08 Mar 2009, 12:25
08 Mar 2009, 20:06
O4 - HKCU\..\RunOnce: [SpybotDeletingB5501] command.com /c del "C:\Program Files\AskSBar\bar\1.bin\A2HIGHIN.EXE"
O23 - Service: AgereModemAudio - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: AntiVirScheduler - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: AntiVirService - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: AudioSrv - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: btwdins - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: clr_optimization_v2.0.50727_32 - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: COMSysApp - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: CryptSvc - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: DcomLaunch - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: Dhcp - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: dmadmin - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: Dot3svc - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: EapHost - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: Eventlog - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: EventSystem - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: FastUserSwitchingCompatibility - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: gupdate1c99d951a4ff84a - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: gusvc - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: hkmsvc - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: HTTPFilter - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: IDriverT - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: idsvc - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: JavaQuickStarterService - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: MDM - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: mnmsrvc - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: napagent - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: Netman - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: Nla - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: ose - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: PCA - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: PlugPlay - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: RasAuto - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
O23 - Service: RasMan - Unknown owner - C:\WINDOWS\TEMP\VRT1AB.tmp (file missing)
Folder::
C:\WINDOWS\Temp
11 Mar 2009, 00:14
Windows Registry Editor Version 5.00
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\
mountpoints2\{d728e54d-ccf9-11dd-a81a-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\
mountpoints2\{f257a55e-ce3d-11db-9450-0018debec359}]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AgereModemAudio]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AntiVirScheduler]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AntiVirService]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AudioSrv]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\btwdins]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\clr_optimization_v2.
0.50727_32]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\COMSysApp]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CryptSvc]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DcomLaunch]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dhcp]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmadmin]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dot3svc]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EapHost]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Eventlog]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EventSystem]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FastUserSwitchingCom
patibility]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gupdate1c99d951a4ff8
4a]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gusvc]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HidServ]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hkmsvc]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HTTPFilter]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IDriverT]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\idsvc]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\JavaQuickStarterServ
ice]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MDM]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mnmsrvc]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\napagent]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetDDE]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetDDEdsdm]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Netman]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Nla]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ose]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCA]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PlugPlay]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasAuto]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasMan]
Folder::
C:\Windows\Temp
Driver::
gupdate1c99d951a4ff84a
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\
mountpoints2\{d728e54d-ccf9-11dd-a81a-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\
mountpoints2\{f257a55e-ce3d-11db-9450-0018debec359}]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AgereModemAudio]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AntiVirScheduler]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AntiVirService]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AudioSrv]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\btwdins]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\clr_optimization_v2.
0.50727_32]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\COMSysApp]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CryptSvc]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DcomLaunch]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dhcp]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmadmin]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dot3svc]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EapHost]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Eventlog]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EventSystem]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FastUserSwitchingCom
patibility]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gupdate1c99d951a4ff8
4a]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gusvc]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HidServ]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hkmsvc]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HTTPFilter]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IDriverT]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\idsvc]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\JavaQuickStarterServ
ice]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MDM]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mnmsrvc]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\napagent]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetDDE]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetDDEdsdm]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Netman]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Nla]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ose]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCA]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PlugPlay]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasAuto]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasMan]
13 Mar 2009, 16:07
Windows Registry Editor Version 5.00
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Eventlog]