This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.Generic & Malware.Trace

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I downloaded some .rar files from filehosting websites, unaware of the malicious content. After extracting the archives, Comodo Internet Security started detecting backdoor trojans and some other stuff (I don't remember exactly what.) Eventually the computer became extremely slow - websites became unresponsive and downloads timed-out.

I'm convinced it was those files as my pc is generally well kept. Anyhow, i ran a full 2 hour system scan with Malwarebytes and it detected and removed a number of threats. The computer began running as normal afterwards. However, i'm still finding processes called Microsoft_KB57H43.exe and XxX.xXx which google revealed as a trojan and malware respectively. Malwarebytes doesn't remove them, so I've turned to HijackThis. The log reads as follows:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 08:20:36 PM, on 2010/10/31
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18498)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
D:\Program Files\Winamp\winampa.exe
D:\Program Files\Comodo\COMODO Internet Security\cfp.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wuauclt.exe
D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Users\Admin\Desktop\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - d:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - d:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WinampAgent] "D:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "D:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "d:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [fsc-reg] c:\fsc-reg\fscreg.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [fsc-reg] c:\fsc-reg\fscreg.exe (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: &Download by Orbit - res://d:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://d:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://d:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://d:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7A012576-F6F8-40AE-B3FA-B646E61259E9}: NameServer = 168.210.2.2 196.14.239.2
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - D:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HideMyIpSRV - HideMyIP - D:\Program Files\Hide My IP\HideMyIpSrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - d:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Windows\System32\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: TVersityMediaServer - Unknown owner - C:\Users\Admin\AppData\Local\TVersity\Media Server\MediaServer.exe

–
End of file - 8041 bytes


Thought i should include the 'ADS Spy' log as well:

C:\ProgramData\TEMP : 343FF046 (155 bytes)
C:\ProgramData\TEMP : 343FF046 (155 bytes)
C:\Users\All Users\TEMP : 343FF046 (155 bytes)
C:\Users\All Users\TEMP : 343FF046 (155 bytes)


Looking forward to your expertise.
Regards.
:welcome:

Those file sharing sites are bad news and you should stay away from them, your downloading that file from an unknown source and some contain malware.

Open Malwarebytes and go to the Report Tab , open it and post the report for me to see.



[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries







Hijackthis is outdated and we don't use it much anymore, run this scan instead and post the log please

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.



Post the
Malwarebytes log
GMER Log
OTL Log
Thanks

but…. <_<

The GMER scan catapults the computer into a blue screen and a system restart. This happened all 3 times that i tried it. When the system starts up again it says that "Windows has recovered from an unexpected shutdown" and the "view problem details" reveals the following:

Problem signature:
Problem Event Name: BlueScreen
OS Version: 6.0.6001.2.1.0.768.3
Locale ID: 7177

Additional information about the problem:

BCCode: 4e
BCP1: 0000009A
BCP2: 0006C685
BCP3: 00000001
BCP4: 00000000
OS Version: 6_0_6001
Service Pack: 1_0
Product: 768_1

Files that help describe the problem:
C:\Windows\Minidump\Mini110310-03.dmp
C:\Users\Admin\AppData\Local\Temp\WER-41589-0.sysdata.xml
C:\Users\Admin\AppData\Local\Temp\WER39B5.tmp.version.txt

Read our privacy statement:

http://go.microsoft.com/fwlink/?linkid=501…mp;clcid=0x0409


Perhaps this problem is worse than i thought :blink:
Maybe not, GMER effects all systems differently.

Try running it in Safemode

To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
Tutorial if you need it How to boot into Safemode


If it still wont run then bypass it and post the Malwarebytes log and the OTL log
Okay, seems to have solved the issue.

I actually ran a quick scan before i did the full scan with Malwarebytes, so i'll include both logs.

Malwarebytes Log(s):

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

2010/10/31 02:40:54 PM
mbam-log-2010-10-31 (14-40-54).txt

Scan type: Quick scan
Objects scanned: 119149
Time elapsed: 6 minute(s), 41 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 1
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{k7t7807o-8f37-v7eu-7hu8-fosmjk02ov5f} (Generic.Bot.H) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Folders Infected:
C:\Windows\System32\Microsoft_KB57H43 (Trojan.Backdoor) -> Quarantined and deleted successfully.

Files Infected:
C:\Users\Admin\Desktop\YAAI.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\IELOGIN.abc (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Roaming\logs.dat (Bifrose.Trace) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> Delete on reboot.
C:\Windows\System32\ovfsthhpobrvcwfloyevtnwjtxgbdvgvbojqky.dat (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Windows\System32\ovfsthnfejfudcehqrvwovlddbrsitlmbhbsvx.dat (Rootkit.TDSS) -> Quarantined and deleted successfully.


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

2010/10/31 05:57:52 PM
mbam-log-2010-10-31 (17-57-52).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 292048
Time elapsed: 2 hour(s), 32 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\VritualRoot\account_generator.exe\HarddiskVolume2\Windows\System32\28463\AKV.exe (PUP.ArdamaxKeyLogger) -> Quarantined and deleted successfully.
C:\VritualRoot\account_generator.exe\HarddiskVolume2\Windows\System32\28463\LYIV.006 (PUP.ArdamaxKeyLogger) -> Quarantined and deleted successfully.


GMER Log:

GMER 1.0.15.15477 - http://www.gmer.net
Rootkit scan 2010-11-03 18:17:48
Windows 6.0.6001 Service Pack 1
Running: gmer.exe; Driver: C:\Users\Admin\AppData\Local\Temp\awlcrpod.sys


—- Services - GMER 1.0.15 —-

Service system32\drivers\ovfsthpephxtpcclpuonmxwvwerxdunsyenrnm.sys (*** hidden *** ) [SYSTEM] ovfsthifysemymjbksxgnuhtphivqpyppmratt <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386@001d3b4a04c5 0xD7 0xBC 0x62 0x6A …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386@00247d4b43b3 0x3A 0x49 0x4F 0x0D …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386@0023b479fd58 0x8E 0x29 0x0D 0x3B …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386@001ca462efbc 0xBF 0xDB 0xCE 0x3B …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386@00247db95c91 0x16 0xFF 0x54 0xD7 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386@0012d233506f 0xD8 0x5A 0x0B 0x66 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386@002108dbc2ae 0xE9 0x66 0x13 0x7B …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386@0cddef0b143b 0x62 0x83 0xEE 0xFD …
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@imagepath \systemroot\system32\drivers\ovfsthpephxtpcclpuonmxwvwerxdunsyenrnm.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@inst 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@ver icv190309
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@cid 01
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@bid 3433472181-1097220164-287428032-609269875
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@aid 303350
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@sid 4
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@feed 0x22 0x64 0x78 0x36 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@cmddelay 14401
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\[removed] ovfsthwi.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\[removed] ovfsthff.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthwblopfhrfwscxvrbkfwpkmrqtvpiegcj.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\drivers\ovfsthpephxtpcclpuonmxwvwerxdunsyenrnm.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthnfejfudcehqrvwovlddbrsitlmbhbsvx.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthuvktjnxtiowespoiqafsaxmarcodknxo.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthgavdhydwetxclwexvkpgcebwduxdywya.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthhpobrvcwfloyevtnwjtxgbdvgvbojqky.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 D:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xAF 0xBF 0x99 0xCD …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x52 0xC9 0xCD 0x62 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xD4 0xA3 0x18 0x8A …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x3B 0x8E 0x4D 0x09 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x56 0xEA 0xCB 0x6D …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xE1 0xC5 0x4F 0x2F …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xB5 0xD6 0x06 0xCB …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386@001d3b4a04c5 0xD7 0xBC 0x62 0x6A …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386@00247d4b43b3 0x3A 0x49 0x4F 0x0D …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386@0023b479fd58 0x8E 0x29 0x0D 0x3B …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386@001ca462efbc 0xBF 0xDB 0xCE 0x3B …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386@00247db95c91 0x16 0xFF 0x54 0xD7 …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386@0012d233506f 0xD8 0x5A 0x0B 0x66 …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386@002108dbc2ae 0xE9 0x66 0x13 0x7B …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386@0cddef0b143b 0x62 0x83 0xEE 0xFD …
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@imagepath \systemroot\system32\drivers\ovfsthpephxtpcclpuonmxwvwerxdunsyenrnm.sys
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@inst 0
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@ver icv190309
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@cid 01
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@bid 3433472181-1097220164-287428032-609269875
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@aid 303350
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@sid 4
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@feed 0x22 0x64 0x78 0x36 …
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@cmddelay 14401
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\[removed] ovfsthwi.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\[removed] ovfsthff.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthwblopfhrfwscxvrbkfwpkmrqtvpiegcj.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\drivers\ovfsthpephxtpcclpuonmxwvwerxdunsyenrnm.sys
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthnfejfudcehqrvwovlddbrsitlmbhbsvx.dat
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthuvktjnxtiowespoiqafsaxmarcodknxo.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthgavdhydwetxclwexvkpgcebwduxdywya.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthhpobrvcwfloyevtnwjtxgbdvgvbojqky.dat
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 D:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xAF 0xBF 0x99 0xCD …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x52 0xC9 0xCD 0x62 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xD4 0xA3 0x18 0x8A …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x3B 0x8E 0x4D 0x09 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x56 0xEA 0xCB 0x6D …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xE1 0xC5 0x4F 0x2F …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xB5 0xD6 0x06 0xCB …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{393AA24A-B2E8-10DC-527E-1CCD3A1A9537}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{393AA24A-B2E8-10DC-527E-1CCD3A1A9537}@mabfmloflcpanelnpkdflnmhan 0x6F 0x61 0x61 0x64 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{393AA24A-B2E8-10DC-527E-1CCD3A1A9537}@abafjmhapchpldmcpomkkbdaadimdcgeid 0x69 0x61 0x70 0x66 …

—- EOF - GMER 1.0.15 —-


OTL Log:

OTL logfile created on: 2010/11/03 06:30:04 PM - Run 1
OTL by OldTimer - Version 3.2.17.2 Folder = D:\Users\Admin\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00001C09 | Country: South Africa | Language: ENS | Date Format: yyyy/MM/dd

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 64.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 76.00 Gb Total Space | 16.62 Gb Free Space | 21.87% Space Free | Partition Type: NTFS
Drive D: | 213.30 Gb Total Space | 11.80 Gb Free Space | 5.53% Space Free | Partition Type: NTFS

Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - D:\Users\Admin\Downloads\OTL.exe (OldTimer Tools)
PRC - D:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO)
PRC - D:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\Users\Admin\AppData\Local\TVersity\Media Server\MediaServer.exe ()
PRC - D:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - D:\Program Files\Hide My IP\HideMyIpSrv.exe (HideMyIP)
PRC - d:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Windows\System32\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe (Fujitsu Siemens Computers)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)


========== Modules (SafeList) ==========

MOD - D:\Users\Admin\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\guard32.dll (COMODO)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (cmdAgent) – D:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (TuneUp.Defrag) – C:\Windows\System32\TuneUpDefragService.exe (TuneUp Software)
SRV - (TVersityMediaServer) – C:\Users\Admin\AppData\Local\TVersity\Media Server\MediaServer.exe ()
SRV - (HideMyIpSRV) – D:\Program Files\Hide My IP\HideMyIpSrv.exe (HideMyIP)
SRV - (MBAMService) – d:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (Stereo Service) – C:\Windows\System32\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (UxTuneUp) – C:\Windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (TestHandler) – C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe (Fujitsu Siemens Computers)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (pgfilter) – d:\Program Files\PeerGuardian2\pgfilter.sys File not found
DRV - (pbfilter) – d:\Program Files\PeerBlock\pbfilter.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (netr28u) – C:\Windows\System32\DRIVERS\netr28u.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (cpuz132) – C:\Users\Admin\AppData\Local\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (btusbflt) – C:\Windows\System32\drivers\btusbflt.sys File not found
DRV - (BOCDRIVE) – D:\Program Files\Comodo\CBOClean\BOCDRIVE.sys File not found
DRV - (ATP) – C:\Windows\System32\DRIVERS\cmdatp.sys File not found
DRV - (inspect) – C:\Windows\System32\drivers\inspect.sys (COMODO)
DRV - (cmdHlp) – C:\Windows\System32\drivers\cmdhlp.sys (COMODO)
DRV - (cmderd) – C:\Windows\System32\drivers\cmderd.sys (COMODO)
DRV - (cmdGuard) – C:\Windows\System32\drivers\cmdGuard.sys (COMODO)
DRV - (taphss) – C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (PSSDK42) – C:\Windows\System32\drivers\pssdk42.sys (microOLAP Technologies LTD)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (mcdbus) – C:\Windows\System32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (UsbserFilt) – C:\Windows\System32\drivers\usbser_lowerfltj.sys (Windows ® Codename Longhorn DDK provider)
DRV - (nmwcdc) – C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (upperdev) – C:\Windows\System32\drivers\usbser_lowerflt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (NVNET) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (ahcix86s) – C:\Windows\system32\drivers\ahcix86s.sys (AMD Technologies Inc.)
DRV - (JRAID) – C:\Windows\system32\drivers\jraid.sys (JMicron Technology Corp.)
DRV - (nmwcdnsu) – C:\Windows\System32\drivers\nmwcdnsu.sys (Nokia)
DRV - (nmwcdnsuc) – C:\Windows\System32\drivers\nmwcdnsuc.sys (Nokia)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (iaStor) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (btwrchid) – C:\Windows\System32\drivers\btwrchid.sys (Broadcom Corporation.)
DRV - (btwavdt) – C:\Windows\System32\drivers\btwavdt.sys (Broadcom Corporation.)
DRV - (btwaudio) – C:\Windows\System32\drivers\btwaudio.sys (Broadcom Corporation.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-fp&p;="
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-fp"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-fp"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "search.yahoo.com"
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:[removed]
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {c4dc572a-3295-40eb-b30f-b54aa4cdc4b7}:0.7.25
FF - prefs.js..extensions.enabledItems: [removed]:2.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.7.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: [removed]:0.1.8
FF - prefs.js..extensions.enabledItems: [removed]:2.4.1
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.12
FF - prefs.js..network.proxy.backup.ftp: "[removed]"
FF - prefs.js..network.proxy.backup.ftp_port: 80
FF - prefs.js..network.proxy.backup.gopher: "[removed]"
FF - prefs.js..network.proxy.backup.gopher_port: 80
FF - prefs.js..network.proxy.backup.socks: "[removed]"
FF - prefs.js..network.proxy.backup.socks_port: 80
FF - prefs.js..network.proxy.backup.ssl: "[removed]"
FF - prefs.js..network.proxy.backup.ssl_port: 80
FF - prefs.js..network.proxy.ftp: "[removed]"
FF - prefs.js..network.proxy.ftp_port: 80
FF - prefs.js..network.proxy.gopher: "[removed]"
FF - prefs.js..network.proxy.gopher_port: 80
FF - prefs.js..network.proxy.http: "[removed]"
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.no_proxies_on: "127.0.0.1"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "[removed]"
FF - prefs.js..network.proxy.socks_port: 80
FF - prefs.js..network.proxy.socks_remote_dns: true
FF - prefs.js..network.proxy.ssl: "[removed]"
FF - prefs.js..network.proxy.ssl_port: 80
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2010/08/19 15:07:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2010/11/01 19:55:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2010/11/01 19:55:26 | 000,000,000 | —D | M]

[2010/10/27 21:37:05 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mozilla\Extensions
[2010/10/27 21:37:05 | 000,000,000 | —D | M] (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009/06/07 16:09:08 | 000,000,000 | —D | M] (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2010/11/02 18:41:47 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions
[2010/10/17 19:37:22 | 000,000,000 | —D | M] (Flashblock) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2010/08/27 10:34:56 | 000,000,000 | —D | M] (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\{5b175400-2368-11de-8c30-0800200c9a66}
[2010/09/17 14:48:24 | 000,000,000 | —D | M] (WOT) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/08/21 12:35:54 | 000,000,000 | —D | M] (wmlbrowser) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\{c4dc572a-3295-40eb-b30f-b54aa4cdc4b7}
[2010/09/14 19:28:41 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/10/09 17:12:45 | 000,000,000 | —D | M] (Download Statusbar) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010/08/18 19:01:03 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/10/25 18:57:56 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\[removed]
[2010/10/29 07:34:50 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\[removed]
[2010/10/27 20:36:21 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\[removed]
[2010/10/27 10:25:27 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\[removed]
[2010/10/25 20:11:36 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\[removed]
[2010/10/27 20:36:20 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\[removed]

O1 HOSTS File: ([2006/09/18 23:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - d:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - d:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - d:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [COMODO Internet Security] D:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] d:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: &Download; by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\System32\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\System32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\System32\wshbth.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\HMIPCore.dll (My Privacy Tools, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\HMIPCore.dll (My Privacy Tools, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\HMIPCore.dll (My Privacy Tools, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\HMIPCore.dll (My Privacy Tools, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Windows\System32\HMIPCore.dll (My Privacy Tools, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.2
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\System32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/x-mrml {C51721BE-858B-4A66-A8BF-D2882FF49820} - C:\Program Files\Common Files\A&W;\MidRadio.ocx (YAMAHA CORPORATION)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\Windows\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\Windows\System32\sysdm.cpl (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\Windows\System32\browseui.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Admin\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Admin\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\System32\credssp.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\System32\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\System32\tspkg.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 23:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{335fede8-59e0-11de-b641-000a3a80f386}\Shell\AutoRun\command - "" = J:\smass\safemass.exe – File not found
O33 - MountPoints2\{335fede8-59e0-11de-b641-000a3a80f386}\Shell\explore\command - "" = J:\.\\\\smass\\\safemass.exe – File not found
O33 - MountPoints2\{335fede8-59e0-11de-b641-000a3a80f386}\Shell\open\command - "" = J:\smass\\\\\safemass.exe – File not found
O33 - MountPoints2\{4327e74b-843c-11df-a306-000a3a80f386}\Shell - "" = AutoRun
O33 - MountPoints2\{4327e74b-843c-11df-a306-000a3a80f386}\Shell\AutoRun\command - "" = M:\autorun.exe – File not found
O33 - MountPoints2\{69426cdc-7787-11de-aeaa-000a3a80f386}\Shell\AutoRun\command - "" = C:\Windows\System32\shell32.dll – [2010/07/26 18:55:26 | 011,581,440 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{7e3c19b4-95ad-11df-8727-000a3a80f386}\Shell\AutoRun\command - "" = L:\SANJA\radic.exe – File not found
O33 - MountPoints2\{7e3c19b4-95ad-11df-8727-000a3a80f386}\Shell\open\command - "" = L:\SANJA\radic.exe – File not found
O33 - MountPoints2\{7e3c19b7-95ad-11df-8727-000a3a80f386}\Shell - "" = AutoRun
O33 - MountPoints2\{7e3c19b7-95ad-11df-8727-000a3a80f386}\Shell\AutoRun\command - "" = M:\LaunchU3.exe – File not found
O33 - MountPoints2\{fe0b9b9f-7c53-11de-b546-000a3a80f386}\Shell - "" = AutoRun
O33 - MountPoints2\{fe0b9b9f-7c53-11de-b546-000a3a80f386}\Shell\AutoRun\command - "" = N:\Autorun.exe – File not found
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\autorun.exe – File not found
O34 - HKLM BootExecute: ("autocheck autochk *") - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/11/03 17:41:13 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\busdsl
[2010/11/03 12:21:24 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\umie work doc's
[2010/11/02 19:29:26 | 000,000,000 | —D | C] – C:\Program Files\CF3B5
[2010/11/02 10:24:39 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\110 Premium HD Wallpapers 1280 X 1024
[2010/10/31 19:53:12 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/10/31 13:55:05 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Roaming\Malwarebytes
[2010/10/31 13:54:59 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/10/31 13:54:58 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/10/31 13:54:57 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/10/31 13:21:48 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\New Folder
[2010/10/30 16:38:13 | 000,282,928 | —- | C] (My Privacy Tools, Inc.) – C:\Windows\System32\HMIPCore.dll
[2010/10/30 15:48:54 | 000,000,000 | —D | C] – C:\Windows\Sun
[2010/10/30 15:15:11 | 000,163,840 | —- | C] (My Privacy Tools, Inc.) – C:\Windows\System32\SecureNet.dll
[2010/10/30 14:50:48 | 000,485,920 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvusmb.exe
[2010/10/30 14:50:47 | 000,155,648 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\NVCOSMB.DLL
[2010/10/30 14:50:12 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\wallpapers
[2010/10/30 11:17:38 | 000,000,000 | —D | C] – C:\Hotspot Shield
[2010/10/28 19:34:19 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\Sorted Albums
[2010/10/26 16:54:17 | 000,000,000 | —D | C] – D:\Users\Admin\Videos\VirtualDJ
[2010/10/25 21:18:37 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Roaming\Dropbox
[2010/10/25 18:58:13 | 000,000,000 | —D | C] – C:\Program Files\DVDVideoSoft
[2010/10/22 10:54:46 | 000,000,000 | —D | C] – C:\Program Files\TVersity Codec Pack
[2010/10/22 10:54:24 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Local\TVersity
[2010/10/21 15:26:23 | 000,000,000 | —D | C] – C:\ProgramData\Trusteer
[2010/10/21 11:19:18 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\nbt
[2010/10/20 19:43:14 | 000,000,000 | —D | C] – C:\Users\Admin\.microemulator
[2010/10/19 12:18:26 | 000,080,936 | —- | C] (Broadcom Corporation.) – C:\Windows\System32\drivers\btwavdt.sys
[2010/10/19 12:18:26 | 000,016,168 | —- | C] (Broadcom Corporation.) – C:\Windows\System32\drivers\btwrchid.sys
[2010/10/19 12:18:25 | 000,079,400 | —- | C] (Broadcom Corporation.) – C:\Windows\System32\drivers\btwaudio.sys
[2010/10/19 12:18:21 | 000,233,472 | —- | C] (Broadcom Corporation.) – C:\Windows\System32\BtwRSupport.dll
[2010/10/19 12:18:03 | 000,000,000 | —D | C] – C:\Windows\System32\es-MX
[2010/10/19 12:18:03 | 000,000,000 | —D | C] – C:\Windows\System32\es-AR
[2010/10/14 20:28:47 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\new house selected
[2010/10/14 11:38:41 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\masud uct
[2010/10/11 14:51:23 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\eU mixes
[2010/10/09 19:40:26 | 000,028,928 | —- | C] (TuneUp Software) – C:\Windows\System32\uxtuneup.dll
[2010/10/09 19:06:45 | 000,000,000 | —D | C] – C:\Program Files\DivX
[2010/10/09 19:01:42 | 000,000,000 | —D | C] – C:\ProgramData\DivX
[2010/10/09 18:50:28 | 000,000,000 | —D | C] – C:\Program Files\TuneUp Utilities 2009

========== Files - Modified Within 30 Days ==========

[2010/11/03 18:28:53 | 001,474,832 | —- | M] () – C:\Windows\System32\drivers\sfi.dat
[2010/11/03 18:28:49 | 000,013,999 | —- | M] () – C:\Users\Admin\Desktop\Okay.docx
[2010/11/03 18:28:31 | 000,002,465 | —- | M] () – C:\Users\Admin\Desktop\Microsoft Word 2007.lnk
[2010/11/03 18:19:25 | 000,031,871 | —- | M] () – C:\ProgramData\nvModes.001
[2010/11/03 18:19:14 | 000,000,508 | —- | M] () – C:\Windows\tasks\1-Click Maintenance.job
[2010/11/03 18:19:13 | 000,031,871 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/11/03 18:19:10 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/03 18:19:08 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/03 18:19:07 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/03 18:18:58 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/11/03 18:18:56 | 2012,397,568 | -HS- | M] () – C:\hiberfil.sys
[2010/11/03 17:17:36 | 000,006,604 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/11/03 16:50:04 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/03 11:00:21 | 000,051,514 | —- | M] () – C:\Users\Admin\Desktop\Composit assignment Nov 03 2010.docx
[2010/11/03 10:03:01 | 000,638,346 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/03 10:03:01 | 000,121,342 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/11/03 10:02:08 | 000,169,472 | —- | M] () – C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/02 18:23:29 | 000,048,252 | —- | M] () – C:\Users\Admin\Desktop\Composit assignment Nov 2010 4-00.docx
[2010/11/02 15:59:50 | 000,000,162 | -H– | M] () – C:\Users\Admin\Desktop\~$mposit assignment Nov 2010 4-00.docx
[2010/11/02 14:27:42 | 000,046,692 | —- | M] () – D:\Users\Admin\Videos\Composit assignment Nov 2010.docx
[2010/11/01 07:23:45 | 003,742,272 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/10/31 19:53:15 | 000,000,810 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2010/10/31 13:56:12 | 000,000,620 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/30 18:55:54 | 000,000,258 | —- | M] () – C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2010/10/30 16:38:01 | 000,000,588 | —- | M] () – C:\Users\Admin\Desktop\Hide My IP.lnk
[2010/10/30 15:32:45 | 000,062,993 | —- | M] () – C:\Users\Admin\AppData\Roaming\SQLite3.dll
[2010/10/30 11:03:19 | 000,000,600 | —- | M] () – C:\Users\Admin\PUTTY.RND
[2010/10/27 21:13:08 | 000,000,754 | —- | M] () – C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/10/26 16:54:27 | 000,000,654 | —- | M] () – C:\Users\Admin\Desktop\Virtual DJ Pro.lnk
[2010/10/26 15:49:06 | 001,717,198 | —- | M] () – C:\Users\Admin\Desktop\Track 2.mp3
[2010/10/26 09:38:54 | 000,000,588 | —- | M] () – C:\Users\Admin\Desktop\Hide My MAC Address.lnk
[2010/10/26 09:07:44 | 000,000,606 | —- | M] () – C:\Users\Admin\Desktop\RAR Repair Tool.lnk
[2010/10/22 22:02:20 | 000,037,249 | —- | M] () – C:\Users\Admin\Desktop\grade 12 external exams.pdf
[2010/10/22 14:43:46 | 000,078,504 | —- | M] (COMODO) – C:\Windows\System32\drivers\inspect.sys
[2010/10/22 10:54:47 | 000,002,220 | —- | M] () – C:\Users\Admin\Desktop\TVersity.lnk
[2010/10/20 20:41:39 | 000,000,568 | —- | M] () – C:\Users\Admin\AppData\Roaming\AutoGK.ini
[2010/10/20 20:38:23 | 000,000,691 | —- | M] () – C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\VLC.lnk
[2010/10/20 19:43:59 | 000,000,008 | —- | M] () – C:\Users\Admin\AppData\Local\.mpid
[2010/10/19 16:00:08 | 000,294,912 | —- | M] () – C:\Users\Admin\Desktop\gmer.exe
[2010/10/19 15:43:09 | 000,022,046 | —- | M] () – C:\Users\Admin\Desktop\rap-rnb disc.nri
[2010/10/19 12:24:18 | 000,000,697 | —- | M] () – C:\Users\Admin\Desktop\IsoBuster.lnk
[2010/10/19 12:18:09 | 000,000,743 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
[2010/10/18 21:07:18 | 000,276,716 | —- | M] () – C:\Users\Admin\Desktop\30402EME2008.pdf
[2010/10/12 14:36:19 | 004,521,903 | —- | M] () – C:\Users\Admin\Desktop\Sound 1.mp3
[2010/10/12 06:54:57 | 000,074,703 | —- | M] () – C:\Windows\System32\mfc45.dll
[2010/10/11 16:05:42 | 003,001,054 | —- | M] () – C:\Users\Admin\Desktop\Sound 2.mp3
[2010/10/09 19:41:22 | 000,001,857 | —- | M] () – C:\Users\Admin\Desktop\TuneUp Utilities.lnk
[2010/10/09 19:41:22 | 000,001,849 | —- | M] () – C:\Users\Admin\Desktop\1-Click Maintenance.lnk
[2010/10/06 10:40:43 | 000,012,589 | —- | M] () – D:\Users\Admin\Videos\Sceanario Planning Summary Session 3.docx
[2010/10/05 21:40:35 | 000,001,038 | —- | M] () – C:\Users\Admin\Desktop\Free Studio.lnk
[2010/10/04 21:01:29 | 000,285,480 | —- | M] (COMODO) – C:\Windows\System32\guard32.dll
[2010/10/04 21:00:17 | 000,030,112 | —- | M] (COMODO) – C:\Windows\System32\drivers\cmdhlp.sys
[2010/10/04 21:00:10 | 000,017,256 | —- | M] (COMODO) – C:\Windows\System32\drivers\cmderd.sys
[2010/10/04 21:00:04 | 000,236,088 | —- | M] (COMODO) – C:\Windows\System32\drivers\cmdGuard.sys

========== Files Created - No Company Name ==========

[2010/11/03 18:28:48 | 000,013,999 | —- | C] () – C:\Users\Admin\Desktop\Okay.docx
[2010/11/03 18:18:56 | 2012,397,568 | -HS- | C] () – C:\hiberfil.sys
[2010/11/03 12:36:14 | 000,294,912 | —- | C] () – C:\Users\Admin\Desktop\gmer.exe
[2010/11/03 10:00:56 | 000,051,514 | —- | C] () – C:\Users\Admin\Desktop\Composit assignment Nov 03 2010.docx
[2010/11/02 15:59:50 | 000,000,162 | -H– | C] () – C:\Users\Admin\Desktop\~$mposit assignment Nov 2010 4-00.docx
[2010/11/02 15:59:49 | 000,048,252 | —- | C] () – C:\Users\Admin\Desktop\Composit assignment Nov 2010 4-00.docx
[2010/11/01 09:21:32 | 000,046,692 | —- | C] () – D:\Users\Admin\Videos\Composit assignment Nov 2010.docx
[2010/10/31 19:53:15 | 000,000,810 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2010/10/31 13:55:01 | 000,000,620 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/30 18:55:54 | 000,000,258 | —- | C] () – C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2010/10/30 16:38:01 | 000,000,588 | —- | C] () – C:\Users\Admin\Desktop\Hide My IP.lnk
[2010/10/30 15:32:45 | 000,062,993 | —- | C] () – C:\Users\Admin\AppData\Roaming\SQLite3.dll
[2010/10/30 14:50:48 | 000,002,674 | —- | C] () – C:\Windows\System32\nvsmb.nvu
[2010/10/30 11:03:08 | 000,000,600 | —- | C] () – C:\Users\Admin\PUTTY.RND
[2010/10/26 16:54:27 | 000,000,654 | —- | C] () – C:\Users\Admin\Desktop\Virtual DJ Pro.lnk
[2010/10/26 09:38:54 | 000,000,588 | —- | C] () – C:\Users\Admin\Desktop\Hide My MAC Address.lnk
[2010/10/26 09:07:44 | 000,000,606 | —- | C] () – C:\Users\Admin\Desktop\RAR Repair Tool.lnk
[2010/10/22 22:02:17 | 000,037,249 | —- | C] () – C:\Users\Admin\Desktop\grade 12 external exams.pdf
[2010/10/22 11:12:00 | 000,085,504 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/10/22 10:54:47 | 000,002,220 | —- | C] () – C:\Users\Admin\Desktop\TVersity.lnk
[2010/10/20 20:38:23 | 000,000,691 | —- | C] () – C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\VLC.lnk
[2010/10/19 15:43:09 | 000,022,046 | —- | C] () – C:\Users\Admin\Desktop\rap-rnb disc.nri
[2010/10/19 12:32:17 | 001,717,198 | —- | C] () – C:\Users\Admin\Desktop\Track 2.mp3
[2010/10/19 12:24:18 | 000,000,697 | —- | C] () – C:\Users\Admin\Desktop\IsoBuster.lnk
[2010/10/18 21:07:13 | 000,276,716 | —- | C] () – C:\Users\Admin\Desktop\30402EME2008.pdf
[2010/10/17 21:21:07 | 000,000,008 | —- | C] () – C:\Users\Admin\AppData\Local\.mpid
[2010/10/13 18:06:10 | 000,000,829 | —- | C] () – C:\Users\Admin\Desktop\Revo Uninstaller.lnk
[2010/10/12 14:30:47 | 000,000,508 | —- | C] () – C:\Windows\tasks\1-Click Maintenance.job
[2010/10/12 06:54:57 | 000,074,703 | —- | C] () – C:\Windows\System32\mfc45.dll
[2010/10/11 16:05:48 | 004,521,903 | —- | C] () – C:\Users\Admin\Desktop\Sound 1.mp3
[2010/10/11 16:05:04 | 003,001,054 | —- | C] () – C:\Users\Admin\Desktop\Sound 2.mp3
[2010/10/09 19:41:22 | 000,001,857 | —- | C] () – C:\Users\Admin\Desktop\TuneUp Utilities.lnk
[2010/10/09 19:41:22 | 000,001,849 | —- | C] () – C:\Users\Admin\Desktop\1-Click Maintenance.lnk
[2010/10/06 10:08:20 | 000,012,589 | —- | C] () – D:\Users\Admin\Videos\Sceanario Planning Summary Session 3.docx
[2010/10/05 21:40:35 | 000,001,038 | —- | C] () – C:\Users\Admin\Desktop\Free Studio.lnk
[2010/09/02 11:26:05 | 000,395,776 | —- | C] () – C:\Windows\System32\libmplayer.dll
[2010/09/02 11:26:05 | 000,262,144 | —- | C] () – C:\Windows\System32\TomsMoComp_ff.dll
[2010/09/02 11:26:04 | 002,255,360 | —- | C] () – C:\Windows\System32\libavcodec.dll
[2010/09/02 11:26:04 | 000,112,640 | —- | C] () – C:\Windows\System32\libmpeg2_ff.dll
[2010/08/23 16:23:54 | 000,819,200 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/08/23 16:23:54 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/08/23 12:20:03 | 000,000,040 | -HS- | C] () – C:\ProgramData\.zreglib
[2010/08/23 11:52:37 | 000,033,792 | —- | C] () – C:\Windows\System32\drivers\libusb0.sys
[2010/08/20 08:19:08 | 000,000,127 | —- | C] () – C:\Windows\System32\MRT.INI
[2010/07/30 20:58:53 | 000,014,324 | —- | C] () – C:\Users\Admin\AppData\Roaming\UserTile.png
[2010/07/30 17:26:09 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2009/07/29 17:08:53 | 000,691,696 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2009/06/10 06:31:04 | 000,089,088 | —- | C] () – C:\Windows\System32\nvimage.dll
[2009/05/17 17:01:04 | 000,000,064 | —- | C] () – C:\Users\Admin\AppData\Roaming\GPRSUAC.ini
[2009/04/14 14:17:21 | 000,001,024 | —- | C] () – C:\Users\Admin\AppData\Roaming\WavCodec.wff
[2009/04/13 11:37:18 | 000,002,554 | —- | C] () – C:\Windows\WAVEMIX.INI
[2009/04/13 11:37:18 | 000,000,165 | —- | C] () – C:\Windows\SimTower.ini
[2009/04/08 00:32:46 | 000,000,027 | —- | C] () – C:\Windows\System32\VideoGenieSetup.ini
[2009/03/26 18:24:44 | 000,000,680 | —- | C] () – C:\Users\Admin\AppData\Local\d3d9caps.dat
[2009/03/15 20:33:09 | 000,000,025 | —- | C] () – C:\Windows\SIERRA.INI
[2009/03/15 20:32:22 | 000,021,840 | —- | C] () – C:\Windows\System32\SIntfNT.dll
[2009/03/15 20:32:22 | 000,017,212 | —- | C] () – C:\Windows\System32\SIntf32.dll
[2009/03/15 20:32:22 | 000,012,067 | —- | C] () – C:\Windows\System32\SIntf16.dll
[2009/03/10 09:45:01 | 000,000,568 | —- | C] () – C:\Users\Admin\AppData\Roaming\AutoGK.ini
[2009/02/08 19:30:05 | 000,001,722 | —- | C] () – C:\Users\Admin\AppData\Roaming\wklnhst.dat
[2009/02/08 14:31:26 | 000,010,240 | —- | C] () – C:\Windows\System32\vidx16.dll
[2009/02/07 21:02:03 | 000,169,472 | —- | C] () – C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/30 18:09:32 | 000,031,871 | —- | C] () – C:\ProgramData\nvModes.001
[2009/01/30 18:09:29 | 000,031,871 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/01/17 16:56:11 | 000,006,596 | —- | C] () – C:\Users\Admin\AppData\Roaming\NMM-MetaData.db
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2008/06/05 08:58:26 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/04/25 16:23:38 | 000,012,288 | —- | C] () – C:\Windows\System32\EvOnlDiag.dll
[2007/08/14 16:35:24 | 000,389,120 | —- | C] () – C:\Windows\System32\btwhidcs.dll
[2007/03/29 23:00:40 | 000,203,264 | R— | C] () – C:\Windows\System32\CddbCdda.dll
[2006/11/02 14:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 09:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2001/11/14 13:56:00 | 001,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll

========== LOP Check ==========

[2009/05/22 14:09:41 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Ableton
[2010/10/09 18:47:58 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Audacity
[2010/09/29 12:13:59 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/02/20 21:17:33 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Command & Conquer 3 Tiberium Wars
[2009/05/14 18:28:02 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\CoSoSys
[2009/07/30 12:28:21 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\DAEMON Tools
[2010/08/16 16:41:39 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\DAEMON Tools Lite
[2010/08/08 22:32:46 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\DAEMON Tools Pro
[2010/10/25 21:37:19 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Dropbox
[2010/08/27 16:47:19 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Foxit Software
[2010/10/01 13:44:58 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\GARMIN
[2010/08/18 19:00:58 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\GrabPro
[2009/02/07 21:58:18 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\iWin
[2010/09/02 11:00:02 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\KC Softwares
[2010/08/18 19:18:09 | 000,000,000 | RHSD | M] – C:\Users\Admin\AppData\Roaming\licenses
[2010/10/19 20:01:33 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mp3tag
[2010/09/11 12:17:37 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\NCH Swift Sound
[2009/01/17 16:56:11 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Nokia
[2009/02/02 00:48:35 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Nokia Multimedia Player
[2010/10/27 21:20:12 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Orbit
[2010/09/29 15:50:34 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\PC Suite
[2010/07/30 20:58:52 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\PeerNetworking
[2009/07/27 16:09:00 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\PopCapv1002
[2009/04/13 12:02:53 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\PopCapv1005eni
[2010/08/18 19:21:40 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\ProgSense
[2009/07/02 22:13:32 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Publish Providers
[2010/06/25 13:29:26 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\RipIt4Me
[2010/06/26 20:01:28 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Sony
[2010/09/29 16:16:03 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2009/03/01 17:30:57 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Template
[2009/07/29 15:29:33 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\TuneUp Software
[2009/06/07 15:59:49 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Uniblue
[2009/04/09 20:31:45 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\VBA-M
[2010/11/03 18:19:14 | 000,000,508 | —- | M] () – C:\Windows\Tasks\1-Click Maintenance.job
[2010/11/03 17:17:37 | 000,032,572 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 155 bytes -> C:\ProgramData\TEMP:343FF046

< End of report >


OTL Extras logfile created on: 2010/11/03 06:30:04 PM - Run 1
OTL by OldTimer - Version 3.2.17.2 Folder = D:\Users\Admin\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00001C09 | Country: South Africa | Language: ENS | Date Format: yyyy/MM/dd

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 64.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 76.00 Gb Total Space | 16.62 Gb Free Space | 21.87% Space Free | Partition Type: NTFS
Drive D: | 213.30 Gb Total Space | 11.80 Gb Free Space | 5.53% Space Free | Partition Type: NTFS

Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.js [@ = Reg Error: Value error.] – Reg Error: Key error. File not found
.txt [@ = Reg Error: Value error.] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – D:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "D:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "D:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "D:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – D:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "D:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [TVersity] – "C:\Users\Admin\AppData\Local\TVersity\Media Server\GUILaunch.exe" -type "folder" -url "%1" -title "" -tags "" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"d:\Program Files\Orbitdownloader\orbitdm.exe" = d:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"d:\Program Files\Orbitdownloader\orbitnet.exe" = d:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit – (Orbitdownloader.com)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{010A52B5-1503-4AA2-815F-5E607C3182B3}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{017D5C4E-CA03-41DD-860A-795E5DA26E02}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0A008A25-8891-4ACB-9041-38FFC16E80ED}" = lport=10243 | protocol=6 | dir=in | app=system |
"{0F9B9839-9137-446F-A9B7-2A514D3A0F77}" = lport=2869 | protocol=6 | dir=in | app=system |
"{10DBC619-53BD-4DF2-9B01-BBCFFBFC789C}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{1B63DDA3-1A2D-49B0-8766-43851AB9596E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2174F2A4-642A-43D6-8F9D-4D169F02C918}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2B9C56EA-794B-46E2-AA1C-F00C9E68AB55}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{452BE090-F2C6-4659-98FB-00A8E9422F93}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{47078F47-9658-4FC2-A086-C189389C5A58}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{4AE81D53-3CF4-45E5-870E-37E270364CBB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5653D1A0-D88A-4393-9038-4AD95D37F5E3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6426DE85-DAD0-455C-B118-2BED2723C65B}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{68A34F69-A932-454F-8A33-CC2AA5F6B87E}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{6F8E9CF7-18B0-41B8-BCE2-89083590906C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6F8EF1D7-6955-4900-AA84-38168108596D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8981149E-3C68-4A67-954F-FF0E33F389A5}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{8D280A15-B5B3-460D-87D0-BE16821219A2}" = rport=10243 | protocol=6 | dir=out | app=system |
"{9B3FABD1-85FE-4DCF-8265-74FCDD2B429C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A4CF896C-0CC7-4D63-BA47-0614CE23ABB5}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{ACD881DD-4A0B-4D85-A3D7-51625FCC9F17}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{B0816E85-E213-4057-AE5A-67F42D48D95C}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{BA00934C-7955-4F9D-AEDE-3F55C2DFD976}" = lport=6004 | protocol=17 | dir=in | app=d:\program files\microsoft office\office12\outlook.exe |
"{C30E763D-FE74-403E-952C-BAD4A80B2860}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{C4F14115-DA3A-48AE-8857-277B341DE530}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D23FACA4-D971-4F8D-8B44-64D330EAD1E0}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D39BC4AA-56FD-4FC6-A51F-AF30FB55598A}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{DD380062-A053-42C5-99A1-9F132D7BDF0A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E6CE22DD-5C59-463F-AE3C-C92DE6212302}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F61D9B4F-0B2B-4864-A762-C8CFC7DF0234}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01A0E047-B5B9-42F9-B586-EE0C2274D1EB}" = protocol=6 | dir=in | app=c:\users\admin\appdata\local\temp\~os5a12.tmp\rlvknlg.exe |
"{029CE5DC-7A35-4447-A56B-EB9DC5A99E99}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{03537E98-9783-40F1-B476-9CCAEC1B3A68}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0A5F7222-FBC8-481A-A5D5-FEE2177C8896}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{126BDA01-BA2F-4061-A10A-1C57ED2F01F5}" = dir=in | app=c:\program files\electronic arts\command & conquer 3\retailexe\1.0\cnc3game.dat |
"{2005C06F-60B1-4C9A-962C-9F45228A8873}" = protocol=17 | dir=in | app=c:\program files\microsoft games\dungeon siege 2\dungeonsiege2.exe |
"{25A1EFBE-D4FC-4DAC-A655-DFCA19BFDB6D}" = protocol=6 | dir=in | app=d:\program files\itunes\itunes.exe |
"{26ECF40B-82E5-443F-BEDC-8BAC721ABA6E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3006944B-54E4-40CD-9830-CEE31FFB4D15}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{35A42432-7F65-49AC-A2B9-DA71C4BFBC96}" = protocol=6 | dir=in | app=c:\users\admin\appdata\roaming\dropbox\bin\dropbox.exe |
"{4072CBC3-219B-48F1-986A-EE0B8B9239B2}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{4415E845-9CA6-4D18-9266-3BA536280DC2}" = protocol=6 | dir=out | app=system |
"{4F998EC3-2A7C-4904-A610-65C504F81622}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{541E312B-AEF2-4FD2-97B2-E1A5A207CA27}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{6A032606-225E-4A43-B7E2-C642A2358E47}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{6DB07A9D-E782-41FF-B19C-F9445A11703A}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{6E739134-2248-4FA4-8BCC-36C440DB5FD8}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{6FC9AE88-960C-4EBB-BCE5-6F141210439E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7069E2B6-8352-416D-87ED-709CA9849A34}" = protocol=17 | dir=in | app=c:\users\admin\appdata\local\tversity\media server\mediaserver.exe |
"{7674B8CD-F682-47E4-8999-873E3636FF49}" = protocol=17 | dir=in | app=d:\program files\frostwire\frostwire.exe |
"{7B3CB058-9691-472B-AFBB-230D015A24FE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{838D9553-86CD-4738-A5D7-AA4B019B602E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{840EEC3F-0A35-4929-B7ED-708730FF6937}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{86B3841E-2652-4BB7-9237-782607E2C6E0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{8E47882E-7CF6-4D0D-90D9-6D7FFFB595C7}" = protocol=6 | dir=in | app=d:\program files\frostwire\frostwire.exe |
"{96BBADAB-C5D9-40C2-B254-889552C09158}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{97B8D886-42E1-4246-8161-8AA5F84472BC}" = protocol=17 | dir=in | app=c:\users\admin\appdata\roaming\dropbox\bin\dropbox.exe |
"{C8BDA7FC-2AC9-45A2-AD09-31397D4B9577}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{C90AECF4-C33C-46FC-955B-357DA0DB2F36}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E564E0D1-864C-48E6-9BB8-732BA4D521D1}" = protocol=6 | dir=in | app=c:\users\admin\appdata\local\tversity\media server\mediaserver.exe |
"{E5FF1FDB-31CD-4F95-B890-48069197D8B7}" = protocol=17 | dir=in | app=d:\program files\itunes\itunes.exe |
"{EFD21019-2202-4D16-8FDC-422D8E886BF3}" = protocol=6 | dir=in | app=c:\program files\microsoft games\dungeon siege 2\dungeonsiege2.exe |
"{F257C99D-AB14-48B5-9967-4362E13BD162}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{2365559B-0531-4C5F-9670-9507BCB2B065}D:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=d:\program files\mozilla firefox\firefox.exe |
"TCP Query User{50511DC7-1528-4F94-918F-7B22B62917EB}D:\program files\musicbrainz picard\picard.exe" = protocol=6 | dir=in | app=d:\program files\musicbrainz picard\picard.exe |
"TCP Query User{AB404709-E06A-4B91-A4E8-0E876823CE76}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"TCP Query User{AED02F83-EBE6-442E-9B8D-7286FE321D91}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{B48F2A79-14B8-41E0-845C-1991919EF0D8}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{CD3FE4EC-9075-402B-8763-D85C377ED227}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{ECA21325-0323-4D3D-9BE3-21A46AFCA332}D:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=d:\program files\mozilla firefox\firefox.exe |
"TCP Query User{F4F9F111-B42E-4E19-AA8E-A754259B4ADA}D:\program files\dc++\dcplusplus.exe" = protocol=6 | dir=in | app=d:\program files\dc++\dcplusplus.exe |
"UDP Query User{0056195B-A82C-407E-AC67-0134B392F466}D:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=d:\program files\mozilla firefox\firefox.exe |
"UDP Query User{11F4DC77-DEE8-424B-A07B-81EA25982F53}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{4DA5C8C4-6D74-45A7-AC89-7BB4F52499CA}D:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=d:\program files\mozilla firefox\firefox.exe |
"UDP Query User{653A51B3-489F-4D9B-903F-875728F72526}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{B3775C90-0D11-4570-AEC0-4086289119CF}D:\program files\musicbrainz picard\picard.exe" = protocol=17 | dir=in | app=d:\program files\musicbrainz picard\picard.exe |
"UDP Query User{B6B997EB-C274-457B-9AB5-BD104477C142}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{C5F21D4E-B0C6-4DC7-B293-26AFA891EE0B}D:\program files\dc++\dcplusplus.exe" = protocol=17 | dir=in | app=d:\program files\dc++\dcplusplus.exe |
"UDP Query User{F7689D61-C6A2-4475-887A-705AB0C9DD0D}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.5400
"{06680048-3E21-46D6-9A91-D927BA08F41D}" = Microsoft Encarta Standard 2006
"{06A1BE8A-4CA4-4A39-B9E4-E815AA8FE05C}" = Sony Noise Reduction Plug-In 2.0h
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{171E6C1E-B5FC-11DF-B115-005056C00008}" = Google Earth Plug-in
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{2A0A6470-FD0F-4F45-9B11-85F3167DB943}" = Nokia Flashing Cable Driver
"{2F926AE7-9FB7-4B34-906F-9C29A6D146A7}" = SystemDiagnostics
"{373C3C97-2FA9-4E18-85A2-255060C21033}" = Nero 8 Essentials
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{60B8D26D-5D6D-21D5-0366-3664E5DE3471}" = ATI Catalyst Install Manager
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6CDC68BB-C997-4ADC-9BA0-6293FB88521E}" = Sonic Foundry Sound Forge 6.0a
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROHYBRIDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9BE2669E-2BD8-4164-A8B5-C904C864B403}" = WA Update v3.50 beta2
"{9C05FA75-0337-4523-AA57-9D3511018887}" = Nokia PC Suite
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A563C4F4-BE36-4956-BA0B-E02BDD9F70D5}" = Dungeon Siege 2 Broken World
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AFC454ED-A26F-4816-826B-C35129D82E1F}" = Fujitsu Siemens Computers Recovery
"{B0C30E93-D3D9-4F04-A2AC-54749B573275}" = Command & Conquer 3
"{B132E67C-EEA5-492B-B368-543CD88D8569}" = AnyDVD Registration
"{B6AA55E6-9228-4392-A19E-593339BC1BE1}" = Garmin ANT Agent
"{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CBDE9C7D-CF52-4558-B23E-B66359CB586A}" = Nokia Connectivity Cable Driver
"{CC6B1BB4-4E06-4A5B-A166-B371B551324B}" = COMODO Internet Security
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DFBABF95-AB6F-4843-BEEE-B6560F355BC2}" = Billion 400G
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{EC2A8F27-4FBF-4E41-B27B-FE822511B761}" = iTunes
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FE4086E1-FA7F-4A7A-8FC5-061337B5787E}" = PS3.ProxyServer
"24DA573F901348FFDFF7717497830D45BE0C362E" = Windows Driver Package - Dynastream Innovations (libusb0) LibUsbDevices (07/07/2009 1.12.2)
"3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0)
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AutoGK" = Auto Gordian Knot 2.55
"AviSynth" = AviSynth 2.5
"CBF192A85B624E32B8D19ADEEF2DCFC5BC3AA73A" = Windows Driver Package - Nokia Modem (03/05/2008 3.7)
"CCleaner" = CCleaner
"ClassicPro" = ClassicPro© v1.15
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"DMX5_is1" = DriverMax 5
"DungeonSiege2" = Dungeon Siege 2
"DVD Shrink_is1" = DVD Shrink 3.2
"E092B2EBF2FFE83E896F8F7F829A7B5D7D1B2F9D" = Windows Driver Package - Nokia Modem (03/13/2008 6.86.0.1)
"EAX™ Unified (SHELL)" = EAX™ Unified (SHELL)
"ExpressBurn" = Express Burn Disc Burning Software
"ffdshow_is1" = ffdshow [rev 3154] [2009-12-09]
"FL Studio 7" = FL Studio 7
"Foxit Reader" = Foxit Reader
"Free DVD Video Burner_is1" = Free DVD Video Burner version 2.4
"Free Video to DVD Converter_is1" = Free Video to DVD Converter version 1.6
"Free Video to MP3 Converter_is1" = Free Video to MP3 Converter version 4.0
"Hide My MAC Address_is1" = Hide My MAC Address 2.2
"HMIP50_is1" = Hide My IP 5.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IsoBuster_is1" = IsoBuster 2.8
"KC Softwares SUMo_is1" = KC Softwares SUMo
"LameACM" = Lame ACM MP3 Codec
"Live 7.0.14" = Live 7.0.14
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MixMeister BPM Analyzer_is1" = MixMeister BPM Analyzer 1.0
"Mozilla Firefox (3.6.11)" = Mozilla Firefox (3.6.11)
"Mp3tag" = Mp3tag v2.46a
"Nokia PC Suite" = Nokia PC Suite
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Orbit_is1" = Orbit Downloader
"PROHYBRIDR" = 2007 Microsoft Office system
"RAR Repair Tool_is1" = RAR Repair Tool v.4.0
"RealAlt_is1" = Real Alternative 2.0.2 Lite
"RegistryBooster 2_is1" = Uniblue RegistryBooster 2
"Revo Uninstaller" = Revo Uninstaller 1.89
"Shockwave" = Shockwave
"Switch" = Switch Sound File Converter
"TVersity Codec Pack" = TVersity Codec Pack 1.4
"TVersity Media Server" = TVersity Media Server 1.9.2
"Uninstall_is1" = Uninstall 1.0.0.1
"Virtual DJ Pro Full - Atomix Productions" = Virtual DJ Pro Full - Atomix Productions
"VLC media player" = VLC media player 1.1.3
"VobSub" = VobSub v2.23 (Remove Only)
"Winamp" = Winamp
"XviD MPEG4 Video Codec" = XviD MPEG4 Video Codec (remove only)
"Xvid_is1" = Xvid 1.2.2 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"419506f87bc706d3" = MXit EVO
"Billion 400G" = Billion 400G
"Dropbox" = Dropbox
"Mozilla Firefox (3.6.12)" = Mozilla Firefox (3.6.12)
"mpowerplayer" = mpowerplayer
"Prism" = Prism Video File Converter
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2010/11/02 04:20:11 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =

Error - 2010/11/02 04:20:39 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =

Error - 2010/11/02 04:21:11 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =

Error - 2010/11/02 04:21:33 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =

Error - 2010/11/02 04:31:31 AM | Computer Name = Admin-PC | Source = WinMgmt | ID = 10
Description =

Error - 2010/11/02 04:33:34 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =

Error - 2010/11/02 04:34:46 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =

Error - 2010/11/02 04:36:03 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =

Error - 2010/11/02 08:09:10 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =

Error - 2010/11/02 08:53:26 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =

[ OSession Events ]
Error - 2009/02/09 02:24:04 PM | Computer Name = Admin-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 44
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 2010/11/03 11:19:39 AM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 2010/11/03 11:19:39 AM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 2010/11/03 11:19:39 AM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 2010/11/03 11:19:46 AM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 2010/11/03 12:19:01 PM | Computer Name = Admin-PC | Source = HTTP | ID = 15016
Description =

Error - 2010/11/03 12:19:14 PM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7023
Description =

Error - 2010/11/03 12:20:38 PM | Computer Name = Admin-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =

Error - 2010/11/03 12:21:09 PM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 2010/11/03 12:21:15 PM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 2010/11/03 12:21:18 PM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7001
Description =


< End of report >

Whoa. A plethora of information up there :wacko:
Hi,

Your infected with the TDSS Rootkit, this is nasty and has to go. Malwarebytes got part of it but not all.

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2


[external image: Posted Image]


[external image: Posted Image]

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
New HijackThis Log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 08:39:02 PM, on 2010/11/03
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18498)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\wuauclt.exe
D:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Users\Admin\Desktop\New Folder\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - d:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - d:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WinampAgent] "D:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "D:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "d:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: &Download by Orbit - res://d:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://d:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://d:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://d:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6D15009E-C521-4553-AFCE-95D4F8251E0E}: NameServer = 168.210.2.2 196.14.239.2
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - D:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HideMyIpSRV - HideMyIP - D:\Program Files\Hide My IP\HideMyIpSrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - d:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Windows\System32\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: TVersityMediaServer - Unknown owner - C:\Users\Admin\AppData\Local\TVersity\Media Server\MediaServer.exe

–
End of file - 6883 bytes


Just thought i should give a mention that after the restart, any application i try to open gives an error message stating: "Illegal operation attempted on a registry key that has been marked for deletion"

Had to run Firefox by opting to "Run as administrator" Is this normal?


ComboFix 10-11-02.06 - Admin 2010/11/03 20:23:13.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.27.1033.18.1919.1183 [GMT 2:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
AV: Norman Security Suite ver. 7.00 *On-access scanning disabled* (Updated) {EB9EFB40-AE72-4C43-B204-0FCD0E92D5F1}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Admin\AppData\Roaming\SQLite3.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ovfsthifysemymjbksxgnuhtphivqpyppmratt
——-\Service_ovfsthifysemymjbksxgnuhtphivqpyppmratt


((((((((((((((((((((((((( Files Created from 2010-10-03 to 2010-11-03 )))))))))))))))))))))))))))))))
.

2010-11-02 17:29 . 2010-11-02 17:29 ——– d—–w- c:\program files\CF3B5
2010-10-31 17:53 . 2010-10-31 17:53 ——– d—–w- c:\program files\CCleaner
2010-10-31 11:55 . 2010-10-31 11:55 ——– d—–w- c:\users\Admin\AppData\Roaming\Malwarebytes
2010-10-31 11:54 . 2010-04-29 13:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-31 11:54 . 2010-10-31 11:54 ——– d—–w- c:\programdata\Malwarebytes
2010-10-31 11:54 . 2010-04-29 13:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-10-30 14:38 . 2010-06-15 16:27 282928 —-a-w- c:\windows\system32\HMIPCore.dll
2010-10-30 13:48 . 2010-10-30 13:48 ——– d—–w- c:\windows\Sun
2010-10-30 13:15 . 2009-01-22 00:40 163840 —-a-w- c:\windows\system32\SecureNet.dll
2010-10-30 12:50 . 2009-07-24 00:44 485920 —-a-w- c:\windows\system32\nvusmb.exe
2010-10-30 12:50 . 2009-07-24 00:44 155648 —-a-w- c:\windows\system32\NVCOSMB.DLL
2010-10-30 09:17 . 2010-10-30 12:13 ——– d—–w- C:\Hotspot Shield
2010-10-25 19:18 . 2010-10-25 19:37 ——– d—–w- c:\users\Admin\AppData\Roaming\Dropbox
2010-10-25 16:58 . 2010-10-25 16:58 ——– d—–w- c:\program files\DVDVideoSoft
2010-10-22 09:12 . 2009-12-05 17:42 85504 —-a-w- c:\windows\system32\ff_vfw.dll
2010-10-22 08:54 . 2010-10-22 08:54 ——– d—–w- c:\program files\TVersity Codec Pack
2010-10-22 08:54 . 2010-10-22 08:54 ——– d—–w- c:\users\Admin\AppData\Local\TVersity
2010-10-21 13:26 . 2010-10-21 13:26 ——– d—–w- c:\programdata\Trusteer
2010-10-20 17:43 . 2010-10-20 17:43 ——– d—–w- c:\users\Admin\.microemulator
2010-10-19 10:18 . 2007-07-16 00:20 16168 —-a-w- c:\windows\system32\drivers\btwrchid.sys
2010-10-19 10:18 . 2007-07-16 00:20 80936 —-a-w- c:\windows\system32\drivers\btwavdt.sys
2010-10-19 10:18 . 2007-07-16 00:20 79400 —-a-w- c:\windows\system32\drivers\btwaudio.sys
2010-10-19 10:18 . 2007-08-14 08:52 233472 —-a-w- c:\windows\system32\BtwRSupport.dll
2010-10-19 10:18 . 2010-10-19 10:18 ——– d—–w- c:\windows\system32\es-MX
2010-10-19 10:18 . 2010-10-19 10:18 ——– d—–w- c:\windows\system32\es-AR
2010-10-12 04:54 . 2010-10-12 04:54 74703 —-a-w- c:\windows\system32\mfc45.dll
2010-10-09 17:40 . 2009-04-27 12:21 28928 —-a-w- c:\windows\system32\uxtuneup.dll
2010-10-09 17:06 . 2010-10-09 17:06 ——– d—–w- c:\program files\DivX
2010-10-09 17:01 . 2010-10-09 17:02 ——– d—–w- c:\programdata\DivX
2010-10-09 16:50 . 2010-10-09 17:24 ——– d—–w- c:\program files\TuneUp Utilities 2009

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-22 12:43 . 2010-06-01 17:00 78504 —-a-w- c:\windows\system32\drivers\inspect.sys
2010-10-04 19:01 . 2010-06-01 17:00 285480 —-a-w- c:\windows\system32\guard32.dll
2010-10-04 19:00 . 2010-06-01 17:00 30112 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-10-04 19:00 . 2010-06-01 17:00 17256 —-a-w- c:\windows\system32\drivers\cmderd.sys
2010-10-04 19:00 . 2010-06-04 09:55 236088 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2010-09-22 19:19 . 2010-09-22 19:19 32768 —-a-w- c:\windows\system32\drivers\taphss.sys
2010-08-28 10:18 . 2009-04-13 09:37 73216 —-a-w- c:\windows\ST6UNST.EXE
2010-08-28 10:18 . 2009-04-13 09:37 249856 ——w- c:\windows\Setup1.exe
2010-08-26 08:39 . 2010-08-26 08:39 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-08-18 15:07 . 2010-08-18 15:07 38976 —-a-w- c:\windows\system32\drivers\pssdk42.sys
2010-08-15 10:37 . 2009-07-29 15:08 691696 —-a-w- c:\windows\system32\drivers\sptd.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-28 6144000]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13785632]
"WinampAgent"="d:\program files\Winamp\winampa.exe" [2010-07-12 74752]
"COMODO Internet Security"="d:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-10-04 2500552]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Malwarebytes' Anti-Malware"="d:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-8-14 727592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PC Suite Tray"="d:\program files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
"SUPERAntiSpyware"=c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
"DriverMax_RESTART"="d:\program files\Innovative Solutions\DriverMax\devices.exe" -RESTART
"ANT Agent"=c:\program files\Garmin\ANT Agent\ANT Agent.exe
"HKCU"=c:\windows\System32\Microsoft_KB57H43\Microsoft_KB57H43.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"FSCRecovery"=c:\program files\Fujitsu Siemens Computers\Fujitsu Siemens Computers Recovery\FSCRecoveryReminder.exe
"FSCRecoveryCleanUp"=c:\program files\Fujitsu Siemens Computers\Fujitsu Siemens Computers Recovery\FSCRecoveryCleanUp.exe
"iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe"
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"SwitchBoard"=c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
"HKLM"=c:\windows\system32\Microsoft_KB57H43\Microsoft_KB57H43.exe

R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-09-20 136176]
R3 ATP;Comodo EasyVPN Miniport Driver;c:\windows\system32\DRIVERS\cmdatp.sys [x]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x]
R3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28u.sys [x]
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2008-02-01 138112]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2008-02-01 8320]
R3 pbfilter;pbfilter;d:\program files\PeerBlock\pbfilter.sys [x]
R3 PSSDK42;PSSDK42;c:\windows\system32\Drivers\pssdk42.sys [2010-08-18 38976]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-08-15 691696]
S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys [2010-10-04 17256]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2010-10-04 236088]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2010-10-04 30112]
S2 MBAMService;MBAMService;d:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-04-29 304464]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\windows\System32\nvSCPAPISvr.exe [2009-06-10 232960]
S3 HideMyIpSRV;HideMyIpSRV;d:\program files\Hide My IP\HideMyIpSrv.exe [2010-07-06 3039536]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-04-29 20952]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-11-03 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:37]

2010-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-20 20:44]

2010-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-20 20:44]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.yahoo.com
IE: &Download by Orbit - d:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - d:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - d:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - d:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\windows\system32\HMIPCore.dll
TCP: {6D15009E-C521-4553-AFCE-95D4F8251E0E} = 168.210.2.2 196.14.239.2
FF - ProfilePath - c:\users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-fp&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - search.yahoo.com
FF - prefs.js: network.proxy.ftp - [removed]
FF - prefs.js: network.proxy.ftp_port - 80
FF - prefs.js: network.proxy.gopher - [removed]
FF - prefs.js: network.proxy.gopher_port - 80
FF - prefs.js: network.proxy.http - [removed]
FF - prefs.js: network.proxy.http_port - 80
FF - prefs.js: network.proxy.socks - [removed]
FF - prefs.js: network.proxy.socks_port - 80
FF - prefs.js: network.proxy.ssl - 217.23.137.56
FF - prefs.js: network.proxy.ssl_port - 80
FF - prefs.js: network.proxy.type - 0
FF - component: d:\program files\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: d:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: d:\program files\Real Alternative\browser\plugins\nppl3260.dll
FF - plugin: d:\program files\Real Alternative\browser\plugins\nprpjplug.dll
FF - plugin: d:\program files\VideoLAN\VLC\npvlc.dll

—- FIREFOX POLICIES —-
d:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
d:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
d:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
d:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
.txt=
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKU-Default-Run-fsc-reg - c:\fsc-reg\fscreg.exe



**************************************************************************
scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1097220164-287428032-609269875-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{393AA24A-B2E8-10DC-527E-1CCD3A1A9537}*]
"mabfmloflcpanelnpkdflnmhan"=hex:6f,61,61,64,69,65,6b,6a,64,70,68,64,70,6d,6e,
70,66,64,6f,6a,6d,6d,69,66,6a,70,63,69,6d,6f,00,00
"abafjmhapchpldmcpomkkbdaadimdcgeid"=hex:69,61,70,66,6e,63,6c,64,70,6c,61,66,
67,65,64,62,66,66,00,00

[HKEY_USERS\S-1-5-21-1097220164-287428032-609269875-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:1c,af,8a,0b,75,ff,3a,fb,10,20,88,45,b6,f2,e7,f6,c8,7f,5f,41,7f,c0,71,
74,38,fe,ae,57,99,1f,c9,4c,7e,b0,39,fd,34,ba,d6,75,42,f0,2e,b9,85,c0,3b,f3,\
"??"=hex:ea,13,2c,15,ee,18,2d,24,c8,b1,25,31,05,0c,1c,71

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0011\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0012\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0013\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(720)
c:\windows\system32\guard32.dll

- - - - - - - > 'Explorer.exe'(3368)
c:\windows\system32\guard32.dll
c:\users\Admin\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\btncopy.dll
d:\program files\Nokia\Nokia PC Suite 6\phonebrowser.dll
d:\program files\Nokia\Nokia PC Suite 6\NGSCM.DLL
d:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr
d:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvvsvc.exe
d:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
c:\users\Admin\AppData\Local\TVersity\Media Server\MediaServer.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\conime.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2010-11-03 20:35:11 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-03 18:34

Pre-Run: 17 489 002 496 bytes free
Post-Run: 17 254 309 888 bytes free

- - End Of File - - 7AA6D378E94126A53E553A3B1A682B88

Attachments:

TDSSKiller Log: 2010/11/04 16:49:31.0006 TDSS rootkit removing tool 2.4.6.0 Nov 3 2010 10:11:43 2010/11/04 16:49:31.0006 ================================================================================ 2010/11/04 16:49:31.0006 SystemInfo: 2010/11/04 16:49:31.0006 2010/11/04 16:49:31.0006 OS Version: 6.0.6001 ServicePack: 1.0 2010/11/04 16:49:31.0006 Product type: Workstation 2010/11/04 16:49:31.0006 ComputerName: ADMIN-PC 2010/11/04 16:49:31.0006 UserName: Admin 2010/11/04 16:49:31.0006 Windows directory: C:\Windows 2010/11/04 16:49:31.0006 System windows directory: C:\Windows 2010/11/04 16:49:31.0006 Processor architecture: Intel x86 2010/11/04 16:49:31.0006 Number of processors: 2 2010/11/04 16:49:31.0006 Page size: 0x1000 2010/11/04 16:49:31.0006 Boot type: Normal boot 2010/11/04 16:49:31.0006 ================================================================================ 2010/11/04 16:49:31.0552 Initialize success 2010/11/04 16:49:37.0137 ================================================================================ 2010/11/04 16:49:37.0137 Scan started 2010/11/04 16:49:37.0137 Mode: Manual; 2010/11/04 16:49:37.0137 ================================================================================ 2010/11/04 16:49:38.0120 ACPI (fcb8c7210f0135e24c6580f7f649c73c) C:\Windows\system32\drivers\acpi.sys 2010/11/04 16:49:38.0182 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 2010/11/04 16:49:38.0213 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 2010/11/04 16:49:38.0260 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 2010/11/04 16:49:38.0291 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 2010/11/04 16:49:38.0338 AFD (763e172a55177e478cb419f88fd0ba03) C:\Windows\system32\drivers\afd.sys 2010/11/04 16:49:38.0369 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 2010/11/04 16:49:38.0416 ahcix86s (fbe4016f9ef3ab3db547e40a936b6cd9) C:\Windows\system32\drivers\ahcix86s.sys 2010/11/04 16:49:38.0447 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 2010/11/04 16:49:38.0478 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 2010/11/04 16:49:38.0510 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 2010/11/04 16:49:38.0541 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 2010/11/04 16:49:38.0556 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 2010/11/04 16:49:38.0588 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys 2010/11/04 16:49:38.0650 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 2010/11/04 16:49:38.0681 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 2010/11/04 16:49:38.0744 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 2010/11/04 16:49:38.0775 atapi (9c0e70031905adbf94edb9ea14af943b) C:\Windows\system32\drivers\atapi.sys 2010/11/04 16:49:38.0868 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 2010/11/04 16:49:38.0915 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 2010/11/04 16:49:39.0040 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys 2010/11/04 16:49:39.0071 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 2010/11/04 16:49:39.0102 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 2010/11/04 16:49:39.0149 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 2010/11/04 16:49:39.0180 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 2010/11/04 16:49:39.0212 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 2010/11/04 16:49:39.0243 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 2010/11/04 16:49:39.0274 BthEnum (da7b195275bda7f8fcf79b40e0f45dde) C:\Windows\system32\DRIVERS\BthEnum.sys 2010/11/04 16:49:39.0321 BTHMODEM (5ffa6988ff9597986ff2ada736cc90c0) C:\Windows\system32\DRIVERS\bthmodem.sys 2010/11/04 16:49:39.0352 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys 2010/11/04 16:49:39.0383 BTHPORT (73d53f8e90550ba81e2cf44a0873b410) C:\Windows\system32\Drivers\BTHport.sys 2010/11/04 16:49:39.0430 BTHUSB (32045a4bb143bbc5bab1298c4e9e309a) C:\Windows\system32\Drivers\BTHUSB.sys 2010/11/04 16:49:39.0508 btwaudio (e6f8c2b62b9eb57d41c0b2c5fd3078a0) C:\Windows\system32\drivers\btwaudio.sys 2010/11/04 16:49:39.0617 btwavdt (195872e48a7fb01f8bc9b800f70f4054) C:\Windows\system32\drivers\btwavdt.sys 2010/11/04 16:49:39.0726 btwrchid (0724e7d6c9b6a289eddda33fa8176e80) C:\Windows\system32\DRIVERS\btwrchid.sys 2010/11/04 16:49:39.0789 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 2010/11/04 16:49:39.0836 cdrom (1ec25cea0de6ac4718bf89f9e1778b57) C:\Windows\system32\DRIVERS\cdrom.sys 2010/11/04 16:49:39.0898 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 2010/11/04 16:49:39.0929 CLFS (465745561c832b29f7c48b488aab3842) C:\Windows\system32\CLFS.sys 2010/11/04 16:49:39.0992 cmderd (b7674a33153d027403032f79e831ee92) C:\Windows\system32\DRIVERS\cmderd.sys 2010/11/04 16:49:40.0038 cmdGuard (594002171dd9f6f8a1600174f1e20efd) C:\Windows\system32\DRIVERS\cmdguard.sys 2010/11/04 16:49:40.0085 cmdHlp (190959127a956528d14fb9bc056241b3) C:\Windows\system32\DRIVERS\cmdhlp.sys 2010/11/04 16:49:40.0132 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 2010/11/04 16:49:40.0148 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys 2010/11/04 16:49:40.0350 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 2010/11/04 16:49:40.0397 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 2010/11/04 16:49:40.0444 DfsC (9e635ae5e8ad93e2b5989e2e23679f97) C:\Windows\system32\Drivers\dfsc.sys 2010/11/04 16:49:40.0491 disk (64109e623abd6955c8fb110b592e68b7) C:\Windows\system32\drivers\disk.sys 2010/11/04 16:49:40.0569 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 2010/11/04 16:49:40.0616 DXGKrnl (85f33880b8cfb554bd3d9ccdb486845a) C:\Windows\System32\drivers\dxgkrnl.sys 2010/11/04 16:49:40.0678 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 2010/11/04 16:49:40.0725 Ecache (dd2cd259d83d8b72c02c5f2331ff9d68) C:\Windows\system32\drivers\ecache.sys 2010/11/04 16:49:40.0787 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 2010/11/04 16:49:40.0818 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 2010/11/04 16:49:40.0881 exfat (0d858eb20589a34efb25695acaa6aa2d) C:\Windows\system32\drivers\exfat.sys 2010/11/04 16:49:40.0912 fastfat (3c489390c2e2064563727752af8eab9e) C:\Windows\system32\drivers\fastfat.sys 2010/11/04 16:49:40.0943 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 2010/11/04 16:49:41.0006 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 2010/11/04 16:49:41.0021 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 2010/11/04 16:49:41.0052 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 2010/11/04 16:49:41.0084 FltMgr (05ea53afe985443011e36dab07343b46) C:\Windows\system32\drivers\fltmgr.sys 2010/11/04 16:49:41.0130 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 2010/11/04 16:49:41.0177 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 2010/11/04 16:49:41.0208 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 2010/11/04 16:49:41.0255 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys 2010/11/04 16:49:41.0286 HDAudBus (c87b1ee051c0464491c1a7b03fa0bc99) C:\Windows\system32\DRIVERS\HDAudBus.sys 2010/11/04 16:49:41.0318 HidBth (204c3b1846e9cbaaef88b8e1f86782f8) C:\Windows\system32\DRIVERS\hidbth.sys 2010/11/04 16:49:41.0364 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 2010/11/04 16:49:41.0411 HidUsb (854ca287ab7faf949617a788306d967e) C:\Windows\system32\DRIVERS\hidusb.sys 2010/11/04 16:49:41.0458 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 2010/11/04 16:49:41.0505 HTTP (96e241624c71211a79c84f50a8e71cab) C:\Windows\system32\drivers\HTTP.sys 2010/11/04 16:49:41.0536 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 2010/11/04 16:49:41.0567 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 2010/11/04 16:49:41.0614 iaStor (e5a0034847537eaee3c00349d5c34c5f) C:\Windows\system32\drivers\iastor.sys 2010/11/04 16:49:41.0645 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 2010/11/04 16:49:41.0676 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 2010/11/04 16:49:41.0754 inspect (17b9e77307cf3b2b5102e17f444c10be) C:\Windows\system32\DRIVERS\inspect.sys 2010/11/04 16:49:41.0832 IntcAzAudAddService (98fb74ec7f46e25ec082f1925eef39cd) C:\Windows\system32\drivers\RTKVHDA.sys 2010/11/04 16:49:41.0926 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 2010/11/04 16:49:41.0957 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 2010/11/04 16:49:42.0004 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2010/11/04 16:49:42.0066 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 2010/11/04 16:49:42.0098 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 2010/11/04 16:49:42.0144 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 2010/11/04 16:49:42.0160 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 2010/11/04 16:49:42.0191 iScsiPrt (f247eec28317f6c739c16de420097301) C:\Windows\system32\DRIVERS\msiscsi.sys 2010/11/04 16:49:42.0222 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 2010/11/04 16:49:42.0238 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 2010/11/04 16:49:42.0285 JRAID (c36f3a1a4e8416ef43f30deab7701730) C:\Windows\system32\drivers\jraid.sys 2010/11/04 16:49:42.0316 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 2010/11/04 16:49:42.0347 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys 2010/11/04 16:49:42.0425 KSecDD (7a0cf7908b6824d6a2a1d313e5ae3dca) C:\Windows\system32\Drivers\ksecdd.sys 2010/11/04 16:49:42.0503 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 2010/11/04 16:49:42.0550 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 2010/11/04 16:49:42.0566 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 2010/11/04 16:49:42.0612 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 2010/11/04 16:49:42.0628 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 2010/11/04 16:49:42.0675 MBAMProtector (67b48a903430c6d4fb58cbaca1866601) C:\Windows\system32\drivers\mbam.sys 2010/11/04 16:49:42.0737 MBAMSwissArmy (c7dd7d9739785bd3a6b8499eec1dee7e) C:\Windows\system32\drivers\mbamswissarmy.sys 2010/11/04 16:49:42.0768 mcdbus (8fd868e32459ece2a1bb0169f513d31e) C:\Windows\system32\DRIVERS\mcdbus.sys 2010/11/04 16:49:42.0815 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 2010/11/04 16:49:42.0846 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 2010/11/04 16:49:42.0893 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 2010/11/04 16:49:42.0909 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 2010/11/04 16:49:42.0956 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 2010/11/04 16:49:42.0971 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 2010/11/04 16:49:42.0987 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 2010/11/04 16:49:43.0018 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 2010/11/04 16:49:43.0049 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 2010/11/04 16:49:43.0080 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 2010/11/04 16:49:43.0112 MRxDAV (ae3de84536b6799d2267443cec8edbb9) C:\Windows\system32\drivers\mrxdav.sys 2010/11/04 16:49:43.0158 mrxsmb (7afc42e60432fd1014f5342f2b1b1f74) C:\Windows\system32\DRIVERS\mrxsmb.sys 2010/11/04 16:49:43.0190 mrxsmb10 (8a75752ae17924f65452746674b14b78) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2010/11/04 16:49:43.0221 mrxsmb20 (f4d0f3252e651f02be64984ffa738394) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2010/11/04 16:49:43.0268 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys 2010/11/04 16:49:43.0299 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 2010/11/04 16:49:43.0346 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 2010/11/04 16:49:43.0377 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 2010/11/04 16:49:43.0439 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 2010/11/04 16:49:43.0486 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 2010/11/04 16:49:43.0502 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 2010/11/04 16:49:43.0533 MsRPC (b5614aecb05a9340aa0fb55bf561cc63) C:\Windows\system32\drivers\MsRPC.sys 2010/11/04 16:49:43.0564 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 2010/11/04 16:49:43.0595 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 2010/11/04 16:49:43.0626 Mup (6dfd1d322de55b0b7db7d21b90bec49c) C:\Windows\system32\Drivers\mup.sys 2010/11/04 16:49:43.0689 NativeWifiP (3c21ce48ff529bb73dadb98770b54025) C:\Windows\system32\DRIVERS\nwifi.sys 2010/11/04 16:49:43.0814 NDIS (9bdc71790fa08f0a0b5f10462b1bd0b1) C:\Windows\system32\drivers\ndis.sys 2010/11/04 16:49:43.0845 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 2010/11/04 16:49:43.0860 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 2010/11/04 16:49:43.0892 NdisWan (3d14c3b3496f88890d431e8aa022a411) C:\Windows\system32\DRIVERS\ndiswan.sys 2010/11/04 16:49:43.0938 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 2010/11/04 16:49:43.0970 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 2010/11/04 16:49:44.0001 netbt (7c5fee5b1c5728507cd96fb4a13e7a02) C:\Windows\system32\DRIVERS\netbt.sys 2010/11/04 16:49:44.0094 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 2010/11/04 16:49:44.0141 nmwcd (9a908a9bb857c2cceb2907eb9dcaeb8b) C:\Windows\system32\drivers\ccdcmb.sys 2010/11/04 16:49:44.0172 nmwcdc (68ec3ee2348e475ea62c66e6aafcfc9b) C:\Windows\system32\drivers\ccdcmbo.sys 2010/11/04 16:49:44.0219 nmwcdnsu (be7fd9ca07e7d39f77c78ba5756930d9) C:\Windows\system32\drivers\nmwcdnsu.sys 2010/11/04 16:49:44.0266 nmwcdnsuc (94651f5808d3328d28ef967a9e853b8f) C:\Windows\system32\drivers\nmwcdnsuc.sys 2010/11/04 16:49:44.0297 Npfs (ecb5003f484f9ed6c608d6d6c7886cbb) C:\Windows\system32\drivers\Npfs.sys 2010/11/04 16:49:44.0328 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 2010/11/04 16:49:44.0391 Ntfs (b4effe29eb4f15538fd8a9681108492d) C:\Windows\system32\drivers\Ntfs.sys 2010/11/04 16:49:44.0438 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 2010/11/04 16:49:44.0469 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 2010/11/04 16:49:44.0531 NVENETFD (d958a2b5f6ad5c3b8ccdc4d7da62466c) C:\Windows\system32\DRIVERS\nvmfdx32.sys 2010/11/04 16:49:44.0750 nvlddmkm (2913f72c5f4007cd2226e5d34e0aeece) C:\Windows\system32\DRIVERS\nvlddmkm.sys 2010/11/04 16:49:44.0859 NVNET (d958a2b5f6ad5c3b8ccdc4d7da62466c) C:\Windows\system32\DRIVERS\nvmfdx32.sys 2010/11/04 16:49:44.0906 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 2010/11/04 16:49:44.0937 nvsmu (c44ee36dd84fa95eb81d79c374756003) C:\Windows\system32\DRIVERS\nvsmu.sys 2010/11/04 16:49:44.0968 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 2010/11/04 16:49:45.0015 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 2010/11/04 16:49:45.0140 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys 2010/11/04 16:49:45.0202 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 2010/11/04 16:49:45.0218 partmgr (3b38467e7c3daed009dfe359e17f139f) C:\Windows\system32\drivers\partmgr.sys 2010/11/04 16:49:45.0249 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 2010/11/04 16:49:45.0358 pccsmcfd (175cc28dcf819f78caa3fbd44ad9e52a) C:\Windows\system32\DRIVERS\pccsmcfd.sys 2010/11/04 16:49:45.0389 pci (01b94418deb235dff777cc80076354b4) C:\Windows\system32\drivers\pci.sys 2010/11/04 16:49:45.0436 pciide (1d8b3d8df8eb7fcf2f0ac02f9f947802) C:\Windows\system32\drivers\pciide.sys 2010/11/04 16:49:45.0467 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 2010/11/04 16:49:45.0545 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 2010/11/04 16:49:45.0748 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 2010/11/04 16:49:45.0795 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 2010/11/04 16:49:45.0857 PSched (bfef604508a0ed1eae2a73e872555ffb) C:\Windows\system32\DRIVERS\pacer.sys 2010/11/04 16:49:45.0888 PSSDK42 (c8eb36910d3bd582891977e80925e21e) C:\Windows\system32\Drivers\pssdk42.sys 2010/11/04 16:49:45.0935 PxHelp20 (81088114178112618b1c414a65e50f7c) C:\Windows\system32\Drivers\PxHelp20.sys 2010/11/04 16:49:45.0982 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 2010/11/04 16:49:46.0029 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 2010/11/04 16:49:46.0060 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 2010/11/04 16:49:46.0076 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 2010/11/04 16:49:46.0107 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 2010/11/04 16:49:46.0154 RasPppoe (3e9d9b048107b40d87b97df2e48e0744) C:\Windows\system32\DRIVERS\raspppoe.sys 2010/11/04 16:49:46.0185 RasSstp (a7d141684e9500ac928a772ed8e6b671) C:\Windows\system32\DRIVERS\rassstp.sys 2010/11/04 16:49:46.0216 rdbss (6e1c5d0457622f9ee35f683110e93d14) C:\Windows\system32\DRIVERS\rdbss.sys 2010/11/04 16:49:46.0247 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 2010/11/04 16:49:46.0294 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 2010/11/04 16:49:46.0310 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 2010/11/04 16:49:46.0356 RDPWD (e1c18f4097a5abcec941dc4b2f99db7e) C:\Windows\system32\drivers\RDPWD.sys 2010/11/04 16:49:46.0419 RFCOMM (34cc78c06587718c2ad6d3aa83b1f072) C:\Windows\system32\DRIVERS\rfcomm.sys 2010/11/04 16:49:46.0481 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 2010/11/04 16:49:46.0512 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 2010/11/04 16:49:46.0590 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2010/11/04 16:49:46.0637 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 2010/11/04 16:49:46.0668 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 2010/11/04 16:49:46.0715 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 2010/11/04 16:49:46.0778 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys 2010/11/04 16:49:46.0793 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 2010/11/04 16:49:46.0824 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys 2010/11/04 16:49:46.0840 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 2010/11/04 16:49:46.0902 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 2010/11/04 16:49:46.0949 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 2010/11/04 16:49:46.0980 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 2010/11/04 16:49:47.0012 Smb (031e6bcd53c9b2b9ace111eafec347b6) C:\Windows\system32\DRIVERS\smb.sys 2010/11/04 16:49:47.0058 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 2010/11/04 16:49:47.0121 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys 2010/11/04 16:49:47.0121 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505 2010/11/04 16:49:47.0121 sptd - detected Locked file (1) 2010/11/04 16:49:47.0168 srv (9a0163e7fbe59da0591bb1ad77d92e63) C:\Windows\system32\DRIVERS\srv.sys 2010/11/04 16:49:47.0214 srv2 (c7da26d2c7d480b1dd38ca19cc90b821) C:\Windows\system32\DRIVERS\srv2.sys 2010/11/04 16:49:47.0261 srvnet (f9c65e1e00a6bbf7c57d9b8ea068c525) C:\Windows\system32\DRIVERS\srvnet.sys 2010/11/04 16:49:47.0355 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 2010/11/04 16:49:47.0386 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 2010/11/04 16:49:47.0417 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 2010/11/04 16:49:47.0433 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 2010/11/04 16:49:47.0526 taphss (0c3b2a9c4bd2dd9a6c2e4084314dd719) C:\Windows\system32\DRIVERS\taphss.sys 2010/11/04 16:49:47.0589 Tcpip (782568ab6a43160a159b6215b70bcce9) C:\Windows\system32\drivers\tcpip.sys 2010/11/04 16:49:47.0651 Tcpip6 (782568ab6a43160a159b6215b70bcce9) C:\Windows\system32\DRIVERS\tcpip.sys 2010/11/04 16:49:47.0714 tcpipreg (d4a2e4a4b011f3a883af77315a5ae76b) C:\Windows\system32\drivers\tcpipreg.sys 2010/11/04 16:49:47.0729 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 2010/11/04 16:49:47.0760 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 2010/11/04 16:49:47.0807 tdx (d09276b1fab033ce1d40dcbdf303d10f) C:\Windows\system32\DRIVERS\tdx.sys 2010/11/04 16:49:47.0838 TermDD (a048056f5e1a96a9bf3071b91741a5aa) C:\Windows\system32\DRIVERS\termdd.sys 2010/11/04 16:49:47.0916 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 2010/11/04 16:49:47.0948 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 2010/11/04 16:49:47.0994 tunnel (6042505ff6fa9ac1ef7684d0e03b6940) C:\Windows\system32\DRIVERS\tunnel.sys 2010/11/04 16:49:48.0026 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 2010/11/04 16:49:48.0057 udfs (8b5088058fa1d1cd897a2113ccff6c58) C:\Windows\system32\DRIVERS\udfs.sys 2010/11/04 16:49:48.0104 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 2010/11/04 16:49:48.0135 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 2010/11/04 16:49:48.0182 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 2010/11/04 16:49:48.0213 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 2010/11/04 16:49:48.0244 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 2010/11/04 16:49:48.0306 upperdev (a34560a5d516a2f5240180370866b99d) C:\Windows\system32\DRIVERS\usbser_lowerflt.sys 2010/11/04 16:49:48.0353 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 2010/11/04 16:49:48.0400 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 2010/11/04 16:49:48.0416 usbehci (cebe90821810e76320155beba722fcf9) C:\Windows\system32\DRIVERS\usbehci.sys 2010/11/04 16:49:48.0462 usbhub (cc6b28e4ce39951357963119ce47b143) C:\Windows\system32\DRIVERS\usbhub.sys 2010/11/04 16:49:48.0509 usbohci (7bdb7b0e7d45ac0402d78b90789ef47c) C:\Windows\system32\DRIVERS\usbohci.sys 2010/11/04 16:49:48.0525 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys 2010/11/04 16:49:48.0556 usbser (a96191470581a7091420d25ecd444502) C:\Windows\system32\DRIVERS\usbser.sys 2010/11/04 16:49:48.0603 UsbserFilt (6410eebd6e0427466812858ee84c8467) C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys 2010/11/04 16:49:48.0634 USBSTOR (87ba6b83c5d19b69160968d07d6e2982) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2010/11/04 16:49:48.0665 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 2010/11/04 16:49:48.0728 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 2010/11/04 16:49:48.0774 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 2010/11/04 16:49:48.0790 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 2010/11/04 16:49:48.0821 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 2010/11/04 16:49:48.0884 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 2010/11/04 16:49:48.0899 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 2010/11/04 16:49:48.0930 volmgrx (98f5ffe6316bd74e9e2c97206c190196) C:\Windows\system32\drivers\volmgrx.sys 2010/11/04 16:49:48.0977 volsnap (d8b4a53dd2769f226b3eb374374987c9) C:\Windows\system32\drivers\volsnap.sys 2010/11/04 16:49:49.0024 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 2010/11/04 16:49:49.0071 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 2010/11/04 16:49:49.0118 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2010/11/04 16:49:49.0133 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2010/11/04 16:49:49.0180 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 2010/11/04 16:49:49.0227 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 2010/11/04 16:49:49.0367 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 2010/11/04 16:49:49.0445 WpdUsb (0cec23084b51b8288099eb710224e955) C:\Windows\system32\DRIVERS\wpdusb.sys 2010/11/04 16:49:49.0476 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 2010/11/04 16:49:49.0539 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 2010/11/04 16:49:49.0617 ================================================================================ 2010/11/04 16:49:49.0617 Scan finished 2010/11/04 16:49:49.0617 ================================================================================ 2010/11/04 16:49:49.0632 Detected object count: 1 2010/11/04 16:49:52.0659 Locked file(sptd) - User select action: Skip
No, thats just a locked file. We can check it though


You need to enable windows to show all files and folders, instructions Here

Go to VirusTotal and submit this file for analysis, just use the browse feature and then Send File, you will get a report back, post the report into this thread for me to see. If the site says this file has been checked before, have them check it again


C:\Windows\system32\Drivers\sptd.sys

If the site is busy you can try this one

http://virusscan.jotti.org/en



Post the log and then run this free online virus scanner and post that log also

Please run this free online virus scanner from ESET
  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
http://virustotal.com uploads the file and then… nothing :huh:
http://virusscan.jotti.org/en says "File is empty (0 bytes)"

Tried more than once on both sites

ESET Online Virus Scanner Log:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=cbb1c1c787189242b9039083eaf738e6
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-11-05 01:22:23
# local_time=2010-11-05 03:22:23 (+0200, South Africa Standard Time)
# country="South Africa"
# lang=1033
# osver=6.0.6001 NT Service Pack 1
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=1024 16777215 100 0 0 0 0 0
# compatibility_mode=3073 16777213 80 92 15201 2737178 0 0
# compatibility_mode=5378 16777214 0 25 2311963 92023637 0 0
# compatibility_mode=5892 16776574 100 100 6202251 126483967 0 0
# compatibility_mode=8192 67108863 100 0 2381 2381 0 0
# scanned=179977
# found=2
# cleaned=2
# scan_time=8504
C:\ProgramData\VistaCodecs\{485E22DC-9EFE-4E26-AAA2-792BB0784D74}\Vista Codec Package.msi Win32/Packed.Autoit.C.Gen application (deleted - quarantined) 00000000000000000000000000000000 C
D:\Users\Admin\Software\Software Updater\SUMO 2.9.exe multiple threats (deleted - quarantined) 00000000000000000000000000000000 C


^ I don't think either of those two files are harmful
Those files it found where part of a torrent download, thats why they where removed. They could or could not be illegal, depending on what you downloaded. Have to tell you that downloading files from the torrents or any file sharing is not good practice and not all but some contain malware, your downloading that file from an unknown and not trusted source.
http://ask-leo.com/is_it_illegal_to_downlo…rent_files.html


How are things running now ?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI