Windows herjaa, ettei virustentorjunta sekä palomuuri ole päällä, löytyisikö ongelma logista?

Viestiketju Virukset ja haittaohjelmat - HijackThis -logit -osiossa. Ketjun avasi Number28 18.05.2011.

  1. Number28

    Number28 Member

    Liittynyt:
    15.11.2009
    Viestejä:
    34
    Kiitokset:
    0
    Pisteet:
    16
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 22:56:47, on 18.5.2011
    Platform: Windows 7 SP1 (WinNT 6.00.3505)
    MSIE: Internet Explorer v9.00 (9.00.8112.16421)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\TypingMaster\KBoost.exe
    C:\Program Files (x86)\MagicDisc\MagicDisc.exe
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
    C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
    c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
    c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
    C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
    C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
    C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fi_FI&c=94&bd=Pavilion&pf=cnnb
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fi_FI&c=94&bd=Pavilion&pf=cnnb
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fi_FI&c=94&bd=Pavilion&pf=cnnb
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylon.com/?babsrc=S...000000ceee6cfa5d5&tlver=1.4.19.19&affID=18606
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: UserInit=userinit.exe,
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\IPSBHO.DLL
    O2 - BHO: Windows Live ID -kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coIEPlg.dll
    O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
    O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
    O4 - HKCU\..\Run: [Google Update] "C:\Users\hp\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [TypingSatellite] "C:\Program Files (x86)\TypingMaster\KBOOST.EXE"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7653] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\chrome.manifest"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3535] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\chrome.manifest"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6742] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\install.rdf"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1564] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\install.rdf"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5441] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\vssver.scc"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4280] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\logo.PNG"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8964] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\components\FFHst.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2764] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\components\FFHst.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7711] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\components\FFHst.xpt"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9038] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\components\FFHst.xpt"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7794] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\babylon.css"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9894] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\babylon.css"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5012] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\babylon.xul"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4922] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\babylon.xul"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8443] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\bbylnDef.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8719] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\bbylnDef.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2931] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\btnInf.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2010] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\btnInf.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8561] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\instlgc.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD334] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\instlgc.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3301] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\mtrprt.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2866] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\mtrprt.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1326] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\PPCB.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD901] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\PPCB.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5528] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\rd.htm"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2648] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\rd.htm"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7781] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\tmplt.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD204] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\tmplt.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6243] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\vssver.scc"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4548] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\vssver.scc"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8975] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\arwDwn.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD700] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\arwDwn.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB328] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\buy.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3255] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\buy.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5166] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\help_16.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5400] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\help_16.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9309] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\home.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8612] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\home.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6347] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\privecy_16_hot.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2014] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\privecy_16_hot.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5438] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\tellafriend.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6257] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\tellafriend.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8469] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\09.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1684] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\09.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9445] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\bbyln.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD7235] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\bbyln.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3844] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\games.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4552] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\games.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9279] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\greenCard.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6596] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\greenCard.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9520] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\icons.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2716] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\icons.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1907] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\languages.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1672] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\languages.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4809] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\logo.PNG"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1679] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\lottery.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6862] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\lottery.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4105] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mj.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9586] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mj.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6026] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\radio.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD7869] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\radio.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6982] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\search.PNG"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8267] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\search.PNG"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB511] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\stat.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5138] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\stat.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB925] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\toolbarIcons_casino.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6040] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\toolbarIcons_casino.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4008] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\toolbar_icons_games.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4121] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\toolbar_icons_games.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB760] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\translate.PNG"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5594] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\translate.PNG"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3452] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\vssver.scc"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5095] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\vssver.scc"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7903] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ae.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD833] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ae.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB700] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\bg.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD253] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\bg.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7885] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ch.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9323] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ch.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8152] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cn.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1288] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cn.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4959] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cz.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9700] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cz.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB356] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\de.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1439] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\de.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4157] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\eg.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5780] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\eg.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4194] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\en.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6023] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\en.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5216] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\es.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9304] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\es.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8246] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\fr.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5695] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\fr.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4699] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\gr.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD583] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\gr.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3341] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\he.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4056] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\he.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5941] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\il.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1561] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\il.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1341] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\it.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5281] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\it.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9927] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ja.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1813] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ja.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7844] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\jp.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5065] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\jp.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3408] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\nl.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD7624] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\nl.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9415] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\no.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3722] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\no.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8110] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pl.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2155] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pl.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6151] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pt.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD7209] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pt.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8459] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ro.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2092] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ro.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6048] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ru.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD7665] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ru.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1316] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sa.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8889] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sa.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1970] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\se.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD7453] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\se.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1659] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sv.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4865] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sv.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4430] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\tr.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5171] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\tr.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9620] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ua.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9052] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ua.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1701] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\us.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4194] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\us.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6523] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\Thumbs.db"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6628] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\Thumbs.db"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5743] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\bg.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4655] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\bg.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8563] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\chooseStation.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD7940] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\chooseStation.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9851] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\pauseBtn.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4729] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\pauseBtn.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6373] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\playBtn.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD7748] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\playBtn.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9849] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\rd_strp.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6391] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\rd_strp.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8642] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\lines.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD781] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\lines.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7616] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\Thumbs.db"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3913] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\Thumbs.db"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7863] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\defaults\preferences\instlPref.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD725] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\defaults\preferences\instlPref.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8258] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\defaults\preferences\vssver.scc"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6473] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\defaults\preferences\vssver.scc"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5724] command.com /c del "C:\Windows\setupact.log"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3545] cmd.exe /c del "C:\Windows\setupact.log"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB194] command.com /c del "C:\Windows\setupact.log"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8337] cmd.exe /c del "C:\Windows\setupact.log"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3563] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\mail.google.com\wakeup.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6170] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\mail.google.com\wakeup.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4392] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\s.ytimg.com\videostats.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5283] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\s.ytimg.com\videostats.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1745] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\secure-uk.imrworldwide.com\_ggCvar.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4208] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\secure-uk.imrworldwide.com\_ggCvar.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9363] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\secure-uk.imrworldwide.com\_ggCvar_temp.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6642] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\secure-uk.imrworldwide.com\_ggCvar_temp.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6125] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\secure-uk.imrworldwide.com\_ggMCvar_1.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9822] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\secure-uk.imrworldwide.com\_ggMCvar_1.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3298] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\secure-uk.imrworldwide.com\_ggMCvar_2.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6735] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\secure-uk.imrworldwide.com\_ggMCvar_2.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1232] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\skype.com\#ui\preferences.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5078] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\skype.com\#ui\preferences.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2117] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\areena.yle.fi\player\Application.swf\yle_areena_player.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD937] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\areena.yle.fi\player\Application.swf\yle_areena_player.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3628] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\resources.infolinks.com\flash\ic.swf\infolinksData.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD7790] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\resources.infolinks.com\flash\ic.swf\infolinksData.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9830] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\chrome.manifest"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4454] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\chrome.manifest"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8509] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\install.rdf"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4901] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\install.rdf"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6752] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\vssver.scc"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2886] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\vssver.scc"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4820] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\components\FFHst.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9359] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\components\FFHst.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB151] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\components\FFHst.xpt"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD7251] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\components\FFHst.xpt"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5266] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\babylon.css"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1343] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\babylon.css"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9324] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\babylon.xul"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5556] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\babylon.xul"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3989] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\bbylnDef.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2147] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\bbylnDef.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5937] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\btnInf.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5117] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\btnInf.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB454] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\instlgc.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9310] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\instlgc.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2606] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\mtrprt.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4887] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\mtrprt.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8639] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\PPCB.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2404] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\PPCB.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2779] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\rd.htm"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9209] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\rd.htm"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1278] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\tmplt.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8030] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\tmplt.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3400] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\vssver.scc"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8857] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\vssver.scc"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4822] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\arwDwn.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8964] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\arwDwn.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5192] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\buy.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3282] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\buy.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5351] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\help_16.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5651] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\help_16.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5950] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\home.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9580] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\home.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2377] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\privecy_16_hot.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD927] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\privecy_16_hot.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6646] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\tellafriend.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1515] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\tellafriend.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1186] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\09.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9379] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\09.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7108] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\bbyln.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9554] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\bbyln.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9604] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\games.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5790] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\games.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1690] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\greenCard.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8292] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\greenCard.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8948] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\icons.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9778] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\icons.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6462] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\languages.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1907] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\languages.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7097] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\logo.PNG"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD7623] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\logo.PNG"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB157] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\lottery.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD296] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\lottery.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7202] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mj.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3234] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mj.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3525] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\radio.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4469] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\radio.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB566] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\search.PNG"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8501] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\search.PNG"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5454] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\stat.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2660] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\stat.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8075] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\toolbarIcons_casino.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4160] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\toolbarIcons_casino.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2084] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\toolbar_icons_games.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD773] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\toolbar_icons_games.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8910] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\translate.PNG"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9849] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\translate.PNG"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3903] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\vssver.scc"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD7389] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\vssver.scc"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3862] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ae.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9131] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ae.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9843] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\bg.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4958] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\bg.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8598] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ch.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1153] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ch.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4773] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cn.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3644] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cn.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3714] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cz.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9274] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cz.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1094] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\de.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3852] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\de.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6612] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\eg.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD7716] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\eg.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5787] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\en.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD318] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\en.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5178] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\es.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9987] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\es.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5429] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\fr.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1083] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\fr.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5365] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\gr.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5114] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\gr.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9597] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\he.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD452] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\he.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7105] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\il.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1310] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\il.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9873] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\it.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5016] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\it.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7381] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ja.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6453] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ja.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3319] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\jp.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3261] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\jp.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4633] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\nl.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4738] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\nl.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2407] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\no.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6607] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\no.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4184] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pl.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3507] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pl.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1681] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pt.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2657] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pt.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5322] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ro.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5713] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ro.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3558] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ru.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9737] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ru.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB343] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sa.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6589] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sa.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6370] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\se.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD144] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\se.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9785] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sv.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3459] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sv.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2104] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\tr.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3318] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\tr.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2985] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ua.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD466] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ua.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4782] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\us.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5788] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\us.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7476] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\Thumbs.db"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9125] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\Thumbs.db"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6650] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\bg.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1341] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\bg.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7390] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\chooseStation.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3513] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\chooseStation.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5403] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\pauseBtn.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6315] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\pauseBtn.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2713] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\playBtn.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9492] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\playBtn.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5255] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\rd_strp.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3456] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\rd_strp.png"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1177] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\lines.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD362] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\lines.gif"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6998] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\Thumbs.db"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9330] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\Thumbs.db"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8742] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\defaults\preferences\instlPref.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6037] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\defaults\preferences\instlPref.js"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8557] command.com /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\defaults\preferences\vssver.scc"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD824] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\2ooqnwuy.default\extensions\ffxtlbr@babylon.com\defaults\preferences\vssver.scc"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7036] command.com /c del "C:\Windows\setupact.log"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4965] cmd.exe /c del "C:\Windows\setupact.log"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8011] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\mail.google.com\wakeup.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD520] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\mail.google.com\wakeup.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9549] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\s.ytimg.com\videostats.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3219] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\s.ytimg.com\videostats.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2875] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\secure-uk.imrworldwide.com\_ggCvar.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3249] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\secure-uk.imrworldwide.com\_ggCvar.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB116] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\secure-uk.imrworldwide.com\_ggCvar_temp.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8294] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\secure-uk.imrworldwide.com\_ggCvar_temp.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2428] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\secure-uk.imrworldwide.com\_ggMCvar_1.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3613] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\secure-uk.imrworldwide.com\_ggMCvar_1.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8331] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\secure-uk.imrworldwide.com\_ggMCvar_2.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2097] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\secure-uk.imrworldwide.com\_ggMCvar_2.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3058] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\skype.com\#ui\preferences.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2859] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\skype.com\#ui\preferences.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3713] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\areena.yle.fi\player\Application.swf\yle_areena_player.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3534] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\areena.yle.fi\player\Application.swf\yle_areena_player.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB965] command.com /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\resources.infolinks.com\flash\ic.swf\infolinksData.sol"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9901] cmd.exe /c del "C:\Users\hp\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\3VDMXDG8\resources.infolinks.com\flash\ic.swf\infolinksData.sol"
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'Paikallinen palvelu')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'Paikallinen palvelu')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'Verkkopalvelu')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'Verkkopalvelu')
    O4 - Startup: MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe
    O4 - Startup: NHL® 09 Registration.lnk = C:\Program Files (x86)\EA Sports\NHL 09\Support\EAregister.exe
    O4 - Startup: OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
    O8 - Extra context menu item: Free YouTube Download - C:\Users\hp\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
    O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\hp\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
    O8 - Extra context menu item: V&ie Microsoft Exceliin - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Lähetä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Läh&etä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx
    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
    O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
    O23 - Service: @%systemroot%\system32\appidsvc.dll,-100 (AppIDSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (AudioSrv) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\AxInstSV.dll,-103 (AxInstSV) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\bdesvc.dll,-100 (BDESVC) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\bthserv.dll,-101 (bthserv) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
    O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\defragsvc.dll,-101 (defragsvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\dhcpcore.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\ehome\ehrecvr.exe,-101 (ehRecvr) - Unknown owner - C:\Windows\ehome\ehRecvr.exe
    O23 - Service: @%SystemRoot%\ehome\ehsched.exe,-101 (ehSched) - Unknown owner - C:\Windows\ehome\ehsched.exe
    O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (eventlog) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: Easybits Shared Services for Windows (ezSharedSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
    O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: Google-päivityspalvelu (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Päivitä-palvelu (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\kmsvc.dll,-6 (hkmsvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\ListSvc.dll,-100 (HomeGroupListener) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\provsvc.dll,-100 (HomeGroupProvider) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
    O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\iphlpsvc.dll,-500 (iphlpsvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
    O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23090 (MpsSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe
    O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
    O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\netprofm.dll,-202 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\SysWOW64\drivers\pclepci.sys
    O23 - Service: @%systemroot%\sysWow64\perfhost.exe,-2 (PerfHost) - Unknown owner - C:\Windows\SysWow64\perfhost.exe
    O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
    O23 - Service: @%SystemRoot%\system32\pnrpauto.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\umpo.dll,-100 (Power) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @regsvc.dll,-1 (RemoteRegistry) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
    O23 - Service: @%windir%\system32\RpcEpMap.dll,-1001 (RpcEptMapper) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\SCardSvr.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: Spybot-S&D 2 Firewall Service (SDFirewallService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFWSvc.exe
    O23 - Service: Spybot-S&D 2 Monitoring Service (SDMonitorService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDMonSvc.exe
    O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
    O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\sensrsvc.dll,-1000 (SensrSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppuinotify.dll,-103 (sppuinotify) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\STacSV64.exe
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (stisvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\themeservice.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\dwm.exe,-2000 (UxSms) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: VoddlerNet - Voddler - C:\Program Files (x86)\Voddler\service\voddler.exe
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbiosrvc.dll,-100 (WbioSrvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%ProgramFiles%\Windows Defender\MsMpRes.dll,-103 (WinDefend) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\wpcsvc.dll,-100 (WPCSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wscsvc.dll,-200 (wscsvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe
    O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wwansvc.dll,-257 (WwanSvc) - Unknown owner - C:\Windows\system32\svchost.exe

    --
    End of file - 90323 bytes
     
  2.  
  3. Number28

    Number28 Member

    Liittynyt:
    15.11.2009
    Viestejä:
    34
    Kiitokset:
    0
    Pisteet:
    16
    Malware Bytes' Anti-Malware logi
    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Tietokantaversio: 6599

    Windows 6.1.7601 Service Pack 1
    Internet Explorer 9.0.8112.16421

    18.5.2011 7:20:37
    mbam-log-2011-05-18 (07-20-37).txt

    Tarkistustyyppi: Täysi tarkistus (C:\|D:\|E:\|F:\|G:\|)
    Tarkistettuja kohteita: 469785
    Kulunut aika: 2 tunti(a), 10 minuutti(a), 46 sekunti(a)

    Saastuneita muistiprosesseja: 0
    Saastuneita muistimoduuleja: 0
    Saastuneita rekisteriavaimia: 2
    Saastuneita rekisteriarvoja: 0
    Saastuneita rekisterikohteita: 0
    Saastuneita kansioita: 0
    Saastuneita tiedostoja: 4

    Saastuneita muistiprosesseja:
    (Ei haitallisia kohteita)

    Saastuneita muistimoduuleja:
    (Ei haitallisia kohteita)

    Saastuneita rekisteriavaimia:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RAY Kasino (PUP.Casino) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\raypoker (PUP.Casino) -> Quarantined and deleted successfully.

    Saastuneita rekisteriarvoja:
    (Ei haitallisia kohteita)

    Saastuneita rekisterikohteita:
    (Ei haitallisia kohteita)

    Saastuneita kansioita:
    (Ei haitallisia kohteita)

    Saastuneita tiedostoja:
    c:\Casino\ray kasino\_setupcasino.exe (PUP.Casino) -> Quarantined and deleted successfully.
    c:\Poker\ray pokeri\_setuppoker.exe (PUP.Casino) -> Quarantined and deleted successfully.
    c:\Users\hp\downloads\setupcasino.exe (PUP.Casino) -> Quarantined and deleted successfully.
    c:\Users\hp\downloads\setuppoker.exe (PUP.Casino) -> Quarantined and deleted successfully.

    HiJackThis-logi, uudempi versio Spybotin & Anti Malwaren jälkeen
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 19:44:02, on 19.5.2011
    Platform: Windows 7 SP1 (WinNT 6.00.3505)
    MSIE: Internet Explorer v9.00 (9.00.8112.16421)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\TypingMaster\KBoost.exe
    C:\Program Files (x86)\MagicDisc\MagicDisc.exe
    C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
    C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
    C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
    c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
    c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
    C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fi_FI&c=94&bd=Pavilion&pf=cnnb
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fi_FI&c=94&bd=Pavilion&pf=cnnb
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fi_FI&c=94&bd=Pavilion&pf=cnnb
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylon.com/?babsrc=S...000000ceee6cfa5d5&tlver=1.4.19.19&affID=18606
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: UserInit=userinit.exe,
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\IPSBHO.DLL
    O2 - BHO: Windows Live ID -kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coIEPlg.dll
    O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
    O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
    O4 - HKCU\..\Run: [Google Update] "C:\Users\hp\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [TypingSatellite] "C:\Program Files (x86)\TypingMaster\KBOOST.EXE"
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'Paikallinen palvelu')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'Paikallinen palvelu')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'Verkkopalvelu')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'Verkkopalvelu')
    O4 - Startup: MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe
    O4 - Startup: NHL® 09 Registration.lnk = C:\Program Files (x86)\EA Sports\NHL 09\Support\EAregister.exe
    O4 - Startup: OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
    O8 - Extra context menu item: Free YouTube Download - C:\Users\hp\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
    O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\hp\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
    O8 - Extra context menu item: V&ie Microsoft Exceliin - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Lähetä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Läh&etä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx
    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
    O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
    O23 - Service: @%systemroot%\system32\appidsvc.dll,-100 (AppIDSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (AudioSrv) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\AxInstSV.dll,-103 (AxInstSV) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\bdesvc.dll,-100 (BDESVC) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\bthserv.dll,-101 (bthserv) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
    O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\defragsvc.dll,-101 (defragsvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\dhcpcore.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\ehome\ehrecvr.exe,-101 (ehRecvr) - Unknown owner - C:\Windows\ehome\ehRecvr.exe
    O23 - Service: @%SystemRoot%\ehome\ehsched.exe,-101 (ehSched) - Unknown owner - C:\Windows\ehome\ehsched.exe
    O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (eventlog) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: Easybits Shared Services for Windows (ezSharedSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
    O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: Google-päivityspalvelu (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Päivitä-palvelu (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\kmsvc.dll,-6 (hkmsvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\ListSvc.dll,-100 (HomeGroupListener) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\provsvc.dll,-100 (HomeGroupProvider) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
    O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\iphlpsvc.dll,-500 (iphlpsvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
    O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23090 (MpsSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe
    O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
    O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\netprofm.dll,-202 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\SysWOW64\drivers\pclepci.sys
    O23 - Service: @%systemroot%\sysWow64\perfhost.exe,-2 (PerfHost) - Unknown owner - C:\Windows\SysWow64\perfhost.exe
    O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
    O23 - Service: @%SystemRoot%\system32\pnrpauto.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\umpo.dll,-100 (Power) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @regsvc.dll,-1 (RemoteRegistry) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
    O23 - Service: @%windir%\system32\RpcEpMap.dll,-1001 (RpcEptMapper) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\SCardSvr.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: Spybot-S&D 2 Firewall Service (SDFirewallService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFWSvc.exe
    O23 - Service: Spybot-S&D 2 Monitoring Service (SDMonitorService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDMonSvc.exe
    O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
    O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\sensrsvc.dll,-1000 (SensrSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppuinotify.dll,-103 (sppuinotify) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\STacSV64.exe
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (stisvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\themeservice.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\dwm.exe,-2000 (UxSms) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: VoddlerNet - Voddler - C:\Program Files (x86)\Voddler\service\voddler.exe
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbiosrvc.dll,-100 (WbioSrvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%ProgramFiles%\Windows Defender\MsMpRes.dll,-103 (WinDefend) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\wpcsvc.dll,-100 (WPCSvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wscsvc.dll,-200 (wscsvc) - Unknown owner - C:\Windows\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe
    O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wwansvc.dll,-257 (WwanSvc) - Unknown owner - C:\Windows\system32\svchost.exe

    --
    End of file - 26631 bytes
     

Jaa tämä sivu