MichaW Posted January 8, 2011 Hello, pls check attached registry entries which seem to be F/P's Nothing was found by: NIS 2011 MBAM A2 Spyware Terminator Spybot Windoes Defender Virus Total HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BACKITUP.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BACKITUP.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CDSPEED.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CDSPEED.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\COVERDES.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\COVERDES.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DRIVESPEED.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DRIVESPEED.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GOOGLEUPDATER.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GOOGLEUPDATER.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IMAGEDRIVE.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IMAGEDRIVE.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\INFOTOOL.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\INFOTOOL.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NERO.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NERO.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NEROHOME.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NEROHOME.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NEROMEDIAHOME.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NEROMEDIAHOME.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NEROSCOUTOPTIONS.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NEROSCOUTOPTIONS.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NEROSTARTSMART.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NEROSTARTSMART.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NEROVISION.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NEROVISION.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PHOTOSNAP.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PHOTOSNAP.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PHOTOSNAPVIEWER.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PHOTOSNAPVIEWER.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RECODE.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RECODE.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUPX.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUPX.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SHOWTIME.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SHOWTIME.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SOUNDTRAX.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SOUNDTRAX.EXE#Debugger HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WAVEEDIT.EXE HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WAVEEDIT.EXE#Debugger Thanks Michael Share this post Link to post Share on other sites
MichaW Posted January 10, 2011 Hello SAS, would someone from SAS provide an answer please? Thanks Michael Share this post Link to post Share on other sites
MichaW Posted January 12, 2011 Hello SAS, why isn't it possible, that nobody from SAS replies to my previous question????? On a daily basis is sent the scan logs directly to SAS but nobody cares about it. The same story we had in August last year. https://forums.superantispyware.com/index.php?/topic/4113-securityhijackimagefileexecutionoptions/ Michael Share this post Link to post Share on other sites