Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Spyware infection! Please review my HJT logfile

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Spyware infection! Please review my HJT logfile

Unread postby arqa » December 2nd, 2005, 12:22 am

Main Problems:
-Blue screen with Red letters sign that reads SPYWARE INFECTION
-Processes start to execute causing the PC to run out of memory
-Impossibility to access the Internet or other applications
-Frequent crashes
Please review and advise. Thanks :)


Logfile of HijackThis v1.99.1
Scan saved at 11:27:42 PM, on 11/30/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\RTVSCN95.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\DEFWATCH.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\INET20001\WINLOGON.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\NSVSVC\NSVSVC.EXE
C:\WINDOWS\SYSTEM\VIDCTRL\VIDCTRL.EXE
C:\WINDOWS\ADATIU.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\HJT\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R3 - URLSearchHook: (no name) - _{004E5031-F379-36E7-C64E-2F646F11EB4C} - (no file)
F1 - win.ini: run=C:\WINDOWS\INET20001\WINLOGON.EXE
O1 - Hosts: 216.39.69.102 view.atdmt.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.02.3000.1002\EN-XU\STMAIN.DLL
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {35AF1B0D-BB36-11B8-8720-16550B86281A} - C:\WINDOWS\SYSTEM\IOK.DLL (file missing)
O2 - BHO: (no name) - {40531B38-BE86-9072-4037-188D011E16C5} - C:\WINDOWS\Ylpyczxj.dll
O2 - BHO: (no name) - {14F01645-ADDB-9559-80BE-F40A7209F49F} - C:\WINDOWS\SYSTEM\UYHGNRR.DLL (file missing)
O2 - BHO: (no name) - {19F01243-ADDE-925A-80CD-820A747DF49E} - C:\WINDOWS\SYSTEM\UYHGNRR.DLL (file missing)
O2 - BHO: (no name) - {20DD2241-80EE-A66C-AD8B-C0274239D9AF} - C:\WINDOWS\SYSTEM\UYHGNRR.DLL (file missing)
O2 - BHO: (no name) - {FF3C9AB9-7D75-3FA4-7D56-71C2CF244695} - C:\WINDOWS\SYSTEM\EKHOLEP.DLL (file missing)
O2 - BHO: (no name) - {FB3C9EB5-7D79-4EA4-7D21-7DC2BE564696} - C:\WINDOWS\SYSTEM\EKHOLEP.DLL (file missing)
O2 - BHO: (no name) - {9945A8B8-5F13-2ECB-5014-49EF8E666BA6} - C:\WINDOWS\SYSTEM\EKHOLEP.DLL (file missing)
O2 - BHO: (no name) - {372D100A-FE95-BC17-C6DD-A95F86B5DD9D} - C:\WINDOWS\SYSTEM\RHATK.DLL (file missing)
O2 - BHO: (no name) - {3365BE9F-520B-17D1-0261-5200C3BE8B9A} - C:\WINDOWS\SYSTEM\WAWIKALW.DLL (file missing)
O2 - BHO: (no name) - {865B860C-319E-7B42-9178-33A6F9DD3991} - C:\WINDOWS\SYSTEM\QUTLENRA.DLL (file missing)
O2 - BHO: (no name) - {C10B6C45-83D3-9F09-D97C-83ADA9C922C3} - C:\WINDOWS\SYSTEM\COFMETV.DLL (file missing)
O2 - BHO: (no name) - {AFE14282-AC15-BFCE-1C80-FC5A161A48CE} - C:\WINDOWS\SYSTEM\HVJICJOC.DLL (file missing)
O2 - BHO: (no name) - {CD5178B5-952F-DDA1-7426-C609F3642392} - C:\WINDOWS\SYSTEM\OLPS.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: (no name) - {E476C9D9-2448-1099-1AB7-2477A5C1599E} - C:\WINDOWS\SYSTEM\QOR.DLL (file missing)
O2 - BHO: (no name) - {E076CDD5-2444-6199-1AC0-2877D4B3599D} - C:\WINDOWS\SYSTEM\QOR.DLL (file missing)
O2 - BHO: (no name) - {33BD2248-988D-AF01-82FE-C06934F889CE} - C:\WINDOWS\SYSTEM\DWOEO.DLL (file missing)
O2 - BHO: (no name) - {37BD2644-9881-DE01-8289-CC69458A89CD} - C:\WINDOWS\SYSTEM\DWOEO.DLL (file missing)
O2 - BHO: (no name) - {60B62541-C0D4-FE00-82FE-C06934F889CF} - C:\WINDOWS\SYSTEM\DWOEO.DLL (file missing)
O2 - BHO: (no name) - {64B6214D-C0D8-8F00-8289-CC69458A89CC} - C:\WINDOWS\SYSTEM\DWOEO.DLL (file missing)
O2 - BHO: (no name) - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - (no file)
O2 - BHO: SABHO - {21B4ACC4-8874-4AEC-AEAC-F567A249B4D4} - C:\PROGRAM FILES\180SEARCHASSISTANT\SALMHOOK.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\NEM220.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: Search - {B3C0AC9A-99DF-B2B0-8931-1CCF05329885} - C:\WINDOWS\Ylpyczxj.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [dlder] C:\WINDOWS\explorer\Explorer.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\en-us\msnappau.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [5QEKE7T5NG9WG2] C:\WINDOWS\SYSTEM\Sgr88m14.exe
O4 - HKLM\..\Run: [ihoodc] C:\WINDOWS\SYSTEM\ihoodc.exe
O4 - HKLM\..\Run: [Zoqtk] C:\PROGRAM FILES\EGOIMLJ\FCGMK.EXE
O4 - HKLM\..\Run: [PSof1] C:\WINDOWS\SYSTEM\PSof1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\SYSTEM\exp.exe
O4 - HKLM\..\Run: [Command] C:\WINDOWS\cmd\command.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\SYSTEM\wintask.exe
O4 - HKLM\..\Run: [MedGS] C:\WINDOWS\SYSTEM\MEDGS1.exe
O4 - HKLM\..\Run: [OPR] C:\WINDOWS\SYSTEM\OPR.exe
O4 - HKLM\..\Run: [autoupdate] rundll32 C:\WINDOWS\SYSTEM\WUAUCLT.DLL,SHStart
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\SYSTEM\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [vidctrl] C:\WINDOWS\SYSTEM\VIDCTRL\VIDCTRL.EXE
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\adatiu.exe reg_run
O4 - HKLM\..\Run: [Windows Incontext] C:\WINDOWS\TEMP\INSEARCH.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [wzcqlrx] c:\windows\system\wzcqlrx.exe
O4 - HKLM\..\Run: [ysbinstall_1] C:\WINDOWS\SYSTEM\ysbinstall_1
O4 - HKLM\..\Run: [app] C:\WINDOWS\SYSTEM\app
O4 - HKLM\..\Run: [testit.exe] C:\WINDOWS\SYSTEM\testit.exe
O4 - HKLM\..\Run: [mmxp2passion.exe] C:\WINDOWS\SYSTEM\mmxp2passion.exe
O4 - HKLM\..\Run: [MediaGateway.exe] C:\WINDOWS\SYSTEM\MediaGateway.exe
O4 - HKLM\..\Run: [mediapluscash.exe] C:\WINDOWS\SYSTEM\mediapluscash.exe
O4 - HKLM\..\Run: [cashplusmedia.exe] C:\WINDOWS\SYSTEM\cashplusmedia.exe
O4 - HKLM\..\Run: [YVIBRVB] C:\WINDOWS\YVIBRVB.exe
O4 - HKLM\..\Run: [7.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [cashplusmedia1.exe] C:\WINDOWS\SYSTEM\cashplusmedia1.exe
O4 - HKLM\..\Run: [0.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\SYSTEM\SPDEVSAW.EXE DO0605
O4 - HKLM\..\Run: [8.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [removeist.exe] C:\WINDOWS\SYSTEM\removeist.exe
O4 - HKLM\..\Run: [3.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [adcomplusanalytic.exe] C:\WINDOWS\SYSTEM\adcomplusanalytic.exe
O4 - HKLM\..\Run: [0.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [mc-58-12-] C:\WINDOWS\SYSTEM\mc-58-12-
O4 - HKLM\..\Run: [2.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [Yunguyo.exe] C:\WINDOWS\SYSTEM\Yunguyo.exe
O4 - HKLM\..\Run: [3.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [SSK3_B5.exe] C:\WINDOWS\SYSTEM\SSK3_B5.exe
O4 - HKLM\..\Run: [8.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [AntiAdware.exe] C:\WINDOWS\SYSTEM\AntiAdware.exe
O4 - HKLM\..\Run: [8.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [silent_partos.exe] C:\WINDOWS\SYSTEM\silent_partos.exe
O4 - HKLM\..\Run: [3.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [wfwall1.exe] C:\WINDOWS\SYSTEM\wfwall1.exe
O4 - HKLM\..\Run: [5.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O4 - HKLM\..\Run: [3.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [webnexus.exe] C:\WINDOWS\SYSTEM\webnexus.exe
O4 - HKLM\..\Run: [7.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [pi1_72.exe] C:\WINDOWS\SYSTEM\pi1_72.exe
O4 - HKLM\..\Run: [3.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [AdCom9788-seedrevshare.exe] C:\WINDOWS\SYSTEM\AdCom9788-seedrevshare.exe
O4 - HKLM\..\Run: [4.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [Setup2-71.exe] C:\WINDOWS\SYSTEM\Setup2-71.exe
O4 - HKLM\..\Run: [9.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [russandmmx.exe] C:\WINDOWS\SYSTEM\russandmmx.exe
O4 - HKLM\..\Run: [7.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [ourcash.exe] C:\WINDOWS\SYSTEM\ourcash.exe
O4 - HKLM\..\Run: [5.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [wrapperouter.exe] C:\WINDOWS\SYSTEM\wrapperouter.exe
O4 - HKLM\..\Run: [4.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [mc-11] C:\WINDOWS\SYSTEM\mc-11
O4 - HKLM\..\Run: [7.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [salm] c:\program files\180searchassistant\salm.exe
O4 - HKLM\..\Run: [7.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [drsmartload183a.exe] C:\WINDOWS\SYSTEM\drsmartload183a.exe
O4 - HKLM\..\Run: [mmxruss.exe] C:\WINDOWS\SYSTEM\mmxruss.exe
O4 - HKLM\..\Run: [7.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [AdCom-SeedRevShare.exe] C:\WINDOWS\SYSTEM\AdCom-SeedRevShare.exe
O4 - HKLM\..\Run: [whCC-CLICK.exe] C:\WINDOWS\SYSTEM\whCC-CLICK.exe
O4 - HKLM\..\Run: [7.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [{00-0A-A0-0D-ZN}] C:\WINDOWS\SYSTEM\RRDSREGO.EXE DO0605
O4 - HKLM\..\Run: [4.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1226345244.exe] C:\WINDOWS\SYSTEM\1226345244.exe
O4 - HKLM\..\Run: [snss Launcher] "C:\Program Files\snss\snss.exe"
O4 - HKLM\..\Run: [7.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\SYSTEM\priva.exe internat.dll,LoadMouseCarpetProfile
O4 - HKLM\..\Run: [load32] C:\WINDOWS\SYSTEM\winldra.exe
O4 - HKLM\..\Run: [7.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [Explorer32] C:\WINDOWS\SYSTEM\efsdfgxg.exe
O4 - HKLM\..\Run: [q3q99.exe] C:\WINDOWS\SYSTEM\q3q99.exe
O4 - HKLM\..\Run: [5.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [ujojsb] C:\WINDOWS\ujojsb.exe
O4 - HKLM\..\Run: [6.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [OSS] C:\WINDOWS\RLVKNLG.EXE -boot
O4 - HKLM\..\Run: [VVSN] C:\PROGRAM FILES\VVSN\VVSN.EXE
O4 - HKLM\..\Run: [2.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\INET20001\WINLOGON.EXE
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [Media Gateway] C:\PROGRAM FILES\MEDIA GATEWAY\MEDIAGATEWAY.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [AolAcsDaemon1] "C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE"
O4 - HKLM\..\RunServices: [rtvscn95] C:\PROGRA~1\SYMANT~1\SYMANT~1\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] C:\PROGRA~1\SYMANT~1\SYMANT~1\defwatch.exe
O4 - HKLM\..\RunServices: [PcCtlCom] C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY 2005\PCCTLCOM.EXE
O4 - HKLM\..\RunServices: [SystemTools] C:\WINDOWS\SYSTEM\kernels32.exe
O4 - HKLM\..\RunServices: [Shell] Explorer.exe C:\WINDOWS\SYSTEM\kernels32.exe
O4 - HKLM\..\RunServices: [Explorer64] C:\WINDOWS\SYSTEM\efsdfgxg.exe
O4 - HKLM\..\RunOnce: [Pest Cleaning] "C:\PROGRAM FILES\COMMON FILES\SCANNER\PPCLEAN.EXE" "clean" "cws" "2"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Weather] C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE 1
O4 - HKCU\..\Run: [Zlyz] C:\WINDOWS\SYSTEM\eol.exe
O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
O4 - HKCU\..\Run: [FCEngine] "C:\Program Files\FCEngine\FCEngine.exe"
O4 - HKCU\..\Run: [CTYRIA] C:\WINDOWS\SYSTEM\CTYRIA.exe
O4 - HKCU\..\Run: [D3DDER] C:\WINDOWS\SYSTEM\D3DDER.exe
O4 - HKCU\..\Run: [MSRFOX] C:\WINDOWS\SYSTEM\MSRFOX.exe
O4 - HKCU\..\Run: [CLOUDSIM] C:\WINDOWS\SYSTEM\CLOUDSIM.exe
O4 - HKCU\..\Run: [FCMan] "C:\Program Files\FCMan\FCMan.exe"
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-110-12-0000122.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [aupd] C:\WINDOWS\SYSTEM\sywsvcs.exe
O4 - HKCU\..\Run: [Lrrn] "C:\Program Files\tpus\btws.exe" -vt rbnd
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\INET20001\WINLOGON.EXE
O4 - HKCU\..\RunServices: [aupd] C:\WINDOWS\SYSTEM\sywsvcs.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: Camio Viewer 3.2.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O4 - Startup: nrna.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\SYSTEM\spdevsaw.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Z_Start.lnk = C:\WINDOWS\SYSTEM\esysehiz.exe
O4 - Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.exe
O4 - Global Startup: Yadio Media Player.lnk = C:\Program Files\Yadio Media Player\Yadiostart.exe
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: &Add to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\WebMenuImg.htm
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O8 - Extra context menu item: Write a Review... - http://client.alexa.com/holiday/script/ ... review.htm
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0322.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0322.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\SYSTEM\maxspeed.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\SYSTEM\maxspeed.exe (file missing)
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com/ (file missing) (HKCU)
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.dellnet.com/
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSIns ... a_ie_2.adp
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {94118C19-B178-4E43-BBE8-0EFDBB391BDB} (SysWebTelecom Class) - http://www.sponsoradulto.com/SysWebTelecom2.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/pages/scanner/WinFi ... nstall.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - ms-its:mhtml:file://c:\nosunex.mht!http://daemonlinks.net/script/ys.chm::/ysb_regular.cab
O16 - DPF: {972BB342-14A7-4660-83C1-51DDBEE171DB} - http://www.pacimedia.com/install/pcs_0009.exe
O16 - DPF: {0878B424-1F95-4E26-B5AB-F0D349D89650} - http://download.bargain-buddy.net/downl ... TING32.cab
O16 - DPF: {1E1B286C-88FF-11D2-8D96-D7ACAC95951F} - http://66.194.67.102/banner/with-report ... nerads.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - ms-its:mhtml:file://c:\nosunel.mht!http://213.158.119.23/script/lc.chm::/bridge-c46.cab
O16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} - http://www.pacimedia.com/install/pcs_0009.exe
O16 - DPF: {99410CDE-6F16-42ce-9D49-3807F78F0287} (ClientInstaller Class) - http://www.180searchassistant.com/180saax.cab
O20 - Winlogon Notify: msupdate - C:\WINDOWS\SYSTEM\msupdate32.dll
O21 - SSODL: hbeUYKE - {07D00A0E-AD7A-A0A4-EAF0-5B7C4D7E07D9} - C:\WINDOWS\SYSTEM\PZRKD.DLL (file missing)
O21 - SSODL: Module - {429F4BB8-7BF7-4152-8011-3C6F9EB7E892} - C:\WINDOWS\SYSTEM\chp.dll
O21 - SSODL: DDE - {F33812FB-F35C-4674-90F6-FD757C419C51} - C:\WINDOWS\SYSTEM\birdihuy32.dll
O21 - SSODL: OLE Module - {203B1C4D9-BC71-8916-38AD-9DEA5D213614} - C:\WINDOWS\SYSTEM\bre.dll
arqa
Regular Member
 
Posts: 55
Joined: December 1st, 2005, 1:21 am
Advertisement
Register to Remove

Unread postby MaKaVeLi » December 2nd, 2005, 11:34 pm

Hi arqa,

This computer has like every virus known to man. Just a quick look through your log shows several trojan horses. All of your personal information could have been compromised. I suggest that you use another computer to download the tools to fix your computer.

