BlitzBlank 1.0.0.32
File/Registry Modification Engine native application
MoveFileOnReboot: sourceFile = "\??\c:\windows\system32\msxun1er9.dll", destinationFile = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\windows\system32\msw-n0ode.dll", destinationFile = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\program files\kergpthwexmxz", destinationDirectory = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\program files\kergpthwexmxz\aysfudh.exe", destinationFile = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\program files\kergpthwexmxz\help.chm", destinationFile = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\program files\kergpthwexmxz\Log", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\program files\kergpthwexmxz\Log\Audio", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\program files\kergpthwexmxz\Log\Text", destinationDirectory = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\program files\kergpthwexmxz\Log\Text\aiocht.dat", destinationFile = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\program files\kergpthwexmxz\Log\Text\aiotxt.dat", destinationFile = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\program files\kergpthwexmxz\Log\Text\aioweb.dat", destinationFile = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\program files\kergpthwexmxz\Log\Visual", destinationDirectory = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\program files\kergpthwexmxz\Log\Visual\04192010.dat", destinationFile = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\program files\kergpthwexmxz\Log\Visual\04202010.dat", destinationFile = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\program files\kergpthwexmxz\Log\Visual\04212010.dat", destinationFile = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\program files\kergpthwexmxz\Log\Visual\04222010.dat", destinationFile = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\program files\kergpthwexmxz\Log\Visual\04232010.dat", destinationFile = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\program files\kergpthwexmxz\Log\Visual\04252010.dat", destinationFile = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\program files\kergpthwexmxz\unins000.dat", destinationFile = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\program files\kergpthwexmxz\unins000.exe", destinationFile = "(null)", replaceWithDummy = 0
DeleteRegistryValueOnReboot: keyName = "\Registry\Machine\hkey_local_machine\software\microsoft\windows\currentversion\run", valueName = "15518", backupFile = "(null)", replaceWithDummy = 0
DeleteRegistryValueByDriver: keyName = "\Registry\Machine\hkey_local_machine\software\microsoft\windows\currentversion\run", valueName = "15518", backupFile = "(null)", replaceWithDummy = 0
DeleteRegistryValueOnReboot: keyName = "\Registry\Machine\hkey_current_user\software\microsoft\windows\currentversion\run", valueName = "15518", backupFile = "(null)", replaceWithDummy = 0
DeleteRegistryValueByDriver: keyName = "\Registry\Machine\hkey_current_user\software\microsoft\windows\currentversion\run", valueName = "15518", backupFile = "(null)", replaceWithDummy = 0
DeleteRegistryKeyOnReboot: keyName = "\Registry\Machine\hkey_local_machine\software\classes\clsid\{6a1247c5-43cb-f9a4-32e1-52dee1fde352}", backupFile = "(null)", replaceWithDummy = 0
DeleteRegistryKeyByDriver: keyName = "\Registry\Machine\hkey_local_machine\software\classes\clsid\{6a1247c5-43cb-f9a4-32e1-52dee1fde352}", backupFile = "(null)", replaceWithDummy = 0
grm.txt
OTL.Txt