ComboFix 08-09-10.02 - user 2008-09-11 14:12:32.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255 [GMT 8:00]
Running from: C:\Documents and Settings\user\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\user\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\1rfw8hjr.com
C:\1t6yxlxx.cmd
C:\2.cmd
C:\b3b9u.com
C:\c9hehpa.bat
C:\Documents and Settings\user\Application Data\Antivirus2008y
C:\Documents and Settings\user\Application Data\Antivirus2008y\antvrs.exe
C:\Documents and Settings\user\Desktop\Error Cleaner.url
C:\Documents and Settings\user\Desktop\Privacy Protector.url
C:\Documents and Settings\user\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\user\Favorites\Error Cleaner.url
C:\Documents and Settings\user\Favorites\Privacy Protector.url
C:\Documents and Settings\user\Favorites\Spyware&Malware Protection.url
C:\ov.cmd
C:\Program Files\PCHealthCenter\
0.exe
C:\Program Files\PCHealthCenter\
0.gif
C:\Program Files\PCHealthCenter\1.exe
C:\Program Files\PCHealthCenter\1.gif
C:\Program Files\PCHealthCenter\1.ico
C:\Program Files\PCHealthCenter\2.exe
C:\Program Files\PCHealthCenter\2.gif
C:\Program Files\PCHealthCenter\2.ico
C:\Program Files\PCHealthCenter\3.exe
C:\Program Files\PCHealthCenter\3.gif
C:\Program Files\PCHealthCenter\5.exe
C:\Program Files\PCHealthCenter\7.exe
C:\Program Files\PCHealthCenter\sc.html
C:\r1y1.bat
C:\svdioajm.cmd
C:\tyktjfww.exe
C:\WINDOWS\emnf.exe
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\system32\ckvo0.dll
C:\WINDOWS\system32\ckvo1.dll
C:\WINDOWS\system32\tdssadw.dll
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\tdssl.dll
C:\WINDOWS\system32\tdsslog.dll
C:\WINDOWS\system32\tdssmain.dll
C:\WINDOWS\system32\tdsspopup.dll
C:\WINDOWS\system32\tdsspopup1.url
C:\WINDOWS\system32\tdsspopup2.url
C:\WINDOWS\system32\tdsspopup3.url
C:\WINDOWS\system32\tdssservers.dat
C:\WINDOWS\system32\YUR7.exe
C:\yssjnngm.cmd
D:\1rfw8hjr.com
D:\2.cmd
D:\b3b9u.com
D:\c9hehpa.bat
D:\ov.cmd
D:\svdioajm.cmd
D:\tyktjfww.exe
D:\yssjnngm.cmd
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
-------\Legacy_TDSSSERV
-------\Service_TDSSserv
((((((((((((((((((((((((( Files Created from 2008-08-11 to 2008-09-11 )))))))))))))))))))))))))))))))
.
2008-09-11 12:30 . 2008-09-11 12:30 88,878 --a------ C:\WINDOWS\system32\casino3.ico
2008-09-11 12:30 . 2008-09-11 12:30 88,878 --a------ C:\WINDOWS\system32\casino2.ico
2008-09-11 12:30 . 2008-09-11 12:30 88,878 --a------ C:\WINDOWS\system32\casino1.ico
2008-09-11 12:29 . 2008-09-11 14:14 <DIR> d-------- C:\Program Files\PCHealthCenter
2008-09-11 12:29 . 2008-09-11 12:29 <DIR> d-------- C:\Program Files\MSA
2008-09-11 12:29 . 2008-09-11 11:40 344,064 --a------ C:\WINDOWS\vmgspntbnrp.dll
2008-09-11 12:29 . 2008-09-11 11:40 294,912 --a------ C:\WINDOWS\dtseqrxk.dll
2008-09-11 12:29 . 2008-09-11 11:40 270,336 --a------ C:\WINDOWS\mgxfebsq.dll
2008-09-11 12:29 . 2008-09-11 11:40 204,800 --a------ C:\WINDOWS\fqbewlna.dll
2008-09-11 12:29 . 2008-09-11 11:40 135,168 --a------ C:\WINDOWS\mqgldfvo.exe
2008-09-11 12:29 . 2008-09-08 17:32 31,232 --a------ C:\x
2008-09-11 12:02 . 2008-09-11 12:02 <DIR> d-------- C:\Program Files\Electronic Arts
2008-09-10 18:27 . 2008-09-11 08:00 115 --a------ C:\autorun.inf.vir
2008-09-09 11:06 . 2008-09-09 11:08 <DIR> d-------- C:\Program Files\DriverCleanerDotNET
2008-09-09 11:00 . 2008-09-09 11:00 <DIR> d-------- C:\Program Files\NVIDIA Corporation
2008-09-09 11:00 . 2008-09-09 11:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
2008-09-09 11:00 . 2006-03-29 08:50 671,744 --a------ C:\WINDOWS\system32\DolbyHph.dll
2008-09-09 11:00 . 2006-03-29 08:51 60,416 --a------ C:\WINDOWS\system32\DSETUP.dll
2008-09-09 11:00 . 2006-03-29 08:49 9,856 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2008-09-09 11:00 . 2006-05-05 19:21 4,608 --a------ C:\WINDOWS\system32\drivers\nvport.sys
2008-09-09 10:24 . 2008-09-09 10:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\{5A76C6B3-3FA8-46D0-AA81-62C3805E38BC}
2008-09-09 08:34 . 2008-05-19 18:16 186,407 --a------ C:\WINDOWS\system32\nvapps.nvb
2008-09-08 08:01 . 2008-09-08 08:01 <DIR> d-------- C:\Documents and Settings\user\Application Data\Simply Super Software
2008-09-08 08:01 . 2008-09-08 08:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-09-08 08:01 . 2006-05-25 15:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-09-08 08:01 . 2003-02-02 20:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-09-08 08:01 . 2005-08-26 01:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-09-08 08:01 . 2002-03-06 01:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-09-08 08:01 . 2006-06-19 13:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-09-07 10:38 . 2008-09-07 10:38 <DIR> d-------- C:\Program Files\AskSBar
2008-09-07 10:29 . 2008-09-07 10:29 <DIR> d-------- C:\Program Files\Google
2008-09-07 10:29 . 2008-09-07 10:35 <DIR> d-------- C:\Program Files\DAP
2008-09-07 10:29 . 2008-09-07 10:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SpeedBit
2008-09-07 10:29 . 2008-09-07 10:29 479,298 --a------ C:\WINDOWS\system32\wbocx.ocx
2008-09-07 10:29 . 2008-09-07 10:29 172,032 --a------ C:\WINDOWS\system32\AniGIF.ocx
2008-09-07 10:29 . 2008-09-07 10:29 50,688 --a------ C:\WINDOWS\system32\wbhelp2.dll
2008-09-07 05:32 . 2008-02-21 23:18 566,624 --a------ C:\WINDOWS\system32\d3d10.dll
2008-09-07 05:32 . 2007-04-19 01:59 519,912 --a------ C:\WINDOWS\system32\d3dx10d_33.dll
2008-09-07 05:32 . 2007-04-19 01:59 519,912 --a------ C:\WINDOWS\system32\d3dx10d.dll
2008-09-07 05:32 . 2008-02-21 23:18 519,912 --a------ C:\WINDOWS\system32\d3dx10.dll
2008-09-07 05:32 . 2008-02-21 23:18 494,557 --a------ C:\WINDOWS\system32\dxgi.dll
2008-09-07 05:32 . 2007-12-22 20:30 34,854 --a------ C:\WINDOWS\system32\directx10logo.bmp
2008-09-07 05:32 . 2008-02-22 00:10 25,037 --a------ C:\WINDOWS\system32\Nucleus.dll
2008-09-05 13:02 . 2008-09-05 13:02 <DIR> d-------- C:\Program Files\MagicDisc
2008-09-05 13:02 . 2008-07-28 17:19 116,736 --a------ C:\WINDOWS\system32\drivers\mcdbus.sys
2008-09-05 08:31 . 2008-09-05 08:31 <DIR> d-------- C:\Documents and Settings\user\Application Data\Leadertech
2008-09-04 12:55 . 2008-09-04 12:55 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Xfire
2008-09-04 12:54 . 2008-09-05 19:21 <DIR> d-------- C:\Program Files\Xfire
2008-09-04 12:54 . 2008-09-11 08:29 <DIR> d-------- C:\Documents and Settings\user\Application Data\Xfire
2008-09-04 05:37 . 2008-09-04 05:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NexonUS
2008-09-01 09:03 . 2008-09-02 07:54 <DIR> d-------- C:\Program Files\Download Direct
2008-08-28 15:40 . 2008-08-29 16:49 89,370 -r-hs---- C:\ph.com
2008-08-28 05:02 . 2008-08-28 05:02 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-08-27 14:12 . 2008-08-27 14:12 <DIR> d--h----- C:\WINDOWS\PIF
2008-08-26 17:45 . 2008-08-26 17:40 89,420 -r-hs---- C:\n.com
2008-08-24 11:37 . 2008-08-24 11:37 <DIR> d-------- C:\Program Files\OpenAL
2008-08-24 11:37 . 2008-08-24 11:37 409,600 --a------ C:\WINDOWS\system32\wrap_oal.dll
2008-08-24 11:37 . 2008-08-24 11:37 114,688 --a------ C:\WINDOWS\system32\OpenAL32.dll
2008-08-21 19:01 . 2008-09-03 23:58 <DIR> d-------- C:\Documents and Settings\user\Application Data\OpenOffice.org2
2008-08-21 18:56 . 2008-09-04 06:25 <DIR> d-------- C:\Program Files\OpenOffice.org 2.4
2008-08-21 08:33 . 2008-08-21 08:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Uniblue
2008-08-21 08:03 . 2008-08-21 08:33 <DIR> d-------- C:\Program Files\Uniblue
2008-08-21 07:57 . 2008-08-21 07:58 <DIR> d-------- C:\Program Files\Mp3 Audio Editor
2008-08-21 07:57 . 2005-03-29 07:57 2,084,864 --a------ C:\WINDOWS\system32\NCTAudioDesign2.dll
2008-08-21 07:57 . 2005-04-04 17:21 602,112 --a------ C:\WINDOWS\system32\NCTAudioTransform2.dll
2008-08-21 07:57 . 2005-03-28 15:54 479,232 --a------ C:\WINDOWS\system32\NCTAudioVisualization2.dll
2008-08-21 07:57 . 2005-03-28 15:54 475,136 --a------ C:\WINDOWS\system32\NCTAudioVisualizationEx2.dll
2008-08-21 07:57 . 2005-04-25 13:01 458,752 --a------ C:\WINDOWS\system32\NCTAudioRecord2.dll
2008-08-21 07:57 . 2005-03-28 15:52 417,792 --a------ C:\WINDOWS\system32\NCTTextToAudio2.dll
2008-08-21 07:57 . 2005-03-28 15:56 417,792 --a------ C:\WINDOWS\system32\NCTAudioDisplay2.dll
2008-08-21 07:57 . 2005-02-24 11:51 348,160 --a------ C:\WINDOWS\system32\NCTWMAFile2.dll
2008-08-21 07:57 . 2006-03-23 12:56 113,486 --a------ C:\WINDOWS\system32\NCTWMAProfiles.prx
2008-08-18 14:04 . 2008-08-18 14:04 <DIR> d-------- C:\Documents and Settings\user\Application Data\MSNInstaller
2008-08-17 06:25 . 2008-08-17 06:25 <DIR> d-------- C:\Program Files\NCH Software
2008-08-17 06:14 . 2008-08-17 06:15 <DIR> d-------- C:\Documents and Settings\user\Application Data\NCH Swift Sound
2008-08-17 06:14 . 2008-08-17 06:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-08-17 06:12 . 2008-08-17 06:23 <DIR> d-------- C:\Program Files\NCH Swift Sound
2008-08-17 05:29 . 2008-08-17 13:17 90,343 -r-hs---- C:\
0.com
2008-08-16 11:56 . 2008-08-19 09:23 <DIR> d-------- C:\Documents and Settings\user\Application Data\Mp3 Audio Editor
2008-08-16 11:55 . 2005-05-17 12:37 1,986,560 --a------ C:\WINDOWS\system32\NCTAudioFile2.dll
2008-08-16 11:55 . 2005-05-18 11:52 1,212,416 --a------ C:\WINDOWS\system32\NCTAudioInformation2.dll
2008-08-16 11:55 . 2005-04-15 12:08 880,640 --a------ C:\WINDOWS\system32\NCTAudioEditor2.dll
2008-08-16 11:55 . 2004-11-04 13:31 835,584 --a------ C:\WINDOWS\system32\NCTAudioCDGrabber2.dll
2008-08-16 11:55 . 2005-04-25 13:01 458,752 --a------ C:\WINDOWS\system32\NCTAudioPlayer2.dll
2008-08-16 11:55 . 2002-01-05 16:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-08-15 13:02 . 2008-08-16 05:52 89,197 -r-hs---- C:\t1ypkh.exe
2008-08-11 07:19 . 2008-08-21 08:33 <DIR> d-------- C:\Documents and Settings\user\Application Data\Uniblue
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-11 06:16 --------- d-----w C:\Documents and Settings\user\Application Data\uTorrent
2008-09-11 06:09 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-11 06:09 --------- d-----w C:\Documents and Settings\user\Application Data\AVG7
2008-09-10 10:27 93,896 ----a-w C:\WINDOWS\system32\ckvo.exe.vir
2008-09-10 02:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-10 02:16 --------- d-----w C:\Program Files\EA GAMES
2008-09-09 11:49 --------- d-----w C:\Program Files\Free Music Zilla
2008-09-08 00:36 --------- d-----w C:\Program Files\YouTube Downloader
2008-09-04 03:10 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-09-04 03:09 --------- d-----w C:\Documents and Settings\user\Application Data\SystemRequirementsLab
2008-08-24 03:47 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-08-21 10:55 --------- d-----w C:\Program Files\Java
2008-08-21 00:38 --------- d-----w C:\Program Files\XoftSpySE
2008-08-21 00:26 --------- d-----w C:\Program Files\uTorrent
2008-08-10 13:42 --------- d-----w C:\Documents and Settings\user\Application Data\AdobeUM
2008-08-10 10:00 --------- d-----w C:\Documents and Settings\user\Application Data\Autodesk
2008-08-10 10:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Autodesk
2008-08-09 07:58 --------- d-----w C:\Documents and Settings\user\Application Data\Disney Interactive Studios
2008-08-09 03:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-08-08 09:13 --------- d-----w C:\Program Files\easetech
2008-08-08 05:59 --------- d-----w C:\Documents and Settings\user\Application Data\Yahoo!
2008-08-08 05:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-08-07 15:18 --------- d-----w C:\Program Files\Yahoo!
2008-08-07 00:10 --------- d-----w C:\Program Files\DivX
2008-08-04 01:11 89,885 --sh--r C:\xqf.com
2008-08-03 01:09 --------- d-----w C:\Documents and Settings\user\Application Data\Activision
2008-08-03 01:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Activision
2008-07-31 03:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-07-25 08:36 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-07-23 16:50 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-23 16:48 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-07-23 16:48 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-07-23 16:46 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-07-22 23:02 --------- d-----w C:\Program Files\WebEye
2008-07-22 22:41 --------- d-----w C:\Program Files\Vimicro
2008-07-22 05:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-07-22 03:24 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-07-22 03:24 --------- d-----w C:\Program Files\AutoCAD 2008
2008-07-22 02:55 --------- d-----w C:\Program Files\Autodesk
2008-07-22 02:51 247,866 ----a-w C:\WINDOWS\Alcohol_Toolbar_Uninstaller_8156.exe
2008-07-22 02:51 --------- d-----w C:\Program Files\Alcohol Toolbar
2008-07-22 02:50 223,128 ----a-w C:\WINDOWS\system32\drivers\vaxscsi.sys
2008-07-22 02:50 --------- d-----w C:\Program Files\Alcohol Soft
2008-07-19 21:55 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-19 15:34 22,328 ----a-w C:\Documents and Settings\user\Application Data\PnkBstrK.sys
2008-07-19 15:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ubisoft
2008-07-18 06:19 --------- d-----w C:\Documents and Settings\user\Application Data\DivX
2008-07-16 09:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-07-13 22:47 --------- d-----w C:\Program Files\Lonely Cat Games
2001-11-23 04:08 712,704 ----a-w C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.
------- Sigcheck -------
2004-08-04 05:14: VIRUS ALERT! 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\system32\dllcache\tcpip.sys
2004-08-04 05:14: VIRUS ALERT! 359040 6a603809f598332dbedd535bdbce313e C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-09-07 10:38: VIRUS ALERT! 66912 --a------ C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7287293E-B0BE-4A31-B52B-EA15F57679E3}]
2008-09-11 11:40: VIRUS ALERT! 344064 --a------ C:\WINDOWS\vmgspntbnrp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{94E952A4-FAE1-40E5-BBE1-8199D8CF7FD0}"= "C:\WINDOWS\fqbewlna.dll" [2008-09-11 204800]
[HKEY_CLASSES_ROOT\clsid\{94e952a4-fae1-40e5-bbe1-8199d8cf7fd0}]
[HKEY_CLASSES_ROOT\fqbewlna.1]
[HKEY_CLASSES_ROOT\TypeLib\{0955BCF0-2DB3-4926-B985-1ED8F0894D73}]
[HKEY_CLASSES_ROOT\fqbewlna]
C:\Documents and Settings\user\Start Menu\Programs\Startup\
MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe [2008-09-05 575488]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
"NoDispCPL"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
"NoToolbarCustomize"= 1 (0x1)
"StartMenuLogoff"= 1 (0x1)
"NoStartMenuMorePrograms"= 1 (0x1)
"NoSetFolders"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\
0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"mgxfebsq"= {3B23FC7B-8B11-4529-9822-13139E0DAFC0} - C:\WINDOWS\mgxfebsq.dll [2008-09-11 270336]
"dtseqrxk"= {F9EC9751-0CA1-436F-B153-F26D354047E9} - C:\WINDOWS\dtseqrxk.dll [2008-09-11 294912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Dragonfly\\Special Force\\specialforce.exe"=
"C:\\Program Files\\AMPED\\WarRock Philippines Installer\\WRLauncher.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"D:\\2142\\BF2142.exe"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2e841fe1-6272-11dd-b0a3-00138fedf29e}]
\Shell\AutoRun\command - F:\svdioajm.cmd
\Shell\explore\Command - F:\svdioajm.cmd
\Shell\open\Command - F:\svdioajm.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{345efeca-442b-11dd-b029-00138fedf29e}]
\Shell\AutoRun\command - J:\1t6yxlxx.cmd
\Shell\explore\Command - J:\1t6yxlxx.cmd
\Shell\open\Command - J:\1t6yxlxx.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{51a73d61-5404-11dd-b06e-00138fedf29e}]
\Shell\AutoRun\command - F:\ffojc.com
\Shell\explore\Command - F:\ffojc.com
\Shell\open\Command - F:\ffojc.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6df458ce-2191-11dd-af90-00138fedf29e}]
\Shell\AutoRun\command - G:\ph.com
\Shell\explore\Command - G:\ph.com
\Shell\open\Command - G:\ph.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{81b28f01-44c8-11dd-b02b-00138fedf29e}]
\Shell\AutoRun\command - G:\xn1i9x.com
\Shell\explore\Command - G:\xn1i9x.com
\Shell\open\Command - G:\xn1i9x.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{81c89c48-58b3-11dd-b080-00138fedf29e}]
\Shell\AutoRun\command - J:\bar311.exe %1
\Shell\Explore\command - J:\bar311.exe %1
\Shell\Open\command - J:\bar311.exe %1
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae898e3c-6f5d-11dd-b0d5-00138fedf29e}]
\Shell\AutoRun\command - F:\2.cmd
\Shell\explore\Command - F:\2.cmd
\Shell\open\Command - F:\2.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b60e1e17-0ccf-11dd-af2e-00138fedf29e}]
\Shell\AutoRun\command - F:\kk3.bat
\Shell\explore\Command - F:\kk3.bat
\Shell\open\Command - F:\kk3.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b60e1e26-0ccf-11dd-af2e-00138fedf29e}]
\Shell\AutoRun\command - G:\1t6yxlxx.cmd
\Shell\explore\Command - G:\1t6yxlxx.cmd
\Shell\open\Command - G:\1t6yxlxx.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eeeb02f5-7ae0-11dd-b10b-00138fedf29e}]
\Shell\AutoRun\command - F:\autorun\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f19f358c-7eb5-11dd-b11b-00138fedf29e}]
\Shell\Autoplay\Command - G:\xmss.exe
\Shell\AutoRun\command - G:\xmss.exe
\Shell\Explore\Command - G:\xmss.exe
\Shell\Open\Command - G:\xmss.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa583259-2d47-11dd-afc6-00138fedf29e}]
\Shell\AutoRun\command - ufjtre.exe
\Shell\explore\Command - ufjtre.exe
\Shell\open\Command - ufjtre.exe
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\b4pbta6a.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-divx&p=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://search.speedbit.com/
FF -: plugin - C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-11 14:16:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\Documents and Settings\user\Application Data\TmpRecentIcons
C:\Documents and Settings\user\Application Data\TmpRecentIcons\Chikka.lnk 1468 bytes
C:\Documents and Settings\user\Application Data\TmpRecentIcons\Free Music Zilla.lnk 733 bytes
C:\Documents and Settings\user\Application Data\TmpRecentIcons\Launch WarRock Philippines.lnk 809 bytes
C:\Documents and Settings\user\Application Data\TmpRecentIcons\Microsoft Office Word 2003.lnk 2497 bytes
C:\Documents and Settings\user\Application Data\TmpRecentIcons\Mp3 Audio Editor.lnk 1594 bytes
C:\Documents and Settings\user\Application Data\TmpRecentIcons\MS Antivirus.lnk 636 bytes
C:\Documents and Settings\user\Application Data\TmpRecentIcons\PC Satellite TV.lnk 798 bytes
C:\Documents and Settings\user\Application Data\TmpRecentIcons\Shortcut to games.lnk 402 bytes
C:\Documents and Settings\user\Application Data\TmpRecentIcons\Shortcut to music.lnk 1186 bytes
C:\Documents and Settings\user\Application Data\TmpRecentIcons\SWAT 4.lnk 659 bytes
scan completed successfully
hidden files: 11
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\.NET CLR Data]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\.NET CLR Networking]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\.NET Data Provider for Oracle]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\.NET Data Provider for SqlServer]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\.NETFramework]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Abiosdsk]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\abp480n5]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ACPI]
"ImagePath"="system32\DRIVERS\ACPI.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ACPIEC]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\adpu160m]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\aec]
"ImagePath"="system32\drivers\aec.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\AFD]
"ImagePath"="\SystemRoot\System32\drivers\afd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Aha154x]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\aic78u2]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\aic78xx]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Alerter]
"ServiceDll"="%SystemRoot%\system32\alrsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ALG]
"ImagePath"="%SystemRoot%\System32\alg.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\AliIde]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\amsint]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\AppMgmt]
"ServiceDll"="%SystemRoot%\System32\appmgmts.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\asc]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\asc3350p]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\asc3550]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ASP.NET]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ASP.NET_1.1.4322]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ASP.NET_2.0.50727]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\aspnet_state]
"ImagePath"="%SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\AsyncMac]
"ImagePath"="system32\DRIVERS\asyncmac.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\atapi]
"ImagePath"="system32\DRIVERS\atapi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Atdisk]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Atmarpc]
"ImagePath"="system32\DRIVERS\atmarpc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\AudioSrv]
"ServiceDll"="%SystemRoot%\System32\audiosrv.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\audstub]
"ImagePath"="system32\DRIVERS\audstub.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Autodesk Licensing Service]
"ImagePath"="\"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Avg7Alrt]
"ImagePath"="C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Avg7Core]
"ImagePath"="\SystemRoot\System32\Drivers\avg7core.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Avg7RsW]
"ImagePath"="\SystemRoot\System32\Drivers\avg7rsw.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Avg7RsXP]
"ImagePath"="\SystemRoot\System32\Drivers\avg7rsxp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Avg7UpdSvc]
"ImagePath"="C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\AvgClean]
"ImagePath"="\SystemRoot\System32\Drivers\avgclean.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\AVGEMS]
"ImagePath"="C:\PROGRA~1\Grisoft\AVG7\avgemc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\AvgTdi]
"ImagePath"="\SystemRoot\System32\Drivers\avgtdi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\BattC]
"MofImagePath"="System32\Drivers\battc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Beep]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\BITS]
"ServiceDll"="%systemroot%\system32\qmgr.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Browser]
"ServiceDll"="%SystemRoot%\System32\browser.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\catchme]
"ImagePath"="\??\C:\DOCUME~1\user\LOCALS~1\Temp\catchme.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\cbidf2k]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\cd20xrnt]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Cdaudio]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Cdfs]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Cdrom]
"ImagePath"="system32\DRIVERS\cdrom.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Changer]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\CiSvc]
"ImagePath"="%SystemRoot%\system32\cisvc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ClipSrv]
"ImagePath"="%SystemRoot%\system32\clipsrv.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\clr_optimization_v2.0.50727_32]
"ImagePath"="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\CmdIde]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\cmuda]
"ImagePath"="system32\drivers\cmuda.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\COMSysApp]
"ImagePath"="C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ContentFilter]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ContentIndex]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Cpqarray]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\CryptSvc]
"ServiceDll"="%SystemRoot%\System32\cryptsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\dac2w2k]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\dac960nt]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\DcomLaunch]
"ServiceDll"="%SystemRoot%\system32\rpcss.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Dhcp]
"ServiceDll"="%SystemRoot%\System32\dhcpcsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Disk]
"ImagePath"="system32\DRIVERS\disk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\dmadmin]
"ImagePath"="%SystemRoot%\System32\dmadmin.exe /com"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\dmboot]
"ImagePath"="System32\drivers\dmboot.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\dmio]
"ImagePath"="System32\drivers\dmio.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\dmload]
"ImagePath"="System32\drivers\dmload.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\dmserver]
"ServiceDll"="%SystemRoot%\System32\dmserver.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\DMusic]
"ImagePath"="system32\drivers\DMusic.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Dnscache]
"ServiceDll"="%SystemRoot%\System32\dnsrslvr.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\dpti2o]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\drmkaud]
"ImagePath"="system32\drivers\drmkaud.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\EagleNT]
"ImagePath"="\??\C:\WINDOWS\system32\drivers\EagleNT.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ERSvc]
"ServiceDll"="%SystemRoot%\System32\ersvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Eventlog]
"ImagePath"="%SystemRoot%\system32\services.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\EventSystem]
"ServiceDll"="C:\WINDOWS\system32\es.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Fastfat]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\FastUserSwitchingCompatibility]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Fdc]
"ImagePath"="system32\DRIVERS\fdc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Fips]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Flpydisk]
"ImagePath"="system32\DRIVERS\flpydisk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\FltMgr]
"ImagePath"="system32\DRIVERS\fltMgr.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Fs_Rec]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Ftdisk]
"ImagePath"="system32\DRIVERS\ftdisk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Gpc]
"ImagePath"="system32\DRIVERS\msgpc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\gusvc]
"ImagePath"="\"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\hamachi]
"ImagePath"="system32\DRIVERS\hamachi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\helpsvc]
"ServiceDll"="%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\HidServ]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\HidUsb]
"ImagePath"="system32\DRIVERS\hidusb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\hpn]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\HTTP]
"ImagePath"="System32\Drivers\HTTP.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\HTTPFilter]
"ServiceDll"="%SystemRoot%\System32\w3ssl.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\i2omgmt]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\i2omp]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\i8042prt]
"ImagePath"="system32\DRIVERS\i8042prt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ICSharing]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Imapi]
"ImagePath"="system32\DRIVERS\imapi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ImapiService]
"ImagePath"="%systemroot%\system32\imapi.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\inetaccs]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ini910u]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Inport]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\IntelIde]
"ImagePath"="system32\DRIVERS\intelide.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\intelppm]
"ImagePath"="system32\DRIVERS\intelppm.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Ip6Fw]
"ImagePath"="system32\DRIVERS\Ip6Fw.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\IpFilterDriver]
"ImagePath"="system32\DRIVERS\ipfltdrv.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\IpInIp]
"ImagePath"="system32\DRIVERS\ipinip.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\IpNat]
"ImagePath"="system32\DRIVERS\ipnat.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\IPSec]
"ImagePath"="system32\DRIVERS\ipsec.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\IRENUM]
"ImagePath"="system32\DRIVERS\irenum.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ISAPISearch]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\isapnp]
"ImagePath"="system32\DRIVERS\isapnp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Kbdclass]
"ImagePath"="system32\DRIVERS\kbdclass.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\kmixer]
"ImagePath"="system32\drivers\kmixer.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\KSecDD]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\lanmanserver]
"ServiceDll"="%SystemRoot%\System32\srvsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\lanmanworkstation]
"ServiceDll"="%SystemRoot%\System32\wkssvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\lbrtfdc]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ldap]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\LicenseService]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\LmHosts]
"ServiceDll"="%SystemRoot%\System32\lmhsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mcdbus]
"ImagePath"="system32\DRIVERS\mcdbus.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Messenger]
"ServiceDll"="%SystemRoot%\System32\msgsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mnmdd]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mnmsrvc]
"ImagePath"="C:\WINDOWS\system32\mnmsrvc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Modem]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Mouclass]
"ImagePath"="system32\DRIVERS\mouclass.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mouhid]
"ImagePath"="system32\DRIVERS\mouhid.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MountMgr]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mraid35x]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MRxDAV]
"ImagePath"="system32\DRIVERS\mrxdav.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MRxSmb]
"ImagePath"="system32\DRIVERS\mrxsmb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MSDTC]
"ImagePath"="C:\WINDOWS\system32\msdtc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Msfs]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MSIServer]
"ImagePath"="%systemroot%\system32\msiexec.exe /V"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MSKSSRV]
"ImagePath"="system32\drivers\MSKSSRV.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MSPCLOCK]
"ImagePath"="system32\drivers\MSPCLOCK.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MSPQM]
"ImagePath"="system32\drivers\MSPQM.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mssmbios]
"ImagePath"="system32\DRIVERS\mssmbios.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Mup]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NDIS]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NdisTapi]
"ImagePath"="system32\DRIVERS\ndistapi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Ndisuio]
"ImagePath"="system32\DRIVERS\ndisuio.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NdisWan]
"ImagePath"="system32\DRIVERS\ndiswan.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NDProxy]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NetBIOS]
"ImagePath"="system32\DRIVERS\netbios.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NetBT]
"ImagePath"="system32\DRIVERS\netbt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NetDDE]
"ImagePath"="%SystemRoot%\system32\netdde.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NetDDEdsdm]
"ImagePath"="%SystemRoot%\system32\netdde.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Netlogon]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Netman]
"ServiceDll"="%SystemRoot%\System32\netman.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Nla]
"ServiceDll"="%SystemRoot%\System32\mswsock.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\nm]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\nmwcd]
"ImagePath"="system32\drivers\ccdcmb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\nmwcdc]
"ImagePath"="system32\drivers\ccdcmbo.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Npfs]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Ntfs]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NtLmSsp]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NtmsSvc]
"ServiceDll"="%SystemRoot%\system32\ntmssvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Null]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\nv]
"ImagePath"="system32\DRIVERS\nv4_mini.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\nvport]
"ImagePath"="\??\C:\WINDOWS\system32\Drivers\nvport.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NWCWorkstation]
"ServiceDll"="%SystemRoot%\System32\nwwks.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NwlnkFlt]
"ImagePath"="system32\DRIVERS\nwlnkflt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NwlnkFwd]
"ImagePath"="system32\DRIVERS\nwlnkfwd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NwlnkIpx]
"ImagePath"="system32\DRIVERS\nwlnkipx.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NwlnkNb]
"ImagePath"="system32\DRIVERS\nwlnknb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NwlnkSpx]
"ImagePath"="system32\DRIVERS\nwlnkspx.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NWRDR]
"ImagePath"="system32\DRIVERS\nwrdr.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ose]
"ImagePath"="\"C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE\""
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Outlook]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Parport]
"ImagePath"="system32\DRIVERS\parport.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PartMgr]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ParVdm]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\pccsmcfd]
"ImagePath"="system32\DRIVERS\pccsmcfd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PCI]
"ImagePath"="system32\DRIVERS\pci.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PCIDump]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PCIIde]
"ImagePath"="system32\DRIVERS\pciide.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Pcmcia]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PDCOMP]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PDFRAME]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PDRELI]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PDRFRAME]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\perc2]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\perc2hib]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PerfDisk]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PerfNet]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PerfOS]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PerfProc]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\pfc]
"ImagePath"="system32\drivers\pfc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PlugPlay]
"ImagePath"="%SystemRoot%\system32\services.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PolicyAgent]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PortProxy]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PptpMiniport]
"ImagePath"="system32\DRIVERS\raspptp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ProtectedStorage]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PSched]
"ImagePath"="system32\DRIVERS\psched.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Ptilink]
"ImagePath"="system32\DRIVERS\ptilink.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PxHelp20]
"ImagePath"="System32\Drivers\PxHelp20.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ql1080]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Ql10wnt]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ql12160]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ql1240]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ql1280]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RasAcd]
"ImagePath"="system32\DRIVERS\rasacd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RasAuto]
"ServiceDll"="%SystemRoot%\System32\rasauto.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Rasl2tp]
"ImagePath"="system32\DRIVERS\rasl2tp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RasMan]
"ServiceDll"="%SystemRoot%\System32\rasmans.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RasPppoe]
"ImagePath"="system32\DRIVERS\raspppoe.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Raspti]
"ImagePath"="system32\DRIVERS\raspti.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Rdbss]
"ImagePath"="system32\DRIVERS\rdbss.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RDPCDD]
"ImagePath"="System32\DRIVERS\RDPCDD.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RDPDD]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\rdpdr]
"ImagePath"="system32\DRIVERS\rdpdr.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RDPNP]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RDPWD]
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RDSessMgr]
"ImagePath"="C:\WINDOWS\system32\sessmgr.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\redbook]
"ImagePath"="system32\DRIVERS\redbook.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RemoteAccess]
"ServiceDll"="%SystemRoot%\System32\mprdim.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RemoteRegistry]
"ServiceDll"="%SystemRoot%\system32\regsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RpcLocator]
"ImagePath"="%SystemRoot%\system32\locator.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RpcSs]
"ServiceDll"="%SystemRoot%\System32\rpcss.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RSVP]
"ImagePath"="%SystemRoot%\system32\rsvp.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\rtl8139]
"ImagePath"="system32\DRIVERS\R8139n51.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SamSs]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SCardSvr]
"ImagePath"="%SystemRoot%\System32\SCardSvr.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Schedule]
"ServiceDll"="%SystemRoot%\system32\schedsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Secdrv]
"ImagePath"="system32\DRIVERS\secdrv.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\seclogon]
"ServiceDll"="%SystemRoot%\System32\seclogon.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SENS]
"ServiceDll"="%SystemRoot%\system32\sens.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\serenum]
"ImagePath"="system32\DRIVERS\serenum.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Serial]
"ImagePath"="system32\DRIVERS\serial.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ServiceLayer]
"ImagePath"="\"C:\Program Files\PC Connectivity Solution\ServiceLayer.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Sfloppy]