Please download Ewido Security Suite from here
(Note: As this is a trial version, after the 14 day trial period has expired Ewido will lose some functionality with it. Ewido will then will work as an On-Demand program, make sure to check for updates regularly).
  1. Install ewido security suite
  2. When installing the program, under "Additional Options" uncheck...
    • Install background guard
    • Install scan via context menu
  3. Launch ewido, there should now be an icon on your desktop, double-click it.
  4. The program will now open to the main screen.
  5. When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  6. You will need to update ewido to the latest definition files:
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  7. The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display "Update successful")
  8. Close Ewido Security Suite
If you are having problems with the updater, you can use this link to manually update ewido.
Ewido manual updates

Once the updates are installed, do the following:
  1. Reboot computer into "Safe Mode" using the "F8" method...
    • As soon as the BIOS is loaded begin tapping the F8 key until the Boot Menu appears
    • Use the arrow keys to select the Safe Mode menu item
  2. Once in Safe Mode start Ewido Security Suite
  3. Click on scanner. (Note: Do not start any programs or open any windows while Ewido is scanning)
  4. Click on Complete System Scan, the scan will now begin.
  5. While the scan is in progress you will be prompted to clean files, click OK.
  6. When it asks if you want to clean the first file, put a checkmark in the lower left corner of the box that says "Perform action on all infections", then choose clean and click OK.
  7. Once the scan has completed, there will be a button located at the bottom of the screen named Save Report.
  8. Click Save Report.
  9. Now save the report .txt file to your desktop.
  10. Close Ewido Security Suite


Now reboot and post a new HijackThis log along with the Ewido log.
User avatar
MaKaVeLi
Regular Member
 
Posts: 263
Joined: July 4th, 2005, 5:46 pm
Location: USA

Can't use EWIDO - Response to MaKaVeLi

Unread postby arqa » December 3rd, 2005, 9:07 pm

Main Problems:
-Blue screen with Red letters sign that reads SPYWARE INFECTION
-Processes start to execute causing the PC to run out of memory
-Impossibility to access the Internet or other applications
-Frequent crashes
Please review and advise. Thanks :)


Logfile of HijackThis v1.99.1
Scan saved at 11:27:42 PM, on 11/30/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\RTVSCN95.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\DEFWATCH.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\INET20001\WINLOGON.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\NSVSVC\NSVSVC.EXE
C:\WINDOWS\SYSTEM\VIDCTRL\VIDCTRL.EXE
C:\WINDOWS\ADATIU.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\HJT\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R3 - URLSearchHook: (no name) - _{004E5031-F379-36E7-C64E-2F646F11EB4C} - (no file)
F1 - win.ini: run=C:\WINDOWS\INET20001\WINLOGON.EXE
O1 - Hosts: 216.39.69.102 view.atdmt.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.02.3000.1002\EN-XU\STMAIN.DLL
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {35AF1B0D-BB36-11B8-8720-16550B86281A} - C:\WINDOWS\SYSTEM\IOK.DLL (file missing)
O2 - BHO: (no name) - {40531B38-BE86-9072-4037-188D011E16C5} - C:\WINDOWS\Ylpyczxj.dll
O2 - BHO: (no name) - {14F01645-ADDB-9559-80BE-F40A7209F49F} - C:\WINDOWS\SYSTEM\UYHGNRR.DLL (file missing)
O2 - BHO: (no name) - {19F01243-ADDE-925A-80CD-820A747DF49E} - C:\WINDOWS\SYSTEM\UYHGNRR.DLL (file missing)
O2 - BHO: (no name) - {20DD2241-80EE-A66C-AD8B-C0274239D9AF} - C:\WINDOWS\SYSTEM\UYHGNRR.DLL (file missing)
O2 - BHO: (no name) - {FF3C9AB9-7D75-3FA4-7D56-71C2CF244695} - C:\WINDOWS\SYSTEM\EKHOLEP.DLL (file missing)
O2 - BHO: (no name) - {FB3C9EB5-7D79-4EA4-7D21-7DC2BE564696} - C:\WINDOWS\SYSTEM\EKHOLEP.DLL (file missing)
O2 - BHO: (no name) - {9945A8B8-5F13-2ECB-5014-49EF8E666BA6} - C:\WINDOWS\SYSTEM\EKHOLEP.DLL (file missing)
O2 - BHO: (no name) - {372D100A-FE95-BC17-C6DD-A95F86B5DD9D} - C:\WINDOWS\SYSTEM\RHATK.DLL (file missing)
O2 - BHO: (no name) - {3365BE9F-520B-17D1-0261-5200C3BE8B9A} - C:\WINDOWS\SYSTEM\WAWIKALW.DLL (file missing)
O2 - BHO: (no name) - {865B860C-319E-7B42-9178-33A6F9DD3991} - C:\WINDOWS\SYSTEM\QUTLENRA.DLL (file missing)
O2 - BHO: (no name) - {C10B6C45-83D3-9F09-D97C-83ADA9C922C3} - C:\WINDOWS\SYSTEM\COFMETV.DLL (file missing)
O2 - BHO: (no name) - {AFE14282-AC15-BFCE-1C80-FC5A161A48CE} - C:\WINDOWS\SYSTEM\HVJICJOC.DLL (file missing)
O2 - BHO: (no name) - {CD5178B5-952F-DDA1-7426-C609F3642392} - C:\WINDOWS\SYSTEM\OLPS.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: (no name) - {E476C9D9-2448-1099-1AB7-2477A5C1599E} - C:\WINDOWS\SYSTEM\QOR.DLL (file missing)
O2 - BHO: (no name) - {E076CDD5-2444-6199-1AC0-2877D4B3599D} - C:\WINDOWS\SYSTEM\QOR.DLL (file missing)
O2 - BHO: (no name) - {33BD2248-988D-AF01-82FE-C06934F889CE} - C:\WINDOWS\SYSTEM\DWOEO.DLL (file missing)
O2 - BHO: (no name) - {37BD2644-9881-DE01-8289-CC69458A89CD} - C:\WINDOWS\SYSTEM\DWOEO.DLL (file missing)
O2 - BHO: (no name) - {60B62541-C0D4-FE00-82FE-C06934F889CF} - C:\WINDOWS\SYSTEM\DWOEO.DLL (file missing)
O2 - BHO: (no name) - {64B6214D-C0D8-8F00-8289-CC69458A89CC} - C:\WINDOWS\SYSTEM\DWOEO.DLL (file missing)
O2 - BHO: (no name) - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - (no file)
O2 - BHO: SABHO - {21B4ACC4-8874-4AEC-AEAC-F567A249B4D4} - C:\PROGRAM FILES\180SEARCHASSISTANT\SALMHOOK.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\NEM220.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: Search - {B3C0AC9A-99DF-B2B0-8931-1CCF05329885} - C:\WINDOWS\Ylpyczxj.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [dlder] C:\WINDOWS\explorer\Explorer.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\en-us\msnappau.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [5QEKE7T5NG9WG2] C:\WINDOWS\SYSTEM\Sgr88m14.exe
O4 - HKLM\..\Run: [ihoodc] C:\WINDOWS\SYSTEM\ihoodc.exe
O4 - HKLM\..\Run: [Zoqtk] C:\PROGRAM FILES\EGOIMLJ\FCGMK.EXE
O4 - HKLM\..\Run: [PSof1] C:\WINDOWS\SYSTEM\PSof1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\SYSTEM\exp.exe
O4 - HKLM\..\Run: [Command] C:\WINDOWS\cmd\command.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\SYSTEM\wintask.exe
O4 - HKLM\..\Run: [MedGS] C:\WINDOWS\SYSTEM\MEDGS1.exe
O4 - HKLM\..\Run: [OPR] C:\WINDOWS\SYSTEM\OPR.exe
O4 - HKLM\..\Run: [autoupdate] rundll32 C:\WINDOWS\SYSTEM\WUAUCLT.DLL,SHStart
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\SYSTEM\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [vidctrl] C:\WINDOWS\SYSTEM\VIDCTRL\VIDCTRL.EXE
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\adatiu.exe reg_run
O4 - HKLM\..\Run: [Windows Incontext] C:\WINDOWS\TEMP\INSEARCH.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [wzcqlrx] c:\windows\system\wzcqlrx.exe
O4 - HKLM\..\Run: [ysbinstall_1] C:\WINDOWS\SYSTEM\ysbinstall_1
O4 - HKLM\..\Run: [app] C:\WINDOWS\SYSTEM\app
O4 - HKLM\..\Run: [testit.exe] C:\WINDOWS\SYSTEM\testit.exe
O4 - HKLM\..\Run: [mmxp2passion.exe] C:\WINDOWS\SYSTEM\mmxp2passion.exe
O4 - HKLM\..\Run: [MediaGateway.exe] C:\WINDOWS\SYSTEM\MediaGateway.exe
O4 - HKLM\..\Run: [mediapluscash.exe] C:\WINDOWS\SYSTEM\mediapluscash.exe
O4 - HKLM\..\Run: [cashplusmedia.exe] C:\WINDOWS\SYSTEM\cashplusmedia.exe
O4 - HKLM\..\Run: [YVIBRVB] C:\WINDOWS\YVIBRVB.exe
O4 - HKLM\..\Run: [7.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [cashplusmedia1.exe] C:\WINDOWS\SYSTEM\cashplusmedia1.exe
O4 - HKLM\..\Run: [0.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\SYSTEM\SPDEVSAW.EXE DO0605
O4 - HKLM\..\Run: [8.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [removeist.exe] C:\WINDOWS\SYSTEM\removeist.exe
O4 - HKLM\..\Run: [3.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [adcomplusanalytic.exe] C:\WINDOWS\SYSTEM\adcomplusanalytic.exe
O4 - HKLM\..\Run: [0.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [mc-58-12-] C:\WINDOWS\SYSTEM\mc-58-12-
O4 - HKLM\..\Run: [2.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [Yunguyo.exe] C:\WINDOWS\SYSTEM\Yunguyo.exe
O4 - HKLM\..\Run: [3.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [SSK3_B5.exe] C:\WINDOWS\SYSTEM\SSK3_B5.exe
O4 - HKLM\..\Run: [8.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [AntiAdware.exe] C:\WINDOWS\SYSTEM\AntiAdware.exe
O4 - HKLM\..\Run: [8.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [silent_partos.exe] C:\WINDOWS\SYSTEM\silent_partos.exe
O4 - HKLM\..\Run: [3.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [wfwall1.exe] C:\WINDOWS\SYSTEM\wfwall1.exe
O4 - HKLM\..\Run: [5.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O4 - HKLM\..\Run: [3.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [webnexus.exe] C:\WINDOWS\SYSTEM\webnexus.exe
O4 - HKLM\..\Run: [7.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [pi1_72.exe] C:\WINDOWS\SYSTEM\pi1_72.exe
O4 - HKLM\..\Run: [3.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [AdCom9788-seedrevshare.exe] C:\WINDOWS\SYSTEM\AdCom9788-seedrevshare.exe
O4 - HKLM\..\Run: [4.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [Setup2-71.exe] C:\WINDOWS\SYSTEM\Setup2-71.exe
O4 - HKLM\..\Run: [9.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [russandmmx.exe] C:\WINDOWS\SYSTEM\russandmmx.exe
O4 - HKLM\..\Run: [7.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [ourcash.exe] C:\WINDOWS\SYSTEM\ourcash.exe
O4 - HKLM\..\Run: [5.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [wrapperouter.exe] C:\WINDOWS\SYSTEM\wrapperouter.exe
O4 - HKLM\..\Run: [4.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [mc-11] C:\WINDOWS\SYSTEM\mc-11
O4 - HKLM\..\Run: [7.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [salm] c:\program files\180searchassistant\salm.exe
O4 - HKLM\..\Run: [7.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [drsmartload183a.exe] C:\WINDOWS\SYSTEM\drsmartload183a.exe
O4 - HKLM\..\Run: [mmxruss.exe] C:\WINDOWS\SYSTEM\mmxruss.exe
O4 - HKLM\..\Run: [7.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [AdCom-SeedRevShare.exe] C:\WINDOWS\SYSTEM\AdCom-SeedRevShare.exe
O4 - HKLM\..\Run: [whCC-CLICK.exe] C:\WINDOWS\SYSTEM\whCC-CLICK.exe
O4 - HKLM\..\Run: [7.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [{00-0A-A0-0D-ZN}] C:\WINDOWS\SYSTEM\RRDSREGO.EXE DO0605
O4 - HKLM\..\Run: [4.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1226345244.exe] C:\WINDOWS\SYSTEM\1226345244.exe
O4 - HKLM\..\Run: [snss Launcher] "C:\Program Files\snss\snss.exe"
O4 - HKLM\..\Run: [7.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\SYSTEM\priva.exe internat.dll,LoadMouseCarpetProfile
O4 - HKLM\..\Run: [load32] C:\WINDOWS\SYSTEM\winldra.exe
O4 - HKLM\..\Run: [7.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [Explorer32] C:\WINDOWS\SYSTEM\efsdfgxg.exe
O4 - HKLM\..\Run: [q3q99.exe] C:\WINDOWS\SYSTEM\q3q99.exe
O4 - HKLM\..\Run: [5.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [ujojsb] C:\WINDOWS\ujojsb.exe
O4 - HKLM\..\Run: [6.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [OSS] C:\WINDOWS\RLVKNLG.EXE -boot
O4 - HKLM\..\Run: [VVSN] C:\PROGRAM FILES\VVSN\VVSN.EXE
O4 - HKLM\..\Run: [2.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\INET20001\WINLOGON.EXE
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [Media Gateway] C:\PROGRAM FILES\MEDIA GATEWAY\MEDIAGATEWAY.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [AolAcsDaemon1] "C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE"
O4 - HKLM\..\RunServices: [rtvscn95] C:\PROGRA~1\SYMANT~1\SYMANT~1\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] C:\PROGRA~1\SYMANT~1\SYMANT~1\defwatch.exe
O4 - HKLM\..\RunServices: [PcCtlCom] C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY 2005\PCCTLCOM.EXE
O4 - HKLM\..\RunServices: [SystemTools] C:\WINDOWS\SYSTEM\kernels32.exe
O4 - HKLM\..\RunServices: [Shell] Explorer.exe C:\WINDOWS\SYSTEM\kernels32.exe
O4 - HKLM\..\RunServices: [Explorer64] C:\WINDOWS\SYSTEM\efsdfgxg.exe
O4 - HKLM\..\RunOnce: [Pest Cleaning] "C:\PROGRAM FILES\COMMON FILES\SCANNER\PPCLEAN.EXE" "clean" "cws" "2"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Weather] C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE 1
O4 - HKCU\..\Run: [Zlyz] C:\WINDOWS\SYSTEM\eol.exe
O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
O4 - HKCU\..\Run: [FCEngine] "C:\Program Files\FCEngine\FCEngine.exe"
O4 - HKCU\..\Run: [CTYRIA] C:\WINDOWS\SYSTEM\CTYRIA.exe
O4 - HKCU\..\Run: [D3DDER] C:\WINDOWS\SYSTEM\D3DDER.exe
O4 - HKCU\..\Run: [MSRFOX] C:\WINDOWS\SYSTEM\MSRFOX.exe
O4 - HKCU\..\Run: [CLOUDSIM] C:\WINDOWS\SYSTEM\CLOUDSIM.exe
O4 - HKCU\..\Run: [FCMan] "C:\Program Files\FCMan\FCMan.exe"
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-110-12-0000122.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [aupd] C:\WINDOWS\SYSTEM\sywsvcs.exe
O4 - HKCU\..\Run: [Lrrn] "C:\Program Files\tpus\btws.exe" -vt rbnd
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\INET20001\WINLOGON.EXE
O4 - HKCU\..\RunServices: [aupd] C:\WINDOWS\SYSTEM\sywsvcs.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: Camio Viewer 3.2.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O4 - Startup: nrna.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\SYSTEM\spdevsaw.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Z_Start.lnk = C:\WINDOWS\SYSTEM\esysehiz.exe
O4 - Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.exe
O4 - Global Startup: Yadio Media Player.lnk = C:\Program Files\Yadio Media Player\Yadiostart.exe
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: &Add to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\WebMenuImg.htm
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O8 - Extra context menu item: Write a Review... - http://client.alexa.com/holiday/script/ ... review.htm
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0322.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0322.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\SYSTEM\maxspeed.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\SYSTEM\maxspeed.exe (file missing)
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com/ (file missing) (HKCU)
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.dellnet.com/
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSIns ... a_ie_2.adp
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {94118C19-B178-4E43-BBE8-0EFDBB391BDB} (SysWebTelecom Class) - http://www.sponsoradulto.com/SysWebTelecom2.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/pages/scanner/WinFi ... nstall.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - ms-its:mhtml:file://c:\nosunex.mht!http://daemonlinks.net/script/ys.chm::/ysb_regular.cab
O16 - DPF: {972BB342-14A7-4660-83C1-51DDBEE171DB} - http://www.pacimedia.com/install/pcs_0009.exe
O16 - DPF: {0878B424-1F95-4E26-B5AB-F0D349D89650} - http://download.bargain-buddy.net/downl ... TING32.cab
O16 - DPF: {1E1B286C-88FF-11D2-8D96-D7ACAC95951F} - http://66.194.67.102/banner/with-report ... nerads.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - ms-its:mhtml:file://c:\nosunel.mht!http://213.158.119.23/script/lc.chm::/bridge-c46.cab
O16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} - http://www.pacimedia.com/install/pcs_0009.exe
O16 - DPF: {99410CDE-6F16-42ce-9D49-3807F78F0287} (ClientInstaller Class) - http://www.180searchassistant.com/180saax.cab
O20 - Winlogon Notify: msupdate - C:\WINDOWS\SYSTEM\msupdate32.dll
O21 - SSODL: hbeUYKE - {07D00A0E-AD7A-A0A4-EAF0-5B7C4D7E07D9} - C:\WINDOWS\SYSTEM\PZRKD.DLL (file missing)
O21 - SSODL: Module - {429F4BB8-7BF7-4152-8011-3C6F9EB7E892} - C:\WINDOWS\SYSTEM\chp.dll
O21 - SSODL: DDE - {F33812FB-F35C-4674-90F6-FD757C419C51} - C:\WINDOWS\SYSTEM\birdihuy32.dll
O21 - SSODL: OLE Module - {203B1C4D9-BC71-8916-38AD-9DEA5D213614} - C:\WINDOWS\SYSTEM\b
arqa
Regular Member
 
Posts: 55
Joined: December 1st, 2005, 1:21 am

Unread postby MaKaVeLi » December 4th, 2005, 11:56 am

Did you download and run Ewido?
User avatar
MaKaVeLi
Regular Member
 
Posts: 263
Joined: July 4th, 2005, 5:46 pm
Location: USA

Can't use EWIDO -Have Windows ME- Response to MaKaVeLi

Unread postby arqa » December 4th, 2005, 4:26 pm

Hello MaKaVeLi
Ewido runs with Windows 2000 or XP
Is there any other software I can use instead?
Please advise. Thanks :)
arqa
Regular Member
 
Posts: 55
Joined: December 1st, 2005, 1:21 am

Unread postby MaKaVeLi » December 4th, 2005, 5:42 pm

Yup I forgot about that. :oops: Let's get rid of all these exe82 lines first.

Start your computer in safe mode. Read this if you don't know how to.

Run HijackThis and put a check next to the following lines: (MAKE SURE YOU GET THEM ALL!)

O4 - HKLM\..\Run: [7.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.70] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [0.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.16] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.82] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.64] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.53] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.77] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.17] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.73] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.59] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.76] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.95] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.80] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.14] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.02] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.90] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.26] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.37] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.52] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.51] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.75] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.27] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.08] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.88] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.38] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.23] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.69] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.91] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.34] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.24] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.41] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.25] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.03] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.89] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.10] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.22] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.40] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.00] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.65] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.92] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.13] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.42] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.50] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.32] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.12] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.36] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.05] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.61] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.29] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.57] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.39] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.86] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.09] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.06] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.81] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.44] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.33] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.21] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.97] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.56] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.04] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.72] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.67] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.84] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.62] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.19] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.31] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.20] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.68] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.78] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.63] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.15] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.35] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.74] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.11] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.18] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.48] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.58] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [8.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.71] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.60] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.45] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.79] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.47] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.30] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.87] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.83] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.98] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [4.85] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.66] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.96] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.49] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.01] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.46] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [1.28] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.54] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.43] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [9.93] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [3.99] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [2.55] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [7.94] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [5.07] C:\WINDOWS\EXE82.exe
O4 - HKLM\..\Run: [6.41] C:\WINDOWS\EXE82.exe


Make sure no programs or windows are open and click Fix checked.

Now delete the following file (if present):

C:\WINDOWS\EXE82.exe
User avatar
MaKaVeLi
Regular Member
 
Posts: 263
Joined: July 4th, 2005, 5:46 pm
Location: USA

Response to MaKaVeLi

Unread postby arqa » December 6th, 2005, 1:20 am

I followed your instructions.
Please advise on next step, thanks :)
Here's a new log

