> "NWEReboot" -> []
YN -> "VirtualCloneDrive" -> ["C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s]
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "12ZFG94-F641-2SF-K31P-5N1ER6H6L2" -> %SystemDrive%\RECYCLER\S-1-5-21-9990256786-6420501526-267239883-2198\service.exe [C:\RECYCLER\S-1-5-21-9990256786-6420501526-267239883-2198\service.exe]
YN -> "Aim6" -> []
YN -> "MsnMsgr" -> %ProgramFiles%\MSN Messenger\MsnMsgr.Exe ["C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background]
YN -> "Uniblue RegistryBooster 2" -> [C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S]
< RunOnce [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
YY -> "gi400296855" -> %UserProfile%\Local Settings\Temp\gi44HUHQ.exe ["C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\gi44HUHQ.exe" /resume:"C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\3644HOGV" /exename:"C:\a Torrents folder\New Folder\SpyHunter Security Suite v3.7.19 [h33t]-MasterUploader\SpyHunter Security Suite v3.7.19 [h33t]-MasterUploader\Setup\spyhunterS.exe"]
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\
YN -> &AOL Toolbar search -> %ProgramFiles%\AOL Toolbar\toolbar.dll [res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML]
YN -> Download with Go!Zilla -> %ProgramFiles%\Go!Zilla\download-with-gozilla.html [file://C:\Program Files\Go!Zilla\download-with-gozilla.html]
YN -> E&xport to Microsoft Excel -> %SystemDrive%\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000]
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\
YN -> {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger]
YN -> {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{2D663D1A-8670-49D9-A1A5-4C56B4E14E84}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\"{4982D40A-C53B-4615-B15B-B5B5E98D167C}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\"{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}" [HKLM] -> [Reg Error: Value MenuText does not exist or could not be read.]
YN -> CmdMapping\\"{D6E814A0-E0C5-11d4-8D29-0050BA6940E3}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger]
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
YN -> amaena.com .[*]-> Trusted sites

YN -> avsystemcare.com .[*]-> Trusted sites

YN -> onerateld.com .[*]-> Trusted sites

YN -> safetydownload.com .[*]-> Trusted sites

YN -> trustedantivirus.com .[*]-> Trusted sites

YN -> virusschlacht.com .[*]-> Trusted sites

< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
YN -> amaena.com .[*]-> Trusted sites

YN -> antimalwareguard.com .[*]-> Trusted sites

YN -> antispyexpert.com .[*]-> Trusted sites

YN -> objects_aol.com [*]-> Out of zone range - ( 5 )

YN -> avsystemcare.com .[*]-> Trusted sites

YN -> gomyhit.com .[*]-> Trusted sites

YN -> imagesrvr.com .[*]-> Trusted sites

YN -> onerateld.com .[*]-> Trusted sites

YN -> safetydownload.com .[*]-> Trusted sites

YN -> spyguardpro.com .[*]-> Trusted sites

YN -> storageguardsoft.com .[*]-> Trusted sites

YN -> trustedantivirus.com .[*]-> Trusted sites

YN -> virusremover2008.com .[*]-> Trusted sites

YN -> virusschlacht.com .[*]-> Trusted sites

< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\
YN -> {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls
YN -> ctsgwt.dll ->
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
YN -> rwachyx ->
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
YN -> "C:\Program Files\BitTorrent\btdownloadgui.exe" -> C:\Program Files\BitTorrent\btdownloadgui.exe [C:\Program Files\BitTorrent\btdownloadgui.exe:*:Enabled:btdownloadgui]
[Registry - Additional Scans - Safe List]
< Disabled MSConfig Registry Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\
YN -> Orb hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
< SafeBoot-Minimal Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\
YN -> ati2ycxx.sys -> Driver
< SafeBoot-Network Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\
YN -> ati2ycxx.sys -> Driver
[Files/Folders - Created Within 90 Days]
NY -> 1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> HJTInstall.exe -> %UserProfile%\Desktop\HJTInstall.exe
NY -> HJTsetup.exe -> %UserProfile%\Desktop\HJTsetup.exe
NY -> SpyHunter.lnk -> %AllUsersProfile%\Desktop\SpyHunter.lnk
NY -> Enigma Software Group -> %ProgramFiles%\Enigma Software Group
NY -> VundoFix Backups -> %SystemDrive%\VundoFix Backups
NY -> tmp.reg -> %SystemRoot%\System32\tmp.reg
NY -> VCCLSID.exe -> %SystemRoot%\System32\VCCLSID.exe
NY -> SrchSTS.exe -> %SystemRoot%\System32\SrchSTS.exe
NY -> swreg.exe -> %SystemRoot%\System32\swreg.exe
NY -> VACFix.exe -> %SystemRoot%\System32\VACFix.exe
NY -> o4Patch.exe -> %SystemRoot%\System32\o4Patch.exe
NY -> IEDFix.exe -> %SystemRoot%\System32\IEDFix.exe
NY -> IEDFix.C.exe -> %SystemRoot%\System32\IEDFix.C.exe
NY -> 404Fix.exe -> %SystemRoot%\System32\404Fix.exe
NY -> swxcacls.exe -> %SystemRoot%\System32\swxcacls.exe
NY -> Process.exe -> %SystemRoot%\System32\Process.exe
NY -> dumphive.exe -> %SystemRoot%\System32\dumphive.exe
NY -> swsc.exe -> %SystemRoot%\System32\swsc.exe
NY -> WS2Fix.exe -> %SystemRoot%\System32\WS2Fix.exe
NY -> ethnqkra.sys -> %SystemRoot%\System32\drivers\ethnqkra.sys
NY -> IUpd721 -> %AppData%\IUpd721
NY -> VC -> %SystemRoot%\System32\VC
NY -> uv9 -> %SystemRoot%\System32\uv9
NY -> ki3 -> %SystemRoot%\System32\ki3
NY -> bin -> %SystemRoot%\System32\bin
NY -> Temp -> %SystemDrive%\Temp
NY -> .# -> %UserProfile%\Local Settings\Application Data\.#
NY -> -663803565 -> %SystemDrive%\-663803565
NY -> pcibigzt.job -> %SystemRoot%\tasks\pcibigzt.job
[File - Lop Check]
NY -> SBSI -> C:\Documents and Settings\All Users\Application Data\SBSI
NY -> uTorrent -> C:\Documents and Settings\Compaq_Owner\Application Data\uTorrent
NY -> Viewpoint -> C:\Documents and Settings\Compaq_Owner\Application Data\Viewpoint
NY -> pcibigzt.job -> C:\WINDOWS\Tasks\pcibigzt.job
[Custom Scans]
NY -> shakira-coolbuddy.zip -> C:\WINDOWS\shakira-coolbuddy.zip
NY -> pcibigzt.job -> C:\WINDOWS\Tasks\pcibigzt.job
[Empty Temp Folders]
[Start Explorer]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.




Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
here's the new OTScanIt2 info:

