Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:28:17 AM, on 1/16/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\sstray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Full Tilt Poker\FullTiltPoker.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://worldofwarcraft.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) -
http://www.eset.eu/OnlineScanner.cabO23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 4874 bytes
========================
Windows Registry Editor Version 5.00
; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.6.0
; Results at 1/16/2009 3:16:54 AM for strings:
; 'avast'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS
[HKEY_LOCAL_MACHINE\SOFTWARE\ALWIL Software\Avast]
[HKEY_LOCAL_MACHINE\SOFTWARE\ALWIL Software\Avast\4.0]
[HKEY_LOCAL_MACHINE\SOFTWARE\ALWIL Software\Avast\4.0]
"Avast4DataFolder"="C:\\Program Files\\Alwil Software\\Avast4\\DATA"
"Avast4SkinFolder"="C:\\Program Files\\Alwil Software\\Avast4\\DATA\\Skin"
"Avast4ProgramFolder"="C:\\Program Files\\Alwil Software\\Avast4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\avast]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.aswcs]
"Content Type"="application/avast-aswcs"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.asws]
"Content Type"="application/avast-asws"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\aswcsfile]
@="avast! Compressed Skin"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\aswcsfile\shell\open\command]
@="\"C:\\Program Files\\Alwil Software\\Avast4\\ashSimpl.exe\" \"%1\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\aswsfile]
@="avast! Skin"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\aswsfile\shell\open\command]
@="\"C:\\Program Files\\Alwil Software\\Avast4\\ashSimpl.exe\" \"%1\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\avast]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\avast\ShellEx]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\avast\ShellEx\ContextMenuHandlers]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
@="avast"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}\InProcServer32]
@="C:\\Program Files\\Alwil Software\\Avast4\\ashShell.dll"
"ReleaseName"="C:\\Program Files\\Alwil Software\\Avast4\\ashShell.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\avast]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\Client\Extensions]
"avast! 4"="4.0;C:\\Program Files\\Alwil Software\\Avast4\\ashOutXt.dll;1;10000111111000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\avast!]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ashAvast.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ashAvast.exe]
"Path"="C:\\Program Files\\Alwil Software\\Avast4"
@="C:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-2007.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-2007.com\www]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-downloads.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-downloads.com\www]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-hq.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-hq.com\www]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-avast.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-avast.com\www]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\free-software-center.com\avast]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\free-software-center.com\www.avast]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\telecharger-avast.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\telecharger-avast.com\www]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{472083B0-C522-11CF-8763-00608CC02F24}"="avast"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\avast!]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\avast!]
"DisplayName"="avast! Antivirus"
"HelpLink"="http://www.avast.com"
"UrlInfoAbout"="http://www.avast.com"
"UrlUpdateInfo"="http://www.avast.com"
"InstallLocation"="C:\\PROGRA~1\\ALWILS~1\\Avast4"
"InstallSource"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\setup"
"DisplayIcon"="C:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"
"UninstallString"="C:\\Program Files\\Alwil Software\\Avast4\\aswRunDll.exe \"C:\\Program Files\\Alwil Software\\Avast4\\Setup\\setiface.dll\",RunSetup"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\VirtualDeviceDrivers]
; Contents of value:
; C:\Program Files\Alwil Software\Avast4\aswMonVd.dll
;
"VDD"=hex(7):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,20,00,\
46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,00,20,00,53,\
00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,5c,00,41,00,76,00,61,00,73,00,\
74,00,34,00,5c,00,61,00,73,00,77,00,4d,00,6f,00,6e,00,56,00,64,00,2e,00,64,\
00,6c,00,6c,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AAVMKER4\0000]
"DeviceDesc"="avast! Asynchronous Virus Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASWMON2\0000]
"DeviceDesc"="avast! Standard Shield Support"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASWSP\0000]
"DeviceDesc"="avast! Self Protection"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASWTDI\0000]
"DeviceDesc"="avast! Network Shield Support"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASWUPDSV\0000]
"DeviceDesc"="avast! iAVS4 Control Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVAST!_ANTIVIRUS]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVAST!_ANTIVIRUS\0000]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVAST!_ANTIVIRUS\0000]
"Service"="avast! Antivirus"
"DeviceDesc"="avast! Antivirus"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVAST!_ANTIVIRUS\0000\Control]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVAST!_ANTIVIRUS\0000\Control]
"ActiveService"="avast! Antivirus"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVAST!_MAIL_SCANNER]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVAST!_MAIL_SCANNER\0000]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVAST!_MAIL_SCANNER\0000]
"Service"="avast! Mail Scanner"
"DeviceDesc"="avast! Mail Scanner"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVAST!_WEB_SCANNER]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVAST!_WEB_SCANNER\0000]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVAST!_WEB_SCANNER\0000]
"Service"="avast! Web Scanner"
"DeviceDesc"="avast! Web Scanner"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Aavmker4]
"DisplayName"="avast! Asynchronous Virus Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aswFsBlk]
"Description"="avast! mini-filter driver (aswFsBlk)"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aswMon2]
"DisplayName"="avast! Standard Shield Support"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aswMon2\Parameters]
"ProgramFolder"="\\Device\\HarddiskVolume1\\Program Files\\Alwil Software\\Avast4"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aswSP]
"DisplayName"="avast! Self Protection"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aswSP\Parameters]
"ProgramFolder"="\\Device\\HarddiskVolume1\\Program Files\\Alwil Software\\Avast4"
"ProgramFolder2"="\\DosDevices\\C:\\Program Files\\Alwil Software\\Avast4"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aswTdi]
"DisplayName"="avast! Network Shield Support"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aswUpdSv]
; Contents of value:
; "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"
"ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\
6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,\
00,20,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,5c,00,41,00,76,00,\
61,00,73,00,74,00,34,00,5c,00,61,00,73,00,77,00,55,00,70,00,64,00,53,00,76,\
00,2e,00,65,00,78,00,65,00,22,00,00,00
"DisplayName"="avast! iAVS4 Control Service"
"Description"="Provides automatic updating for the avast! antivirus."
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avast! Antivirus]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avast! Antivirus]
; Contents of value:
; "C:\Program Files\Alwil Software\Avast4\ashServ.exe"
"ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\
6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,\
00,20,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,5c,00,41,00,76,00,\
61,00,73,00,74,00,34,00,5c,00,61,00,73,00,68,00,53,00,65,00,72,00,76,00,2e,\
00,65,00,78,00,65,00,22,00,00,00
"DisplayName"="avast! Antivirus"
"Description"="Manages and implements avast! antivirus services for this computer. This includes the resident protection, the virus chest and the scheduler."
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avast! Antivirus\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avast! Antivirus\Enum]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avast! Antivirus\Enum]
"0"="Root\\LEGACY_AVAST!_ANTIVIRUS\\0000"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avast! Mail Scanner]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avast! Mail Scanner]
; Contents of value:
; "C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service
"ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\
6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,\
00,20,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,5c,00,41,00,76,00,\
61,00,73,00,74,00,34,00,5c,00,61,00,73,00,68,00,4d,00,61,00,69,00,53,00,76,\
00,2e,00,65,00,78,00,65,00,22,00,20,00,2f,00,73,00,65,00,72,00,76,00,69,00,\
63,00,65,00,00,00
"DisplayName"="avast! Mail Scanner"
; Contents of value:
; avast! Antivirus
;
"DependOnService"=hex(7):61,00,76,00,61,00,73,00,74,00,21,00,20,00,41,00,6e,00,\
74,00,69,00,76,00,69,00,72,00,75,00,73,00,00,00,00,00
"Description"="Implements mail scanning for avast! antivirus."
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avast! Mail Scanner\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avast! Mail Scanner\Enum]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avast! Mail Scanner\Enum]
"0"="Root\\LEGACY_AVAST!_MAIL_SCANNER\\0000"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avast! Web Scanner]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avast! Web Scanner]
; Contents of value:
; "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service
"ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\
6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,\
00,20,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,5c,00,41,00,76,00,\
61,00,73,00,74,00,34,00,5c,00,61,00,73,00,68,00,57,00,65,00,62,00,53,00,76,\
00,2e,00,65,00,78,00,65,00,22,00,20,00,2f,00,73,00,65,00,72,00,76,00,69,00,\
63,00,65,00,00,00
"DisplayName"="avast! Web Scanner"
; Contents of value:
; avast! Antivirus
;
"DependOnService"=hex(7):61,00,76,00,61,00,73,00,74,00,21,00,20,00,41,00,6e,00,\
74,00,69,00,76,00,69,00,72,00,75,00,73,00,00,00,00,00
"Description"="Implements web (HTTP) scanning for avast! antivirus."
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avast! Web Scanner\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avast! Web Scanner\Enum]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avast! Web Scanner\Enum]
"0"="Root\\LEGACY_AVAST!_WEB_SCANNER\\0000"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Antivirus]
; Contents of value:
; avast!
; Antivirus
;
"Sources"=hex(7):61,00,76,00,61,00,73,00,74,00,21,00,00,00,41,00,6e,00,74,00,\
69,00,76,00,69,00,72,00,75,00,73,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Antivirus\avast!]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Antivirus\avast!]
"CategoryMessageFile"="C:\\Program Files\\Alwil Software\\Avast4\\aswRes.dll"
"EventMessageFile"="C:\\Program Files\\Alwil Software\\Avast4\\aswRes.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\VirtualDeviceDrivers]
; Contents of value:
; C:\Program Files\Alwil Software\Avast4\aswMonVd.dll
;
"VDD"=hex(7):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,20,00,\
46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,00,20,00,53,\
00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,5c,00,41,00,76,00,61,00,73,00,\
74,00,34,00,5c,00,61,00,73,00,77,00,4d,00,6f,00,6e,00,56,00,64,00,2e,00,64,\
00,6c,00,6c,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AAVMKER4\0000]
"DeviceDesc"="avast! Asynchronous Virus Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ASWMON2\0000]
"DeviceDesc"="avast! Standard Shield Support"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ASWSP\0000]
"DeviceDesc"="avast! Self Protection"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ASWTDI\0000]
"DeviceDesc"="avast! Network Shield Support"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ASWUPDSV\0000]
"DeviceDesc"="avast! iAVS4 Control Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVAST!_ANTIVIRUS]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVAST!_ANTIVIRUS\0000]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVAST!_ANTIVIRUS\0000]
"Service"="avast! Antivirus"
"DeviceDesc"="avast! Antivirus"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVAST!_MAIL_SCANNER]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVAST!_MAIL_SCANNER\0000]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVAST!_MAIL_SCANNER\0000]
"Service"="avast! Mail Scanner"
"DeviceDesc"="avast! Mail Scanner"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVAST!_WEB_SCANNER]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVAST!_WEB_SCANNER\0000]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVAST!_WEB_SCANNER\0000]
"Service"="avast! Web Scanner"
"DeviceDesc"="avast! Web Scanner"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Aavmker4]
"DisplayName"="avast! Asynchronous Virus Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\aswFsBlk]
"Description"="avast! mini-filter driver (aswFsBlk)"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\aswMon2]
"DisplayName"="avast! Standard Shield Support"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\aswMon2\Parameters]
"ProgramFolder"="\\Device\\HarddiskVolume1\\Program Files\\Alwil Software\\Avast4"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\aswSP]
"DisplayName"="avast! Self Protection"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\aswSP\Parameters]
"ProgramFolder"="\\Device\\HarddiskVolume1\\Program Files\\Alwil Software\\Avast4"
"ProgramFolder2"="\\DosDevices\\C:\\Program Files\\Alwil Software\\Avast4"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\aswTdi]
"DisplayName"="avast! Network Shield Support"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\aswUpdSv]
; Contents of value:
; "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"
"ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\
6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,\
00,20,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,5c,00,41,00,76,00,\
61,00,73,00,74,00,34,00,5c,00,61,00,73,00,77,00,55,00,70,00,64,00,53,00,76,\
00,2e,00,65,00,78,00,65,00,22,00,00,00
"DisplayName"="avast! iAVS4 Control Service"
"Description"="Provides automatic updating for the avast! antivirus."
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\avast! Antivirus]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\avast! Antivirus]
; Contents of value:
; "C:\Program Files\Alwil Software\Avast4\ashServ.exe"
"ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\
6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,\
00,20,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,5c,00,41,00,76,00,\
61,00,73,00,74,00,34,00,5c,00,61,00,73,00,68,00,53,00,65,00,72,00,76,00,2e,\
00,65,00,78,00,65,00,22,00,00,00
"DisplayName"="avast! Antivirus"
"Description"="Manages and implements avast! antivirus services for this computer. This includes the resident protection, the virus chest and the scheduler."
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\avast! Antivirus\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\avast! Mail Scanner]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\avast! Mail Scanner]
; Contents of value:
; "C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service
"ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\
6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,\
00,20,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,5c,00,41,00,76,00,\
61,00,73,00,74,00,34,00,5c,00,61,00,73,00,68,00,4d,00,61,00,69,00,53,00,76,\
00,2e,00,65,00,78,00,65,00,22,00,20,00,2f,00,73,00,65,00,72,00,76,00,69,00,\
63,00,65,00,00,00
"DisplayName"="avast! Mail Scanner"
; Contents of value:
; avast! Antivirus
;
"DependOnService"=hex(7):61,00,76,00,61,00,73,00,74,00,21,00,20,00,41,00,6e,00,\
74,00,69,00,76,00,69,00,72,00,75,00,73,00,00,00,00,00
"Description"="Implements mail scanning for avast! antivirus."
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\avast! Mail Scanner\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\avast! Web Scanner]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\avast! Web Scanner]
; Contents of value:
; "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service
"ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\
6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,\
00,20,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,5c,00,41,00,76,00,\
61,00,73,00,74,00,34,00,5c,00,61,00,73,00,68,00,57,00,65,00,62,00,53,00,76,\
00,2e,00,65,00,78,00,65,00,22,00,20,00,2f,00,73,00,65,00,72,00,76,00,69,00,\
63,00,65,00,00,00
"DisplayName"="avast! Web Scanner"
; Contents of value:
; avast! Antivirus
;
"DependOnService"=hex(7):61,00,76,00,61,00,73,00,74,00,21,00,20,00,41,00,6e,00,\
74,00,69,00,76,00,69,00,72,00,75,00,73,00,00,00,00,00
"Description"="Implements web (HTTP) scanning for avast! antivirus."
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\avast! Web Scanner\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Antivirus]
; Contents of value:
; avast!
; Antivirus
;
"Sources"=hex(7):61,00,76,00,61,00,73,00,74,00,21,00,00,00,41,00,6e,00,74,00,\
69,00,76,00,69,00,72,00,75,00,73,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Antivirus\avast!]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Antivirus\avast!]
"CategoryMessageFile"="C:\\Program Files\\Alwil Software\\Avast4\\aswRes.dll"
"EventMessageFile"="C:\\Program Files\\Alwil Software\\Avast4\\aswRes.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers]
; Contents of value:
; C:\Program Files\Alwil Software\Avast4\aswMonVd.dll
;
"VDD"=hex(7):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,20,00,\
46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,00,20,00,53,\
00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,5c,00,41,00,76,00,61,00,73,00,\
74,00,34,00,5c,00,61,00,73,00,77,00,4d,00,6f,00,6e,00,56,00,64,00,2e,00,64,\
00,6c,00,6c,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AAVMKER4\0000]
"DeviceDesc"="avast! Asynchronous Virus Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMON2\0000]
"DeviceDesc"="avast! Standard Shield Support"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWSP\0000]
"DeviceDesc"="avast! Self Protection"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWTDI\0000]
"DeviceDesc"="avast! Network Shield Support"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWUPDSV\0000]
"DeviceDesc"="avast! iAVS4 Control Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVAST!_ANTIVIRUS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVAST!_ANTIVIRUS\0000]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVAST!_ANTIVIRUS\0000]
"Service"="avast! Antivirus"
"DeviceDesc"="avast! Antivirus"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVAST!_ANTIVIRUS\0000\Control]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVAST!_ANTIVIRUS\0000\Control]
"ActiveService"="avast! Antivirus"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVAST!_MAIL_SCANNER]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVAST!_MAIL_SCANNER\0000]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVAST!_MAIL_SCANNER\0000]
"Service"="avast! Mail Scanner"
"DeviceDesc"="avast! Mail Scanner"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVAST!_WEB_SCANNER]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVAST!_WEB_SCANNER\0000]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVAST!_WEB_SCANNER\0000]
"Service"="avast! Web Scanner"
"DeviceDesc"="avast! Web Scanner"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Aavmker4]
"DisplayName"="avast! Asynchronous Virus Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aswFsBlk]
"Description"="avast! mini-filter driver (aswFsBlk)"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aswMon2]
"DisplayName"="avast! Standard Shield Support"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aswMon2\Parameters]
"ProgramFolder"="\\Device\\HarddiskVolume1\\Program Files\\Alwil Software\\Avast4"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aswSP]
"DisplayName"="avast! Self Protection"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aswSP\Parameters]
"ProgramFolder"="\\Device\\HarddiskVolume1\\Program Files\\Alwil Software\\Avast4"
"ProgramFolder2"="\\DosDevices\\C:\\Program Files\\Alwil Software\\Avast4"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aswTdi]
"DisplayName"="avast! Network Shield Support"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aswUpdSv]
; Contents of value:
; "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"
"ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\
6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,\
00,20,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,5c,00,41,00,76,00,\
61,00,73,00,74,00,34,00,5c,00,61,00,73,00,77,00,55,00,70,00,64,00,53,00,76,\
00,2e,00,65,00,78,00,65,00,22,00,00,00
"DisplayName"="avast! iAVS4 Control Service"
"Description"="Provides automatic updating for the avast! antivirus."
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avast! Antivirus]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avast! Antivirus]
; Contents of value:
; "C:\Program Files\Alwil Software\Avast4\ashServ.exe"
"ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\
6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,\
00,20,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,5c,00,41,00,76,00,\
61,00,73,00,74,00,34,00,5c,00,61,00,73,00,68,00,53,00,65,00,72,00,76,00,2e,\
00,65,00,78,00,65,00,22,00,00,00
"DisplayName"="avast! Antivirus"
"Description"="Manages and implements avast! antivirus services for this computer. This includes the resident protection, the virus chest and the scheduler."
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avast! Antivirus\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avast! Antivirus\Enum]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avast! Antivirus\Enum]
"0"="Root\\LEGACY_AVAST!_ANTIVIRUS\\0000"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avast! Mail Scanner]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avast! Mail Scanner]
; Contents of value:
; "C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service
"ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\
6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,\
00,20,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,5c,00,41,00,76,00,\
61,00,73,00,74,00,34,00,5c,00,61,00,73,00,68,00,4d,00,61,00,69,00,53,00,76,\
00,2e,00,65,00,78,00,65,00,22,00,20,00,2f,00,73,00,65,00,72,00,76,00,69,00,\
63,00,65,00,00,00
"DisplayName"="avast! Mail Scanner"
; Contents of value:
; avast! Antivirus
;
"DependOnService"=hex(7):61,00,76,00,61,00,73,00,74,00,21,00,20,00,41,00,6e,00,\
74,00,69,00,76,00,69,00,72,00,75,00,73,00,00,00,00,00
"Description"="Implements mail scanning for avast! antivirus."
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avast! Mail Scanner\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avast! Mail Scanner\Enum]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avast! Mail Scanner\Enum]
"0"="Root\\LEGACY_AVAST!_MAIL_SCANNER\\0000"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avast! Web Scanner]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avast! Web Scanner]
; Contents of value:
; "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service
"ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\
6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,\
00,20,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,5c,00,41,00,76,00,\
61,00,73,00,74,00,34,00,5c,00,61,00,73,00,68,00,57,00,65,00,62,00,53,00,76,\
00,2e,00,65,00,78,00,65,00,22,00,20,00,2f,00,73,00,65,00,72,00,76,00,69,00,\
63,00,65,00,00,00
"DisplayName"="avast! Web Scanner"
; Contents of value:
; avast! Antivirus
;
"DependOnService"=hex(7):61,00,76,00,61,00,73,00,74,00,21,00,20,00,41,00,6e,00,\
74,00,69,00,76,00,69,00,72,00,75,00,73,00,00,00,00,00
"Description"="Implements web (HTTP) scanning for avast! antivirus."
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avast! Web Scanner\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avast! Web Scanner\Enum]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avast! Web Scanner\Enum]
"0"="Root\\LEGACY_AVAST!_WEB_SCANNER\\0000"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Antivirus]
; Contents of value:
; avast!
; Antivirus
;
"Sources"=hex(7):61,00,76,00,61,00,73,00,74,00,21,00,00,00,41,00,6e,00,74,00,\
69,00,76,00,69,00,72,00,75,00,73,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Antivirus\avast!]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Antivirus\avast!]
"CategoryMessageFile"="C:\\Program Files\\Alwil Software\\Avast4\\aswRes.dll"
"EventMessageFile"="C:\\Program Files\\Alwil Software\\Avast4\\aswRes.dll"
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast]
@="avast! antivirus"
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Automatic VPS update]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Automatic VPS update\.Current]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Automatic VPS update\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\vpsupd.wav"
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Automatic VPS update\.Modified]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Automatic VPS update\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\vpsupd.wav"
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Detection of suspicious message]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Detection of suspicious message\.Current]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Detection of suspicious message\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\suspic.wav"
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Detection of suspicious message\.Modified]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Detection of suspicious message\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\suspic.wav"
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Mouse over the simple user interface button]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Mouse over the simple user interface button\.Current]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Mouse over the simple user interface button\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\hover.wav"
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Mouse over the simple user interface button\.Modified]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Mouse over the simple user interface button\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\hover.wav"
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Other malware found]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Other malware found\.Current]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Other malware found\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\malfound.wav"
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Other malware found\.Modified]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Other malware found\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\malfound.wav"
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Program end]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Program end\.Current]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Program end\.Modified]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Program start]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Program start\.Current]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Program start\.Modified]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Simple user interface button pressed]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Simple user interface button pressed\.Current]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Simple user interface button pressed\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\press.wav"
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Simple user interface button pressed\.Modified]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Simple user interface button pressed\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\press.wav"
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Task done]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Task done\.Current]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Task done\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\ready.wav"
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Task done\.Modified]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Task done\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\ready.wav"
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Virus found]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Virus found\.Current]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Virus found\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\virfound.wav"
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Virus found\.Modified]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\Avast\Virus found\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\virfound.wav"
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-2007.com]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-2007.com\www]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-downloads.com]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-downloads.com\www]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-hq.com]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-hq.com\www]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-avast.com]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-avast.com\www]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\free-software-center.com\avast]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\free-software-center.com\www.avast]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\telecharger-avast.com]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\telecharger-avast.com\www]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast]
@="avast! antivirus"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Automatic VPS update]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Automatic VPS update\.Current]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Automatic VPS update\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\vpsupd.wav"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Automatic VPS update\.Modified]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Automatic VPS update\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\vpsupd.wav"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Detection of suspicious message]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Detection of suspicious message\.Current]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Detection of suspicious message\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\suspic.wav"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Detection of suspicious message\.Modified]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Detection of suspicious message\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\suspic.wav"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Mouse over the simple user interface button]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Mouse over the simple user interface button\.Current]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Mouse over the simple user interface button\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\hover.wav"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Mouse over the simple user interface button\.Modified]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Mouse over the simple user interface button\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\hover.wav"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Other malware found]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Other malware found\.Current]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Other malware found\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\malfound.wav"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Other malware found\.Modified]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Other malware found\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\malfound.wav"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Program end]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Program end\.Current]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Program end\.Modified]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Program start]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Program start\.Current]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Program start\.Modified]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Simple user interface button pressed]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Simple user interface button pressed\.Current]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Simple user interface button pressed\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\press.wav"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Simple user interface button pressed\.Modified]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Simple user interface button pressed\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\press.wav"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Task done]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Task done\.Current]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Task done\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\ready.wav"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Task done\.Modified]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Task done\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\ready.wav"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Virus found]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Virus found\.Current]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Virus found\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\virfound.wav"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Virus found\.Modified]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\AppEvents\Schemes\Apps\Avast\Virus found\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\virfound.wav"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\ALWIL Software\Avast]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\ALWIL Software\Avast\4.0]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\ALWIL Software\Avast\4.0\ashAvast]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\ALWIL Software\Avast\4.0\ashAvast\splash]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\ALWIL Software\Avast\4.0\ashChest]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\ALWIL Software\Avast\4.0\ashChest\ChestFileList]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\ALWIL Software\Avast\4.0\ashChest\Settings]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\ALWIL Software\Avast\4.0\ashSimpl]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\ALWIL Software\Avast\4.0\ashSimpl\Settings]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\ALWIL Software\Avast\4.0\ashUInt]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\ALWIL Software\Avast\4.0\ashUInt\Settings]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\BillP Studios\Detected\ActiveTasks]
"C:\\PROGRAM FILES\\ALWIL SOFTWARE\\Avast4\\aswUpdSv.exe"="11/05/2008 2:54 AM"
"C:\\PROGRAM FILES\\ALWIL SOFTWARE\\Avast4\\ashServ.exe"="11/05/2008 2:54 AM"
"C:\\Program Files\\Alwil Software\\Avast4\\ashDisp.exe"="11/05/2008 2:54 AM"
"C:\\PROGRAM FILES\\ALWIL SOFTWARE\\Avast4\\ashMaiSv.exe"="11/05/2008 2:54 AM"
"C:\\PROGRAM FILES\\ALWIL SOFTWARE\\Avast4\\ashWebSv.exe"="11/05/2008 2:54 AM"
"C:\\PROGRAM FILES\\ALWIL SOFTWARE\\Avast4\\ashSimpl.exe"="11/05/2008 3:39 AM"
"C:\\PROGRAM FILES\\ALWIL SOFTWARE\\Avast4\\Setup\\AVAST.SETUP"="11/05/2008 11:48 AM"
"C:\\PROGRAM FILES\\ALWIL SOFTWARE\\Avast4\\ashAvast.exe"="01/12/2009 10:01 PM"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\BillP Studios\Detected\Services]
"C:\\Program Files\\Alwil Software\\Avast4\\aswUpdSv.exe"="11/05/2008 2:54 AM"
"C:\\Program Files\\Alwil Software\\Avast4\\ashServ.exe"="11/05/2008 2:54 AM"
"C:\\PROGRAM FILES\\ALWIL SOFTWARE\\AVAST4\\ASHMAISV.EXE"="11/13/2008 1:59 AM"
"C:\\PROGRAM FILES\\ALWIL SOFTWARE\\AVAST4\\ASHWEBSV.EXE"="11/13/2008 1:59 AM"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\BillP Studios\Detected\Startup]
"C:\\Program Files\\Alwil Software\\Avast4\\ashDisp.exe"="11/05/2008 2:54 AM"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\BillP Studios\WinPatrol\Run]
"C:\\Program Files\\Alwil Software\\Avast4\\ashDisp.exe"="1"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\BillP Studios\WinPatrol\Services]
"avast! iAVS4 Control Service"="700"
"avast! Antivirus"="700"
"avast! Mail Scanner"="700"
"avast! Web Scanner"="700"
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\avast! Antivirus]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-2007.com]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-2007.com\www]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-downloads.com]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-downloads.com\www]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-hq.com]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-hq.com\www]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-avast.com]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-avast.com\www]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\free-software-center.com\avast]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\free-software-center.com\www.avast]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\telecharger-avast.com]
[HKEY_USERS\S-1-5-21-1123561945-1177238915-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\telecharger-avast.com\www]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast]
@="avast! antivirus"
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Automatic VPS update]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Automatic VPS update\.Current]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Automatic VPS update\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\vpsupd.wav"
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Automatic VPS update\.Modified]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Automatic VPS update\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\vpsupd.wav"
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Detection of suspicious message]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Detection of suspicious message\.Current]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Detection of suspicious message\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\suspic.wav"
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Detection of suspicious message\.Modified]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Detection of suspicious message\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\suspic.wav"
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Mouse over the simple user interface button]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Mouse over the simple user interface button\.Current]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Mouse over the simple user interface button\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\hover.wav"
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Mouse over the simple user interface button\.Modified]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Mouse over the simple user interface button\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\hover.wav"
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Other malware found]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Other malware found\.Current]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Other malware found\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\malfound.wav"
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Other malware found\.Modified]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Other malware found\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\malfound.wav"
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Program end]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Program end\.Current]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Program end\.Modified]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Program start]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Program start\.Current]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Program start\.Modified]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Simple user interface button pressed]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Simple user interface button pressed\.Current]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Simple user interface button pressed\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\press.wav"
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Simple user interface button pressed\.Modified]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Simple user interface button pressed\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\press.wav"
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Task done]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Task done\.Current]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Task done\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\ready.wav"
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Task done\.Modified]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Task done\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\ready.wav"
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Virus found]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Virus found\.Current]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Virus found\.Current]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\virfound.wav"
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Virus found\.Modified]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\Avast\Virus found\.Modified]
@="C:\\Program Files\\Alwil Software\\Avast4\\English\\virfound.wav"
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-2007.com]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-2007.com\www]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-downloads.com]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-downloads.com\www]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-hq.com]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avast-hq.com\www]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-avast.com]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-avast.com\www]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\free-software-center.com\avast]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\free-software-center.com\www.avast]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\telecharger-avast.com]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\telecharger-avast.com\www]
; End Of The Log...
=====================
01/16/09 02:59:09 [Info]: BlackLight Engine 1.0.70 initialized
01/16/09 02:59:10 [Info]: OS: 5.1 build 2600 (Service Pack 2)
01/16/09 02:59:10 [Note]: 7019 4
01/16/09 02:59:10 [Note]: 7005 0
01/16/09 02:59:12 [Note]: 7006 0
01/16/09 02:59:12 [Note]: 7011 1548
01/16/09 02:59:12 [Note]: 7035 0
01/16/09 02:59:12 [Note]: 7026 0
01/16/09 02:59:12 [Note]: 7026 0
01/16/09 02:59:15 [Note]: FSRAW library version 1.7.1024
01/16/09 03:05:52 [Note]: 7007 0
Obviously no luck on Avast.
Hope I got everything correct. Talk to you soon. And as always
Thank You Again!