Logfile of HijackThis v1.99.1
Scan saved at 10:57:59 PM, on 12/5/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HJT\HIJACKTHIS.EXE
C:\PROGRAM FILES\ACCESSORIES\WORDPAD.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R3 - URLSearchHook: (no name) - {004E5031-F379-36E7-C64E-2F646F11EB4C} - C:\WINDOWS\Ylpyczxj.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F1 - win.ini: run=C:\WINDOWS\INET20066\SERVICES.EXE
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.02.3000.1002\EN-XU\STMAIN.DLL
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {35AF1B0D-BB36-11B8-8720-16550B86281A} - C:\WINDOWS\SYSTEM\IOK.DLL (file missing)
O2 - BHO: (no name) - {40531B38-BE86-9072-4037-188D011E16C5} - C:\WINDOWS\Ylpyczxj.dll
O2 - BHO: (no name) - {14F01645-ADDB-9559-80BE-F40A7209F49F} - C:\WINDOWS\SYSTEM\UYHGNRR.DLL (file missing)
O2 - BHO: (no name) - {19F01243-ADDE-925A-80CD-820A747DF49E} - C:\WINDOWS\SYSTEM\UYHGNRR.DLL (file missing)
O2 - BHO: (no name) - {20DD2241-80EE-A66C-AD8B-C0274239D9AF} - C:\WINDOWS\SYSTEM\UYHGNRR.DLL (file missing)
O2 - BHO: (no name) - {FF3C9AB9-7D75-3FA4-7D56-71C2CF244695} - C:\WINDOWS\SYSTEM\EKHOLEP.DLL (file missing)
O2 - BHO: (no name) - {FB3C9EB5-7D79-4EA4-7D21-7DC2BE564696} - C:\WINDOWS\SYSTEM\EKHOLEP.DLL (file missing)
O2 - BHO: (no name) - {9945A8B8-5F13-2ECB-5014-49EF8E666BA6} - C:\WINDOWS\SYSTEM\EKHOLEP.DLL (file missing)
O2 - BHO: (no name) - {372D100A-FE95-BC17-C6DD-A95F86B5DD9D} - C:\WINDOWS\SYSTEM\RHATK.DLL (file missing)
O2 - BHO: (no name) - {3365BE9F-520B-17D1-0261-5200C3BE8B9A} - C:\WINDOWS\SYSTEM\WAWIKALW.DLL (file missing)
O2 - BHO: (no name) - {865B860C-319E-7B42-9178-33A6F9DD3991} - C:\WINDOWS\SYSTEM\QUTLENRA.DLL (file missing)
O2 - BHO: (no name) - {C10B6C45-83D3-9F09-D97C-83ADA9C922C3} - C:\WINDOWS\SYSTEM\COFMETV.DLL (file missing)
O2 - BHO: (no name) - {AFE14282-AC15-BFCE-1C80-FC5A161A48CE} - C:\WINDOWS\SYSTEM\HVJICJOC.DLL (file missing)
O2 - BHO: (no name) - {CD5178B5-952F-DDA1-7426-C609F3642392} - C:\WINDOWS\SYSTEM\OLPS.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: (no name) - {E476C9D9-2448-1099-1AB7-2477A5C1599E} - C:\WINDOWS\SYSTEM\QOR.DLL (file missing)
O2 - BHO: (no name) - {E076CDD5-2444-6199-1AC0-2877D4B3599D} - C:\WINDOWS\SYSTEM\QOR.DLL (file missing)
O2 - BHO: (no name) - {33BD2248-988D-AF01-82FE-C06934F889CE} - C:\WINDOWS\SYSTEM\DWOEO.DLL (file missing)
O2 - BHO: (no name) - {37BD2644-9881-DE01-8289-CC69458A89CD} - C:\WINDOWS\SYSTEM\DWOEO.DLL (file missing)
O2 - BHO: (no name) - {60B62541-C0D4-FE00-82FE-C06934F889CF} - C:\WINDOWS\SYSTEM\DWOEO.DLL (file missing)
O2 - BHO: (no name) - {64B6214D-C0D8-8F00-8289-CC69458A89CC} - C:\WINDOWS\SYSTEM\DWOEO.DLL (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: (no name) - {73816D1E-83D6-EF5A-831E-DE1853AC9299} - C:\WINDOWS\SYSTEM\YBNMGUIA.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: Search - {B3C0AC9A-99DF-B2B0-8931-1CCF05329885} - C:\WINDOWS\Ylpyczxj.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [dlder] C:\WINDOWS\explorer\Explorer.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\en-us\msnappau.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [5QEKE7T5NG9WG2] C:\WINDOWS\SYSTEM\Ahm9.exe
O4 - HKLM\..\Run: [ihoodc] C:\WINDOWS\SYSTEM\ihoodc.exe
O4 - HKLM\..\Run: [Zoqtk] C:\PROGRAM FILES\EGOIMLJ\FCGMK.EXE
O4 - HKLM\..\Run: [PSof1] C:\WINDOWS\SYSTEM\PSof1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\SYSTEM\exp.exe
O4 - HKLM\..\Run: [Command] C:\WINDOWS\cmd\command.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\SYSTEM\wintask.exe
O4 - HKLM\..\Run: [OPR] C:\WINDOWS\SYSTEM\OPR.exe
O4 - HKLM\..\Run: [autoupdate] rundll32 C:\WINDOWS\SYSTEM\WUAUCLT.DLL,SHStart
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\SYSTEM\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [vidctrl] C:\WINDOWS\SYSTEM\VIDCTRL\VIDCTRL.EXE
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\adatiu.exe reg_run
O4 - HKLM\..\Run: [Windows Incontext] C:\WINDOWS\TEMP\INSEARCH.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [wzcqlrx] c:\windows\system\wzcqlrx.exe
O4 - HKLM\..\Run: [ysbinstall_1] C:\WINDOWS\SYSTEM\ysbinstall_1
O4 - HKLM\..\Run: [app] C:\WINDOWS\SYSTEM\app
O4 - HKLM\..\Run: [testit.exe] C:\WINDOWS\SYSTEM\testit.exe
O4 - HKLM\..\Run: [mmxp2passion.exe] C:\WINDOWS\SYSTEM\mmxp2passion.exe
O4 - HKLM\..\Run: [MediaGateway.exe] C:\WINDOWS\SYSTEM\MediaGateway.exe
O4 - HKLM\..\Run: [mediapluscash.exe] C:\WINDOWS\SYSTEM\mediapluscash.exe
O4 - HKLM\..\Run: [cashplusmedia.exe] C:\WINDOWS\SYSTEM\cashplusmedia.exe
O4 - HKLM\..\Run: [YVIBRVB] C:\WINDOWS\YVIBRVB.exe
O4 - HKLM\..\Run: [cashplusmedia1.exe] C:\WINDOWS\SYSTEM\cashplusmedia1.exe
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\SYSTEM\SPDEVSAW.EXE DO0605
O4 - HKLM\..\Run: [removeist.exe] C:\WINDOWS\SYSTEM\removeist.exe
O4 - HKLM\..\Run: [adcomplusanalytic.exe] C:\WINDOWS\SYSTEM\adcomplusanalytic.exe
O4 - HKLM\..\Run: [mc-58-12-] C:\WINDOWS\SYSTEM\mc-58-12-
O4 - HKLM\..\Run: [Yunguyo.exe] C:\WINDOWS\SYSTEM\Yunguyo.exe
O4 - HKLM\..\Run: [SSK3_B5.exe] C:\WINDOWS\SYSTEM\SSK3_B5.exe
O4 - HKLM\..\Run: [AntiAdware.exe] C:\WINDOWS\SYSTEM\AntiAdware.exe
O4 - HKLM\..\Run: [silent_partos.exe] C:\WINDOWS\SYSTEM\silent_partos.exe
O4 - HKLM\..\Run: [wfwall1.exe] C:\WINDOWS\SYSTEM\wfwall1.exe
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O4 - HKLM\..\Run: [webnexus.exe] C:\WINDOWS\SYSTEM\webnexus.exe
O4 - HKLM\..\Run: [pi1_72.exe] C:\WINDOWS\SYSTEM\pi1_72.exe
O4 - HKLM\..\Run: [AdCom9788-seedrevshare.exe] C:\WINDOWS\SYSTEM\AdCom9788-seedrevshare.exe
O4 - HKLM\..\Run: [Setup2-71.exe] C:\WINDOWS\SYSTEM\Setup2-71.exe
O4 - HKLM\..\Run: [russandmmx.exe] C:\WINDOWS\SYSTEM\russandmmx.exe
O4 - HKLM\..\Run: [ourcash.exe] C:\WINDOWS\SYSTEM\ourcash.exe
O4 - HKLM\..\Run: [wrapperouter.exe] C:\WINDOWS\SYSTEM\wrapperouter.exe
O4 - HKLM\..\Run: [mc-11] C:\WINDOWS\SYSTEM\mc-11
O4 - HKLM\..\Run: [drsmartload183a.exe] C:\WINDOWS\SYSTEM\drsmartload183a.exe
O4 - HKLM\..\Run: [mmxruss.exe] C:\WINDOWS\SYSTEM\mmxruss.exe
O4 - HKLM\..\Run: [AdCom-SeedRevShare.exe] C:\WINDOWS\SYSTEM\AdCom-SeedRevShare.exe
O4 - HKLM\..\Run: [whCC-CLICK.exe] C:\WINDOWS\SYSTEM\whCC-CLICK.exe
O4 - HKLM\..\Run: [{00-0A-A0-0D-ZN}] C:\WINDOWS\SYSTEM\RRDSREGO.EXE DO0605
O4 - HKLM\..\Run: [1226345244.exe] C:\WINDOWS\SYSTEM\1226345244.exe
O4 - HKLM\..\Run: [snss Launcher] "C:\Program Files\snss\snss.exe"
O4 - HKLM\..\Run: [load32] C:\WINDOWS\SYSTEM\winldra.exe
O4 - HKLM\..\Run: [Explorer32] C:\WINDOWS\SYSTEM\efsdfgxg.exe
O4 - HKLM\..\Run: [q3q99.exe] C:\WINDOWS\SYSTEM\q3q99.exe
O4 - HKLM\..\Run: [ujojsb] C:\WINDOWS\ujojsb.exe
O4 - HKLM\..\Run: [inrh95] C:\WINDOWS\SYSTEM\inrh95
O4 - HKLM\..\Run: [cstfh.exe] cstfh.exe
O4 - HKLM\..\Run: [dmlsa.exe] C:\WINDOWS\SYSTEM\dmlsa.exe
O4 - HKLM\..\Run: [Microsoft standard protector] C:\WINDOWS\INET20066\SOCKS.EXE 20066
O4 - HKLM\..\Run: [P2Passion_Setup.exe] C:\WINDOWS\SYSTEM\P2Passion_Setup.exe
O4 - HKLM\..\Run: [OSS] C:\WINDOWS\RLVKNLG.EXE -boot
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [AolAcsDaemon1] "C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE"
O4 - HKLM\..\RunServices: [rtvscn95] C:\PROGRA~1\SYMANT~1\SYMANT~1\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] C:\PROGRA~1\SYMANT~1\SYMANT~1\defwatch.exe
O4 - HKLM\..\RunServices: [PcCtlCom] C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY 2005\PCCTLCOM.EXE
O4 - HKLM\..\RunServices: [Shell] Explorer.exe C:\WINDOWS\SYSTEM\kernels32.exe
O4 - HKLM\..\RunServices: [Explorer64] C:\WINDOWS\SYSTEM\efsdfgxg.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Weather] C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE 1
O4 - HKCU\..\Run: [Zlyz] C:\WINDOWS\SYSTEM\eol.exe
O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
O4 - HKCU\..\Run: [FCEngine] "C:\Program Files\FCEngine\FCEngine.exe"
O4 - HKCU\..\Run: [CTYRIA] C:\WINDOWS\SYSTEM\CTYRIA.exe
O4 - HKCU\..\Run: [D3DDER] C:\WINDOWS\SYSTEM\D3DDER.exe
O4 - HKCU\..\Run: [MSRFOX] C:\WINDOWS\SYSTEM\MSRFOX.exe
O4 - HKCU\..\Run: [CLOUDSIM] C:\WINDOWS\SYSTEM\CLOUDSIM.exe
O4 - HKCU\..\Run: [FCMan] "C:\Program Files\FCMan\FCMan.exe"
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-110-12-0000122.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [aupd] C:\WINDOWS\SYSTEM\sywsvcs.exe
O4 - HKCU\..\Run: [Lrrn] "C:\Program Files\tpus\btws.exe" -vt ndrv
O4 - HKCU\..\Run: [desktop] C:\WINDOWS\SYSTEM\IDEMLOG.EXE
O4 - HKCU\..\Run: [UnSpyPC] "C:\Program Files\UnSpyPC\UnSpyPC.exe"
O4 - HKCU\..\RunServices: [aupd] C:\WINDOWS\SYSTEM\sywsvcs.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: Camio Viewer 3.2.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O4 - Startup: nrna.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\SYSTEM\spdevsaw.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Z_Start.lnk = C:\WINDOWS\SYSTEM\esysehiz.exe
O4 - Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.exe
O4 - Global Startup: Yadio Media Player.lnk = C:\Program Files\Yadio Media Player\Yadiostart.exe
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: &Add to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\WebMenuImg.htm
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O8 - Extra context menu item: Write a Review... - http://client.alexa.com/holiday/script/ ... review.htm
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0322.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0322.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\SYSTEM\maxspeed.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\SYSTEM\maxspeed.exe (file missing)
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com/ (file missing) (HKCU)
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
O9 - Extra button: Scan and protect your PC - {BF69DF00-4734-477F-8257-27CD04F88779} - C:\Program Files\UnSpyPC\UnSpyPC.exe (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Scan and protect your PC - {BF69DF00-4734-477F-8257-27CD04F88779} - C:\Program Files\UnSpyPC\UnSpyPC.exe (file missing) (HKCU)
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.dellnet.com/
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSIns ... a_ie_2.adp
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {94118C19-B178-4E43-BBE8-0EFDBB391BDB} (SysWebTelecom Class) - http://www.sponsoradulto.com/SysWebTelecom2.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/pages/scanner/WinFi ... nstall.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - ms-its:mhtml:file://c:\nosunex.mht!http://daemonlinks.net/script/ys.chm::/ysb_regular.cab
O16 - DPF: {972BB342-14A7-4660-83C1-51DDBEE171DB} - http://www.pacimedia.com/install/pcs_0009.exe
O16 - DPF: {0878B424-1F95-4E26-B5AB-F0D349D89650} - http://download.bargain-buddy.net/downl ... TING32.cab
O16 - DPF: {1E1B286C-88FF-11D2-8D96-D7ACAC95951F} - http://66.194.67.102/banner/with-report ... nerads.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - ms-its:mhtml:file://c:\nosunel.mht!http://213.158.119.23/script/lc.chm::/bridge-c46.cab
O16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} - http://www.pacimedia.com/install/pcs_0009.exe
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 85.255.113.138,85.255.112.13
O20 - Winlogon Notify: msupdate - C:\WINDOWS\SYSTEM\msupdate32.dll
O20 - Winlogon Notify: st3 - C:\WINDOWS\Q-3518960.DLL (file missing)
O21 - SSODL: hbeUYKE - {07D00A0E-AD7A-A0A4-EAF0-5B7C4D7E07D9} - C:\WINDOWS\SYSTEM\PZRKD.DLL (file missing)
O21 - SSODL: Module - {429F4BB8-7BF7-4152-8011-3C6F9EB7E892} - C:\WINDOWS\SYSTEM\chp.dll
O21 - SSODL: DDE - {F33812FB-F35C-4674-90F6-FD757C419C51} - C:\WINDOWS\SYSTEM\birdihuy32.dll
O21 - SSODL: OLE Module - {203B1C4D9-BC71-8916-38AD-9DEA5D213614} - C:\WINDOWS\SYSTEM\bre.dll (file missing)
O21 - SSODL: SysTray.Exsl - {6368D5FC-6F5C-4f5b-B164-E67214F67859} - C:\WINDOWS\SYSTEM\dgkaoipe.dll (file missing)
arqa
Regular Member
 