Process Explorer.EXE killed successfully!
[Win32 Services - Safe List]
Service Viewpoint Manager Service stopped successfully!
Service Viewpoint Manager Service deleted successfully!
File not found.
[Registry - Safe List]
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0347C33E-8762-4905-BF09-768834316C61}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31FF080D-12A3-439A-A2EF-4BA95A3148E8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31FF080D-12A3-439A-A2EF-4BA95A3148E8}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9ECB9560-04F9-4bbc-943D-298DDF1699E1}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9ECB9560-04F9-4bbc-943D-298DDF1699E1}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B56A7D7D-6927-48C8-A975-17DF180C71AC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B56A7D7D-6927-48C8-A975-17DF180C71AC}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDF3E430-B101-42AD-A544-FADC6B084872}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{CF9C3686-E61C-433A-864A-E04DD590B578} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF9C3686-E61C-433A-864A-E04DD590B578}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4982D40A-C53B-4615-B15B-B5B5E98D167C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4982D40A-C53B-4615-B15B-B5B5E98D167C}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CF9C3686-E61C-433A-864A-E04DD590B578} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF9C3686-E61C-433A-864A-E04DD590B578}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\NWEReboot not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\VirtualCloneDrive deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\12ZFG94-F641-2SF-K31P-5N1ER6H6L2 deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Aim6 not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\MsnMsgr deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Uniblue RegistryBooster 2 deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\\gi400296855 deleted successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\gi44HUHQ.exe moved successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&AOL; Toolbar search\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download with Go!Zilla\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\E&xport; to Microsoft Excel\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{2D663D1A-8670-49D9-A1A5-4C56B4E14E84} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D663D1A-8670-49D9-A1A5-4C56B4E14E84}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{4982D40A-C53B-4615-B15B-B5B5E98D167C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4982D40A-C53B-4615-B15B-B5B5E98D167C}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D6E814A0-E0C5-11d4-8D29-0050BA6940E3}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\amaena.com\\* deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avsystemcare.com\\* deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\onerateld.com\\* deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\safetydownload.com\\* deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\trustedantivirus.com\\* deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\virusschlacht.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\amaena.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\antimalwareguard.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\antispyexpert.com\\* deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\objects_aol.com\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avsystemcare.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\gomyhit.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\imagesrvr.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\onerateld.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\safetydownload.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyguardpro.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\storageguardsoft.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\trustedantivirus.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\virusremover2008.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\virusschlacht.com\\* deleted successfully.
Starting removal of ActiveX control {04E214E5-63AF-4236-83C6-A7ADCBF9BD02}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{04E214E5-63AF-4236-83C6-A7ADCBF9BD02}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04E214E5-63AF-4236-83C6-A7ADCBF9BD02}\ not found.
Starting removal of ActiveX control {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FCDF9D9-A28B-480F-8C3D-581F119A8AB8}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FCDF9D9-A28B-480F-8C3D-581F119A8AB8}\ not found.
Starting removal of ActiveX control {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B38870E4-7ECB-40DA-8C6A-595F0A5519FF}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B38870E4-7ECB-40DA-8C6A-595F0A5519FF}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\Contains\Files\ not found.
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:ctsgwt.dll deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rwachyx\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\BitTorrent\btdownloadgui.exe deleted successfully.
[Registry - Additional Scans - Safe List]
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Orb hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ not found.
File not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2ycxx.sys\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ati2ycxx.sys\ deleted successfully.
[Files/Folders - Created Within 90 Days]
File delete failed. C:\WINDOWS\S529E7295.tmp scheduled to be deleted on reboot.
C:\Documents and Settings\Compaq_Owner\Desktop\HJTInstall.exe moved successfully.
C:\Documents and Settings\Compaq_Owner\Desktop\HJTsetup.exe moved successfully.
C:\Documents and Settings\All Users\Desktop\SpyHunter.lnk moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Rollback folder moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Download folder moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter folder moved successfully.
C:\Program Files\Enigma Software Group folder moved successfully.
C:\VundoFix Backups folder moved successfully.
C:\WINDOWS\System32\tmp.reg moved successfully.
C:\WINDOWS\System32\VCCLSID.exe moved successfully.
C:\WINDOWS\System32\SrchSTS.exe moved successfully.
C:\WINDOWS\System32\swreg.exe moved successfully.
C:\WINDOWS\System32\VACFix.exe moved successfully.
C:\WINDOWS\System32\o4Patch.exe moved successfully.
C:\WINDOWS\System32\IEDFix.exe moved successfully.
C:\WINDOWS\System32\IEDFix.C.exe moved successfully.
C:\WINDOWS\System32\404Fix.exe moved successfully.
C:\WINDOWS\System32\swxcacls.exe moved successfully.
C:\WINDOWS\System32\Process.exe moved successfully.
C:\WINDOWS\System32\dumphive.exe moved successfully.
C:\WINDOWS\System32\swsc.exe moved successfully.
C:\WINDOWS\System32\WS2Fix.exe moved successfully.
C:\WINDOWS\System32\drivers\ethnqkra.sys moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\IUpd721\Logs folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\IUpd721 folder moved successfully.
C:\WINDOWS\System32\VC folder moved successfully.
C:\WINDOWS\System32\uv9 folder moved successfully.
C:\WINDOWS\System32\ki3 folder moved successfully.
C:\WINDOWS\System32\bin folder moved successfully.
C:\Temp\tn3 folder moved successfully.
C:\Temp\DIV55 folder moved successfully.
C:\Temp folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\.# folder moved successfully.
C:\-663803565 moved successfully.
C:\WINDOWS\tasks\pcibigzt.job moved successfully.
[File - Lop Check]
C:\Documents and Settings\All Users\Application Data\SBSI\ORUN folder moved successfully.
C:\Documents and Settings\All Users\Application Data\SBSI folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\uTorrent folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03 folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02 folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01 folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00 folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\Viewpoint\Viewpoint Experience Technology\Resources folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\Viewpoint\Viewpoint Experience Technology folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\Viewpoint folder moved successfully.
File C:\WINDOWS\Tasks\pcibigzt.job not found!
[Custom Scans]
C:\WINDOWS\shakira-coolbuddy.zip moved successfully.
File/Folder C:\WINDOWS\Tasks\pcibigzt.job not found.
[Empty Temp Folders]
File delete failed. C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\etilqs_XM88fwNvtt640dJhZvns scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
RecycleBin -> emptied.
Explorer started successfully
< End of fix log >
OTScanIt2 by OldTimer - Version 1.0.4.2 fix logfile created on 12312008_171458

Files moved on Reboot…
File move failed. C:\WINDOWS\S529E7295.tmp scheduled to be moved on reboot.
File C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\etilqs_XM88fwNvtt640dJhZvns not found!
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat moved successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\XUL.mfl moved successfully.

Registry entries deleted on Reboot…

and here is the combofix.txt:

ComboFix 08-12-30.02 - Compaq_Owner 2008-12-31 17:22:36.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.447.104 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 081230-0] *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Compaq_Owner\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\Mozilla Firefox\plugins\npclntax.dll
c:\windows\IE4 Error Log.txt
c:\windows\Readme.txt
c:\windows\system32\TDSSmtvd.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_FCI
——-\Legacy_ICF
——-\Legacy_MSDIRECTX
——-\Legacy_NPF
——-\Legacy_RESTORE
——-\Legacy_TDSSSERV.SYS
——-\Service_TDSSserv.sys


((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-31 )))))))))))))))))))))))))))))))
.

2008-12-31 17:14 . 2008-12-31 17:14 d——– C:\_OTScanIt
2008-12-30 12:05 . 2008-12-30 12:05 d——– c:\program files\Trend Micro
2008-12-29 05:43 . 2008-12-31 05:54 d——– C:\1
2008-12-26 20:34 . 2008-12-26 20:34 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Real Audio (Helix) Encoder.bmp
2008-12-26 20:34 . 2008-12-26 20:34 11,473 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Real Audio (Helix) Encoder.dat
2008-12-26 20:31 . 2008-12-26 20:31 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.bmp
2008-12-26 20:31 . 2008-12-26 20:31 13,785 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2008-12-23 17:56 . 2008-12-23 17:56 d——– c:\documents and settings\Compaq_Owner\Application Data\Uniblue
2008-12-23 17:55 . 2008-12-23 17:55 d——– c:\program files\Uniblue
2008-12-23 17:36 . 2008-12-23 17:36 d——– c:\documents and settings\Compaq_Owner\Application Data\dBpoweramp
2008-12-23 17:21 . 2008-12-23 17:21 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Windows Media Audio 10 Codec.bmp
2008-12-23 17:21 . 2008-12-23 17:20 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Shorten Codec.bmp
2008-12-23 17:21 . 2008-12-23 17:21 3,411 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Shorten Codec.dat
2008-12-23 17:21 . 2008-12-23 17:21 3,400 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Windows Media Audio 10 Codec.dat
2008-12-23 17:19 . 2008-12-23 17:19 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Midi Decoder.bmp
2008-12-23 17:19 . 2008-12-23 17:19 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp m4a Codec.bmp
2008-12-23 17:19 . 2008-12-23 17:19 3,625 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp m4a Codec.dat
2008-12-23 17:19 . 2008-12-23 17:19 2,649 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Midi Decoder.dat
2008-12-23 17:02 . 2008-12-23 17:02 d——– c:\documents and settings\Compaq_Owner\Application Data\AccurateRip
2008-12-23 16:53 . 2008-12-23 16:53 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp WavPack Codec.bmp
2008-12-23 16:53 . 2008-12-23 16:53 3,008 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp WavPack Codec.dat
2008-12-23 16:52 . 2008-12-23 16:56 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp TTA Codec.bmp
2008-12-23 16:52 . 2008-12-23 16:57 3,417 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp TTA Codec.dat
2008-12-23 16:46 . 2008-12-23 16:45 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP WMA V9 Codec.bmp
2008-12-23 16:46 . 2008-12-23 16:46 2,181 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP WMA V9 Codec.dat
2008-12-23 16:45 . 2008-12-23 16:45 28,898 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP VQF Codec.bmp
2008-12-23 16:45 . 2008-12-23 16:44 28,898 –a—— c:\windows\system32\SpoonUninstall-dBPowerAMP Real Audio Encoder R3.bmp
2008-12-23 16:45 . 2008-12-23 16:45 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Winamp Codec.bmp
2008-12-23 16:45 . 2008-12-23 16:45 2,995 –a—— c:\windows\system32\SpoonUninstall-dBPowerAMP Real Audio Encoder R3.dat
2008-12-23 16:45 . 2008-12-23 16:45 2,234 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP VQF Codec.dat
2008-12-23 16:45 . 2008-12-23 16:45 1,327 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Winamp Codec.dat
2008-12-23 16:44 . 2008-12-23 17:20 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.bmp
2008-12-23 16:44 . 2008-12-23 17:20 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Musepack Codec.bmp
2008-12-23 16:44 . 2008-12-23 16:44 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Real Audio Codec.bmp
2008-12-23 16:44 . 2008-12-23 16:44 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP FAAC Mp4 Codec.bmp
2008-12-23 16:44 . 2008-12-23 17:20 3,283 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Musepack Codec.dat
2008-12-23 16:44 . 2008-12-23 17:20 3,065 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat
2008-12-23 16:44 . 2008-12-23 16:44 1,928 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Real Audio Codec.dat
2008-12-23 16:44 . 2008-12-23 16:44 620 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP FAAC Mp4 Codec.dat
2008-12-23 16:43 . 2008-12-23 16:43 27,958 –a—— c:\windows\system32\SpoonUninstall-dMC mp3PRO (CLI) Encoder.bmp
2008-12-23 16:43 . 2008-12-23 16:43 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Mp4 & AAC Decode Codec.bmp
2008-12-23 16:43 . 2008-12-23 16:43 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP mp3PRO Input Codec.bmp
2008-12-23 16:43 . 2008-12-23 16:43 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP AAC to Mp4 Codec.bmp
2008-12-23 16:43 . 2008-12-23 16:43 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP AAC Codec.bmp
2008-12-23 16:43 . 2008-12-23 16:43 2,467 –a—— c:\windows\system32\SpoonUninstall-dMC mp3PRO (CLI) Encoder.dat
2008-12-23 16:43 . 2008-12-23 16:43 2,218 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Mp4 & AAC Decode Codec.dat
2008-12-23 16:43 . 2008-12-23 16:43 2,074 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP mp3PRO Input Codec.dat
2008-12-23 16:43 . 2008-12-23 16:43 1,122 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP AAC Codec.dat
2008-12-23 16:43 . 2008-12-23 16:43 516 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP AAC to Mp4 Codec.dat
2008-12-23 16:42 . 2008-12-23 17:19 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Monkeys Audio Codec.bmp
2008-12-23 16:42 . 2008-12-23 17:18 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp FLAC Codec.bmp
2008-12-23 16:42 . 2008-12-23 17:11 28,898 –a—— c:\windows\system32\SpoonUninstall-dBPowerAMP AIFF codec r4.bmp
2008-12-23 16:42 . 2008-12-23 17:20 3,107 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Monkeys Audio Codec.dat
2008-12-23 16:42 . 2008-12-23 17:19 2,987 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2008-12-23 16:42 . 2008-12-23 17:11 739 –a—— c:\windows\system32\SpoonUninstall-dBPowerAMP AIFF codec r4.dat
2008-12-23 16:39 . 2008-12-23 17:14 4,044,152 –a—— c:\windows\system32\SpoonUninstall.exe
2008-12-23 16:38 . 2008-12-23 16:38 d——– c:\program files\Illustrate
2008-12-23 15:27 . 2008-12-31 12:24 d——– C:\AudioConverter
2008-12-23 11:27 . 2008-12-23 12:17 398 –a—— c:\windows\AudioConverter.INI
2008-12-23 11:26 . 2008-12-23 11:26 d——– c:\program files\easetech
2008-12-22 11:02 . 2008-12-22 11:02 d——– c:\program files\MSXML 4.0
2008-12-21 22:20 . 2008-12-21 23:16 d——– c:\windows\system32\CatRoot_bak
2008-12-21 22:09 . 2008-12-21 22:09 0 –ah—– c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2008-12-21 22:09 . 2008-12-21 22:09 0 –ah—– c:\windows\system32\drivers\Msft_Kernel_zumbus_01007.Wdf
2008-12-21 22:08 . 2008-03-21 13:57 14,640 ——— c:\windows\system32\spmsgXP_2k3.dll
2008-12-21 22:07 . 2008-10-16 14:38 6,066,176 —–c— c:\windows\system32\dllcache\ieframe.dll
2008-12-21 22:07 . 2007-04-17 03:32 2,455,488 —–c— c:\windows\system32\dllcache\ieapfltr.dat
2008-12-21 22:07 . 2007-03-07 23:10 991,232 —–c— c:\windows\system32\dllcache\ieframe.dll.mui
2008-12-21 22:07 . 2008-10-16 14:38 459,264 —–c— c:\windows\system32\dllcache\msfeeds.dll
2008-12-21 22:07 . 2008-10-16 14:38 383,488 —–c— c:\windows\system32\dllcache\ieapfltr.dll
2008-12-21 22:07 . 2008-10-16 14:38 267,776 —–c— c:\windows\system32\dllcache\iertutil.dll
2008-12-21 22:07 . 2008-10-16 14:38 63,488 —–c— c:\windows\system32\dllcache\icardie.dll
2008-12-21 22:07 . 2008-10-16 14:38 52,224 —–c— c:\windows\system32\dllcache\msfeedsbs.dll
2008-12-21 22:07 . 2008-10-16 07:11 13,824 —–c— c:\windows\system32\dllcache\ieudinit.exe
2008-12-21 22:06 . 2008-12-21 22:10 d——– c:\program files\Zune
2008-12-21 22:05 . 2008-08-14 04:00 2,180,352 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-21 22:05 . 2008-08-14 03:58 2,136,064 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-21 22:05 . 2008-08-14 03:22 2,057,728 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-21 22:05 . 2008-08-14 03:22 2,015,744 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-21 22:02 . 2008-05-02 07:30 464,384 ——— c:\windows\system32\imapi2fs.dll
2008-12-21 22:02 . 2008-05-02 07:30 464,384 —–c— c:\windows\system32\dllcache\imapi2fs.dll
2008-12-21 22:02 . 2008-05-02 07:30 317,952 ——— c:\windows\system32\imapi2.dll
2008-12-21 22:02 . 2008-05-02 07:30 317,952 —–c— c:\windows\system32\dllcache\imapi2.dll
2008-12-21 22:02 . 2008-06-13 07:10 272,128 ——— c:\windows\system32\drivers\bthport.sys
2008-12-21 22:02 . 2008-06-13 07:10 272,128 —–c— c:\windows\system32\dllcache\bthport.sys
2008-12-21 22:02 . 2008-05-02 03:05 62,592 —–c— c:\windows\system32\dllcache\cdrom.sys
2008-12-21 21:52 . 2008-10-16 14:09 31,768 –a—— c:\windows\system32\wucltui.dll.mui
2008-12-21 21:52 . 2008-10-16 14:07 23,576 –a—— c:\windows\system32\wuaucpl.cpl.mui
2008-12-21 21:52 . 2008-10-16 14:07 23,576 –a—— c:\windows\system32\wuapi.dll.mui
2008-12-21 21:52 . 2008-10-16 14:07 18,456 –a—— c:\windows\system32\wuaueng.dll.mui
2008-12-21 15:13 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101b.dll
2008-12-21 15:13 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101b.dll
2008-12-21 14:34 . 2008-12-21 14:34 d——– c:\windows\system32\GASVRCG
2008-12-21 14:34 . 2002-10-30 18:56 498,176 –a—— c:\windows\system32\GaSaver.scr
2008-12-21 14:34 . 2002-10-24 19:14 1,238 –a—— c:\windows\system32\Gascr.ini
2008-12-21 13:57 . 2004-07-26 12:12 166,912 –a—— c:\windows\lame_enc.dll
2008-12-21 13:41 . 2008-12-21 13:41 d——– c:\program files\River Past
2008-12-21 13:41 . 2008-12-21 13:41 d——– c:\program files\Common Files\River Past
2008-12-21 13:41 . 2008-12-21 13:41 d——– c:\documents and settings\Compaq_Owner\Application Data\River Past G5
2008-12-21 13:41 . 2008-12-21 13:59 d——– c:\documents and settings\All Users\Application Data\River Past G5
2008-12-21 13:41 . 2008-12-21 13:41 165,048 –a—— c:\windows\Audio Converter Pro Uninstaller.exe
2008-12-20 21:59 . 2008-12-30 11:46 d——– c:\program files\DSP-worx
2008-12-18 21:53 . 2008-12-18 21:53 d——– c:\program files\7-Zip
2008-12-13 17:12 . 2008-12-13 17:12 d——– c:\program files\OGPlanet
2008-12-12 18:25 . 2008-12-20 18:11 d——– C:\Episodes
2008-12-12 12:41 . 2008-12-12 12:41 243,840 –a—— c:\windows\system32\ZuneWlanCfgSvc.exe
2008-12-12 12:41 . 2008-12-12 12:41 60,032 –a—— c:\windows\system32\ZuneBusEnum.exe
2008-12-12 10:25 . 2008-12-12 10:36 d——– C:\Ruby
2008-12-05 17:26 . 2008-12-05 17:27 d——– c:\program files\Race War Kingdoms
2008-12-05 17:11 . 2008-12-05 17:11 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-05 17:11 . 2008-12-05 17:11 d——– c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes
2008-12-05 17:11 . 2008-12-05 17:11 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-05 17:11 . 2008-12-03 19:54 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-05 17:11 . 2008-12-03 19:54 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-05 09:24 . 2008-12-05 10:12 d——– c:\documents and settings\Administrator\Application Data\uTorrent
2008-12-02 20:28 . 2008-12-02 20:28 d—s—- c:\windows\system32\config\systemprofile\UserData
2008-12-02 17:05 . 2008-12-02 17:05 d——– c:\documents and settings\Administrator\Application Data\Media Player Classic
2008-12-02 17:05 . 2008-12-02 17:05 d——– c:\documents and settings\Administrator\Application Data\DivX
2008-12-02 17:04 . 2008-12-02 17:04 d——– c:\documents and settings\Administrator\Application Data\Aim
2008-12-01 07:59 . 2008-12-01 08:00 31 –a—— c:\documents and settings\Compaq_Owner\jagex_runescape_preferences.dat
2008-11-20 07:48 . 2008-12-02 21:36 d——– c:\program files\Viewpoint
2008-11-20 07:48 . 2008-11-20 07:50 d——– c:\documents and settings\All Users\Application Data\AOL OCP
2008-11-20 07:48 . 2008-11-20 07:48 d——– c:\documents and settings\All Users\Application Data\acccore
2008-11-20 07:47 . 2008-11-22 10:45 2,093 –ah—– C:\IPH.PH
2008-11-14 14:58 . 2008-11-14 15:10 d——– c:\program files\FlashGet

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-30 18:58 ——— d—–w c:\program files\Avast4
2008-12-27 01:54 ——— d—–w c:\program files\Combined Community Codec Pack
2008-12-21 20:33 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-21 17:59 ——— d—–w c:\program files\Winamp
2008-12-20 23:48 ——— d—–w c:\program files\Media Player Classic
2008-12-14 04:28 ——— d—–w c:\program files\GetRight
2008-12-11 12:05 ——— d—–w c:\documents and settings\All Users\Application Data\EmailNotifier
2008-12-11 04:02 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-11 04:01 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-12-10 02:22 ——— d—–w c:\documents and settings\Compaq_Owner\Application Data\Hamachi
2008-12-05 03:47 ——— d—–w c:\program files\Diablo II
2008-12-04 02:23 ——— d—–w c:\program files\Yahoo!
2008-12-04 01:48 ——— d—–w c:\program files\Common Files\AOL
2008-12-04 01:47 ——— d—–w c:\program files\Common Files\Nullsoft
2008-12-02 21:09 ——— d—–w c:\documents and settings\Compaq_Owner\Application Data\HPAppData
2008-11-20 13:49 ——— d—–w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-11-20 13:48 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2008-11-19 16:34 ——— d—–w c:\program files\AIM
2008-11-09 02:10 ——— d—–w c:\documents and settings\Compaq_Owner\Application Data\tunebite
2008-11-03 14:54 ——— d—–w c:\program files\BitComet
2008-10-29 19:07 ——— d—–w c:\program files\PowerISO
2008-10-27 16:37 699,488 —-a-w c:\program files\JUN2007_d3dx10_34_x86.cab
2008-10-27 16:36 526,160 —-a-w c:\program files\DXSETUP.exe
2008-10-23 00:56 122,129 —-a-w c:\windows\File Renamer - Basic Uninstaller.exe
2007-03-09 07:12 27,648 –sha-w c:\windows\system32\AVSredirect.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 94208]
"Uniblue RegistryBooster 2"="c:\program files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2008-05-05 1923352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-12-12 157312]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"WD Button Manager"="WDBtnMgr.exe" [2007-06-28 c:\windows\system32\WDBtnMgr.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.iac2"= c:\progra~1\REPLAY~2\iac25_32.ax
"VIDC.FFDS"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
–a—— 2008-11-26 11:18 81000 c:\progra~1\Avast4\ashDisp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2007-08-06 17:37 214296 c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs—- 2008-09-16 11:16 1833296 c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-09-25 01:11 132496 c:\program files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2007-08-06 17:37 185632 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"c:\\WINDOWS\\system32"=
"c:\\Program Files\\utorrent\\utorrent.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Best Buy Rhapsody\\rhapsody.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\SMC_mIRC\\SysReset 2.53\\mirc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"21142:TCP"= 21142:TCP:BitComet 21142 TCP
"21142:UDP"= 21142:UDP:BitComet 21142 UDP
"18314:TCP"= 18314:TCP:BitComet 18314 TCP
"18314:UDP"= 18314:UDP:BitComet 18314 UDP
"17978:TCP"= 17978:TCP:BitComet 17978 TCP
"17978:UDP"= 17978:UDP:BitComet 17978 UDP
"9842:TCP"= 9842:TCP:*:Disabled:SolidNetworkManager
"9842:UDP"= 9842:UDP:*:Disabled:SolidNetworkManager

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-05 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-05 20560]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
S1 ethnqkra;ethnqkra;c:\windows\system32\drivers\ethnqkra.sys []
S3 scskusbf;USB SCSK Filter Driver Service;c:\windows\system32\drivers\scskusbf.sys [2007-09-13 19504]
S3 scskusbs;USB SCSK Driver Service;c:\windows\system32\drivers\scskusbs.sys [2007-09-13 83160]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-Run-vxvjeppy.exe - c:\windows\vxvjeppy.exe
HKU-Default-Run-jrfyvaod.exe - c:\windows\jrfyvaod.exe


.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q404&bd;=presario&pf;=desktop
uStart Page = www.google.com/
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q404&bd;=presario&pf;=desktop
IE: Download with GetRight - c:\program files\GetRight\GRdownload.htm
IE: Open with GetRight Browser - c:\program files\GetRight\GRbrowse.htm
FF - ProfilePath - c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;=
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-31 17:30:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\.Default\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Ding.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\.Default\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\AppGPFault\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\AppGPFault\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\CCSelect\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\CCSelect\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\Close\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\Close\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\CriticalBatteryAlarm\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\CriticalBatteryAlarm\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\DeviceConnect\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Hardware Insert.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\DeviceConnect\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\DeviceDisconnect\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Hardware Remove.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\DeviceDisconnect\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\DeviceFail\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Hardware Fail.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\DeviceFail\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\LowBatteryAlarm\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Battery Low.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\LowBatteryAlarm\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\MailBeep\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Notify.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\MailBeep\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\Maximize\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\Maximize\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\MenuCommand\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\MenuCommand\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\MenuPopup\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\MenuPopup\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\Minimize\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\Minimize\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\NMain-MouseClick\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\NMain-MouseClick\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\NMain-MouseLeave\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\NMain-MouseLeave\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\NMain-MouseOver\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\NMain-MouseOver\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\Open\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\Open\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\PrintComplete\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\PrintComplete\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\RestoreDown\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\RestoreDown\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\RestoreUp\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\RestoreUp\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\ShowBand\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\ShowBand\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemAsterisk\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Error.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemAsterisk\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemExclamation\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Exclamation.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemExclamation\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemExit\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Shutdown.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemExit\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemHand\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Critical Stop.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemHand\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemNotification\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Balloon.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemNotification\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemQuestion\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemQuestion\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemStart\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Startup.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemStart\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\WindowsLogoff\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Logoff Sound.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\WindowsLogoff\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\WindowsLogon\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Logon Sound.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\WindowsLogon\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Alert\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Alert\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\BuddyIn\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\BuddyIn\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\BuddyOut\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\BuddyOut\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Drop\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Drop\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\File's Done\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\File's Done\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Goodbye\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Goodbye\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\IM\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\IM\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Inactivity45\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Inactivity45\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\More Mail\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\More Mail\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\OCW\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\OCW\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\PanelIn\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\PanelIn\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\PanelOut\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\PanelOut\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\popupblock\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\popupblock\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Slide\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Slide\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\TalkRing\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\TalkRing\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Urgent\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Urgent\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Welcome\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Welcome\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\ygp\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\ygp\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Ygvm\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Ygvm\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\You've Got Mail\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\You've Got Mail\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Conf\Person Joins\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Conf\Person Joins\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Conf\Person Leaves\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Conf\Person Leaves\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Conf\Receive Call\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Conf\Receive Call\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Conf\Receive Request to Join\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Conf\Receive Request to Join\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\ActivatingDocument\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\ActivatingDocument\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\BlockedPopup\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\BlockedPopup\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\EmptyRecycleBin\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Recycle.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\EmptyRecycleBin\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\FaxError\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\FaxError\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\FaxLineRings\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\FaxLineRings\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\FaxNew\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\FaxNew\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\FaxSent\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\FaxSent\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\MoveMenuItem\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\MoveMenuItem\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\Navigating\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Start.wav"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\Navigating\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\SecurityBand\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\SecurityBand\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_ContactOnline\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_ContactOnline\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_NewAlert\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_NewAlert\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_NewMail\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_NewMail\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_NewMessage\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_NewMessage\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\Banner\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\Banner\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\DragDrop\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\DragDrop\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\Popup\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\Popup\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\Reminder\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\Reminder\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\Selection\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\Selection\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksLauncher\ListSelect\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksLauncher\ListSelect\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksLauncher\MSwitch\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksLauncher\MSwitch\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksLauncher\ViewSwitch\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksLauncher\ViewSwitch\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbChangeSb\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbChangeSb\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbCloseLmDrop\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbCloseLmDrop\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbDropItem\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbDropItem\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbItemSelect\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbItemSelect\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbMenuOpen\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbMenuOpen\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbNewMode\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbNewMode\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbOpenLmDrop\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbOpenLmDrop\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbSnapWidget\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbSnapWidget\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Names\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@="nos"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Names\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@="RFS"

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\’u*NULL*’*NULL*’b*NULL*’R*NULL*’`*NULL*[*NULL*]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
"Order"=hex:08,00,00,00,02,00,00,00,7c,00,00,00,01,00,00,00,01,00,00,00,70,00,\
00,00,00,00,00,00,62,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,50,00,31,\
00,00,00,00,00,95,39,38,a4,10,00,47,41,54,42,43,7e,31,00,2c,00,03,00,04,00,\
ef,be,95,39,38,a4,95,39,3a,a4,14,00,00,00,47,00,41,00,1c,20,c1,00,1c,20,54,\
00,1a,20,62,00,1a,20,63,00,00,00,16,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,\
16,00,00,00,00,00,00,00,00,00

[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*NULL*]
@Security="Inherited"

[HKEY_LOCAL_MACHINE\software\BROCCOLI\G*NULL*A*NULL*’f*NULL*’X*NULL*’N*NULL*’g*NULL*’b*NULL*’v*NULL*’A*NUL
L*’N*NULL*’Z*NULL*’T*NULL*’`*NULL*[*NULL*2*NULL*L*NULL*E*NULL*]
@Security="Inherited"

[HKEY_LOCAL_MACHINE\software\BROCCOLI\G*NULL*A*NULL*’f*NULL*’X*NULL*’N*NULL*’g*NULL*’b*NULL*’v*NULL*’A*NUL
L*’N*NULL*’Z*NULL*’T*NULL*’`*NULL*[*NULL*2*NULL*L*NULL*E*NULL*\1.00.000]
@Security="Inherited"

[HKEY_LOCAL_MACHINE\software\Classes\.APE)\?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL* *NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL* *NULL* ?*NULL*?*NULL*?*NULL*?*NULL* ]
@Security="Inherited"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}]
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Denied: (A 2) (Everyone)
@Denied: (A 2) (S-1-5-7)
@="FlashProp Class"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\InprocServer32]
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\Flash9.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\Programmable]
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\system32\ZuneBusEnum.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-12-31 17:35:51 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-31 23:35:46

Pre-Run: 63,861,796,864 bytes free
Post-Run: 63,803,240,448 bytes free

2041 — E O F — 2008-12-22 17:08:31
hello

Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    ethnqkra
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
I started also having a new problem. I somehow lost admin rights even though its my computer. but regardless, here is the info: ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== Service ethnqkra stopped successfully. Service ethnqkra deleted successfully. ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_bNdiIZfIeOPe68cUUQ8C scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\l46lfxlk.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\l46lfxlk.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\l46lfxlk.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\l46lfxlk.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\l46lfxlk.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\l46lfxlk.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 01022009_080243
Ok

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
I couldnt run Kaspersky. and my windows update seems to be out of wack. it just brings up msn.com but here is the Malwarebytes' Anti-Malware Log: Malwarebytes' Anti-Malware 1.31 Database version: 1456 Windows 5.1.2600 Service Pack 2 1/2/2009 9:55:26 AM mbam-log-2009-01-02 (09-55-26).txt Scan type: Quick Scan Objects scanned: 55242 Time elapsed: 7 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 3 Registry Keys Infected: 14 Registry Values Infected: 4 Registry Data Items Infected: 2 Folders Infected: 1 Files Infected: 12 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\cgsflyxw.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\ssqRJbyv.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\vtUlMcYp.dll (Trojan.Vundo.H) -> Delete on reboot. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{49582d01-5592-4e9a-b672-fbabab3b9a2c} (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtulmcyp (Trojan.Vundo.H) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{49582d01-5592-4e9a-b672-fbabab3b9a2c} (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c125ebd6-811c-4875-8970-2743b46e9ddc} (Trojan.Vundo.H) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{c125ebd6-811c-4875-8970-2743b46e9ddc} (Trojan.Vundo.H) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{49582d01-5592-4e9a-b672-fbabab3b9a2c} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c125ebd6-811c-4875-8970-2743b46e9ddc} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\d86f29fc (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{49582d01-5592-4e9a-b672-fbabab3b9a2c} (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xsjfn83jkemfofght (Trojan.Agent) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\ssqrjbyv -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\ssqrjbyv -> Delete on reboot. Folders Infected: C:\resycled (Trojan.DNSChanger) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\system32\vtUlMcYp.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\ssqRJbyv.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\vybJRqss.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\vybJRqss.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\cgsflyxw.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\wxylfsgc.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\drivers\mrxdavv.sys (Rootkit.Agent.H) -> Delete on reboot. C:\WINDOWS\server.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\WINDOWS\system32\hgGvvsqN.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\k86.bin (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\Documents and Settings\Compaq_Owner\Local Settings\temp\winlogin.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\kwave.sys (Trojan.Agent) -> Delete on reboot.
hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.



Then delete ComboFix.exe and the folders C:\qoobox and C:\ComboFix and do this

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.




Please download Gmer:

http://www.gmer.net/gmer.zip

Now let's perform a Gmer rootkit scan:

  • Double-click Gmer.exe to run the program.
  • When the program opens, click the >>> Tab
  • On the right-side, check all the items to be scanned, but leave "Show All" unchecked
  • Select all drives that are connected to your system to be scanned
  • Click the Scan button
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard
  • Open Notepad or a similar text editor
  • Paste the clipboard contents into a text file by clicking Edit | Paste or Ctl V
  • Save the gmer scan log and post it in your next reply.
  • Close Gmer
  • Open a command prompt (Start | run |type cmd and hit Enter)
  • Type or paste the following to unload the Gmer driver:
    • net stop gmer
  • Hit Enter
  • Exit the command prompt.
ok.
here is SDFix:


SDFix: Version 1.240
Run by [removed] on Fri 01/02/2009 at 10:48 AM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-02 10:55:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

disk error: C:\WINDOWS\system32\config\system, 0
scanning hidden registry entries …

disk error: C:\WINDOWS\system32\config\software, 0
disk error: C:\Documents and Settings\Piccolo\ntuser.dat, 0
scanning hidden files …

disk error: C:\WINDOWS\

please note that you need administrator rights to perform deep scan

Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"="C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe:*:Enabled:BackWeb for Presario"
"C:\\WINDOWS\\system32"="C:\\WINDOWS\\system32:*:Enabled:lockx"
"C:\\Program Files\\utorrent\\utorrent.exe"="C:\\Program Files\\utorrent\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Hamachi\\hamachi.exe"="C:\\Program Files\\Hamachi\\hamachi.exe:*:Enabled:Hamachi Client"
"C:\\Program Files\\Best Buy Rhapsody\\rhapsody.exe"="C:\\Program Files\\Best Buy Rhapsody\\rhapsody.exe:*:Enabled:Rhapsody Media Player"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\SMC_mIRC\\SysReset 2.53\\mirc.exe"="C:\\SMC_mIRC\\SysReset 2.53\\mirc.exe:*:Enabled:mIRC"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Remaining Files :



Files with Hidden Attributes :

Fri 4 Feb 2005 211 A.SHR — "C:\BOOT.BAK"
Sun 24 Feb 2008 0 ..SH. — "C:\WINDOWS\S529E7295.tmp"
Wed 4 Aug 2004 60,416 A.SH. — "C:\Program Files\Outlook Express\msimn.exe"
Sun 26 Jun 2005 616,448 A.SHR — "C:\Program Files\Replay Converter\cygwin1.dll"
Tue 21 Jun 2005 45,568 A.SHR — "C:\Program Files\Replay Converter\cygz.dll"
Mon 9 Dec 2002 102,437 A..HR — "C:\Program Files\Replay Converter\drv13260.dll"
Mon 9 Dec 2002 176,165 A..HR — "C:\Program Files\Replay Converter\drv23260.dll"
Mon 9 Dec 2002 208,935 A..HR — "C:\Program Files\Replay Converter\drv33260.dll"
Mon 9 Dec 2002 217,127 A..HR — "C:\Program Files\Replay Converter\drv43260.dll"
Sun 9 Jun 2002 40,448 A..HR — "C:\Program Files\Replay Converter\dspr3260.dll"
Sat 3 Nov 2001 225,280 A..HR — "C:\Program Files\Replay Converter\ivvideo.dll"
Tue 10 Apr 2001 225,280 A..HR — "C:\Program Files\Replay Converter\qtmlClient.dll"
Fri 20 Feb 2004 232,960 A..HR — "C:\Program Files\Replay Converter\raac.dll"
Sun 9 Jun 2002 525,824 A..HR — "C:\Program Files\Replay Converter\rnco3260.dll"
Mon 9 Dec 2002 245,805 A..HR — "C:\Program Files\Replay Converter\rnlt3260.dll"
Mon 9 Dec 2002 45,093 A..HR — "C:\Program Files\Replay Converter\rv103260.dll"
Mon 9 Dec 2002 98,341 A..HR — "C:\Program Files\Replay Converter\rv203260.dll"
Mon 9 Dec 2002 94,247 A..HR — "C:\Program Files\Replay Converter\rv303260.dll"
Mon 9 Dec 2002 90,151 A..HR — "C:\Program Files\Replay Converter\rv403260.dll"
Sun 9 Jun 2002 49,152 A..HR — "C:\Program Files\Replay Converter\tokr3260.dll"
Wed 22 Oct 2008 949,072 A.SHR — "C:\Program Files\Spybot - Search & Destroy\advcheck.dll"
Mon 15 Sep 2008 1,562,960 A.SHR — "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll"
Mon 28 Jan 2008 1,404,240 A.SHR — "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR — "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Tue 16 Sep 2008 1,833,296 A.SHR — "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Wed 22 Oct 2008 962,896 A.SHR — "C:\Program Files\Spybot - Search & Destroy\Tools.dll"
Fri 9 Mar 2007 27,648 A.SH. — "C:\WINDOWS\system32\AVSredirect.dll"
Tue 23 Dec 2008 26,112 A.SH. — "C:\WINDOWS\system32\mss.dll"
Thu 17 Mar 2005 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 17 Mar 2005 401 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv11.bak"
Wed 11 Jan 2006 401 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv15.bak"
Tue 28 Nov 2000 36,864 A..H. — "C:\Program Files\Elaborate Bytes\CloneCD\InstallHelp.dll"
Thu 1 Jan 2009 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\066d6b6f1db2fb7733670d09b62362cd\BIT75.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\0c114cf5b19927cfea8b29c83de1ed86\BIT79.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\0f8a5d0d09e527fa35dec9e085d4b802\BIT72.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\131ae35a2f5be2cefedd349d083bb253\BIT69.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\299966e551b4462ae94e39e251e277b6\BIT65.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\29f79ad83880337acafe2a37966d9d29\BIT76.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\304c19f1612f37ffa8967147d3cb7464\BIT66.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\30afadc4c35db2f5d8b4c076a49edc7b\BIT6B.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\33831624a2e810dc854ea2f820d0dd53\BIT70.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\379c3e87f4016899bd06cdf1184d31ce\BIT7B.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\37fefde58a963f27982e5f97ce053f7f\BIT7C.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\393673217fc83f2b990ca70aa98f1df8\BIT6C.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\40a830826de015286a7a5523023b1e09\BIT81.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\4387300ca1dcf29784a47c30e67cb637\BIT6D.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\50d0c9ff929a7477233edd0771ffdb01\BIT83.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\526e15b6e1b5300357490c8089b5f84e\BIT80.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\582374c56f566bb2a83a59d0c2cd7d87\BIT7E.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\612ce0df709f1f49b2994166ec93f292\BIT6A.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\6b5f9b6e24a379bdb34ad3589556de3e\BIT8C.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\881d7070640a4412a784782616794afa\BIT82.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\8a10de02595aa748279afc6c628f49a8\BIT77.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\972f9ceb5c3be430fe6cdcb43653d74d\BIT7A.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\991099a35378d98f420ab4028323ec84\BIT7D.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\aa19f15378aa75d2b2c7ba5771e0c521\BIT71.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\ab9217b6e5750f9481b4ee261d21b730\BIT8A.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\ac396c0c2d53942a12157d0ad3c4135a\BIT86.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\b79f0480d592be3a8c6db381ffc0c693\BIT7F.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\c1b0851ac9312d2f7e1ab716c11967b5\BIT74.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\c3c3c6d9de8be474641d4bbceb22a36f\BIT78.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\d037d9bbbbdf880e477c3840b38c3180\BIT85.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\d05e90bdbe498b084a93603bc30f3c3c\BIT6E.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\d20fc1765c1d2a8e6c26cf77036ce48f\BIT89.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\d820fbd6e1527bc9c51d0c3b240b96fd\BIT87.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\d8816d09f86abbe0c321ddc90d5c0948\BIT88.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\da70638ee8e6f6c7eff37e755cd6f449\BIT73.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\e7d26e5776f9930c6ad9dff351940707\BIT84.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\ed6cff8bccff865b52b93292e144ada6\BIT67.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\ee52836d5c671146809a1dc54498be1f\BIT8B.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\f6745971ce358ebfe796f14b47a12533\BIT6F.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\fc75a45b73372bd0c2a61e3a51d766ff\BIT68.tmp"
Sun 21 Dec 2008 5,652,328 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\7ae70469dfa8c930825894df6cd175e5\BIT35.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\9709275ebe80c968f4c21ec857115cc3\BIT37.tmp"
Mon 27 Aug 2007 25,755,448 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\bb5c3edd4ebcf72602f3f9ef3df7c5ca\BIT2172.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\e6026e9d3f2125bce6aa173639d1d829\BIT38.tmp"
Sun 21 Dec 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\eaca1e1abf5fb68e65678bb74c2d4b5c\BIT3B.tmp"

Finished!

ComboFix:

ComboFix 09-01-01.02 - Piccolo 2009-01-02 11:10:51.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.447.225 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 081230-0] *On-access scanning disabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\autorun.inf
c:\windows\system32\drivers\mrxdavv.sys
c:\windows\system32\drivers\msqpdxwwbwruwk.sys
c:\windows\system32\jkse73hedfdgf.dll
c:\windows\system32\kwave.sys
c:\windows\system32\msqpdxowipxdap.dll
c:\windows\system32\oeqtqgao.dll
c:\windows\system32\uuejiz.dll
K:\Autorun.inf
K:\resycled
k:\resycled\boot.com

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_MSQPDXSERV.SYS


((((((((((((((((((((((((( Files Created from 2008-12-02 to 2009-01-02 )))))))))))))))))))))))))))))))
.

2009-01-02 10:45 . 2009-01-02 10:45 d——– c:\windows\ERUNT
2009-01-02 10:41 . 2009-01-02 10:56 d——– C:\SDFix
2009-01-02 10:37 . 2009-01-02 10:37 d——– c:\documents and settings\Piccolo\Application Data\HP
2009-01-02 10:15 . 2009-01-02 10:15 d——– C:\VundoFix Backups
2009-01-02 09:45 . 2009-01-02 09:45 d——– c:\documents and settings\Piccolo\Application Data\Malwarebytes
2009-01-02 08:41 . 2009-01-02 08:41 d——– c:\documents and settings\Piccolo\Application Data\Aim
2009-01-02 08:37 . 2004-08-09 02:55 d——– c:\documents and settings\Piccolo\WINDOWS
2009-01-02 08:37 . 2004-08-10 17:45 d——– c:\documents and settings\Piccolo\Application Data\Symantec
2009-01-02 08:37 . 2004-08-09 02:57 d——– c:\documents and settings\Piccolo\Application Data\SampleView
2009-01-02 08:37 . 2009-01-02 08:37 d——– c:\documents and settings\Piccolo
2009-01-02 08:28 . 2009-01-02 08:28 d——– c:\documents and settings\Administrator\Application Data\MSNInstaller
2009-01-02 08:02 . 2009-01-02 08:02 d——– C:\_OTMoveIt
2009-01-02 07:50 . 2009-01-02 07:50 d——– c:\documents and settings\Administrator\Application Data\Aim
2009-01-01 11:03 . 2008-12-23 18:01 26,112 –ahs—- c:\windows\system32\mss.dll
2009-01-01 10:54 . 2009-01-01 13:20 22,152 –a—— c:\windows\system32\swapdm.dll
2009-01-01 10:54 . 2009-01-01 10:54 8,512 –a—— c:\windows\system32\swapm.sys
2009-01-01 10:54 . 2009-01-01 10:54 8,512 –a—— c:\windows\system32\drivers\sptd.sys
2009-01-01 10:54 . 2009-01-01 10:54 8,512 –a—— c:\windows\system32\drivers\ethnqkra.sys
2009-01-01 10:54 . 2009-01-01 11:02 4,707 –a—— c:\windows\system32\aidb.dat
2009-01-01 10:54 . 2009-01-01 10:54 0 –a—— C:\-663803565
2009-01-01 10:30 . 2009-01-01 10:43 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2009-01-01 09:28 . 2009-01-01 21:16 d——– c:\program files\x86
2009-01-01 09:28 . 2009-01-01 21:16 d——– c:\program files\x64
2009-01-01 08:53 . 2009-01-01 23:57 23,392 –a—— c:\windows\system32\nscompat.tlb
2009-01-01 08:53 . 2009-01-01 23:57 16,832 –a—— c:\windows\system32\amcompat.tlb
2008-12-31 17:14 . 2008-12-31 17:14 d——– C:\_OTScanIt
2008-12-30 12:05 . 2008-12-30 12:05 d——– c:\program files\Trend Micro
2008-12-29 05:43 . 2008-12-31 05:54 d——– C:\1
2008-12-26 20:34 . 2008-12-26 20:34 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Real Audio (Helix) Encoder.bmp
2008-12-26 20:34 . 2008-12-26 20:34 11,473 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Real Audio (Helix) Encoder.dat
2008-12-26 20:31 . 2008-12-26 20:31 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.bmp
2008-12-26 20:31 . 2008-12-26 20:31 13,785 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2008-12-23 17:55 . 2008-12-23 17:55 d——– c:\program files\Uniblue
2008-12-23 17:21 . 2008-12-23 17:21 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Windows Media Audio 10 Codec.bmp
2008-12-23 17:21 . 2008-12-23 17:20 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Shorten Codec.bmp
2008-12-23 17:21 . 2008-12-23 17:21 3,411 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Shorten Codec.dat
2008-12-23 17:21 . 2008-12-23 17:21 3,400 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Windows Media Audio 10 Codec.dat
2008-12-23 17:19 . 2008-12-23 17:19 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Midi Decoder.bmp
2008-12-23 17:19 . 2008-12-23 17:19 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp m4a Codec.bmp
2008-12-23 17:19 . 2008-12-23 17:19 3,625 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp m4a Codec.dat
2008-12-23 17:19 . 2008-12-23 17:19 2,649 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Midi Decoder.dat
2008-12-23 16:53 . 2008-12-23 16:53 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp WavPack Codec.bmp
2008-12-23 16:53 . 2008-12-23 16:53 3,008 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp WavPack Codec.dat
2008-12-23 16:52 . 2008-12-23 16:56 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp TTA Codec.bmp
2008-12-23 16:52 . 2008-12-23 16:57 3,417 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp TTA Codec.dat
2008-12-23 16:46 . 2008-12-23 16:45 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP WMA V9 Codec.bmp
2008-12-23 16:46 . 2008-12-23 16:46 2,181 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP WMA V9 Codec.dat
2008-12-23 16:45 . 2008-12-23 16:45 28,898 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP VQF Codec.bmp
2008-12-23 16:45 . 2008-12-23 16:44 28,898 –a—— c:\windows\system32\SpoonUninstall-dBPowerAMP Real Audio Encoder R3.bmp
2008-12-23 16:45 . 2008-12-23 16:45 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Winamp Codec.bmp
2008-12-23 16:45 . 2008-12-23 16:45 2,995 –a—— c:\windows\system32\SpoonUninstall-dBPowerAMP Real Audio Encoder R3.dat
2008-12-23 16:45 . 2008-12-23 16:45 2,234 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP VQF Codec.dat
2008-12-23 16:45 . 2008-12-23 16:45 1,327 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Winamp Codec.dat
2008-12-23 16:44 . 2008-12-23 17:20 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.bmp
2008-12-23 16:44 . 2008-12-23 17:20 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Musepack Codec.bmp
2008-12-23 16:44 . 2008-12-23 16:44 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Real Audio Codec.bmp
2008-12-23 16:44 . 2008-12-23 16:44 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP FAAC Mp4 Codec.bmp
2008-12-23 16:44 . 2008-12-23 17:20 3,283 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Musepack Codec.dat
2008-12-23 16:44 . 2008-12-23 17:20 3,065 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat
2008-12-23 16:44 . 2008-12-23 16:44 1,928 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Real Audio Codec.dat
2008-12-23 16:44 . 2008-12-23 16:44 620 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP FAAC Mp4 Codec.dat
2008-12-23 16:43 . 2008-12-23 16:43 27,958 –a—— c:\windows\system32\SpoonUninstall-dMC mp3PRO (CLI) Encoder.bmp
2008-12-23 16:43 . 2008-12-23 16:43 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Mp4 & AAC Decode Codec.bmp
2008-12-23 16:43 . 2008-12-23 16:43 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP mp3PRO Input Codec.bmp
2008-12-23 16:43 . 2008-12-23 16:43 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP AAC to Mp4 Codec.bmp
2008-12-23 16:43 . 2008-12-23 16:43 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP AAC Codec.bmp
2008-12-23 16:43 . 2008-12-23 16:43 2,467 –a—— c:\windows\system32\SpoonUninstall-dMC mp3PRO (CLI) Encoder.dat
2008-12-23 16:43 . 2008-12-23 16:43 2,218 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Mp4 & AAC Decode Codec.dat
2008-12-23 16:43 . 2008-12-23 16:43 2,074 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP mp3PRO Input Codec.dat
2008-12-23 16:43 . 2008-12-23 16:43 1,122 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP AAC Codec.dat
2008-12-23 16:43 . 2008-12-23 16:43 516 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP AAC to Mp4 Codec.dat
2008-12-23 16:42 . 2008-12-23 17:19 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Monkeys Audio Codec.bmp
2008-12-23 16:42 . 2008-12-23 17:18 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp FLAC Codec.bmp
2008-12-23 16:42 . 2008-12-23 17:11 28,898 –a—— c:\windows\system32\SpoonUninstall-dBPowerAMP AIFF codec r4.bmp
2008-12-23 16:42 . 2008-12-23 17:20 3,107 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Monkeys Audio Codec.dat
2008-12-23 16:42 . 2008-12-23 17:19 2,987 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2008-12-23 16:42 . 2008-12-23 17:11 739 –a—— c:\windows\system32\SpoonUninstall-dBPowerAMP AIFF codec r4.dat
2008-12-23 16:39 . 2008-12-23 17:14 4,044,152 –a—— c:\windows\system32\SpoonUninstall.exe
2008-12-23 16:38 . 2008-12-23 16:38 d——– c:\program files\Illustrate
2008-12-23 15:27 . 2008-12-31 12:24 d——– C:\AudioConverter
2008-12-23 11:27 . 2008-12-23 12:17 398 –a—— c:\windows\AudioConverter.INI
2008-12-23 11:26 . 2008-12-23 11:26 d——– c:\program files\easetech
2008-12-22 11:02 . 2008-12-22 11:02 d——– c:\program files\MSXML 4.0
2008-12-21 22:20 . 2008-12-31 18:54 d——– c:\windows\system32\CatRoot_bak
2008-12-21 22:09 . 2008-12-21 22:09 0 –ah—– c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2008-12-21 22:09 . 2008-12-21 22:09 0 –ah—– c:\windows\system32\drivers\Msft_Kernel_zumbus_01007.Wdf
2008-12-21 22:08 . 2008-03-21 13:57 14,640 ——— c:\windows\system32\spmsgXP_2k3.dll
2008-12-21 22:07 . 2008-10-16 14:38 6,066,176 —–c— c:\windows\system32\dllcache\ieframe.dll
2008-12-21 22:07 . 2007-04-17 03:32 2,455,488 —–c— c:\windows\system32\dllcache\ieapfltr.dat
2008-12-21 22:07 . 2007-03-07 23:10 991,232 —–c— c:\windows\system32\dllcache\ieframe.dll.mui
2008-12-21 22:07 . 2008-10-16 14:38 459,264 —–c— c:\windows\system32\dllcache\msfeeds.dll
2008-12-21 22:07 . 2008-10-16 14:38 383,488 —–c— c:\windows\system32\dllcache\ieapfltr.dll
2008-12-21 22:07 . 2008-10-16 14:38 267,776 —–c— c:\windows\system32\dllcache\iertutil.dll
2008-12-21 22:07 . 2008-10-16 14:38 63,488 —–c— c:\windows\system32\dllcache\icardie.dll
2008-12-21 22:07 . 2008-10-16 14:38 52,224 —–c— c:\windows\system32\dllcache\msfeedsbs.dll
2008-12-21 22:07 . 2008-10-16 07:11 13,824 —–c— c:\windows\system32\dllcache\ieudinit.exe
2008-12-21 22:05 . 2008-08-14 04:00 2,180,352 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-21 22:05 . 2008-08-14 03:58 2,136,064 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-21 22:05 . 2008-08-14 03:22 2,057,728 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-21 22:05 . 2008-08-14 03:22 2,015,744 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-21 22:02 . 2008-05-02 07:30 464,384 ——— c:\windows\system32\imapi2fs.dll
2008-12-21 22:02 . 2008-05-02 07:30 464,384 —–c— c:\windows\system32\dllcache\imapi2fs.dll
2008-12-21 22:02 . 2008-05-02 07:30 317,952 ——— c:\windows\system32\imapi2.dll
2008-12-21 22:02 . 2008-05-02 07:30 317,952 —–c— c:\windows\system32\dllcache\imapi2.dll
2008-12-21 22:02 . 2008-06-13 07:10 272,128 ——— c:\windows\system32\drivers\bthport.sys
2008-12-21 22:02 . 2008-06-13 07:10 272,128 —–c— c:\windows\system32\dllcache\bthport.sys
2008-12-21 22:02 . 2008-05-02 03:05 62,592 —–c— c:\windows\system32\dllcache\cdrom.sys
2008-12-21 21:52 . 2008-10-16 14:09 31,768 –a—— c:\windows\system32\wucltui.dll.mui
2008-12-21 21:52 . 2008-10-16 14:07 23,576 –a—— c:\windows\system32\wuaucpl.cpl.mui
2008-12-21 21:52 . 2008-10-16 14:07 23,576 –a—— c:\windows\system32\wuapi.dll.mui
2008-12-21 21:52 . 2008-10-16 14:07 18,456 –a—— c:\windows\system32\wuaueng.dll.mui
2008-12-21 15:13 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101b.dll
2008-12-21 15:13 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101b.dll
2008-12-21 14:34 . 2008-12-21 14:34 d——– c:\windows\system32\GASVRCG
2008-12-21 14:34 . 2002-10-30 18:56 498,176 –a—— c:\windows\system32\GaSaver.scr
2008-12-21 14:34 . 2002-10-24 19:14 1,238 –a—— c:\windows\system32\Gascr.ini
2008-12-21 13:57 . 2004-07-26 12:12 166,912 –a—— c:\windows\lame_enc.dll
2008-12-21 13:41 . 2008-12-21 13:41 d——– c:\program files\River Past
2008-12-21 13:41 . 2008-12-21 13:41 d——– c:\program files\Common Files\River Past
2008-12-21 13:41 . 2008-12-21 13:59 d——– c:\documents and settings\All Users\Application Data\River Past G5
2008-12-21 13:41 . 2008-12-21 13:41 165,048 –a—— c:\windows\Audio Converter Pro Uninstaller.exe
2008-12-20 21:59 . 2008-12-30 11:46 d——– c:\program files\DSP-worx
2008-12-18 21:53 . 2008-12-18 21:53 d——– c:\program files\7-Zip
2008-12-13 17:12 . 2008-12-13 17:12 d——– c:\program files\OGPlanet
2008-12-12 18:25 . 2008-12-20 18:11 d——– C:\Episodes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-01 15:51 ——— d—–w c:\program files\Windows Media Connect 2
2008-12-30 18:58 ——— d—–w c:\program files\Avast4
2008-12-27 01:54 ——— d—–w c:\program files\Combined Community Codec Pack
2008-12-21 20:33 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-21 17:59 ——— d—–w c:\program files\Winamp
2008-12-20 23:48 ——— d—–w c:\program files\Media Player Classic
2008-12-14 04:28 ——— d—–w c:\program files\GetRight
2008-12-11 12:05 ——— d—–w c:\documents and settings\All Users\Application Data\EmailNotifier
2008-12-11 04:02 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-11 04:01 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-12-05 03:47 ——— d—–w c:\program files\Diablo II
2008-12-04 02:23 ——— d—–w c:\program files\Yahoo!
2008-12-04 01:48 ——— d—–w c:\program files\Common Files\AOL
2008-12-04 01:47 ——— d—–w c:\program files\Common Files\Nullsoft
2008-12-03 03:36 ——— d—–w c:\program files\Viewpoint
2008-11-20 13:50 ——— d—–w c:\documents and settings\All Users\Application Data\AOL OCP
2008-11-20 13:49 ——— d—–w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-11-20 13:48 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2008-11-20 13:48 ——— d—–w c:\documents and settings\All Users\Application Data\acccore
2008-11-19 16:34 ——— d—–w c:\program files\AIM
2008-11-14 21:10 ——— d—–w c:\program files\FlashGet
2008-11-10 18:09 40,832 —-a-w c:\windows\system32\drivers\zumbus.sys
2008-11-05 15:00 ——— d—–w c:\program files\NeoSpeech
2008-11-05 14:56 ——— d—–w c:\program files\ATTNaturalVoices
2008-11-05 14:53 ——— d—–w c:\program files\TextSpeech Pro
2008-11-03 14:54 ——— d—–w c:\program files\BitComet
2008-10-27 16:37 699,488 —-a-w c:\program files\JUN2007_d3dx10_34_x86.cab
2008-10-27 16:36 526,160 —-a-w c:\program files\DXSETUP.exe
2008-10-23 00:56 122,129 —-a-w c:\windows\File Renamer - Basic Uninstaller.exe
2007-03-09 07:12 27,648 –sha-w c:\windows\system32\AVSredirect.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"AIM"="c:\program files\AIM\aim.exe" [2005-08-05 67160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-08-06 185632]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2007-08-06 214296]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"WD Button Manager"="WDBtnMgr.exe" [2007-06-28 c:\windows\system32\WDBtnMgr.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\swapdm]
2009-01-01 13:20 22152 c:\windows\system32\swapdm.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=mss.dll uuejiz.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.iac2"= c:\progra~1\REPLAY~2\iac25_32.ax
"VIDC.FFDS"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2ycxx.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"c:\\WINDOWS\\system32"=
"c:\\Program Files\\utorrent\\utorrent.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Best Buy Rhapsody\\rhapsody.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\SMC_mIRC\\SysReset 2.53\\mirc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"21142:TCP"= 21142:TCP:BitComet 21142 TCP
"21142:UDP"= 21142:UDP:BitComet 21142 UDP
"18314:TCP"= 18314:TCP:BitComet 18314 TCP
"18314:UDP"= 18314:UDP:BitComet 18314 UDP
"17978:TCP"= 17978:TCP:BitComet 17978 TCP
"17978:UDP"= 17978:UDP:BitComet 17978 UDP
"9842:TCP"= 9842:TCP:*:Disabled:SolidNetworkManager
"9842:UDP"= 9842:UDP:*:Disabled:SolidNetworkManager

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-05 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-05 20560]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
S3 scskusbf;USB SCSK Filter Driver Service;c:\windows\system32\drivers\scskusbf.sys [2007-09-13 19504]
S3 scskusbs;USB SCSK Driver Service;c:\windows\system32\drivers\scskusbs.sys [2007-09-13 83160]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
- - - - ORPHANS REMOVED - - - -

BHO-{C72AC000-47EA-4CCC-A46C-0B4BCF4843AA} - (no file)
HKLM-Run-RegistryMechanic - (no file)
Notify-rwachyx - (no file)
SafeBoot-ethnqkra.sys


.
——- Supplementary Scan ——-
.
uStart Page = www.google.com/
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q404&bd;=presario&pf;=desktop
uInternet Connection Wizard,ShellNext = hxxp://aimtoday.aol.com/today/aimtoday.adp?type=2&product;=9&platform;=1&channel;=283&build;=3861&SN;=DCONGLHDEJCLOOGKGFFL&CC;=BINOFCEK&PC;=HCLEDICABB&segment;=-1&UTC;=1230907291<=1230885691&nlogin;=1
IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-02 11:16:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\docume~1\Piccolo\LOCALS~1\Temp\DIO9.tmp 47416 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2009-01-02 11:21:35 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-02 17:21:31

Pre-Run: 64,455,450,624 bytes free
Post-Run: 64,430,989,312 bytes free

295 — E O F — 2009-01-01 17:06:13

and Gmer:

GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-01-02 11:54:51
Windows 5.1.2600 Service Pack 2


—- Registry - GMER 1.0.14 —-

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC0 0xCA 0xDC 0x9D …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x87 0x8A 0xCC 0x72 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xBA 0xB2 0x7F 0x20 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xC3 0x0D 0xB1 0x49 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC0 0xCA 0xDC 0x9D …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x87 0x8A 0xCC 0x72 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xBA 0xB2 0x7F 0x20 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xC3 0x0D 0xB1 0x49 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC0 0xCA 0xDC 0x9D …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x87 0x8A 0xCC 0x72 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xBA 0xB2 0x7F 0x20 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xC3 0x0D 0xB1 0x49 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC0 0xCA 0xDC 0x9D …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x87 0x8A 0xCC 0x72 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xBA 0xB2 0x7F 0x20 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xC3 0x0D 0xB1 0x49 …
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv.sys@imagepath \systemroot\system32\drivers\TDSSmqlt.sys
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv.sys\modules
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv.sys\modules@TDSSserv \systemroot\system32\drivers\TDSSmqlt.sys
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv.sys\modules@TDSSl \systemroot\system32\TDSSoiqt.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv.sys\modules@tdssservers \systemroot\system32\TDSSmtvd.dat
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv.sys\modules@tdssmain \systemroot\system32\TDSShrxx.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv.sys\modules@tdsslog \systemroot\system32\TDSSvkql.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv.sys\modules@tdssadw \systemroot\system32\TDSScfmm.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv.sys\modules@tdssinit \systemroot\system32\TDSSlxcp.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv.sys\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv.sys\modules@tdsspanels \systemroot\system32\TDSSsahc.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv.sys\modules@tdsserrors \systemroot\system32\TDSSkhyf.log
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv.sys\modules@TDSSproc \systemroot\system32\TDSSkkai.log
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC0 0xCA 0xDC 0x9D …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x87 0x8A 0xCC 0x72 …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xBA 0xB2 0x7F 0x20 …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xC3 0x0D 0xB1 0x49 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC0 0xCA 0xDC 0x9D …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x87 0x8A 0xCC 0x72 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xBA 0xB2 0x7F 0x20 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xC3 0x0D 0xB1 0x49 …
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC0 0xCA 0xDC 0x9D …
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x87 0x8A 0xCC 0x72 …
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xBA 0xB2 0x7F 0x20 …
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xC3 0x0D 0xB1 0x49 …
Reg HKLM\SOFTWARE\Classes\CLSID\{14427C58-FFDA-DC11-C543-A85CDB4A49C1}\InprocServer32@ C:\WINDOWS\system32\qedit.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{14427C58-FFDA-DC11-C543-A85CDB4A49C1}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{14427C58-FFDA-DC11-C543-A85CDB4A49C1}\ProgID@ qedit.Xml2Dex.1
Reg HKLM\SOFTWARE\Classes\CLSID\{14427C58-FFDA-DC11-C543-A85CDB4A49C1}\VersionIndependentProgID@ qedit.Xml2Dex
Reg HKLM\SOFTWARE\Classes\CLSID\{BB55E03B-8313-39B8-6664-72DC1427FEC0}\ExtendedErrors@ Extended Error Service
Reg HKLM\SOFTWARE\Classes\CLSID\{BB55E03B-8313-39B8-6664-72DC1427FEC0}\ExtendedErrors\{C0932C62-38E5-11d0-97AB-00C04FC2AD98}
Reg HKLM\SOFTWARE\Classes\CLSID\{BB55E03B-8313-39B8-6664-72DC1427FEC0}\ExtendedErrors\{C0932C62-38E5-11d0-97AB-00C04FC2AD98}@ SQLOLEDB Error Lookup
Reg HKLM\SOFTWARE\Classes\CLSID\{BB55E03B-8313-39B8-6664-72DC1427FEC0}\Implemented Categories\{D267E19A-0B97-11D2-BB1C-00C04FC9B532}
Reg HKLM\SOFTWARE\Classes\CLSID\{BB55E03B-8313-39B8-6664-72DC1427FEC0}\InprocServer32@ C:\Program Files\Common Files\System\Ole DB\sqloledb.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{BB55E03B-8313-39B8-6664-72DC1427FEC0}\InprocServer32@ThreadingModel Both
Reg HKLM\SOFTWARE\Classes\CLSID\{BB55E03B-8313-39B8-6664-72DC1427FEC0}\OLE DB Provider@ Microsoft OLE DB Provider for SQL Server
Reg HKLM\SOFTWARE\Classes\CLSID\{BB55E03B-8313-39B8-6664-72DC1427FEC0}\ProgID@ SQLOLEDB.1
Reg HKLM\SOFTWARE\Classes\CLSID\{BB55E03B-8313-39B8-6664-72DC1427FEC0}\VersionIndependentProgID@ SQLOLEDB
Reg HKLM\SOFTWARE\Classes\CLSID\{D5FB6EA8-66EC-2BC4-4EF8-7AD546D9619D}\InprocServer32@ %ProgramFiles%\Outlook Express\oeimport.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{D5FB6EA8-66EC-2BC4-4EF8-7AD546D9619D}\InprocServer32@ThreadingModel Apartment

—- EOF - GMER 1.0.14 —-
hello

Open notepad and copy/paste the text in the quotebox below into it:
http://forums.whatthetech.com/Hijackthis_Log_t98455.html&gopid=515207#entry515207

Collect::[11]
c:\windows\system32\mss.dll
c:\windows\system32\drivers\ethnqkra.sys
c:\windows\system32\aidb.dat
C:\-663803565
c:\windows\system32\swapdm.dll
c:\windows\system32\swapm.sys
c:\windows\system32\nscompat.tlb
c:\windows\system32\amcompat.tlb

folder::
c:\program files\x86
c:\program files\x64

Suspect::

Registry::
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2ycxx.sys]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\TDSSserv.sys]

Driver::
TDSSserv
ati2ycxx
ethnqkra
Save this as CFScript.txt


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
  • A browser will open.
  • Simply follow the instructions to copy/paste/send the requested file.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI