This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Cant Run Spybot SD, Malwarebytes, etc

167 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey guys, Thanks for your help in advance. I did go through the self fixes. I could run ATF fine. My computer wont let me run Malware antibytes or spybot S&D. It gives me the following error msg : c:\program files\malwarebytes' anti-malware\mbam.exe X Windows cannot access the specified device,path, or file. You may not have the appropriate permissions to access the item. It gives me the exact same msg for spybot, but with the appropriate file name. Also, when I open a lotta folders, etc…I get this msg.. NERO This program requires the file advrcntr2.dll, which was not found on this system. And thirdly, it did start opening random internet explorer windows. Never had this problem before this. One more thing I find funny, and I dont use internet explorer much, but everytime I open it, it asks me to update to explorer version 8. I have already done this like 5x and it still asks me this. Ah, While I was typing this, I tried to run Hijack this and it gives me the same lame msg like spybot and malware >< I dunno how to get the logs. **EDIT : TO make things interesting, it gives me the exact same msg even when I run hijackthis, spybot, malware in SAFE MODE. I have no clue how I can get logs now >< Ok, I cant run ANY kind of spyware removal or virus removal >< I even tried to reinstall Hijackthis, and before running it, I renamed it to H.exe. But it still gave me same error ><
OK, So I tried few more things while waiting on reply, hoping I can pinpoint my problem more precisely. Here are few problems.. 1. Spybot SD wont run. Same with Malwarebytes, Hijackthis, SuperAntispyware. I did try to rename the installation files and then install and run it. But no luck. Furthest I got was with SuperAntiSpyware, which scanned for about 5 mins, then the window just closed. Now I cant run the main file. It gives exact same error as I posted in the above post. 2. I tried kaspersky's online scanner. It was almost done updating, but got error and failed. Now, just like any other softwares mentioned above, I cant run it. Error goes soemthing like… Update has failed. Program has failed to start. Close the Kas online scanner 7.0 window and open it again to install program. Then it gives some big line about you have to be online and at the end it says, KEY IS EXPIRED. 3. It was making it harder for me to get into safe mode too. But, regardless, I cant run any of the above mentioned softwares in safe mode either. It gives me the exact same errors. I have no clue what kinda virus I have. If I could use any of the softwares, maybe I can figure it out and post some logs. But to get to that point, is my problem. Atleast the virus is friendly enough that it doesnt stop me from browsing web, or running ANY other application that DOESNT try to remove any spyware/malware/viruses/trojans. I have never seen anything like this before lol. Its like the dang thing evolves and adapts. **EDIT Sorry forgot to mention couple more things >< I can open task manager, but it has no tabs on top now. SO I cant check what processes are running. All I can see the tasks and end task. I cant even close the task manager cuz it doesnt have the X on top right. And the other thing is, Once I run malwarebytes and stuff, As I already posted, it doesnt finish and it just closes the window. I cant even rename the files in that folder cuz it says *You do not have the permission*. All I have is 1 account on this computer and its admin account.
[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to take a look at your log.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay, but I will do my best to keep it as short as possible.

I will be back to you shortly with instructions. :) In the meantime, please do not perform anymore fixes.
[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.

Note: As you are running Vista, please run all of our applications by right-clicking on them and selecting Run as Administrator

1) DDS
[external image: Posted Image]
Please download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.

2) GMER
Please download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Rename GMER.exe to REMG.exe
  • Double click REMG.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and put it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


3) RR
Please download RootRepeal.zip.
Save it to your Desktop. Alternate download links here or here.
Please print these instructions, you will not have an Internet connection!
If you have a 3rd party "unzipping" program…use it to open the zipped file…then skip to Step 5. Otherwise…
  • Right click on RootRepeal.zip and select "Extract All"….
  • Click Next on the "Welcome to the Compressed (zipped) Folders Extraction Wizard."
  • Click on the Browse…button, then click on Desktop, then click OK.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Before running RootRepeal:
    • Disconnect from the Internet as your system will be unprotected while using this tool.
      Close all programs and temporarily disable your anti-virus, Firewall and any anti-malware real-time protection before performing a scan.
  • Open the RootRepeal folder and double-click on RootRepeal.exe to launch it.
  • When the program opens, click the Report tab at the bottom, then click the Scan button.
  • In the Select Scan, dialog which asks What do you want to include in the scan?, check ALL the boxes.
    🖼Click to load external image (Posted Image)
  • Click OK.
  • In the Select Drives, dialog Please select drives to scan: select all drives showing, then click OK.
    The scan can take some time to finish. Do not use the computer while the scan is running.
    When the scan has completed, a list of files will be generated in the RootRepeal window.
  • Click on the Save Report button and save it as "rootrepeal.txt" to your desktop.
  • Close and exit RootRepeal
  • Double-click on the file rootrepeal.txt… Notepad will open… copy/paste the file contents in your next reply.

Make sure to enable your anti-virus, Firewall and any other security programs you disabled.
Note: If RootRepeal cannot complete a scan and results in a crash report, try repeating the scan in "safe mode".

4) What You Will Need To Post:
  • DDS logs
  • GMER log
  • RootRepeal log
Well, I am about to disappoint you. The dds.scr, DId you mean download from here AND here AND here ? Cuz all 3 of them are different..ie pif, com, scr. I got all 3 to try it anyway since I kept getting error. All 3 of them gave me this error and still do… 16 bit MS-DOS subsystem c:\windows\system32\desot.exe The NTVDM CPU has encountered an illegal instruction. CS:fef0 IP:9a0e OP:ff ff ff ff ff Choose 'Chose' to terminate the application. I did try to RIGHT click and run it as admin, but ther is no option to run it as ADMIN. So I tried to go in the properties. I saw there that it already has full permission to run as admin. Now, I cant run it. Ok, then I moved on to the next one..GMER, I did rename it and followed the EXACT directions. It did start the scan and after about 3-5 mins, it gave blue screen, killed process. Just like it did with malaware byes, etc. I had to reboot in safe mode with networking. It did start scan with GMER in safe mode, but same thing, after few mins it just killed the process. Now I get the same exact error that I get with spybot SD, Malwarebytes, etc. Rootrepeal - Same problem as GMER. I cant run the file now. It did start the scan initially, but it killed the process >< I am really sorry I am not being much helpfull, but this thing is getting on my nerves. Any more suggestions ?
I ran the explorer process thing to get the info on processes, maybe it can help you better. Here are the results… *IN SAFE MODE Process PID CPU Description Company Name System Idle Process 0 97.99 Interrupts n/a Hardware Interrupts DPCs n/a Deferred Procedure Calls System 4 smss.exe 396 Windows Session Manager Microsoft Corporation csrss.exe 456 Client Server Runtime Process Microsoft Corporation csrss.exe 492 Client Server Runtime Process Microsoft Corporation wininit.exe 500 Windows Start-Up Application Microsoft Corporation services.exe 572 Services and Controller app Microsoft Corporation svchost.exe 740 Host Process for Windows Services Microsoft Corporation unsecapp.exe 1424 Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation WmiPrvSE.exe 868 WMI Provider Host Microsoft Corporation IDMan.exe 2732 Internet Download Manager (IDM) Tonec Inc. svchost.exe 812 Host Process for Windows Services Microsoft Corporation svchost.exe 980 Host Process for Windows Services Microsoft Corporation svchost.exe 1004 Host Process for Windows Services Microsoft Corporation svchost.exe 1064 Host Process for Windows Services Microsoft Corporation svchost.exe 1084 Host Process for Windows Services Microsoft Corporation svchost.exe 1100 Host Process for Windows Services Microsoft Corporation svchost.exe 1336 Host Process for Windows Services Microsoft Corporation svchost.exe 1452 Host Process for Windows Services Microsoft Corporation lsass.exe 588 Local Security Authority Process Microsoft Corporation lsm.exe 596 Local Session Manager Service Microsoft Corporation winlogon.exe 528 Windows Logon Application Microsoft Corporation explorer.exe 1820 Windows Explorer Microsoft Corporation trillian.exe 1240 Trillian Cerulean Studios firefox.exe 1928 Firefox Mozilla Corporation WinRAR.exe 4056 WinRAR archiver Alexander Roshal procexp.exe 3876 3.11 Sysinternals Process Explorer Sysinternals - www.sysinternals.com **IN NORMAL MODE Process PID CPU Description Company Name System Idle Process 0 98.44 Interrupts n/a 0.75 Hardware Interrupts DPCs n/a Deferred Procedure Calls System 4 smss.exe 444 Windows Session Manager Microsoft Corporation csrss.exe 512 Client Server Runtime Process Microsoft Corporation wininit.exe 564 Windows Start-Up Application Microsoft Corporation services.exe 616 Services and Controller app Microsoft Corporation svchost.exe 788 Host Process for Windows Services Microsoft Corporation WmiPrvSE.exe 3220 WMI Provider Host Microsoft Corporation unsecapp.exe 4628 Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation nvvsvc.exe 876 NVIDIA Driver Helper Service, Version 176.44 NVIDIA Corporation rundll32.exe 1488 Windows host process (Rundll32) Microsoft Corporation svchost.exe 920 Host Process for Windows Services Microsoft Corporation svchost.exe 1064 Host Process for Windows Services Microsoft Corporation audiodg.exe 1288 Windows Audio Device Graph Isolation Microsoft Corporation svchost.exe 1132 Host Process for Windows Services Microsoft Corporation wlanext.exe 1808 Windows Wireless LAN 802.11 Extensibility Framework Microsoft Corporation dwm.exe 3960 Desktop Window Manager Microsoft Corporation svchost.exe 1208 Host Process for Windows Services Microsoft Corporation taskeng.exe 688 Task Scheduler Engine Microsoft Corporation taskeng.exe 3816 Task Scheduler Engine Microsoft Corporation CTAudSvc.exe 1328 Creative Audio Service Creative Technology Ltd svchost.exe 1372 Host Process for Windows Services Microsoft Corporation SLsvc.exe 1420 Microsoft Software Licensing Service Microsoft Corporation svchost.exe 1452 Host Process for Windows Services Microsoft Corporation svchost.exe 1616 Host Process for Windows Services Microsoft Corporation spoolsv.exe 1876 Spooler SubSystem App Microsoft Corporation svchost.exe 1940 Host Process for Windows Services Microsoft Corporation AEstSrv.exe 780 Andrea filters APO access service (32-bit) Andrea Electronics Corporation svchast.exe 800 AppleMobileDeviceService.exe 1052 Apple Mobile Device Service Apple Inc. mDNSResponder.exe 776 Bonjour Service Apple Inc. svchost.exe 1564 Host Process for Windows Services Microsoft Corporation CreativeLicensing.exe 1684 System Level Service Utility Creative Labs dlcdcoms.exe 1968 Printer Communication System EvtEng.exe 692 Intel® PROSet/Wireless Event Log Intel Corporation IAANTmon.exe 2076 RAID Monitor Intel Corporation PnkBstrA.exe 2212 svchost.exe 2316 Host Process for Windows Services Microsoft Corporation RegSrvc.exe 2364 Intel® PROSet/Wireless Registry Service Intel Corporation RoxWatch9.exe 2408 RoxSniffer9 Module Sonic Solutions stacsv.exe 2484 STacSV Module IDT, Inc. svchost.exe 2536 Host Process for Windows Services Microsoft Corporation ViewpointService.exe 2568 ViewMgr Viewpoint Corporation svchost.exe 2668 Host Process for Windows Services Microsoft Corporation SearchIndexer.exe 2748 Microsoft Windows Search Indexer Microsoft Corporation alg.exe 3072 Application Layer Gateway Service Microsoft Corporation svchost.exe 4864 Host Process for Windows Services Microsoft Corporation lsass.exe 628 Local Security Authority Process Microsoft Corporation lsm.exe 640 Local Session Manager Service Microsoft Corporation csrss.exe 572 Client Server Runtime Process Microsoft Corporation winlogon.exe 836 Windows Logon Application Microsoft Corporation explorer.exe 3996 0.75 Windows Explorer Microsoft Corporation firefox.exe 5864 Firefox Mozilla Corporations procexp.exe 5628 0.75 Sysinternals Process Explorer Sysinternals - www.sysinternals.com You will notice VNC in there, Which I ended up uninstalling. I really dont remember installing it and even if I did, it prolly was really long time ago. So I uninstalled it and got a new process log. ** NEW log, after uninstalling VNC Process PID CPU Description Company Name System Idle Process 0 91.90 Interrupts n/a Hardware Interrupts DPCs n/a 1.52 Deferred Procedure Calls System 4 smss.exe 444 Windows Session Manager Microsoft Corporation csrss.exe 512 Client Server Runtime Process Microsoft Corporation wininit.exe 564 Windows Start-Up Application Microsoft Corporation services.exe 616 Services and Controller app Microsoft Corporation svchost.exe 788 Host Process for Windows Services Microsoft Corporation WmiPrvSE.exe 3220 WMI Provider Host Microsoft Corporation unsecapp.exe 4628 Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation nvvsvc.exe 876 NVIDIA Driver Helper Service, Version 176.44 NVIDIA Corporation rundll32.exe 1488 Windows host process (Rundll32) Microsoft Corporation svchost.exe 920 Host Process for Windows Services Microsoft Corporation svchost.exe 1064 Host Process for Windows Services Microsoft Corporation audiodg.exe 1288 Windows Audio Device Graph Isolation Microsoft Corporation svchost.exe 1132 Host Process for Windows Services Microsoft Corporation wlanext.exe 1808 Windows Wireless LAN 802.11 Extensibility Framework Microsoft Corporation dwm.exe 3960 Desktop Window Manager Microsoft Corporation svchost.exe 1208 Host Process for Windows Services Microsoft Corporation taskeng.exe 688 Task Scheduler Engine Microsoft Corporation taskeng.exe 3816 0.76 Task Scheduler Engine Microsoft Corporation CTAudSvc.exe 1328 Creative Audio Service Creative Technology Ltd svchost.exe 1372 Host Process for Windows Services Microsoft Corporation SLsvc.exe 1420 Microsoft Software Licensing Service Microsoft Corporation svchost.exe 1452 Host Process for Windows Services Microsoft Corporation svchost.exe 1616 Host Process for Windows Services Microsoft Corporation spoolsv.exe 1876 Spooler SubSystem App Microsoft Corporation svchost.exe 1940 Host Process for Windows Services Microsoft Corporation AEstSrv.exe 780 Andrea filters APO access service (32-bit) Andrea Electronics Corporation svchast.exe 800 AppleMobileDeviceService.exe 1052 Apple Mobile Device Service Apple Inc. mDNSResponder.exe 776 Bonjour Service Apple Inc. svchost.exe 1564 Host Process for Windows Services Microsoft Corporation CreativeLicensing.exe 1684 System Level Service Utility Creative Labs dlcdcoms.exe 1968 Printer Communication System EvtEng.exe 692 Intel® PROSet/Wireless Event Log Intel Corporation IAANTmon.exe 2076 RAID Monitor Intel Corporation PnkBstrA.exe 2212 svchost.exe 2316 Host Process for Windows Services Microsoft Corporation RegSrvc.exe 2364 Intel® PROSet/Wireless Registry Service Intel Corporation RoxWatch9.exe 2408 RoxSniffer9 Module Sonic Solutions stacsv.exe 2484 STacSV Module IDT, Inc. svchost.exe 2536 Host Process for Windows Services Microsoft Corporation ViewpointService.exe 2568 ViewMgr Viewpoint Corporation svchost.exe 2668 Host Process for Windows Services Microsoft Corporation SearchIndexer.exe 2748 Microsoft Windows Search Indexer Microsoft Corporation alg.exe 3072 Application Layer Gateway Service Microsoft Corporation svchost.exe 4864 Host Process for Windows Services Microsoft Corporation lsass.exe 628 Local Security Authority Process Microsoft Corporation lsm.exe 640 Local Session Manager Service Microsoft Corporation csrss.exe 572 2.28 Client Server Runtime Process Microsoft Corporation winlogon.exe 836 Windows Logon Application Microsoft Corporation explorer.exe 3996 Windows Explorer Microsoft Corporation firefox.exe 5864 0.76 Firefox Mozilla Corporation procexp.exe 6140 1.52 Sysinternals Process Explorer Sysinternals - www.sysinternals.com Raktor, Please dont take this as me trying to go over you lol. I am just trying to help as much as I can, since not much I can do from work. Just hoping we can resolve this quicker and we dont have to go thru the formatting route =) Thanks again for your help bud. Parth
Note: We recommend that you save these instructions to your desktop, or print them out, as we will be going into Safe Mode during part of this fix. Select all of the text, copy (Ctrl+C) and paste (Ctrl+V) to a Notepad (Start->Programs->Accessories) document, then save (Ctrl+S) to your desktop.

1) Unhide Files and Folders
  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.

2) File Removal
  • Navigate to your c:\documents and settings\all users\application data folder
  • Look for a file/folder with a random 8 digit number ie 19285624\19285624.exe (your number will be different)
  • Drag this file/folder c:\documents and settings\all users\application data\19285624\19285624.exe to the desktop (drag - not delete)
  • Reboot.

3) OTL
Download OTL by Old Timer and save it to your Desktop.

Please reboot your computer in Safe Mode by doing the following:
  • Restart your computer.
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually.
  • Instead of Windows loading as normal, a menu with options should appear.
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.

  • Double click on OTL.exe to run it.
  • Under Output, ensure that Minimal Output is selected.
  • Under Extra Registry section, select Use SafeList.
  • Click the Scan All Users checkbox.
  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open.
    • OTListIt.txt <– Will be opened
    • Extra.txt <– Will be minimized
  • Please post the contents of these 2 Notepad files in your next reply.

4) SysProt
Please download Sysprot Antirootkit from here

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.

  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select all items.
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to.
  • Open the text file and copy/paste the log here.

5) What You Will Need To Post:
  • OTL logs
  • SysProt log

Raktor, Please dont take this as me trying to go over you lol. I am just trying to help as much as I can, since not much I can do from work. Just hoping we can resolve this quicker and we dont have to go thru the formatting route =)


That's absolutely fine, this is just a newer infection that takes a little more work to get rid of.
Alright, Now we in business!! I am so happy that we finally got a dang scan done!!! lol

Ok, I am sorry I had just mentioned it in PM to you raktor, but..I have VISTA…When I had made the post initially, my profile still showed XP. Sorry about that.

1. Showing hidden files and stuff done successfully.

2. I cannot find any folder/file with a name as a 8 digit number. I even searched for *.exe under c:\users and no luck.
I did look under documents and settings also, but none there either.


OTListIt.txt :

OTL logfile created on: 8/11/2009 10:11:53 AM - Run 1
OTL by OldTimer - Version 3.0.10.5 Folder = C:\Users\Parth\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 220.31 Gb Total Space | 69.58 Gb Free Space | 31.59% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.88 Gb Free Space | 58.80% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PARTH-PC
Current User Name: Parth
Logged in as Administrator.

Current Boot Mode: SafeMode
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Users\Parth\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wbem\wmiprvse.exe (Microsoft Corporation)

========== Win32 Services (SafeList) ==========

SRV - (AESTFilters [Auto | Stopped]) – C:\Windows\System32\aestsrv.exe (Andrea Electronics Corporation)
SRV - (AntipPro2009_12 [Auto | Stopped]) – C:\Windows\svchast.exe ()
SRV - (Apple Mobile Device [Auto | Stopped]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Bonjour Service [Auto | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Creative ALchemy AL6 Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (Creative Labs Licensing Service [Auto | Stopped]) – C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
SRV - (Creative Media Toolbox 6 Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe (Creative Labs)
SRV - (CTAudSvcService [Auto | Stopped]) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (dlcd_device [Auto | Stopped]) – C:\Windows\System32\dlcdcoms.exe ( )
SRV - (DSBrokerService [On_Demand | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (Eventlog [Auto | Running]) – C:\Windows\System32\wevtsvc.dll (Microsoft Corporation)
SRV - (EvtEng [Auto | Stopped]) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GoToAssist [On_Demand | Stopped]) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (IAANTMON [Auto | Stopped]) – C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (LMIMaint [Auto | Stopped]) – File not found
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NMIndexingService [Disabled | Stopped]) – File not found
SRV - (nvsvc [Auto | Stopped]) – C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation)
SRV - (PnkBstrA [Auto | Stopped]) – C:\Windows\System32\PnkBstrA.exe ()
SRV - (RapiMgr [Auto | Stopped]) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (RegSrvc [Auto | Stopped]) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (RoxMediaDB9 [On_Demand | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
SRV - (RoxWatch9 [Auto | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
SRV - (rpcapd [On_Demand | Stopped]) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)
SRV - (STacSV [Auto | Stopped]) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\STacSV.exe (IDT, Inc.)
SRV - (stllssvr [On_Demand | Stopped]) – C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Auto | Stopped]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WcesComm [Auto | Stopped]) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (WinDefend [Auto | Stopped]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WLSetupSvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (adp94xx [Disabled | Stopped]) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (aic78xx [Disabled | Stopped]) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ApfiltrService [On_Demand | Running]) – C:\Windows\System32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (arc [Disabled | Stopped]) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (atksgt [Auto | Stopped]) – C:\Windows\System32\DRIVERS\atksgt.sys ()
DRV - (BrFiltLo [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (btwaudio [On_Demand | Stopped]) – C:\Windows\System32\drivers\btwaudio.sys (Broadcom Corporation.)
DRV - (btwavdt [On_Demand | Stopped]) – C:\Windows\System32\drivers\btwavdt.sys (Broadcom Corporation.)
DRV - (btwrchid [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\btwrchid.sys (Broadcom Corporation.)
DRV - (cmdide [Disabled | Stopped]) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (DSproct [On_Demand | Stopped]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Stopped]) – C:\Windows\System32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (e1express [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\e1e6032.sys (Intel Corporation)
DRV - (E1G60 [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (elxstor [Disabled | Stopped]) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\Windows\System32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HpCISSs [Disabled | Stopped]) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (iaNvStor [Disabled | Stopped]) – C:\Windows\system32\drivers\ianvstor.sys (Intel Corporation)
DRV - (iaStor [Boot | Running]) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (iaStorV [Boot | Running]) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (iteatapi [Disabled | Stopped]) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (ksaud [On_Demand | Stopped]) – C:\Windows\System32\drivers\ksaud.sys (Creative Technology Ltd.)
DRV - (lirsgt [Auto | Stopped]) – C:\Windows\System32\DRIVERS\lirsgt.sys ()
DRV - (lmimirr [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\lmimirr.sys (LogMeIn, Inc.)
DRV - (LMIRfsClientNP [Disabled | Stopped]) – C:\Windows\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (LMIRfsDriver [Auto | Stopped]) – C:\Windows\System32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LSI_FC [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (megasas [Disabled | Stopped]) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Mraid35x [Disabled | Stopped]) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (MREMP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NETw4v32 [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\NETw4v32.sys (Intel Corporation)
DRV - (nfrd960 [Disabled | Stopped]) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (NPF [On_Demand | Stopped]) – C:\Windows\System32\drivers\npf.sys (CACE Technologies)
DRV - (ntrigdigi [Disabled | Stopped]) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (nvlddmkm [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\nvlddmkm.sys (NVIDIA Corporation)
DRV - (nvraid [Disabled | Stopped]) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (OEM02Dev [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (OEM02Vfx [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (pcouffin [On_Demand | Stopped]) – C:\Windows\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (PxHelp20 [Boot | Running]) – C:\Windows\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql2300 [Disabled | Stopped]) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (R300 [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV - (rimmptsk [Auto | Running]) – C:\Windows\System32\DRIVERS\rimmptsk.sys (REDC)
DRV - (rimsptsk [Auto | Running]) – C:\Windows\System32\DRIVERS\rimsptsk.sys (REDC)
DRV - (rismxdp [Auto | Running]) – C:\Windows\System32\DRIVERS\rixdptsk.sys (REDC)
DRV - (SASDIFSV [System | Stopped]) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Stopped]) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Stopped]) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (secdrv [Auto | Stopped]) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid2 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid4 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (sptd [Boot | Running]) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (STHDA [On_Demand | Stopped]) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (Symc8xx [Disabled | Stopped]) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (TcUsb [On_Demand | Stopped]) – C:\Windows\System32\Drivers\tcusb.sys (UPEK Inc.)
DRV - (uliahci [Disabled | Stopped]) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\Windows\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\Windows\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (usb_rndisx [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\usb8023x.sys (Microsoft Corporation)
DRV - (viaide [Disabled | Stopped]) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Disabled | Stopped]) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (yukonwlh [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\yk60x86.sys (Marvell)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Local Page = http://www.iesearch.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.iesearch.com/
IE - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\S-1-5-21-3256818742-1514715972-2829636577-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\S-1-5-21-3256818742-1514715972-2829636577-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "FireSearch"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com"
FF - prefs.js..extensions.enabledItems: [removed]:5.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07103010
FF - prefs.js..extensions.enabledItems: [removed]:2
FF - prefs.js..extensions.enabledItems: 4
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: [removed]:1.3
FF - prefs.js..extensions.enabledItems: [removed]:1.4
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13
FF - prefs.js..keyword.URL: "http://www.ffsearch.net/s/?ref=adr&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/05/26 19:01:00 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/25 09:38:29 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/04 16:01:07 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/04 16:01:07 | 00,000,000 | —D | M]

[2009/05/23 18:22:01 | 00,000,000 | —D | M] – C:\Users\Parth\AppData\Roaming\mozilla\Extensions
[2008/08/26 20:51:03 | 00,000,000 | —D | M] – C:\Users\Parth\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/23 18:22:01 | 00,000,000 | —D | M] – C:\Users\Parth\AppData\Roaming\mozilla\Extensions\[removed]
[2009/08/10 15:47:55 | 00,000,000 | —D | M] – C:\Users\Parth\AppData\Roaming\mozilla\Firefox\Profiles\nz19xi5p.default\extensions
[2009/06/25 11:11:43 | 00,000,000 | —D | M] – C:\Users\Parth\AppData\Roaming\mozilla\Firefox\Profiles\nz19xi5p.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/05/04 10:16:15 | 00,000,000 | —D | M] – C:\Users\Parth\AppData\Roaming\mozilla\Firefox\Profiles\nz19xi5p.default\extensions\[removed]
[2008/07/03 13:35:59 | 00,000,000 | —D | M] – C:\Users\Parth\AppData\Roaming\mozilla\Firefox\Profiles\nz19xi5p.default\extensions\[removed]
[2008/02/07 11:45:21 | 00,002,920 | —- | M] () – C:\Users\Parth\AppData\Roaming\Mozilla\FireFox\Profiles\nz19xi5p.default\searchplugins\daemon-search.xml
[2008/03/10 19:05:30 | 00,000,996 | —- | M] () – C:\Users\Parth\AppData\Roaming\Mozilla\FireFox\Profiles\nz19xi5p.default\searchplugins\FireSearch.xml
[2009/08/10 15:47:55 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/08/04 16:01:07 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/12/30 21:04:30 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/05/02 15:24:13 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/08/26 20:51:00 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\[removed]
[2009/08/04 16:01:06 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/04 16:01:06 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2007/04/17 01:10:32 | 00,539,136 | —- | M] (UPEK Inc.) – C:\Program Files\mozilla firefox\components\pbgk1_8.dll
[2007/04/10 18:21:08 | 00,163,256 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\np-mswmp.dll
[2008/08/06 17:22:02 | 00,114,688 | —- | M] (Adobe Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\np32dsw.dll
[2008/10/17 14:29:52 | 01,332,224 | —- | M] (DivX,Inc.) – C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2008/01/07 19:14:26 | 00,098,304 | —- | M] (DivX, Inc) – C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll
[2007/10/11 15:17:50 | 01,435,688 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009/08/04 16:01:06 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2008/10/14 22:33:30 | 00,095,600 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2008/05/26 19:00:54 | 00,144,984 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2009/04/04 13:38:37 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/04/04 13:38:38 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/04/04 13:38:38 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/04/04 13:38:38 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/04/04 13:38:38 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/04/04 13:38:38 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/04/04 13:38:38 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2008/05/26 19:01:07 | 00,008,192 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprjplug.dll
[2008/05/26 19:00:51 | 00,094,208 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2008/09/15 11:52:06 | 00,376,832 | —- | M] ( ) – C:\Program Files\mozilla firefox\plugins\npsnapfish.dll
[2008/05/12 10:31:02 | 01,212,416 | —- | M] (cedelia) – C:\Program Files\mozilla firefox\plugins\NPStreamPlug.dll
[2008/11/04 21:50:22 | 00,221,184 | —- | M] (CNN) – C:\Program Files\mozilla firefox\plugins\NPTURNMED.dll
[2007/04/16 13:07:12 | 00,180,293 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2008/09/30 10:52:58 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/09/30 10:52:58 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/09/30 10:52:58 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/14 09:17:58 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/09/30 10:52:58 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/09/30 10:52:58 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/09/30 10:52:58 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (27 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\IDM.5.14.Build.3.Fixed-REA\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {46d2b8e4-b1a2-4e71-b177-0d681ad96db1} - C:\Windows\System32\himesuvo.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (ICQSys (IE PlugIn)) - {F54AF7DE-6038-4026-8433-CC30E3F17212} - C:\Windows\System32\dddesot.dll (ASC - AntiSpyware)
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (Veoh Browser Plug-in) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll (Veoh Networks Inc)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [CPM294f4f23] C:\Windows\System32\titewiko.DLL ()
O4 - HKLM..\Run: [Creative SB Monitoring Utility] C:\Windows\System32\sbavmon.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [jofefevemi] C:\Windows\System32\pipidesa.DLL ()
O4 - HKLM..\Run: [Module Loader] C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PSQLLauncher] C:\Program Files\Fingerprint Reader Suite\launcher.exe (UPEK Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\Sound Blaster X-Fi Notebook\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000..\Run: [IDMan] C:\IDM.5.14.Build.3.Fixed-REA\IDMan.exe (Tonec Inc.)
O4 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableCAD = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O7 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download all links with IDM - C:\IDM.5.14.Build.3.Fixed-REA\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\IDM.5.14.Build.3.Fixed-REA\IEGetVL.htm File not found
O8 - Extra context menu item: Download with IDM - C:\IDM.5.14.Build.3.Fixed-REA\IEExt.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\System32\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3256818742-1514715972-2829636577-1000\..Trusted Domains: blank ([]about in Trusted sites)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://echat.bellsouth.net/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} http://www.worldwinner.com/games/v50/tpir/tpir.cab (TPIR Control)
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} http://www.worldwinner.com/games/v50/pool/pool.cab (Pool Control)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab (Windows Live OneCare safety scanner control)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} http://www.worldwinner.com/games/v63/bjattack/bja.cab (BJA Control)
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab (Bejeweled Control)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab (WordMojo Control)
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} http://www.worldwinner.com/games/v57/wof/wof.cab (WoF Control)
O16 - DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0} http://www.idesitv.com/livetv.ocx (KooPlayer Control)
O16 - DPF: {ADACAA8F-3595-47FE-9C31-9C7471B9BEC7} http://68.213.32.251/cab/OCXChecker_8198.cab (OCXDownloadChecker Control)
O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} http://www.worldwinner.com/games/v45/royal/royal.cab (Royal Control)
O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} http://www.worldwinner.com/games/v50/dinerdash/dinerdash.cab (DinerDash Control)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} http://www.worldwinner.com/games/v47/famil…/familyfeud.cab (FamilyFeud Control)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/softwareupdate/su2…15106/CTPID.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} http://www.worldwinner.com/games/v53/h2hpool/h2hpool.cab (H2hPool Control)
O16 - DPF: {FEC048AB-277A-460C-BF50-1A4193AEF148} http://68.213.32.251/cab/DownloadCenter_8200.cab (DownloadCenter Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\Windows\system32\jufuvowa.dll) - C:\Windows\System32\jufuvowa.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\sarotehi.dll) - C:\Windows\System32\sarotehi.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\titewiko.dll) - C:\Windows\System32\titewiko.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (vrlogon.dll) - C:\Windows\System32\vrlogon.dll (UPEK Inc.)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll File not found
O20 - Winlogon\Notify\psfus: DllName - C:\Windows\system32\psqlpwd.dll - C:\Windows\System32\psqlpwd.dll File not found
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - C:\Windows\System32\titewiko.dll ()
O22 - SharedTaskScheduler: {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - STS - C:\Windows\System32\titewiko.dll ()
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 00,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2008/08/10 16:03:10 | 00,000,000 | —D | M] - C:\autorefresh – [ NTFS ]
O33 - MountPoints2\{01277b41-4f67-11dd-b96f-001dd9e85b36}\Shell\Auto\command - "" = wscript "esta ig.vbs"
O33 - MountPoints2\{47b55a55-53a2-11de-ab4b-001dd9e85b36}\Shell\Auto\command - "" = wscript "esta ig.vbs"
O33 - MountPoints2\{4d76c645-53cd-11de-a767-001dd9e85b36}\Shell\Auto\command - "" = wscript "esta ig.vbs"
O33 - MountPoints2\{85e62f6f-cd16-11dd-b9bb-001dd9e85b36}\Shell - "" = AutoRun
O33 - MountPoints2\{85e62f6f-cd16-11dd-b9bb-001dd9e85b36}\Shell\AutoRun\command - "" = G:\LapNetWizard.exe – File not found
O33 - MountPoints2\{d1f3d59c-bf6e-11dd-a748-001dd9e85b36}\Shell\Auto\command - "" = wscript "esta ig.vbs"
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/08/11 10:07:24 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Users\Parth\Desktop\OTL.exe
[2009/08/10 21:46:55 | 03,739,490 | -H– | C] () – C:\Users\Parth\AppData\Local\IconCache.db
[2009/08/10 11:55:43 | 03,550,592 | —- | C] (Sysinternals - www.sysinternals.com) – C:\Users\Parth\Desktop\procexp.exe
[2009/08/10 11:55:43 | 00,072,138 | —- | C] () – C:\Users\Parth\Desktop\procexp.chm
[2009/08/10 11:49:41 | 01,615,732 | —- | C] () – C:\Users\Parth\Desktop\PE.zip
[2009/08/09 15:39:04 | 00,034,816 | —- | C] () – C:\Windows\System32\drivers\rr.sys
[2009/08/09 15:38:52 | 00,470,528 | —- | C] () – C:\Users\Parth\Desktop\RootRepeal.exe
[2009/08/09 15:38:30 | 00,462,996 | —- | C] () – C:\Users\Parth\Desktop\rr.zip
[2009/08/09 15:30:22 | 00,359,932 | R— | C] () – C:\Users\Parth\Desktop\dd.com
[2009/08/09 15:07:58 | 00,359,932 | —- | C] () – C:\Users\Parth\Desktop\dd.scr
[2009/08/09 15:05:57 | 00,000,000 | —D | C] – C:\Users\Parth\Desktop\gmer
[2009/08/09 10:25:57 | 00,000,000 | —D | C] – C:\Users\Parth\Desktop\rootrepeal
[2009/08/09 10:04:09 | 00,287,744 | —- | C] () – C:\Users\Parth\Desktop\remg.exe
[2009/08/08 18:10:21 | 00,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2009/08/08 18:10:21 | 00,000,000 | RHS- | C] () – C:\IO.SYS
[2009/08/08 11:24:38 | 00,000,030 | —- | C] () – C:\Windows\System32\sonhelp.htm
[2009/08/08 10:34:39 | 00,001,382 | —- | C] () – C:\Windows\System32\onhelp.htm
[2009/08/08 10:18:53 | 00,000,004 | —- | C] () – C:\Windows\System32\bincd32.dat
[2009/08/08 10:18:15 | 00,000,036 | —- | C] () – C:\Windows\System32\sysnet.dat
[2009/08/08 10:18:08 | 00,827,392 | —- | C] (ASC - AntiSpyware) – C:\Windows\System32\dddesot.dll
[2009/08/08 10:18:08 | 00,176,128 | —- | C] () – C:\Windows\svchast.exe
[2009/08/08 10:18:08 | 00,016,384 | —- | C] () – C:\Windows\System32\desot.exe
[2009/08/08 10:18:08 | 00,000,064 | —- | C] () – C:\Windows\ppp4.dat
[2009/08/08 10:18:08 | 00,000,009 | —- | C] () – C:\Windows\System32\bennuar.old
[2009/08/08 10:18:08 | 00,000,003 | —- | C] () – C:\Windows\ppp3.dat
[2009/08/08 10:17:59 | 00,000,000 | —D | C] – C:\Program Files\Windows Antivirus Pro
[2009/08/07 19:57:20 | 00,001,744 | —- | C] () – C:\Users\Parth\Desktop\Mozilla Firefox.lnk
[2009/08/07 19:41:55 | 00,000,820 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/07 19:41:53 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/08/07 19:41:52 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/08/07 19:41:52 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/08/07 19:29:34 | 00,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2009/08/07 19:27:52 | 00,000,904 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/08/07 19:27:51 | 00,000,000 | —D | C] – C:\Users\Parth\AppData\Roaming\SUPERAntiSpyware.com
[2009/08/07 19:27:51 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2009/08/07 19:13:57 | 01,343,651 | —- | C] () – C:\MGtools.exe
[2009/08/07 16:43:23 | 00,000,000 | —D | C] – C:\sdfix
[2009/08/07 15:54:15 | 00,000,000 | —D | C] – C:\Spybot
[2009/08/07 15:42:25 | 00,000,000 | -H-D | C] – C:\Windows\PIF
[2009/08/07 15:22:43 | 00,000,000 | —D | C] – C:\ht
[2009/08/07 15:02:41 | 00,000,000 | —D | C] – C:\Users\Parth\AppData\Local\Adobe
[2009/08/07 14:44:03 | 00,000,000 | —D | C] – C:\Program Files\ht
[2009/08/07 14:43:39 | 00,488,144 | —- | C] (Soeperman Enterprises Ltd ) – C:\Users\Parth\Desktop\HJTsetup.exe
[2009/08/07 14:37:41 | 00,050,688 | —- | C] (Atribune.org) – C:\Users\Parth\Desktop\ATF-Cleaner.exe
[2009/08/07 11:15:49 | 00,000,282 | -H– | C] () – C:\Windows\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
[2009/08/07 11:15:49 | 00,000,240 | -H– | C] () – C:\Windows\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[2009/08/01 11:36:22 | 00,000,000 | —D | C] – C:\Users\Parth\AppData\Local\Smilebox
[2009/08/01 11:36:20 | 00,000,000 | —D | C] – C:\Users\Parth\Documents\My Smilebox Creations
[2009/08/01 11:36:00 | 00,000,000 | —D | C] – C:\Users\Parth\AppData\Roaming\Smilebox
[2009/07/29 10:51:37 | 11,067,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/07/29 10:51:37 | 05,937,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/07/29 10:51:36 | 01,985,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/07/29 10:51:36 | 01,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2009/07/29 10:51:36 | 01,208,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/07/29 10:51:36 | 00,915,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/07/29 10:51:36 | 00,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/07/29 10:51:36 | 00,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/07/29 10:51:36 | 00,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\occache.dll
[2009/07/29 10:51:35 | 01,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/07/29 10:51:35 | 00,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2009/07/29 10:51:35 | 00,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2009/07/29 10:51:35 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2009/07/29 10:51:35 | 00,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/07/29 10:51:35 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2009/07/29 10:51:35 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2009/07/29 10:51:35 | 00,057,667 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2009/07/29 10:51:35 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2009/07/29 10:51:35 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2009/07/29 10:51:35 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/07/29 10:51:35 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2009/07/28 12:26:14 | 03,844,129 | —- | C] () – C:\Users\Parth\Desktop\clan eat.rar
[2009/07/21 16:21:46 | 00,000,000 | —D | C] – C:\Users\Parth\AppData\Roaming\IrfanView
[2009/07/21 16:21:46 | 00,000,000 | —D | C] – C:\Program Files\IrfanView
[2009/07/15 14:02:01 | 00,289,792 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2009/07/15 14:02:01 | 00,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2009/07/15 14:02:01 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2009/07/15 14:02:00 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dciman32.dll
[2009/07/13 14:41:45 | 00,000,000 | —D | C] – C:\Users\Parth\AppData\Local\RapidShare
[2009/07/13 14:41:15 | 00,002,633 | —- | C] () – C:\Users\Parth\Desktop\RapidShare Manager.lnk
[2009/05/11 09:21:48 | 00,084,480 | -HS- | C] () – C:\Windows\System32\titewiko.dll
[2009/05/11 09:21:48 | 00,037,376 | -HS- | C] () – C:\Windows\System32\hajigira.dll
[2009/05/10 21:10:52 | 00,083,968 | -HS- | C] () – C:\Windows\System32\sarotehi.dll
[2009/05/10 21:10:52 | 00,037,376 | -HS- | C] () – C:\Windows\System32\losesafa.dll
[2009/05/10 09:11:23 | 00,050,176 | -HS- | C] () – C:\Windows\System32\pipidesa.dll
[2009/05/10 09:11:23 | 00,050,176 | -HS- | C] () – C:\Windows\System32\jufuvowa.dll
[2009/05/10 09:11:23 | 00,050,176 | -HS- | C] () – C:\Windows\System32\himesuvo.dll
[2009/05/10 09:10:51 | 00,084,480 | -HS- | C] () – C:\Windows\System32\sinehotu.dll
[2009/05/10 09:10:51 | 00,050,176 | -HS- | C] () – C:\Windows\System32\kizomelo.dll
[2009/05/10 09:10:51 | 00,037,888 | -HS- | C] () – C:\Windows\System32\gokisoso.dll
[2009/05/09 15:38:59 | 00,084,992 | -HS- | C] () – C:\Windows\System32\kegezadu.dll
[2009/05/09 15:38:59 | 00,037,888 | -HS- | C] () – C:\Windows\System32\kewevuro.dll
[2009/05/08 22:38:28 | 00,085,504 | -HS- | C] () – C:\Windows\System32\buhivayi.dll
[2009/05/08 22:38:28 | 00,049,664 | -HS- | C] () – C:\Windows\System32\zoyiboha.dll
[2009/05/08 22:38:28 | 00,038,400 | -HS- | C] () – C:\Windows\System32\gugasara.dll
[2009/05/08 10:38:02 | 00,084,992 | -HS- | C] () – C:\Windows\System32\siruguhu.dll
[2009/05/08 10:38:02 | 00,038,400 | -HS- | C] () – C:\Windows\System32\pufajahe.dll
[2008/11/14 13:40:44 | 00,022,350 | R— | C] () – C:\Windows\System32\kschimp.ini
[2008/11/14 13:40:31 | 00,028,234 | —- | C] () – C:\Windows\System32\ksaud.ini
[2008/11/14 13:40:31 | 00,000,029 | —- | C] () – C:\Windows\System32\ctzapxx.ini
[2008/10/25 20:24:00 | 00,164,352 | —- | C] () – C:\Windows\System32\unrar.dll
[2008/10/25 20:24:00 | 00,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2008/10/25 20:23:59 | 00,755,027 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2008/10/25 20:23:59 | 00,159,839 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/10/25 20:23:57 | 00,007,680 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2008/10/25 20:23:57 | 00,000,547 | —- | C] () – C:\Windows\System32\ff_vfw.dll.manifest
[2008/09/23 09:47:45 | 00,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2008/09/21 16:16:49 | 00,000,119 | —- | C] () – C:\Windows\GeoLan.ini
[2008/09/20 15:13:06 | 00,000,128 | —- | C] () – C:\Windows\multiview.ini
[2008/09/20 15:12:51 | 00,000,082 | —- | C] () – C:\Windows\GeoPAL.ini
[2008/09/20 15:06:44 | 00,200,704 | —- | C] () – C:\Windows\JxIni.dll
[2008/09/20 15:06:44 | 00,139,264 | —- | C] () – C:\Windows\GV_GeoPTZini.dll
[2008/09/20 15:06:44 | 00,139,264 | —- | C] () – C:\Windows\GeoEditAVIDll.dll
[2008/09/20 15:06:44 | 00,024,576 | —- | C] ( ) – C:\Windows\GV_AccessIni_Memory.dll
[2008/05/29 10:16:31 | 00,060,928 | —- | C] () – C:\Windows\System32\scecli.dll
[2008/05/26 19:01:30 | 00,000,025 | —- | C] () – C:\Windows\cdplayer.ini
[2008/03/04 19:52:34 | 00,286,720 | —- | C] () – C:\Windows\System32\libcurl.dll
[2008/02/07 14:08:12 | 00,022,328 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2008/02/07 11:39:48 | 00,716,272 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2008/01/04 17:58:50 | 03,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/01/04 17:57:22 | 00,000,416 | —- | C] () – C:\Windows\System32\dtu100.dll.manifest
[2008/01/04 17:57:22 | 00,000,416 | —- | C] () – C:\Windows\System32\dpl100.dll.manifest
[2008/01/03 15:23:54 | 00,278,984 | —- | C] () – C:\Windows\System32\drivers\atksgt.sys
[2008/01/03 15:23:54 | 00,025,416 | —- | C] () – C:\Windows\System32\drivers\lirsgt.sys
[2007/12/21 09:43:28 | 00,167,936 | —- | C] () – C:\Windows\System32\nvccoin.dll
[2007/12/21 09:43:27 | 00,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2007/12/21 02:04:38 | 00,127,488 | —- | C] () – C:\Windows\System32\APOMngr.DLL
[2007/12/21 02:04:38 | 00,069,120 | —- | C] () – C:\Windows\System32\CmdRtr.DLL
[2007/12/21 02:04:38 | 00,000,628 | —- | C] () – C:\Windows\System32\PCI_VEN_1102&DEV_FF05&SUBSYS_00001102.ini
[2007/11/06 16:19:28 | 00,053,299 | —- | C] () – C:\Windows\System32\pthreadVC.dll
[2007/10/31 09:39:54 | 00,059,904 | —- | C] () – C:\Windows\System32\zlib1.dll
[2007/07/25 18:40:02 | 00,999,424 | —- | C] () – C:\Windows\System32\WLIHVUI.dll
[2007/05/17 14:58:10 | 00,143,360 | —- | C] () – C:\Windows\System32\libexpatw.dll
[2007/01/03 17:58:58 | 00,344,064 | —- | C] () – C:\Windows\System32\dlcdcoin.dll
[2006/12/20 21:12:18 | 00,069,632 | —- | C] () – C:\Windows\System32\dlcdcfg.dll
[2006/12/20 17:08:24 | 00,643,072 | —- | C] ( ) – C:\Windows\System32\dlcdpmui.dll
[2006/12/20 17:06:58 | 01,224,704 | —- | C] ( ) – C:\Windows\System32\dlcdserv.dll
[2006/12/20 17:01:04 | 00,421,888 | —- | C] ( ) – C:\Windows\System32\dlcdcomm.dll
[2006/12/20 16:59:24 | 00,585,728 | —- | C] ( ) – C:\Windows\System32\dlcdlmpm.dll
[2006/12/20 16:58:02 | 00,397,312 | —- | C] ( ) – C:\Windows\System32\dlcdiesc.dll
[2006/12/20 16:55:40 | 00,094,208 | —- | C] ( ) – C:\Windows\System32\dlcdpplc.dll
[2006/12/20 16:54:54 | 00,684,032 | —- | C] ( ) – C:\Windows\System32\dlcdcomc.dll
[2006/12/20 16:54:20 | 00,163,840 | —- | C] ( ) – C:\Windows\System32\dlcdprox.dll
[2006/12/20 16:47:32 | 00,413,696 | —- | C] ( ) – C:\Windows\System32\dlcdinpa.dll
[2006/12/20 16:46:50 | 00,991,232 | —- | C] ( ) – C:\Windows\System32\dlcdusb1.dll
[2006/12/20 16:42:36 | 00,696,320 | —- | C] ( ) – C:\Windows\System32\dlcdhbn3.dll
[2006/12/06 23:56:58 | 00,106,496 | —- | C] () – C:\Windows\System32\dlcdinsr.dll
[2006/12/06 23:56:50 | 00,036,864 | —- | C] () – C:\Windows\System32\dlcdcur.dll
[2006/12/06 23:56:16 | 00,135,168 | —- | C] () – C:\Windows\System32\dlcdjswr.dll
[2006/12/06 23:52:36 | 00,176,128 | —- | C] () – C:\Windows\System32\dlcdinsb.dll
[2006/12/06 23:52:30 | 00,086,016 | —- | C] () – C:\Windows\System32\dlcdcub.dll
[2006/12/06 23:52:18 | 00,073,728 | —- | C] () – C:\Windows\System32\dlcdcu.dll
[2006/12/06 23:52:14 | 00,159,744 | —- | C] () – C:\Windows\System32\dlcdins.dll
[2006/12/06 23:51:00 | 00,434,176 | —- | C] () – C:\Windows\System32\dlcdutil.dll
[2006/11/07 15:25:58 | 00,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/03 19:25:56 | 00,389,120 | —- | C] () – C:\Windows\System32\btwhidcs.dll
[2006/11/02 08:35:32 | 00,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:25:44 | 00,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 06:23:31 | 00,000,215 | —- | C] () – C:\Windows\system.ini
[2006/11/02 06:23:31 | 00,000,144 | —- | C] () – C:\Windows\win.ini
[2006/11/02 03:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/09/17 01:36:50 | 00,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/17 01:36:50 | 00,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2005/08/18 06:26:46 | 00,040,960 | —- | C] () – C:\Windows\System32\dlcdvs.dll
[2005/05/17 18:17:52 | 00,061,440 | —- | C] () – C:\Windows\System32\dlcdcnv4.dll
[2001/11/14 14:56:00 | 01,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll

========== Files - Modified Within 30 Days ==========

[5 C:\Windows\System32\*.tmp files]
[2009/08/11 10:10:04 | 00,011,168 | -H– | M] () – C:\Windows\System32\mupepidu
[2009/08/11 10:09:32 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/08/11 10:08:07 | 00,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/08/11 10:08:07 | 00,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/08/11 10:08:07 | 00,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2009/08/11 10:08:07 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/08/11 10:08:01 | 03,739,490 | -H– | M] () – C:\Users\Parth\AppData\Local\IconCache.db
[2009/08/11 10:07:18 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Users\Parth\Desktop\OTL.exe
[2009/08/11 10:06:45 | 00,000,069 | —- | M] () – C:\Windows\NeroDigital.ini
[2009/08/11 10:00:02 | 00,000,240 | -H– | M] () – C:\Windows\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[2009/08/11 10:00:01 | 00,000,282 | -H– | M] () – C:\Windows\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
[2009/08/11 09:46:28 | 00,000,004 | —- | M] () – C:\Windows\System32\bincd32.dat
[2009/08/11 09:25:57 | 00,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/08/11 09:25:57 | 00,595,684 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/08/11 09:25:57 | 00,101,350 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/08/11 09:22:24 | 00,027,839 | —- | M] () – C:\ProgramData\nvModes.dat
[2009/08/11 09:22:24 | 00,027,839 | —- | M] () – C:\ProgramData\nvModes.001
[2009/08/11 09:21:49 | 00,084,480 | -HS- | M] () – C:\Windows\System32\titewiko.dll
[2009/08/11 09:21:48 | 00,037,376 | -HS- | M] () – C:\Windows\System32\hajigira.dll
[2009/08/10 21:10:53 | 00,083,968 | -HS- | M] () – C:\Windows\System32\sarotehi.dll
[2009/08/10 21:10:52 | 00,037,376 | -HS- | M] () – C:\Windows\System32\losesafa.dll
[2009/08/10 14:28:58 | 29,626,7221 | —- | M] () – C:\Windows\MEMORY.DMP
[2009/08/10 11:49:33 | 01,615,732 | —- | M] () – C:\Users\Parth\Desktop\PE.zip
[2009/08/10 09:11:22 | 00,050,176 | -HS- | M] () – C:\Windows\System32\kizomelo.dll
[2009/08/10 09:10:52 | 00,084,480 | -HS- | M] () – C:\Windows\System32\sinehotu.dll
[2009/08/10 09:10:52 | 00,037,888 | -HS- | M] () – C:\Windows\System32\gokisoso.dll
[2009/08/09 16:03:05 | 00,015,872 | —- | M] () – C:\Users\Parth\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/09 15:40:25 | 00,001,356 | —- | M] () – C:\Users\Parth\AppData\Local\d3d9caps.dat
[2009/08/09 15:39:16 | 00,034,816 | —- | M] () – C:\Windows\System32\drivers\rr.sys
[2009/08/09 15:39:00 | 00,084,992 | -HS- | M] () – C:\Windows\System32\kegezadu.dll
[2009/08/09 15:39:00 | 00,037,888 | -HS- | M] () – C:\Windows\System32\kewevuro.dll
[2009/08/09 15:38:25 | 00,462,996 | —- | M] () – C:\Users\Parth\Desktop\rr.zip
[2009/08/09 15:30:22 | 00,359,932 | R— | M] () – C:\Users\Parth\Desktop\dd.com
[2009/08/09 15:07:58 | 00,359,932 | —- | M] () – C:\Users\Parth\Desktop\dd.scr
[2009/08/08 22:38:59 | 00,049,664 | -HS- | M] () – C:\Windows\System32\zoyiboha.dll
[2009/08/08 22:38:29 | 00,085,504 | -HS- | M] () – C:\Windows\System32\buhivayi.dll
[2009/08/08 22:38:29 | 00,038,400 | -HS- | M] () – C:\Windows\System32\gugasara.dll
[2009/08/08 18:10:21 | 00,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2009/08/08 18:10:21 | 00,000,000 | RHS- | M] () – C:\IO.SYS
[2009/08/08 18:00:02 | 00,016,384 | —- | M] () – C:\Windows\System32\desot.exe
[2009/08/08 18:00:02 | 00,000,064 | —- | M] () – C:\Windows\ppp4.dat
[2009/08/08 18:00:02 | 00,000,003 | —- | M] () – C:\Windows\ppp3.dat
[2009/08/08 17:57:37 | 00,001,382 | —- | M] () – C:\Windows\System32\onhelp.htm
[2009/08/08 17:36:24 | 00,827,392 | —- | M] (ASC - AntiSpyware) – C:\Windows\System32\dddesot.dll
[2009/08/08 11:24:38 | 00,000,030 | —- | M] () – C:\Windows\System32\sonhelp.htm
[2009/08/08 10:38:02 | 00,084,992 | -HS- | M] () – C:\Windows\System32\siruguhu.dll
[2009/08/08 10:38:02 | 00,038,400 | -HS- | M] () – C:\Windows\System32\pufajahe.dll
[2009/08/08 10:18:15 | 00,000,036 | —- | M] () – C:\Windows\System32\sysnet.dat
[2009/08/08 10:18:08 | 00,176,128 | —- | M] () – C:\Windows\svchast.exe
[2009/08/08 10:18:08 | 00,000,009 | —- | M] () – C:\Windows\System32\bennuar.old
[2009/08/07 19:41:55 | 00,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/07 19:27:52 | 00,000,904 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/08/07 19:13:58 | 01,343,651 | —- | M] () – C:\MGtools.exe
[2009/08/07 14:43:44 | 00,488,144 | —- | M] (Soeperman Enterprises Ltd ) – C:\Users\Parth\Desktop\HJTsetup.exe
[2009/08/07 14:37:42 | 00,050,688 | —- | M] (Atribune.org) – C:\Users\Parth\Desktop\ATF-Cleaner.exe
[2009/08/07 09:39:38 | 00,287,744 | —- | M] () – C:\Users\Parth\Desktop\remg.exe
[2009/08/05 15:43:44 | 00,000,038 | —- | M] () – C:\Windows\avisplitter.ini
[2009/08/04 21:30:28 | 00,056,440 | —- | M] () – C:\Windows\War3Unin.dat
[2009/08/03 13:36:28 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/08/03 13:36:06 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/07/30 15:45:38 | 00,470,528 | —- | M] () – C:\Users\Parth\Desktop\RootRepeal.exe
[2009/07/28 12:26:21 | 03,844,129 | —- | M] () – C:\Users\Parth\Desktop\clan eat.rar
[2009/07/21 17:52:28 | 00,915,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/07/21 17:52:13 | 01,208,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/07/21 17:50:46 | 00,206,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\occache.dll
[2009/07/21 17:48:31 | 05,937,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/07/21 17:48:27 | 00,594,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/07/21 17:48:27 | 00,055,296 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2009/07/21 17:47:47 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/07/21 17:47:41 | 01,469,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2009/07/21 17:47:28 | 00,164,352 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2009/07/21 17:47:28 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2009/07/21 17:47:27 | 01,985,536 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/07/21 17:47:27 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2009/07/21 17:47:26 | 11,067,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/07/21 17:47:26 | 00,184,320 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2009/07/21 17:47:26 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2009/07/21 17:47:21 | 00,386,048 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/07/21 16:13:58 | 00,133,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/07/21 16:13:51 | 00,173,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2009/07/21 16:13:15 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2009/07/21 16:12:49 | 01,638,912 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/07/21 14:31:43 | 00,057,667 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2009/07/16 10:13:28 | 00,277,864 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 14:41:15 | 00,002,633 | —- | M] () – C:\Users\Parth\Desktop\RapidShare Manager.lnk
< End of report >
Extra.txt :

OTL Extras logfile created on: 8/11/2009 10:11:53 AM - Run 1
OTL by OldTimer - Version 3.0.10.5 Folder = C:\Users\Parth\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 220.31 Gb Total Space | 69.58 Gb Free Space | 31.59% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.88 Gb Free Space | 58.80% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PARTH-PC
Current User Name: Parth
Logged in as Administrator.

Current Boot Mode: SafeMode
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.exe [@ = exefile] – C:\Windows\System32\desot.exe ()
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – File not found


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1996A714-62CE-49A8-807F-637F3E2858C5}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{246CA6E0-7223-4A1C-8594-920FD8B90619}" = lport=3724 | protocol=6 | dir=in | name=wow1 |
"{2B646809-10D3-4738-91B2-C2732D0DF32C}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{311D271E-6E03-4D09-9E7C-CA017DB704F1}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{3DE24231-D99E-43FF-97F3-14F49CBBC68F}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{4928856D-3673-4D0D-8EAC-30808E1B4AFC}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{4EB6CFE7-6F95-4CA7-9D3A-CE79BD976106}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{55AE2868-6304-433A-943C-583F1BFC0BC3}" = lport=6112 | protocol=6 | dir=in | name=wow2 |
"{6B2A76F8-97E8-4733-9F85-C770543C379D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{794E6826-A1F8-4A2B-9762-7D85DB0933FE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{9998E179-96A7-4D3B-84E5-369C8101243F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{DC873E6F-9740-4AEB-9849-476D2997AB37}" = lport=2869 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0174BA73-C659-4CB0-8EA6-ABB25B3FB353}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{0251B950-0D57-4212-8ECF-B790350C6E0E}" = protocol=6 | dir=in | app=c:\windows\system32\dlcdcoms.exe |
"{02710CEF-503C-4376-A7AE-6EEC5DDB22D2}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{04308690-9594-4229-9FAB-83ECECE0C067}" = protocol=17 | dir=in | app=c:\program files\v8200\dmmultiview\multiview.exe |
"{0475821F-2E1C-43FE-9331-7B71D57CE2B5}" = protocol=17 | dir=in | app=c:\windows\system32\wininit.exe |
"{070D2743-C20E-477C-BE42-4EC4C5C3EA88}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{0E944ABA-139C-4FCD-8DBB-32ACEC774A74}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{1239262A-DECF-4D86-84E0-02D6070FC99C}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{13CBBD69-BE5E-49F9-8418-E47FE64097B8}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{1529009B-9EDD-4ED6-A2FA-DD2D854F2501}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe |
"{198163A3-878C-42F8-9C58-CDECA5C7FE81}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{1C821CC3-3F4D-4561-9EDC-DA9FAFCADBF1}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe |
"{25A3AC47-8339-4F4D-B65E-706C5C390CD8}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{30CA2A84-95E8-4661-A0DE-6BEF00025FE0}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{352FD3BA-D3CF-436B-B299-41BB5A73C9A9}" = protocol=17 | dir=in | app=c:\windows\system32\wininit.exe |
"{372FD7C3-C1AF-491A-AC4F-03E354197D9B}" = protocol=17 | dir=in | app=c:\windows\system32\lsass.exe |
"{37E31F5A-915E-4DF2-9073-631EA0DBC4E0}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe |
"{40109EE7-88BC-4D83-BA63-EF4C5032BD04}" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\backgrounddownloader.exe |
"{48EAD19A-105D-48EA-AA96-720B6665FA43}" = protocol=17 | dir=in | app=c:\program files\bellsouth\mccibrowser.exe |
"{554D5F28-73C3-4E92-878B-419609B9873D}" = protocol=17 | dir=in | app=c:\program files\windows antivirus pro\windows antivirus pro.exe |
"{57D8B0BE-78FF-47BC-B109-73536DCAD8F2}" = protocol=6 | dir=in | app=c:\program files\ea games\battlefield 2\bf2.exe |
"{5D2315F3-309A-4735-A7E5-0778C4905DBD}" = protocol=6 | dir=in | app=c:\windows\system32\lsass.exe |
"{60AF08B6-88BF-4F83-8D71-95716600DD0E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{60B3937C-99FF-4D7C-96C6-02188729171C}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe |
"{66F2CA88-7DE8-4732-B2F6-B54DFB739C60}" = dir=in | app=c:\program files\dell\mediadirect\powercinema.exe |
"{70198901-026D-49FE-86F8-BC2ADE6FEC4D}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dmp\clbrowserengine.exe |
"{74AFC14A-B65E-4215-9826-13A6915103A7}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{8716A1F9-02CC-4EC8-9099-2F10BEA12988}" = protocol=6 | dir=in | app=c:\windows\system32\wininit.exe |
"{88D55D51-B619-4C80-A6D5-CF7F267428B4}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{9205FA42-DD42-4F44-8FD4-8320E1931B04}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dms\clmsservice.exe |
"{9775308E-03FD-43AF-A8A4-BBF9F36186EF}" = protocol=6 | dir=in | app=c:\windows\system32\lsass.exe |
"{9FE93B16-36DA-480E-870F-CFBAFF618FC6}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{A4394D1A-677A-423A-8B03-4C810A8FD562}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{A4A2F112-BEF5-46DA-B063-E60E4D2431DF}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{A4BD06F2-D99F-481A-92F0-017435CEFFA2}" = protocol=17 | dir=in | app=c:\windows\system32\lsass.exe |
"{A93537FA-79E9-4F6C-90D5-F2398B084970}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe |
"{AC74DD96-B3F1-493F-8F25-6657B9532E05}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe |
"{B01DAAB7-12A6-4171-9A4C-FE57982F29DF}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{B2A31E5A-8721-4329-A204-B069E32D0B3D}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{B2B7DAEE-F9AB-4477-B618-A5BA4E00A29C}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{B4D82011-96AE-4D27-B7EE-2FB5A64AA9C2}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{B6D847CA-1BF6-4171-99D6-370527F51AA0}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{B7CCD874-0B60-4785-B107-57D81A60788A}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{B97E2D95-AFC7-471A-9F15-B7D874947B3D}" = protocol=6 | dir=in | app=c:\windows\system32\wininit.exe |
"{C2AE5F90-5763-4C8C-9FB8-B8C66DEE97B9}" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"{C5FC70BB-4E68-4A7E-BC00-EB167E4DB8A2}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{C61BEEF0-F872-4CB6-B2E0-6601B19805E1}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{CC27DC2A-F5FB-4AA2-86BC-452D44F9CCD0}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{CCEAC5A7-F494-4477-A8BD-4D256ED100BF}" = protocol=17 | dir=in | app=c:\windows\system32\dlcdcoms.exe |
"{CE493BB7-44F6-4E8B-9D57-87342BC31CFE}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{D3C7AD0F-FFD0-44AD-9F9D-E073A38C6FFE}" = protocol=17 | dir=in | app=c:\program files\ea games\battlefield 2\bf2.exe |
"{D63161CD-9813-464F-B85C-06DDA33AB55E}" = protocol=6 | dir=in | app=c:\program files\windows antivirus pro\windows antivirus pro.exe |
"{D793678D-672C-4B5E-B3B6-E71D2353FE64}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{D7CA3649-DA11-45F6-B2E6-4122D2B22F45}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{D90C4401-3C92-4043-998D-4ADBD69FCB1A}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{DBC79688-C520-4E5E-88A8-5C1F3913F31D}" = dir=in | app=c:\program files\dell\mediadirect\pcmservice.exe |
"{E063103F-9614-4721-91E8-95BA362CC284}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"{E3996EC5-D44C-4402-929E-5D173B1CE46E}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{E445E565-F036-4108-8B0E-A703B800409B}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{E8D74301-4679-437A-AF75-79DBB2B419C9}" = protocol=6 | dir=in | app=c:\program files\bellsouth\mccibrowser.exe |
"{EC1E7A59-DDE5-45D6-AF3A-92CCC7E5853E}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{EF577000-C652-4045-A822-407E825B194D}" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\backgrounddownloader.exe |
"{F2DFD7CE-3376-4AFB-842A-6D841199E701}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F5BA7B86-79A3-41C6-82D2-1C642B1460CD}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{F905572E-8BE9-4DA1-92DA-6B7B25CB3C5E}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{F9F32DC3-8945-4888-81A6-A5CD1EBE975F}" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"{FB8C96F6-BB1A-42EE-9D95-F7AC01856791}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{FBFC1016-29AC-4DA6-B9C4-29A6B0E8D242}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{FC9F29EB-C019-4629-B00E-15297DC83889}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{FF3A05A3-8ECA-4DD5-AF83-7ED9AB6FE645}" = protocol=6 | dir=in | app=c:\program files\v8200\dmmultiview\multiview.exe |
"TCP Query User{0572CFCE-AB5A-4763-B809-28FFA4918A09}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{07874CE6-EFC9-4649-8FB1-8A94A2E1C7A0}C:\program files\trillian\trillian.exe" = protocol=6 | dir=in | app=c:\program files\trillian\trillian.exe |
"TCP Query User{265BD7B2-059A-409F-9AD3-75B5821B62DB}C:\program files\veoh networks\veoh\veohclient.exe" = protocol=6 | dir=in | app=c:\program files\veoh networks\veoh\veohclient.exe |
"TCP Query User{32BB32BF-AA7C-4E9F-BDB3-C3BF02F6B097}C:\users\parth\appdata\local\temp\blizzard launcher temporary - 872d6440\launcher.exe" = protocol=6 | dir=in | app=c:\users\parth\appdata\local\temp\blizzard launcher temporary - 872d6440\launcher.exe |
"TCP Query User{73DF1D6B-62C0-4D20-9629-FE8F74A189D5}C:\users\public\games\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"TCP Query User{7AAB4082-90ED-4467-8A56-FDBBBA71F548}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{CD743903-17D9-4707-84DF-72306DB67A15}C:\program files\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files\mirc\mirc.exe |
"TCP Query User{F51AC86E-9605-4E9D-B4DF-2D4238E919C0}C:\program files\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files\mirc\mirc.exe |
"UDP Query User{2EF24FC8-B4BD-4485-9267-296EA34F2589}C:\program files\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files\mirc\mirc.exe |
"UDP Query User{4D3642E2-EDC0-456C-8482-163E3FCB83E7}C:\program files\veoh networks\veoh\veohclient.exe" = protocol=17 | dir=in | app=c:\program files\veoh networks\veoh\veohclient.exe |
"UDP Query User{5F6074DA-610E-441B-92A0-19D6AA1EADC4}C:\users\parth\appdata\local\temp\blizzard launcher temporary - 872d6440\launcher.exe" = protocol=17 | dir=in | app=c:\users\parth\appdata\local\temp\blizzard launcher temporary - 872d6440\launcher.exe |
"UDP Query User{84A9E7F5-8256-4FCA-9A51-6F21D766F038}C:\users\public\games\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"UDP Query User{87FA17A8-D249-4BEF-87A3-136CDAE0A173}C:\program files\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files\mirc\mirc.exe |
"UDP Query User{8C4A395F-B63D-4AF8-9704-4D005C4C4DD6}C:\program files\trillian\trillian.exe" = protocol=17 | dir=in | app=c:\program files\trillian\trillian.exe |
"UDP Query User{C20E44A0-9C92-4B19-9AF7-DC832888D842}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{ED9715A8-6995-4283-A35A-401BB44B36DA}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{0405E51E-9582-4207-8F38-AC44201D3808}" = VeohTV BETA
"{0434E275-020A-4A2E-B35A-D5652E464E32}" = DMMultiView
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = QualxServ Service Agreement
"{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1D5E29AD-39A9-4D0A-A8B6-46A6FCD8C995}" = Live! Cam Avatar v1.0
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{2F29D6D2-824E-4FEF-8AED-7013F39F642A}" = OpenOffice.org 2.3
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{4D3C9F4B-4B7D-4E5D-99B9-0123AB0D51ED}" = Dell DataSafe Online
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{50D4CB89-AF34-4978-96DC-C3034062E901}" = Battlefield 2: Special Forces
"{53C6D09E-EAB6-49E5-BA4C-BA7FF13830FB}" = Sound Blaster Audigy ADVANCED MB
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}" = iTunes
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6AF7058C-0CF4-458F-84ED-A1D28461DB6F}" = DMMultiView
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD [removed]
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7E7658A2-CD3F-48A7-93EA-0882BCA4FD2A}" = LogMeIn
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{89CEAE14-DD0F-448E-9554-15781EC9DB24}" = Product Documentation Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A4D41F3-3EDA-4DAC-9403-839708EA0667}" = Install(US)2
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile Device Center
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{9778D3EB-319A-4E06-A64E-E67C14996950}" = Sound Blaster X-Fi Notebook
"{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}" = OutlookAddinSetup
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A13E07E1-A423-44FB-9DEE-B24C75C1BAF2}" = WIDCOMM Bluetooth Software 6.0.1.3100
"{A2289997-10A3-48F2-AA03-99180D761661}" = Fingerprint Reader Suite 5.6
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A59A1422-F883-48EE-8B1B-B140553B0E4D}" = DisableUAC
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{AB67580-257C-45FF-B8F4-C8C30682091A}_is1" = SIW version 1.73
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.6
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AFA20D47-69C3-4030-8DF8-D37466E70F13}" = Apple Mobile Device Support
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BB406CEB-6207-4512-9BB2-89950DC9D6B6}_is1" = ConvertXtoDVD 2.2.3.258h
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{C4972073-2BFE-475D-8441-564EA97DA161}" = QuickSet
"{C894366E-51C4-4162-BA82-ECBEFC1C2C61}" = PayPal Plug-In
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
"{D7769185-9A7C-48D4-8874-5388743A1DE2}" = Music, Photos & Videos Launcher
"{E65310A3-5EBD-4702-9812-341C094D87B3}" = DMMultiView
"{E7044E25-3038-4A76-9064-344AC038043E}" = Windows Mobile Device Center Driver Update
"{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F1A14CB2-A048-45A6-AFDA-3571296E1D76}" = Creative Media Toolbox 6
"{F5D7FAB5-A1FD-4DD3-983E-4155B09D7102}" = mCore
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Advanced Video FX Engine" = Advanced Video FX Engine
"ALchemy" = Creative ALchemy
"Codec_264" = GeoVision H264
"Codec_amp4" = GeoVision MPEG4 ASP
"Codec_AVC" = GeoVision MPEG4 AVC
"Codec_jpeg" = GeoVision JPEG
"Codec_mp2" = GeoVision MPEG2
"Creative OEM002" = Laptop Integrated Webcam Driver (1.04.01.1011)
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Dell Webcam Center" = Dell Webcam Center
"Dell Webcam Manager" = Dell Webcam Manager
"FBrowsingAdvisor_is1" = FBrowsingAdvisor
"GeoADPCM" = GeoVision ADPCM
"GEOXCodec" = GeoVision MPEG4
"GoToAssist" = GoToAssist 8.0.0.514
"HijackThis" = HijackThis 1.99.1
"Hijackthis_is1" = Hijackthis 1.99.1
"InstallShield_{0405E51E-9582-4207-8F38-AC44201D3808}" = VeohTV BETA
"InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"IrfanView" = IrfanView (remove only)
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.2.5 (Full)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Maxthon" = Maxthon Browser (remove only)
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"mIRC" = mIRC
"Mozilla Firefox (3.0.13)" = Mozilla Firefox (3.0.13)
"NVIDIA Drivers" = NVIDIA Drivers
"ProInst" = Intel® PROSet/Wireless Software
"RealPlayer 6.0" = RealPlayer
"RocketDock_is1" = RocketDock 1.3.5
"SmartEnhancer" = SmartEnhancer
"Starcraft" = Starcraft
"StealthBot v2.6 Revision 3" = StealthBot v2.6 Revision 3 (remove only)
"StreamPlug" = StreamPlug Player
"SysInfo" = Creative System Information
"Trillian" = Trillian
"Uninstaller_B4736000_Creative Media Toolbox 6" = Creative Media Toolbox 6 (Shared Components)
"Veoh Web Player Beta" = Veoh Web Player Beta
"ViewpointMediaPlayer" = Viewpoint Media Player
"Warcraft III" = Warcraft III
"Win Antivirus Pro" = Windows Antivirus Pro
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"WinPcapInst" = WinPcap 4.0.2
"WinRAR archiver" = WinRAR archiver
"World of Warcraft" = World of Warcraft
"XnView_is1" = XnView 1.95.4
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3256818742-1514715972-2829636577-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"5f48e2ab41c5d005" = RapidShare Manager
"BitTorrent DNA" = DNA
"Smilebox" = Smilebox
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/8/2009 5:48:56 PM | Computer Name = Parth-PC | Source = Winlogon | ID = 4102
Description = Windows license is invalid. Error 0xC004F027. Policy Value 0x00000000.

Error - 8/8/2009 5:51:08 PM | Computer Name = Parth-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x00000000.

Error - 8/8/2009 5:51:15 PM | Computer Name = Parth-PC | Source = Application Error | ID = 1000
Description = Faulting application winlogon.exe, version 6.0.6001.18000, time stamp
0x47918db3, faulting module kernel32.dll, version 6.0.6001.18215, time stamp 0x49953395,
exception code 0xc06d007e, fault offset 0x000442eb, process id 0xfd8, application
start time 0x01ca187258641148.

Error - 8/8/2009 6:06:03 PM | Computer Name = Parth-PC | Source = EventSystem | ID = 4609
Description =

Error - 8/8/2009 6:38:33 PM | Computer Name = Parth-PC | Source = Application Error | ID = 1000
Description = Faulting application ntvdm.exe, version 6.0.6001.18000, time stamp
0x47918baf, faulting module kernel32.dll, version 6.0.6001.18215, time stamp 0x49953395,
exception code 0xc0000005, fault offset 0x000442eb, process id 0x6bc, application
start time 0x01ca1878f3b17495.

Error - 8/8/2009 6:38:33 PM | Computer Name = Parth-PC | Source = Application Error | ID = 1000
Description = Faulting application ntvdm.exe, version 6.0.6001.18000, time stamp
0x47918baf, faulting module kernel32.dll, version 6.0.6001.18215, time stamp 0x49953395,
exception code 0xc0000005, fault offset 0x000442eb, process id 0xdd8, application
start time 0x01ca1878f3bafa15.

Error - 8/8/2009 6:38:34 PM | Computer Name = Parth-PC | Source = Application Error | ID = 1000
Description = Faulting application ntvdm.exe, version 6.0.6001.18000, time stamp
0x47918baf, faulting module kernel32.dll, version 6.0.6001.18215, time stamp 0x49953395,
exception code 0xc0000005, fault offset 0x000442eb, process id 0xfec, application
start time 0x01ca1878f3d2c7d5.

Error - 8/8/2009 6:38:36 PM | Computer Name = Parth-PC | Source = Application Error | ID = 1000
Description = Faulting application ntvdm.exe, version 6.0.6001.18000, time stamp
0x47918baf, faulting module kernel32.dll, version 6.0.6001.18215, time stamp 0x49953395,
exception code 0xc0000005, fault offset 0x000442eb, process id 0x87c, application
start time 0x01ca1878f3acb1d5.

Error - 8/8/2009 6:38:38 PM | Computer Name = Parth-PC | Source = Application Error | ID = 1000
Description = Faulting application ntvdm.exe, version 6.0.6001.18000, time stamp
0x47918baf, faulting module kernel32.dll, version 6.0.6001.18215, time stamp 0x49953395,
exception code 0xc0000005, fault offset 0x000442eb, process id 0xa80, application
start time 0x01ca1878f3f8ddd5.

Error - 8/8/2009 6:38:38 PM | Computer Name = Parth-PC | Source = Application Error | ID = 1000
Description = Faulting application ntvdm.exe, version 6.0.6001.18000, time stamp
0x47918baf, faulting module kernel32.dll, version 6.0.6001.18215, time stamp 0x49953395,
exception code 0xc0000005, fault offset 0x000442eb, process id 0x230, application
start time 0x01ca1878f3e11015.

[ System Events ]
Error - 8/11/2009 10:10:45 AM | Computer Name = Parth-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 8/11/2009 10:10:45 AM | Computer Name = Parth-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 8/11/2009 10:10:45 AM | Computer Name = Parth-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 8/11/2009 10:10:45 AM | Computer Name = Parth-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 8/11/2009 10:10:45 AM | Computer Name = Parth-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 8/11/2009 10:10:45 AM | Computer Name = Parth-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 8/11/2009 10:10:45 AM | Computer Name = Parth-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 8/11/2009 10:10:45 AM | Computer Name = Parth-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 8/11/2009 10:10:45 AM | Computer Name = Parth-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 8/11/2009 10:10:55 AM | Computer Name = Parth-PC | Source = Service Control Manager | ID = 7001
Description =


< End of report >
Sysprot.log : SysProt AntiRootkit v1.0.1.0 by swatkat ******************************************************************************** ********** ******************************************************************************** ********** Process: Name: [System Idle Process] PID: 0 Hidden: No Window Visible: No Name: System PID: 4 Hidden: No Window Visible: No Name: C:\Windows\System32\smss.exe PID: 444 Hidden: No Window Visible: No Name: C:\Windows\System32\csrss.exe PID: 512 Hidden: No Window Visible: No Name: C:\Windows\System32\wininit.exe PID: 564 Hidden: No Window Visible: No Name: C:\Windows\System32\csrss.exe PID: 580 Hidden: No Window Visible: No Name: C:\Windows\System32\services.exe PID: 616 Hidden: No Window Visible: No Name: C:\Windows\System32\lsass.exe PID: 636 Hidden: No Window Visible: No Name: C:\Windows\System32\lsm.exe PID: 648 Hidden: No Window Visible: No Name: C:\Windows\System32\svchost.exe PID: 820 Hidden: No Window Visible: No Name: C:\Windows\System32\nvvsvc.exe PID: 880 Hidden: No Window Visible: No Name: C:\Windows\System32\winlogon.exe PID: 908 Hidden: No Window Visible: No Name: C:\Windows\System32\svchost.exe PID: 944 Hidden: No Window Visible: No Name: C:\Windows\System32\svchost.exe PID: 1080 Hidden: No Window Visible: No Name: C:\Windows\System32\svchost.exe PID: 1112 Hidden: No Window Visible: No Name: C:\Windows\System32\svchost.exe PID: 1200 Hidden: No Window Visible: No Name: C:\Windows\System32\audiodg.exe PID: 1268 Hidden: No Window Visible: No Name: C:\Program Files\Creative\Shared Files\CTAudSvc.exe PID: 1352 Hidden: No Window Visible: No Name: C:\Windows\System32\svchost.exe PID: 1376 Hidden: No Window Visible: No Name: C:\Windows\System32\SLsvc.exe PID: 1428 Hidden: No Window Visible: No Name: C:\Windows\System32\svchost.exe PID: 1464 Hidden: No Window Visible: No Name: C:\Windows\System32\rundll32.exe PID: 1492 Hidden: No Window Visible: No Name: C:\Windows\System32\svchost.exe PID: 1636 Hidden: No Window Visible: No Name: C:\Windows\System32\wlanext.exe PID: 1820 Hidden: No Window Visible: No Name: C:\Windows\System32\spoolsv.exe PID: 1888 Hidden: No Window Visible: No Name: C:\Windows\System32\svchost.exe PID: 1960 Hidden: No Window Visible: No Name: C:\Windows\System32\AEstSrv.exe PID: 584 Hidden: No Window Visible: No Name: C:\Windows\svchast.exe PID: 1100 Hidden: No Window Visible: No Name: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe PID: 1248 Hidden: No Window Visible: No Name: C:\Program Files\Bonjour\mDNSResponder.exe PID: 1552 Hidden: No Window Visible: No Name: C:\Windows\System32\svchost.exe PID: 1684 Hidden: No Window Visible: No Name: C:\Windows\System32\taskeng.exe PID: 1784 Hidden: No Window Visible: No Name: C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe PID: 1540 Hidden: No Window Visible: No Name: C:\Windows\System32\dlcdcoms.exe PID: 292 Hidden: No Window Visible: No Name: C:\Program Files\Intel\Wireless\Bin\EvtEng.exe PID: 844 Hidden: No Window Visible: No Name: C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe PID: 2120 Hidden: No Window Visible: No Name: C:\Windows\System32\PnkBstrA.exe PID: 2268 Hidden: No Window Visible: No Name: C:\Windows\System32\svchost.exe PID: 2344 Hidden: No Window Visible: No Name: C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe PID: 2376 Hidden: No Window Visible: No Name: C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe PID: 2420 Hidden: No Window Visible: No Name: C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\stacsv.exe PID: 2496 Hidden: No Window Visible: No Name: C:\Windows\System32\svchost.exe PID: 2612 Hidden: No Window Visible: No Name: C:\Program Files\Viewpoint\Common\ViewpointService.exe PID: 2648 Hidden: No Window Visible: No Name: C:\Windows\System32\svchost.exe PID: 2748 Hidden: No Window Visible: No Name: C:\Windows\System32\SearchIndexer.exe PID: 2784 Hidden: No Window Visible: No Name: C:\Windows\System32\alg.exe PID: 3040 Hidden: No Window Visible: No Name: C:\Windows\System32\taskeng.exe PID: 3540 Hidden: No Window Visible: No Name: C:\Windows\System32\dwm.exe PID: 3584 Hidden: No Window Visible: No Name: C:\Windows\explorer.exe PID: 3656 Hidden: No Window Visible: No Name: C:\Windows\System32\wbem\unsecapp.exe PID: 3288 Hidden: No Window Visible: No Name: C:\Windows\System32\wbem\WmiPrvSE.exe PID: 1288 Hidden: No Window Visible: No Name: C:\Windows\System32\svchost.exe PID: 3900 Hidden: No Window Visible: No Name: C:\Program Files\Mozilla Firefox\firefox.exe PID: 4644 Hidden: No Window Visible: No Name: C:\IDM.5.14.Build.3.Fixed-REA\IDMan.exe PID: 5196 Hidden: No Window Visible: No Name: C:\Users\Parth\Desktop\SysProt\SysProt.exe PID: 4220 Hidden: No Window Visible: Yes ******************************************************************************** ********** ******************************************************************************** ********** Kernel Modules: Module Name: \systemroot\system32\drivers\SKYNETydyeqewv.sys Service Name: SKYNETsibytlbi Module Base: — Module End: — Hidden: Yes Module Name: \??\C:\Users\Parth\Desktop\SysProt\SysProtDrv.sys Service Name: SysProtDrv.sys Module Base: CF722000 Module End: CF72D000 Hidden: No Module Name: C:\Windows\system32\ntkrnlpa.exe Service Name: — Module Base: E1E0B000 Module End: E21C4000 Hidden: No Module Name: C:\Windows\system32\hal.dll Service Name: — Module Base: E21C4000 Module End: E21F7000 Hidden: No Module Name: C:\Windows\system32\kdcom.dll Service Name: — Module Base: B6403000 Module End: B640B000 Hidden: No Module Name: C:\Windows\system32\mcupdate_GenuineIntel.dll Service Name: — Module Base: B640B000 Module End: B646B000 Hidden: No Module Name: C:\Windows\system32\PSHED.dll Service Name: — Module Base: B646B000 Module End: B647C000 Hidden: No Module Name: C:\Windows\system32\BOOTVID.dll Service Name: — Module Base: B647C000 Module End: B6484000 Hidden: No Module Name: C:\Windows\system32\CLFS.SYS Service Name: CLFS Module Base: B6484000 Module End: B64C5000 Hidden: No Module Name: C:\Windows\system32\CI.dll Service Name: — Module Base: B64C5000 Module End: B65A5000 Hidden: No Module Name: C:\Windows\system32\drivers\Wdf01000.sys Service Name: Wdf01000 Module Base: B660C000 Module End: B6688000 Hidden: No Module Name: C:\Windows\system32\drivers\WDFLDR.SYS Service Name: — Module Base: B6688000 Module End: B6695000 Hidden: No Module Name: \SystemRoot\System32\Drivers\spla.sys Service Name: — Module Base: B6695000 Module End: B6792000 Hidden: Yes Module Name: C:\Windows\System32\Drivers\WMILIB.SYS Service Name: — Module Base: B6792000 Module End: B679B000 Hidden: No Module Name: C:\Windows\System32\Drivers\SCSIPORT.SYS Service Name: — Module Base: B679B000 Module End: B67C1000 Hidden: No Module Name: C:\Windows\system32\drivers\acpi.sys Service Name: ACPI Module Base: B65A5000 Module End: B65EB000 Hidden: No Module Name: C:\Windows\system32\drivers\msisadrv.sys Service Name: msisadrv Module Base: B67C1000 Module End: B67C9000 Hidden: No Module Name: C:\Windows\system32\drivers\pci.sys Service Name: pci Module Base: B67C9000 Module End: B67F0000 Hidden: No Module Name: C:\Windows\System32\drivers\partmgr.sys Service Name: partmgr Module Base: B67F0000 Module End: B67FF000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\compbatt.sys Service Name: Compbatt Module Base: B6600000 Module End: B6603000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\BATTC.SYS Service Name: BattC Module Base: B65EB000 Module End: B65F5000 Hidden: No Module Name: C:\Windows\system32\drivers\volmgr.sys Service Name: volmgr Module Base: B680C000 Module End: B681B000 Hidden: No Module Name: C:\Windows\System32\drivers\volmgrx.sys Service Name: volmgrx Module Base: B681B000 Module End: B6865000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\intelide.sys Service Name: intelide Module Base: B6865000 Module End: B686C000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\PCIIDEX.SYS Service Name: — Module Base: B686C000 Module End: B687A000 Hidden: No Module Name: C:\Windows\system32\drivers\pciide.sys Service Name: pciide Module Base: B687A000 Module End: B6881000 Hidden: No Module Name: C:\Windows\System32\drivers\mountmgr.sys Service Name: MountMgr Module Base: B6881000 Module End: B6891000 Hidden: No Module Name: C:\Windows\system32\drivers\iastorv.sys Service Name: iaStorV Module Base: B6891000 Module End: B6931000 Hidden: No Module Name: C:\Windows\system32\drivers\iastor.sys Service Name: iaStor Module Base: B6931000 Module End: B69F8000 Hidden: No Module Name: C:\Windows\system32\drivers\atapi.sys Service Name: atapi Module Base: B69F8000 Module End: B6A00000 Hidden: No Module Name: C:\Windows\system32\drivers\ataport.SYS Service Name: — Module Base: B6A0F000 Module End: B6A2D000 Hidden: No Module Name: C:\Windows\system32\drivers\fltmgr.sys Service Name: FltMgr Module Base: B6A2D000 Module End: B6A5F000 Hidden: No Module Name: C:\Windows\system32\drivers\fileinfo.sys Service Name: FileInfo Module Base: B6A5F000 Module End: B6A6F000 Hidden: No Module Name: C:\Windows\System32\Drivers\PxHelp20.sys Service Name: PxHelp20 Module Base: B6A6F000 Module End: B6A78000 Hidden: No Module Name: C:\Windows\System32\Drivers\ksecdd.sys Service Name: KSecDD Module Base: B6A78000 Module End: B6AE9000 Hidden: No Module Name: C:\Windows\system32\drivers\ndis.sys Service Name: NDIS Module Base: B6AE9000 Module End: B6BF4000 Hidden: No Module Name: C:\Windows\system32\drivers\msrpc.sys Service Name: MsRPC Module Base: B6C02000 Module End: B6C2D000 Hidden: No Module Name: C:\Windows\system32\drivers\NETIO.SYS Service Name: — Module Base: B6C2D000 Module End: B6C67000 Hidden: No Module Name: C:\Windows\System32\drivers\tcpip.sys Service Name: Tcpip Module Base: B6C67000 Module End: B6D4E000 Hidden: No Module Name: C:\Windows\System32\drivers\fwpkclnt.sys Service Name: — Module Base: B6D4E000 Module End: B6D69000 Hidden: No Module Name: C:\Windows\System32\Drivers\Ntfs.sys Service Name: Ntfs Module Base: B6E0F000 Module End: B6F1E000 Hidden: No Module Name: C:\Windows\system32\drivers\volsnap.sys Service Name: volsnap Module Base: B6F1E000 Module End: B6F57000 Hidden: No Module Name: C:\Windows\System32\Drivers\spldr.sys Service Name: spldr Module Base: B6F57000 Module End: B6F5F000 Hidden: No Module Name: C:\Windows\System32\Drivers\mup.sys Service Name: Mup Module Base: B6F5F000 Module End: B6F6E000 Hidden: No Module Name: C:\Windows\System32\drivers\ecache.sys Service Name: Ecache Module Base: B6F6E000 Module End: B6F95000 Hidden: No Module Name: C:\Windows\system32\drivers\disk.sys Service Name: disk Module Base: B6F95000 Module End: B6FA6000 Hidden: No Module Name: C:\Windows\system32\drivers\CLASSPNP.SYS Service Name: — Module Base: B6FA6000 Module End: B6FC7000 Hidden: No Module Name: C:\Windows\system32\drivers\crcdisk.sys Service Name: crcdisk Module Base: B6FC7000 Module End: B6FD0000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\tunnel.sys Service Name: tunnel Module Base: BA0D6000 Module End: BA0E1000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\tunmp.sys Service Name: tunmp Module Base: BA0E1000 Module End: BA0EA000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\intelppm.sys Service Name: intelppm Module Base: BA0EA000 Module End: BA0F9000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\nvlddmkm.sys Service Name: nvlddmkm Module Base: BA608000 Module End: BAD44000 Hidden: No Module Name: C:\Windows\System32\drivers\dxgkrnl.sys Service Name: DXGKrnl Module Base: BAD44000 Module End: BADE3000 Hidden: No Module Name: C:\Windows\System32\drivers\watchdog.sys Service Name: — Module Base: BADE3000 Module End: BADF0000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\usbuhci.sys Service Name: usbuhci Module Base: BADF0000 Module End: BADFB000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\USBPORT.SYS Service Name: — Module Base: BA0F9000 Module End: BA137000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\usbehci.sys Service Name: usbehci Module Base: BA137000 Module End: BA146000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\HDAudBus.sys Service Name: HDAudBus Module Base: BA146000 Module End: BA158000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\yk60x86.sys Service Name: yukonwlh Module Base: BA158000 Module End: BA1A4000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\NETw4v32.sys Service Name: NETw4v32 Module Base: BAE0D000 Module End: BB03C000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\ohci1394.sys Service Name: ohci1394 Module Base: BB03C000 Module End: BB04C000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\1394BUS.SYS Service Name: — Module Base: BB04C000 Module End: BB05A000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\sdbus.sys Service Name: sdbus Module Base: BB05A000 Module End: BB074000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\rimmptsk.sys Service Name: rimmptsk Module Base: BB074000 Module End: BB083000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\rimsptsk.sys Service Name: rimsptsk Module Base: BB083000 Module End: BB097000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\rixdptsk.sys Service Name: rismxdp Module Base: BB097000 Module End: BB0E8000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\i8042prt.sys Service Name: i8042prt Module Base: BB0E8000 Module End: BB0FB000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\Apfiltr.sys Service Name: ApfiltrService Module Base: BB0FB000 Module End: BB127000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\mouclass.sys Service Name: mouclass Module Base: BB127000 Module End: BB132000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\kbdclass.sys Service Name: kbdclass Module Base: BB132000 Module End: BB13D000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\cdrom.sys Service Name: cdrom Module Base: BB13D000 Module End: BB155000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\GEARAspiWDM.sys Service Name: GEARAspiWDM Module Base: BB155000 Module End: BB15F000 Hidden: No Module Name: \SystemRoot\System32\Drivers\abrouwxy.SYS Service Name: — Module Base: BB15F000 Module End: BB1C4000 Hidden: Yes Module Name: C:\Windows\system32\DRIVERS\CmBatt.sys Service Name: CmBatt Module Base: BB1C4000 Module End: BB1C8000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\wmiacpi.sys Service Name: WmiAcpi Module Base: BB1C8000 Module End: BB1D1000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\msiscsi.sys Service Name: iScsiPrt Module Base: BA1A4000 Module End: BA1D2000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\storport.sys Service Name: — Module Base: B6D69000 Module End: B6DAA000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\TDI.SYS Service Name: — Module Base: BB1E0000 Module End: BB1EB000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\rasl2tp.sys Service Name: Rasl2tp Module Base: BA1D2000 Module End: BA1E9000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\ndistapi.sys Service Name: NdisTapi Module Base: BB1EB000 Module End: BB1F6000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\ndiswan.sys Service Name: NdisWan Module Base: B6FDD000 Module End: B7000000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\raspppoe.sys Service Name: RasPppoe Module Base: BA1E9000 Module End: BA1F8000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\raspptp.sys Service Name: PptpMiniport Module Base: B6DAA000 Module End: B6DBE000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\rassstp.sys Service Name: RasSstp Module Base: B6DBE000 Module End: B6DD3000 Hidden: No Module Name: C:\Windows\System32\Drivers\pcouffin.sys Service Name: pcouffin Module Base: BAE00000 Module End: BAE0C000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\termdd.sys Service Name: TermDD Module Base: B6DD3000 Module End: B6DE3000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\swenum.sys Service Name: swenum Module Base: BB1F6000 Module End: BB1F8000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\ks.sys Service Name: — Module Base: BB40D000 Module End: BB437000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\mssmbios.sys Service Name: mssmbios Module Base: BB437000 Module End: BB441000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\umbus.sys Service Name: umbus Module Base: BB441000 Module End: BB44E000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\usbhub.sys Service Name: usbhub Module Base: BB44E000 Module End: BB482000 Hidden: No Module Name: C:\Windows\system32\drivers\stwrt.sys Service Name: STHDA Module Base: BB482000 Module End: BB4D7000 Hidden: No Module Name: C:\Windows\system32\drivers\portcls.sys Service Name: — Module Base: BB4D7000 Module End: BB504000 Hidden: No Module Name: C:\Windows\system32\drivers\drmk.sys Service Name: — Module Base: BB504000 Module End: BB529000 Hidden: No Module Name: C:\Windows\System32\Drivers\NDProxy.SYS Service Name: NDProxy Module Base: BB529000 Module End: BB53A000 Hidden: No Module Name: C:\Windows\System32\Drivers\tcusb.sys Service Name: TcUsb Module Base: BB53A000 Module End: BB545000 Hidden: No Module Name: C:\Windows\System32\Drivers\USBD.SYS Service Name: — Module Base: BB545000 Module End: BB547000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\usbccgp.sys Service Name: usbccgp Module Base: BB547000 Module End: BB55E000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\hidusb.sys Service Name: HidUsb Module Base: BB55E000 Module End: BB567000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\HIDCLASS.SYS Service Name: — Module Base: BB567000 Module End: BB577000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\HIDPARSE.SYS Service Name: — Module Base: BB577000 Module End: BB57E000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\OEM02Dev.sys Service Name: OEM02Dev Module Base: BB57E000 Module End: BB5B8000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\OEM02Vfx.sys Service Name: OEM02Vfx Module Base: BB5B8000 Module End: BB5BA000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\mouhid.sys Service Name: mouhid Module Base: BB5BA000 Module End: BB5C2000 Hidden: No Module Name: C:\Windows\System32\Drivers\Fs_Rec.SYS Service Name: Fs_Rec Module Base: BB5C2000 Module End: BB5CB000 Hidden: No Module Name: C:\Windows\System32\Drivers\Null.SYS Service Name: Null Module Base: BB5CB000 Module End: BB5D2000 Hidden: No Module Name: C:\Windows\System32\Drivers\Beep.SYS Service Name: Beep Module Base: BB5D2000 Module End: BB5D9000 Hidden: No Module Name: C:\Windows\System32\drivers\vga.sys Service Name: vga Module Base: BB5E2000 Module End: BB5EE000 Hidden: No Module Name: C:\Windows\System32\drivers\VIDEOPRT.SYS Service Name: — Module Base: BCA04000 Module End: BCA25000 Hidden: No Module Name: C:\Windows\System32\DRIVERS\RDPCDD.sys Service Name: RDPCDD Module Base: BCA25000 Module End: BCA2D000 Hidden: No Module Name: C:\Windows\system32\drivers\rdpencdd.sys Service Name: RDPENCDD Module Base: BCA2D000 Module End: BCA35000 Hidden: No Module Name: C:\Windows\System32\Drivers\Msfs.SYS Service Name: Msfs Module Base: BCA35000 Module End: BCA40000 Hidden: No Module Name: C:\Windows\System32\Drivers\Npfs.SYS Service Name: Npfs Module Base: BCA40000 Module End: BCA4E000 Hidden: No Module Name: C:\Windows\System32\Drivers\BTHUSB.sys Service Name: BTHUSB Module Base: BCA73000 Module End: BCA7F000 Hidden: No Module Name: C:\Windows\System32\Drivers\bthport.sys Service Name: BTHPORT Module Base: BCA7F000 Module End: BCAB9000 Hidden: No Module Name: C:\Windows\System32\DRIVERS\rasacd.sys Service Name: RasAcd Module Base: BCAB9000 Module End: BCAC2000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\tdx.sys Service Name: tdx Module Base: BCAC2000 Module End: BCAD8000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\smb.sys Service Name: Smb Module Base: BCAD8000 Module End: BCAEC000 Hidden: No Module Name: C:\Windows\system32\drivers\afd.sys Service Name: AFD Module Base: BCAEC000 Module End: BCB34000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\rfcomm.sys Service Name: RFCOMM Module Base: BCB34000 Module End: BCB45000 Hidden: No Module Name: C:\Windows\System32\DRIVERS\netbt.sys Service Name: netbt Module Base: BCB45000 Module End: BCB77000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\BthEnum.sys Service Name: BthEnum Module Base: BCB77000 Module End: BCB81000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\pacer.sys Service Name: PSched Module Base: BCB81000 Module End: BCB97000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\bthpan.sys Service Name: BthPan Module Base: BCB97000 Module End: BCBB1000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\netbios.sys Service Name: NetBIOS Module Base: BCBB1000 Module End: BCBBF000 Hidden: No Module Name: C:\Windows\system32\drivers\btwavdt.sys Service Name: btwavdt Module Base: BCC01000 Module End: BCC67000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\wanarp.sys Service Name: Wanarp Module Base: BCC67000 Module End: BCC7A000 Hidden: No Module Name: C:\Windows\system32\drivers\btwaudio.sys Service Name: btwaudio Module Base: BCC7A000 Module End: BCCF5000 Hidden: No Module Name: \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys Service Name: SASKUTIL Module Base: BCCF5000 Module End: BCD1A000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\btwrchid.sys Service Name: btwrchid Module Base: BCD1A000 Module End: BCD1D000 Hidden: No Module Name: \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS Service Name: SASDIFSV Module Base: BCD1D000 Module End: BCD23000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\rdbss.sys Service Name: rdbss Module Base: BCD23000 Module End: BCD5F000 Hidden: No Module Name: C:\Windows\system32\drivers\nsiproxy.sys Service Name: nsiproxy Module Base: BCD5F000 Module End: BCD69000 Hidden: No Module Name: C:\Windows\System32\Drivers\dfsc.sys Service Name: DfsC Module Base: BCD69000 Module End: BCD80000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\kbdhid.sys Service Name: kbdhid Module Base: BCD80000 Module End: BCD89000 Hidden: No Module Name: C:\Windows\System32\Drivers\crashdmp.sys Service Name: — Module Base: BCD89000 Module End: BCD96000 Hidden: No Module Name: \SystemRoot\System32\Drivers\dump_iaStor.sys Service Name: — Module Base: BA000000 Module End: BA0C7000 Hidden: Yes Module Name: C:\Windows\System32\drivers\Dxapi.sys Service Name: — Module Base: BCD96000 Module End: BCDA0000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\monitor.sys Service Name: monitor Module Base: BCDA0000 Module End: BCDAF000 Hidden: No Module Name: \systemroot\win32k.sys:1 Service Name: — Module Base: BCDAF000 Module End: BCDB4000 Hidden: Yes Module Name: \systemroot\win32k.sys:2 Service Name: — Module Base: BCDB4000 Module End: BCDC3000 Hidden: Yes Module Name: C:\Windows\system32\drivers\luafv.sys Service Name: luafv Module Base: BCDC3000 Module End: BCDDE000 Hidden: No Module Name: C:\Windows\system32\drivers\spsys.sys Service Name: — Module Base: CD204000 Module End: CD2B3000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\lltdio.sys Service Name: lltdio Module Base: CD2B3000 Module End: CD2C3000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\nwifi.sys Service Name: NativeWifiP Module Base: CD2C3000 Module End: CD2ED000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\ndisuio.sys Service Name: Ndisuio Module Base: CD2ED000 Module End: CD2F7000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\rspndr.sys Service Name: rspndr Module Base: CD2F7000 Module End: CD30A000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\cdfs.sys Service Name: cdfs Module Base: CD30A000 Module End: CD320000 Hidden: No Module Name: C:\Windows\system32\drivers\HTTP.sys Service Name: HTTP Module Base: CD320000 Module End: CD38B000 Hidden: No Module Name: C:\Windows\System32\DRIVERS\srvnet.sys Service Name: srvnet Module Base: CD38B000 Module End: CD3A8000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\bowser.sys Service Name: bowser Module Base: CD3A8000 Module End: CD3C1000 Hidden: No Module Name: C:\Windows\System32\drivers\mpsdrv.sys Service Name: mpsdrv Module Base: CD3C1000 Module End: CD3D6000 Hidden: No Module Name: C:\Windows\system32\drivers\mrxdav.sys Service Name: MRxDAV Module Base: CD3D6000 Module End: CD3F6000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\mrxsmb.sys Service Name: mrxsmb Module Base: BCBBF000 Module End: BCBDE000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\mrxsmb10.sys Service Name: mrxsmb10 Module Base: CE800000 Module End: CE839000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\mrxsmb20.sys Service Name: mrxsmb20 Module Base: CE839000 Module End: CE851000 Hidden: No Module Name: C:\Windows\System32\DRIVERS\srv2.sys Service Name: srv2 Module Base: CE851000 Module End: CE878000 Hidden: No Module Name: C:\Windows\System32\DRIVERS\srv.sys Service Name: srv Module Base: CE878000 Module End: CE8C4000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\atksgt.sys Service Name: atksgt Module Base: CE8DC000 Module End: CE91F000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\dsunidrv.sys Service Name: dsunidrv Module Base: CE91F000 Module End: CE921000 Hidden: No Module Name: C:\Windows\System32\Drivers\fastfat.SYS Service Name: fastfat Module Base: CE921000 Module End: CE949000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\lirsgt.sys Service Name: lirsgt Module Base: CE949000 Module End: CE94E000 Hidden: No Module Name: \??\C:\Windows\system32\drivers\LMIRfsDriver.sys Service Name: LMIRfsDriver Module Base: CE94E000 Module End: CE958000 Hidden: No Module Name: C:\Windows\system32\drivers\peauth.sys Service Name: PEAUTH Module Base: CF608000 Module End: CF6E6000 Hidden: No Module Name: C:\Windows\System32\Drivers\secdrv.SYS Service Name: secdrv Module Base: CF6E6000 Module End: CF6F0000 Hidden: No Module Name: C:\Windows\System32\drivers\tcpipreg.sys Service Name: tcpipreg Module Base: CF6F0000 Module End: CF6FC000 Hidden: No Module Name: C:\Windows\system32\DRIVERS\ipnat.sys Service Name: IPNAT Module Base: CF6FC000 Module End: CF722000 Hidden: No ******************************************************************************** ********** ******************************************************************************** ********** No SSDT Hooks found ******************************************************************************** ********** ******************************************************************************** ********** Kernel Hooks: Hooked Function: ZwFlushInstructionCache At Address: E1FBD30B Jump To: B57ED3E4 Module Name: _unknown_ Hooked Function: ZwEnumerateKey At Address: E2012BA2 Jump To: B585C81C Module Name: _unknown_ Hooked Function: IofCompleteRequest At Address: E1E44FE2 Jump To: B5E796F3 Module Name: _unknown_ Hooked Function: IofCallDriver At Address: E1EC6F6F Jump To: B57FC33A Module Name: _unknown_ ******************************************************************************** ********** ******************************************************************************** ********** IRP Hooks: Hooked Module: C:\Windows\system32\drivers\iastorv.sys Hooked IRP: IRP_MJ_CREATE Jump To: B132C1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\iastorv.sys Hooked IRP: IRP_MJ_CLOSE Jump To: B132C1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\iastorv.sys Hooked IRP: IRP_MJ_DEVICE_CONTROL Jump To: B132C1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\iastorv.sys Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL Jump To: B132C1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\iastorv.sys Hooked IRP: IRP_MJ_POWER Jump To: B132C1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\iastorv.sys Hooked IRP: IRP_MJ_SYSTEM_CONTROL Jump To: B132C1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\atapi.sys Hooked IRP: IRP_MJ_CREATE Jump To: B132E1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\atapi.sys Hooked IRP: IRP_MJ_CLOSE Jump To: B132E1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\atapi.sys Hooked IRP: IRP_MJ_DEVICE_CONTROL Jump To: B132E1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\atapi.sys Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL Jump To: B132E1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\atapi.sys Hooked IRP: IRP_MJ_POWER Jump To: B132E1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\atapi.sys Hooked IRP: IRP_MJ_SYSTEM_CONTROL Jump To: B132E1F8 Hooking Module: _unknown_ Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_CREATE Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_CREATE_NAMED_PIPE Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_CLOSE Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_READ Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_WRITE Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_QUERY_INFORMATION Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_SET_INFORMATION Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_QUERY_EA Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_SET_EA Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_FLUSH_BUFFERS Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_QUERY_VOLUME_INFORMATION Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_SET_VOLUME_INFORMATION Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_DIRECTORY_CONTROL Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_FILE_SYSTEM_CONTROL Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_DEVICE_CONTROL Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_SHUTDOWN Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_LOCK_CONTROL Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_CLEANUP Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_CREATE_MAILSLOT Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_QUERY_SECURITY Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_SET_SECURITY Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_POWER Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_SYSTEM_CONTROL Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_DEVICE_CHANGE Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_QUERY_QUOTA Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\sptd Hooked IRP: IRP_MJ_SET_QUOTA Jump To: B6696000 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: C:\Windows\system32\DRIVERS\usbuhci.sys Hooked IRP: IRP_MJ_CREATE Jump To: B296C1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\usbuhci.sys Hooked IRP: IRP_MJ_CLOSE Jump To: B296C1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\usbuhci.sys Hooked IRP: IRP_MJ_DEVICE_CONTROL Jump To: B296C1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\usbuhci.sys Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL Jump To: B296C1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\usbuhci.sys Hooked IRP: IRP_MJ_POWER Jump To: B296C1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\usbuhci.sys Hooked IRP: IRP_MJ_SYSTEM_CONTROL Jump To: B296C1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\iastor.sys Hooked IRP: IRP_MJ_CREATE Jump To: B69756D0 Hooking Module: C:\Windows\system32\drivers\iastor.sys Hooked Module: C:\Windows\system32\drivers\iastor.sys Hooked IRP: IRP_MJ_CLOSE Jump To: B69756D0 Hooking Module: C:\Windows\system32\drivers\iastor.sys Hooked Module: C:\Windows\system32\drivers\iastor.sys Hooked IRP: IRP_MJ_DEVICE_CONTROL Jump To: B69756D0 Hooking Module: C:\Windows\system32\drivers\iastor.sys Hooked Module: C:\Windows\system32\drivers\iastor.sys Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL Jump To: B69756D0 Hooking Module: C:\Windows\system32\drivers\iastor.sys Hooked Module: C:\Windows\system32\drivers\iastor.sys Hooked IRP: IRP_MJ_POWER Jump To: B69756D0 Hooking Module: C:\Windows\system32\drivers\iastor.sys Hooked Module: C:\Windows\system32\drivers\iastor.sys Hooked IRP: IRP_MJ_SYSTEM_CONTROL Jump To: B69756D0 Hooking Module: C:\Windows\system32\drivers\iastor.sys Hooked Module: C:\Windows\system32\DRIVERS\smb.sys Hooked IRP: IRP_MJ_CREATE Jump To: B589A500 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\smb.sys Hooked IRP: IRP_MJ_CLOSE Jump To: B589A500 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\smb.sys Hooked IRP: IRP_MJ_DEVICE_CONTROL Jump To: B589A500 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\smb.sys Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL Jump To: B589A500 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\smb.sys Hooked IRP: IRP_MJ_CLEANUP Jump To: B589A500 Hooking Module: _unknown_ Hooked Module: C:\Windows\System32\DRIVERS\netbt.sys Hooked IRP: IRP_MJ_CREATE Jump To: B5838500 Hooking Module: _unknown_ Hooked Module: C:\Windows\System32\DRIVERS\netbt.sys Hooked IRP: IRP_MJ_CLOSE Jump To: B5838500 Hooking Module: _unknown_ Hooked Module: C:\Windows\System32\DRIVERS\netbt.sys Hooked IRP: IRP_MJ_DEVICE_CONTROL Jump To: B5838500 Hooking Module: _unknown_ Hooked Module: C:\Windows\System32\DRIVERS\netbt.sys Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL Jump To: B5838500 Hooking Module: _unknown_ Hooked Module: C:\Windows\System32\DRIVERS\netbt.sys Hooked IRP: IRP_MJ_CLEANUP Jump To: B5838500 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\msiscsi.sys Hooked IRP: IRP_MJ_CREATE Jump To: B2A861F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\msiscsi.sys Hooked IRP: IRP_MJ_CLOSE Jump To: B2A861F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\msiscsi.sys Hooked IRP: IRP_MJ_DEVICE_CONTROL Jump To: B2A861F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\msiscsi.sys Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL Jump To: B2A861F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\msiscsi.sys Hooked IRP: IRP_MJ_POWER Jump To: B2A861F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\msiscsi.sys Hooked IRP: IRP_MJ_SYSTEM_CONTROL Jump To: B2A861F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\cdrom.sys Hooked IRP: IRP_MJ_CREATE Jump To: B2A181F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\cdrom.sys Hooked IRP: IRP_MJ_CLOSE Jump To: B2A181F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\cdrom.sys Hooked IRP: IRP_MJ_READ Jump To: B2A181F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\cdrom.sys Hooked IRP: IRP_MJ_WRITE Jump To: B2A181F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\cdrom.sys Hooked IRP: IRP_MJ_FLUSH_BUFFERS Jump To: B2A181F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\cdrom.sys Hooked IRP: IRP_MJ_DEVICE_CONTROL Jump To: B2A181F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\cdrom.sys Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL Jump To: B2A181F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\cdrom.sys Hooked IRP: IRP_MJ_SHUTDOWN Jump To: B2A181F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\cdrom.sys Hooked IRP: IRP_MJ_POWER Jump To: B2A181F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\cdrom.sys Hooked IRP: IRP_MJ_SYSTEM_CONTROL Jump To: B2A181F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\volmgr.sys Hooked IRP: IRP_MJ_CREATE Jump To: B09971F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\volmgr.sys Hooked IRP: IRP_MJ_READ Jump To: B09971F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\volmgr.sys Hooked IRP: IRP_MJ_WRITE Jump To: B09971F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\volmgr.sys Hooked IRP: IRP_MJ_FLUSH_BUFFERS Jump To: B09971F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\volmgr.sys Hooked IRP: IRP_MJ_DEVICE_CONTROL Jump To: B09971F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\volmgr.sys Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL Jump To: B09971F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\volmgr.sys Hooked IRP: IRP_MJ_SHUTDOWN Jump To: B09971F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\volmgr.sys Hooked IRP: IRP_MJ_CLEANUP Jump To: B09971F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\volmgr.sys Hooked IRP: IRP_MJ_POWER Jump To: B09971F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\drivers\volmgr.sys Hooked IRP: IRP_MJ_SYSTEM_CONTROL Jump To: B09971F8 Hooking Module: _unknown_ Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_CREATE Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_CREATE_NAMED_PIPE Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_CLOSE Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_READ Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_WRITE Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_QUERY_INFORMATION Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_SET_INFORMATION Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_QUERY_EA Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_SET_EA Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_FLUSH_BUFFERS Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_QUERY_VOLUME_INFORMATION Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_SET_VOLUME_INFORMATION Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_DIRECTORY_CONTROL Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_FILE_SYSTEM_CONTROL Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_DEVICE_CONTROL Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_SHUTDOWN Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_LOCK_CONTROL Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_CLEANUP Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_CREATE_MAILSLOT Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_QUERY_SECURITY Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_SET_SECURITY Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_POWER Jump To: B669DE1C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_SYSTEM_CONTROL Jump To: B66B1514 Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_DEVICE_CHANGE Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_QUERY_QUOTA Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: \Driver\PCI_PNP7495 Hooked IRP: IRP_MJ_SET_QUOTA Jump To: B66D7B0C Hooking Module: \SystemRoot\System32\Drivers\spla.sys Hooked Module: C:\Windows\system32\DRIVERS\usbehci.sys Hooked IRP: IRP_MJ_CREATE Jump To: B296B1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\usbehci.sys Hooked IRP: IRP_MJ_CLOSE Jump To: B296B1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\usbehci.sys Hooked IRP: IRP_MJ_DEVICE_CONTROL Jump To: B296B1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\usbehci.sys Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL Jump To: B296B1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\usbehci.sys Hooked IRP: IRP_MJ_POWER Jump To: B296B1F8 Hooking Module: _unknown_ Hooked Module: C:\Windows\system32\DRIVERS\usbehci.sys Hooked IRP: IRP_MJ_SYSTEM_CONTROL Jump To: B296B1F8 Hooking Module: _unknown_ Hooked Module: \SystemRoot\System32\Drivers\abrouwxy.SYS Hooked IRP: IRP_MJ_CREATE Jump To: B2A7D1F8 Hooking Module: _unknown_ Hooked Module: \SystemRoot\System32\Drivers\abrouwxy.SYS Hooked IRP: IRP_MJ_CLOSE Jump To: B2A7D1F8 Hooking Module: _unknown_ Hooked Module: \SystemRoot\System32\Drivers\abrouwxy.SYS Hooked IRP: IRP_MJ_DEVICE_CONTROL Jump To: B2A7D1F8 Hooking Module: _unknown_ Hooked Module: \SystemRoot\System32\Drivers\abrouwxy.SYS Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL Jump To: B2A7D1F8 Hooking Module: _unknown_ Hooked Module: \SystemRoot\System32\Drivers\abrouwxy.SYS Hooked IRP: IRP_MJ_POWER Jump To: B2A7D1F8 Hooking Module: _unknown_ Hooked Module: \SystemRoot\System32\Drivers\abrouwxy.SYS Hooked IRP: IRP_MJ_SYSTEM_CONTROL Jump To: B2A7D1F8 Hooking Module: _unknown_ ******************************************************************************** ********** ******************************************************************************** ********** Ports: Local Address: PARTH-PC:50119 Remote Address: 8.17.64.46:HTTP Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: PARTH-PC:49919 Remote Address: GW-IN-F106.GOOGLE.COM:HTTP Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: PARTH-PC:49170 Remote Address: STATIC.91.213.46.78.CLIENTS.YOUR-SERVER.DE:HTTPS Type: TCP Process: C:\Windows\System32\svchost.exe State: CLOSE_WAIT Local Address: PARTH-PC:NETBIOS-SSN Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: PARTH-PC:50118 Remote Address: LOCALHOST:20644 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: PARTH-PC:49918 Remote Address: LOCALHOST:20644 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: PARTH-PC:49567 Remote Address: LOCALHOST:49566 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: PARTH-PC:49566 Remote Address: LOCALHOST:49567 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: PARTH-PC:49565 Remote Address: LOCALHOST:49564 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: PARTH-PC:49564 Remote Address: LOCALHOST:49565 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: PARTH-PC:27015 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe State: LISTENING Local Address: PARTH-PC:20644 Remote Address: LOCALHOST:50118 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: PARTH-PC:20644 Remote Address: LOCALHOST:49918 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: PARTH-PC:20644 Remote Address: LOCALHOST:49668 Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: PARTH-PC:20644 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: LISTENING Local Address: PARTH-PC:7438 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Windows\System32\svchost.exe State: LISTENING Local Address: PARTH-PC:DCCM Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Windows\System32\svchost.exe State: LISTENING Local Address: PARTH-PC:5354 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Bonjour\mDNSResponder.exe State: LISTENING Local Address: PARTH-PC:49164 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Windows\System32\services.exe State: LISTENING Local Address: PARTH-PC:49157 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Windows\System32\lsass.exe State: LISTENING Local Address: PARTH-PC:49155 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Windows\System32\svchost.exe State: LISTENING Local Address: PARTH-PC:49153 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Windows\System32\svchost.exe State: LISTENING Local Address: PARTH-PC:49152 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Windows\System32\wininit.exe State: LISTENING Local Address: PARTH-PC:10026 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Windows\System32\dlcdcoms.exe State: LISTENING Local Address: PARTH-PC:5357 Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: PARTH-PC:FTPS Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Windows\System32\svchost.exe State: LISTENING Local Address: PARTH-PC:MICROSOFT-DS Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: PARTH-PC:EPMAP Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Windows\System32\svchost.exe State: LISTENING Local Address: PARTH-PC:57638 Remote Address: NA Type: UDP Process: C:\Windows\System32\svchost.exe State: NA Local Address: PARTH-PC:5353 Remote Address: NA Type: UDP Process: C:\Program Files\Bonjour\mDNSResponder.exe State: NA Local Address: PARTH-PC:SSDP Remote Address: NA Type: UDP Process: C:\Windows\System32\svchost.exe State: NA Local Address: PARTH-PC:138 Remote Address: NA Type: UDP Process: System State: NA Local Address: PARTH-PC:NETBIOS-NS Remote Address: NA Type: UDP Process: System State: NA Local Address: PARTH-PC:57639 Remote Address: NA Type: UDP Process: C:\Windows\System32\svchost.exe State: NA Local Address: PARTH-PC:44301 Remote Address: NA Type: UDP Process: C:\Windows\System32\PnkBstrA.exe State: NA Local Address: PARTH-PC:SSDP Remote Address: NA Type: UDP Process: C:\Windows\System32\svchost.exe State: NA Local Address: PARTH-PC:59453 Remote Address: NA Type: UDP Process: C:\Program Files\Bonjour\mDNSResponder.exe State: NA Local Address: PARTH-PC:51405 Remote Address: NA Type: UDP Process: C:\Program Files\Bonjour\mDNSResponder.exe State: NA Local Address: PARTH-PC:LLMNR Remote Address: NA Type: UDP Process: C:\Windows\System32\svchost.exe State: NA Local Address: PARTH-PC:IPSEC-MSFT Remote Address: NA Type: UDP Process: C:\Windows\System32\svchost.exe State: NA Local Address: PARTH-PC:500 Remote Address: NA Type: UDP Process: C:\Windows\System32\svchost.exe State: NA Local Address: PARTH-PC:123 Remote Address: NA Type: UDP Process: C:\Windows\System32\svchost.exe State: NA ******************************************************************************** ********** ******************************************************************************** ********** Hidden files/folders: Object: C:\$Recycle.Bin\S-1-5-21-3256818742-1514715972-2829636577-1000\$RDNHDMI\ Status: Hidden Object: C:\Windows\System32\drivers\SKYNETydyeqewv.sys Status: Hidden Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl Status: Access denied Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl Status: Access denied Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl Status: Access denied Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl Status: Access denied Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMuroc System Trace.etl Status: Access denied Object: C:\Windows\System32\SKYNETcbdjmnqx.dll Status: Hidden Object: C:\Windows\System32\SKYNETjxboiipt.dll Status: Hidden Object: C:\Windows\System32\SKYNETmmyovptn.dat Status: Hidden Object: C:\Windows\System32\SKYNETtfvuanlp.dat Status: Hidden Object: C:\Windows\TEMP\SKYNETbecptxnocp.tmp Status: Hidden Object: C:\Windows\TEMP\SKYNETmwtmtrnfbr.tmp Status: Hidden Object: C:\Windows\TEMP\SKYNETpcyquvbeni.tmp Status: Hidden Object: C:\Windows\TEMP\SKYNETpshpbjjkyb.tmp Status: Hidden Object: C:\Windows\TEMP\SKYNETyfbckbjxvl.tmp Status: Hidden
We need to run an OTL Fix

  • Double-click OTL.exe to start the program.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word Code
    :OTL
    PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
    SRV - (AntipPro2009_12 [Auto | Stopped]) – C:\Windows\svchast.exe ()
    O2 - BHO: (no name) - {46d2b8e4-b1a2-4e71-b177-0d681ad96db1} - C:\Windows\System32\himesuvo.dll ()
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
    O2 - BHO: (ICQSys (IE PlugIn)) - {F54AF7DE-6038-4026-8433-CC30E3F17212} - C:\Windows\System32\dddesot.dll (ASC - AntiSpyware)
    O4 - HKLM..\Run: [CPM294f4f23] C:\Windows\System32\titewiko.DLL ()
    O20 - AppInit_DLLs: (C:\Windows\system32\jufuvowa.dll) - C:\Windows\System32\jufuvowa.dll ()
    O20 - AppInit_DLLs: (c:\windows\system32\sarotehi.dll) - C:\Windows\System32\sarotehi.dll ()
    O20 - AppInit_DLLs: (c:\windows\system32\titewiko.dll) - C:\Windows\System32\titewiko.dll ()
    O20 - Winlogon\Notify\psfus: DllName - C:\Windows\system32\psqlpwd.dll - C:\Windows\System32\psqlpwd.dll File not found
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - C:\Windows\System32\titewiko.dll ()
    O22 - SharedTaskScheduler: {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - STS - C:\Windows\System32\titewiko.dll ()
    [2009/08/08 10:18:08 | 00,827,392 | —- | C] (ASC - AntiSpyware) – C:\Windows\System32\dddesot.dll
    [2009/08/08 10:18:08 | 00,176,128 | —- | C] () – C:\Windows\svchast.exe
    [2009/08/08 10:18:08 | 00,016,384 | —- | C] () – C:\Windows\System32\desot.exe
    [2009/08/08 10:18:08 | 00,000,064 | —- | C] () – C:\Windows\ppp4.dat
    [2009/08/08 10:18:08 | 00,000,009 | —- | C] () – C:\Windows\System32\bennuar.old
    [2009/08/08 10:18:08 | 00,000,003 | —- | C] () – C:\Windows\ppp3.dat
    [2009/05/11 09:21:48 | 00,084,480 | -HS- | C] () – C:\Windows\System32\titewiko.dll
    [2009/05/11 09:21:48 | 00,037,376 | -HS- | C] () – C:\Windows\System32\hajigira.dll
    [2009/05/10 21:10:52 | 00,083,968 | -HS- | C] () – C:\Windows\System32\sarotehi.dll
    [2009/05/10 21:10:52 | 00,037,376 | -HS- | C] () – C:\Windows\System32\losesafa.dll
    [2009/05/10 09:11:23 | 00,050,176 | -HS- | C] () – C:\Windows\System32\pipidesa.dll
    [2009/05/10 09:11:23 | 00,050,176 | -HS- | C] () – C:\Windows\System32\jufuvowa.dll
    [2009/05/10 09:11:23 | 00,050,176 | -HS- | C] () – C:\Windows\System32\himesuvo.dll
    [2009/05/10 09:10:51 | 00,084,480 | -HS- | C] () – C:\Windows\System32\sinehotu.dll
    [2009/05/10 09:10:51 | 00,050,176 | -HS- | C] () – C:\Windows\System32\kizomelo.dll
    [2009/05/10 09:10:51 | 00,037,888 | -HS- | C] () – C:\Windows\System32\gokisoso.dll
    [2009/05/09 15:38:59 | 00,084,992 | -HS- | C] () – C:\Windows\System32\kegezadu.dll
    [2009/05/09 15:38:59 | 00,037,888 | -HS- | C] () – C:\Windows\System32\kewevuro.dll
    [2009/05/08 22:38:28 | 00,085,504 | -HS- | C] () – C:\Windows\System32\buhivayi.dll
    [2009/05/08 22:38:28 | 00,049,664 | -HS- | C] () – C:\Windows\System32\zoyiboha.dll
    [2009/05/08 22:38:28 | 00,038,400 | -HS- | C] () – C:\Windows\System32\gugasara.dll
    [2009/05/08 10:38:02 | 00,084,992 | -HS- | C] () – C:\Windows\System32\siruguhu.dll
    [2009/05/08 10:38:02 | 00,038,400 | -HS- | C] () – C:\Windows\System32\pufajahe.dll
    [2008/11/14 13:40:44 | 00,022,350 | R— | C] () – C:\Windows\System32\kschimp.ini
    [2008/11/14 13:40:31 | 00,028,234 | —- | C] () – C:\Windows\System32\ksaud.ini
    [2008/11/14 13:40:31 | 00,000,029 | —- | C] () – C:\Windows\System32\ctzapxx.ini
    [2009/08/11 10:10:04 | 00,011,168 | -H– | M] () – C:\Windows\System32\mupepidu
    [2009/08/11 09:21:49 | 00,084,480 | -HS- | M] () – C:\Windows\System32\titewiko.dll
    [2009/08/11 09:21:48 | 00,037,376 | -HS- | M] () – C:\Windows\System32\hajigira.dll
    [2009/08/10 21:10:53 | 00,083,968 | -HS- | M] () – C:\Windows\System32\sarotehi.dll
    [2009/08/10 21:10:52 | 00,037,376 | -HS- | M] () – C:\Windows\System32\losesafa.dll
    [2009/08/10 09:11:22 | 00,050,176 | -HS- | M] () – C:\Windows\System32\kizomelo.dll
    [2009/08/10 09:10:52 | 00,084,480 | -HS- | M] () – C:\Windows\System32\sinehotu.dll
    [2009/08/10 09:10:52 | 00,037,888 | -HS- | M] () – C:\Windows\System32\gokisoso.dll
    [2009/08/09 15:39:00 | 00,084,992 | -HS- | M] () – C:\Windows\System32\kegezadu.dll
    [2009/08/09 15:39:00 | 00,037,888 | -HS- | M] () – C:\Windows\System32\kewevuro.dll
    [2009/08/08 22:38:59 | 00,049,664 | -HS- | M] () – C:\Windows\System32\zoyiboha.dll
    [2009/08/08 22:38:29 | 00,085,504 | -HS- | M] () – C:\Windows\System32\buhivayi.dll
    [2009/08/08 22:38:29 | 00,038,400 | -HS- | M] () – C:\Windows\System32\gugasara.dll
    [2009/08/08 18:00:02 | 00,016,384 | —- | M] () – C:\Windows\System32\desot.exe
    [2009/08/08 18:00:02 | 00,000,064 | —- | M] () – C:\Windows\ppp4.dat
    [2009/08/08 18:00:02 | 00,000,003 | —- | M] () – C:\Windows\ppp3.dat
    [2009/08/08 10:38:02 | 00,084,992 | -HS- | M] () – C:\Windows\System32\siruguhu.dll
    [2009/08/08 10:38:02 | 00,038,400 | -HS- | M] () – C:\Windows\System32\pufajahe.dll
    [2009/08/08 10:18:08 | 00,176,128 | —- | M] () – C:\Windows\svchast.exe
    [2009/08/08 10:18:08 | 00,000,009 | —- | M] () – C:\Windows\System32\bennuar.old
    
    :Files
    C:\Windows\system32\drivers\SKYNETydyeqewv.sys
    C:\Windows\System32\SKYNETcbdjmnqx.dll
    C:\Windows\System32\SKYNETjxboiipt.dll
    C:\Windows\System32\SKYNETmmyovptn.dat
    C:\Windows\System32\SKYNETtfvuanlp.dat
    C:\Windows\TEMP\SKYNETbecptxnocp.tmp
    C:\Windows\TEMP\SKYNETmwtmtrnfbr.tmp
    C:\Windows\TEMP\SKYNETpcyquvbeni.tmp
    C:\Windows\TEMP\SKYNETpshpbjjkyb.tmp
    C:\Windows\TEMP\SKYNETyfbckbjxvl.tmp
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top.
  • Click [external image: Posted Image].
  • OTL may ask to reboot the machine. Please do so if asked.
  • The report should appear in Notepad after the reboot.Copy and Paste that report in your next reply.
Hey Raktor, I did get the log. First time I copy/pasted the text in OTL and clicked RUN FIX, it did for a while, then it was emptying the temp folder and I got a error… Range Check error or something. I clicked OK and then at the bottom it still kept saying EMPTYING TEMP folder, plz dont do anything. It stayed like that for like 10-15ish mins. I ended up pasting the text AGAIN in the CUSTOM FIX area and clicked RUN FIX again. This time it worked and rebooted the computer. Here is the log…. All processes killed ========== OTL ========== No active process named Explorer.EXE was found! Service\Driver AntipPro2009_12 not found. Service\Driver AntipPro2009_12 not found. File C:\Windows\svchast.exe not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{46d2b8e4-b1a2-4e71-b177-0d681ad96db1}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{46d2b8e4-b1a2-4e71-b177-0d681ad96db1}\ deleted successfully. File C:\Windows\System32\himesuvo.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F54AF7DE-6038-4026-8433-CC30E3F17212}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F54AF7DE-6038-4026-8433-CC30E3F17212}\ not found. File C:\Windows\System32\dddesot.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\CPM294f4f23 deleted successfully. File C:\Windows\System32\titewiko.DLL not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\Windows\system32\jufuvowa.dll deleted successfully. File C:\Windows\System32\jufuvowa.dll not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\sarotehi.dll scheduled to be deleted on reboot. File C:\Windows\System32\sarotehi.dll not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\titewiko.dll scheduled to be deleted on reboot. File C:\Windows\System32\titewiko.dll not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\SSODL deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\ deleted successfully. File C:\Windows\System32\titewiko.dll not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\ not found. File C:\Windows\System32\titewiko.dll not found. File C:\Windows\System32\dddesot.dll not found. File C:\Windows\svchast.exe not found. File C:\Windows\System32\desot.exe not found. File C:\Windows\ppp4.dat not found. File C:\Windows\System32\bennuar.old not found. File C:\Windows\ppp3.dat not found. File C:\Windows\System32\titewiko.dll not found. File C:\Windows\System32\hajigira.dll not found. File C:\Windows\System32\sarotehi.dll not found. File C:\Windows\System32\losesafa.dll not found. File C:\Windows\System32\pipidesa.dll not found. File C:\Windows\System32\jufuvowa.dll not found. File C:\Windows\System32\himesuvo.dll not found. File C:\Windows\System32\sinehotu.dll not found. File C:\Windows\System32\kizomelo.dll not found. File C:\Windows\System32\gokisoso.dll not found. File C:\Windows\System32\kegezadu.dll not found. File C:\Windows\System32\kewevuro.dll not found. File C:\Windows\System32\buhivayi.dll not found. File C:\Windows\System32\zoyiboha.dll not found. File C:\Windows\System32\gugasara.dll not found. File C:\Windows\System32\siruguhu.dll not found. File C:\Windows\System32\pufajahe.dll not found. File C:\Windows\System32\kschimp.ini not found. File C:\Windows\System32\ksaud.ini not found. File C:\Windows\System32\ctzapxx.ini not found. C:\Windows\System32\mupepidu moved successfully. File C:\Windows\System32\titewiko.dll not found. File C:\Windows\System32\hajigira.dll not found. File C:\Windows\System32\sarotehi.dll not found. File C:\Windows\System32\losesafa.dll not found. File C:\Windows\System32\kizomelo.dll not found. File C:\Windows\System32\sinehotu.dll not found. File C:\Windows\System32\gokisoso.dll not found. File C:\Windows\System32\kegezadu.dll not found. File C:\Windows\System32\kewevuro.dll not found. File C:\Windows\System32\zoyiboha.dll not found. File C:\Windows\System32\buhivayi.dll not found. File C:\Windows\System32\gugasara.dll not found. File C:\Windows\System32\desot.exe not found. File C:\Windows\ppp4.dat not found. File C:\Windows\ppp3.dat not found. File C:\Windows\System32\siruguhu.dll not found. File C:\Windows\System32\pufajahe.dll not found. File C:\Windows\svchast.exe not found. File C:\Windows\System32\bennuar.old not found. ========== FILES ========== File\Folder C:\Windows\system32\drivers\SKYNETydyeqewv.sys not found. File\Folder C:\Windows\System32\SKYNETcbdjmnqx.dll not found. File\Folder C:\Windows\System32\SKYNETjxboiipt.dll not found. File\Folder C:\Windows\System32\SKYNETmmyovptn.dat not found. File\Folder C:\Windows\System32\SKYNETtfvuanlp.dat not found. File\Folder C:\Windows\TEMP\SKYNETbecptxnocp.tmp not found. File\Folder C:\Windows\TEMP\SKYNETmwtmtrnfbr.tmp not found. File\Folder C:\Windows\TEMP\SKYNETpcyquvbeni.tmp not found. File\Folder C:\Windows\TEMP\SKYNETpshpbjjkyb.tmp not found. File\Folder C:\Windows\TEMP\SKYNETyfbckbjxvl.tmp not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Parth ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.0.10.5 log created on 08112009_124601
Please read through the instructions to familiarize yourself with what to expect when the tool runs.

Please download Combofix from either of the links below, and save it to your desktop.
You must rename it before saving it. Save it as Combo-Fix.exe.

[external image: Posted Image]

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link:How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts. Close all browsers/windows first.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hey Raktor, I renamed and saved combo-fix.exe to desktop. First time I ran it(right click and run as admin), The small window opened and combo fix bar filled up, then another window popped up and it asked me what software I wanted to use to run the file. You know it asks you that when u like double click a .tig file or something. I just clicked cancel on that, it refreshed my desktop and nothing. Then I tried to run it AGAIN. Same thing, bar filled up, refreshed desktop and NOTHING. Next I booted in safe mode and tried to run it. I had also REdownloaded the file. But, no luck. It did the exact same thing as it did in normal mode. I did get a new error when I booted back in normal mode… RUNDLL Error Loading c:\windows\system32\pipidesa.dll Could not be found. But thats about it… Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI