Jump to content

computer crushed after the update


Recommended Posts

bascailly after the scan and I stupidly did what Malwarebytes told me to which was quarantined the window files. So now I am screwed, my computer can't boot into window nor safe mode; startup repaire and system restore did not help to solve the problem at all. Please help man!

Link to post
Share on other sites

  • Replies 68
  • Created
  • Last Reply

Top Posters In This Topic

my log before my computer went unbootable

 

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 7/26/2014
Scan Time: 5:55:45 PM
Logfile: 665.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.07.26.09
Rootkit Database: v2014.07.17.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: kliu

Scan Type: Hyper Scan
Result: Completed
Objects Scanned: 239945
Time Elapsed: 0 min, 33 sec

Memory: Enabled
Startup: Enabled
Filesystem: Disabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 7
Trojan.FakeMS.ED, C:\Windows\System32\lsm.exe, 640, , [af728420413ae35307ebc7dafc0545bb]
Trojan.FakeMS.ED, C:\Windows\System32\taskhost.exe, 1684, , [fa275e467b0075c1c2300d94be43ed13]
Trojan.FakeMS.ED, C:\Windows\System32\dwm.exe, 1768, , [0a172381146730062ec4851c16eb3bc5]
Trojan.FakeMS.ED, C:\Windows\System32\conhost.exe, 3324, , [c45d34700a717bbb638f4b5615ec6a96]
Trojan.FakeMS.ED, C:\Windows\System32\conhost.exe, 3344, , [c45d34700a717bbb638f4b5615ec6a96]
Trojan.FakeMS.ED, C:\Windows\System32\SEARCHINDEXER.EXE, 3976, , [22ffbbe9710ae74fda189f0251b026da]
Trojan.FakeMS.ED, C:\Windows\System32\wbem\WmiPrvSE.exe, 3468, , [b8698222a6d5bb7bdf13f3ae9a67e61a]

Modules: 290
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, C:\Windows\System32\profapi.dll, , [c75af1b30378211550a2237e49b858a8],
Trojan.FakeMS.ED, C:\Windows\System32\profapi.dll, , [c75af1b30378211550a2237e49b858a8],
Trojan.FakeMS.ED, C:\Windows\System32\profapi.dll, , [c75af1b30378211550a2237e49b858a8],
Trojan.FakeMS.ED, C:\Windows\System32\profapi.dll, , [c75af1b30378211550a2237e49b858a8],
Trojan.FakeMS.ED, C:\Windows\System32\profapi.dll, , [c75af1b30378211550a2237e49b858a8],
Trojan.FakeMS.ED, C:\Windows\System32\profapi.dll, , [c75af1b30378211550a2237e49b858a8],
Trojan.FakeMS.ED, C:\Windows\System32\profapi.dll, , [c75af1b30378211550a2237e49b858a8],
Trojan.FakeMS.ED, C:\Windows\System32\profapi.dll, , [c75af1b30378211550a2237e49b858a8],
Trojan.FakeMS.ED, C:\Windows\System32\profapi.dll, , [c75af1b30378211550a2237e49b858a8],
Trojan.FakeMS.ED, C:\Windows\System32\profapi.dll, , [c75af1b30378211550a2237e49b858a8],
Trojan.FakeMS.ED, C:\Windows\System32\profapi.dll, , [c75af1b30378211550a2237e49b858a8],
Trojan.FakeMS.ED, C:\Windows\System32\profapi.dll, , [c75af1b30378211550a2237e49b858a8],
Trojan.FakeMS.ED, C:\Windows\System32\profapi.dll, , [c75af1b30378211550a2237e49b858a8],
Trojan.FakeMS.ED, C:\Windows\System32\profapi.dll, , [c75af1b30378211550a2237e49b858a8],
Trojan.FakeMS.ED, C:\Windows\System32\mpr.dll, , [a9784262562583b33ab8e8b9cb363ac6],
Trojan.FakeMS.ED, C:\Windows\System32\mpr.dll, , [a9784262562583b33ab8e8b9cb363ac6],
Trojan.FakeMS.ED, C:\Windows\System32\mpr.dll, , [a9784262562583b33ab8e8b9cb363ac6],
Trojan.FakeMS.ED, C:\Windows\System32\IPHLPAPI.DLL, , [71b04e56a9d2c17535bd515050b1ad53],
Trojan.FakeMS.ED, C:\Windows\System32\IPHLPAPI.DLL, , [71b04e56a9d2c17535bd515050b1ad53],
Trojan.FakeMS.ED, C:\Windows\System32\IPHLPAPI.DLL, , [71b04e56a9d2c17535bd515050b1ad53],
Trojan.FakeMS.ED, C:\Windows\System32\IPHLPAPI.DLL, , [71b04e56a9d2c17535bd515050b1ad53],
Trojan.FakeMS.ED, C:\Windows\System32\IPHLPAPI.DLL, , [71b04e56a9d2c17535bd515050b1ad53],
Trojan.FakeMS.ED, C:\Windows\System32\IPHLPAPI.DLL, , [71b04e56a9d2c17535bd515050b1ad53],
Trojan.FakeMS.ED, C:\Windows\System32\IPHLPAPI.DLL, , [71b04e56a9d2c17535bd515050b1ad53],
Trojan.FakeMS.ED, C:\Windows\System32\IPHLPAPI.DLL, , [71b04e56a9d2c17535bd515050b1ad53],
Trojan.FakeMS.ED, C:\Windows\System32\IPHLPAPI.DLL, , [71b04e56a9d2c17535bd515050b1ad53],
Trojan.FakeMS.ED, C:\Windows\System32\IPHLPAPI.DLL, , [71b04e56a9d2c17535bd515050b1ad53],
Trojan.FakeMS.ED, C:\Windows\System32\IPHLPAPI.DLL, , [71b04e56a9d2c17535bd515050b1ad53],
Trojan.FakeMS.ED, C:\Windows\System32\IPHLPAPI.DLL, , [71b04e56a9d2c17535bd515050b1ad53],
Trojan.FakeMS.ED, C:\Windows\System32\IPHLPAPI.DLL, , [71b04e56a9d2c17535bd515050b1ad53],
Trojan.FakeMS.ED, C:\Windows\System32\winnsi.dll, , [21005b4948330d2912e0465b5ca5c838],
Trojan.FakeMS.ED, C:\Windows\System32\winnsi.dll, , [21005b4948330d2912e0465b5ca5c838],
Trojan.FakeMS.ED, C:\Windows\System32\winnsi.dll, , [21005b4948330d2912e0465b5ca5c838],
Trojan.FakeMS.ED, C:\Windows\System32\winnsi.dll, , [21005b4948330d2912e0465b5ca5c838],
Trojan.FakeMS.ED, C:\Windows\System32\winnsi.dll, , [21005b4948330d2912e0465b5ca5c838],
Trojan.FakeMS.ED, C:\Windows\System32\winnsi.dll, , [21005b4948330d2912e0465b5ca5c838],
Trojan.FakeMS.ED, C:\Windows\System32\winnsi.dll, , [21005b4948330d2912e0465b5ca5c838],
Trojan.FakeMS.ED, C:\Windows\System32\winnsi.dll, , [21005b4948330d2912e0465b5ca5c838],
Trojan.FakeMS.ED, C:\Windows\System32\winnsi.dll, , [21005b4948330d2912e0465b5ca5c838],
Trojan.FakeMS.ED, C:\Windows\System32\winnsi.dll, , [21005b4948330d2912e0465b5ca5c838],
Trojan.FakeMS.ED, C:\Windows\System32\winnsi.dll, , [21005b4948330d2912e0465b5ca5c838],
Trojan.FakeMS.ED, C:\Windows\System32\winnsi.dll, , [21005b4948330d2912e0465b5ca5c838],
Trojan.FakeMS.ED, C:\Windows\System32\winnsi.dll, , [21005b4948330d2912e0465b5ca5c838],
Trojan.FakeMS.ED, C:\Windows\System32\winmm.dll, , [24fd3e66106b4fe733bfa5fc3cc513ed],
Trojan.FakeMS.ED, C:\Windows\System32\winmm.dll, , [24fd3e66106b4fe733bfa5fc3cc513ed],
Trojan.FakeMS.ED, C:\Windows\System32\winmm.dll, , [24fd3e66106b4fe733bfa5fc3cc513ed],
Trojan.FakeMS.ED, C:\Windows\System32\winmm.dll, , [24fd3e66106b4fe733bfa5fc3cc513ed],
Trojan.FakeMS.ED, C:\Windows\System32\winmm.dll, , [24fd3e66106b4fe733bfa5fc3cc513ed],
Trojan.FakeMS.ED, C:\Windows\System32\winmm.dll, , [24fd3e66106b4fe733bfa5fc3cc513ed],
Trojan.FakeMS.ED, C:\Windows\System32\winmm.dll, , [24fd3e66106b4fe733bfa5fc3cc513ed],
Trojan.FakeMS.ED, C:\Windows\System32\winmm.dll, , [24fd3e66106b4fe733bfa5fc3cc513ed],
Trojan.FakeMS.ED, C:\Windows\System32\winmm.dll, , [24fd3e66106b4fe733bfa5fc3cc513ed],
Trojan.FakeMS.ED, C:\Windows\System32\winmm.dll, , [24fd3e66106b4fe733bfa5fc3cc513ed],
Trojan.FakeMS.ED, C:\Windows\System32\uxtheme.dll, , [8998297b2853eb4b6092861b0bf6bc44],
Trojan.FakeMS.ED, C:\Windows\System32\uxtheme.dll, , [8998297b2853eb4b6092861b0bf6bc44],
Trojan.FakeMS.ED, C:\Windows\System32\uxtheme.dll, , [8998297b2853eb4b6092861b0bf6bc44],
Trojan.FakeMS.ED, C:\Windows\System32\uxtheme.dll, , [8998297b2853eb4b6092861b0bf6bc44],
Trojan.FakeMS.ED, C:\Windows\System32\uxtheme.dll, , [8998297b2853eb4b6092861b0bf6bc44],
Trojan.FakeMS.ED, C:\Windows\System32\uxtheme.dll, , [8998297b2853eb4b6092861b0bf6bc44],
Trojan.FakeMS.ED, C:\Windows\System32\uxtheme.dll, , [8998297b2853eb4b6092861b0bf6bc44],
Trojan.FakeMS.ED, C:\Windows\System32\uxtheme.dll, , [8998297b2853eb4b6092861b0bf6bc44],
Trojan.FakeMS.ED, C:\Windows\System32\uxtheme.dll, , [8998297b2853eb4b6092861b0bf6bc44],
Trojan.FakeMS.ED, C:\Windows\System32\uxtheme.dll, , [8998297b2853eb4b6092861b0bf6bc44],
Trojan.FakeMS.ED, C:\Windows\System32\uxtheme.dll, , [8998297b2853eb4b6092861b0bf6bc44],
Trojan.FakeMS.ED, C:\Windows\System32\uxtheme.dll, , [8998297b2853eb4b6092861b0bf6bc44],
Trojan.FakeMS.ED, C:\Windows\System32\uxtheme.dll, , [8998297b2853eb4b6092861b0bf6bc44],
Trojan.FakeMS.ED, C:\Windows\System32\uxtheme.dll, , [8998297b2853eb4b6092861b0bf6bc44],
Trojan.FakeMS.ED, C:\Windows\System32\uxtheme.dll, , [8998297b2853eb4b6092861b0bf6bc44],
Trojan.FakeMS.ED, C:\Windows\System32\netapi32.dll, , [c0614064fb8060d61cd66938669b41bf],
Trojan.FakeMS.ED, C:\Windows\System32\netapi32.dll, , [c0614064fb8060d61cd66938669b41bf],
Trojan.FakeMS.ED, C:\Windows\System32\netapi32.dll, , [c0614064fb8060d61cd66938669b41bf],
Trojan.FakeMS.ED, C:\Windows\System32\netapi32.dll, , [c0614064fb8060d61cd66938669b41bf],
Trojan.FakeMS.ED, C:\Windows\System32\netapi32.dll, , [c0614064fb8060d61cd66938669b41bf],
Trojan.FakeMS.ED, C:\Windows\System32\netapi32.dll, , [c0614064fb8060d61cd66938669b41bf],
Trojan.FakeMS.ED, C:\Windows\System32\netapi32.dll, , [c0614064fb8060d61cd66938669b41bf],
Trojan.FakeMS.ED, C:\Windows\System32\netapi32.dll, , [c0614064fb8060d61cd66938669b41bf],
Trojan.FakeMS.ED, C:\Windows\System32\netutils.dll, , [3fe2f7ad4a3184b26f83f3ae9d64d22e],
Trojan.FakeMS.ED, C:\Windows\System32\netutils.dll, , [3fe2f7ad4a3184b26f83f3ae9d64d22e],
Trojan.FakeMS.ED, C:\Windows\System32\netutils.dll, , [3fe2f7ad4a3184b26f83f3ae9d64d22e],
Trojan.FakeMS.ED, C:\Windows\System32\netutils.dll, , [3fe2f7ad4a3184b26f83f3ae9d64d22e],
Trojan.FakeMS.ED, C:\Windows\System32\netutils.dll, , [3fe2f7ad4a3184b26f83f3ae9d64d22e],
Trojan.FakeMS.ED, C:\Windows\System32\netutils.dll, , [3fe2f7ad4a3184b26f83f3ae9d64d22e],
Trojan.FakeMS.ED, C:\Windows\System32\netutils.dll, , [3fe2f7ad4a3184b26f83f3ae9d64d22e],
Trojan.FakeMS.ED, C:\Windows\System32\netutils.dll, , [3fe2f7ad4a3184b26f83f3ae9d64d22e],
Trojan.FakeMS.ED, C:\Windows\System32\srvcli.dll, , [4cd57f2518633501945ee1c013eec937],
Trojan.FakeMS.ED, C:\Windows\System32\srvcli.dll, , [4cd57f2518633501945ee1c013eec937],
Trojan.FakeMS.ED, C:\Windows\System32\srvcli.dll, , [4cd57f2518633501945ee1c013eec937],
Trojan.FakeMS.ED, C:\Windows\System32\srvcli.dll, , [4cd57f2518633501945ee1c013eec937],
Trojan.FakeMS.ED, C:\Windows\System32\srvcli.dll, , [4cd57f2518633501945ee1c013eec937],
Trojan.FakeMS.ED, C:\Windows\System32\srvcli.dll, , [4cd57f2518633501945ee1c013eec937],
Trojan.FakeMS.ED, C:\Windows\System32\srvcli.dll, , [4cd57f2518633501945ee1c013eec937],
Trojan.FakeMS.ED, C:\Windows\System32\srvcli.dll, , [4cd57f2518633501945ee1c013eec937],
Trojan.FakeMS.ED, C:\Windows\System32\srvcli.dll, , [4cd57f2518633501945ee1c013eec937],
Trojan.FakeMS.ED, C:\Windows\System32\wkscli.dll, , [958cc6de6a1163d3846e138eeb162cd4],
Trojan.FakeMS.ED, C:\Windows\System32\wkscli.dll, , [958cc6de6a1163d3846e138eeb162cd4],
Trojan.FakeMS.ED, C:\Windows\System32\wkscli.dll, , [958cc6de6a1163d3846e138eeb162cd4],
Trojan.FakeMS.ED, C:\Windows\System32\wkscli.dll, , [958cc6de6a1163d3846e138eeb162cd4],
Trojan.FakeMS.ED, C:\Windows\System32\wkscli.dll, , [958cc6de6a1163d3846e138eeb162cd4],
Trojan.FakeMS.ED, C:\Windows\System32\wkscli.dll, , [958cc6de6a1163d3846e138eeb162cd4],
Trojan.FakeMS.ED, C:\Windows\System32\wkscli.dll, , [958cc6de6a1163d3846e138eeb162cd4],
Trojan.FakeMS.ED, C:\Windows\System32\wkscli.dll, , [958cc6de6a1163d3846e138eeb162cd4],
Trojan.FakeMS.ED, C:\Windows\System32\dwmapi.dll, , [041d2c78a4d7b284be346b368978f10f],
Trojan.FakeMS.ED, C:\Windows\System32\dwmapi.dll, , [041d2c78a4d7b284be346b368978f10f],
Trojan.FakeMS.ED, C:\Windows\System32\dwmapi.dll, , [041d2c78a4d7b284be346b368978f10f],
Trojan.FakeMS.ED, C:\Windows\System32\dwmapi.dll, , [041d2c78a4d7b284be346b368978f10f],
Trojan.FakeMS.ED, C:\Windows\System32\dwmapi.dll, , [041d2c78a4d7b284be346b368978f10f],
Trojan.FakeMS.ED, C:\Windows\System32\dwmapi.dll, , [041d2c78a4d7b284be346b368978f10f],
Trojan.FakeMS.ED, C:\Windows\System32\dwmapi.dll, , [041d2c78a4d7b284be346b368978f10f],
Trojan.FakeMS.ED, C:\Windows\System32\dwmapi.dll, , [041d2c78a4d7b284be346b368978f10f],
Trojan.FakeMS.ED, C:\Windows\System32\apphelp.dll, , [5dc4bee69dde86b003ef099839c8b947],
Trojan.FakeMS.ED, C:\Windows\System32\apphelp.dll, , [5dc4bee69dde86b003ef099839c8b947],
Trojan.FakeMS.ED, C:\Windows\System32\apphelp.dll, , [5dc4bee69dde86b003ef099839c8b947],
Trojan.FakeMS.ED, C:\Windows\System32\apphelp.dll, , [5dc4bee69dde86b003ef099839c8b947],
Trojan.FakeMS.ED, C:\Windows\System32\apphelp.dll, , [5dc4bee69dde86b003ef099839c8b947],
Trojan.FakeMS.ED, C:\Windows\System32\apphelp.dll, , [5dc4bee69dde86b003ef099839c8b947],
Trojan.FakeMS.ED, C:\Windows\System32\apphelp.dll, , [5dc4bee69dde86b003ef099839c8b947],
Trojan.FakeMS.ED, C:\Windows\System32\apphelp.dll, , [5dc4bee69dde86b003ef099839c8b947],
Trojan.FakeMS.ED, C:\Windows\System32\apphelp.dll, , [5dc4bee69dde86b003ef099839c8b947],
Trojan.FakeMS.ED, C:\Windows\System32\propsys.dll, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, C:\Windows\System32\propsys.dll, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, C:\Windows\System32\propsys.dll, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, C:\Windows\System32\propsys.dll, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, C:\Windows\System32\ntmarta.dll, , [e9387c282358d36329c9e8b9d03118e8],
Trojan.FakeMS.ED, C:\Windows\System32\ntmarta.dll, , [e9387c282358d36329c9e8b9d03118e8],
Trojan.FakeMS.ED, C:\Windows\System32\ntmarta.dll, , [e9387c282358d36329c9e8b9d03118e8],
Trojan.FakeMS.ED, C:\Windows\System32\ntmarta.dll, , [e9387c282358d36329c9e8b9d03118e8],
Trojan.FakeMS.ED, C:\Windows\System32\ntmarta.dll, , [e9387c282358d36329c9e8b9d03118e8],
Trojan.FakeMS.ED, C:\Windows\System32\ntmarta.dll, , [e9387c282358d36329c9e8b9d03118e8],
Trojan.FakeMS.ED, C:\Windows\System32\ntmarta.dll, , [e9387c282358d36329c9e8b9d03118e8],
Trojan.FakeMS.ED, C:\Windows\System32\ntmarta.dll, , [e9387c282358d36329c9e8b9d03118e8],
Trojan.FakeMS.ED, C:\Windows\System32\ntmarta.dll, , [e9387c282358d36329c9e8b9d03118e8],
Trojan.FakeMS.ED, C:\Windows\System32\ntmarta.dll, , [e9387c282358d36329c9e8b9d03118e8],
Trojan.FakeMS.ED, C:\Windows\System32\ntmarta.dll, , [e9387c282358d36329c9e8b9d03118e8],
Trojan.FakeMS.ED, C:\Windows\System32\ntmarta.dll, , [e9387c282358d36329c9e8b9d03118e8],
Trojan.FakeMS.ED, C:\Windows\System32\ntshrui.dll, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, C:\Windows\System32\ntshrui.dll, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, C:\Windows\System32\ntshrui.dll, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, C:\Windows\System32\cscapi.dll, , [61c0dacaadce66d0fef4b7eaea1740c0],
Trojan.FakeMS.ED, C:\Windows\System32\cscapi.dll, , [61c0dacaadce66d0fef4b7eaea1740c0],
Trojan.FakeMS.ED, C:\Windows\System32\cscapi.dll, , [61c0dacaadce66d0fef4b7eaea1740c0],
Trojan.FakeMS.ED, C:\Windows\System32\cscapi.dll, , [61c0dacaadce66d0fef4b7eaea1740c0],
Trojan.FakeMS.ED, C:\Windows\System32\mswsock.dll, , [e53cefb59cdfcf6703efd8c9946d60a0],
Trojan.FakeMS.ED, C:\Windows\System32\mswsock.dll, , [e53cefb59cdfcf6703efd8c9946d60a0],
Trojan.FakeMS.ED, C:\Windows\System32\mswsock.dll, , [e53cefb59cdfcf6703efd8c9946d60a0],
Trojan.FakeMS.ED, C:\Windows\System32\mswsock.dll, , [e53cefb59cdfcf6703efd8c9946d60a0],
Trojan.FakeMS.ED, C:\Windows\System32\mswsock.dll, , [e53cefb59cdfcf6703efd8c9946d60a0],
Trojan.FakeMS.ED, C:\Windows\System32\mswsock.dll, , [e53cefb59cdfcf6703efd8c9946d60a0],
Trojan.FakeMS.ED, C:\Windows\System32\mswsock.dll, , [e53cefb59cdfcf6703efd8c9946d60a0],
Trojan.FakeMS.ED, C:\Windows\System32\mswsock.dll, , [e53cefb59cdfcf6703efd8c9946d60a0],
Trojan.FakeMS.ED, C:\Windows\System32\mswsock.dll, , [e53cefb59cdfcf6703efd8c9946d60a0],
Trojan.FakeMS.ED, C:\Windows\System32\mswsock.dll, , [e53cefb59cdfcf6703efd8c9946d60a0],
Trojan.FakeMS.ED, C:\Windows\System32\mswsock.dll, , [e53cefb59cdfcf6703efd8c9946d60a0],
Trojan.FakeMS.ED, C:\Windows\System32\wship6.dll, , [9c85554f700b7eb8f8fa376a1ae711ef],
Trojan.FakeMS.ED, C:\Windows\System32\wship6.dll, , [9c85554f700b7eb8f8fa376a1ae711ef],
Trojan.FakeMS.ED, C:\Windows\System32\wship6.dll, , [9c85554f700b7eb8f8fa376a1ae711ef],
Trojan.FakeMS.ED, C:\Windows\System32\wship6.dll, , [9c85554f700b7eb8f8fa376a1ae711ef],
Trojan.FakeMS.ED, C:\Windows\System32\wship6.dll, , [9c85554f700b7eb8f8fa376a1ae711ef],
Trojan.FakeMS.ED, C:\Windows\System32\wship6.dll, , [9c85554f700b7eb8f8fa376a1ae711ef],
Trojan.FakeMS.ED, C:\Windows\System32\wship6.dll, , [9c85554f700b7eb8f8fa376a1ae711ef],
Trojan.FakeMS.ED, C:\Windows\System32\wship6.dll, , [9c85554f700b7eb8f8fa376a1ae711ef],
Trojan.FakeMS.ED, C:\Windows\System32\wship6.dll, , [9c85554f700b7eb8f8fa376a1ae711ef],
Trojan.FakeMS.ED, C:\Windows\System32\FWPUCLNT.DLL, , [8899554fb0cb0234ec064f5258a95ba5],
Trojan.FakeMS.ED, C:\Windows\System32\FWPUCLNT.DLL, , [8899554fb0cb0234ec064f5258a95ba5],
Trojan.FakeMS.ED, C:\Windows\System32\FWPUCLNT.DLL, , [8899554fb0cb0234ec064f5258a95ba5],
Trojan.FakeMS.ED, C:\Windows\System32\FWPUCLNT.DLL, , [8899554fb0cb0234ec064f5258a95ba5],
Trojan.FakeMS.ED, C:\Windows\System32\FWPUCLNT.DLL, , [8899554fb0cb0234ec064f5258a95ba5],
Trojan.FakeMS.ED, C:\Windows\System32\FWPUCLNT.DLL, , [8899554fb0cb0234ec064f5258a95ba5],
Trojan.FakeMS.ED, C:\Windows\System32\FWPUCLNT.DLL, , [8899554fb0cb0234ec064f5258a95ba5],
Trojan.FakeMS.ED, C:\Windows\System32\FWPUCLNT.DLL, , [8899554fb0cb0234ec064f5258a95ba5],
Trojan.FakeMS.ED, C:\Windows\System32\FWPUCLNT.DLL, , [8899554fb0cb0234ec064f5258a95ba5],
Trojan.FakeMS.ED, C:\Windows\System32\RPCRTREMOTE.DLL, , [e43dfea6e398280e8e64158cd0316e92],
Trojan.FakeMS.ED, C:\Windows\System32\RPCRTREMOTE.DLL, , [e43dfea6e398280e8e64158cd0316e92],
Trojan.FakeMS.ED, C:\Windows\System32\RPCRTREMOTE.DLL, , [e43dfea6e398280e8e64158cd0316e92],
Trojan.FakeMS.ED, C:\Windows\System32\RPCRTREMOTE.DLL, , [e43dfea6e398280e8e64158cd0316e92],
Trojan.FakeMS.ED, C:\Windows\System32\RPCRTREMOTE.DLL, , [e43dfea6e398280e8e64158cd0316e92],
Trojan.FakeMS.ED, C:\Windows\System32\RPCRTREMOTE.DLL, , [e43dfea6e398280e8e64158cd0316e92],
Trojan.FakeMS.ED, C:\Windows\System32\RPCRTREMOTE.DLL, , [e43dfea6e398280e8e64158cd0316e92],
Trojan.FakeMS.ED, C:\Windows\System32\RPCRTREMOTE.DLL, , [e43dfea6e398280e8e64158cd0316e92],
Trojan.FakeMS.ED, C:\Windows\System32\RPCRTREMOTE.DLL, , [e43dfea6e398280e8e64158cd0316e92],
Trojan.FakeMS.ED, C:\Windows\System32\RPCRTREMOTE.DLL, , [e43dfea6e398280e8e64158cd0316e92],
Trojan.FakeMS.ED, C:\Windows\System32\RPCRTREMOTE.DLL, , [e43dfea6e398280e8e64158cd0316e92],
Trojan.FakeMS.ED, C:\Windows\System32\RPCRTREMOTE.DLL, , [e43dfea6e398280e8e64158cd0316e92],
Trojan.FakeMS.ED, C:\Windows\System32\mssprxy.dll, , [6ab77a2a66150a2c757dd9c830d1e020],
Trojan.FakeMS.ED, C:\Windows\System32\mssprxy.dll, , [6ab77a2a66150a2c757dd9c830d1e020],
Trojan.FakeMS.ED, C:\Windows\System32\devrtl.dll, , [9f823b69631855e13db5960b9869cf31],
Trojan.FakeMS.ED, C:\Windows\System32\SPInf.dll, , [b0712a7a5c1f56e0945eaef3ac552fd1],
Trojan.FakeMS.ED, C:\Windows\System32\dbghelp.dll, , [da4742621c5f8da9b83a7f229d649b65],
Trojan.FakeMS.ED, C:\Windows\System32\dbghelp.dll, , [da4742621c5f8da9b83a7f229d649b65],
Trojan.FakeMS.ED, C:\Windows\System32\dbghelp.dll, , [da4742621c5f8da9b83a7f229d649b65],
Trojan.FakeMS.ED, C:\Windows\System32\dbghelp.dll, , [da4742621c5f8da9b83a7f229d649b65],
Trojan.FakeMS.ED, C:\Windows\System32\secur32.dll, , [ae73cadae794ac8aeb073b66728fc23e],
Trojan.FakeMS.ED, C:\Windows\System32\secur32.dll, , [ae73cadae794ac8aeb073b66728fc23e],
Trojan.FakeMS.ED, C:\Windows\System32\secur32.dll, , [ae73cadae794ac8aeb073b66728fc23e],
Trojan.FakeMS.ED, C:\Windows\System32\secur32.dll, , [ae73cadae794ac8aeb073b66728fc23e],
Trojan.FakeMS.ED, C:\Windows\System32\rtutils.dll, , [e73af9ab037821156f833170ca37fc04],
Trojan.FakeMS.ED, C:\Windows\System32\rtutils.dll, , [e73af9ab037821156f833170ca37fc04],
Trojan.FakeMS.ED, C:\Windows\System32\DHCPCSVC6.DLL, , [da475b494b30dd59a34f812042bff50b],
Trojan.FakeMS.ED, C:\Windows\System32\DHCPCSVC6.DLL, , [da475b494b30dd59a34f812042bff50b],
Trojan.FakeMS.ED, C:\Windows\System32\DHCPCSVC6.DLL, , [da475b494b30dd59a34f812042bff50b],
Trojan.FakeMS.ED, C:\Windows\System32\dhcpcsvc.dll, , [130e0c985a21c2748f631c85c33e1ce4],
Trojan.FakeMS.ED, C:\Windows\System32\dhcpcsvc.dll, , [130e0c985a21c2748f631c85c33e1ce4],
Trojan.FakeMS.ED, C:\Windows\System32\dhcpcsvc.dll, , [130e0c985a21c2748f631c85c33e1ce4],
Trojan.FakeMS.ED, C:\Windows\System32\nlaapi.dll, , [fd24287c334860d6bc36d0d1bc45c33d],
Trojan.FakeMS.ED, C:\Windows\System32\nlaapi.dll, , [fd24287c334860d6bc36d0d1bc45c33d],
Trojan.FakeMS.ED, C:\Windows\System32\nlaapi.dll, , [fd24287c334860d6bc36d0d1bc45c33d],
Trojan.FakeMS.ED, C:\Windows\System32\NapiNSP.dll, , [27faf4b091eae353df139f025ca5e51b],
Trojan.FakeMS.ED, C:\Windows\System32\NapiNSP.dll, , [27faf4b091eae353df139f025ca5e51b],
Trojan.FakeMS.ED, C:\Windows\System32\NapiNSP.dll, , [27faf4b091eae353df139f025ca5e51b],
Trojan.FakeMS.ED, C:\Windows\System32\pnrpnsp.dll, , [f9286044f28946f06a88435efd046c94],
Trojan.FakeMS.ED, C:\Windows\System32\pnrpnsp.dll, , [f9286044f28946f06a88435efd046c94],
Trojan.FakeMS.ED, C:\Windows\System32\pnrpnsp.dll, , [f9286044f28946f06a88435efd046c94],
Trojan.FakeMS.ED, C:\Windows\System32\winrnr.dll, , [a978baea9dde90a621d1772af70add23],
Trojan.FakeMS.ED, C:\Windows\System32\winrnr.dll, , [a978baea9dde90a621d1772af70add23],
Trojan.FakeMS.ED, C:\Windows\System32\winrnr.dll, , [a978baea9dde90a621d1772af70add23],
Trojan.FakeMS.ED, C:\Windows\System32\rasapi32.dll, , [ea37ddc7ec8fb581fbf73b6625dc2dd3],
Trojan.FakeMS.ED, C:\Windows\System32\rasman.dll, , [d051584c1a617bbba74b940ddf22b24e],
Trojan.FakeMS.ED, C:\Windows\System32\xmllite.dll, , [88995c48106b2e08e40ecfd2946d3ac6],
Trojan.FakeMS.ED, C:\Windows\System32\oleacc.dll, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, C:\Windows\System32\oleacc.dll, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, C:\Windows\System32\oleacc.dll, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, C:\Windows\System32\oleacc.dll, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, C:\Windows\System32\oleacc.dll, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, C:\Windows\System32\oleacc.dll, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, C:\Windows\System32\oleacc.dll, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, C:\Windows\System32\oleacc.dll, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, C:\Windows\System32\sxs.dll, , [a9787e26fc7f67cf2cc64a57e021a65a],
Trojan.FakeMS.ED, C:\Windows\System32\sxs.dll, , [a9787e26fc7f67cf2cc64a57e021a65a],
Trojan.FakeMS.ED, C:\Windows\System32\sxs.dll, , [a9787e26fc7f67cf2cc64a57e021a65a],
Trojan.FakeMS.ED, C:\Windows\System32\sxs.dll, , [a9787e26fc7f67cf2cc64a57e021a65a],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\wbemprox.dll, , [36eb9a0a39429c9ae9099f0259a89d63],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\wbemprox.dll, , [36eb9a0a39429c9ae9099f0259a89d63],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\wbemprox.dll, , [36eb9a0a39429c9ae9099f0259a89d63],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\wbemprox.dll, , [36eb9a0a39429c9ae9099f0259a89d63],
Trojan.FakeMS.ED, C:\Windows\System32\wbemcomn.dll, , [43de6a3a96e54fe729c9970a29d8e818],
Trojan.FakeMS.ED, C:\Windows\System32\wbemcomn.dll, , [43de6a3a96e54fe729c9970a29d8e818],
Trojan.FakeMS.ED, C:\Windows\System32\wbemcomn.dll, , [43de6a3a96e54fe729c9970a29d8e818],
Trojan.FakeMS.ED, C:\Windows\System32\wbemcomn.dll, , [43de6a3a96e54fe729c9970a29d8e818],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\wbemsvc.dll, , [f42ddfc5d5a666d07a78a4fd7b866898],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\wbemsvc.dll, , [f42ddfc5d5a666d07a78a4fd7b866898],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\wbemsvc.dll, , [f42ddfc5d5a666d07a78a4fd7b866898],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\wbemsvc.dll, , [f42ddfc5d5a666d07a78a4fd7b866898],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\fastprox.dll, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\fastprox.dll, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\fastprox.dll, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\fastprox.dll, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, C:\Windows\System32\ntdsapi.dll, , [77aa81231467c96d1ed49a07e61b36ca],
Trojan.FakeMS.ED, C:\Windows\System32\ntdsapi.dll, , [77aa81231467c96d1ed49a07e61b36ca],
Trojan.FakeMS.ED, C:\Windows\System32\ntdsapi.dll, , [77aa81231467c96d1ed49a07e61b36ca],
Trojan.FakeMS.ED, C:\Windows\System32\ntdsapi.dll, , [77aa81231467c96d1ed49a07e61b36ca],
Trojan.FakeMS.ED, C:\Windows\System32\webio.dll, , [0e13bee6a1dab680f5fd960b7a87a25e],
Trojan.FakeMS.ED, C:\Windows\System32\webio.dll, , [0e13bee6a1dab680f5fd960b7a87a25e],
Trojan.FakeMS.ED, C:\Windows\System32\webio.dll, , [0e13bee6a1dab680f5fd960b7a87a25e],
Trojan.FakeMS.ED, C:\Windows\System32\webio.dll, , [0e13bee6a1dab680f5fd960b7a87a25e],
Trojan.FakeMS.ED, C:\Windows\System32\ncrypt.dll, , [36ebaef6fd7e30067b77930e7889916f],
Trojan.FakeMS.ED, C:\Windows\System32\ncrypt.dll, , [36ebaef6fd7e30067b77930e7889916f],
Trojan.FakeMS.ED, C:\Windows\System32\ncrypt.dll, , [36ebaef6fd7e30067b77930e7889916f],
Trojan.FakeMS.ED, C:\Windows\System32\bcrypt.dll, , [44ddd8ccec8f082e539f4e53ca3703fd],
Trojan.FakeMS.ED, C:\Windows\System32\bcrypt.dll, , [44ddd8ccec8f082e539f4e53ca3703fd],
Trojan.FakeMS.ED, C:\Windows\System32\bcrypt.dll, , [44ddd8ccec8f082e539f4e53ca3703fd],
Trojan.FakeMS.ED, C:\Windows\System32\gpapi.dll, , [849d158ff586b97dfcf62b7606fb57a9],
Trojan.FakeMS.ED, C:\Windows\System32\gpapi.dll, , [849d158ff586b97dfcf62b7606fb57a9],
Trojan.FakeMS.ED, C:\Windows\System32\gpapi.dll, , [849d158ff586b97dfcf62b7606fb57a9],
Trojan.FakeMS.ED, C:\Windows\System32\cryptnet.dll, , [6eb391131a61ba7c5f93534e8180fd03],
Trojan.FakeMS.ED, C:\Windows\System32\cryptnet.dll, , [6eb391131a61ba7c5f93534e8180fd03],
Trojan.FakeMS.ED, C:\Windows\System32\SensApi.dll, , [5ec35351e59663d3c62c6f32b24f9868],
Trojan.FakeMS.ED, C:\Windows\System32\msvcr110_clr0400.dll, , [b36eacf866151f17a151f1b035ccb64a],
Trojan.FakeMS.ED, C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll, , [a180e2c20675072fc929a8f9936e43bd],
Trojan.FakeMS.ED, C:\Windows\System32\logoncli.dll, , [ed341b89c9b259dd7181861b1de456aa],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\wmiutils.dll, , [af72dcc8ea916fc7bd35f4adef123dc3],
Trojan.FakeMS.ED, C:\Windows\System32\msi.dll, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, C:\Windows\System32\msi.dll, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, C:\Windows\System32\netbios.dll, , [f72ae7bd92e9c96d846e1e83f90824dc],
Trojan.FakeMS.ED, C:\Windows\System32\mstask.dll, , [2bf65054c5b656e0bb37336e35ccf10f],
Trojan.FakeMS.ED, C:\Windows\System32\msvcp100.dll, , [18092381621977bfa64cc8d94bb653ad],
Trojan.FakeMS.ED, C:\Windows\System32\msvcp100.dll, , [18092381621977bfa64cc8d94bb653ad],
Trojan.FakeMS.ED, C:\Windows\System32\msvcr100.dll, , [d34edbc90e6d42f4c82a28796d94d828],
Trojan.FakeMS.ED, C:\Windows\System32\msvcr100.dll, , [d34edbc90e6d42f4c82a28796d94d828],

Registry Keys: 614
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\APPID\{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{042dc17c-023f-43df-a3ec-982b4dc78a64}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{042DC17C-023F-43DF-A3EC-982B4DC78A64}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{8d80504a-0826-40c5-97e1-ebc68f953792}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{8D80504A-0826-40C5-97E1-EBC68F953792}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{97e467b4-98c6-4f19-9588-161b7773d6f6}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{97E467B4-98C6-4F19-9588-161B7773D6F6}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{9a02e012-6303-4e1e-b9a1-630f802592c5}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{9A02E012-6303-4E1E-B9A1-630F802592C5}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{9cfc2df3-6ba3-46ef-a836-e519e81f0ec4}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{9CFC2DF3-6BA3-46EF-A836-E519E81F0EC4}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{b8967f85-58ae-4f46-9fb2-5d7904798f4b}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{B8967F85-58AE-4F46-9FB2-5D7904798F4B}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{C2566514-DD44-4c6c-AAAD-FBD2F18D8DEE}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C2566514-DD44-4C6C-AAAD-FBD2F18D8DEE}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{08244EE6-92F0-47f2-9FC9-929BAA2E7235}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{08244EE6-92F0-47F2-9FC9-929BAA2E7235}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{0A88C858-7D0C-4549-9499-7DB05F0CB0BF}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0A88C858-7D0C-4549-9499-7DB05F0CB0BF}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{12367cf8-6222-4b34-8ca8-3ce703999e28}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{12367CF8-6222-4B34-8CA8-3CE703999E28}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{1A0391BF-9564-4294-B0A4-06C298929EF9}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{1A0391BF-9564-4294-B0A4-06C298929EF9}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{40dd6e20-7c17-11ce-a804-00aa003ca9f6}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{40DD6E20-7C17-11CE-A804-00AA003CA9F6}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{49F371E1-8C5C-4d9c-9A3B-54A6827F513C}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{49F371E1-8C5C-4D9C-9A3B-54A6827F513C}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{59A437AB-74F3-4de2-AFE6-54203634C4DD}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{59A437AB-74F3-4DE2-AFE6-54203634C4DD}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{6311429E-2F1A-4777-880F-C7289FD10169}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6311429E-2F1A-4777-880F-C7289FD10169}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{77F419AA-771A-45ff-AC66-7567FA3243D3}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{77F419AA-771A-45FF-AC66-7567FA3243D3}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{7b4a83b6-f704-4b77-8e3d-c6087e3a21d2}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{7B4A83B6-F704-4B77-8E3D-C6087E3A21D2}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{CFF9990B-6414-43F1-A526-14EA5EEAFBDA}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CFF9990B-6414-43F1-A526-14EA5EEAFBDA}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{d4f01ada-979c-491e-bac3-cd3c0e7bcf82}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D4F01ADA-979C-491E-BAC3-CD3C0E7BCF82}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{edb5f444-cb8d-445a-a523-ec5ab6ea33c7}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\APPID\{EDB5F444-CB8D-445A-A523-EC5AB6EA33C7}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{EDB5F444-CB8D-445A-A523-EC5AB6EA33C7}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{EDB5F444-CB8D-445A-A523-EC5AB6EA33C7}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F81E9010-6EA4-11CE-A7FF-00AA003CA9F6}, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{B056521A-9B10-425E-B616-1FCD828DB3B1}, , [6ab77a2a66150a2c757dd9c830d1e020],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{B056521A-9B10-425E-B616-1FCD828DB3B1}, , [6ab77a2a66150a2c757dd9c830d1e020],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B056521A-9B10-425E-B616-1FCD828DB3B1}, , [6ab77a2a66150a2c757dd9c830d1e020],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{B056521A-9B10-425E-B616-1FCD828DB3B1}, , [6ab77a2a66150a2c757dd9c830d1e020],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{03022430-ABC4-11D0-BDE2-00AA001A1953}, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{03022430-ABC4-11D0-BDE2-00AA001A1953}, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03022430-ABC4-11D0-BDE2-00AA001A1953}, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03022430-ABC4-11D0-BDE2-00AA001A1953}, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{53362C32-A296-4F2D-A2F8-FD984D08340B}, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\TYPELIB\{8628F27C-64A2-4ed6-906B-E6155314C16A}, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{8628F27D-64A2-4ED6-906B-E6155314C16A}, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8628F27D-64A2-4ED6-906B-E6155314C16A}, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{8628F27C-64A2-4ed6-906B-E6155314C16A}, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\APPID\{53362C32-A296-4F2D-A2F8-FD984D08340B}, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{53362C32-A296-4F2D-A2F8-FD984D08340B}, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{53362C64-A296-4F2D-A2F8-FD984D08340B}, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\APPID\{53362C64-A296-4F2D-A2F8-FD984D08340B}, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{53362C64-A296-4F2D-A2F8-FD984D08340B}, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{443E7B79-DE31-11D2-B340-00104BCC4B4A}, , [36eb9a0a39429c9ae9099f0259a89d63],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{443E7B79-DE31-11D2-B340-00104BCC4B4A}, , [36eb9a0a39429c9ae9099f0259a89d63],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}, , [36eb9a0a39429c9ae9099f0259a89d63],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\WBEMComLocator, , [36eb9a0a39429c9ae9099f0259a89d63],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\WBEMComLocator, , [36eb9a0a39429c9ae9099f0259a89d63],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}, , [36eb9a0a39429c9ae9099f0259a89d63],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{CB8555CC-9128-11D1-AD9B-00C04FD8FDFF}, , [36eb9a0a39429c9ae9099f0259a89d63],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CB8555CC-9128-11D1-AD9B-00C04FD8FDFF}, , [36eb9a0a39429c9ae9099f0259a89d63],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{CD184336-9128-11D1-AD9B-00C04FD8FDFF}, , [36eb9a0a39429c9ae9099f0259a89d63],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CD184336-9128-11D1-AD9B-00C04FD8FDFF}, , [36eb9a0a39429c9ae9099f0259a89d63],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}, , [f42ddfc5d5a666d07a78a4fd7b866898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{7C857801-7381-11CF-884D-00AA004B2E24}, , [f42ddfc5d5a666d07a78a4fd7b866898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{7C857801-7381-11CF-884D-00AA004B2E24}, , [f42ddfc5d5a666d07a78a4fd7b866898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}, , [f42ddfc5d5a666d07a78a4fd7b866898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{29B5828C-CAB9-11D2-B35C-00105A1F8177}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{29B5828C-CAB9-11D2-B35C-00105A1F8177}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{7016F8FA-CCDA-11D2-B35C-00105A1F8177}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{7016F8FA-CCDA-11D2-B35C-00105A1F8177}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{78103FB7-AED7-4066-8BCD-30BB27B02331}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{78103FB7-AED7-4066-8BCD-30BB27B02331}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{8D1C559D-84F0-4BB3-A7D5-56A7435A9BA6}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{8D1C559D-84F0-4BB3-A7D5-56A7435A9BA6}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{9A653086-174F-11D2-B5F9-00104B703EFD}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{9A653086-174F-11D2-B5F9-00104B703EFD}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{C71566F2-561E-11D1-AD87-00C04FD8FDFF}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C71566F2-561E-11D1-AD87-00C04FD8FDFF}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{CC9072AB-C000-49D8-A5AA-00266C8DBB9B}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CC9072AB-C000-49D8-A5AA-00266C8DBB9B}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{CD1ABFC8-6C5E-4A8D-B90B-2A3B153B886D}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CD1ABFC8-6C5E-4A8D-B90B-2A3B153B886D}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{DCF33DF4-B510-439F-832A-16B6B514F2A7}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{DCF33DF4-B510-439F-832A-16B6B514F2A7}, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}, , [af72dcc8ea916fc7bd35f4adef123dc3],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}, , [af72dcc8ea916fc7bd35f4adef123dc3],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{EAC8A024-21E2-4523-AD73-A71A0AA2F56A}, , [af72dcc8ea916fc7bd35f4adef123dc3],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{EAC8A024-21E2-4523-AD73-A71A0AA2F56A}, , [af72dcc8ea916fc7bd35f4adef123dc3],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{EB87E1BD-3233-11D2-AEC9-00C04FB68820}, , [af72dcc8ea916fc7bd35f4adef123dc3],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{EB87E1BD-3233-11D2-AEC9-00C04FB68820}, , [af72dcc8ea916fc7bd35f4adef123dc3],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{000C103E-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{000C103E-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{000C1090-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\TYPELIB\{000C1092-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{000C1090-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{000C1093-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{000C1095-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{000C1096-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{000C109A-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{000C109B-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{000C109C-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{000C109D-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{000C109E-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{000C109F-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{000C10A0-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{000C10A1-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{000C1090-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{000C1093-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{000C1095-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{000C1096-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{000C109A-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{000C109B-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{000C109C-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{000C109D-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{000C109E-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{000C109F-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{000C10A0-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{000C10A1-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{000C1092-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\WindowsInstaller.Installer, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\WindowsInstaller.Installer, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{000C1090-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{000C1094-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{000C1094-0000-0000-C000-000000000046}, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WSearch, , [22ffbbe9710ae74fda189f0251b026da],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{148BD520-A2AB-11CE-B11F-00AA00530503}, , [2bf65054c5b656e0bb37336e35ccf10f],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\JobObject, , [2bf65054c5b656e0bb37336e35ccf10f],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\JobObject, , [2bf65054c5b656e0bb37336e35ccf10f],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{148BD520-A2AB-11CE-B11F-00AA00530503}, , [2bf65054c5b656e0bb37336e35ccf10f],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}, , [2bf65054c5b656e0bb37336e35ccf10f],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}, , [2bf65054c5b656e0bb37336e35ccf10f],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\1394ohci, , [45dcf2b22754a294a74b8c15c43d837d],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\i8042prt, , [c958fda74536e551fbf76e334fb24cb4],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\usbcir, , [849dabf973087eb88969fba650b157a9],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\blbdrive, , [ff2201a369123402638f6c35af52649c],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\sffdisk, , [b071e2c280fb74c26c86178a0bf604fc],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\isapnp, , [78a9267eeb9055e137bb940d1de4fd03],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\AcpiPmi, , [879af9ab0279e2540be78f1222dfde22],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\AFD, , [6fb26c386a1196a003ef9f0219e86c94],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\AsyncMac, , [64bd12929fdc12243ab8722f0100f010],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\srv, , [fa27911380fb74c249a96f32847d3ec2],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Smb, , [ef32bce8adce4ee8569c8e13fa0735cb],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\AmdPPM, , [849d119347348caa27cbbce5b74aaa56],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CLFS, , [ef32b3f14d2e043248aa2081ef12b14f],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\amdide, , [72af188c3f3c90a6648edcc5bd44b14f],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\AmdK8, , [b36e23817a013bfbfef4871a8b7634cc],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\circlass, , [34ed2b79cdae50e61ad8c1e0bc45ac54],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Mup, , [a978aafaa6d5d75f72803968f70ae11f],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CmBatt, , [9d84bee67ffca88e3fb3a00132cfe31d],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\AppID, , [43deb2f26d0edf57688abce5b34ea759],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\srv2, , [071a20840279f541d2200899b54cda26],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\bowser, , [a27f1490671469cdf5fdb8e9de23916f],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\intelide, , [958c1f851665c37309e9d6cbbd44669a],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\usbprint, , [c45d9f0503782412787a960beb16f30d],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\mountmgr, , [43de5c48324956e004ee633e28d9629e],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\BTHMODEM, , [8d94c6debdbecb6b07eba8f99e6342be],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\intelppm, , [8b96851f16654beb767c178a37ca946c],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\clr_optimization_v4.0.30319_64, , [978a4262473472c409e9c0e1b34ea957],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\cdfs, , [bb66b5ef1665c96dfef4851c40c1748c],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\srvnet, , [f72a960e97e4cc6ae111b9e810f16e92],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CSC, , [cb569b09275465d1fef4f4ad15ecc739],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CNG, , [6db4d4d0c8b380b617db2e7381804bb5],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WIMMount, , [aa778d17b1ca0630c32f079ad32eca36],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\MRxDAV, , [a67beaba82f91125be34bde417ea837d],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Compbatt, , [1f02762e0972fe3829c9752cb64bad53],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CompositeBus, , [59c88f152a5196a028ca376a9e63867a],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\crcdisk, , [a67bd4d089f200368f63594838c9c43c],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Disk, , [a67b554f9cdf00363db5168bd52c728e],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\DfsC, , [67bae9bb007b42f43cb6f5ace819fa06],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RasPppoe, , [50d17e2686f5e65079798819679a0bf5],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\discache, , [23fe871dec8f1d19ea087130e91818e8],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\dmvsc, , [33eedaca700bd95db73b6041d62b7a86],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\drmkaud, , [9e83d6ce215a2d09836fb3eeda2742be],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\DXGKrnl, , [71b0b1f36d0e0f27c82aa100a45ded13],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\UmPass, , [2af7a6fe4932b87efaf8c4dd03fe45bb],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TDTCP, , [2cf53c6893e8b0868b678120f30ef40c],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Tcpip, , [3de4792bee8df640f7fb465bf60bbe42],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP6, , [3de4792bee8df640f7fb465bf60bbe42],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\mrxsmb20, , [56cb1c8828532a0c975b267bed1425db],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\mrxsmb10, , [54cd11930e6da49227cb2e73857c6f91],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ehRecvr, , [c9581490f8839c9ac62cadf4b150c33d],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ehSched, , [120fb0f4572464d2c62cecb5c839f20e],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ErrDev, , [fd24287c2d4eb5814da56839a35e9c64],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\FileInfo, , [f031f7ad3e3dfa3cae441091649d18e8],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\fdc, , [bf62f4b05922171fc72ba3fe728f09f7],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IpFilterDriver, , [0d146044b7c444f247ab445da25fcc34],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Filetrace, , [140d7f25fa81ce6844aecdd427da0ff1],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\flpydisk, , [ec35aef69ae13bfb1ad84a57738eef11],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\FltMgr, , [be6370348af187afe80aa5fce51caf51],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\monitor, , [66bbadf7700b989e3cb6d0d1d42d0ff1],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\FsDepends, , [fd240e960e6d51e522d0c6db1de423dd],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\fvevol, , [33eef0b4a1da25117c76851c52afba46],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\gagp30kx, , [01209c08ea9163d3836fd8c904fdd729],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Rasl2tp, , [bc65fea6fb8052e4f4fedfc211f033cd],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\mrxsmb, , [ca57f9ab3e3dd75f28ca8b16b34eda26],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\HdAudAddService, , [55cc4460136866d019d9a8f901006799],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\HDAudBus, , [6eb3881c512ab581539f8c15d52cfa06],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\HidBatt, , [bf62b9ebc6b5dc5a61917e23c43d24dc],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\HidBth, , [77aac0e4750626104fa3f4adfb0654ac],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\HidIr, , [39e82c78f784bb7bd41e7928dc253ac6],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\HidUsb, , [30f1198bccaf3ff73db5d1d00ff2c33d],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\HTTP, , [db46b0f45a2168cea34ff8a9887923dd],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\hwpolicy, , [55cc00a43546bd795b97fca522dff010],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\idsvc, , [130ec8dc413a93a306ec4f5236cb30d0],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IPMIDRV, , [46db426282f91026b73b8d144cb50cf4],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IPNAT, , [36eb1b8917646bcbb73b2b764db4ba46],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IRENUM, , [f928c2e23447fb3b836f6b36be43c838],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\iScsiPrt, , [cf528e165d1e89ad0be7cfd2f30e0000],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\mssmbios, , [d849b9eb83f83bfb03ef7f22b1509070],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\volmgr, , [6cb57331f18adb5b8b67d5ccbf422dd3],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\kbdhid, , [0a17a6fe1d5eda5ced05524fc93814ec],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ws2ifsl, , [5ac78a1a027940f6cd2530718978817f],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\KSecDD, , [1e033e66295257df26cc524fad549b65],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\KSecPkg, , [58c9396bea915adc9161e2bf5ba625db],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ksthunk, , [a47d7133760596a02fc3ddc48f7214ec],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\lltdio, , [041dffa5e49737ff34be039eae53f60a],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\tunnel, , [dc45bbe982f9c175668cf5ac38c951af],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NdisTapi, , [8c959212ef8c92a40ce69c05c041d927],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\luafv, , [978a366ecbb0d85ed51d574a867b45bb],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\mpio, , [61c0b3f1f685aa8c3db5dac7aa5709f7],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\msdsm, , [fb26772d1c5f3600f3ff5f42fd04c33d],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Modem, , [1011a6fea6d5b77f20d2eeb35ba6659b],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\mouclass, , [58c9564e87f40531c72bd9c8f60bf10f],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\mouhid, , [f72a2a7add9e76c0648ee3be3bc67d83],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\mpsdrv, , [81a06242ef8c71c5ce245d44de23a957],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\msahci, , [fb2620846d0eb3839b57e1c0b34ed828],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\mshidkmdf, , [7ba68a1af883201602f07a27c8390bf5],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\MSTEE, , [a67b8b1980fb7bbba44eb8e9e21f3fc1],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\msisadrv, , [958c5c48c8b3e4521dd5099821e038c8],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\MTConfig, , [ec35663e3744d66045ad138edc25b34d],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NativeWifiP, , [08195e466a111d1929c9416011f0c43c],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NdisCap, , [8e93f8acdaa1d264db17574acf3242be],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Ndisuio, , [ae735054e19ab482dd153b665ca56898],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NdisWan, , [9f82c0e4611ad75f6191dfc2de23c838],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NetBT, , [cd54b9ebafccfe38ba38732e1ee3ef11],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\nsiproxy, , [7aa77430d8a341f516dcb2ef68991be5],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\nv_agp, , [b66be5bf017a6ccacf23d8c91de4ac54],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ohci1394, , [0b16c4e0b8c32e080ae8039e6a9725db],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Parport, , [2df4dfc5710a90a603efbfe2d62bb54b],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\partmgr, , [65bc693b1368122432c0f1b01ce58878],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\pcw, , [0120970da0db280e559d574ac73adc24],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\pciide, , [9c8591135229cb6bc52de7bab8497789],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\pcmcia, , [3ae77a2a017a9e988270b0f1f0119d63],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\PEAUTH, , [a47d03a193e839fdcd25b3ee37cad927],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\QWAVEdrv, , [72af6a3a3c3f4de904ee9a07689920e0],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\PptpMiniport, , [b0716044770460d6d121247d2bd6a060],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Processor, , [ca571c88f685fc3a8c668b16e51cf60a],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Psched, , [52cfa9fbbfbc77bf48aa38695ca54db3],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RasAcd, , [5fc2a5ff1f5caa8cb1416b362fd2728e],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RasAgileVpn, , [8f92455fdaa174c2d022b7ea55ac6f91],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\rdbss, , [012003a19fdc7eb820d20d94966b3fc1],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RasSstp, , [25fc347009725bdb9260554c926f758b],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\rdpbus, , [c0617e26a5d6b48250a25f42d928ee12],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\rspndr, , [849d5e46ef8cea4caa48455c2fd2bc44],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RDPCDD, , [9c85ecb84437ff37e50d8a1752af3ac6],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RDPDR, , [f72ae2c2bebd8aac21d1e6bb04fd04fc],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RDPENCDD, , [2bf6376df9825cda1dd50b96bf42a65a],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RDPREFMP, , [ce532d772259c373569cdbc63cc5768a],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RdpVideoMiniport, , [91909d07bebdf83ec1318b168c758f71],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\rdyboost, , [0c15c9dbd3a83ff77f73e7badf2249b7],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\s3cap, , [43decbd9bfbc1026d9196a37fa078a76],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\sbp2port, , [25fc7f255b200b2b8f638d148d7403fd],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\scfilter, , [948d3d67671490a61bd7acf5af529f61],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Serenum, , [7fa2aafa3e3dd46247ab5a47e61b19e7],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\sermouse, , [e0415a4a0a71fb3b3eb4c8d908f939c7],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\sffp_mmc, , [130e475daecdcf671dd5cfd2f30e837d],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\sffp_sd, , [d24f7232dd9eee48668c960b778a6e92],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\sfloppy, , [7fa20f95304b6dc9de14039e778a60a0],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\storflt, , [8d94f7ad027948ee24ce148dc04160a0],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\storvsc, , [e839386ca5d6bc7ada1871307889e917],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\swenum, , [061bf8ac0b7048ee9959762b42bf1ae6],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\tcpipreg, , [0d14485ca6d50d2900f2871a659c4eb2],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TDPIPE, , [a47d2381740760d65999317023deec14],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\tdx, , [d150e8bc62195ed8e30fcdd438c9bc44],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TermDD, , [91909410ee8df83e50a2920f49b81ee2],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\tssecsrv, , [59c8eeb6116a092d6f834160dd241fe1],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TsUsbFlt, , [a47d4b59413ab383d31faff2e51cd52b],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TsUsbGD, , [9f82a7fdabd00e28e80a6140ac558c74],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\uagp35, , [9c85dbc9d6a579bd10e29908689905fb],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\udfs, , [df423e66c9b2dc5a2ac8455cde236c94],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\uliagpkx, , [d64bb9eb95e653e3a250059ce21fb749],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\umbus, , [23feeeb628538fa7f101544d10f102fe],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\usbaudio, , [938e8f1577047cba638fd6cb936e10f0],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\usbccgp, , [f829c6de2e4d8babd919732e36cb817f],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\usbuhci, , [a37efca842393bfbad455051867b2cd4],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\usbohci, , [48d98c1883f8e74fb939287931d00af6],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\usbehci, , [a47dd8cc2b50f1453bb78a17c938cd33],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\USBSTOR, , [061b772d1b60ba7ca54d673a47bacd33],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\vdrvroot, , [948de3c1dc9f51e5ee042a772bd68e72],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\vga, , [bb66e8bc285383b3b939ecb5c140bc44],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\VgaSave, , [ea37ffa5b3c8cd693db5930eb74ad828],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\vhdmp, , [f32e1c8876051f17fcf6722f4ab733cd],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\vmbus, , [4dd404a0f883f1453db51b8630d1f50b],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\VMBusHID, , [4cd5594bb0cb37ff17dbfba62cd53fc1],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\volmgrx, , [df425c48ed8e171f5c962a778f722bd5],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\vwifibus, , [879a495b4a31ce68ec062f72c83927d9],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WacomPen, , [48d9ced6b8c33df9975b6a37e61b2bd5],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WUDFRd, , [b56ca400304b90a6658d346db15018e8],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WANARP, , [ce53f7ad3e3d053100f22180cb36e21e],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Wanarpv6, , [ce53f7ad3e3d053100f22180cb36e21e],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WinUsb, , [c061990b106b1a1cb939d9c8a1609070],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Wd, , [c65bfea6b0cbf64035bd2978ef12ec14],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WfpLwf, , [db46257f4c2fbc7a3bb7366b847dac54],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WmiAcpi, , [9f82f4b01c5fd462678b3a67a75a7987],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WudfPf, , [c55ce8bc433867cf589a1190b74acd33],
Trojan.FakeMS.ED, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\xusb21, , [e73a752fb9c267cf43af861bea1727d9],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{0700F42F-EEE3-443a-9899-166F16286796}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0700F42F-EEE3-443A-9899-166F16286796}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{0D0E47ED-7220-411f-8F81-1118095DA5E7}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0D0E47ED-7220-411F-8F81-1118095DA5E7}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{19352205-42B0-4690-9AA4-D7DB9AE5F259}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{19352205-42B0-4690-9AA4-D7DB9AE5F259}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{3ABEAFC4-F48F-4517-A9B0-8AD6A94A99A1}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3ABEAFC4-F48F-4517-A9B0-8AD6A94A99A1}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{5E032150-8C1E-4c9e-BC60-36E9BFFCFF56}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{7be73787-ce71-4b33-b4c8-00d32b54bea8}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{7BE73787-CE71-4B33-B4C8-00D32B54BEA8}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{9F36C194-166C-4cbf-B7EA-BF039F950172}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{C605507B-9613-4756-9C07-E0D74321CB1E}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C605507B-9613-4756-9C07-E0D74321CB1E}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{C707F6A6-A1F3-45d7-99AA-A2B9491E84AD}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C707F6A6-A1F3-45D7-99AA-A2B9491E84AD}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{DE77BA04-3C92-4d11-A1A5-42352A53E0E3}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{DE77BA04-3C92-4D11-A1A5-42352A53E0E3}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{DF60686C-2941-4893-80C0-F13173B719D3}, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{4E14FBA2-2E22-11D1-9964-00C04FBBB345}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\EventSystem.EventSystem.1, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\EventSystem.EventSystem, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\EventSystem.EventSystem, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\EventSystem.EventSystem.1, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\APPID\{4E14FBA2-2E22-11D1-9964-00C04FBBB345}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{4E14FBA2-2E22-11D1-9964-00C04FBBB345}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4E14FBA2-2E22-11D1-9964-00C04FBBB345}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{64B8F404-A4AE-11D1-B7B6-00C04FB926AF}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{64B8F404-A4AE-11D1-B7B6-00C04FB926AF}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{64B8F404-A4AE-11D1-B7B6-00C04FB926AF}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{64B8F404-A4AE-11D1-B7B6-00C04FB926AF}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{7542E960-79C7-11D1-88F9-0080C7D771BF}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\EventSystem.EventSubscription, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\EventSystem.EventSubscription.1, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\EventSystem.EventSubscription.1, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\EventSystem.EventSubscription, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{7542E960-79C7-11D1-88F9-0080C7D771BF}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{AB944620-79C6-11D1-88F9-0080C7D771BF}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\EventSystem.EventPublisher.1, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\EventSystem.EventPublisher, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\EventSystem.EventPublisher, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\EventSystem.EventPublisher.1, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{AB944620-79C6-11D1-88F9-0080C7D771BF}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{BB07BACD-CD56-4E63-A8FF-CBF0355FB9F4}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\APPID\{BB07BACD-CD56-4E63-A8FF-CBF0355FB9F4}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{BB07BACD-CD56-4E63-A8FF-CBF0355FB9F4}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{BB07BACD-CD56-4E63-A8FF-CBF0355FB9F4}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{CDBEC9C0-7A68-11D1-88F9-0080C7D771BF}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\EventSystem.EventClass, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\EventSystem.EventClass.1, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\EventSystem.EventClass.1, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\EventSystem.EventClass, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CDBEC9C0-7A68-11D1-88F9-0080C7D771BF}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{D0565000-9DF4-11D1-A281-00C04FCA0AA7}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\APPID\{D0565000-9DF4-11D1-A281-00C04FCA0AA7}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D0565000-9DF4-11D1-A281-00C04FCA0AA7}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D0565000-9DF4-11D1-A281-00C04FCA0AA7}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{D5978620-5B9F-11D1-8DD2-00AA004ABD5E}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D5978620-5B9F-11D1-8DD2-00AA004ABD5E}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{D5978630-5B9F-11D1-8DD2-00AA004ABD5E}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D5978630-5B9F-11D1-8DD2-00AA004ABD5E}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{D5978640-5B9F-11D1-8DD2-00AA004ABD5E}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D5978640-5B9F-11D1-8DD2-00AA004ABD5E}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{D5978650-5B9F-11D1-8DD2-00AA004ABD5E}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D5978650-5B9F-11D1-8DD2-00AA004ABD5E}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{ECABB0C3-7F19-11D2-978E-0000F8757E2A}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\APPID\{ECABB0C3-7F19-11D2-978E-0000F8757E2A}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{ECABB0C3-7F19-11D2-978E-0000F8757E2A}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{ECABB0C3-7F19-11D2-978E-0000F8757E2A}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{ECABB0C6-7F19-11D2-978E-0000F8757E2A}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\APPID\{ECABB0C6-7F19-11D2-978E-0000F8757E2A}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{ECABB0C6-7F19-11D2-978E-0000F8757E2A}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{ECABB0C6-7F19-11D2-978E-0000F8757E2A}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\APPID\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\TYPELIB\{4E14FB90-2E22-11D1-9964-00C04FBBB345}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{0343E2F4-86F6-11D1-B760-00C04FB926AF}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{0771CB93-DA7C-44B5-8196-422E6A2FBC40}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{4A6B0E15-2E38-11D1-9965-00C04FBBB345}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{4A6B0E16-2E38-11D1-9965-00C04FBBB345}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E14FB9F-2E22-11D1-9964-00C04FBBB345}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{784121F1-62A6-4B89-855F-D65F296DE83A}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{7FB7EA43-2D76-4EA8-8CD9-3DECC270295E}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{99CC098F-A48A-4E9C-8E58-965C0AFC19D5}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{DA538EE2-F4DE-11D1-B6BB-00805FC79216}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{E0498C93-4EFE-11D1-9971-00C04FBBB345}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{E341516B-2E32-11D1-9964-00C04FBBB345}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{F89AC270-D4EB-11D1-B682-00805FC79216}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{FB2B72A0-7A68-11D1-88F9-0080C7D771BF}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{FB2B72A1-7A68-11D1-88F9-0080C7D771BF}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{FBC1D17D-C498-43A0-81AF-423DDD530AF6}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0343E2F4-86F6-11D1-B760-00C04FB926AF}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0771CB93-DA7C-44B5-8196-422E6A2FBC40}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4A6B0E15-2E38-11D1-9965-00C04FBBB345}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4A6B0E16-2E38-11D1-9965-00C04FBBB345}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E14FB9F-2E22-11D1-9964-00C04FBBB345}, , [4ed3b2f23843ba7c09e98f12b051c838],
 

Link to post
Share on other sites

Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{784121F1-62A6-4B89-855F-D65F296DE83A}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{7FB7EA43-2D76-4EA8-8CD9-3DECC270295E}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{99CC098F-A48A-4E9C-8E58-965C0AFC19D5}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DA538EE2-F4DE-11D1-B6BB-00805FC79216}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E0498C93-4EFE-11D1-9971-00C04FBBB345}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E341516B-2E32-11D1-9964-00C04FBBB345}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F89AC270-D4EB-11D1-B682-00805FC79216}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FB2B72A0-7A68-11D1-88F9-0080C7D771BF}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FB2B72A1-7A68-11D1-88F9-0080C7D771BF}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FBC1D17D-C498-43A0-81AF-423DDD530AF6}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{4E14FB90-2E22-11D1-9964-00C04FBBB345}, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{ADAB9B51-4CDD-4af0-892C-AB7FA7B3293F}, , [0e132d775d1e8da9cb27bae739c81ee2],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{ADAB9B51-4CDD-4AF0-892C-AB7FA7B3293F}, , [0e132d775d1e8da9cb27bae739c81ee2],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{B3FF88A4-96EC-4CC1-983F-72BE0EBB368B}, , [0e132d775d1e8da9cb27bae739c81ee2],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\TYPELIB\{DCB00D01-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{DCB00000-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{DCB00001-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{DCB00002-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{DCB00003-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{DCB00004-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{DCB00005-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{DCB00006-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{DCB00007-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DCB00000-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DCB00001-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DCB00002-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DCB00003-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DCB00004-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DCB00005-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DCB00006-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DCB00007-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{DCB00D01-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{03837511-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\TYPELIB\{03837500-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{038374FF-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{03837502-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{03837506-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{0383750B-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{03837510-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{03837512-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{03837514-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{03837516-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{0383751a-098b-11d8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{03837520-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{03837524-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{03837533-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{03837534-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{0383753A-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{0383753D-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{03837541-098b-11d8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{03837543-098b-11d8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\INTERFACE\{03837544-098b-11d8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{038374FF-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03837502-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03837506-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0383750B-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03837510-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03837512-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03837514-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03837516-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0383751a-098b-11d8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03837520-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03837524-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03837533-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03837534-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0383753A-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0383753D-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03837541-098b-11d8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03837543-098b-11d8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{03837544-098b-11d8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{03837500-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.TraceDataProviderCollection.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.TraceDataProviderCollection, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.TraceDataProviderCollection, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.TraceDataProviderCollection.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03837511-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{03837513-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.TraceDataProvider.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.TraceDataProvider, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.TraceDataProvider, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.TraceDataProvider.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03837513-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{0383751C-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.TraceSession.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.TraceSession, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.TraceSession, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.TraceSession.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0383751C-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{03837521-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.DataCollectorSet.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.DataCollectorSet, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.DataCollectorSet, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.DataCollectorSet.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03837521-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{03837525-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.DataCollectorSetCollection.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.DataCollectorSetCollection, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.DataCollectorSetCollection, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.DataCollectorSetCollection.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03837525-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{03837526-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.LegacyDataCollectorSet.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.LegacyDataCollectorSet, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.LegacyDataCollectorSet, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.LegacyDataCollectorSet.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03837526-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{03837527-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.LegacyDataCollectorSetCollection.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.LegacyDataCollectorSetCollection, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.LegacyDataCollectorSetCollection, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.LegacyDataCollectorSetCollection.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03837527-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{03837528-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.LegacyTraceSession.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.LegacyTraceSession, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.LegacyTraceSession, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.LegacyTraceSession.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03837528-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{03837529-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.LegacyTraceSessionCollection.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.LegacyTraceSessionCollection, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.LegacyTraceSessionCollection, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.LegacyTraceSessionCollection.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03837529-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{03837530-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.TraceSessionCollection.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.TraceSessionCollection, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.TraceSessionCollection, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.TraceSessionCollection.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03837530-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{03837531-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.ServerDataCollectorSet.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.ServerDataCollectorSet, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.ServerDataCollectorSet, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.ServerDataCollectorSet.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03837531-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{03837532-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.ServerDataCollectorSetCollection.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.ServerDataCollectorSetCollection, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.ServerDataCollectorSetCollection, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.ServerDataCollectorSetCollection.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03837532-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{03837538-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.BootTraceSession.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.BootTraceSession, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.BootTraceSession, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.BootTraceSession.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03837538-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{03837539-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.BootTraceSessionCollection.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.BootTraceSessionCollection, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.BootTraceSessionCollection, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.BootTraceSessionCollection.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03837539-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{03837546-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.SystemDataCollectorSet.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.SystemDataCollectorSet, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.SystemDataCollectorSet, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.SystemDataCollectorSet.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03837546-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{03837547-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.SystemDataCollectorSetCollection.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\PLA.SystemDataCollectorSetCollection, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.SystemDataCollectorSetCollection, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PLA.SystemDataCollectorSetCollection.1, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03837547-098B-11D8-9414-505054503030}, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{55B3A0BD-4D28-42fe-8CFB-FA3EDFF969B8}, , [051c7c28186376c020d289189c65f20e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{A6A3E580-083F-471b-8F08-87D34F678C95}, , [051c7c28186376c020d289189c65f20e],
Trojan.FakeMS.ED, HKLM\SOFTWARE\CLASSES\CLSID\{900be39d-6be8-461a-bc4d-b0fa71f5ecb1}, , [cc55fca83f3cc67033bf742d8180f808],
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{900BE39D-6BE8-461A-BC4D-B0FA71F5ECB1}, , [cc55fca83f3cc67033bf742d8180f808],

Registry Values: 6
Trojan.FakeMS.ED, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\SHAREDDLLS|C:\WINDOWS\SYSTEM32\MSVCR110_CLR0400.DLL, 1, , [b36eacf866151f17a151f1b035ccb64a]
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\SHAREDDLLS|C:\WINDOWS\SYSTEM32\MSVCR110_CLR0400.DLL, 1, , [b36eacf866151f17a151f1b035ccb64a]
Trojan.FakeMS.ED, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\SHAREDDLLS|C:\WINDOWS\SYSTEM32\MSVCP100.DLL, 1, , [18092381621977bfa64cc8d94bb653ad]
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\SHAREDDLLS|C:\WINDOWS\SYSTEM32\MSVCP100.DLL, 1, , [18092381621977bfa64cc8d94bb653ad]
Trojan.FakeMS.ED, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\SHAREDDLLS|C:\WINDOWS\SYSTEM32\MSVCR100.DLL, 1, , [d34edbc90e6d42f4c82a28796d94d828]
Trojan.FakeMS.ED, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\SHAREDDLLS|C:\WINDOWS\SYSTEM32\MSVCR100.DLL, 1, , [d34edbc90e6d42f4c82a28796d94d828]

Registry Data: 7
Trojan.FakeMS.ED, HKLM\SYSTEM\CurrentControlSet\Control\Lsa|Authentication Packages, msv1_0^^, Good: (), Bad: (msv1_0),,[19080d979ae147eff2003b66d031f907]
Trojan.FakeMS.ED, HKLM\SYSTEM\CurrentControlSet\Control\Lsa|Security Packages, kerberos^msv1_0^schannel^wdigest^tspkg^pku2u^^, Good: (), Bad: (msv1_0),,[19080d979ae147eff2003b66d031f907]
Trojan.FakeMS.ED, HKLM\SYSTEM\CurrentControlSet\Control\Lsa|Notification Packages, scecli^^, Good: (), Bad: (scecli),,[071a1e867b001026c82aeeb30af7f808]
Trojan.FakeMS.ED, HKLM\SYSTEM\CurrentControlSet\Control\Lsa|Security Packages, kerberos^msv1_0^schannel^wdigest^tspkg^pku2u^^, Good: (), Bad: (kerberos),,[b66b099b700bc96d4ba76a37df227c84]
Trojan.FakeMS.ED, HKLM\SYSTEM\CurrentControlSet\Control\Lsa|Security Packages, kerberos^msv1_0^schannel^wdigest^tspkg^pku2u^^, Good: (), Bad: (schannel),,[b46de9bb0972082e579b425f4cb5f10f]
Trojan.FakeMS.ED, HKLM\SYSTEM\CurrentControlSet\Control\Lsa|Security Packages, kerberos^msv1_0^schannel^wdigest^tspkg^pku2u^^, Good: (), Bad: (wdigest),,[62bf980c651634021bd7aff236cbff01]
Trojan.FakeMS.ED, HKLM\SYSTEM\CurrentControlSet\Control\Lsa|Security Packages, kerberos^msv1_0^schannel^wdigest^tspkg^pku2u^^, Good: (), Bad: (tspkg),,[7aa7edb780fb1d1924cefba6768baa56]

Folders: 0
(No malicious items detected)

Files: 298
Trojan.FakeMS.ED, C:\Windows\System32\userenv.dll, , [d74a6f35adce8fa7faf8dbc6ed145fa1],
Trojan.FakeMS.ED, C:\Windows\System32\profapi.dll, , [c75af1b30378211550a2237e49b858a8],
Trojan.FakeMS.ED, C:\Windows\System32\mpr.dll, , [a9784262562583b33ab8e8b9cb363ac6],
Trojan.FakeMS.ED, C:\Windows\System32\IPHLPAPI.DLL, , [71b04e56a9d2c17535bd515050b1ad53],
Trojan.FakeMS.ED, C:\Windows\System32\winnsi.dll, , [21005b4948330d2912e0465b5ca5c838],
Trojan.FakeMS.ED, C:\Windows\System32\winmm.dll, , [24fd3e66106b4fe733bfa5fc3cc513ed],
Trojan.FakeMS.ED, C:\Windows\System32\uxtheme.dll, , [8998297b2853eb4b6092861b0bf6bc44],
Trojan.FakeMS.ED, C:\Windows\System32\netapi32.dll, , [c0614064fb8060d61cd66938669b41bf],
Trojan.FakeMS.ED, C:\Windows\System32\netutils.dll, , [3fe2f7ad4a3184b26f83f3ae9d64d22e],
Trojan.FakeMS.ED, C:\Windows\System32\srvcli.dll, , [4cd57f2518633501945ee1c013eec937],
Trojan.FakeMS.ED, C:\Windows\System32\wkscli.dll, , [958cc6de6a1163d3846e138eeb162cd4],
Trojan.FakeMS.ED, C:\Windows\System32\dwmapi.dll, , [041d2c78a4d7b284be346b368978f10f],
Trojan.FakeMS.ED, C:\Windows\System32\apphelp.dll, , [5dc4bee69dde86b003ef099839c8b947],
Trojan.FakeMS.ED, C:\Windows\System32\propsys.dll, , [e23fa004b3c8b18528ca673aab568080],
Trojan.FakeMS.ED, C:\Windows\System32\ntmarta.dll, , [e9387c282358d36329c9e8b9d03118e8],
Trojan.FakeMS.ED, C:\Windows\System32\ntshrui.dll, , [a879dacab4c773c3dc167d249a67cc34],
Trojan.FakeMS.ED, C:\Windows\System32\cscapi.dll, , [61c0dacaadce66d0fef4b7eaea1740c0],
Trojan.FakeMS.ED, C:\Windows\System32\mswsock.dll, , [e53cefb59cdfcf6703efd8c9946d60a0],
Trojan.FakeMS.ED, C:\Windows\System32\wship6.dll, , [9c85554f700b7eb8f8fa376a1ae711ef],
Trojan.FakeMS.ED, C:\Windows\System32\FWPUCLNT.DLL, , [8899554fb0cb0234ec064f5258a95ba5],
Trojan.FakeMS.ED, C:\Windows\System32\RPCRTREMOTE.DLL, , [e43dfea6e398280e8e64158cd0316e92],
Trojan.FakeMS.ED, C:\Windows\System32\mssprxy.dll, , [6ab77a2a66150a2c757dd9c830d1e020],
Trojan.FakeMS.ED, C:\Windows\System32\lsm.exe, , [af728420413ae35307ebc7dafc0545bb],
Trojan.FakeMS.ED, C:\Windows\System32\devrtl.dll, , [9f823b69631855e13db5960b9869cf31],
Trojan.FakeMS.ED, C:\Windows\System32\SPInf.dll, , [b0712a7a5c1f56e0945eaef3ac552fd1],
Trojan.FakeMS.ED, C:\Windows\System32\dbghelp.dll, , [da4742621c5f8da9b83a7f229d649b65],
Trojan.FakeMS.ED, C:\Windows\System32\secur32.dll, , [ae73cadae794ac8aeb073b66728fc23e],
Trojan.FakeMS.ED, C:\Windows\System32\rtutils.dll, , [e73af9ab037821156f833170ca37fc04],
Trojan.FakeMS.ED, C:\Windows\System32\DHCPCSVC6.DLL, , [da475b494b30dd59a34f812042bff50b],
Trojan.FakeMS.ED, C:\Windows\System32\dhcpcsvc.dll, , [130e0c985a21c2748f631c85c33e1ce4],
Trojan.FakeMS.ED, C:\Windows\System32\nlaapi.dll, , [fd24287c334860d6bc36d0d1bc45c33d],
Trojan.FakeMS.ED, C:\Windows\System32\NapiNSP.dll, , [27faf4b091eae353df139f025ca5e51b],
Trojan.FakeMS.ED, C:\Windows\System32\pnrpnsp.dll, , [f9286044f28946f06a88435efd046c94],
Trojan.FakeMS.ED, C:\Windows\System32\winrnr.dll, , [a978baea9dde90a621d1772af70add23],
Trojan.FakeMS.ED, C:\Windows\System32\rasapi32.dll, , [ea37ddc7ec8fb581fbf73b6625dc2dd3],
Trojan.FakeMS.ED, C:\Windows\System32\rasman.dll, , [d051584c1a617bbba74b940ddf22b24e],
Trojan.FakeMS.ED, C:\Windows\System32\xmllite.dll, , [88995c48106b2e08e40ecfd2946d3ac6],
Trojan.FakeMS.ED, C:\Windows\System32\taskhost.exe, , [fa275e467b0075c1c2300d94be43ed13],
Trojan.FakeMS.ED, C:\Windows\System32\dwm.exe, , [0a172381146730062ec4851c16eb3bc5],
Trojan.FakeMS.ED, C:\Windows\System32\oleacc.dll, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, C:\Windows\SysWOW64\oleacc.dll, , [de436d37e19a93a38b6788198a7744bc],
Trojan.FakeMS.ED, C:\Windows\System32\sxs.dll, , [a9787e26fc7f67cf2cc64a57e021a65a],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\wbemprox.dll, , [36eb9a0a39429c9ae9099f0259a89d63],
Trojan.FakeMS.ED, C:\Windows\System32\wbemcomn.dll, , [43de6a3a96e54fe729c9970a29d8e818],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\wbemsvc.dll, , [f42ddfc5d5a666d07a78a4fd7b866898],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\fastprox.dll, , [b46dd1d3f685fe38faf82e7335cca35d],
Trojan.FakeMS.ED, C:\Windows\System32\ntdsapi.dll, , [77aa81231467c96d1ed49a07e61b36ca],
Trojan.FakeMS.ED, C:\Windows\System32\webio.dll, , [0e13bee6a1dab680f5fd960b7a87a25e],
Trojan.FakeMS.ED, C:\Windows\System32\ncrypt.dll, , [36ebaef6fd7e30067b77930e7889916f],
Trojan.FakeMS.ED, C:\Windows\System32\bcrypt.dll, , [44ddd8ccec8f082e539f4e53ca3703fd],
Trojan.FakeMS.ED, C:\Windows\System32\gpapi.dll, , [849d158ff586b97dfcf62b7606fb57a9],
Trojan.FakeMS.ED, C:\Windows\System32\cryptnet.dll, , [6eb391131a61ba7c5f93534e8180fd03],
Trojan.FakeMS.ED, C:\Windows\System32\SensApi.dll, , [5ec35351e59663d3c62c6f32b24f9868],
Trojan.FakeMS.ED, C:\Windows\System32\msvcr110_clr0400.dll, , [b36eacf866151f17a151f1b035ccb64a],
Trojan.FakeMS.ED, C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll, , [a180e2c20675072fc929a8f9936e43bd],
Trojan.FakeMS.ED, C:\Windows\System32\logoncli.dll, , [ed341b89c9b259dd7181861b1de456aa],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\wmiutils.dll, , [af72dcc8ea916fc7bd35f4adef123dc3],
Trojan.FakeMS.ED, C:\Windows\System32\msi.dll, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, C:\Windows\SysWOW64\msi.dll, , [8f924b596c0fa49214deacf59e63837d],
Trojan.FakeMS.ED, C:\Windows\System32\netbios.dll, , [f72ae7bd92e9c96d846e1e83f90824dc],
Trojan.FakeMS.ED, C:\Windows\System32\conhost.exe, , [c45d34700a717bbb638f4b5615ec6a96],
Trojan.FakeMS.ED, C:\Windows\System32\SEARCHINDEXER.EXE, , [22ffbbe9710ae74fda189f0251b026da],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\WmiPrvSE.exe, , [b8698222a6d5bb7bdf13f3ae9a67e61a],
Trojan.FakeMS.ED, C:\Windows\System32\mstask.dll, , [2bf65054c5b656e0bb37336e35ccf10f],
Trojan.FakeMS.ED, C:\Windows\System32\msvcp100.dll, , [18092381621977bfa64cc8d94bb653ad],
Trojan.FakeMS.ED, C:\Windows\System32\msvcr100.dll, , [d34edbc90e6d42f4c82a28796d94d828],
Trojan.FakeMS.ED, C:\Windows\System32\msv1_0.dll, , [19080d979ae147eff2003b66d031f907],
Trojan.FakeMS.ED, C:\Windows\System32\scecli.dll, , [071a1e867b001026c82aeeb30af7f808],
Trojan.FakeMS.ED, C:\Windows\System32\kerberos.dll, , [b66b099b700bc96d4ba76a37df227c84],
Trojan.FakeMS.ED, C:\Windows\System32\schannel.dll, , [b46de9bb0972082e579b425f4cb5f10f],
Trojan.FakeMS.ED, C:\Windows\System32\wdigest.dll, , [62bf980c651634021bd7aff236cbff01],
Trojan.FakeMS.ED, C:\Windows\System32\TSpkg.dll, , [7aa7edb780fb1d1924cefba6768baa56],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\1394ohci.sys, , [45dcf2b22754a294a74b8c15c43d837d],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\i8042prt.sys, , [c958fda74536e551fbf76e334fb24cb4],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\usbcir.sys, , [849dabf973087eb88969fba650b157a9],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\blbdrive.sys, , [ff2201a369123402638f6c35af52649c],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\sffdisk.sys, , [b071e2c280fb74c26c86178a0bf604fc],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\isapnp.sys, , [78a9267eeb9055e137bb940d1de4fd03],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\acpipmi.sys, , [879af9ab0279e2540be78f1222dfde22],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\afd.sys, , [6fb26c386a1196a003ef9f0219e86c94],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\cdrom.sys, , [f22f950f522924129d55069bbe43b44c],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\asyncmac.sys, , [64bd12929fdc12243ab8722f0100f010],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\AGP440.sys, , [39e87034c4b75dd99959564bcd3430d0],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\srv.sys, , [fa27911380fb74c249a96f32847d3ec2],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\smb.sys, , [ef32bce8adce4ee8569c8e13fa0735cb],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\amdppm.sys, , [849d119347348caa27cbbce5b74aaa56],
Trojan.FakeMS.ED, C:\Windows\System32\clfs.sys, , [ef32b3f14d2e043248aa2081ef12b14f],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\amdide.sys, , [72af188c3f3c90a6648edcc5bd44b14f],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\amdk8.sys, , [b36e23817a013bfbfef4871a8b7634cc],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\circlass.sys, , [34ed2b79cdae50e61ad8c1e0bc45ac54],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\mup.sys, , [a978aafaa6d5d75f72803968f70ae11f],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\CmBatt.sys, , [9d84bee67ffca88e3fb3a00132cfe31d],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\appid.sys, , [43deb2f26d0edf57688abce5b34ea759],
Trojan.FakeMS.ED, C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe, , [c35e396bb5c6033302f09809bd4425db],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\srv2.sys, , [071a20840279f541d2200899b54cda26],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\bowser.sys, , [a27f1490671469cdf5fdb8e9de23916f],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\intelide.sys, , [958c1f851665c37309e9d6cbbd44669a],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\usbprint.sys, , [c45d9f0503782412787a960beb16f30d],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\mountmgr.sys, , [43de5c48324956e004ee633e28d9629e],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\bthmodem.sys, , [8d94c6debdbecb6b07eba8f99e6342be],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\intelppm.sys, , [8b96851f16654beb767c178a37ca946c],
Trojan.FakeMS.ED, C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe, , [978a4262473472c409e9c0e1b34ea957],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\cdfs.sys, , [bb66b5ef1665c96dfef4851c40c1748c],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\srvnet.sys, , [f72a960e97e4cc6ae111b9e810f16e92],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\csc.sys, , [cb569b09275465d1fef4f4ad15ecc739],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\cng.sys, , [6db4d4d0c8b380b617db2e7381804bb5],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\wimmount.sys, , [aa778d17b1ca0630c32f079ad32eca36],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\mrxdav.sys, , [a67beaba82f91125be34bde417ea837d],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\compbatt.sys, , [1f02762e0972fe3829c9752cb64bad53],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\CompositeBus.sys, , [59c88f152a5196a028ca376a9e63867a],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\crcdisk.sys, , [a67bd4d089f200368f63594838c9c43c],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\disk.sys, , [a67b554f9cdf00363db5168bd52c728e],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\dfsc.sys, , [67bae9bb007b42f43cb6f5ace819fa06],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\raspppoe.sys, , [50d17e2686f5e65079798819679a0bf5],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\discache.sys, , [23fe871dec8f1d19ea087130e91818e8],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\dmvsc.sys, , [33eedaca700bd95db73b6041d62b7a86],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\drmkaud.sys, , [9e83d6ce215a2d09836fb3eeda2742be],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\dxgkrnl.sys, , [71b0b1f36d0e0f27c82aa100a45ded13],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\umpass.sys, , [2af7a6fe4932b87efaf8c4dd03fe45bb],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\tdtcp.sys, , [2cf53c6893e8b0868b678120f30ef40c],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\tcpip.sys, , [3de4792bee8df640f7fb465bf60bbe42],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\mrxsmb20.sys, , [56cb1c8828532a0c975b267bed1425db],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\mrxsmb10.sys, , [54cd11930e6da49227cb2e73857c6f91],
Trojan.FakeMS.ED, C:\Windows\ehome\ehrecvr.exe, , [c9581490f8839c9ac62cadf4b150c33d],
Trojan.FakeMS.ED, C:\Windows\ehome\ehsched.exe, , [120fb0f4572464d2c62cecb5c839f20e],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\errdev.sys, , [fd24287c2d4eb5814da56839a35e9c64],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\fileinfo.sys, , [f031f7ad3e3dfa3cae441091649d18e8],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\fdc.sys, , [bf62f4b05922171fc72ba3fe728f09f7],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\ipfltdrv.sys, , [0d146044b7c444f247ab445da25fcc34],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\FILETRACE.SYS, , [140d7f25fa81ce6844aecdd427da0ff1],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\flpydisk.sys, , [ec35aef69ae13bfb1ad84a57738eef11],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\fltMgr.sys, , [be6370348af187afe80aa5fce51caf51],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\monitor.sys, , [66bbadf7700b989e3cb6d0d1d42d0ff1],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\FSDEPENDS.SYS, , [fd240e960e6d51e522d0c6db1de423dd],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\fvevol.sys, , [33eef0b4a1da25117c76851c52afba46],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\GAGP30KX.SYS, , [01209c08ea9163d3836fd8c904fdd729],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\rasl2tp.sys, , [bc65fea6fb8052e4f4fedfc211f033cd],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\mrxsmb.sys, , [ca57f9ab3e3dd75f28ca8b16b34eda26],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\HdAudio.sys, , [55cc4460136866d019d9a8f901006799],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\hdaudbus.sys, , [6eb3881c512ab581539f8c15d52cfa06],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\hidbatt.sys, , [bf62b9ebc6b5dc5a61917e23c43d24dc],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\hidbth.sys, , [77aac0e4750626104fa3f4adfb0654ac],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\hidir.sys, , [39e82c78f784bb7bd41e7928dc253ac6],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\hidusb.sys, , [30f1198bccaf3ff73db5d1d00ff2c33d],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\http.sys, , [db46b0f45a2168cea34ff8a9887923dd],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\hwpolicy.sys, , [55cc00a43546bd795b97fca522dff010],
Trojan.FakeMS.ED, C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe, , [130ec8dc413a93a306ec4f5236cb30d0],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\IPMIDrv.sys, , [46db426282f91026b73b8d144cb50cf4],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\ipnat.sys, , [36eb1b8917646bcbb73b2b764db4ba46],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\irenum.sys, , [f928c2e23447fb3b836f6b36be43c838],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\msiscsi.sys, , [cf528e165d1e89ad0be7cfd2f30e0000],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\mssmbios.sys, , [d849b9eb83f83bfb03ef7f22b1509070],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\volmgr.sys, , [6cb57331f18adb5b8b67d5ccbf422dd3],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\kbdhid.sys, , [0a17a6fe1d5eda5ced05524fc93814ec],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\ws2ifsl.sys, , [5ac78a1a027940f6cd2530718978817f],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\ksecdd.sys, , [1e033e66295257df26cc524fad549b65],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\ksecpkg.sys, , [58c9396bea915adc9161e2bf5ba625db],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\ksthunk.sys, , [a47d7133760596a02fc3ddc48f7214ec],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\lltdio.sys, , [041dffa5e49737ff34be039eae53f60a],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\tunnel.sys, , [dc45bbe982f9c175668cf5ac38c951af],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\ndistapi.sys, , [8c959212ef8c92a40ce69c05c041d927],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\luafv.sys, , [978a366ecbb0d85ed51d574a867b45bb],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\mpio.sys, , [61c0b3f1f685aa8c3db5dac7aa5709f7],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\msdsm.sys, , [fb26772d1c5f3600f3ff5f42fd04c33d],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\modem.sys, , [1011a6fea6d5b77f20d2eeb35ba6659b],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\mouclass.sys, , [58c9564e87f40531c72bd9c8f60bf10f],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\mouhid.sys, , [f72a2a7add9e76c0648ee3be3bc67d83],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\mpsdrv.sys, , [81a06242ef8c71c5ce245d44de23a957],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\msahci.sys, , [fb2620846d0eb3839b57e1c0b34ed828],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\MSHIDKMDF.SYS, , [7ba68a1af883201602f07a27c8390bf5],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\mstee.sys, , [a67b8b1980fb7bbba44eb8e9e21f3fc1],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\msisadrv.sys, , [958c5c48c8b3e4521dd5099821e038c8],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\MTConfig.sys, , [ec35663e3744d66045ad138edc25b34d],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\nwifi.sys, , [08195e466a111d1929c9416011f0c43c],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\ndiscap.sys, , [8e93f8acdaa1d264db17574acf3242be],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\ndisuio.sys, , [ae735054e19ab482dd153b665ca56898],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\ndiswan.sys, , [9f82c0e4611ad75f6191dfc2de23c838],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\netbt.sys, , [cd54b9ebafccfe38ba38732e1ee3ef11],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\nsiproxy.sys, , [7aa77430d8a341f516dcb2ef68991be5],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\NV_AGP.SYS, , [b66be5bf017a6ccacf23d8c91de4ac54],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\ohci1394.sys, , [0b16c4e0b8c32e080ae8039e6a9725db],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\parport.sys, , [2df4dfc5710a90a603efbfe2d62bb54b],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\partmgr.sys, , [65bc693b1368122432c0f1b01ce58878],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\pcw.sys, , [0120970da0db280e559d574ac73adc24],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\pciide.sys, , [9c8591135229cb6bc52de7bab8497789],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\pcmcia.sys, , [3ae77a2a017a9e988270b0f1f0119d63],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\PEAuth.sys, , [a47d03a193e839fdcd25b3ee37cad927],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\qwavedrv.sys, , [72af6a3a3c3f4de904ee9a07689920e0],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\raspptp.sys, , [b0716044770460d6d121247d2bd6a060],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\processr.sys, , [ca571c88f685fc3a8c668b16e51cf60a],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\pacer.sys, , [52cfa9fbbfbc77bf48aa38695ca54db3],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\rasacd.sys, , [5fc2a5ff1f5caa8cb1416b362fd2728e],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\agilevpn.sys, , [8f92455fdaa174c2d022b7ea55ac6f91],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\rdbss.sys, , [012003a19fdc7eb820d20d94966b3fc1],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\rassstp.sys, , [25fc347009725bdb9260554c926f758b],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\rdpbus.sys, , [c0617e26a5d6b48250a25f42d928ee12],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\rspndr.sys, , [849d5e46ef8cea4caa48455c2fd2bc44],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\RDPCDD.sys, , [9c85ecb84437ff37e50d8a1752af3ac6],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\rdpdr.sys, , [f72ae2c2bebd8aac21d1e6bb04fd04fc],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\RDPENCDD.sys, , [2bf6376df9825cda1dd50b96bf42a65a],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\RDPREFMP.sys, , [ce532d772259c373569cdbc63cc5768a],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\RDPVIDEOMINIPORT.SYS, , [91909d07bebdf83ec1318b168c758f71],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\rdyboost.sys, , [0c15c9dbd3a83ff77f73e7badf2249b7],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\vms3cap.sys, , [43decbd9bfbc1026d9196a37fa078a76],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\sbp2port.sys, , [25fc7f255b200b2b8f638d148d7403fd],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\scfilter.sys, , [948d3d67671490a61bd7acf5af529f61],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\serenum.sys, , [7fa2aafa3e3dd46247ab5a47e61b19e7],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\sermouse.sys, , [e0415a4a0a71fb3b3eb4c8d908f939c7],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\sffp_mmc.sys, , [130e475daecdcf671dd5cfd2f30e837d],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\sffp_sd.sys, , [d24f7232dd9eee48668c960b778a6e92],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\sfloppy.sys, , [7fa20f95304b6dc9de14039e778a60a0],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\vmstorfl.sys, , [8d94f7ad027948ee24ce148dc04160a0],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\storvsc.sys, , [e839386ca5d6bc7ada1871307889e917],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\swenum.sys, , [061bf8ac0b7048ee9959762b42bf1ae6],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\tcpipreg.sys, , [0d14485ca6d50d2900f2871a659c4eb2],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\tdpipe.sys, , [a47d2381740760d65999317023deec14],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\tdx.sys, , [d150e8bc62195ed8e30fcdd438c9bc44],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\termdd.sys, , [91909410ee8df83e50a2920f49b81ee2],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\tssecsrv.sys, , [59c8eeb6116a092d6f834160dd241fe1],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\TsUsbFlt.sys, , [a47d4b59413ab383d31faff2e51cd52b],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\TsUsbGD.sys, , [9f82a7fdabd00e28e80a6140ac558c74],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\UAGP35.SYS, , [9c85dbc9d6a579bd10e29908689905fb],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\udfs.sys, , [df423e66c9b2dc5a2ac8455cde236c94],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\ULIAGPKX.SYS, , [d64bb9eb95e653e3a250059ce21fb749],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\umbus.sys, , [23feeeb628538fa7f101544d10f102fe],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\USBAUDIO.sys, , [938e8f1577047cba638fd6cb936e10f0],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\usbccgp.sys, , [f829c6de2e4d8babd919732e36cb817f],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\usbuhci.sys, , [a37efca842393bfbad455051867b2cd4],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\usbohci.sys, , [48d98c1883f8e74fb939287931d00af6],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\usbehci.sys, , [a47dd8cc2b50f1453bb78a17c938cd33],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\USBSTOR.SYS, , [061b772d1b60ba7ca54d673a47bacd33],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\vdrvroot.sys, , [948de3c1dc9f51e5ee042a772bd68e72],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\vgapnp.sys, , [bb66e8bc285383b3b939ecb5c140bc44],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\vga.sys, , [ea37ffa5b3c8cd693db5930eb74ad828],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\vhdmp.sys, , [f32e1c8876051f17fcf6722f4ab733cd],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\vmbus.sys, , [4dd404a0f883f1453db51b8630d1f50b],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\VMBusHID.sys, , [4cd5594bb0cb37ff17dbfba62cd53fc1],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\volmgrx.sys, , [df425c48ed8e171f5c962a778f722bd5],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\vwifibus.sys, , [879a495b4a31ce68ec062f72c83927d9],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\wacompen.sys, , [48d9ced6b8c33df9975b6a37e61b2bd5],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\WUDFRd.sys, , [b56ca400304b90a6658d346db15018e8],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\wanarp.sys, , [ce53f7ad3e3d053100f22180cb36e21e],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\winusb.sys, , [c061990b106b1a1cb939d9c8a1609070],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\wd.sys, , [c65bfea6b0cbf64035bd2978ef12ec14],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\wfplwf.sys, , [db46257f4c2fbc7a3bb7366b847dac54],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\wmiacpi.sys, , [9f82f4b01c5fd462678b3a67a75a7987],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\WUDFPf.sys, , [c55ce8bc433867cf589a1190b74acd33],
Trojan.FakeMS.ED, C:\Windows\System32\drivers\xusb21.sys, , [e73a752fb9c267cf43af861bea1727d9],
Trojan.FakeMS.ED, C:\Windows\System32\umpnpmgr.dll, , [54cdb2f2d2a9b086b73b6d34d130916f],
Trojan.FakeMS.ED, C:\Windows\System32\appinfo.dll, , [031e881c4e2dc373747e9b06a65be020],
Trojan.FakeMS.ED, C:\Windows\System32\audiosrv.dll, , [4fd204a0accf53e3ac46920f3ec3748c],
Trojan.FakeMS.ED, C:\Windows\System32\RpcEpMap.dll, , [60c15252dba07abc50a2821f23de9a66],
Trojan.FakeMS.ED, C:\Windows\System32\BFE.DLL, , [b1707331f289cd69ac46673a0ef334cc],
Trojan.FakeMS.ED, C:\Windows\System32\umpo.dll, , [ea37cfd56615e353e012b4ed8c75bb45],
Trojan.FakeMS.ED, C:\Windows\System32\netman.dll, , [d1500a9a6417ba7cb141e9b86a97ad53],
Trojan.FakeMS.ED, C:\Windows\System32\cscsvc.dll, , [4ed3cadaa8d3dc5ab53d8e13c14017e9],
Trojan.FakeMS.ED, C:\Windows\System32\dhcpcore.dll, , [5bc61193502b4beb16dc5849ff02ed13],
Trojan.FakeMS.ED, C:\Windows\System32\provsvc.dll, , [0d14dec6ed8e40f6a74beeb32bd6d22e],
Trojan.FakeMS.ED, C:\Windows\System32\profsvc.dll, , [8b966f35f18a280e8c66ecb53ac7e719],
Trojan.FakeMS.ED, C:\Windows\System32\cryptsvc.dll, , [a57cabf9d8a3cf679062b5ec679a2ad6],
Trojan.FakeMS.ED, C:\Windows\System32\DEFRAGSVC.DLL, , [fc252480364502348a68574a679a8d73],
Trojan.FakeMS.ED, C:\Windows\System32\MPSSVC.dll, , [73ae8a1ae398cf67955dc8d909f88e72],
Trojan.FakeMS.ED, C:\Windows\System32\fdPHost.dll, , [839e0b99b9c24de910e2e5bcd22fea16],
Trojan.FakeMS.ED, C:\Windows\System32\dnsrslvr.dll, , [d44d079de89315216b87128fe31e15eb],
Trojan.FakeMS.ED, C:\Windows\System32\wscsvc.dll, , [041d980c1269a49234bed2cfe9183bc5],
Trojan.FakeMS.ED, C:\Windows\System32\wkssvc.dll, , [2bf6ccd818636dc94ca6376ad9282bd5],
Trojan.FakeMS.ED, C:\Windows\System32\dps.dll, , [ad74e3c11269e353b33f653cdb26da26],
Trojan.FakeMS.ED, C:\Windows\System32\es.dll, , [4ed3b2f23843ba7c09e98f12b051c838],
Trojan.FakeMS.ED, C:\Windows\System32\srvsvc.dll, , [3de4cdd7bfbce254a44e6b36c93856aa],
Trojan.FakeMS.ED, C:\Windows\System32\gpsvc.dll, , [0e132d775d1e8da9cb27bae739c81ee2],
Trojan.FakeMS.ED, C:\Windows\System32\msdtckrm.dll, , [5ac7e4c09fdcaf87f200d2cfdd24da26],
Trojan.FakeMS.ED, C:\Windows\System32\rasmans.dll, , [a47d2d77f289241213dfddc443bef30d],
Trojan.FakeMS.ED, C:\Windows\System32\IKEEXT.DLL, , [f42da3016b10280e6e84871a6e93f010],
Trojan.FakeMS.ED, C:\Windows\System32\IPSECSVC.DLL, , [8b96b6ee740742f46d85465bbf42ad53],
Trojan.FakeMS.ED, C:\Windows\System32\lmhsvc.dll, , [e33e7f25e09b38fe1bd7554cda27867a],
Trojan.FakeMS.ED, C:\Windows\System32\mmcss.dll, , [91907133a3d82a0c2dc5089961a011ef],
Trojan.FakeMS.ED, C:\Windows\System32\QAGENTRT.DLL, , [e23f683cfc7f73c3569c7d245ea35ba5],
Trojan.FakeMS.ED, C:\Windows\System32\pcasvc.dll, , [8d94950f314ae15545ad722f53ae2ad6],
Trojan.FakeMS.ED, C:\Windows\System32\netprofm.dll, , [b46d871d0d6e4de9668c069b44bd936d],
Trojan.FakeMS.ED, C:\Windows\System32\nlasvc.dll, , [ad747f258eed171f8a685f42d32e42be],
Trojan.FakeMS.ED, C:\Windows\System32\pla.dll, , [f031bde79be07cbad2209a07f0116898],
Trojan.FakeMS.ED, C:\Windows\System32\regsvc.dll, , [889990147803340215dd8a1759a837c9],
Trojan.FakeMS.ED, C:\Windows\System32\schedsvc.dll, , [f928a20281fa0c2a3ab87829fd0426da],
Trojan.FakeMS.ED, C:\Windows\System32\seclogon.dll, , [67bab0f4b3c8c86ef6fcfea3d62b7888],
Trojan.FakeMS.ED, C:\Windows\System32\Sens.dll, , [3fe2ccd880fb9b9bf8fa604129d8f20e],
Trojan.FakeMS.ED, C:\Windows\System32\shsvcs.dll, , [130e71337605d363e9099908a859c33d],
Trojan.FakeMS.ED, C:\Windows\System32\sstpsvc.dll, , [24fd0a9a77041e18539fc5dc7f8228d8],
Trojan.FakeMS.ED, C:\Windows\System32\sysmain.dll, , [051c7c28186376c020d289189c65f20e],
Trojan.FakeMS.ED, C:\Windows\System32\termsrv.dll, , [26fb881cc3b8270f3cb6099838c9a15f],
Trojan.FakeMS.ED, C:\Windows\System32\tapisrv.dll, , [59c8376d4734f04625cdc1e0ed146a96],
Trojan.FakeMS.ED, C:\Windows\System32\trkwks.dll, , [50d17d27b0cb2214bd35d8c9689933cd],
Trojan.FakeMS.ED, C:\Windows\System32\umrdp.dll, , [859cb1f33f3c30066c86a7faec15f808],
Trojan.FakeMS.ED, C:\Windows\System32\uxsms.dll, , [4ad74163394235019d553968d62bd52b],
Trojan.FakeMS.ED, C:\Windows\System32\w32time.dll, , [73ae644013687cba2bc7adf4669b41bf],
Trojan.FakeMS.ED, C:\Windows\System32\WebClnt.dll, , [f829752f95e62c0a08eac0e19d6440c0],
Trojan.FakeMS.ED, C:\Windows\System32\wdi.dll, , [cc55fca83f3cc67033bf742d8180f808],
Trojan.FakeMS.ED, C:\Windows\System32\wbem\WMIsvc.dll, , [c75ac0e478030531bf33722ffc05c53b],
Trojan.FakeMS.ED, C:\Windows\System32\WPDBUSENUM.DLL, , [42df2e765c1f999d0de5b2ef837ed030],

Physical Sectors: 0
(No malicious items detected)


(end)

Link to post
Share on other sites

Hello kayliu:

Until a Malwarebytes staff employee, or qualified forum helper, weighs in on your issue again, I strongly recommend you leave your computer as is, and ignore the unsolicited suggestions of others.

Further un-guided actions on your part may make possible recovery that much more difficult.

Thank you for your patience and understanding.

Link to post
Share on other sites

  • Root Admin

Do you have access to another system running the same version of Windows and a large 4GB or larger USB thumb drive or external USB drive that you can use to try a repair?

DO NOT use this method or idea if the versions of Windows are not the same. ie.. do not use XP or Vista to fix a Windows 7 box or vice-verse

You should be able to use Robocopy to put back enough of the files to allow the system to boot again.

Assuming you have a USB drive on F: please create a folder called Windows in the root/top of the drive.

Then click on start and type in CMD.EXE and when it shows in the start menu right click over it and choose "Run as administrator" and type in the following and press the Enter key.

ROBOCOPY "C:\WINDOWS" "F:\Windows" /s /xo /xj *.exe *.dll *.sys /r:0 /w:0
Then start the affected computer up with the USB drive attached and issue the following command

This assumes that the USB drive is now D: from within the Recovery Console if not then adjust to the correct drive letter. You can run NOTEPAD and then try File Open to locate the drive, then close Notepad.

ROBOCOPY "D:\WINDOWS" "C:\Windows" /s /xo /xj *.exe *.dll *.sys /r:0 /w:0
Once completed try to restart the computer now in Normal Mode

Please let me know how that works out.

Link to post
Share on other sites

Do you have access to another system running the same version of Windows and a large 4GB or larger USB thumb drive or external USB drive that you can use to try a repair?

DO NOT use this method or idea if the versions of Windows are not the same. ie.. do not use XP or Vista to fix a Windows 7 box or vice-verse

You should be able to use Robocopy to put back enough of the files to allow the system to boot again.

Assuming you have a USB drive on F: please create a folder called Windows in the root/top of the drive.

Then click on start and type in CMD.EXE and when it shows in the start menu right click over it and choose "Run as administrator" and type in the following and press the Enter key.

 

ROBOCOPY "C:\WINDOWS" "F:\Windows" /s /xo /xj *.exe *.dll *.sys /r:0 /w:0
Then start the affected computer up with the USB drive attached and issue the following command

This assumes that the USB drive is now D: from within the Recovery Console if not then adjust to the correct drive letter. You can run NOTEPAD and then try File Open to locate the drive, then close Notepad.

ROBOCOPY "D:\WINDOWS" "C:\Windows" /s /xo /xj *.exe *.dll *.sys /r:0 /w:0
Once completed try to restart the computer now in Normal Mode

Please let me know how that works out.

 

 

I can do the first part to copy the Window from another computer which the same OS. However, since my infected computer can't boot into the Window or the Safe Mode, how can I run CMD.EXE  and copy and replace the files with the infected pc?

Link to post
Share on other sites

Is it possible to try and do a System Restore to a previous time from the Recovery Environment?

 

Please see if one of these articles can get the system running again

 

How to Do a System Restore in Windows 7

How to Run a Startup Repair in Windows 7

 

 

No System Restore and Startup repair did not work. Just in case you don't understand what I am saying I took some photos and a video which show the problem that I encounter.

 

In this video you can see that when I select Start Window Normally, it will auto boot into Startup Repair mode.

 

HzIHm8I.jpg

 

4gJ3tu6.jpg

 

wDsdDDq.jpg

Link to post
Share on other sites

Just some information on a repair reinstall. It didn't work with my upgrade dvd when I needed it.

 

My dvd didn't have sp1 on it, was the problem.

 

There are LEGAL Win 7 iso files around, but don't have the address so do a search.

 

You need the one that is your version ( Home prem ,Pro ) and 32 or 64 bit.

 

I will be back if I can find a good source.

thanks for the advice and the link

 

Well at this point it looks like you will probably have to go with this method.

 

How to Do a Repair Install to Fix Windows 7

I will try that and let you know whether or not it works tomorrow

Link to post
Share on other sites

I tried to do a repair install, but this message poped up when I was trying to select the Upgrade, "the computer started using the windows installation disc. Remove the installation disc and restart your computer so that windows starts normally."

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.