Here are the logs:
ComboFix 08-08-09.06 - kaitlyn 2008-08-10 8:46:42.1 - NTFSx86
Running from: C:\Documents and Settings\kaitlyn\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\kaitlyn\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
.
The following files were disabled during the run:c:\windows\system32\dbi102.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator.YOUR-09DEDAFE33\Application Data\macromedia\Flash Player\#SharedObjects\FP5V6A8Z\interclick.com
C:\Documents and Settings\Administrator.YOUR-09DEDAFE33\Application Data\macromedia\Flash Player\#SharedObjects\FP5V6A8Z\interclick.com\ud.sol
C:\Documents and Settings\Administrator.YOUR-09DEDAFE33\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Administrator.YOUR-09DEDAFE33\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\kaitlyn\Application Data\macromedia\Flash Player\#SharedObjects\KHSEX6B7\interclick.com
C:\Documents and Settings\kaitlyn\Application Data\macromedia\Flash Player\#SharedObjects\KHSEX6B7\interclick.com\ud.sol
C:\Documents and Settings\kaitlyn\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\kaitlyn\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\kaitlyn\Application Data\PrivacyProtector Free
C:\Documents and Settings\kaitlyn\Application Data\PrivacyProtector Free\Logs\update.log
C:\Documents and Settings\kaitlyn\Application Data\rhcavqj0e9tj
C:\Documents and Settings\kaitlyn\err.log
C:\Program Files\wintouch
C:\WINDOWS\b122.exe
C:\WINDOWS\b129.exe
C:\WINDOWS\b136.exe
C:\WINDOWS\b138.exe
C:\WINDOWS\BM66f780d5.txt
C:\WINDOWS\BM66f780d5.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\ORUN32.EXE
C:\WINDOWS\system32\__c00C6912.exe
C:\WINDOWS\system32\6to4ex.dll
C:\WINDOWS\system32\alog.txt
C:\WINDOWS\system32\app.exe
C:\WINDOWS\system32\awtqnkhe.dll
C:\WINDOWS\system32\bund1
C:\WINDOWS\system32\bund1\temp.txt
C:\WINDOWS\system32\cedjic.dll
C:\WINDOWS\system32\CMMGR32.EXE
C:\WINDOWS\system32\comsa32.sys
c:\WINDOWS\system32\dbi102.dll.vir
C:\WINDOWS\system32\DgQWvyxx.ini
C:\WINDOWS\system32\DgQWvyxx.ini2
C:\WINDOWS\system32\dkpmbuuf.dll
C:\WINDOWS\system32\drivers\core.cache(2).dsk
C:\WINDOWS\system32\drivers\core.cache(3).dsk
C:\WINDOWS\system32\drivers\core.cache(4).dsk
C:\WINDOWS\system32\drivers\core.cache(5).dsk
C:\WINDOWS\system32\eaxwsdej.dll
C:\WINDOWS\system32\gvrnaswk.ini
C:\WINDOWS\system32\hhgsjxog.dll
C:\WINDOWS\system32\install.exe
C:\WINDOWS\system32\iqajkh.dll
C:\WINDOWS\system32\jedswxae.ini
C:\WINDOWS\system32\jxuoeghq.dll
C:\WINDOWS\system32\kvgooehf.dll
C:\WINDOWS\system32\kwsanrvg.dll
C:\WINDOWS\system32\macidwe.exe
C:\WINDOWS\system32\mgetrrsr.ini
C:\WINDOWS\system32\mmchost.dll
C:\WINDOWS\system32\model.dat
C:\WINDOWS\system32\Nobicyt.exe
C:\WINDOWS\system32\opnnNDWp.dll
C:\WINDOWS\system32\qctinksa.dll
C:\WINDOWS\system32\qpiuqryy.ini
C:\WINDOWS\system32\qrdygk.dll
C:\WINDOWS\system32\rsrrtegm.dll
C:\WINDOWS\system32\syspilog.pil
C:\WINDOWS\system32\tdxdowkc.exe
C:\WINDOWS\system32\url(2).dll
C:\WINDOWS\system32\xxyvWQgD.dll
C:\WINDOWS\system32\yazjbb.dll
C:\WINDOWS\system32\yyrquipq.dll
C:\xcrashdump.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AFINDING
-------\Legacy_CORE
-------\Legacy_IPRIP
-------\Legacy_MACIDWE
-------\Legacy_NNSERV
-------\Legacy_PERFS
-------\Legacy_ROUTING
-------\Legacy_SEICTRL
-------\Legacy_TDXDOWKC
-------\Legacy_WSERVING
-------\Service_macidwe
-------\Service_NNServ
-------\Service_seictrl
-------\Service_tdxdowkc
-------\Legacy_nobicyt
-------\Service_nobicyt
((((((((((((((((((((((((( Files Created from 2008-07-10 to 2008-08-10 )))))))))))))))))))))))))))))))
.
2008-08-10 06:47 . 2008-08-10 06:47 2,048 --a------ C:\WINDOWS\system32\lvfgpwvs.exe
2008-08-09 21:45 . 2008-08-09 21:45 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-09 12:34 . 2008-08-09 14:47 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-08-08 23:51 . 2008-08-08 23:51 2,855 --a------ C:\WINDOWS\system32\install.PIF
2008-08-08 23:40 . 2008-08-08 23:55 2,048 --a------ C:\WINDOWS\system32\rqglqcna.exe
2008-08-08 21:12 . 2008-08-08 21:12 1 --a------ C:\WINDOWS\system32\tb.dr
2008-08-08 21:11 . 2008-08-08 21:11 <DIR> d--hs---- C:\WINDOWS\system32\config\systemprofile\Temporary Internet Files
2008-08-08 21:11 . 2008-08-08 21:11 <DIR> d--hs---- C:\WINDOWS\system32\config\systemprofile\History
2008-08-08 21:10 . 2008-08-08 21:11 <DIR> d-------- C:\Program Files\Microsoft Common
2008-08-08 21:10 . 2008-08-08 21:10 60,416 --a------ C:\WINDOWS\inform.dat
2008-08-08 21:10 . 2008-08-08 21:10 45,568 --a------ C:\WINDOWS\system32\pns32.dll
2008-08-08 19:45 . 2008-08-08 19:45 2,048 --a------ C:\WINDOWS\system32\jaltcfeo.exe
2008-08-08 19:34 . 2008-08-10 07:15 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-08-08 19:34 . 2008-08-08 19:34 <DIR> d-------- C:\Documents and Settings\kaitlyn\Application Data\SUPERAntiSpyware.com
2008-08-08 19:34 . 2008-08-08 19:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-08-08 19:33 . 2008-08-08 19:33 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-08-08 18:41 . 2008-08-09 15:20 1,848 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-08 18:38 . 2006-05-09 08:14 <DIR> d-------- C:\Documents and Settings\Administrator.YOUR-09DEDAFE33\Application Data\Symantec
2008-08-08 18:38 . 2006-05-09 08:20 <DIR> d-------- C:\Documents and Settings\Administrator.YOUR-09DEDAFE33\Application Data\Intuit
2008-08-08 18:38 . 2008-08-08 18:38 <DIR> d-------- C:\Documents and Settings\Administrator.YOUR-09DEDAFE33
2008-08-08 18:06 . 2008-08-08 18:06 <DIR> d-------- C:\VundoFix Backups
2008-08-08 16:05 . 2008-08-08 16:05 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-08-07 22:29 . 2008-08-07 22:29 2,185 --a------ C:\WINDOWS\Active Setup Log.BAK
2008-08-07 18:21 . 2008-08-07 18:21 2,048 --a------ C:\WINDOWS\system32\hsmytbah.exe
2008-08-06 13:40 . 2008-08-06 13:50 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-06 13:39 . 2008-08-06 13:39 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-08-06 13:39 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-08-04 19:57 . 2008-08-04 19:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PopCap
2008-08-04 19:21 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-08-04 17:10 . 2008-08-04 17:15 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-08-03 18:46 . 2008-08-04 16:49 <DIR> d-------- C:\Program Files\Windows Defender
2008-08-03 17:41 . 2008-08-03 17:41 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-03 17:41 . 2008-08-03 17:41 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-03 17:38 . 2008-08-03 17:41 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-03 16:44 . 2004-07-17 11:35 67,866 --a------ C:\WINDOWS\system32\drivers\netwlan5.img
2008-08-03 16:43 . 2004-07-17 11:36 64,352 --a------ C:\WINDOWS\system32\drivers\ativmc20.cod
2008-08-03 16:43 . 2006-12-28 14:01 19,569 --a------ C:\WINDOWS\
002743_.tmp
2008-08-03 16:17 . 2008-08-04 18:06 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-08-02 00:02 . 2008-08-08 21:09 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-08-02 00:02 . 2008-08-02 00:02 1,409 --a------ C:\WINDOWS\QTFont.for
2008-08-01 19:59 . 2008-08-01 20:00 <DIR> d-------- C:\Program Files\WON
2008-08-01 19:55 . 2008-08-01 19:55 327,681 --a------ C:\wonplay.exe
2008-07-24 01:22 . 1997-12-11 05:15 161,792 --a------ C:\WINDOWS\uninst95.exe
2008-07-23 00:19 . 2008-07-23 00:19 986 --a------ C:\WINDOWS\POWER.INI
2008-07-23 00:15 . 2008-07-23 00:15 958 --a------ C:\WINDOWS\ANIMATE.INI
2008-07-22 23:57 . 2008-07-22 23:57 972 --a------ C:\WINDOWS\8BALL.INI
2008-07-22 23:55 . 2008-07-26 16:26 403 --a------ C:\WINDOWS\2XStars.ini
2008-07-22 23:55 . 2008-07-22 23:55 338 --a------ C:\WINDOWS\2XDyna.ini
2008-07-22 23:54 . 2008-07-22 23:54 1,010 --a------ C:\WINDOWS\ABSOLUTE.INI
2008-07-22 23:29 . 2008-07-24 22:50 38 --a------ C:\WINDOWS\STUDPOK.INI
2008-07-22 22:52 . 2008-07-22 22:52 <DIR> d-------- C:\BEARWARE
2008-07-22 22:50 . 1998-07-02 14:25 398,416 --a------ C:\WINDOWS\system\Vbrun300.dll
2008-07-22 22:50 . 1997-07-19 16:00 193,296 --a------ C:\WINDOWS\system\Mci32.ocx
2008-07-22 22:50 . 1998-05-11 22:51 133,088 --a------ C:\WINDOWS\system\Cncs.dll
2008-07-22 22:50 . 1998-05-12 10:44 30,544 --a------ C:\WINDOWS\system\Dib.drv
2008-07-22 22:50 . 2008-07-22 22:50 99 --a------ C:\WINDOWS\Ultisoft.ini
2008-07-22 22:50 . 1998-12-08 13:18 9 --a------ C:\WINDOWS\Collida.ini
2008-07-22 22:50 . 1998-12-08 13:15 9 --a------ C:\WINDOWS\Brick.ini
2008-07-22 22:36 . 1997-07-19 17:00 227,600 --a------ C:\WINDOWS\system32\Msflxgrd.ocx
2008-07-22 22:36 . 1996-06-06 22:06 189,952 --a------ C:\WINDOWS\QCARD32.DLL
2008-07-22 22:24 . 2008-07-22 22:34 436 --a------ C:\WINDOWS\Win95dll.ini
2008-07-22 22:12 . 2008-07-22 22:36 <DIR> d-------- C:\Program Files\Galaxy of Games
2008-07-22 22:12 . 2008-07-22 22:12 0 --a------ C:\WINDOWS\PROTOCOL.INI
2008-07-22 16:51 . 2000-04-24 11:20 544,768 --a------ C:\WINDOWS\system32\SierraNW.DLL
2008-07-22 16:51 . 2000-04-21 17:15 200,704 --a------ C:\WINDOWS\system32\SNWValid.dll
2008-07-22 16:46 . 2008-07-22 16:51 <DIR> d-------- C:\Sierra
2008-07-22 16:46 . 2008-07-22 16:51 <DIR> d-------- C:\Program Files\Sierra On-Line
2008-07-22 16:44 . 2008-07-22 16:53 584 --a------ C:\WINDOWS\SIERRA.INI
2008-07-22 16:32 . 2008-07-22 16:32 <DIR> d-------- C:\Program Files\Millennium Gamepak Gold
2008-07-22 16:32 . 2008-07-22 16:32 286,720 --a------ C:\WINDOWS\iun506.exe
2008-07-21 15:19 . 2004-08-04 08:00 33,792 --a------ C:\WINDOWS\system32\lmmib2.dll
2008-07-21 15:19 . 2004-08-04 08:00 33,792 --a------ C:\WINDOWS\system32\dllcache\lmmib2.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-10 11:42 4,224 ----a-w C:\WINDOWS\system32\drivers\beep.sys
2008-08-09 18:37 22 ----a-w C:\Program Files\c.zip
2008-08-09 18:37 22 ----a-w C:\Program Files\b.zip
2008-08-09 18:37 22 ----a-w C:\Program Files\a.zip
2008-08-09 05:35 --------- d-----w C:\Program Files\Windows Live
2008-08-09 00:51 --------- d-----w C:\Program Files\NetWaiting
2008-08-09 00:51 --------- d-----w C:\Program Files\Hp
2008-08-08 21:03 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-08 13:25 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-08 04:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-06 19:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-06 19:24 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-05 00:21 --------- d-----w C:\Program Files\Java
2008-08-05 00:08 --------- d-----w C:\Program Files\Google
2008-08-04 06:40 78,360 ----a-w C:\Program Files\uy.exe
2008-08-04 06:40 203,149 ----a-w C:\Documents and Settings\kaitlyn\lo.exe
2008-07-08 05:11 --------- d-----w C:\Program Files\Broadcom
2008-07-08 03:17 --------- d-----w C:\Documents and Settings\kaitlyn\Application Data\funkitron
2008-07-07 02:41 --------- d-----w C:\Program Files\LimeWire
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2007-11-19 18:41 1,100 ----a-w C:\Documents and Settings\kaitlyn\Application Data\wklnhst.dat
2007-07-01 20:26 141 ----a-w C:\Documents and Settings\kaitlyn\5039.bat
2007-07-01 20:20 66,048 ----a-w C:\Documents and Settings\kaitlyn\x.exe
2007-07-01 00:55 25,214 ----a-w C:\Program Files\B.ico
2007-07-01 00:55 25,214 ----a-w C:\Program Files\A.ico
2007-06-05 18:11 167 ----a-w C:\Documents and Settings\kaitlyn\6006.bat
2007-05-29 18:57 167 ----a-w C:\Documents and Settings\kaitlyn\1096.bat
2000-02-02 00:01 40,960 --sha-r C:\WINDOWS\system32\KarnaDrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-02-27 17:02:06 581693]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^kaitlyn^Start Menu^Programs^StartUp^LimeWire On Startup.lnk]
path=C:\Documents and Settings\kaitlyn\Start Menu\Programs\StartUp\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^kaitlyn^Start Menu^Programs^StartUp^Slide.exe.lnk]
path=C:\Documents and Settings\kaitlyn\Start Menu\Programs\StartUp\Slide.exe.lnk
backup=C:\WINDOWS\pss\Slide.exe.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^kaitlyn^Start Menu^Programs^StartUp^Vongo Tray.lnk]
path=C:\Documents and Settings\kaitlyn\Start Menu\Programs\StartUp\Vongo Tray.lnk
backup=C:\WINDOWS\pss\Vongo Tray.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--a------ 2006-03-23 16:43 53408 c:\Program Files\Common Files\Symantec Shared\CCAPP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 16:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2006-11-13 13:39 1289000 C:\Program Files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2006-02-19 03:41 49152 C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 2006-03-23 07:13 77824 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 2006-03-23 07:17 118784 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 2006-03-23 07:17 94208 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-08-11 18:30 249856 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-08-11 18:30 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2006-02-23 15:45 278528 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 12:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
--a------ 2006-03-07 15:38 131072 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
--a------ 2006-04-11 23:54 102400 C:\Program Files\Hp\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-15 20:17 155648 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-07-30 14:45 1829712 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-07-06 22:11 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2006-11-30 22:49 4662776 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
--a------ 2007-11-15 22:51 166304 c:\Program Files\Zune\ZuneLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
--a------ 2006-04-18 06:29 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ZuneNetworkSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"SNDSrvc"=3 (0x3)
"SAVScan"=3 (0x3)
"NSCService"=3 (0x3)
"NNServ"=2 (0x2)
"iPodService"=3 (0x3)
"Symantec Core LC"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"navapsvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccProxy"=2 (0x2)
"ccEvtMgr"=2 (0x2)
"Vongo Service"=2 (0x2)
"IDriverT"=3 (0x3)
"ccISPwdSvc"=3 (0x3)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"LightScribeService"=2 (0x2)
"gusvc"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Cpqset"=C:\Program Files\HPQ\Default Settings\cpqset.exe
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\WON\\wonplay.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15101:TCP"= 15101:TCP:Won
"15200:TCP"= 15200:TCP:Won
"15500:TCP"= 15500:TCP:Won
"26901:TCP"= 26901:TCP:Won
"26902:TCP"= 26902:TCP:Won
"26903:TCP"= 26903:TCP:Won
"26904:TCP"= 26904:TCP:Won
"26905:TCP"= 26905:TCP:Won
"26906:TCP"= 26906:TCP:Won
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c037ffed-20e1-11db-8bc5-806d6172696f}]
\Shell\AutoRun\command - D:\setupSNK.exe
*Newly Created Service* - 6TO4
*Newly Created Service* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9988775D-4368-4857-871A-D01D66CA3A71}]
rundll32 pns32.dll,InitO
.
Contents of the 'Scheduled Tasks' folder
2008-08-10 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - kaitlyn.job
- c:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe [2006-02-05 01:03]
2008-08-09 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe [2008-07-30 14:45]
2008-08-10 C:\WINDOWS\Tasks\Symantec NetDetect.job
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE []
.
- - - - ORPHANS REMOVED - - - -
BHO-{D21D9540-6415-4288-BDD0-4453088D9D38} - pns32.dll
BHO-{E6182BBF-0047-49E7-8FBF-2F2C380BA48C} - C:\WINDOWS\system32\awvtt.dll
ShellExecuteHooks-{E60A0B68-2F3C-A1D2-A901-9381E036D21A} - (no file)
Notify-__c008D764 - C:\WINDOWS\system32\__c008D764.dat
Notify-cbxvutu - cbxvutu.dll
Notify-opnOifDt - opnOifDt.dll
MSConfigStartUp-65c4b349 - C:\WINDOWS\system32\kwsanrvg.dll
MSConfigStartUp-DW4 - C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
MSConfigStartUp-IpWins - C:\Program Files\Ipwindows\ipwins.exe
MSConfigStartUp-lphcevqj0e9tj - C:\WINDOWS\system32\lphcevqj0e9tj.exe
MSConfigStartUp-runner1 - C:\WINDOWS\retadpu1000137.exe
MSConfigStartUp-SMrhcavqj0e9tj - C:\Program Files\rhcavqj0e9tj\rhcavqj0e9tj.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
O16 -: {F2D35D99-63B1-46D3-970C-6E22320D5DCB} - hxxp://www.ksolo.com/getPlugin.do
C:\WINDOWS\Downloaded Program Files\kSoloClientIE.inf
C:\Program Files\Pinnacle\Shared Files\Filter\lame_enc.dll
C:\WINDOWS\Downloaded Program Files\kSoloClientIE.ocx
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-10 08:59:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET CLR Data]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET CLR Networking]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET Data Provider for Oracle]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET Data Provider for SqlServer]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NETFramework]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\6to4]
"ServiceDll"="C:\WINDOWS\system32\6to4ex.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Abiosdsk]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\abp480n5]
"ImagePath"="\SystemRoot\system32\DRIVERS\ABP480N5.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ACPI]
"ImagePath"="system32\DRIVERS\ACPI.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ACPIEC]
"ImagePath"="system32\DRIVERS\ACPIEC.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\adpu160m]
"ImagePath"="\SystemRoot\system32\DRIVERS\adpu160m.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aec]
"ImagePath"="system32\drivers\aec.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AFD]
"ImagePath"="\SystemRoot\System32\drivers\afd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\agp440]
"ImagePath"="\SystemRoot\system32\DRIVERS\agp440.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\agpCPQ]
"ImagePath"="\SystemRoot\system32\DRIVERS\agpCPQ.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Aha154x]
"ImagePath"="\SystemRoot\system32\DRIVERS\aha154x.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aic78u2]
"ImagePath"="\SystemRoot\system32\DRIVERS\aic78u2.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aic78xx]
"ImagePath"="\SystemRoot\system32\DRIVERS\aic78xx.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Alerter]
"ServiceDll"="%SystemRoot%\system32\alrsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ALG]
"ImagePath"="%SystemRoot%\System32\alg.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AliIde]
"ImagePath"="system32\DRIVERS\aliide.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\alim1541]
"ImagePath"="\SystemRoot\system32\DRIVERS\alim1541.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\amdagp]
"ImagePath"="\SystemRoot\system32\DRIVERS\amdagp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\amsint]
"ImagePath"="\SystemRoot\system32\DRIVERS\amsint.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AppMgmt]
"ServiceDll"="%SystemRoot%\System32\appmgmts.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Arp1394]
"ImagePath"="system32\DRIVERS\arp1394.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASAPIW2k]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc]
"ImagePath"="\SystemRoot\system32\DRIVERS\asc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc3350p]
"ImagePath"="\SystemRoot\system32\DRIVERS\asc3350p.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc3550]
"ImagePath"="\SystemRoot\system32\DRIVERS\asc3550.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET_1.1.4322]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET_2.0.50727]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aspnet_state]
"ImagePath"="%SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AsyncMac]
"ImagePath"="system32\DRIVERS\asyncmac.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\atapi]
"ImagePath"="system32\DRIVERS\atapi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Atdisk]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Atmarpc]
"ImagePath"="system32\DRIVERS\atmarpc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AudioSrv]
"ServiceDll"="%SystemRoot%\System32\audiosrv.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\audstub]
"ImagePath"="system32\DRIVERS\audstub.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Automatic LiveUpdate Scheduler]
"ImagePath"="\"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BattC]
"MofImagePath"="System32\Drivers\battc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BCM43XX]
"ImagePath"="system32\DRIVERS\bcmwl5.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Beep]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BITS]
"ServiceDll"="%systemroot%\system32\qmgr.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Browser]
"ServiceDll"="%SystemRoot%\System32\browser.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\btaudio]
"ImagePath"="system32\drivers\btaudio.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BTDriver]
"ImagePath"="system32\DRIVERS\btport.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BTKRNL]
"ImagePath"="system32\DRIVERS\btkrnl.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\btwdins]
"ImagePath"="C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BTWDNDIS]
"ImagePath"="system32\DRIVERS\btwdndis.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\btwmodem]
"ImagePath"="system32\DRIVERS\btwmodem.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BTWUSB]
"ImagePath"="System32\Drivers\btwusb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\catchme]
"ImagePath"="\??\C:\ComboFix\catchme.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cbidf]
"ImagePath"="\SystemRoot\system32\DRIVERS\cbidf2k.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cbidf2k]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CCDECODE]
"ImagePath"="system32\DRIVERS\CCDECODE.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr]
"ImagePath"="\"c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccISPwdSvc]
"ImagePath"="\"c:\Program Files\Norton Internet Security\ccPwdSvc.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccProxy]
"ImagePath"="\"c:\Program Files\Common Files\Symantec Shared\ccProxy.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccSetMgr]
"ImagePath"="\"c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cd20xrnt]
"ImagePath"="\SystemRoot\system32\DRIVERS\cd20xrnt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdaudio]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdfs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdrom]
"ImagePath"="system32\DRIVERS\cdrom.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Changer]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CiSvc]
"ImagePath"="%SystemRoot%\system32\cisvc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ClipSrv]
"ImagePath"="%SystemRoot%\system32\clipsrv.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CmBatt]
"ImagePath"="system32\DRIVERS\CmBatt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CmdIde]
"ImagePath"="\SystemRoot\system32\DRIVERS\cmdide.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\comHost]
"ImagePath"="\"c:\Program Files\Norton Internet Security\comHost.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Compbatt]
"ImagePath"="system32\DRIVERS\compbatt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\COMSysApp]
"ImagePath"="C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ContentFilter]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ContentIndex]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cpqarray]
"ImagePath"="\SystemRoot\system32\DRIVERS\cpqarray.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CryptSvc]
"ServiceDll"="%SystemRoot%\System32\cryptsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dac2w2k]
"ImagePath"="\SystemRoot\system32\DRIVERS\dac2w2k.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dac960nt]
"ImagePath"="\SystemRoot\system32\DRIVERS\dac960nt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DcomLaunch]
"ServiceDll"="%SystemRoot%\system32\rpcss.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dhcp]
"ServiceDll"="%SystemRoot%\System32\dhcpcsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Disk]
"ImagePath"="system32\DRIVERS\disk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmadmin]
"ImagePath"="%SystemRoot%\System32\dmadmin.exe /com"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmboot]
"ImagePath"="System32\drivers\dmboot.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmio]
"ImagePath"="System32\drivers\dmio.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmload]
"ImagePath"="System32\drivers\dmload.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmserver]
"ServiceDll"="%SystemRoot%\System32\dmserver.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DMusic]
"ImagePath"="system32\drivers\DMusic.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dnscache]
"ServiceDll"="%SystemRoot%\System32\dnsrslvr.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dpti2o]
"ImagePath"="\SystemRoot\system32\DRIVERS\dpti2o.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\drmkaud]
"ImagePath"="system32\drivers\drmkaud.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\E100B]
"ImagePath"="system32\DRIVERS\e100b325.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\eabfiltr]
"ImagePath"="system32\DRIVERS\eabfiltr.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\eabusb]
"ImagePath"="system32\DRIVERS\eabusb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\eeCtrl]
"ImagePath"="\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EraserUtilRebootDrv]
"ImagePath"="\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ERSvc]
"ServiceDll"="%SystemRoot%\System32\ersvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Eventlog]
"ImagePath"="%SystemRoot%\system32\services.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EventSystem]
"ServiceDll"="C:\WINDOWS\system32\es.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fastfat]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FastUserSwitchingCompatibility]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fdc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fips]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Flpydisk]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FltMgr]
"ImagePath"="system32\DRIVERS\fltMgr.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fs_Rec]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ftdisk]
"ImagePath"="system32\DRIVERS\ftdisk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GEARAspiWDM]
"ImagePath"="System32\Drivers\GEARAspiWDM.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Gpc]
"ImagePath"="system32\DRIVERS\msgpc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gusvc]
"ImagePath"="\"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HBtnKey]
"ImagePath"="system32\DRIVERS\cpqbttn.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HdAudAddService]
"ImagePath"="system32\drivers\CHDAud.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HDAudBus]
"ImagePath"="system32\DRIVERS\HDAudBus.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\helpsvc]
"ServiceDll"="%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HidServ]
"ServiceDll"="%SystemRoot%\System32\hidserv.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HidUsb]
"ImagePath"="system32\DRIVERS\hidusb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hpn]
"ImagePath"="\SystemRoot\system32\DRIVERS\hpn.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hpqwmiex]
"ImagePath"="C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HPZid412]
"ImagePath"="system32\DRIVERS\HPZid412.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HPZipr12]
"ImagePath"="system32\DRIVERS\HPZipr12.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HPZius12]
"ImagePath"="system32\DRIVERS\HPZius12.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HSFHWAZL]
"ImagePath"="system32\DRIVERS\HSFHWAZL.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HSF_DPV]
"ImagePath"="system32\DRIVERS\HSF_DPV.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HTTP]
"ImagePath"="System32\Drivers\HTTP.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HTTPFilter]
"ServiceDll"="%SystemRoot%\System32\w3ssl.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i2omgmt]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i2omp]
"ImagePath"="\SystemRoot\system32\DRIVERS\i2omp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i8042prt]
"ImagePath"="system32\DRIVERS\i8042prt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ialm]
"ImagePath"="system32\DRIVERS\ialmnt5.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iaStor]
"ImagePath"="system32\DRIVERS\iaStor.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IDriverT]
"ImagePath"="\"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Imapi]
"ImagePath"="system32\DRIVERS\imapi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ImapiService]
"ImagePath"="%systemroot%\system32\imapi.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\inetaccs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ini910u]
"ImagePath"="\SystemRoot\system32\DRIVERS\ini910u.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Inport]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IntelIde]
"ImagePath"="system32\DRIVERS\intelide.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\intelppm]
"ImagePath"="system32\DRIVERS\intelppm.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ip6Fw]
"ImagePath"="system32\DRIVERS\Ip6Fw.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpFilterDriver]
"ImagePath"="system32\DRIVERS\ipfltdrv.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpInIp]
"ImagePath"="system32\DRIVERS\ipinip.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpNat]
"ImagePath"="system32\DRIVERS\ipnat.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iPodService]
"ImagePath"="C:\Program Files\iPod\bin\iPodService.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IPSec]
"ImagePath"="system32\DRIVERS\ipsec.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IRENUM]
"ImagePath"="system32\DRIVERS\irenum.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ISAPISearch]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\isapnp]
"ImagePath"="system32\DRIVERS\isapnp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Kbdclass]
"ImagePath"="system32\DRIVERS\kbdclass.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kbdhid]
"ImagePath"="system32\DRIVERS\kbdhid.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kmixer]
"ImagePath"="system32\drivers\kmixer.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\KSecDD]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lanmanserver]
"ServiceDll"="%SystemRoot%\System32\srvsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lanmanworkstation]
"ServiceDll"="%SystemRoot%\System32\wkssvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lbrtfdc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ldap]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LicenseService]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LightScribeService]
"ImagePath"="\"C:\Program Files\Common Files\LightScribe\LSSrvc.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LiveUpdate]
"ImagePath"="\"C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LmHosts]
"ServiceDll"="%SystemRoot%\System32\lmhsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MarvinBus]
"ImagePath"="system32\DRIVERS\MarvinBus.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mdmxsdk]
"ImagePath"="system32\DRIVERS\mdmxsdk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Messenger]
"ServiceDll"="%SystemRoot%\System32\msgsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mnmdd]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mnmsrvc]
"ImagePath"="C:\WINDOWS\system32\mnmsrvc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Modem]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Mouclass]
"ImagePath"="system32\DRIVERS\mouclass.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mouhid]
"ImagePath"="system32\DRIVERS\mouhid.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MountMgr]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mraid35x]
"ImagePath"="\SystemRoot\system32\DRIVERS\mraid35x.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MRxDAV]
"ImagePath"="system32\DRIVERS\mrxdav.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MRxSmb]
"ImagePath"="system32\DRIVERS\mrxsmb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSDTC]
"ImagePath"="C:\WINDOWS\system32\msdtc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Msfs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSIServer]
"ImagePath"="%systemroot%\system32\msiexec.exe /V"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSKSSRV]
"ImagePath"="system32\drivers\MSKSSRV.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSPCLOCK]
"ImagePath"="system32\drivers\MSPCLOCK.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSPQM]
"ImagePath"="system32\drivers\MSPQM.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mssmbios]
"ImagePath"="system32\DRIVERS\mssmbios.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSTEE]
"ImagePath"="system32\drivers\MSTEE.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Mup]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NABTSFEC]
"ImagePath"="system32\DRIVERS\NABTSFEC.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\navapsvc]
"ImagePath"="\"c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NAVENG]
"ImagePath"="\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061210.007\NAVENG.Sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NAVEX15]
"ImagePath"="\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061210.007\NavEx15.Sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NDIS]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NdisIP]
"ImagePath"="system32\DRIVERS\NdisIP.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NdisTapi]
"ImagePath"="system32\DRIVERS\ndistapi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ndisuio]
"ImagePath"="system32\DRIVERS\ndisuio.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NdisWan]
"ImagePath"="system32\DRIVERS\ndiswan.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NDProxy]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetBIOS]
"ImagePath"="system32\DRIVERS\netbios.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetBT]
"ImagePath"="system32\DRIVERS\netbt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetDDE]
"ImagePath"="%SystemRoot%\system32\netdde.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetDDEdsdm]
"ImagePath"="%SystemRoot%\system32\netdde.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Netlogon]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Netman]
"ServiceDll"="%SystemRoot%\System32\netman.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NIC1394]
"ImagePath"="system32\DRIVERS\nic1394.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Nla]
"ServiceDll"="%SystemRoot%\System32\mswsock.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Npfs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NSCService]
"ImagePath"="\"c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ntfs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtLmSsp]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtmsSvc]
"ServiceDll"="%SystemRoot%\system32\ntmssvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Null]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NwlnkFlt]
"ImagePath"="system32\DRIVERS\nwlnkflt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NwlnkFwd]
"ImagePath"="system32\DRIVERS\nwlnkfwd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ohci1394]
"ImagePath"="system32\DRIVERS\ohci1394.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Parport]<