Posts: 55
Joined: December 1st, 2005, 1:21 am

Unread postby MaKaVeLi » December 6th, 2005, 7:44 pm

You have been infected with a very dangerous keylogger. Please follow these steps to remove it.

Download the keylogger remover here and save it to your desktop. Now double click on SSACleaner.exe and hit Check System. When it's finished scanning save the log to a Notepad file.

Run HijackThis and put a check next to the following lines:

R3 - URLSearchHook: (no name) - {004E5031-F379-36E7-C64E-2F646F11EB4C} - C:\WINDOWS\Ylpyczxj.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {35AF1B0D-BB36-11B8-8720-16550B86281A} - C:\WINDOWS\SYSTEM\IOK.DLL (file missing)
O2 - BHO: (no name) - {40531B38-BE86-9072-4037-188D011E16C5} - C:\WINDOWS\Ylpyczxj.dll
O2 - BHO: (no name) - {14F01645-ADDB-9559-80BE-F40A7209F49F} - C:\WINDOWS\SYSTEM\UYHGNRR.DLL (file missing)
O2 - BHO: (no name) - {19F01243-ADDE-925A-80CD-820A747DF49E} - C:\WINDOWS\SYSTEM\UYHGNRR.DLL (file missing)
O2 - BHO: (no name) - {20DD2241-80EE-A66C-AD8B-C0274239D9AF} - C:\WINDOWS\SYSTEM\UYHGNRR.DLL (file missing)
O2 - BHO: (no name) - {FF3C9AB9-7D75-3FA4-7D56-71C2CF244695} - C:\WINDOWS\SYSTEM\EKHOLEP.DLL (file missing)
O2 - BHO: (no name) - {FB3C9EB5-7D79-4EA4-7D21-7DC2BE564696} - C:\WINDOWS\SYSTEM\EKHOLEP.DLL (file missing)
O2 - BHO: (no name) - {9945A8B8-5F13-2ECB-5014-49EF8E666BA6} - C:\WINDOWS\SYSTEM\EKHOLEP.DLL (file missing)
O2 - BHO: (no name) - {372D100A-FE95-BC17-C6DD-A95F86B5DD9D} - C:\WINDOWS\SYSTEM\RHATK.DLL (file missing)
O2 - BHO: (no name) - {3365BE9F-520B-17D1-0261-5200C3BE8B9A} - C:\WINDOWS\SYSTEM\WAWIKALW.DLL (file missing)
O2 - BHO: (no name) - {865B860C-319E-7B42-9178-33A6F9DD3991} - C:\WINDOWS\SYSTEM\QUTLENRA.DLL (file missing)
O2 - BHO: (no name) - {C10B6C45-83D3-9F09-D97C-83ADA9C922C3} - C:\WINDOWS\SYSTEM\COFMETV.DLL (file missing)
O2 - BHO: (no name) - {AFE14282-AC15-BFCE-1C80-FC5A161A48CE} - C:\WINDOWS\SYSTEM\HVJICJOC.DLL (file missing)
O2 - BHO: (no name) - {CD5178B5-952F-DDA1-7426-C609F3642392} - C:\WINDOWS\SYSTEM\OLPS.DLL (file missing)
O2 - BHO: (no name) - {E476C9D9-2448-1099-1AB7-2477A5C1599E} - C:\WINDOWS\SYSTEM\QOR.DLL (file missing)
O2 - BHO: (no name) - {E076CDD5-2444-6199-1AC0-2877D4B3599D} - C:\WINDOWS\SYSTEM\QOR.DLL (file missing)
O2 - BHO: (no name) - {33BD2248-988D-AF01-82FE-C06934F889CE} - C:\WINDOWS\SYSTEM\DWOEO.DLL (file missing)
O2 - BHO: (no name) - {37BD2644-9881-DE01-8289-CC69458A89CD} - C:\WINDOWS\SYSTEM\DWOEO.DLL (file missing)
O2 - BHO: (no name) - {60B62541-C0D4-FE00-82FE-C06934F889CF} - C:\WINDOWS\SYSTEM\DWOEO.DLL (file missing)
O2 - BHO: (no name) - {64B6214D-C0D8-8F00-8289-CC69458A89CC} - C:\WINDOWS\SYSTEM\DWOEO.DLL (file missing)
O2 - BHO: (no name) - {73816D1E-83D6-EF5A-831E-DE1853AC9299} - C:\WINDOWS\SYSTEM\YBNMGUIA.DLL
O3 - Toolbar: Search - {B3C0AC9A-99DF-B2B0-8931-1CCF05329885} - C:\WINDOWS\Ylpyczxj.dll
O4 - HKLM\..\Run: [mmxp2passion.exe] C:\WINDOWS\SYSTEM\mmxp2passion.exe
O4 - HKLM\..\Run: [MediaGateway.exe] C:\WINDOWS\SYSTEM\MediaGateway.exe
O4 - HKLM\..\Run: [mediapluscash.exe] C:\WINDOWS\SYSTEM\mediapluscash.exe
O4 - HKLM\..\Run: [cashplusmedia.exe] C:\WINDOWS\SYSTEM\cashplusmedia.exe
O4 - HKLM\..\Run: [YVIBRVB] C:\WINDOWS\YVIBRVB.exe
O4 - HKLM\..\Run: [cashplusmedia1.exe] C:\WINDOWS\SYSTEM\cashplusmedia1.exe
O4 - HKLM\..\Run: [load32] C:\WINDOWS\SYSTEM\winldra.exe
O4 - HKCU\..\Run: [UnSpyPC] "C:\Program Files\UnSpyPC\UnSpyPC.exe"
O9 - Extra button: Scan and protect your PC - {BF69DF00-4734-477F-8257-27CD04F88779} - C:\Program Files\UnSpyPC\UnSpyPC.exe (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Scan and protect your PC - {BF69DF00-4734-477F-8257-27CD04F88779} - C:\Program Files\UnSpyPC\UnSpyPC.exe (file missing) (HKCU)
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSIns ... a_ie_2.adp
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {94118C19-B178-4E43-BBE8-0EFDBB391BDB} (SysWebTelecom Class) - http://www.sponsoradulto.com/SysWebTelecom2.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/pages/scanner/WinFi ... nstall.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - ms-its:mhtml:file://c:\nosunex.mht!http://daemonlinks.net/script/ys.chm::/ysb_regular.cab
O16 - DPF: {972BB342-14A7-4660-83C1-51DDBEE171DB} - http://www.pacimedia.com/install/pcs_0009.exe
O16 - DPF: {0878B424-1F95-4E26-B5AB-F0D349D89650} - http://download.bargain-buddy.net/downl ... TING32.cab
O16 - DPF: {1E1B286C-88FF-11D2-8D96-D7ACAC95951F} - http://66.194.67.102/banner/with-report ... nerads.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - ms-its:mhtml:file://c:\nosunel.mht!http://213.158.119.23/script/lc.chm::/bridge-c46.cab
O16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} - http://www.pacimedia.com/install/pcs_0009.exe
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 85.255.113.138,85.255.112.13

Make sure no programs or windows are open and click Fix checked.

Delete the following files (if present):

C:\WINDOWS\Ylpyczxj.dll
C:\WINDOWS\SYSTEM\IOK.DLL
C:\WINDOWS\SYSTEM\UYHGNRR.DLL
C:\WINDOWS\SYSTEM\EKHOLEP.DLL
C:\WINDOWS\SYSTEM\RHATK.DLL
C:\WINDOWS\SYSTEM\WAWIKALW.DLL
C:\WINDOWS\SYSTEM\QUTLENRA.DLL
C:\WINDOWS\SYSTEM\COFMETV.DLL
C:\WINDOWS\SYSTEM\HVJICJOC.DLL
C:\WINDOWS\SYSTEM\OLPS.DLL
C:\WINDOWS\SYSTEM\QOR.DLL
C:\WINDOWS\SYSTEM\DWOEO.DLL
C:\WINDOWS\SYSTEM\YBNMGUIA.DLL
C:\WINDOWS\SYSTEM\mmxp2passion.exe
C:\WINDOWS\SYSTEM\MediaGateway.exe
C:\WINDOWS\SYSTEM\mediapluscash.exe
C:\WINDOWS\YVIBRVB.exe
C:\WINDOWS\SYSTEM\cashplusmedia1.exe
C:\WINDOWS\SYSTEM\winldra.exe

Delete the following folder (if present):

C:\Program Files\UnSpyPC\

Call all your credit card and bank companies immediately and have them put a watch on your account in case your passwords, account info, SSN, and other personal data have been stolen.

Immediately change all your passwords to something nobody else would know.

Now reboot and post a new HijackThis log and the log from the SSACleaner.
User avatar
MaKaVeLi
Regular Member
 
Posts: 263
Joined: July 4th, 2005, 5:46 pm
Location: USA

Can't download SSAcleaner from link- Response to MaKaVeLi

Unread postby arqa » December 7th, 2005, 12:41 am

Hello MaKaVeLi,

Wonder if the keylogger entered between both HJT logs...
Is that the case?

Can't download SSAcleaner from link, when trying to save to
computer it crushes the Internet.
Please tell me Web address.
Thanks :)
arqa
Regular Member
 
Posts: 55
Joined: December 1st, 2005, 1:21 am

Unread postby MaKaVeLi » December 7th, 2005, 4:21 pm

Try downloading it from here and then continue with the fix.

http://research.sunbelt-software.com/ssaclean.cfm
User avatar
MaKaVeLi
Regular Member
 
Posts: 263
Joined: July 4th, 2005, 5:46 pm
Location: USA

Response to MaKaVaLi

Unread postby arqa » December 8th, 2005, 12:04 am

I went to this site to dowmload, but found the following

NOTE: Since the SSA-KeyLogger spyware cannot be installed on the following platforms, it is not necessary to run the SSA-KeyLogger Clean software:
Windows 95
Windows 98
Windows 98SE
Windows ME
Windows NT4

Is there other option?
Please advise.
Thanks:)
arqa
Regular Member
 
Posts: 55
Joined: December 1st, 2005, 1:21 am

Unread postby MaKaVeLi » December 8th, 2005, 4:23 pm

Maybe it's a new version. Please go to the following site and upload the following file:

Site: http://virusscan.jotti.org/

File: C:\WINDOWS\SYSTEM\winldra.exe

Put that into the top box and hit Submit. Wait for it scan then copy the results and paste it into your next reply.
User avatar
MaKaVeLi
Regular Member
 
Posts: 263
Joined: July 4th, 2005, 5:46 pm
Location: USA

Response to MaKaVeLi

Unread postby arqa » December 8th, 2005, 10:35 pm

I uploaded the file and this is a copy of the results

Jotti's malware scan 2.99-TRANSITION_TO_3.00


Service
Service load: 0% 100%

File: winldra.exe
Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 86995c50ab6a61fdc4b90c6d9a3f921d
Packers detected: PE_PATCH
Scanner results
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found Backdoor.Dumador.VM
ClamAV Found nothing
Dr.Web Found BackDoor.Dumaru.34
F-Prot Antivirus Found nothing
Fortinet Found W32/Dumaru.4A33-mm
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
UNA Found nothing
VBA32 Found BackDoor.Dumaru.34

Please tell me what to do next. Thanks :)


PS This appeared while writing to you...


Scan type: Realtime Protection Scan

Event: Virus Found!
Virus name: Bloodhound.Exploit.6
File: C:\WINDOWS\Temporary Internet Files\Content.IE5\KJFNU0L5\posting[1].htm
Location: Quarantine

User: Not-Logged-In
Action taken: Clean failed : Quarantine succeeded : Access denied
Date found: Thu Dec 08 21:32:38 2005
arqa
Regular Member
 
Posts: 55
Joined: December 1st, 2005, 1:21 am

Unread postby MaKaVeLi » December 8th, 2005, 11:11 pm

Send me a copy of the winldra.exe file located here:

C:\WINDOWS\SYSTEM\winldra.exe

To my email address:

MaKaVeLi03 [AT] gmail [DOT] com

Replace [AT] with @ and [DOT] with . and remove the spaces.

Make sure you do this first. When I get the email I'll give you a new set of instructions.
User avatar
MaKaVeLi
Regular Member
 
Posts: 263
Joined: July 4th, 2005, 5:46 pm
Location: USA

Unread postby MaKaVeLi » December 11th, 2005, 2:33 pm

Are you still there? Did you send the file?
User avatar
MaKaVeLi
Regular Member
 
Posts: 263
Joined: July 4th, 2005, 5:46 pm
Location: USA
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 46 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware