[Kill Explorer]
[Unregister Dlls]
[Win32 Services - Non-Microsoft Only]
YY -> (FWSvc) Firewall service [Win32_Own | On_Demand | Stopped] ->
[Driver Services - Non-Microsoft Only]
YY -> (FOPN) FOPN [File_System | Boot | Stopped] -> %SystemRoot%\System32\Drivers\FOPN.sys
YY -> (musbehco) musbehco [Kernel | On_Demand | Stopped] -> %SystemDrive%\DOCUME~1\%Username%\LOCALS~1\Temp\musbehco.sys
[Registry - Non-Microsoft Only]
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
YN -> [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [fairydom]
YN -> {79FEACFF-FFCE-815E-A900-316290B5B738} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\System32\Ecjfcehc.dll [Microsoft DirectXb]
NY -> {9A687AAC-F227-4138-A626-FE5EFD603479} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\tdomgafw.dll [tdomgafw]
YY -> {E87A380D-C707-4DAE-B847-2D9FAE3CC752} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\wetkadmr.dll [wetkadmr]
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
YY -> {CE86878F-D099-4FFC-A4DC-E51D192063B1} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\yayaYRkK.dll []
< SharedTaskScheduler [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
YN -> fairydom [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [ ]
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
YY -> yayaYRkK -> %SystemRoot%\system32\yayaYRkK.dll
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > ->
YN -> HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://internetsearchservice.com
YN -> HKEY_LOCAL_MACHINE\: Main\\Search Bar -> http://internetsearchservice.com/ie6.html
YN -> HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://internetsearchservice.com
YN -> HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://internetsearchservice.com
< Internet Explorer Settings [HKEY_CURRENT_USER\] > ->
YN -> HKEY_CURRENT_USER\: Main\\Default_Search_URL -> http://internetsearchservice.com
YN -> HKEY_CURRENT_USER\: Main\\Search Bar -> http://internetsearchservice.com/ie6.html
YN -> HKEY_CURRENT_USER\: Main\\Search Page -> http://internetsearchservice.com
YN -> HKEY_CURRENT_USER\: Search\\SearchAssistant -> http://internetsearchservice.com
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YY -> {100EB1FD-D03E-47FD-81F3-EE91287F9465} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\ShoppingReport\Bin\2.0.26\ShoppingReport.dll [ShoppingReport]
YY -> {18CB1A7B-94CD-4582-8022-ADA16851E44B} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\CenterLock\CenterLock.dll [CenterLock Class]
YN -> {36ADA89D-2440-4DC4-820A-3A05E8630935} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\VIDEO ACTIVEX ACCESS\IESPLG.DLL [Reg Error: Value does not exist or could not be read.]
YN -> {54160F28-994B-48DD-8D83-1B2F6B9EB054} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [527631 Class]
YY -> {559A0463-48BF-433C-AC59-289E222FB77A} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\qvlbodmnfxv.dll [DVA First]
YN -> {7C109800-A5D5-438F-9640-18D17E168B88} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetProject\sbmdl.dll [Reg Error: Value does not exist or could not be read.]
YY -> {CE86878F-D099-4FFC-A4DC-E51D192063B1} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\yayaYRkK.dll [Reg Error: Value does not exist or could not be read.]
YY -> {D9B86731-513C-4C08-82ED-CD0C263AD93F} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\ddcCSKDv.dll [Reg Error: Value does not exist or could not be read.]
< Internet Explorer Bars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\
YN -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YY -> {A7CDDCDC-BEEB-4685-A062-978F5E07CEEE} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\ShoppingReport\Bin\2.0.26\ShoppingReport.dll [ShopperReports]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
YN -> {29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\VIDEO ACTIVEX ACCESS\IESBPL.DLL [Protection Bar]
YY -> {6E8E8B03-9F95-4E6D-9EE0-AF2305509D7B} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\mkrndofl.dll [mkrndofl]
YN -> {BA52B914-B692-46c4-B683-905236F6F655} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\{07AA283A-43D7-4CBE-A064-32A21112D94D} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\{29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\VIDEO ACTIVEX ACCESS\IESBPL.DLL [Protection Bar]
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. []
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\{C5428486-50A0-4a02-9D20-520B59A9F9B2} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\{C5428486-50A0-4a02-9D20-520B59A9F9B3} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.]
[Registry - Additional Scans - Non-Microsoft Only]
< BotCheck > ->
*Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
YY -> C:\WINDOWS\system32\ddcCSKDv -> %SystemRoot%\system32\ddcCSKDv.dll
< BotCheck > ->
[Files/Folders - Created Within 30 days]
NY -> 527631 -> %SystemRoot%\System32\527631
NY -> 2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> apbrrewv.ini -> %SystemRoot%\System32\apbrrewv.ini
NY -> bjgprqqx.ini -> %SystemRoot%\System32\bjgprqqx.ini
NY -> bwqqiwqv.dll -> %SystemRoot%\System32\bwqqiwqv.dll
NY -> cfbnpjvr.dll -> %SystemRoot%\System32\cfbnpjvr.dll
NY -> ctfmona.exe -> %SystemRoot%\System32\ctfmona.exe
NY -> ctfmonb.bmp -> %SystemRoot%\System32\ctfmonb.bmp
NY -> ddcCSKDv.dll -> %SystemRoot%\System32\ddcCSKDv.dll
NY -> ebwxbvdo.ini -> %SystemRoot%\System32\ebwxbvdo.ini
NY -> edxugyeo.dll -> %SystemRoot%\System32\edxugyeo.dll
NY -> hayrrcvq.ini -> %SystemRoot%\System32\hayrrcvq.ini
NY -> hpvhorho.dll -> %SystemRoot%\System32\hpvhorho.dll
NY -> kr_done1de -> %SystemRoot%\System32\kr_done1de
NY -> odvbxwbe.dll -> %SystemRoot%\System32\odvbxwbe.dll
NY -> oeyguxde.ini -> %SystemRoot%\System32\oeyguxde.ini
NY -> ohrohvph.ini -> %SystemRoot%\System32\ohrohvph.ini
NY -> qjtxueow.dll -> %SystemRoot%\System32\qjtxueow.dll
NY -> qvcrryah.dll -> %SystemRoot%\System32\qvcrryah.dll
NY -> rvjpnbfc.ini -> %SystemRoot%\System32\rvjpnbfc.ini
NY -> vDKSCcdd.ini -> %SystemRoot%\System32\vDKSCcdd.ini
NY -> vDKSCcdd.ini2 -> %SystemRoot%\System32\vDKSCcdd.ini2
NY -> vqwiqqwb.ini -> %SystemRoot%\System32\vqwiqqwb.ini
NY -> vwerrbpa.dll -> %SystemRoot%\System32\vwerrbpa.dll
NY -> woeuxtjq.ini -> %SystemRoot%\System32\woeuxtjq.ini
NY -> xqqrpgjb.dll -> %SystemRoot%\System32\xqqrpgjb.dll
NY -> yayaYRkK.dll -> %SystemRoot%\System32\yayaYRkK.dll
NY -> knxsrgte.exe -> %SystemRoot%\knxsrgte.exe
NY -> mkrndofl.dll -> %SystemRoot%\mkrndofl.dll
NY -> privacy_danger -> %SystemRoot%\privacy_danger
NY -> 7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> qvlbodmnfxv.dll -> %SystemRoot%\qvlbodmnfxv.dll
NY -> svorbmke.exe -> %SystemRoot%\svorbmke.exe
NY -> tdomgafw.dll -> %SystemRoot%\tdomgafw.dll
NY -> wetkadmr.dll -> %SystemRoot%\wetkadmr.dll
[Files Created - Additional Folder Scans - Non-Microsoft Only]
NY -> 1 C:\Documents and Settings\%Username%\My Documents\*.tmp files -> C:\Documents and Settings\%Username%\My Documents\*.tmp
NY -> Error Cleaner.url -> %UserProfile%\Desktop\Error Cleaner.url
NY -> Privacy Protector.url -> %UserProfile%\Desktop\Privacy Protector.url
NY -> AntiSpywareMaster -> %ProgramFiles%\AntiSpywareMaster
NY -> AntiSpywareShield -> %ProgramFiles%\AntiSpywareShield
NY -> CenterLock -> %ProgramFiles%\CenterLock
NY -> VirusHeat 4.4 -> %ProgramFiles%\VirusHeat 4.4
[Files/Folders - Modified Within 30 days]
NY -> 527631 -> %SystemRoot%\System32\527631
NY -> 2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> apbrrewv.ini -> %SystemRoot%\System32\apbrrewv.ini
NY -> bjgprqqx.ini -> %SystemRoot%\System32\bjgprqqx.ini
NY -> blackster.scr -> %SystemRoot%\System32\blackster.scr
NY -> bwqqiwqv.dll -> %SystemRoot%\System32\bwqqiwqv.dll
NY -> cfbnpjvr.dll -> %SystemRoot%\System32\cfbnpjvr.dll
NY -> ctfmona.exe -> %SystemRoot%\System32\ctfmona.exe
NY -> ctfmonb.bmp -> %SystemRoot%\System32\ctfmonb.bmp
NY -> ddcCSKDv.dll -> %SystemRoot%\System32\ddcCSKDv.dll
NY -> ebwxbvdo.ini -> %SystemRoot%\System32\ebwxbvdo.ini
NY -> edxugyeo.dll -> %SystemRoot%\System32\edxugyeo.dll
NY -> hayrrcvq.ini -> %SystemRoot%\System32\hayrrcvq.ini
NY -> hpvhorho.dll -> %SystemRoot%\System32\hpvhorho.dll
NY -> kr_done1de -> %SystemRoot%\System32\kr_done1de
NY -> odvbxwbe.dll -> %SystemRoot%\System32\odvbxwbe.dll
NY -> oeyguxde.ini -> %SystemRoot%\System32\oeyguxde.ini
NY -> ohrohvph.ini -> %SystemRoot%\System32\ohrohvph.ini
NY -> qdsba.dll -> %SystemRoot%\System32\qdsba.dll
NY -> qjtxueow.dll -> %SystemRoot%\System32\qjtxueow.dll
NY -> qvcrryah.dll -> %SystemRoot%\System32\qvcrryah.dll
NY -> rvjpnbfc.ini -> %SystemRoot%\System32\rvjpnbfc.ini
NY -> vDKSCcdd.ini -> %SystemRoot%\System32\vDKSCcdd.ini
NY -> vDKSCcdd.ini2 -> %SystemRoot%\System32\vDKSCcdd.ini2
NY -> vqwiqqwb.ini -> %SystemRoot%\System32\vqwiqqwb.ini
NY -> vwerrbpa.dll -> %SystemRoot%\System32\vwerrbpa.dll
NY -> woeuxtjq.ini -> %SystemRoot%\System32\woeuxtjq.ini
NY -> xqqrpgjb.dll -> %SystemRoot%\System32\xqqrpgjb.dll
NY -> yayaYRkK.dll -> %SystemRoot%\System32\yayaYRkK.dll
NY -> 7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> knxsrgte.exe -> %SystemRoot%\knxsrgte.exe
NY -> mkrndofl.dll -> %SystemRoot%\mkrndofl.dll
NY -> privacy_danger -> %SystemRoot%\privacy_danger
NY -> qvlbodmnfxv.dll -> %SystemRoot%\qvlbodmnfxv.dll
NY -> svorbmke.exe -> %SystemRoot%\svorbmke.exe
NY -> tdomgafw.dll -> %SystemRoot%\tdomgafw.dll
NY -> wetkadmr.dll -> %SystemRoot%\wetkadmr.dll
NY -> qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
NY -> qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
NY -> ZAN4.exe -> C:\Documents and Settings\%Username%\Local Settings\Temp\ZAN4.exe
NY -> C:\Documents and Settings\%Username%\Local Settings\Temp\nsw7.tmp\ -> C:\Documents and Settings\%Username%\Local Settings\Temp\nsw7.tmp\
NY -> C:\Documents and Settings\%Username%\Local Settings\Temp\nsz3.tmp\ -> C:\Documents and Settings\%Username%\Local Settings\Temp\nsz3.tmp\
[Files Modified - Additional Folder Scans - Non-Microsoft Only]
NY -> @Alternate Data Stream - 102 bytes -> %AllUsersProfile%\Application Data\TEMP:A11F741D
NY -> @Alternate Data Stream - 182 bytes -> %AllUsersProfile%\Application Data\TEMP:AA6DEB48
NY -> @Alternate Data Stream - 125 bytes -> %AllUsersProfile%\Application Data\TEMP:ECF5194F
NY -> TmpRecentIcons -> %AppData%\TmpRecentIcons
NY -> 1 C:\Documents and Settings\%Username%\My Documents\*.tmp files -> C:\Documents and Settings\%Username%\My Documents\*.tmp
NY -> AntiSpywareMaster.lnk -> %UserProfile%\Desktop\AntiSpywareMaster.lnk
NY -> Error Cleaner.url -> %UserProfile%\Desktop\Error Cleaner.url
NY -> Privacy Protector.url -> %UserProfile%\Desktop\Privacy Protector.url
[Extra Files]
%ProgramFiles%\ShoppingReport\
%ProgramFiles%\VIDEO ACTIVEX ACCESS\
%ProgramFiles%\NetProject\
[Empty Temp Folders]
[Start Explorer]