il est ou,le fichier report texte?
j'ai trouvé une liste sous fdfix, ci-joint
[Top]
SDFix v1.127
Updated 17th January 9am
SDFix will only run on Windows 2000 and Windows XP in Safe Mode !
( Requires Administrator Account Privileges )
Press Enter or CTRL & F to Search with Firefox
View Changelog (Online)
--------------------------------------------------------------------------------Catchme W2K/XP/Vista - Rootkit/Stealth Malware Detector by Gmer -
www.gmer.net
--------------------------------------------------------------------------------
SDFix uses files by the following developers:
Bill Stewart Charles Dye Craig Peacock Flexhex Frank Heyne Gmer Info-Zip Lars Hederer Noël Danjou Robin Keir SteelWerX Thankyou to them. everyone at SpywareInfo and the MR team
--------------------------------------------------------------------------------
Notes:
If this error message is displayed when running SDFix:
The command prompt has been disabled by your administrator.
Press any key to continue . . .
Please goto Start Menu > Run > then copy and paste the following line:
%systemdrive%\SDFix\apps\swreg IMPORT %systemdrive%\SDFix\apps\Enable_Command_Prompt.reg
Press OK then run SDFix again
If the Command Prompt window flashes on then off again on XP or Windows2000
Goto Start Menu > Run > then copy and paste the following line:
%systemroot%\system32\cmd.exe /K %systemdrive%\SDFix\apps\FixPath.exe
Click OK, then type Y and press Enter when prompted, Reboot and start SDFix again
If SDFix still doesnt run check the %comspec% variable
Goto Start Menu > Right click My Computer > click properties > click Advanced
Click Environment Variables and check that the ComSpec variable points to cmd.exe
%SystemRoot%\system32\cmd.exe
SDFix uses ERUNT to create a registry backup which can be restored using Start > Run:
%SystemRoot%\ERUNT\SDFix\ERDNT.EXE
--------------------------------------------------------------------------------
The fixtool removes these Trojan Variants (Listed using Trend Micro's - HijackThis)
Backdoor (IRCBot) Trojans:
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\accwiz.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\astra32.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\Avsynmgr.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\BTStack.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\BTTray.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\ctfmon.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\czsrv.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\DivXsm.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\dsserv.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\hkcmd.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\kasvc.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\lanbg.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\LBTSERV.EXE
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\Manager.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\Mrshield.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\MSASCu.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\mssq.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\MSTask.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\navapsvc.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\nbsrv.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\netserv.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\ntlsrv.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\ntvdm.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\nzbd.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\pcsrv.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\QuickTime.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\rstrui.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\rtvscan.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\srvrmgr.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\stisvc.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\tcpip.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\tremapi.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\VTTray.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\VTTrayp.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\WinDV.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\WinMgmt.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\winsrv.exe
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\wuauclt.exe
F2 - REG:system.ini: Shell=Explorer.exe asus.exe
F2 - REG:system.ini: Shell=Explorer.exe bootini.exe
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\lsass.exe
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\svcmgr32.exe
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\drivers\ntndis.exe
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\WinConfSrv.exe
F2 - REG:system.ini: Shell=Explorer.exe chh.exe
F2 - REG:system.ini: Shell=Explorer.exe creative.exe
F2 - REG:system.ini: Shell=Explorer.exe esijavaupdt32.exe
F2 - REG:system.ini: Shell=Explorer.exe glossary.exe
F2 - REG:system.ini: Shell=Explorer.exe javaapplet.exe
F2 - REG:system.ini: Shell=Explorer.exe javaapplets.exe
F2 - REG:system.ini: Shell=Explorer.exe javanet.exe
F2 - REG:system.ini: Shell=Explorer.exe jconsole.exe
F2 - REG:system.ini: Shell=Explorer.exe msclt.exe
F2 - REG:system.ini: Shell=Explorer.exe msdhcp.exe
F2 - REG:system.ini: Shell=Explorer.exe msdhcprs.exe
F2 - REG:system.ini: Shell=Explorer.exe msdn-nt.exe
F2 - REG:system.ini: Shell=Explorer.exe msdnxp.exe
F2 - REG:system.ini: Shell=Explorer.exe msguard.exe
F2 - REG:system.ini: Shell=Explorer.exe msi32info.exe
F2 - REG:system.ini: Shell=Explorer.exe msident.exe
F2 - REG:system.ini: Shell=Explorer.exe msijavaupdt32.exe
F2 - REG:system.ini: Shell=Explorer.exe msjava.exe
F2 - REG:system.ini: Shell=Explorer.exe msjavames.exe
F2 - REG:system.ini: Shell=Explorer.exe msjavaxps.exe
F2 - REG:system.ini: Shell=Explorer.exe mssqlsnt.exe
F2 - REG:system.ini: Shell=Explorer.exe osndyrn.exe
F2 - REG:system.ini: Shell=Explorer.exe SndMAX.exe
F2 - REG:system.ini: Shell=explorer.exe SNDVOLTASK.EXE
F2 - REG:system.ini: Shell=Explorer.exe update.exe
F2 - REG:system.ini: Shell=Explorer.exe wincomm.exe
F2 - REG:system.ini: Shell=Explorer.exe windfe.exe
F2 - REG:system.ini: Shell=Explorer.exe winser.exe
F2 - REG:system.ini: Shell=Explorer.exe winservnt32.exe
F2 - REG:system.ini: Shell=Explorer.exe winskd.exe
F2 - REG:system.ini: Shell=Explorer.exe winsys.exe
F2 - REG:system.ini: Shell=Explorer.exe wintask32.exe
F2 - REG:system.ini: Shell=Explorer.exe wkssvr.exe
F2 - REG:system.ini: Shell=Explorer.exe wrapper.exe
F2 - REG:system.ini: Shell=Explorer.exe xpjavams.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,asus.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,bootini.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,chh.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,creative.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,esijavaupdt32.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,glossary.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,javaapplet.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,javaapplets.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,javanet.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,jconsole.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,msclt.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,msdn-nt.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,msdnxp.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,msguard.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,msi32info.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,msident.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,msijavaupdt32.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,msjava.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,msjavames.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,msjavaxps.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,mssqlsnt.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,osndyrn.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,update.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,wincomm.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,windfe.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,winser.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,winservnt32.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,winskd.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,winsys.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,wintask32.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,wkssvr.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,wrapper.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,xpjavams.exe
F3 - REG:win.ini: run=c:\windows\system\programas\svchost.exe
F3 - REG:win.ini: run=c:\windows\system32\shellext\czvhost.exe
F3 - REG:win.ini: load=C:\DaNeT\RVHOST.exe
F3 - REG:win.ini: load=C:\Jaws\RVHOST.exe
F3 - REG:win.ini: load=C:\WINDOWS\system32\zura\RVHOST.exe
O4 - Startup: MY_C4D.jpg
O4 - Startup: rBot.exe
O4 - Startup: svchost.exe
O4 - Startup: winlogon.lnk = ?
O4 - Global Startup: msconfig.exe
O4 - Global Startup: svchost.exe
O4 - Global Startup: taskmgr.exe
O4 - Global Startup: Wincbr.exe
O4 - Global Startup: winlogin.exe
O4 - Global Startup: wupdmgr.exe
O4 - HKLM\..\Run: [] ajsha5.exe
O4 - HKLM\..\RunServices: [] ajsha5.exe
O4 - HKCU\..\Run: [] ajsha5.exe
O4 - HKLM\..\Run: [] C:\WINDOWS\scvhost.exe
O4 - HKLM\..\RunServices: [] C:\WINDOWS\scvhost.exe
O4 - HKLM\..\Run: [] iexplorer.exe
O4 - HKLM\..\RunServices: [] iexplorer.exe
O4 - HKLM\..\Run: [] ifconfig.exe
O4 - HKLM\..\RunServices: [] ifconfig.exe
O4 - HKCU\..\Run: [] ifconfig.exe
O4 - HKLM\..\Run: [] lsvhostwinlk.exe
O4 - HKLM\..\RunServices: [] lsvhostwinlk.exe
O4 - HKLM\..\Run: [] ne.exe
O4 - HKLM\..\RunServices: [] ne.exe
O4 - HKCU\..\Run: [] ne.exe
O4 - HKLM\..\Run: [] win32sys.exe
O4 - HKLM\..\RunServices: [] win32sys.exe
O4 - HKLM\..\Run: [] winxp.exe
O4 - HKLM\..\RunServices: [] winxp.exe
O4 - HKCU\..\Run: [] winxp.exe
O4 - HKLM\..\Run: [::1] C:\WINDOWS\rbot.exe
O4 - HKLM\..\Run: [1] system32.exe
O4 - HKLM\..\RunServices: [1] system32.exe
O4 - HKLM\..\Run: [388529725448] AutomaticUpdates.exe
O4 - HKLM\..\RunServices: [388529725448] AutomaticUpdates.exe
O4 - HKCU\..\Run: [388529725448] AutomaticUpdates.exe
O4 - HKLM\..\Run: [4684735485910] netdll32.exe
O4 - HKLM\..\RunServices: [4684735485910] netdll32.exe
O4 - HKCU\..\Run: [4684735485910] netdll32.exe
O4 - HKLM\..\Run: [6435748] winupdates.exe
O4 - HKLM\..\RunServices: [6435748] winupdates.exe
O4 - HKCU\..\Run: [6435748] winupdates.exe
O4 - HKLM\..\Run: [64823457] taskdll32.exe
O4 - HKLM\..\RunServices: [64823457] taskdll32.exe
O4 - HKCU\..\Run: [64823457] taskdll32.exe
O4 - HKLM\..\Run: [.nvsvc] %Appdata%\smss.exe /w
O4 - HKLM\..\Run: [.nvsvc] C:\WINDOWS\system\smss.exe /w
O4 - HKLM\..\Run: [.nvsvcb] C:\WINDOWS\System32\smssb.exe
O4 - HKLM\..\Run: [*windows update] wscxt.exe
O4 - HKLM\..\RunServices: [*windows update] wscxt.exe
O4 - HKCU\..\Run: [*windows update] wscxt.exe
O4 - HKLM\..\Run: [aa bbcc dde effgghh jj] update.exe
O4 - HKCU\..\Run: [aa bbcc dde effgghh jj] update.exe
O4 - HKLM\..\Run: [AAMSFree702] C:\windows\system32\sys.exe
O4 - HKLM\..\Run: [Acess2007a] access2007a.exe
O4 - HKLM\..\RunServices: [Acess2007a] access2007a.exe
O4 - HKLM\..\Run: [Acrobat Read] C:\WINDOWS\System32\acroup32.exe
O4 - HKCU\..\Run: [Acrobat Read] C:\WINDOWS\System32\acroup32.exe
O4 - HKLM\..\Run: [Acronis.exe] C:\WINDOWS\Acronis.exe
O4 - HKLM\..\Run: [ActiveScan Antivirus] ActiveScan.exe
O4 - HKLM\..\RunServices: [ActiveScan Antivirus] ActiveScan.exe
O4 - HKCU\..\Run: [ActiveScan Antivirus] ActiveScan.exe
O4 - HKCU\..\RunServices: [ActiveScan Antivirus] ActiveScan.exe
O4 - HKLM\..\Run: [ActiveScript32] C:\WINDOWS\System32\nod.exe
O4 - HKLM\..\RunServices: [ActiveScript32] C:\WINDOWS\System32\nod.exe
O4 - HKLM\..\Run: [ActiveSync] C:\WINDOWS\System32\wcescom32.exe
O4 - HKCU\..\Run: [ActiveSync] C:\WINDOWS\System32\wcescom32.exe
O4 - HKLM\..\Run: [ADDITIONAL Services] pkgadd.exe
O4 - HKLM\..\RunServices: [ADDITIONAL Services] pkgadd.exe
O4 - HKCU\..\Run: [ADDITIONAL Services] pkgadd.exe
O4 - HKCU\..\RunServices: [ADDITIONAL Services] pkgadd.exe
O4 - HKLM\..\Run: [AdobeReader] msni.exe
O4 - HKLM\..\RunServices: [AdobeReader] msni.exe
O4 - HKLM\..\Run: [AdobeReaderPro] msnserve.exe
O4 - HKLM\..\RunServices: [AdobeReaderPro] msnserve.exe
O4 - HKLM\..\Run: [AdobeReaderPro] subset.exe
O4 - HKLM\..\RunServices: [AdobeReaderPro] subset.exe
O4 - HKLM\..\Run: [AdobeReaderPro] updt.exe
O4 - HKLM\..\RunServices: [AdobeReaderPro] updt.exe
O4 - HKLM\..\Run: [AdobeReaderPro] winini.exe
O4 - HKLM\..\RunServices: [AdobeReaderPro] winini.exe
O4 - HKLM\..\Run: [AdobeReaderPro] winslog.exe
O4 - HKLM\..\RunServices: [AdobeReaderPro] winslog.exe
O4 - HKCU\..\Run: [AdobeReaderPro] winslog.exe
O4 - HKLM\..\Run: [AdobeReaderProfessional] msx64.exe
O4 - HKLM\..\RunServices: [AdobeReaderProfessional] msx64.exe
O4 - HKLM\..\Run: [AdobeReaderPros] sysmsn.exe
O4 - HKLM\..\RunServices: [AdobeReaderPros] sysmsn.exe
O4 - HKLM\..\Run: [ADSL Rundll32.exe] C:\WINDOWS\system32\helpw86.exe
O4 - HKLM\..\RunServices: [ADSL Rundll32.exe] C:\WINDOWS\system32\helpw86.exe
O4 - HKLM\..\Run: [Ag3nt Servers Nt] ag3nt.exe
O4 - HKLM\..\RunServices: [Ag3nt Servers Nt] ag3nt.exe
O4 - HKLM\..\Run: [America Online 8.0] taskrg.exe
O4 - HKCU\..\RunOnce: [America Online 8.0] taskrg.exe
O4 - HKLM\..\Run: [AntiVirus Process] C:\WINDOWS\system32\Com\virprot.exe
O4 - HKLM\..\RunServices: [AntiVirus Process] C:\WINDOWS\system32\Com\virprot.exe
O4 - HKCU\..\Run: [AntiVirus Process] C:\WINDOWS\system32\Com\virprot.exe
O4 - HKLM\..\Run: [Antivirus Startup] C:\WINDOWS\system32\inetsrv\antivir.exe
O4 - HKLM\..\RunServices: [Antivirus Startup] C:\WINDOWS\system32\inetsrv\antivir.exe
O4 - HKCU\..\Run: [Antivirus Startup] C:\WINDOWS\system32\inetsrv\antivir.exe
O4 - HKLM\..\Run: [AOL Instant Messenger] aimsgr.exe
O4 - HKLM\..\RunServices: [AOL Instant Messenger] aimsgr.exe
O4 - HKLM\..\Run: [aolupdater.exe] aolupdater.exe
O4 - HKLM\..\RunServices: [aolupdater.exe] aolupdater.exe
O4 - HKLM\..\Run: [Append] C:\WINDOWS\system32\apend.exe
O4 - HKLM\..\Run: [AppletINIT] INITIATE.EXE
O4 - HKCU\..\RunOnce: [AppletINIT] INITIATE.EXE
O4 - HKLM\..\Run: [Application Layer Gateway Service] aIg.exe
O4 - HKLM\..\RunServices: [Application Layer Gateway Service] aIg.exe
O4 - HKLM\..\Run: [Application Layer Gateway Service] C:\WINDOWS\system32\algs.exe
O4 - HKLM\..\Run: [Application Layer Services] avrsvc.exe
O4 - HKLM\..\Run: [ApplicationProtocolRun] smsbvl32.exe
O4 - HKCU\..\Run: [ApplicationProtocolRun] smsbvl32.exe
O4 - HKLM\..\Run: [Application Task Service] lssys.exe
O4 - HKLM\..\RunServices: [Application Task Service] lssys.exe
O4 - HKLM\..\Run: [asedwes] C:\WINDOWS\system32\(Random 8 Letter).exe
O4 - HKCU\..\Run: [asedwes] C:\WINDOWS\system32\(Random 8 Letter).exe
O4 - HKLM\..\Run: [asnconsole] msasn.exe
O4 - HKLM\..\RunServices: [asnconsole] msasn.exe
O4 - HKLM\..\Run: [Asus MotherBoard Utility] asus.exe
O4 - HKLM\..\RunServices: [Asus MotherBoard Utility] asus.exe
O4 - HKCU\..\Run: [Asus MotherBoard Utility] asus.exe
O4 - HKCU\..\RunServices: [Asus MotherBoard Utility] asus.exe
O4 - HKLM\..\Run: [ATI] msnmsur.exe
O4 - HKLM\..\Run: [Ati2evxx] C:\WINDOWS\system32\Ati2evxx.com
O4 - HKLM\..\Run: [ATI Active Graphics Card Monitor] C:\WINDOWS\System32\atievx.exe
O4 - HKLM\..\Run: [ATI AS Filter] msnse.exe
O4 - HKLM\..\RunServices: [ATI AS Filter] msnse.exe
O4 - HKCU\..\Run: [ATI AS Filter] msnse.exe
O4 - HKCU\..\RunServices: [ATI AS Filter] msnse.exe
O4 - HKLM\..\Run: [ATI Display Driver] C:\WINDOWS\system32\drivers\atixd.exe
O4 - HKLM\..\RunServices: [ATI Display Driver] C:\WINDOWS\system32\drivers\atixd.exe
O4 - HKLM\..\Run: [Ati Display Settings] C:\WINDOWS\System32\atividx.exe
O4 - HKLM\..\RunServices: [Ati Display Settings] C:\WINDOWS\System32\atividx.exe
O4 - HKLM\..\Run: [ATI Video Driver Control] atigfx.exe
O4 - HKLM\..\RunServices: [ATI Video Driver Control] atigfx.exe
O4 - HKCU\..\Run: [ATI Video Driver Control] atigfx.exe
O4 - HKCU\..\RunServices: [ATI Video Driver Control] atigfx.exe
O4 - HKLM\..\Run: [ATI Video Driver Control] blah.exe
O4 - HKLM\..\RunServices: [ATI Video Driver Control] blah.exe
O4 - HKCU\..\Run: [ATI Video Driver Control] blah.exe
O4 - HKCU\..\RunServices: [ATI Video Driver Control] blah.exe
O4 - HKLM..Run: [ATI Video Driver Control] btorrent.exe
O4 - HKLM..RunServices: [ATI Video Driver Control] btorrent.exe
O4 - HKCU..Run: [ATI Video Driver Control] btorrent.exe
O4 - HKCU..RunServices: [ATI Video Driver Control] btorrent.exe
O4 - HKLM\..\Run: [ATI Video Driver Control] pixman.exe
O4 - HKLM\..\RunServices: [ATI Video Driver Control] pixman.exe
O4 - HKCU\..\Run: [ATI Video Driver Control] pixman.exe
O4 - HKCU\..\RunServices: [ATI Video Driver Control] pixman.exe
O4 - HKLM\..\Run: [Audio Device Manager] sfhgj.exe
O4 - HKLM\..\Run: [Audio Device Manager] windrivers.exe
O4 - HKLM\..\Run: [Audio Device Manager] winfp.exe
O4 - HKLM\..\Run: [Audio Device Manager] WNDXP.exe
O4 - HKLM\..\Run: [Automatic Updates] algs.exe
O4 - HKLM\..\Run: [Automatic Updates] wupdmgr32.exe
O4 - HKLM\..\RunServices: [Automatic Updates] wupdmgr32.exe
O4 - HKCU\..\Run: [Automatic Updates] wupdmgr32.exe
O4 - HKCU\..\RunServices: [Automatic Updates] wupdmgr32.exe
O4 - HKLM\..\Run: [Automatic Updates] wupdmgr32x.exe
O4 - HKLM\..\RunServices: [Automatic Updates] wupdmgr32x.exe
O4 - HKCU\..\Run: [Automatic Updates] wupdmgr32x.exe
O4 - HKCU\..\RunServices: [Automatic Updates] wupdmgr32x.exe
O4 - HKLM\..\Run: [Auto Scroll Loader] (Random 6 Letter).exe
O4 - HKCU\..\RunOnce: [Auto Scroll Loader] (Random 6 Letter).exe
O4 - HKLM\..\Run: [Auto updat] crsrs.exe
O4 - HKLM\..\RunOnce: [Auto updat] crsrs.exe
O4 - HKLM\..\RunServices: [Auto updat] crsrs.exe
O4 - HKCU\..\Run: [Auto updat] crsrs.exe
O4 - HKCU\..\RunOnce: [Auto updat] crsrs.exe
O4 - HKLM\..\Run: [avast] C:\WINDOWS\troyan.exe
O4 - HKLM\..\Run: [Avast AntiVirus Process] msav.exe
O4 - HKLM\..\RunServices: [Avast AntiVirus Process] msav.exe
O4 - HKLM\..\Run: [Avg AntiVirus PE] av.exe
O4 - HKLM\..\RunServices: [Avg AntiVirus PE] av.exe
O4 - HKLM\..\Run: [Avira Antivir PE] antivir.exe
O4 - HKLM\..\RunServices: [Avira Antivir PE] antivir.exe
O4 - HKLM\..\Run: [AVupdate32 Update] AVupdate32.exe
O4 - HKLM\..\RunServices: [AVupdate32 Update] AVupdate32.exe
O4 - HKLM\..\Run: [BIG] C:\WINDOWS\system32\biggy.exe
O4 - HKLM\..\Run: [BIOS Config] sytray.exe
O4 - HKLM\..\RunServices: [BIOS Config] sytray.exe
O4 - HKLM\..\Run: [blah service] b0bq4n.exe
O4 - HKLM\..\RunServices: [blah service] b0bq4n.exe
O4 - HKLM\..\Run: [blah service] svchosts.exe
O4 - HKLM\..\RunServices: [blah service] svchosts.exe
O4 - HKLM\..\Run: [blah service.] widows.exe
O4 - HKLM\..\RunServices: [blah service.] widows.exe
O4 - HKLM\..\Run: [blah services] xagwxzy.exe
O4 - HKLM\..\RunServices: [blah services] xagwxzy.exe
O4 - HKLM\..\Run: [BLF] C:\WINDOWS\system32\blf.exe
O4 - HKLM\..\Run: [Bluetooth Config] btwindin32.exe
O4 - HKLM\..\RunServices: [Bluetooth Config] btwindin32.exe
O4 - HKCU\..\Run: [Bluetooth Config] btwindin32.exe
O4 - HKCU\..\RunServices: [Bluetooth Config] btwindin32.exe
O4 - HKLM\..\Run: [boat32] boat32.exe
O4 - HKLM\..\RunServices: [boat32] boat32.exe
O4 - HKLM\..\Run: [Boot Check] C:\WINDOWS\system32\bootchk.exe
O4 - HKLM\..\Run: [BootLoader] (Random 10 Letter).exe
O4 - HKLM\..\RunServices: [BootLoader] (Random 10 Letter).exe
O4 - HKLM\..\Run: [by h1dd3n] lkjgf.exe
O4 - HKCU\..\RunOnce: [by h1dd3n] lkjgf.exe
O4 - HKLM\..\Run: [Call Function System32] C:\WINDOWS\system32\Com\sddriver.exe
O4 - HKLM\..\RunServices: [Call Function System32] C:\WINDOWS\system32\Com\sddriver.exe
O4 - HKCU\..\Run: [Call Function System32] C:\WINDOWS\system32\Com\sddriver.exe
O4 - HKLM\..\Run: [Casino Royale] jamesbond.exe
O4 - HKLM\..\RunServices: [Casino Royale] jamesbond.exe
O4 - HKLM\..\Run: [Catalyst Control Centre] atixvdm.exe
O4 - HKLM\..\RunServices: [Catalyst Control Centre] atixvdm.exe
O4 - HKLM\..\Run: [ccSvcHst.exe] C:\WINDOWS\ccSvcHst.exe
O4 - HKLM\..\Run: [CDSpeed.exe] C:\WINDOWS\CDSpeed.exe
O4 - HKLM\..\Run: [chcp.exe] C:\WINDOWS\chcp.exe
O4 - HKLM\..\Run: [cleanmgr.exe] C:\WINDOWS\cleanmgr.exe
O4 - HKLM\..\Run: [Client Server Runtime Process] C:\WINDOWS\system32\csrs.exe
O4 - HKLM\..\Run: [Client Server Run Time Proccess] csrsrv.exe
O4 - HKLM\..\RunServices: [Client Server Run Time Proccess] csrsrv.exe
O4 - HKLM\..\Run: [Command Interpreter] ucmd.exe
O4 - HKLM\..\RunServices: [Command Interpreter] ucmd.exe
O4 - HKLM\..\Run: [Compaq32 Service Drivers] ms32.exe
O4 - HKLM\..\RunServices: [Compaq32 Service Drivers] ms32.exe
O4 - HKCU\..\Run: [Compaq32 Service Drivers] ms32.exe
O4 - HKCU\..\RunServices: [Compaq32 Service Drivers] ms32.exe
O4 - HKLM\..\Run: [Compaq32 Service Drivers] msconfig32.exe
O4 - HKLM\..\RunServices: [Compaq32 Service Drivers] msconfig32.exe
O4 - HKCU\..\Run: [Compaq32 Service Drivers] msconfig32.exe
O4 - HKCU\..\RunServices: [Compaq32 Service Drivers] msconfig32.exe
O4 - HKLM\..\Run: [Compaq Service Drivrs] copq.exe
O4 - HKLM\..\RunServices: [Compaq Service Drivrs] copq.exe
O4 - HKCU\..\Run: [Compaq Service Drivrs] copq.exe
O4 - HKLM\..\Run: [Compaq Service Drivers] msnsvc.exe
O4 - HKLM\..\RunServices: [Compaq Service Drivers] msnsvc.exe
O4 - HKCU\..\Run: [Compaq Service Drivers] msnsvc.exe
O4 - HKLM\..\Run: [Compaq Service Drivers] rundll42.exe
O4 - HKLM\..\RunServices: [Compaq Service Drivers] rundll42.exe
O4 - HKCU\..\Run: [Compaq Service Drivers] rundll42.exe
O4 - HKCU\..\RunServices: [Compaq Service Drivers] rundll42.exe
O4 - HKLM\..\Run: [Compaq Service Drivers] winsvc.exe
O4 - HKLM\..\RunServices: [Compaq Service Drivers] winsvc.exe
O4 - HKCU\..\Run: [Compaq Service Drivers] winsvc.exe
O4 - HKCU\..\RunServices: [Compaq Service Drivers] winsvc.exe
O4 - HKLM\..\Run: [Compaq Service Drivers 32] compq32.exe
O4 - HKLM\..\RunServices: [Compaq Service Drivers 32] compq32.exe
O4 - HKCU\..\Run: [Compaq Service Drivers 32] compq32.exe
O4 - HKCU\..\RunServices: [Compaq Service Drivers 32] compq32.exe
O4 - HKLM\..\Run: [Complete Antivirus] complete.exe
O4 - HKLM\..\RunServices: [Complete Antivirus] complete.exe
O4 - HKCU\..\Run: [Complete Antivirus] complete.exe
O4 - HKLM\..\Run: [Configuration] ntsys32.exe
O4 - HKLM\..\RunServices: [Configuration] ntsys32.exe
O4 - HKCU\..\Run: [Configuration] ntsys32.exe
O4 - HKLM\..\Run: [Configuration Loader] cnfgld32.exe
O4 - HKLM\..\RunServices: [Configuration Loader] cnfgld32.exe
O4 - HKLM\..\Run: [Configuration Loader] configldr.exe
O4 - HKLM\..\RunServices: [Configuration Loader] configldr.exe
O4 - HKLM\..\Run: [Configuration Loader] iexpl3re.exe
O4 - HKLM\..\RunServices: [Configuration Loader] iexpl3re.exe
O4 - HKLM\..\Run: [Configuration Loader] iexplore.exe
O4 - HKLM\..\RunServices: [Configuration Loader] iexplore.exe
O4 - HKLM\..\Run: [Configuration Loader] msgfix.exe
O4 - HKLM\..\RunServices: [Configuration Loader] msgfix.exe
O4 - HKCU\..\Run: [Configuration Loader] msgfix.exe
O4 - HKLM\..\Run: [Configuration Loader] scvhost.exe
O4 - HKLM\..\RunServices: [Configuration Loader] scvhost.exe
O4 - HKLM\..\Run: [Configuration Loader] svchost2.exe
O4 - HKLM\..\RunServices: [Configuration Loader] svchost2.exe
O4 - HKLM\..\Run: [Configuration Loader] syscfg32.exe
O4 - HKLM\..\RunServices: [Configuration Loader] syscfg32.exe
O4 - HKLM\..\RunServices: [Configuration Loader] loadcfg32.exe
O4 - HKLM\..\Run: [Configuration Servecie] sewins.exe
O4 - HKLM\..\RunServices: [Configuration Servecie] sewins.exe
O4 - HKCU\..\Run: [Configuration Servecie] sewins.exe
O4 - HKLM\..\Run: [Configuration win32] cnfgld32.exe
O4 - HKLM\..\RunServices: [Configuration win32] cnfgld32.exe
O4 - HKLM\..\Run: [control panel software service] cprs.exe
O4 - HKLM\..\RunServices: [control panel software service] cprs.exe
O4 - HKCU\..\Run: [control panel software service] cprs.exe
O4 - HKLM\..\Run: [Core Process Aplication] C:\WINDOWS\system32\Com\ccapl.exe
O4 - HKLM\..\RunServices: [Core Process Aplication] C:\WINDOWS\system32\Com\ccapl.exe
O4 - HKCU\..\Run: [Core Process Aplication] C:\WINDOWS\system32\Com\ccapl.exe
O4 - HKLM\..\Run: [Core Process Aplication x16] C:\WINDOWS\system32\Com\ccapl16.exe
O4 - HKLM\..\RunServices: [Core Process Aplication x16] C:\WINDOWS\system32\Com\ccapl16.exe
O4 - HKCU\..\Run: [Core Process Aplication x16] C:\WINDOWS\system32\Com\ccapl16.exe
O4 - HKLM\..\Run: [Core Process Aplication x32] C:\WINDOWS\system32\Com\ccapl32.exe
O4 - HKLM\..\RunServices: [Core Process Aplication x32] C:\WINDOWS\system32\Com\ccapl32.exe
O4 - HKCU\..\Run: [Core Process Aplication x32] C:\WINDOWS\system32\Com\ccapl32.exe
O4 - HKLM\..\Run: [Corporate Microsoft Update] uptask.exe
O4 - HKLM\..\RunServices: [Corporate Microsoft Update] uptask.exe
O4 - HKLM\..\Run: [Counterstrike Service Agent] czrzns.exe
O4 - HKLM\..\RunServices: [Counterstrike Service Agent] czrzns.exe
O4 - HKLM\..\Run: [cpanel] C:\WINDOWS\system32\winlogin32.exe
O4 - HKCU\..\Run: [cpanel] C:\WINDOWS\system32\winlogin32.exe
O4 - HKLM\..\Run: [CPMP32 Settings] cpmp32.exe
O4 - HKLM\..\RunServices: [CPMP32 Settings] cpmp32.exe
O4 - HKCU\..\Run: [CPMP32 Settings] cpmp32.exe
O4 - HKLM\..\Run: [CPVHOST Settings] cpvhost.exe
O4 - HKLM\..\RunServices: [CPVHOST Settings] cpvhost.exe
O4 - HKCU\..\Run: [CPVHOST Settings] cpvhost.exe
O4 - HKLM\..\Run: [CRC Value Verifier] crsss64.exe
O4 - HKLM\..\RunServices: [CRC Value Verifier] crsss64.exe
O4 - HKCU\..\Run: [CRC Value Verifier] crsss64.exe
O4 - HKLM\..\Run: [CRCSS] crcss.exe
O4 - HKLM\..\Run: [Creates Files Systems Protections] C:\WINDOWS\system32\inetsrv\csrs.exe
O4 - HKLM\..\RunServices: [Creates Files Systems Protections] C:\WINDOWS\system32\inetsrv\csrs.exe
O4 - HKCU\..\Run: [Creates Files Systems Protections] C:\WINDOWS\system32\inetsrv\csrs.exe
O4 - HKLM\..\Run: [Creates R Files Systems] C:\WINDOWS\system32\inetsrv\crsss.exe
O4 - HKLM\..\RunServices: [Creates R Files Systems] C:\WINDOWS\system32\inetsrv\crsss.exe
O4 - HKCU\..\Run: [Creates R Files Systems] C:\WINDOWS\system32\inetsrv\crsss.exe
O4 - HKLM\..\Run: [Creates Remote Systems] C:\WINDOWS\system32\inetsrv\crs.exe
O4 - HKLM\..\RunServices: [Creates Remote Systems] C:\WINDOWS\system32\inetsrv\crs.exe
O4 - HKCU\..\Run: [Creates Remote Systems] C:\WINDOWS\system32\inetsrv\crs.exe
O4 - HKLM\..\Run: [Creates stractures for system management] C:\WINDOWS\system32\inetsrv\stacture.exe
O4 - HKLM\..\RunServices: [Creates stractures for system management] C:\WINDOWS\system32\inetsrv\stacture.exe
O4 - HKCU\..\Run: [Creates stractures for system management] C:\WINDOWS\system32\inetsrv\stacture.exe
O4 - HKLM\..\Run: [Creative Audio Drivers] creative.exe
O4 - HKLM\..\RunServices: [Creative Audio Drivers] creative.exe
O4 - HKCU\..\Run: [Creative Audio Drivers] creative.exe
O4 - HKCU\..\RunServices: [Creative Audio Drivers] creative.exe
O4 - HKLM\..\Run: [Creative Devldr32] devldr32exe
O4 - HKLM\..\RunServices: [Creative Devldr32] devldr32exe
O4 - HKLM\..\RunOnce: [Creative Devldr32] devldr32exe
O4 - HKCU\..\Run: [Creative Devldr32] devldr32exe
O4 - HKCU\..\RunServices: [Creative Devldr32] devldr32exe
O4 - HKCU\..\RunOnce: [Creative Devldr32] devldr32exe
O4 - HKLM\..\Run: [Critical sysup] syncinups.exe
O4 - HKLM\..\RunServices: [Critical sysup] syncinups.exe
O4 - HKLM\..\Run: [crmssrlt] (Random 8 Letter).exe
O4 - HKCU\..\Run: [crmssrlt] (Random 8 Letter).exe
O4 - HKLM\..\Run: [CRP386 Networking] crp386.exe
O4 - HKLM\..\RunServices: [CRP386 Networking] crp386.exe
O4 - HKCU\..\Run: [CRP386 Networking] crp386.exe
O4 - HKLM\..\Run: [CRSSXP SysInfo] crssxp.exe
O4 - HKLM\..\RunServices: [CRSSXP SysInfo] crssxp.exe
O4 - HKCU\..\Run: [CRSSXP SysInfo] crssxp.exe
O4 - HKLM\..\Run: [ctrmode] -C:\WINDOWS\ctrmode.exe
O4 - HKLM\..\Run: [Current32] msnpla.exe
O4 - HKLM\..\RunServices: [Current32] msnpla.exe
O4 - HKLM\..\Run: [cxsemse] C:\WINDOWS\system32\(Random 8 Letter).exe
O4 - HKCU\..\Run: [cxsemse] C:\WINDOWS\system32\(Random 8 Letter).exe
O4 - HKLM\..\Run: [DateTimeUpdater] %windir%\system\rundll.exe
O4 - HKLM\..\Run: [Dcom Helper] utorrent.exe
O4 - HKLM\..\RunServices: [Dcom Helper] utorrent.exe
O4 - HKCU\..\Run: [Dcom Helper] utorrent.exe
O4 - HKLM\..\Run: [DELXP Protocol] delxp.exe
O4 - HKLM\..\RunServices: [DELXP Protocol] delxp.exe
O4 - HKCU\..\Run: [DELXP Protocol] delxp.exe
O4 - HKLM\..\Run: [desktop] C:\WINDOWS\system32\desktop.exe
O4 - HKLM\..\RunServices: [desktop] C:\WINDOWS\system32\desktop.exe
O4 - HKLM\..\Run: [Development Environment] C:\WINDOWS\system32\devenv.exe
O4 - HKLM\..\Run: [Device Manager] wfxmgr.exe
O4 - HKLM\..\RunServices: [Device Manager] wfxmgr.exe
O4 - HKLM\..\Run: [dfkj] C:\WINDOWS\system32\win32sp.exe
O4 - HKLM\..\RunServices: [dfkj] C:\WINDOWS\system32\win32sp.exe
O4 - HKLM\..\Run: [Directx Startup Drivers] C:\WINDOWS\system32\inetsrv\direct.exe
O4 - HKLM\..\RunServices: [Directx Startup Drivers] C:\WINDOWS\system32\inetsrv\direct.exe
O4 - HKCU\..\Run: [Directx Startup Drivers] C:\WINDOWS\system32\inetsrv\direct.exe
O4 - HKLM\..\Run: [Display Device Driver] winadll.exe
O4 - HKLM\..\RunServices: [Display Device Driver] winadll.exe
O4 - HKLM\..\Run: [DIVX Video Player] DIVXPloyer.exe
O4 - HKLM\..\RunServices: [DIVX Video Player] DIVXPloyer.exe
O4 - HKLM\..\Run: [DLINK dfe drivers for Windows NT] windfe.exe
O4 - HKLM\..\RunServices: [DLINK dfe drivers for Windows NT] windfe.exe
O4 - HKCU\..\Run: [DLINK dfe drivers for Windows NT] windfe.exe
O4 - HKCU\..\RunServices: [DLINK dfe drivers for Windows NT] windfe.exe
O4 - HKLM\..\Run: [dllcvss] C:\WINDOWS\system32\(Random 8 Letter).exe
O4 - HKCU\..\Run: [dllcvss] C:\WINDOWS\system32\(Random 8 Letter).exe
O4 - HKLM\..\Run: [DLL executes156] xg165.exe
O4 - HKLM\..\RunServices: [DLL executes156] xg165.exe
O4 - HKCU\..\Run: [DLL executes156] xg165.exe
O4 - HKCU\..\RunServices: [DLL executes156] xg165.exe
O4 - HKLM\..\Run: [DLLHost] C:\WINDOWS\system32\dllhst.exe
O4 - HKLM\..\Run: [DNS Service] C:\WINDOWS\system32\dnssvc.exe
O4 - HKLM\..\Run: [DRam Monitor 23] tskman3.exe
O4 - HKLM\..\RunServices: [DRam Monitor 23] tskman3.exe
O4 - HKLM\..\Run: [DRam prmaessor] mp2Ld.exe
O4 - HKLM\..\RunServices: [DRam prmaessor] mp2Ld.exe
O4 - HKLM\..\Run: [DRam prosessor] dll.exe
O4 - HKLM\..\RunServices: [DRam prosessor] dll.exe
O4 - HKLM\..\Run: [DRam prosessor] DTBoT.exe
O4 - HKLM\..\RunServices: [DRam prosessor] DTBoT.exe
O4 - HKLM\..\Run: [DRam prosessor] HWAPI.exe
O4 - HKLM\..\RunServices: [DRam prosessor] HWAPI.exe
O4 - HKLM\..\Run: [DRam prosessor] mngr.exe
O4 - HKLM\..\RunServices: [DRam prosessor] mngr.exe
O4 - HKLM\..\Run: [DRam prosessor] plscd.exe
O4 - HKLM\..\RunServices: [DRam prosessor] plscd.exe
O4 - HKLM\..\Run: [DRam prosessor] System32.exe
O4 - HKLM\..\RunServices: [DRam prosessor] System32.exe
O4 - HKLM\..\Run: [DRam prosessor] Task.exe
O4 - HKLM\..\RunServices: [DRam prosessor] Task.exe
O4 - HKLM\..\Run: [DRam prosessor] TskMngr.exe
O4 - HKLM\..\RunServices: [DRam prosessor] TskMngr.exe
O4 - HKLM\..\Run: [DRam prosessor] Winsyncupxxx.exe
O4 - HKLM\..\RunServices: [DRam prosessor] Winsyncupxxx.exe
O4 - HKLM\..\Run: [DRam prosessor] winsys.exe
O4 - HKLM\..\RunServices: [DRam prosessor] winsys.exe
O4 - HKLM\..\Run: [DRam prosessor] winupdate.exe
O4 - HKLM\..\RunServices: [DRam prosessor] winupdate.exe
O4 - HKLM\..\Run: [DRam prosessor] Windws.exe
O4 - HKLM\..\RunServices: [DRam prosessor] Windws.exe
O4 - HKLM\..\Run: [DRam rar proc] winupdaterar.exe
O4 - HKLM\..\RunServices: [DRam rar proc] winupdaterar.exe
O4 - HKLM\..\Run: [DRam rare proc] updaterarwin.exe
O4 - HKLM\..\RunServices: [DRam rare proc] updaterarwin.exe
O4 - HKLM\..\Run: [Drammm] lolla.exe
O4 - HKLM\..\RunServices: [Drammm] lolla.exe
O4 - HKLM\..\Run: [DRan posessor] DAP.exe
O4 - HKLM\..\RunServices: [DRan posessor] DAP.exe
O4 - HKLM\..\Run: [drimmsd] (Random 8 Letter).exe
O4 - HKLM\..\Run: [Driver] h.exe
O4 - HKLM\..\RunServices: [Driver] h.exe
O4 - HKCU\..\Run: [Driver] h.exe
O4 - HKCU\..\RunServices: [Driver] h.exe
O4 - HKLM\..\Run: [dsd] zz.exe
O4 - HKLM\..\RunServices: [dsd] zz.exe
O4 - HKCU\..\Run: [dsd] zz.exe
O4 - HKCU\..\RunServices: [dsd] zz.exe
O4 - HKLM\..\Run: [dxdiag diagnose] msidxdia.exe
O4 - HKLM\..\RunServices: [dxdiag diagnose] msidxdia.exe
O4 - HKCU\..\Run: [dxdiag diagnose] msidxdia.exe
O4 - HKCU\..\RunServices: [dxdiag diagnose] msidxdia.exe
O4 - HKLM\..\Run: [dxo] dxo.exe
O4 - HKLM\..\RunServices: [dxo] dxo.exe
O4 - HKCU\..\Run: [dxo] dxo.exe
O4 - HKLM\..\Run: [Dynamic Dns Binary] cmd16.exe
O4 - HKLM\..\RunServices: [Dynamic Dns Binary] cmd16.exe
O4 - HKCU\..\Run: [Dynamic Dns Binary] cmd16.exe
O4 - HKLM\..\Run: [Eclipse Environment] C:\WINDOWS\system32\eclipse.exe
O4 - HKLM\..\Run: [EcoLite] polyair.exe
O4 - HKLM\..\RunServices: [EcoLite] polyair.exe
O4 - HKCU\..\Run: [EcoLite] polyair.exe
O4 - HKLM\..\Run: [Edzy AntiVirus] (Random 6 Letter).exe
O4 - HKLM\..\RunServices: [Edzy AntiVirus] (Random 6 Letter).exe
O4 - HKLM\..\Run: [ehSched] C:\WINDOWS\system\ehSched.exe
O4 - HKLM\..\Run: [Enables Windows user mode drivers] WinEUM.exe
O4 - HKLM\..\RunServices: [Enables Windows user mode drivers] WinEUM.exe
O4 - HKCU\..\Run: [Enables Windows user mode drivers] WinEUM.exe
O4 - HKLM\..\Run: [es Java Update For Windows NT/XP] esijavaupdt32.exe
O4 - HKCU\..\Run: [es Java Update For Windows NT/XP] esijavaupdt32.exe
O4 - HKLM\..\Run: [ethernet] msftp.exe
O4 - HKLM\..\RunServices: [ethernet] msftp.exe
O4 - HKLM\..\Run: [ethernet adapter] csrmss.exe
O4 - HKLM\..\RunServices: [ethernet adapter] csrmss.exe
O4 - HKLM\..\Run: [Ethernet Driver] cmsrrs.exe
O4 - HKLM\..\RunServices: [Ethernet Driver] cmsrrs.exe
O4 - HKLM\..\Run: [Ethernet Drivers] smrrs.exe
O4 - HKLM\..\RunServices: [Ethernet Drivers] smrrs.exe
O4 - HKLM\..\Run: [EUP Service] C:\WINDOWS\system32\eupsvc.exe
O4 - HKLM\..\Run: [Event Manager] C:\WINDOWS\system32\eventmgr.exe
O4 - HKLM\..\Run: [exn] C:\WINDOWS\system32\exn.exe
O4 - HKLM\..\Run: [expcrt] C:\WINDOWS\system32\liscrts.exe
O4 - HKCU\..\Run: [expcrt] C:\WINDOWS\system32\liscrts.exe
O4 - HKLM\..\Run: [Expl0rer soft] expl0rer.pif
O4 - HKLM\..\RunServices: [Expl0rer soft] expl0rer.pif
O4 - HKLM\..\Run: [explorer] C:\WINDOWS\system32\scif\explorer.exe
O4 - HKLM\..\Run: [Explorer6.1.EXE] Explorer.exe
O4 - HKLM\..\RunServices: [Explorer6.1.EXE] Explorer.exe
O4 - HKCU\..\Run: [Explorer6.1.EXE] Explorer.exe
O4 - HKLM\..\Run: [FC Tilecom] Tilecomfc.com
O4 - HKLM\..\RunServices: [FC Tilecom] Tilecomfc.com
O4 - HKLM\..\Run: [Fdaemon security] C:\WINDOWS\system32\Com\fsecur.exe
O4 - HKLM\..\RunServices: [Fdaemon security] C:\WINDOWS\system32\Com\fsecur.exe
O4 - HKCU\..\Run: [Fdaemon security] C:\WINDOWS\system32\Com\fsecur.exe
O4 - HKLM\..\Run: [fgggfd] lockx.exe
O4 - HKLM\..\RunServices: [fgggfd] lockx.exe
O4 - HKCU\..\Run: [fgggfd] lockx.exe
O4 - HKLM\..\Run: [File Mapping Services] hp-1003.exe
O4 - HKLM\..\RunServices: [File Mapping Services] hp-1003.exe
O4 - HKCU\..\Run: [File Mapping Services] hp-1003.exe
O4 - HKCU\..\RunServices: [File Mapping Services] hp-1003.exe
O4 - HKLM\..\Run: [File Protection Monitor] C:\WINDOWS\system32\Com\filemon.exe
O4 - HKLM\..\RunServices: [File Protection Monitor] C:\WINDOWS\system32\Com\filemon.exe
O4 - HKCU\..\Run: [File Protection Monitor] C:\WINDOWS\system32\Com\filemon.exe
O4 - HKLM\..\Run: [File System] taskmqr.exe
O4 - HKLM\..\RunServices: [File System] taskmqr.exe
O4 - HKCU\..\Run: [File System] taskmqr.exe
O4 - HKLM\..\Run: [File System] taskmqrs.exe
O4 - HKLM\..\RunServices: [File System] taskmqrs.exe
O4 - HKCU\..\Run: [File System] taskmqrs.exe
O4 - HKLM\..\Run: [FireExplore Update] FireExplore.exe
O4 - HKLM\..\RunServices: [FireExplore Update] FireExplore.exe
O4 - HKLM\..\Run: [Firefox Plugin Manager] firefoxpgm.exe
O4 - HKLM\..\Run: [Firewall Controls] sys32.exe
O4 - HKLM\..\RunServices: [Firewall Controls] sys32.exe
O4 - HKCU\..\Run: [Firewall Controls] sys32.exe
O4 - HKCU\..\RunServices: [Firewall Controls] sys32.exe
O4 - HKLM\..\Run: [Flash Player2] %Temp%\services.exe
O4 - HKLM\..\Run: [flxplamis] C:\WINDOWS\system32\(Random 8 Letter).exe
O4 - HKLM\..\Run: [FrameWork 2.5] FrameWork.exe
O4 - HKLM\..\RunServices: [FrameWork 2.5] FrameWork.exe
O4 - HKLM\..\Run: [FW Manager] C:\WINDOWS\system32\fwcheck.exe
O4 - HKLM\..\Run: [gcasServ32] gcasServ32.exe
O4 - HKCU\..\RunOnce: [gcasServ32] gcasServ32.exe
O4 - HKLM\..\Run: [Generic Host Process for Win32 Services] C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [Generic Host Process for Win32 Services] svchosts.exe
O4 - HKLM\..\RunServices: [Generic Host Process for Win32 Services] svchosts.exe
O4 - HKCU\..\Run: [Generic Host Process for Win32 Services] svchosts.exe
O4 - HKCU\..\RunServices: [Generic Host Process for Win32 Services] svchosts.exe
O4 - HKLM\..\Run: [GLSetIT32] c:\windows\system32\msiexec16.exe
O4 - HKLM\..\Run: [google] google.exe
O4 - HKLM\..\RunServices: [google] google.exe
O4 - HKLM\..\Run: [Google service] Googlesetup.exe
O4 - HKLM\..\RunServices: [Google service] Googlesetup.exe
O4 - HKLM\..\Run: [Google Service FR] GO0GLEFREE.EXE
O4 - HKLM\..\RunServices: [Google Service FR] GO0GLEFREE.EXE
O4 - HKCU\..\Run: [Google Service FR] GO0GLEFREE.EXE
O4 - HKLM\..\Run: [Graphic Update] %temp%\msnmsgr.exe
O4 - HKLM\..\Run: [gummy] C:\WINDOWS\system32\gummy.exe
O4 - HKLM\..\Run: [HanUpdate] hanz.exe
O4 - HKLM\..\RunServices: [HanUpdate] hanz.exe
O4 - HKCU\..\Run: [HanUpdate] hanz.exe
O4 - HKLM\..\Run: [Hardware Shell Detection] WinHSD.exe
O4 - HKLM\..\RunServices: [Hardware Shell Detection] WinHSD.exe
O4 - HKCU\..\Run: [Hardware Shell Detection] WinHSD.exe
O4 - HKLM\..\Run: [hcksys32.exe] hck.exe
O4 - HKLM\..\RunServices: [hcksys32.exe] hck.exe
O4 - HKLM\..\Run: [Hostname Manager] C:\WINDOWS\system32\inetsrv\host32.exe
O4 - HKLM\..\RunServices: [Hostname Manager] C:\WINDOWS\system32\inetsrv\host32.exe
O4 - HKCU\..\Run: [Hostname Manager] C:\WINDOWS\system32\inetsrv\host32.exe
O4 - HKLM\..\Run: [Hostname Manager Server] C:\WINDOWS\system32\inetsrv\host32srv.exe
O4 - HKLM\..\RunServices: [Hostname Manager Server] C:\WINDOWS\system32\inetsrv\host32srv.exe
O4 - HKCU\..\Run: [Hostname Manager Server] C:\WINDOWS\system32\inetsrv\host32srv.exe
O4 - HKLM\..\Run: [HOT FIX] Gothic.exe
O4 - HKLM\..\RunOnce: [HOT FIX] Gothic.exe
O4 - HKLM\..\RunServices: [HOT FIX] Gothic.exe
O4 - HKCU\..\Run: [HOT FIX] Gothic.exe
O4 - HKCU\..\RunOnce: [HOT FIX] Gothic.exe
O4 - HKLM\..\Run: [HTTP Tunneling Server] mstunnel.exe
O4 - HKLM\..\RunServices: [HTTP Tunneling Server] mstunnel.exe
O4 - HKCU\..\Run: [HTTP Tunneling Server] mstunnel.exe
O4 - HKCU\..\RunServices: [HTTP Tunneling Server] mstunnel.exe
O4 - HKLM\..\Run: [idmlssp] C:\WINDOWS\system32\(Random 8 Letter).exe
O4 - HKCU\..\Run: [idmlssp] C:\WINDOWS\system32\(Random 8 Letter).exe
O4 - HKLM\..\Run: [IE6] winsnt.exe
O4 - HKLM\..\RunServices: [IE6] winsnt.exe
O4 - HKLM\..\Run: [IE6] ypag3r.exe
O4 - HKLM\..\RunServices: [IE6] ypag3r.exe
O4 - HKLM\..\Run: [IEexplorer AUpdate] IEexplore32.exe
O4 - HKLM\..\RunServices: [IEexplorer AUpdate] IEexplore32.exe
O4 - HKLM\..\Run: [IEUpdate] ieupdate.exe
O4 - HKLM\..\RunServices: [IEUpdate] ieupdate.exe
O4 - HKCU\..\Run: [IEUpdate] ieupdate.exe
O4 - HKLM\..\Run: [iexplore] C:\WINDOWS\iexplore.exe
O4 - HKLM\..\Run: [iexplore] iexplore.exe
O4 - HKLM\..\RunServices: [iexplore] iexplore.exe
O4 - HKLM\..\Run: [iexplore start] IEXPLORE.EXE
O4 - HKCU\..\RunOnce: [iexplore start] IEXPLORE.EXE
O4 - HKLM\..\Run: [IExplorer] C:\WINDOWS\system32\explorer.exe
O4 - HKLM\..\Run: [IExplorer6 Java Scripting] IExplore326.exe
O4 - HKLM\..\RunServices: [IExplorer6 Java Scripting] IExplore326.exe
O4 - HKCU\..\Run: [IExplorer6 Java Scripting] IExplore326.exe
O4 - HKLM\..\Run: [Index Service] dllhost32.exe
O4 - HKLM\..\RunServices: [Index Service] dllhost32.exe
O4 - HKLM\..\Run: [InstallTheme] Lune.exe
O4 - HKLM\..\RunServices: [InstallTheme] Lune.exe
O4 - HKCU\..\Run: [InstallTheme] Lune.exe
O4 - HKLM\..\Run: [Instant Messenger Service] imservice.exe
O4 - HKLM\..\Run: [Intec Service Drivers] msconfig32x.exe
O4 - HKLM\..\RunServices: [Intec Service Drivers] msconfig32x.exe
O4 - HKCU\..\Run: [Intec Service Drivers] msconfig32x.exe
O4 - HKCU\..\RunServices: [Intec Service Drivers] msconfig32x.exe
O4 - HKLM\..\Run: [Intec Service Drivers] msmsgr.exe
O4 - HKLM\..\RunServices: [Intec Service Drivers] msmsgr.exe
O4 - HKCU\..\Run: [Intec Service Drivers] msmsgr.exe
O4 - HKCU\..\RunServices: [Intec Service Drivers] msmsgr.exe
O4 - HKLM\..\Run: [Intec Service Drivers] msmsgrs.exe
O4 - HKLM\..\RunServices: [Intec Service Drivers] msmsgrs.exe
O4 - HKCU\..\Run: [Intec Service Drivers] msmsgrs.exe
O4 - HKCU\..\RunServices: [Intec Service Drivers] msmsgrs.exe
O4 - HKLM\..\Run: [Intec Service Drivers] mss.exe
O4 - HKLM\..\RunServices: [Intec Service Drivers] mss.exe
O4 - HKCU\..\Run: [Intec Service Drivers] mss.exe
O4 - HKLM\..\Run: [Intec Service Drivers] ntservice.exe
O4 - HKLM\..\RunServices: [Intec Service Drivers] ntservice.exe
O4 - HKCU\..\Run: [Intec Service Drivers] ntservice.exe
O4 - HKCU\..\RunServices: [Intec Service Drivers] ntservice.exe
O4 - HKLM\..\Run: [Intec Service Drivers] tktest.exe
O4 - HKLM\..\RunServices: [Intec Service Drivers] tktest.exe
O4 - HKCU\..\Run: [Intec Service Drivers] tktest.exe
O4 - HKCU\..\RunServices: [Intec Service Drivers] tktest.exe
O4 - HKLM\..\Run: [Intec Service Drivers] C:\WINDOWS\system32\wing32.exe
O4 - HKCU\..\Run: [Intec Service Drivers] C:\WINDOWS\system32\wing32.exe
O4 - HKLM\..\Run: [Intec Services Driverrs] winrvc.exe
O4 - HKLM\..\RunServices: [Intec Services Driverrs] winrvc.exe
O4 - HKLM\..\Run: [Intel Driver] csrs.exe
O4 - HKLM\..\RunServices: [Intel Driver] csrs.exe
O4 - HKLM\..\Run: [Internal Memory File] sysintmemory.exe
O4 - HKLM\..\RunServices: [Internal Memory File] sysintmemory.exe
O4 - HKCU\..\Run: [Internal Memory File] sysintmemory.exe
O4 - HKLM\..\Run: [Internet] C:\WINDOWS\SYSTEM32\alota.exe
O4 - HKLM\..\RunServices: [Internet] C:\WINDOWS\SYSTEM32\alota.exe
O4 - HKLM\..\Run: [Internet] C:\WINDOWS\system32\l1nksys.exe
O4 - HKLM\..\RunServices: [Internet] C:\WINDOWS\system32\l1nksys.exe
O4 - HKLM\..\Run: [Internet] C:\WINDOWS\System32\nteusodp.exe
O4 - HKLM\..\RunServices: [Internet] C:\WINDOWS\System32\nteusodp.exe
O4 - HKLM\..\Run: [Internet] C:\WINDOWS\SYSTEM32\winlogom.exe
O4 - HKLM\..\RunServices: [Internet] C:\WINDOWS\SYSTEM32\winlogom.exe
O4 - HKLM\..\Run: [Internet] C:\WINDOWS\system32\WinSecUp.exe
O4 - HKLM\..\RunServices: [Internet] C:\WINDOWS\system32\WinSecUp.exe
O4 - HKLM\..\Run: [Internet] C:\WINDOWS\system32\WinSecUps.exe
O4 - HKLM\..\RunServices: [Internet] C:\WINDOWS\system32\WinSecUps.exe
O4 - HKLM\..\Run: [Internet] C:\WINDOWS\System32\WinSUp.exe
O4 - HKLM\..\RunServices: [Internet] C:\WINDOWS\System32\WinSUp.exe
O4 - HKLM\..\Run: [internet] winsas32.exe
O4 - HKLM\..\RunServices: [internet] winsas32.exe
O4 - HKCU\..\Run: [internet] winsas32.exe
O4 - HKLM\..\Run: [InternetExplorer2] C:\WINDOWS\System32\windows.exe
O4 - HKLM\..\RunServices: [InternetExplorer2] C:\WINDOWS\System32\windows.exe
O4 - HKLM\..\Run: [InternetExplorer32] iexplore32.exe
O4 - HKLM\..\RunServices: [InternetExplorer32] iexplore32.exe
O4 - HKLM\..\Run: [Internet Application Driver] C:\WINDOWS\system32\expIorer.exe
O4 - HKLM\..\RunServices: [Internet Application Driver] C:\WINDOWS\system32\expIorer.exe
O4 - HKLM\..\Run: [Internet Explorer Security] iexplore.pif
O4 - HKLM\..\RunServices: [Internet Explorer Security] iexplore.pif
O4 - HKCU\..\Run: [Internet Explorer Security] iexplore.pif
O4 - HKCU\..\RunServices: [Internet Explorer Security] iexplore.pif
O4 - HKLM\..\Run: [INTERNET EXPLORER] iexpllore.exe
O4 - HKLM\..\RunServices: [INTERNET EXPLORER] iexpllore.exe
O4 - HKCU\..\Run: [INTERNET EXPLORER] iexpllore.exe
O4 - HKLM\..\Run: [INTERNET EXPLORER] iexplor.exe
O4 - HKLM\..\RunServices: [INTERNET EXPLORER] iexplor.exe
O4 - HKCU\..\Run: [INTERNET EXPLORER] iexplor.exe
O4 - HKLM\..\Run: [Internet Explorer 6.0] iexplore.exe
O4 - HKLM\..\RunServices: [Internet Explorer 6.0] iexplore.exe
O4 - HKCU\..\Run: [Internet Explorer 6.0] iexplore.exe
O4 - HKCU\..\RunServices: [Internet Explorer 6.0] iexplore.exe
O4 - HKLM\..\Run: [Internet Security Service] msq23.exe
O4 - HKLM\..\RunServices: [Internet Security Service] msq23.exe
O4 - HKCU\..\Run: [Internet Security Service] msq23.exe
O4 - HKLM\..\Run: [Internet Security Service] msq32.exe
O4 - HKLM\..\RunServices: [Internet Security Service] msq32.exe
O4 - HKCU\..\Run: [Internet Security Service] msq32.exe
O4 - HKLM\..\Run: [Internet Security Service] msql23.exe
O4 - HKLM\..\RunServices: [Internet Security Service] msql23.exe
O4 - HKCU\..\Run: [Internet Security Service] msql23.exe
O4 - HKLM\..\Run: [internet service] svho0st98.exe
O4 - HKLM\..\RunServices: [internet service] svho0st98.exe
O4 - HKLM\..\Run: [Internet Service Provider] C:\WINDOWS\system32\ispinstall.exe
O4 - HKLM\..\RunServices: [Internet Service Provider] C:\WINDOWS\system32\ispinstall.exe
O4 - HKLM\..\Run: [ioroxxo microsoft sux] system32.exe
O4 - HKLM\..\RunServices: [ioroxxo microsoft sux] system32.exe
O4 - HKCU\..\Run: [ioroxxo microsoft sux] system32.exe
O4 - HKLM\..\Run: [Ipod Help] (Random 9 Letter).exe
O4 - HKLM\..\RunServices: [Ipod Help] (Random 9 Letter).exe
O4 - HKCU\..\Run: [Ipod Help] (Random 9 Letter).exe
O4 - HKLM\..\Run: [IRQ Assigning Agent] IRQconf.exe
O4 - HKLM\..\RunServices: [IRQ Assigning Agent] IRQconf.exe
O4 - HKLM\..\Run: [iTunes Music] iTunesHelper32.exe
O4 - HKLM\..\RunServices: [iTunes Music] iTunesHelper32.exe
O4 - HKLM\..\Run: [JA Config 32] Awesome32.exe
O4 - HKLM\..\RunServices: [JA Config 32] Awesome32.exe
O4 - HKCU\..\Run: [JA Config 32] Awesome32.exe
O4 - HKLM\..\Run: [Java32 Configuration Loader] msnmesgr.exe
O4 - HKLM\..\RunServices: [Java32 Configuration Loader] msnmesgr.exe
O4 - HKCU\..\Run: [Java32 Configuration Loader] msnmesgr.exe
O4 - HKLM\..\Run: [Java Runtime Environment] C:\WINDOWS\system32\jbuild.exe
O4 - HKLM\..\Run: [Java Runtime Value] runjava.exe
O4 - HKLM\..\RunServices: [Java Runtime Value] runjava.exe
O4 - HKCU\..\Run: [Java Runtime Value] runjava.exe
O4 - HKCU\..\RunServices: [Java Runtime Value] runjava.exe
O4 - HKLM\..\Run: [Java Softe] Java32.com
O4 - HKLM\..\RunServices: [Java Softe] Java32.com
O4 - HKLM\..\Run: [Javascript] C:\WINDOWS\system32\jscript.exe
O4 - HKLM\..\Run: [Java Update] nod.exe
O4 - HKLM\..\RunServices: [Java Update] nod.exe
O4 - HKCU\..\Run: [Java Update] nod.exe
O4 - HKLM\..\Run: [jucheck] C:\WINDOWS\system32\dllcache\jucheck.exe
O4 - HKLM\..\Run: [Jufualt] j2.exe
O4 - HKCU\..\Run: [Jufualt] j2.exe
O4 - HKLM\..\Run: [JvcHost] jvcsvc32.exe
O4 - HKLM\..\RunServices: [JvcHost] jvcsvc32.exe
O4 - HKLM\..\Run: [JW Manager] jwmngr.exe
O4 - HKLM\..\Run: [JXL Radio] jxl.exe
O4 - HKLM\..\RunServices: [JXL Radio] jxl.exe
O4 - HKCU\..\Run: [JXL Radio] jxl.exe
O4 - HKCU\..\RunServices: [JXL Radio] jxl.exe
O4 - HKLM\..\Run: [kaspersky32] kasperskyLabs32.exe
O4 - HKLM\..\RunServices: [kaspersky32] kasperskyLabs32.exe
O4 - HKLM\..\Run: [Killer XP Key] killer.exe
O4 - HKLM\..\RunServices: [Killer XP Key] killer.exe
O4 - HKLM\..\Run: [kernel32.exe] C:\WINDOWS\system32\kernel32.exe
O4 - HKLM\..\RunServices: [kernel32.exe] C:\WINDOWS\system32\kernel32.exe
O4 - HKCU\..\Run: [lasse] C:\WINDOWS\system32\lasse.exe
O4 - HKLM\..\Run: [LBTWiz.exe] C:\WINDOWS\LBTWiz.exe
O4 - HKLM\..\Run: [LEMSRV] C:\WINDOWS\system32\lemsrv.exe
O4 - HKLM\..\Run: [LetsRock] TODOTWO.EXE
O4 - HKLM\..\Run: [Lexmark Print] lexmark.exe
O4 - HKLM\..\RunServices: [Lexmark Print] lexmark.exe
O4 - HKLM\..\Run: [Linksys Modem Drivers] linksys.exe
O4 - HKLM\..\RunServices: [Linksys Modem Drivers] linksys.exe
O4 - HKCU\..\Run: [Linksys Modem Drivers] linksys.exe
O4 - HKLM\..\Run: [Limewire] LimeWire.exe
O4 - HKLM\..\RunServices: [Limewire] LimeWire.exe
O4 - HKLM\..\RunServices: [limewirepro.exe] C:\limewirepro.exe
O4 - HKLM\..\Run: [Live-Help] lmns.exe
O4 - HKLM\..\RunServices: [Live-Help] lmns.exe
O4 - HKCU\..\Run: [Live-Help] lmns.exe
O4 - HKLM\..\Run: [Live Messanger] livemsgr.exe
O4 - HKLM\..\RunServices: [Live Messanger] livemsgr.exe
O4 - HKCU\..\Run: [Live Messanger] livemsgr.exe
O4 - HKLM\..\Run: [lnternet Update] lExplore.exe
O4 - HKLM\..\RunServices: [lnternet Update] lExplore.exe
O4 - HKLM\..\Run: [lnternet Update] sysmem.exe
O4 - HKLM\..\RunServices: [lnternet Update] sysmem.exe
O4 - HKLM\..\Run: [L0aders] faxneti.exe
O4 - HKLM\..\RunServices: [L0aders] faxneti.exe
O4 - HKCU\..\Run: [L0aders] faxneti.exe
O4 - HKLM\..\Run: [Loader msgzl] msgzl.exe
O4 - HKLM\..\RunServices: [Loader msgzl] msgzl.exe
O4 - HKLM\..\Run: [Loader msgzl] msgzl.exe
O4 - HKLM\..\Run: [Local area connection] winlive.exe
O4 - HKLM\..\RunServices: [Local area connection] winlive.exe
O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\system32\lssas.exe
O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\system32\Isass.exe
O4 - HKLM\..\Run: [Local Services] winserv32.exe
O4 - HKLM\..\RunServices: [Local Services] winserv32.exe
O4 - HKLM\..\Run: [LoghDriver] winlde.exe
O4 - HKLM\..\RunServices: [LoghDriver] winlde.exe
O4 - HKLM\..\Run: [LoghDriverr] winnlde.exe
O4 - HKLM\..\RunServices: [LoghDriverr] winnlde.exe
O4 - HKLM\..\Run: [Logical Disk Browser] mcrsvc.exe
O4 - HKLM\..\Run: [lost] WinUpdate.exe
O4 - HKLM\..\RunServices: [lost] WinUpdate.exe
O4 - HKCU\..\Run: [lost] WinUpdate.exe
O4 - HKLM\..\Run: [lpddcls] (Random 8 Letter).exe
O4 - HKCU\..\Run: [lpddcls] (Random 8 Letter).exe
O4 - HKLM\..\Run: [LSA] scvhost.exe
O4 - HKLM\..\RunServices: [LSA] scvhost.exe
O4 - HKCU\..\Run: [LSA] scvhost.exe
O4 - HKCU\..\RunServices: [LSA] scvhost.exe
O4 - HKLM\..\Run: [LSA Shell] C:\WINDOWS\system\lsass.exe
O4 - HKLM\..\Run: [LSA Shell (Export Version)] lsasss.exe
O4 - HKLM\..\RunServices: [LSA Shell (Export Version)] lsasss.exe
O4 - HKCU\..\Run: [LSA Shell (Export Version)] lsasss.exe
O4 - HKLM\..\Run: [lsass] svchost32.exe
O4 - HKLM\..\RunServices: [lsass] svchost32.exe
O4 - HKLM\..\Run: [Lsass16] C:\WINDOWS\lsass16.exe
O4 - HKLM\..\Run: [lsass2k Update] lsass2k.exe
O4 - HKLM\..\RunServices: [lsass2k Update] lsass2k.exe
O4 - HKCU\..\Run: [lsass2k Update] lsass2k.exe
O4 - HKLM\..\Run: [lsass32] lsass32.exe
O4 - HKLM\..\RunServices: [lsass32] lsass32.exe
O4 - HKLM\..\Run: [Machine Debug Mgr] mdn.exe
O4 - HKLM\..\Run: [mackfy.exe] msms.exe
O4 - HKLM\..\RunServices: [mackfy.exe] msms.exe
O4 - HKLM\..\Run: [Managment Service] xagwxzyrxbce.exe
O4 - HKLM\..\RunServices: [Managment Service] xagwxzyrxbce.exe
O4 - HKLM\..\Run: [MasterBoot Switch] popupkill.exe
O4 - HKLM\..\RunServices: [MasterBoot Switch] popupkill.exe
O4 - HKCU\..\Run: [MasterBoot Switch] popupkill.exe
O4 - HKLM\..\Run: [Master Card Updaate 32] Mastercard32.exe
O4 - HKLM\..\RunServices: [Master Card Updaate 32] Mastercard32.exe
O4 - HKLM\..\Run: [McAfee Online virus Scanner] avp.exe
O4 - HKLM\..\RunServices: [McAfee Online virus Scanner] avp.exe
O4 - HKLM\..\Run: [Media Software UPdater] sscs.exe
O4 - HKLM\..\RunServices: [Media Software UPdater] sscs.exe
O4 - HKCU\..\Run: [Media Software UPdater] sscs.exe
O4 - HKLM\..\Run: [MediaXPServicePack] mxpsp.exe
O4 - HKLM\..\RunServices: [MediaXPServicePack] mxpsp.exe
O4 - HKCU\..\Run: [MediaXPServicePack] mxpsp.exe
O4 - HKCU\..\RunServices: [MediaXPServicePack] mxpsp.exe
O4 - HKLM\..\Run: [Memory Allocation Host] cihost.exe
O4 - HKLM\..\Run: [Memory Allocation Server] ciserv.exe
O4 - HKLM\..\Run: [Messanger modix Configuration] winmsn.exe
O4 - HKLM\..\RunServices: [Messanger modix Configuration] winmsn.exe
O4 - HKLM\..\Run: [Messenger91] messengersystem.exe
O4 - HKLM\..\RunServices: [Messenger91] messengersystem.exe
O4 - HKLM\..\Run: [Mi7sft sdce] scorti.exe
O4 - HKLM\..\RunServices: [Mi7sft sdce] scorti.exe
O4 - HKLM\..\Run: [Micosoft Data Core] antivir32.exe
O4 - HKLM\..\RunServices: [Micosoft Data Core] antivir32.exe
O4 - HKLM\..\Run: [Micosoft Data Core] iexplore.exe
O4 - HKLM\..\RunServices: [Micosoft Data Core] iexplore.exe
O4 - HKLM\..\Run: [Micosoft Data Core] shell32.exe
O4 - HKLM\..\RunServices: [Micosoft Data Core] shell32.exe
O4 - HKLM\..\Run: [Micosoft Data Core stuff] atiwarez.exe
O4 - HKLM\..\RunServices: [Micosoft Data Core stuff] atiwarez.exe
O4 - HKLM\..\Run: [Micosoft Data Core stuff] cores.exe
O4 - HKLM\..\RunServices: [Micosoft Data Core stuff] cores.exe
O4 - HKLM\..\Run: [Micosoft Data Core stuff] datacorez.exe
O4 - HKLM\..\RunServices: [Micosoft Data Core stuff] datacorez.exe
O4 - HKLM\..\Run: [Micosoft Data Core stuff] svshosts.exe
O4 - HKLM\..\RunServices: [Micosoft Data Core stuff] svshosts.exe
O4 - HKLM\..\Run: [Micromedia Flash Update] xptxt.exe
O4 - HKLM\..\RunServices: [Micromedia Flash Update] xptxt.exe
O4 - HKLM\..\Run: [Microsft Conf 32] msaconf.exe
O4 - HKLM\..\RunServices: [Microsft Conf 32] msaconf.exe
O4 - HKCU\..\Run: [Microsft Conf 32] msaconf.exe
O4 - HKLM\..\Run: [Microsft Corporation Version 2001.12.4414] C:\WINDOWS\system32\Com\comrel.exe
O4 - HKLM\..\RunServices: [Microsft Corporation Version 2001.12.4414] C:\WINDOWS\system32\Com\comrel.exe
O4 - HKCU\..\Run: [Microsft Corporation Version 2001.12.4414] C:\WINDOWS\system32\Com\comrel.exe
O4 - HKLM\..\Run: [Microsft Corporation Version 2002.12.2414] C:\WINDOWS\system32\Com\comserv.exe
O4 - HKLM\..\RunServices: [Microsft Corporation Version 2002.12.2414] C:\WINDOWS\system32\Com\comserv.exe
O4 - HKCU\..\Run: [Microsft Corporation Version 2002.12.2414] C:\WINDOWS\system32\Com\comserv.exe
O4 - HKLM\..\Run: [Microsft Security Monitor Process] cmh.exe
O4 - HKLM\..\RunServices: [Microsft Security Monitor Process] cmh.exe
O4 - HKLM\..\Run: [Microsft Security Monitor Process] mssmpp.exe
O4 - HKLM\..\RunServices: [Microsft Security Monitor Process] mssmpp.exe
O4 - HKLM\..\Run: [Microsft Security Monitor Process] mssmppp.exe
O4 - HKLM\..\RunServices: [Microsft Security Monitor Process] mssmppp.exe
O4 - HKLM\..\Run: [Microsft Word] MSWORD.exe
O4 - HKLM\..\RunServices: [Microsft Word] MSWORD.exe
O4 - HKLM\..\Run: [Microsoff Windows Update] mswins.exe
O4 - HKLM\..\RunServices: [Microsoff Windows Update] mswins.exe
O4 - HKLM\..\Run: [Microsoft] .exe
O4 - HKLM\..\RunServices: [Microsoft] .exe
O4 - HKLM\..\Run: [Microsoft] aim.exe
O4 - HKLM\..\RunServices: [Microsoft] aim.exe
O4 - HKLM\..\Run: [Microsoft] avgemcu.exe
O4 - HKLM\..\RunServices: [Microsoft] avgemcu.exe
O4 - HKLM\..\Run: [Microsoft] C:\WINDOWS\System32\Isass.exe
O4 - HKLM\..\RunServices: [Microsoft] C:\WINDOWS\System32\Isass.exe
O4 - HKLM\..\Run: [Microsoft] C:\WINDOWS\System32\taskbar.exe
O4 - HKLM\..\RunServices: [Microsoft] C:\WINDOWS\System32\taskbar.exe
O4 - HKLM\..\Run: [Microsoft] derservice.exe
O4 - HKLM\..\RunServices: [Microsoft] derservice.exe
O4 - HKLM\..\Run: [Microsoft] Explorerr.exe
O4 - HKLM\..\RunServices: [Microsoft] Explorerr.exe
O4 - HKLM\..\Run: [Microsoft] firefox.exe
O4 - HKLM\..\RunServices: [Microsoft] firefox.exe
O4 - HKLM\..\Run: [Microsoft] guard.exe
O4 - HKLM\..\RunServices: [Microsoft] guard.exe
O4 - HKCU\..\Run: [Microsoft] guard.exe
O4 - HKLM\..\Run: [Microsoft] iexplore.exe
O4 - HKLM\..\RunServices: [Microsoft] iexplore.exe
O4 - HKLM\..\Run: [Microsoft] iexplorer.exe
O4 - HKLM\..\RunServices: [Microsoft] iexplorer.exe
O4 - HKLM\..\Run: [Microsoft] iusr.exe
O4 - HKLM\..\RunServices: [Microsoft] iusr.exe
O4 - HKCU\..\Run: [Microsoft] iusr.exe
O4 - HKLM\..\Run: [Microsoft] kasperskyLive32.exe
O4 - HKLM\..\RunServices: [Microsoft] kasperskyLive32.exe
O4 - HKLM\..\Run: [Microsoft] listc.exe
O4 - HKLM\..\RunServices: [Microsoft] listc.exe
O4 - HKCU\..\Run: [Microsoft] listc.exe
O4 - HKLM\..\Run: [Microsoft] lol.exe
O4 - HKLM\..\RunServices: [Microsoft] lol.exe
O4 - HKLM\..\Run: [Microsoft] loval32.exe
O4 - HKLM\..\RunServices: [Microsoft] loval32.exe
O4 - HKLM\..\Run: [Microsoft] lsass.ppf
O4 - HKLM\..\RunServices: [Microsoft] lsass.ppf
O4 - HKCU\..\Run: [Microsoft] lsass.ppf
O4 - HKLM\..\Run: [Microsoft] mdms.exe
O4 - HKLM\..\RunServices: [Microsoft] mdms.exe
O4 - HKCU\..\Run: [Microsoft] mdms.exe
O4 - HKLM\..\Run: [Microsoft] mixers.exe
O4 - HKLM\..\RunServices: [Microsoft] mixers.exe
O4 - HKCU\..\Run: [Microsoft] mixers.exe
O4 - HKLM\..\Run: [Microsoft] msmsger.exe
O4 - HKLM\..\RunServices: [Microsoft] msmsger.exe
O4 - HKCU\..\Run: [Microsoft] msmsger.exe
O4 - HKLM\..\Run: [Microsoft] msngerf.exe
O4 - HKLM\..\RunServices: [Microsoft] msngerf.exe
O4 - HKLM\..\Run: [Microsoft] msns.exe
O4 - HKLM\..\RunServices: [Microsoft] msns.exe
O4 - HKLM\..\Run: [Microsoft] msserv32.exe
O4 - HKLM\..\RunServices: [Microsoft] msserv32.exe
O4 - HKLM\..\Run: [Microsoft] MSUPDATE.exe
O4 - HKCU\..\Run: [Microsoft] MSUPDATE.exe
O4 - HKLM\..\Run: [Microsoft] msvchost.exe
O4 - HKLM\..\RunServices: [Microsoft] msvchost.exe
O4 - HKLM\..\Run: [Microsoft] msvcs.exe
O4 - HKLM\..\RunServices: [Microsoft] msvcs.exe
O4 - HKLM\..\Run: [Microsoft] netfix32.exe
O4 - HKLM\..\RunServices: [Microsoft] netfix32.exe
O4 - HKLM\..\Run: [Microsoft] netshield.exe
O4 - HKLM\..\RunServices: [Microsoft] netshield.exe
O4 - HKLM\..\Run: [Microsoft] netsrv.exe
O4 - HKLM\..\RunServices: [Microsoft] netsrv.exe
O4 - HKCU\..\Run: [Microsoft] netsrv.exe
O4 - HKLM\..\Run: [Microsoft] Nvpss.exe
O4 - HKLM\..\RunServices: [Microsoft] Nvpss.exe
O4 - HKLM\..\Run: [Microsoft] prefinal.exe
O4 - HKLM\..\RunServices: [Microsoft] prefinal.exe
O4 - HKLM\..\Run: [Microsoft] qtask.exe
O4 - HKLM\..\RunServices: [Microsoft] qtask.exe
O4 - HKCU\..\Run: [Microsoft] qtask.exe
O4 - HKLM\..\Run: [Microsoft] radnom.exe
O4 - HKLM\..\RunServices: [Microsoft] radnom.exe
O4 - HKCU\..\Run: [Microsoft] radnom.exe
O4 - HKLM\..\Run: [Microsoft] rtvcscan.exe
O4 - HKLM\..\RunServices: [Microsoft] rtvcscan.exe
O4 - HKCU\..\Run: [Microsoft] rtvcscan.exe
O4 - HKLM\..\Run: [Microsoft] rundll.exe
O4 - HKLM\..\RunServices: [Microsoft] rundll.exe
O4 - HKCU\..\Run: [Microsoft] rundll.exe
O4 - HKLM\..\Run: [Microsoft] scvhost32.exe
O4 - HKLM\..\RunServices: [Microsoft] scvhost32.exe
O4 - HKLM\..\Run: [Microsoft] sdcom.exe
O4 - HKLM\..\RunServices: [Microsoft] sdcom.exe
O4 - HKLM\..\Run: [Microsoft] services.exe
O4 - HKLM\..\RunServices: [Microsoft] services.exe
O4 - HKLM\..\Run: [Microsoft] servicess.exe
O4 - HKLM\..\RunServices: [Microsoft] servicess.exe
O4 - HKCU\..\Run: [Microsoft] servicess.exe
O4 - HKLM\..\Run: [Microsoft] soundvol32.exe
O4 - HKLM\..\RunServices: [Microsoft] soundvol32.exe
O4 - HKLM\..\Run: [Microsoft] sql.exe
O4 - HKLM\..\RunServices: [Microsoft] sql.exe
O4 - HKLM\..\Run: [Microsoft] steam.exe
O4 - HKLM\..\RunServices: [Microsoft] steam.exe
O4 - HKLM\..\Run: [Microsoft] svchost32.exe
O4 - HKLM\..\RunServices: [Microsoft] svchost32.exe
O4 - HKLM\..\Run: [Microsoft] svhcost.exe
O4 - HKLM\..\RunServices: [Microsoft] svhcost.exe
O4 - HKLM\..\Run: [Microsoft] synstat.exe
O4 - HKLM\..\RunServices: [Microsoft] synstat.exe
O4 - HKCU\..\Run: [Microsoft] synstat.exe
O4 - HKLM\..\Run: [Microsoft] system32.exe
O4 - HKLM\..\RunServices: [Microsoft] system32.exe
O4 - HKLM\..\Run: [Microsoft] systemdtm.exe
O4 - HKLM\..\RunServices: [Microsoft] systemdtm.exe
O4 - HKLM\..\Run: [Microsoft] systern.exe
O4 - HKLM\..\RunServices: [Microsoft] systern.exe
O4 - HKLM\..\Run: [Microsoft] taskmaneger.exe
O4 - HKLM\..\RunServices: [Microsoft] taskmaneger.exe
O4 - HKLM\..\Run: [Microsoft] updater.exe
O4 - HKLM\..\RunServices: [Microsoft] updater.exe
O4 - HKLM\..\Run: [Microsoft] verticals.exe
O4 - HKLM\..\RunServices: [Microsoft] verticals.exe
O4 - HKLM\..\Run: [Microsoft] wcsntfy.exe
O4 - HKLM\..\RunServices: [Microsoft] wcsntfy.exe
O4 - HKCU\..\Run: [Microsoft] wcsntfy.exe
O4 - HKLM\..\Run: [Microsoft] windl32.exe
O4 - HKLM\..\RunServices: [Microsoft] windl32.exe
O4 - HKCU\..\Run: [Microsoft] windl32.exe
O4 - HKLM\..\Run: [Microsoft] winlog.exe
O4 - HKLM\..\RunServices: [Microsoft] winlog.exe
O4 - HKCU\..\Run: [Microsoft] winlog.exe
O4 - HKLM\..\Run: [Microsoft] winlogom.exe
O4 - HKLM\..\RunServices: [Microsoft] winlogom.exe
O4 - HKLM\..\Run: [Microsoft] winlogon.exe
O4 - HKLM\..\RunServices: [Microsoft] winlogon.exe
O4 - HKLM\..\Run: [Microsoft] WinSecUp.exe
O4 - HKLM\..\RunServices: [Microsoft] WinSecUp.exe
O4 - HKLM\..\Run: [Microsoft] winsock.exe
O4 - HKLM\..\RunServices: [Microsoft] winsock.exe
O4 - HKLM\..\Run: [Microsoft] winsys32.exe
O4 - HKLM\..\RunServices: [Microsoft] winsys32.exe
O4 - HKLM\..\Run: [Microsoft] wsim32.exe
O4 - HKLM\..\RunServices: [Microsoft] wsim32.exe
O4 - HKLM\..\Run: [Microsoft] wuaudit.exe
O4 - HKLM\..\RunServices: [Microsoft] wuaudit.exe
O4 - HKLM\..\Run: [Microsoft] xhost.exe
O4 - HKLM\..\RunServices: [Microsoft] xhost.exe
O4 - HKCU\..\Run: [Microsoft] xhost.exe
O4 - HKLM\..\Run: [Microsoft.exe] (Random 7 Letter).exe
O4 - HKLM\..\RunServices: [Microsoft.exe] (Random 7 Letter).exe
O4 - HKLM\..\Run: [Microsoft Admin Protocal] MSADNIN.exe
O4 - HKLM\..\RunServices: [Microsoft Admin Protocal] MSADNIN.exe
O4 - HKCU\..\Run: [Microsoft Admin Protocal] MSADNIN.exe
O4 - HKCU\..\RunServices: [Microsoft Admin Protocal] MSADNIN.exe
O4 - HKLM\..\Run: [Microsoft ALG32 Protocol] alg32.exe
O4 - HKLM\..\RunServices: [Microsoft ALG32 Protocol] alg32.exe
O4 - HKCU\..\Run: [Microsoft ALG32 Protocol] alg32.exe
O4 - HKLM\..\Run: [Microsoft Anivirus Monitor Process] antiv.exe
O4 - HKLM\..\RunServices: [Microsoft Anivirus Monitor Process] antiv.exe
O4 - HKLM\..\Run: [Microsoft AntiSpyware] KT06.pif
O4 - HKLM\..\RunServices: [Microsoft AntiSpyware] KT06.pif
O4 - HKLM\..\Run: [Microsoft AntiVirus] winav32.exe
O4 - HKLM\..\RunServices: [Microsoft AntiVirus] winav32.exe
O4 - HKLM\..\Run: [Microsoft AUT Update] MSlti32.exe
O4 - HKLM\..\RunServices: [Microsoft AUT Update] MSlti32.exe
O4 - HKCM\..\Run: [Microsoft AUT Update] MSlti32.exe
O4 - HKCU\..\RunServices: [Microsoft AUT Update] MSlti32.exe
O4 - HKLM\..\Run: [Micrcsoft Certificate Services] cflmon.exe
O4 - HKLM\..\RunServices: [Micrcsoft Certificate Services] cflmon.exe
O4 - HKCU\..\Run: [Micrcsoft Certificate Services] cflmon.exe
O4 - HKCU\..\RunServices: [Micrcsoft Certificate Services] cflmon.exe
O4 - HKLM\..\Run: [Microsoft Chat] mIRC.exe
O4 - HKLM\..\RunServices: [Microsoft Chat] mIRC.exe
O4 - HKLM\..\Run: [Microsoft Client] mshost.exe
O4 - HKLM\..\RunServices: [Microsoft Client] mshost.exe
O4 - HKCU\..\Run: [Microsoft Client] mshost.exe
O4 - HKCU\..\RunServices: [Microsoft Client] mshost.exe
O4 - HKLM\..\Run: [Microsoft Command Line] wincmd.exe
O4 - HKLM\..\RunServices: [Microsoft Command Line] wincmd.exe
O4 - HKLM\..\Run: [Microsoft CONFIG] winmx.exe
O4 - HKLM\..\RunServices: [Microsoft CONFIG] winmx.exe
O4