This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Stubborn Spy/Hook

45 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:34:51 AM, on 2/17/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\user1\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickCare] C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe /P QuickCare
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
O4 - HKLM\..\Run: [OnAccess] "C:\Program Files\eAcceleration\OnAccess\onaccess.exe" -erk
O4 - HKLM\..\Run: [eanth_critical_update_alert] C:\PROGRA~1\ACCELE~1\ANTI-V~1\EANTH_~1.EXE /Startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233948222608
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: eAcceleration Notification Service (eac_notifysvc) - Unknown owner - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe (file missing)
O23 - Service: eAcceleration Product Manager Service (eac_productsvc) - Unknown owner - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SupportSoft Listener Service (sprtlisten) - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
O23 - Service: StopSign Antivirus Security Center Provider (sstsmonsvc) - Unknown owner - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe (file missing)

–
End of file - 6733 bytes


——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, February 17, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, February 17, 2009 14:39:41
Records in database: 1808551
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\

Scan statistics:
Files scanned: 43352
Threat name: 2
Infected objects: 2
Suspicious objects: 0
Duration of the scan: 01:37:19


File name / Threat name / Threats count
C:\_OTMoveIt\MovedFiles\02052009_100145\Program Files\MSN Messenger\msimg32.dll Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.cv 1
C:\_OTMoveIt\MovedFiles\02052009_100145\Program Files\MSN Messenger\riched20.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.cj 1

The selected area was scanned.
your logs are clean


Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    [external image: Posted Image]



Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
  • Click the Pt. Restauration button and press OK to the prompts.
  • Click the Corbeille button and press OK to the prompt.
  • Click the Fichiers temp button and press OK to the prompt.
  • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
  • Once it is done click the Suppression button and let it remove anything it finds.
  • Close the program



Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.



Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

  • Please read my guide on how to prevent malware and about safe computing here
Thank you for your patience, and performing all of the procedures requested.
your logs are clean


Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    [external image: Posted Image]



Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
  • Click the Pt. Restauration button and press OK to the prompts.
  • Click the Corbeille button and press OK to the prompt.
  • Click the Fichiers temp button and press OK to the prompt.
  • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
  • Once it is done click the Suppression button and let it remove anything it finds.
  • Close the program



Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.



Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

  • Please read my guide on how to prevent malware and about safe computing here
Thank you for your patience, and performing all of the procedures requested.
your logs are clean


Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    [external image: Posted Image]



Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
  • Click the Pt. Restauration button and press OK to the prompts.
  • Click the Corbeille button and press OK to the prompt.
  • Click the Fichiers temp button and press OK to the prompt.
  • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
  • Once it is done click the Suppression button and let it remove anything it finds.
  • Close the program



Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.



Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

  • Please read my guide on how to prevent malware and about safe computing here
Thank you for your patience, and performing all of the procedures requested.
Thanks for all your help, the system is much better. I still am pulling up eAcceleration/stopsign though when I scan with Spybot. Looking back through the entire post, we have tried to get rid of this a few times and it keeps creeping back in somehow. It is not in the uninstall programs but still shows up in the scans from spybot and hijackthis. When I check fixall the eAcceleration/stopsign entries in hijackthis it comes back, but malwarebytes doesn't see it as a problem/threat. Can you help me get rid of this last one?
sure lets knock it out of the park

Download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.
  • Open the OTScanIt2 folder and double-click on OTScanIt.exe to start the program. Make sure you close all other programs and don't use the PC while the scan runs.
  • Under File Age at the top, change it from 30 days to 90 days
  • Under Additional Scans check the boxes beside Reg - ActiveX StubPath, Reg - App Paths, Reg - ColumnHandlers, Reg - Desktop Components, Reg - Disabled MS Config Items, Reg - File Associations, Reg - ICQ Agent, Reg - NetSvcs, Reg - Print Monitors, Reg - Protocol Filters, Reg - Protocol Handlers, Reg - SafeBoot Minimal, Reg - SafeBoot Network, Reg - Session Manager Settings, Reg - Winsock2 Catalogs, File - Lop Check, File - Purity Scan, Files - Signature Check, and Evnt - EventViewer Logs ( Last 10 Errors).
  • Under Rootkit Search change it to Yes
  • Under the Custom Scans box at the bottom left paste the following in

    %systemroot%\Prefetch\*.* /s
    %systemroot%\system32\drivers\*.dat
    %systemroot%\system32\*aef
    %systemroot%\system32\drivers\*aef
    %systemroot%\Temp\bca4e2da.$$$
    %systemroot%\Temp\ed47fa.$
    %systemroot%\Temp\fa56d7ec.$$$
    %systemroot%\Temp\*.$$$
    %systemroot%\System32\antiwpa.dll
    %systemroot%\SYSTEM32\wpa.dll
    %systemroot%\setup\scripts\biestart.exe
    %System%\AcroIeHelpe.dll
    %SYSTEMDRIVE%\*.epk
    %systemroot%\*.epk
    %systemroot%\system32\*.epk
    %systemroot%\system32\bb*.dat
    %systemroot%\system32\cookie*.dat
    %systemroot%\system32\kaxs.dat
    %systemroot%\system32\ps*.dat
    %systemroot%\system32\*32.sys
    %systemroot%\*.dr
    %SYSTEMDRIVE%\*.dr
    %systemroot%\system32\*.dr
    %systemroot%\system32\nods32.dll
    %systemroot%\*.res
    %SYSTEMDRIVE%\*.res
    %systemroot%\system32\*.res
    %systemroot%\system32\sockins32.dll
    %systemroot%\system32\Spool\*.*
    %systemroot%\system32\Spool\*.exe
    %systemroot%\system32\Spool\*.rar /s
    %systemroot%\system32\Spool\*.zip /s
    %systemroot%\system32\Spool\*.dat /s
    %ProgramFiles%\MSN Messenger\*.zip
    %ProgramFiles%\MSN Messenger\*.exe
    %ProgramFiles%\MSN Messenger\*.rar.
    %SYSTEMDRIVE%\*.zip
    %SYSTEMDRIVE%\*.rar
    %SYSTEMDRIVE%\*.exe
    %SYSTEMDRIVE%\*.dll
    %systemroot%\*.zip
    %systemroot%\*.rar
    %systemroot%\system32\*.zip
    %systemroot%\system32\*.rar
    %PROGRAMFILES%\*.*
    %DESKTOP%\*.zip
    %DESKTOP%\*.rar
    %DESKTOP%\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %PROGRAMFILES%\Common Files\*bak*.
    %systemroot%\SYSTEM32\*bak*.
    %PROGRAMFILES%\*bak*.
    %systemroot%\ime\imjp8_1\*bak*.
    %PROGRAMFILES%\QuickTime\*bak*.
    %PROGRAMFILES%\Viewpoint\Viewpoint Manager\*bak*.
    %PROGRAMFILES%\Analog Devices\Core\*bak*.
    %SYSTEMDRIVE%\hp\KBD\*bak*.
    %PROGRAMFILES%\Adobe\Photoshop Album Starter Edition\3.2\Apps\*bak*.
    %PROGRAMFILES%\BillP Studios\WinPatrol\*bak*.
    %PROGRAMFILES%\BroadJump\Client Foundation\*bak*.
    %PROGRAMFILES%\Common Files\Real\Update_OB\*bak*.
    %PROGRAMFILES%\Common Files\Sonic\Update Manager\*bak*.
    %PROGRAMFILES%\\Google\GoogleToolbarNotifier\*bak*.
    %PROGRAMFILES%\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\*bak*.
    %PROGRAMFILES%\Yahoo!\Messenger\*bak*.
    %USERNAME%\*.zip
    %USERNAME%\*.rar
    %USERNAME%\*.exe
    %USERPROFILE%\*.zip
    %USERPROFILE%\*.rar
    %USERPROFILE%\*.exe
    %ALLUSERSPROFILE%\*.zip
    %ALLUSERSPROFILE%\*.rar
    %ALLUSERSPROFILE%\*.exe
    %APPDATA%\*.zip
    %APPDATA%\*.rar
    %APPDATA%\*.exe
    %ALLUSERSSTARTMENU%\*.zip
    %ALLUSERSSTARTMENU%\*.rar
    %ALLUSERSSTARTMENU%\*.exe
    %ALLUSERSSTARTUP%\*.zip
    %ALLUSERSSTARTUP%\*.rar
    %ALLUSERSSTARTUP%\*.exe
    %ALLUSERSPROGRAMS%\*.zip
    %ALLUSERSPROGRAMS%\*.rar
    %ALLUSERSPROGRAMS%\*.exe
    %ALLUSERSAPPDATA%\*.zip
    %ALLUSERSAPPDATA%\*.rar
    %ALLUSERSAPPDATA%\*.exe
    %APPDATA%\*.zip
    %APPDATA%\*.rar
    %APPDATA%\*.exe
    %APPDATA%\*.dat
    %APPDATA%\*.dll
    %QUICKLAUNCH%\*.zip
    %QUICKLAUNCH%\*.rar
    %QUICKLAUNCH%\*.exe
    %STARTUP%\*.zip
    %STARTUP%\*.rar
    %STARTUP%\*.exe
    %STARTMENU%\*.zip
    %STARTMENU%\*.rar
    %STARTMENU%\*.exe
    %MYDOCUMENTS%\*.zip
    %MYDOCUMENTS%\*.rar
    %MYDOCUMENTS%\*.exe
    %MYDOCUMENTS%\*crack*.
    %MYDOCUMENTS%\*keygen*.
    %PROGRAMFILES%\Mozilla Firefox\plugins\*.*
    %PROGRAMFILES%\Internet Explorer\*.*
    %PROGRAMFILES%\Internet Explorer\PLUGINS\*.*
    %PROGRAMFILES%\Mozilla Firefox\*.zip /s
    %PROGRAMFILES%\Mozilla Firefox\*.rar /s
    %PROGRAMFILES%\Mozilla Firefox\*.exe /s
    %PROGRAMFILES%\Internet Explorer\*.zip /s
    %PROGRAMFILES%\Internet Explorer\*.rar /s
    %PROGRAMFILES%\Internet Explorer\*.exe /s
    %SYSTEMDRIVE%\*.dat
    %SYSTEMDRIVE%\*.sys
    %SYSTEMROOT%\*.dat
    %SYSTEMROOT%\*.sys
    %systemroot%\system32\drivers\*.exe /s
    %systemroot%\system32\drivers\*.zip /s
    %systemroot%\system32\drivers\*.rar /s
    %systemroot%\system\*.exe /s
    %systemroot%\system\*.zip /s
    %systemroot%\system\*.rar /s
    %systemroot%\AppPatch\*.exe /s
    %systemroot%\AppPatch\*.zip /s
    %systemroot%\AppPatch\*.rar /s
    %systemroot%\Cache\*.*
    %systemroot%\Downloaded Program Files\*.*
    %systemroot%\Fonts\*.exe /s
    %systemroot%\Fonts\*.zip /s
    %systemroot%\Fonts\*.rar /s
    %systemroot%\Fonts\*.dll /s
    %systemroot%\Help\*.exe /s
    %systemroot%\Help\*.zip /s
    %systemroot%\Help\*.rar /s
    %systemroot%\Tasks\*.*
    %APPDATA%\*.sys
    %APPDATA%\Google\*.*
    %systemroot%\system32\serauth1.dll
    %systemroot%\system32\serauth2.dll
    %systemroot%\system32\sysaudio.sys
    %systemroot%\system32\wdmaud.sys
    %systemroot%\system32\aeaudio.sys
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\serauth1.dll /rs
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\serauth2.dll /rs
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\sysaudio.sys /rs
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\aeaudio.sys /rs
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\wdmaud.sys /rs
    %PROGRAMFILES%\*TinyProxy*.
    HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla|extensions /rs
    %systemroot%\system32\inf\*.exe /s
    %systemroot%\system32\inf\*.zip /s
    %systemroot%\system32\inf\*.rar /s
    %systemroot%\system32\inf\*.dll /s
    %APPDATA%\Opera\Opera\profile\widgets\*.*
    %PROGRAMFILES%\Opera\program\plugins\*.* /s
    %APPDATA%\Opera\Opera\profile\toolbar\*.* /s
    %systemroot%\Web\*.exe /s
    %systemroot%\Web\*.dat /s
    %systemroot%\Web\*.dll /s
    %systemroot%\Web\*.sys /s
    %systemroot%\Web\*.zip /s
    %systemroot%\Web\*.rar /s
    %systemroot%\Wbem\*.exe /s
    %systemroot%\Wbem\*.rar /s
    %systemroot%\Wbem\*.zip /s
    %systemroot%\Wbem\*.dll /s
    %systemroot%\Wbem\*.sys /s
    %systemroot%\Wbem\*.dat /s
    %systemroot%\twain_32\*.exe
    %systemroot%\twain_32\*.dat
    %systemroot%\twain_32\*.dll
    %systemroot%\twain_32\*.sys /s
    %systemroot%\twain_32\*.zip /s
    %systemroot%\twain_32\*.rar /s
    %systemroot%\system\*.sys /s
    %systemroot%\system\*.dat /s
    %systemroot%\WinSxS\*.exe /s
    %systemroot%\WinSxS\*.dat /s
    %systemroot%\WinSxS\*.sys /s
    %systemroot%\WinSxS\*.zip /s
    %systemroot%\WinSxS\*.rar /s
    %systemroot%\Sun\*.dll /s
    %systemroot%\Sun\*.rar /s
    %systemroot%\Sun\*.zip /s
    %systemroot%\Sun\*.exe /s
    %systemroot%\Sun\*.sys /s
    %systemroot%\Sun\*.dat /s
    %systemroot%\srchasst\*.rar /s
    %systemroot%\srchasst\*.zip /s
    %systemroot%\srchasst\*.exe /s
    %systemroot%\srchasst\*.dat /s
    %systemroot%\srchasst\*.sys /s
    %systemroot%\Shellnew\*.rar /s
    %systemroot%\Shellnew\*.zip /s
    %systemroot%\Shellnew\*.dat /s
    %systemroot%\Shellnew\*.exe /s
    %systemroot%\Shellnew\*.sys /s
    %systemroot%\Shellnew\*.dll /s
    %systemroot%\Security\*.rar /s
    %systemroot%\Security\*.zip /s
    %systemroot%\Security\*.dat /s
    %systemroot%\Security\*.exe /s
    %systemroot%\Security\*.sys /s
    %systemroot%\Security\*.dll /s
    %systemroot%\Resources\*.rar /s
    %systemroot%\Resources\*.zip /s
    %systemroot%\Resources\*.dat /s
    %systemroot%\Resources\*.exe /s
    %systemroot%\Resources\*.sys /s
    %systemroot%\Repair\*.sys /s
    %systemroot%\Repair\*.exe /s
    %systemroot%\Repair\*.dll /s
    %systemroot%\Repair\*.zip /s
    %systemroot%\Repair\*.rar /s
    %systemroot%\Registration\*.exe /s
    %systemroot%\Registration\*.dat /s
    %systemroot%\Registration\*.zip /s
    %systemroot%\Registration\*.rar /s
    %systemroot%\Registration\*.dll /s
    %systemroot%\Registration\*.sys /s
    %systemroot%\RegisteredPackages\*.rar /s
    %systemroot%\RegisteredPackages\*.zip /s
    %systemroot%\pss\*.rar /s
    %systemroot%\pss\*.zip /s
    %systemroot%\pss\*.exe /s
    %systemroot%\pss\*.dll /s
    %systemroot%\pss\*.dat /s
    %systemroot%\pss\*.sys /s
    %systemroot%\Provisioning\*.rar /s
    %systemroot%\Provisioning\*.zip /s
    %systemroot%\Provisioning\*.exe /s
    %systemroot%\Provisioning\*.sys /s
    %systemroot%\Provisioning\*.dat /s
    %systemroot%\Provisioning\*.dll /s
    %systemroot%\PIF\*.*
    %systemroot%\PeerNet\*.rar /s
    %systemroot%\PeerNet\*.zip /s
    %systemroot%\PeerNet\*.dat /s
    %systemroot%\PeerNet\*.sys /s
    %systemroot%\PeerNet\*.exe /s
    %systemroot%\PcTel\*.rar /s
    %systemroot%\PcTel\*.zip /s
    %systemroot%\Offline Web Pages\*.exe /s
    %systemroot%\Offline Web Pages\*.zip /s
    %systemroot%\Offline Web Pages\*.rar /s
    %systemroot%\Offline Web Pages\*.sys /s
    %systemroot%\Offline Web Pages\*.dat /s
    %systemroot%\network diagnostic\*.sys /s
    %systemroot%\network diagnostic\*.rar /s
    %systemroot%\network diagnostic\*.zip /s
    %systemroot%\network diagnostic\*.dat /s
    %systemroot%\mui\*.*
    %systemroot%\msapps\*.*
    %systemroot%\msagent\*.zip /s
    %systemroot%\msagent\*.rar /s
    %systemroot%\msagent\*.sys /s
    %systemroot%\msagent\*.dat /s
    %systemroot%\minidump\*.*
    %systemroot%\media\*.sys /s
    %systemroot%\media\*.dat /s
    %systemroot%\media\*.rar /s
    %systemroot%\media\*.zip /s
    %systemroot%\media\*.exe /s
    %systemroot%\media\*.dll /s
    %systemroot%\Help\*.sys /s
    %systemroot%\Help\*.dat /s
    %systemroot%\ie7\*.sys /s
    %systemroot%\ie7\*.zip /s
    %systemroot%\ie7\*.rar /s
    %systemroot%\ie7\*.dat /s
    %systemroot%\ie7updates\*.sys /s
    %systemroot%\ie7updates\*.zip /s
    %systemroot%\ie7updates\*.rar /s
    %systemroot%\ime\*.sys /s
    %systemroot%\ime\*.zip /s
    %systemroot%\ime\*.rar /s
    %systemroot%\inf\*.sys /s
    %systemroot%\inf\*.dat /s
    %systemroot%\installer\*.sys /s
    %systemroot%\installer\*.zip /s
    %systemroot%\installer\*.rar /s
    %systemroot%\installer\*.dat /s
    %systemroot%\internet logs\*.sys /s
    %systemroot%\Cursors\*.rar /s
    %systemroot%\Cursors\*.sys /s
    %systemroot%\Cursors\*.exe /s
    %systemroot%\Cursors\*.dat /s
    %systemroot%\Cursors\*.zip /s
    %systemroot%\Cursors\*.vbs /s
    %systemroot%\Cursors\*.dll /s
    %systemroot%\Config\*.*
    %systemroot%\Config\*.rar /s
    %systemroot%\Config\*.sys /s
    %systemroot%\Config\*.exe /s
    %systemroot%\Config\*.dat /s
    %systemroot%\internet logs\*.dat /s
    %systemroot%\Assembly\*sys /s
    %systemroot%\Assembly\*.rar /s
    %systemroot%\internet logs\*.rar /s
    %systemroot%\AppPatch\*.sys
    %systemroot%\AppPatch\*.dat
    %systemroot%\internet logs\*.zip /s
    %systemroot%\internet logs\*.exe /s
    %systemroot%\internet logs\*.dll /s
    %systemroot%\l2schemas\*.sys /s
    %systemroot%\l2schemas\*.dat /s
    %systemroot%\l2schemas\*.rar /s
    %systemroot%\l2schemas\*.zip /s
    %systemroot%\l2schemas\*.exe /s
    %systemroot%\l2schemas\*.dll /s
    %systemroot%\Fonts\*.dat /s
    %systemroot%\Fonts\*.sys /s
    %systemroot%\Debug\*.rar /s
    %systemroot%\Debug\*.sys /s
    %systemroot%\Debug\*.exe /s
    %systemroot%\Debug\*.dat /s
    %systemroot%\Debug\*.zip /s
    %systemroot%\Debug\*.dll /s
    %systemroot%\ehome\*.dll /s
    %systemroot%\ehome\*.sys /s
    %systemroot%\ehome\*.rar /s
    %systemroot%\ehome\*.dat /s
    %systemroot%\ehome\*.zip /s
    %systemroot%\Connection Wizard\*.dat /s
    %systemroot%\Connection Wizard\*.exe /s
    %systemroot%\Connection Wizard\*.sys /s
    %systemroot%\Connection Wizard\*.rar /s
    %systemroot%\Connection Wizard\*.zip /s
    %systemroot%\Connection Wizard\*.*
    %systemroot%\system32\1025\*.*
    %systemroot%\system32\1028\*.*
    %systemroot%\system32\1031\*.*
    %systemroot%\system32\1033\*.exe
    %systemroot%\system32\1033\*.sys
    %systemroot%\system32\1033\*.zip
    %systemroot%\system32\1033\*.rar
    %systemroot%\system32\1033\*.dat
    %systemroot%\system32\1037\*.*
    %systemroot%\system32\1041\*.*
    %systemroot%\system32\1042\*.*
    %systemroot%\system32\1054\*.*
    %systemroot%\system32\2052\*.*
    %systemroot%\system32\3076\*.*
    %systemroot%\system32\appmgmt\*.exe /s
    %systemroot%\system32\appmgmt\*.sys /s
    %systemroot%\system32\appmgmt\*.dll /s
    %systemroot%\system32\appmgmt\*.dat /s
    %systemroot%\system32\appmgmt\*.zip /s
    %systemroot%\system32\appmgmt\*.rar /s
    %systemroot%\system32\bits\*.rar /s
    %systemroot%\system32\bits\*.zip /s
    %systemroot%\system32\bits\*.exe /s
    %systemroot%\system32\bits\*.dat /s
    %systemroot%\system32\bits\*.sys /s
    %systemroot%\system32\catroot\*.rar /s
    %systemroot%\system32\catroot\*.zip /s
    %systemroot%\system32\catroot\*.dll /s
    %systemroot%\system32\catroot\*.sys /s
    %systemroot%\system32\catroot\*.exe /s
    %systemroot%\system32\catroot\*.dat /s
    %systemroot%\system32\catroot2\*.rar /s
    %systemroot%\system32\catroot2\*.zip /s
    %systemroot%\system32\catroot2\*.exe /s
    %systemroot%\system32\catroot2\*.dat /s
    %systemroot%\system32\catroot2\*.dll /s
    %systemroot%\system32\catroot2\*.sys /s
    %systemroot%\system32\com\*.sys /s
    %systemroot%\system32\com\*.zip /s
    %systemroot%\system32\com\*.rar /s
    %systemroot%\system32\config\*.rar /s
    %systemroot%\system32\config\*.zip /s
    %systemroot%\system32\config\*.sys /s
    %systemroot%\system32\config\*.dll /s
    %systemroot%\system32\config\*.exe /s
    %systemroot%\system32\dhcp\*.*
    %systemroot%\system32\DirectX\*.rar /s
    %systemroot%\system32\DirectX\*.zip /s
    %systemroot%\system32\DirectX\*.sys /s
    %systemroot%\system32\DirectX\*.dll /s
    %systemroot%\system32\DirectX\*.exe /s
    %systemroot%\system32\DirectX\*.dat /s
    %systemroot%\system32\Dllcache\*.zip /s
    %systemroot%\system32\Dllcache\*.rar /s
    %systemroot%\system32\drivers\*.dat
    %systemroot%\system32\drivers\*.exe /s
    %systemroot%\system32\drivers\*.zip /s
    %systemroot%\system32\drivers\*.rar /s
    %systemroot%\system32\drvstore\*.dat
    %systemroot%\system32\drvstore\*.exe /s
    %systemroot%\system32\drvstore\*.zip /s
    %systemroot%\system32\drvstore\*.rar /s
    %systemroot%\system32\en\*.dat /s
    %systemroot%\system32\en\*.exe /s
    %systemroot%\system32\en\*.zip /s
    %systemroot%\system32\en\*.rar /s
    %systemroot%\system32\en\*.sys /s
    %systemroot%\system32\en\*.sys /s
    %systemroot%\system32\en\*.dat /s
    %systemroot%\system32\en-us\*.exe /s
    %systemroot%\system32\en-us\*.zip /s
    %systemroot%\system32\en-us\*.rar /s
    %systemroot%\system32\en-us\*.dll /s
    %systemroot%\system32\export\*.*
    %systemroot%\system32\GroupPolicy\*.sys /s
    %systemroot%\system32\GroupPolicy\*.dat /s
    %systemroot%\system32\GroupPolicy\*.exe /s
    %systemroot%\system32\GroupPolicy\*.zip /s
    %systemroot%\system32\GroupPolicy\*.rar /s
    %systemroot%\system32\GroupPolicy\*.dll /s
    %systemroot%\system32\ias\*.sys /s
    %systemroot%\system32\ias\*.dat /s
    %systemroot%\system32\ias\*.exe /s
    %systemroot%\system32\ias\*.zip /s
    %systemroot%\system32\ias\*.rar /s
    %systemroot%\system32\ias\*.dll /s
    %systemroot%\system32\icsxml\*.sys /s
    %systemroot%\system32\icsxml\*.dat /s
    %systemroot%\system32\icsxml\*.exe /s
    %systemroot%\system32\icsxml\*.zip /s
    %systemroot%\system32\icsxml\*.rar /s
    %systemroot%\system32\icsxml\*.dll /s
    %systemroot%\system32\ime\*.sys /s
    %systemroot%\system32\ime\*.dat /s
    %systemroot%\system32\ime\*.zip /s
    %systemroot%\system32\ime\*.rar /s
    %systemroot%\system32\inetsrv\*.sys /s
    %systemroot%\system32\inetsrv\*.dat /s
    %systemroot%\system32\inetsrv\*.exe /s
    %systemroot%\system32\inetsrv\*.zip /s
    %systemroot%\system32\inetsrv\*.rar /s
    %systemroot%\system32\LogFiles\*.sys /s
    %systemroot%\system32\LogFiles\*.dat /s
    %systemroot%\system32\LogFiles\*.exe /s
    %systemroot%\system32\LogFiles\*.zip /s
    %systemroot%\system32\LogFiles\*.rar /s
    %systemroot%\system32\LogFiles\*.dll /s
    %systemroot%\system32\Macromed\*.sys /s
    %systemroot%\system32\Macromed\*.dat /s
    %systemroot%\system32\Macromed\*.zip /s
    %systemroot%\system32\Macromed\*.rar /s
    %systemroot%\system32\Microsoft\*.sys /s
    %systemroot%\system32\Microsoft\*.dat /s
    %systemroot%\system32\Microsoft\*.exe /s
    %systemroot%\system32\Microsoft\*.zip /s
    %systemroot%\system32\Microsoft\*.rar /s
    %systemroot%\system32\Microsoft\*.dll /s
    %systemroot%\system32\Msdtc\*.sys /s
    %systemroot%\system32\Msdtc\*.dat /s
    %systemroot%\system32\Msdtc\*.exe /s
    %systemroot%\system32\Msdtc\*.zip /s
    %systemroot%\system32\Msdtc\*.rar /s
    %systemroot%\system32\Msdtc\*.dll /s
    %systemroot%\system32\Mui\*.sys /s
    %systemroot%\system32\Mui\*.dat /s
    %systemroot%\system32\Mui\*.exe /s
    %systemroot%\system32\Mui\*.zip /s
    %systemroot%\system32\Mui\*.rar /s
    %systemroot%\system32\npp\*.sys /s
    %systemroot%\system32\npp\*.dat /s
    %systemroot%\system32\npp\*.zip /s
    %systemroot%\system32\npp\*.rar /s
    %systemroot%\system32\NtMsData\*.sys /s
    %systemroot%\system32\NtMsData\*.dat /s
    %systemroot%\system32\NtMsData\*.exe /s
    %systemroot%\system32\NtMsData\*.zip /s
    %systemroot%\system32\NtMsData\*.rar /s
    %systemroot%\system32\NtMsData\*.dll /s
    %systemroot%\system32\oobe\*.sys /s
    %systemroot%\system32\oobe\*.dat /s
    %systemroot%\system32\oobe\*.zip /s
    %systemroot%\system32\oobe\*.rar /s
    %systemroot%\system32\PreInstall\*.sys /s
    %systemroot%\system32\PreInstall\*.dat /s
    %systemroot%\system32\PreInstall\*.exe /s
    %systemroot%\system32\PreInstall\*.zip /s
    %systemroot%\system32\PreInstall\*.rar /s
    %systemroot%\system32\PreInstall\*.dll /s
    %systemroot%\system32\ras\*.sys /s
    %systemroot%\system32\ras\*.dat /s
    %systemroot%\system32\ras\*.exe /s
    %systemroot%\system32\ras\*.zip /s
    %systemroot%\system32\ras\*.rar /s
    %systemroot%\system32\ras\*.dll /s
    %systemroot%\system32\ReInstallBackups\*.dat /s
    %systemroot%\system32\ReInstallBackups\*.zip /s
    %systemroot%\system32\ReInstallBackups\*.rar /s
    %systemroot%\system32\Restore\*.sys /s
    %systemroot%\system32\Restore\*.zip /s
    %systemroot%\system32\Restore\*.rar /s
    %systemroot%\system32\Restore\*.dll /s
    %systemroot%\system32\Scripting\*.sys /s
    %systemroot%\system32\Scripting\*.dat /s
    %systemroot%\system32\Scripting\*.exe /s
    %systemroot%\system32\Scripting\*.zip /s
    %systemroot%\system32\Scripting\*.rar /s
    %systemroot%\system32\Scripting\*.dll /s
    %systemroot%\system32\Setup\*.sys /s
    %systemroot%\system32\Setup\*.dat /s
    %systemroot%\system32\Setup\*.exe /s
    %systemroot%\system32\Setup\*.zip /s
    %systemroot%\system32\Setup\*.rar /s
    %systemroot%\system32\ShellExt\*.*
    %systemroot%\system32\SoftwareDistribution\*.sys /s
    %systemroot%\system32\SoftwareDistribution\*.dat /s
    %systemroot%\system32\SoftwareDistribution\*.exe /s
    %systemroot%\system32\SoftwareDistribution\*.zip /s
    %systemroot%\system32\SoftwareDistribution\*.rar /s
    %systemroot%\system32\URTTEmp\*.sys /s
    %systemroot%\system32\URTTEmp\*.dat /s
    %systemroot%\system32\URTTEmp\*.zip /s
    %systemroot%\system32\URTTEmp\*.rar /s
    %systemroot%\system32\USMT\*.sys /s
    %systemroot%\system32\USMT\*.dat /s
    %systemroot%\system32\USMT\*.zip /s
    %systemroot%\system32\USMT\*.rar /s
    %systemroot%\system32\Wbem\*.sys /s
    %systemroot%\system32\Wbem\*.zip /s
    %systemroot%\system32\Wbem\*.rar /s
    %systemroot%\system32\Wins\*.*
    %systemroot%\system32\Xircom\*.*
    %systemroot%\system32\XPSViewer\*.sys /s
    %systemroot%\system32\XPSViewer\*.dat /s
    %systemroot%\system32\XPSViewer\*.zip /s
    %systemroot%\system32\XPSViewer\*.rar /s
    %systemroot%\system32\XPSViewer\*.dll /s
    %COMMONPROGRAMFILES%\*.sys /s
    %COMMONPROGRAMFILES%\*.zip /s
    %COMMONPROGRAMFILES%\*.rar /s
    %COMMONPROGRAMFILES%\*.*
    %ProgramFiles%\Movie Maker\*.dll
    %DriveLetter%\RECYCLER\*S-%d-%d-%d-%d%d%d-%d%d%d-%d%d%d-%d*.
    %systemroot%\java\apps\*.*
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Shell Folders
    HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
    %systemroot%\winstart.bat
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Runonce
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunonceEx
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VxD
    HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System\Scripts|Startup /rs
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MPRServices
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Option
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Monitors
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AeDebug
    %systemroot%\system32\basequu32.dll
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BootVerificationProgram
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\ChkDskPath
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\cleanuppath
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\DefragPath




  • Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and post the information back here in an attachment. I will review it when it comes in. The last line is < End of Report >, so make sure that is the last line in the attached report.


Make sure you attach the report in your reply. If it is too big to upload, then zip the text file and upload it that way
hello


Start OTScanIt2. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Unregister Dlls]
[Win32 Services - Safe List]
YY -> (eac_notifysvc) eAcceleration Notification Service [Win32_Shared | Auto | Stopped] ->
YY -> (eac_productsvc) eAcceleration Product Manager Service [Win32_Own | Auto | Stopped] ->
YY -> (sstsmonsvc) StopSign Antivirus Security Center Provider [Win32_Shared | Auto | Stopped] ->
[Registry - Safe List]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "eanth_critical_update_alert" -> [C:\PROGRA~1\ACCELE~1\ANTI-V~1\EANTH_~1.EXE /Startup]
YN -> "OnAccess" -> %ProgramFiles%\eAcceleration\OnAccess\onaccess.exe ["C:\Program Files\eAcceleration\OnAccess\onaccess.exe" -erk]
YN -> "SoftwareStation" -> %ProgramFiles%\eAcceleration\Station\station.exe ["C:\Program Files\eAcceleration\Station\station.exe" /b Startup]
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\
YN -> {c95fe080-8f5d-11d2-a20b-00aa003c157a}:%SystemRoot%\web\related.htm [HKLM] -> %SystemRoot%\web\related.htm [Button: @shdoclc.dll,-866]
YN -> {c95fe080-8f5d-11d2-a20b-00aa003c157a}:%SystemRoot%\web\related.htm [HKLM] -> %SystemRoot%\web\related.htm [Menu: @shdoclc.dll,-864]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{A75C6120-9B36-11d4-A3F0-009027427750}" [HKLM] -> [Reg Error: Key error.]
YN -> CmdMapping\\"{c95fe080-8f5d-11d2-a20b-00aa003c157a}" [HKLM] -> [@shdoclc.dll,-866]
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\
YN -> {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab [Java Plug-in 1.6.0_07]
[Files/Folders - Created Within 90 Days]
NY -> 4 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp
NY -> 4 C:\windows\*.tmp files -> C:\windows\*.tmp
NY -> JavaRa.zip -> %UserProfile%\Desktop\JavaRa.zip
NY -> CF29848.exe -> %SystemRoot%\System32\CF29848.exe
NY -> 32788R22FWJFW -> %SystemDrive%\32788R22FWJFW
NY -> _OTListIt -> %SystemDrive%\_OTListIt
NY -> Rooter$ -> %SystemDrive%\Rooter$
[Empty Temp Folders]
[Start Explorer]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.



also post a new HJT Log
I think that did it!

OT log

Process Explorer.EXE killed successfully!
[Win32 Services - Safe List]
Service eac_notifysvc stopped successfully!
Service eac_notifysvc deleted successfully!
File not found.
Service eac_productsvc stopped successfully!
Service eac_productsvc deleted successfully!
File not found.
Service sstsmonsvc stopped successfully!
Service sstsmonsvc deleted successfully!
File not found.
[Registry - Safe List]
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\eanth_critical_update_alert deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\OnAccess deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SoftwareStation deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c95fe080-8f5d-11d2-a20b-00aa003c157a}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c95fe080-8f5d-11d2-a20b-00aa003c157a}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{A75C6120-9B36-11d4-A3F0-009027427750} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A75C6120-9B36-11d4-A3F0-009027427750}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c95fe080-8f5d-11d2-a20b-00aa003c157a}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\Contains\Files\ not found.
not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
[Files/Folders - Created Within 90 Days]
C:\Documents and Settings\user1\Desktop\JavaRa.zip moved successfully.
C:\windows\System32\CF29848.exe moved successfully.
C:\32788R22FWJFW folder moved successfully.
C:\_OTListIt\MovedFiles\02072009_181955\WINDOWS\temp folder moved successfully.
C:\_OTListIt\MovedFiles\02072009_181955\WINDOWS folder moved successfully.
C:\_OTListIt\MovedFiles\02072009_181955\Documents and Settings\user1\Local Settings\Temp folder moved successfully.
C:\_OTListIt\MovedFiles\02072009_181955\Documents and Settings\user1\Local Settings folder moved successfully.
C:\_OTListIt\MovedFiles\02072009_181955\Documents and Settings\user1 folder moved successfully.
C:\_OTListIt\MovedFiles\02072009_181955\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5 folder moved successfully.
C:\_OTListIt\MovedFiles\02072009_181955\Documents and Settings\LocalService\Local Settings\Temporary Internet Files folder moved successfully.
C:\_OTListIt\MovedFiles\02072009_181955\Documents and Settings\LocalService\Local Settings folder moved successfully.
C:\_OTListIt\MovedFiles\02072009_181955\Documents and Settings\LocalService folder moved successfully.
C:\_OTListIt\MovedFiles\02072009_181955\Documents and Settings folder moved successfully.
C:\_OTListIt\MovedFiles\02072009_181955 folder moved successfully.
C:\_OTListIt\MovedFiles\02062009_105745\WINDOWS\Web folder moved successfully.
C:\_OTListIt\MovedFiles\02062009_105745\WINDOWS\temp folder moved successfully.
C:\_OTListIt\MovedFiles\02062009_105745\WINDOWS folder moved successfully.
C:\_OTListIt\MovedFiles\02062009_105745\Documents and Settings\user1\Local Settings\Temp folder moved successfully.
C:\_OTListIt\MovedFiles\02062009_105745\Documents and Settings\user1\Local Settings folder moved successfully.
C:\_OTListIt\MovedFiles\02062009_105745\Documents and Settings\user1 folder moved successfully.
C:\_OTListIt\MovedFiles\02062009_105745\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5 folder moved successfully.
C:\_OTListIt\MovedFiles\02062009_105745\Documents and Settings\LocalService\Local Settings\Temporary Internet Files folder moved successfully.
C:\_OTListIt\MovedFiles\02062009_105745\Documents and Settings\LocalService\Local Settings folder moved successfully.
C:\_OTListIt\MovedFiles\02062009_105745\Documents and Settings\LocalService folder moved successfully.
C:\_OTListIt\MovedFiles\02062009_105745\Documents and Settings folder moved successfully.
C:\_OTListIt\MovedFiles\02062009_105745 folder moved successfully.
C:\_OTListIt\MovedFiles\02052009_190608\WINDOWS\temp folder moved successfully.
C:\_OTListIt\MovedFiles\02052009_190608\WINDOWS folder moved successfully.
C:\_OTListIt\MovedFiles\02052009_190608\Documents and Settings\user1\Local Settings\Temp folder moved successfully.
C:\_OTListIt\MovedFiles\02052009_190608\Documents and Settings\user1\Local Settings folder moved successfully.
C:\_OTListIt\MovedFiles\02052009_190608\Documents and Settings\user1 folder moved successfully.
C:\_OTListIt\MovedFiles\02052009_190608\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5 folder moved successfully.
C:\_OTListIt\MovedFiles\02052009_190608\Documents and Settings\LocalService\Local Settings\Temporary Internet Files folder moved successfully.
C:\_OTListIt\MovedFiles\02052009_190608\Documents and Settings\LocalService\Local Settings folder moved successfully.
C:\_OTListIt\MovedFiles\02052009_190608\Documents and Settings\LocalService folder moved successfully.
C:\_OTListIt\MovedFiles\02052009_190608\Documents and Settings folder moved successfully.
C:\_OTListIt\MovedFiles\02052009_190608 folder moved successfully.
C:\_OTListIt\MovedFiles folder moved successfully.
C:\_OTListIt folder moved successfully.
C:\Rooter$ folder moved successfully.
[Empty Temp Folders]
File delete failed. C:\Documents and Settings\user1\Local Settings\temp\~DF235A.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\user1\Local Settings\temp\~DFB760.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\user1\Local Settings\temp\~DFD01B.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\windows\temp\Perflib_Perfdata_198.dat scheduled to be deleted on reboot.
File delete failed. C:\windows\temp\Perflib_Perfdata_4b0.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
RecycleBin -> emptied.
Explorer started successfully
< End of fix log >
OTScanIt2 by OldTimer - Version 1.0.8.0 fix logfile created on 02222009_173259

Files moved on Reboot…
C:\Documents and Settings\user1\Local Settings\temp\~DF235A.tmp moved successfully.
File C:\Documents and Settings\user1\Local Settings\temp\~DFB760.tmp not found!
File C:\Documents and Settings\user1\Local Settings\temp\~DFD01B.tmp not found!
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat moved successfully.
File C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat not found!
File C:\windows\temp\Perflib_Perfdata_198.dat not found!
File C:\windows\temp\Perflib_Perfdata_4b0.dat not found!

Registry entries deleted on Reboot…


HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:41:36 PM, on 2/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\windows\Explorer.EXE
C:\windows\notepad.exe
C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\windows\system32\wuauclt.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [QuickCare] C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe /P QuickCare
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233948222608
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SupportSoft Listener Service (sprtlisten) - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe

–
End of file - 5916 bytes
Super, you are awesome! Thanks for all your help, it may have took awhile but I learned some in the process as well. Thanks again, and thanks to the folks that keep this forum going as well!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI