This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Nasty Rootkit

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ok, please take your time. I appreciate you patience and persistence with this rootkit. It's easily the nastiest infection I have ever had on a computer of mine.
I found something that may help you… I ran a dr web cureit scan and it found evidence of the rootkit running inside of explorer.exe, but it did not successfully remove it as on reboot it picked it up again. It is the infamous TDSS 565. Here is a picture of what it found.

Attachments:

OK that tells me it is running in memory - so it is injecting explorer on reboot. Could you run Dr Web again and let it remove it but do not reboot. Immediately try to run either combofix or TDSSKiller - I am still running over the entire thread looking for anything that I may have missed
Ok. I will try that. So do you mean immediately after it detects and "erradicates" it to attempt to run of those programs? Or wait till the entire scan finishes?
Ughhh. Still not going. I have some information that might help you. TDSS Killer was terminated after a few seconds. Combofix crashes to a BSOD saying to "Run the driver verifier blah blah" The specific STOP was
0x000000C5 (0x0000000, 0x00000002, 0x00000001, 0x825197AE)

On attempting to boot into safe mode, the BSOD says
0x0000007B (0x80699BBD, 0xC0000034, 0x00000000, 0x00000000)
The error code states that it is a driver crashing - so I would like two quick programme runs to see what is evident. They are both quite fast

Please RIGHT-CLICK HERE and Save As (in IE it's "Save Target As", in FF it's "Save Link As") to download Silent Runners.
  • Save it to the desktop.
  • Run Silent Runner's by doubleclicking the "Silent Runners" icon on your desktop.
  • You will receive a prompt:
    • Do you want to skip supplementary searches?
      click NO
  • If you receive an error just click OK and double-click it to run it again - sometimes it won't run as it's supposed to the first time but will in subsequent runs.
  • You will see a text file appear on the desktop - it's not done, let it run (it won't appear to be doing anything!)
  • Once you receive the prompt All Done!, open the text file on the desktop, copy that entire log, and paste it here.
*NOTE* If you receive any warning message about scripts, please choose to allow the script to run.

THEN


  • Download RootRepeal from the following location and save it to your desktop.
  • Extract RootRepeal.exe from the archive.
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check all seven boxes: [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.
Here is the log from Silent Runners. Rootkit Repeal is currently scanning. It's taking a loooooooooong time to scan the "\windows\winsxs\Manifests" folder and its using over 1gb of my memory. Is this normal? It kind of sounds like a memory leak.
"Silent Runners.vbs", revision 63, http://www.silentrunners.org/
Operating System: Windows Vista SP1
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
———————————

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"ehTray.exe" = "C:\Windows\ehome\ehTray.exe" [MS]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"Windows Defender" = "%ProgramFiles%\Windows Defender\MSASCui.exe -hide" [MS]
"PWRISOVM.EXE" = "C:\Program Files\PowerISO\PWRISOVM.EXE" ["PowerISO Computing, Inc."]
"QuickTime Task" = ""C:\Program Files\QuickTime\QTTask.exe" -atboottime" ["Apple Inc."]
"iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Inc."]
"BCSSync" = ""C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices" [MS]
"Grid Service" = ""C:\Program Files\GridService\peer.exe" -n Grid" ["FS2YOU"]
"TkBellExe" = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."]
"UnlockerAssistant" = ""C:\Program Files\Unlocker\UnlockerAssistant.exe"" [null data]
"avast5" = ""C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui" ["AVAST Software"]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM…CLSID} = "Adobe PDF Reader Link Helper"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]

{0A0DDBD3-6641-40B9-873F-BBDD26D6C14E}\(Default) = (no title provided)
-> {HKLM…CLSID} = "IE2EMBHO Class"
\InProcServer32\(Default) = "C:\Program Files\easyMule\modules\IE2EM.dll" ["VeryCD.com"]

{3049C3E9-B461-4BC5-8870-4C09146192CA}\(Default) = (no title provided)
-> {HKLM…CLSID} = "RealPlayer Download and Record Plugin for Internet Explorer"
\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll" ["RealPlayer"]

{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\(Default) = (no title provided)
-> {HKLM…CLSID} = "Groove GFS Browser Helper"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

{9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided)
-> {HKLM…CLSID} = "Windows Live Sign-in Helper"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" [MS]

{B4F3A835-0E21-4959-BA22-42B3008E02FF}\(Default) = "URLRedirectionBHO"
-> {HKLM…CLSID} = "Office Document Cache Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL" [MS]

{bf00e119-21a3-4fd1-b178-3b8537e75c92}\(Default) = "MegaIEMn"
-> {HKLM…CLSID} = "IeMonitorBho Class"
\InProcServer32\(Default) = "C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll" ["Megaupload Limited"]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\

Groove Explorer Icon Overlay 1 (GFS Unread Stub)\(Default) = "{99FD978C-D287-4F50-827F-B2C658EDA8E7}"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 1 (GFS Unread Stub)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

Groove Explorer Icon Overlay 2 (GFS Stub)\(Default) = "{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 2 (GFS Stub)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)\(Default) = "{920E6DB1-9907-4370-B3A0-BAFC03D81399}"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

Groove Explorer Icon Overlay 3 (GFS Folder)\(Default) = "{16F3DD56-1AF5-4347-846D-7C10C4192619}"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 3 (GFS Folder)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

Groove Explorer Icon Overlay 4 (GFS Unread Mark)\(Default) = "{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 4 (GFS Unread Mark)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\

"{FBF23B40-E3F0-101B-8488-00AA003E56F8}" = "InternetShortcut"
-> {HKCU…CLSID} = "Internet Shortcut"
\InProcServer32\(Default) = "shdocvw.dll" [MS]

"{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]

"{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]

"{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]

"{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]

"{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}" = "PowerISO"
-> {HKLM…CLSID} = "PowerISO"
\InProcServer32\(Default) = "C:\Program Files\PowerISO\PWRISOSH.DLL" ["PowerISO Computing, Inc."]

"{23170F69-40C1-278A-1000-000100020000}" = "7-Zip Shell Extension"
-> {HKLM…CLSID} = "7-Zip Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\7-Zip\7-zip.dll" ["Igor Pavlov"]

"{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
-> {HKLM…CLSID} = "DesktopContext Class"
\InProcServer32\(Default) = "C:\Windows\system32\nvcpl.dll" ["NVIDIA Corporation"]

"{4ADF8C01-0AC7-4403-888C-012E6EA2F67E}" = "Sims2Pack Clean Installer Shell Extension"
-> {HKLM…CLSID} = "S2PCISE.S2PCISE"
\InProcServer32\(Default) = "mscoree.dll" [MS]

"{0563DB41-F538-4B37-A92D-4659049B7766}" = "WLMD Message Handler"
-> {HKLM…CLSID} = "CLSID_WLMCMimeFilter"
\InProcServer32\(Default) = "C:\Program Files\Windows Live\Mail\mailcomm.dll" [MS]

"{0E223B1F-FF38-452A-AC36-E2A6E8561F8B}" = "iPhone"
-> {HKLM…CLSID} = "iPhone"
\InProcServer32\(Default) = "C:\Program Files\ImTOO\iPod Computer Transfer\IPhoneExplorer.dll" [null data]

"{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}" = "UnlockerShellExtension"
-> {HKLM…CLSID} = "UnlockerShellExtension"
\InProcServer32\(Default) = "C:\Program Files\Unlocker\UnlockerCOM.dll" [null data]

"{D9D587F5-8284-45CC-AA5C-D2123D8852D9}" = "iPhone filesystem view"
-> {HKLM…CLSID} = "iPhone folders"
\InProcServer32\(Default) = "C:\Program Files\iPhone Folders\\iPhoneNSE.dll" ["Artem Redart Bozhenov"]

"{89EE4B92-EA79-4414-9BF9-CFCA8922C6F7}" = "iPhoneFolders Property Sheet"
-> {HKLM…CLSID} = "iPhoneFolders Property Sheet"
\InProcServer32\(Default) = "C:\Program Files\iPhone Folders\\iPhoneNSE.dll" ["Artem Redart Bozhenov"]

"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {HKLM…CLSID} = "RealOne Player Context Menu Class"
\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]

"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"
-> {HKLM…CLSID} = "iTunes"
\InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Inc."]

"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKCU…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\msohevi.dll" [file not found]
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office14\msohevi.dll" [MS]

"{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}" = "Microsoft Office Metadata Handler"
-> {HKLM…CLSID} = "Microsoft Office Metadata Handler"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll" [MS]

"{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}" = "Microsoft Office Thumbnail Handler"
-> {HKLM…CLSID} = "Microsoft Office Thumbnail Handler"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll" [MS]

"{3D60EDA7-9AB4-4DA8-864C-D9B5F2E7281D}" = "Groove Namespace Extension"
-> {HKLM…CLSID} = "Workspaces"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

"{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}" = "Microsoft OneNote Namespace Extension for Windows Desktop Search"
-> {HKLM…CLSID} = "Microsoft OneNote Namespace Extension for Windows Desktop Search"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office14\ONFILTER.DLL" [MS]

"{506F4668-F13E-4AA1-BB04-B43203AB3CC0}" = "{506F4668-F13E-4AA1-BB04-B43203AB3CC0}"
-> {HKLM…CLSID} = "ImageExtractorShellExt Class"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office14\VISSHE.DLL" [MS]

"{D66DC78C-4F61-447F-942B-3FB6980118CF}" = "{D66DC78C-4F61-447F-942B-3FB6980118CF}"
-> {HKLM…CLSID} = "CInfoTipShellExt Class"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office14\VISSHE.DLL" [MS]

"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}" = "Groove GFS Browser Helper"
-> {HKLM…CLSID} = "Groove GFS Browser Helper"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

"{6C467336-8281-4E60-8204-430CED96822D}" = "Groove GFS Context Menu Handler"
-> {HKLM…CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}" = "Groove GFS Explorer Bar"
-> {HKLM…CLSID} = "Groove Folder Synchronization"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

"{16F3DD56-1AF5-4347-846D-7C10C4192619}" = "Groove Explorer Icon Overlay 3 (GFS Folder)"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 3 (GFS Folder)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" = "Groove GFS Stub Execution Hook"
-> {HKLM…CLSID} = "Groove GFS Stub Execution Hook"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

"{A449600E-1DC6-4232-B948-9BD794D62056}" = "Groove GFS Stub Icon Handler"
-> {HKLM…CLSID} = "Groove GFS Stub Icon Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

"{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}" = "Groove Explorer Icon Overlay 2 (GFS Stub)"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 2 (GFS Stub)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

"{920E6DB1-9907-4370-B3A0-BAFC03D81399}" = "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

"{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}" = "Groove Explorer Icon Overlay 4 (GFS Unread Mark)"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 4 (GFS Unread Mark)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

"{99FD978C-D287-4F50-827F-B2C658EDA8E7}" = "Groove Explorer Icon Overlay 1 (GFS Unread Stub)"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 1 (GFS Unread Stub)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

"{387E725D-DC16-4D76-B310-2C93ED4752A0}" = "Groove XML Icon Handler"
-> {HKLM…CLSID} = "Groove XML Icon Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

"{00020D75-0000-0000-C000-000000000046}" = "Microsoft Outlook Desktop Icon Handler"
-> {HKLM…CLSID} = "Microsoft Outlook"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\MLSHEXT.DLL" [MS]

"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {HKLM…CLSID} = "Outlook File Icon Extension"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office14\OLKFSTUB.DLL" [MS]

"{0561EC90-CE54-4f0c-9C55-E226110A740C}" = "Haali Column Provider"
-> {HKLM…CLSID} = "Haali Column Provider"
\InProcServer32\(Default) = "C:\Windows\system32\mmfinfo.dll" [null data]

"{5574006C-28F5-4a65-A28C-74DE6BFBE0BB}" = "Haali Matroska Shell Property Page"
-> {HKLM…CLSID} = "Haali Matroska Shell Property Page"
\InProcServer32\(Default) = "C:\Windows\system32\mmfinfo.dll" [null data]

"{327669A0-59A7-4be9-B99E-1C9F3A57611A}" = "Haali Matroska Thumbnail Extractor"
-> {HKLM…CLSID} = "Haali Matroska Thumbnail Extractor"
\InProcServer32\(Default) = "C:\Windows\system32\mmfinfo.dll" [null data]

"{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
-> {HKLM…CLSID} = "NVIDIA CPL Extension"
\InProcServer32\(Default) = "C:\Windows\system32\nvcpl.dll" ["NVIDIA Corporation"]

"{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9}" = "NVIDIA Play On My TV Context Menu Extension"
-> {HKLM…CLSID} = "NVIDIA CPL Context Menu Extension"
\InProcServer32\(Default) = "C:\Windows\system32\nvshext.dll" ["NVIDIA Corporation"]

"{3FCEF010-09A4-11D4-8D3B-D12F9D3D8B02}" = "TIShelEx Shell Extension"
-> {HKLM…CLSID} = "FileTimeShlExt Class"
\InProcServer32\(Default) = "C:\PROGRA~2\COMMON~1\TISHAR~1\TICONN~1\TIShlExt.dll" ["Texas Instruments Incorporated"]

"{FC6ABB6A-36E7-4622-841B-23687F423AE8}" = "ZipScanEval"
-> {HKLM…CLSID} = "FindMenuEval Class"
\InProcServer32\(Default) = "C:\Program Files\ZipScan Evaluation\zscom.dll" ["Adrian Bhagat"]

"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
-> {HKLM…CLSID} = "avast"
\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast5\ashShell.dll" ["AVAST Software"]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\

<> "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" = "Groove GFS Stub Execution Hook"
-> {HKLM…CLSID} = "Groove GFS Stub Execution Hook"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\

<> text/xml\CLSID = "{807573E5-5146-11D5-A672-00B0D022E945}"
-> {HKLM…CLSID} = "Microsoft Office InfoPath XML Mime Filter"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL" [MS]

HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\

<> ms-help\CLSID = "{314111c7-a502-11d2-bbca-00c04f8ec294}"
-> {HKLM…CLSID} = "HxProtocol Class"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll" [MS]

<> msnim\CLSID = "{828030A1-22C1-4009-854F-8E305202313F}"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = ""C:\PROGRA~2\MSNMES~1\msgrapp.dll"" [MS]

<> wlmailhtml\CLSID = "{03C514A3-1EFB-4856-9F99-10D7BE1653C0}"
-> {HKLM…CLSID} = "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler"
\InProcServer32\(Default) = "C:\Program Files\Windows Live\Mail\mailcomm.dll" [MS]

HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\

7-Zip\(Default) = "{23170F69-40C1-278A-1000-000100020000}"
-> {HKLM…CLSID} = "7-Zip Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\7-Zip\7-zip.dll" ["Igor Pavlov"]

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM…CLSID} = "avast"
\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast5\ashShell.dll" ["AVAST Software"]

PowerISO\(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
-> {HKLM…CLSID} = "PowerISO"
\InProcServer32\(Default) = "C:\Program Files\PowerISO\PWRISOSH.DLL" ["PowerISO Computing, Inc."]

WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]

XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
-> {HKLM…CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

ZipScanEval\(Default) = "{FC6ABB6A-36E7-4622-841B-23687F423AE8}"
-> {HKLM…CLSID} = "FindMenuEval Class"
\InProcServer32\(Default) = "C:\Program Files\ZipScan Evaluation\zscom.dll" ["Adrian Bhagat"]

HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\

MBAMShlExt\(Default) = "{57CE581A-0CB6-4266-9CA0-19364C90A0B3}"
-> {HKLM…CLSID} = "MBAMShlExt Class"
\InProcServer32\(Default) = "C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll" ["Malwarebytes Corporation"]

UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"
-> {HKLM…CLSID} = "UnlockerShellExtension"
\InProcServer32\(Default) = "C:\Program Files\Unlocker\UnlockerCOM.dll" [null data]

XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
-> {HKLM…CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\

7-Zip\(Default) = "{23170F69-40C1-278A-1000-000100020000}"
-> {HKLM…CLSID} = "7-Zip Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\7-Zip\7-zip.dll" ["Igor Pavlov"]

PowerISO\(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
-> {HKLM…CLSID} = "PowerISO"
\InProcServer32\(Default) = "C:\Program Files\PowerISO\PWRISOSH.DLL" ["PowerISO Computing, Inc."]

WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]

XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
-> {HKLM…CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

ZipScanEval\(Default) = "{FC6ABB6A-36E7-4622-841B-23687F423AE8}"
-> {HKLM…CLSID} = "FindMenuEval Class"
\InProcServer32\(Default) = "C:\Program Files\ZipScan Evaluation\zscom.dll" ["Adrian Bhagat"]

HKLM\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\

FileZilla3CopyHook\(Default) = "{DB70412E-EEC9-479C-BBA9-BE36BFDDA41B}"
-> {HKLM…CLSID} = "FileZilla 3 Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\FileZilla FTP Client\fzshellext.dll" [null data]

HKLM\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\

7-Zip\(Default) = "{23170F69-40C1-278A-1000-000100020000}"
-> {HKLM…CLSID} = "7-Zip Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\7-Zip\7-zip.dll" ["Igor Pavlov"]

WinZip\(Default) = "{E0D79305-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]

HKLM\SOFTWARE\Classes\Directory\Background\shellex\ContextMenuHandlers\

aZipScanEval\(Default) = "{FC6ABB6A-36E7-4622-841B-23687F423AE8}"
-> {HKLM…CLSID} = "FindMenuEval Class"
\InProcServer32\(Default) = "C:\Program Files\ZipScan Evaluation\zscom.dll" ["Adrian Bhagat"]

NvCplDesktopContext\(Default) = "{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9}"
-> {HKLM…CLSID} = "NVIDIA CPL Context Menu Extension"
\InProcServer32\(Default) = "C:\Windows\system32\nvshext.dll" ["NVIDIA Corporation"]

XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
-> {HKLM…CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\

{04DAAD08-70EF-450E-834A-DCFAF9B48748}\(Default) = "Folder Size column"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\FolderSize\FolderSizeColumn.dll" ["Brio"]

{0561EC90-CE54-4f0c-9C55-E226110A740C}\(Default) = "Haali Column Provider"
-> {HKLM…CLSID} = "Haali Column Provider"
\InProcServer32\(Default) = "C:\Windows\system32\mmfinfo.dll" [null data]

{140B30F3-E361-409F-8461-95C795AE09F9}\(Default) = (no title provided)
-> {HKLM…CLSID} = "ColHandler Class"
\InProcServer32\(Default) = "C:\Windows\system32\dirsize.dll" [empty string]

{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
-> {HKLM…CLSID} = "PDF Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]

HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM…CLSID} = "avast"
\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast5\ashShell.dll" ["AVAST Software"]

MBAMShlExt\(Default) = "{57CE581A-0CB6-4266-9CA0-19364C90A0B3}"
-> {HKLM…CLSID} = "MBAMShlExt Class"
\InProcServer32\(Default) = "C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll" ["Malwarebytes Corporation"]

PowerISO\(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
-> {HKLM…CLSID} = "PowerISO"
\InProcServer32\(Default) = "C:\Program Files\PowerISO\PWRISOSH.DLL" ["PowerISO Computing, Inc."]

S2PCI\(Default) = "{4ADF8C01-0AC7-4403-888C-012E6EA2F67E}"
-> {HKLM…CLSID} = "S2PCISE.S2PCISE"
\InProcServer32\(Default) = "mscoree.dll" [MS]

UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"
-> {HKLM…CLSID} = "UnlockerShellExtension"
\InProcServer32\(Default) = "C:\Program Files\Unlocker\UnlockerCOM.dll" [null data]

WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]

XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
-> {HKLM…CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\

WinZip\(Default) = "{E0D79305-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]


Default executables:
——————–

<> HKCU\Software\Classes\.bat\(Default) = "batfile"

<> HKCU\Software\Classes\.cmd\(Default) = "cmdfile"

<> HKCU\Software\Classes\.com\(Default) = "comfile"

<> HKCU\Software\Classes\.exe\(Default) = "exefile"
HKCU\Software\Classes\.exe\shell\open\command\(Default) = (value not set)

<> HKCU\Software\Classes\.pif\(Default) = "piffile"


Group Policies {GPedit.msc branch and setting}:
———————————————–

Note: detected settings may not have any effect.

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\

"LowRiskFileTypes" = (REG_SZ) /{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:
{unrecognized setting}

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\

"SaveZoneInformation" = (REG_DWORD) dword:0x00000001
{User Configuration|Administrative Templates|Windows Components|Attachment Manager|
Do not preserve zone information in file attachments}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\

"AllowLegacyWebView" = (REG_DWORD) dword:0x00000001
{unrecognized setting}

"AllowUnhashedWebView" = (REG_DWORD) dword:0x00000001
{unrecognized setting}

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\

"disableregistrytools" = (REG_DWORD) dword:0x00000000
{User Configuration|Administrative Templates|System|
Prevent access to registry editing tools}

"DisableTaskMgr" = (REG_DWORD) dword:0x00000000
{unrecognized setting}

HKCU\Software\Policies\Microsoft\Windows\System\

"disablecmd" = (REG_DWORD) dword:0x00000000
{User Configuration|Administrative Templates|System|
Prevent access to the command prompt}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\

"EnableLUA" = (REG_DWORD) dword:0x00000000
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Run All Administrators In Admin Approval Mode}


Active Desktop and Wallpaper:
—————————–

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\Windows\system32\config\systemprofile\Pictures\thanksgiving.jpg"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Users\Buddy\Pictures\thanksgiving.jpg"


Enabled Screen Saver:
———————

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\Windows\system32\Bubbles.scr" [MS]


Windows Portable Device AutoPlay Handlers
—————————————–

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\

BridgeCS3ImportMediaOnArrival\
"Provider" = "Adobe Bridge CS3"
"InvokeProgID" = "Adobe.adobebridge"
"InvokeVerb" = "launch"
HKLM\SOFTWARE\Classes\Adobe.adobebridge\shell\launch\command\(Default) = "C:\Program Files\Adobe\Adobe Bridge CS3\bridgeproxy.exe -v %1" ["Adobe Systems, Inc."]

ImgBurnBDBurningOnArrival_BuildImage\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "HandleBDBurningOnArrival_BuildImage"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\HandleBDBurningOnArrival_BuildImage\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE BUILD /OUTPUTMODE DEVICE /DEST "%1"" ["LIGHTNING UK!"]

ImgBurnBDBurningOnArrival_BurnImage\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "HandleBDBurningOnArrival_BurnImage"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\HandleBDBurningOnArrival_BurnImage\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE WRITE /DEST "%1"" ["LIGHTNING UK!"]

ImgBurnCDBurningOnArrival_BuildImage\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "HandleCDBurningOnArrival_BuildImage"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\HandleCDBurningOnArrival_BuildImage\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE BUILD /OUTPUTMODE DEVICE /DEST "%1"" ["LIGHTNING UK!"]

ImgBurnCDBurningOnArrival_BurnImage\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "HandleCDBurningOnArrival_BurnImage"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\HandleCDBurningOnArrival_BurnImage\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE WRITE /DEST "%1"" ["LIGHTNING UK!"]

ImgBurnDVDBurningOnArrival_BuildImage\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "HandleDVDBurningOnArrival_BuildImage"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\HandleDVDBurningOnArrival_BuildImage\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE BUILD /OUTPUTMODE DEVICE /DEST "%1"" ["LIGHTNING UK!"]

ImgBurnDVDBurningOnArrival_BurnImage\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "HandleDVDBurningOnArrival_BurnImage"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\HandleDVDBurningOnArrival_BurnImage\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE WRITE /DEST "%1"" ["LIGHTNING UK!"]

ImgBurnHDDVDBurningOnArrival_BuildImage\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "HandleHDDVDBurningOnArrival_BuildImage"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\HandleHDDVDBurningOnArrival_BuildImage\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE BUILD /OUTPUTMODE DEVICE /DEST "%1"" ["LIGHTNING UK!"]

ImgBurnHDDVDBurningOnArrival_BurnImage\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "HandleHDDVDBurningOnArrival_BurnImage"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\HandleHDDVDBurningOnArrival_BurnImage\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE WRITE /DEST "%1"" ["LIGHTNING UK!"]

ImgBurnPlayBluRayOnArrival_ReadDisc\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "PlayBluRayOnArrival_ReadDisc"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\PlayBluRayOnArrival_ReadDisc\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE READ /SRC "%1"" ["LIGHTNING UK!"]

ImgBurnPlayCDAudioOnArrival_ReadDisc\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "PlayCDAudioOnArrival_ReadDisc"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\PlayCDAudioOnArrival_ReadDisc\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE READ /SRC "%1"" ["LIGHTNING UK!"]

ImgBurnPlayDVDMovieOnArrival_ReadDisc\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "PlayDVDMovieOnArrival_ReadDisc"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\PlayDVDMovieOnArrival_ReadDisc\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE READ /SRC "%1"" ["LIGHTNING UK!"]

ImgBurnPlayHDDVDOnArrival_ReadDisc\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "PlayHDDVDOnArrival_ReadDisc"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\PlayHDDVDOnArrival_ReadDisc\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE READ /SRC "%1"" ["LIGHTNING UK!"]

iTunesBurnCDOnArrival\
"Provider" = "iTunes"
"InvokeProgID" = "iTunes.BurnCD"
"InvokeVerb" = "burn"
HKLM\SOFTWARE\Classes\iTunes.BurnCD\shell\burn\command\(Default) = ""C:\Program Files\iTunes\iTunes.exe" /AutoPlayBurn "%L"" ["Apple Inc."]

iTunesImportSongsOnArrival\
"Provider" = "iTunes"
"InvokeProgID" = "iTunes.ImportSongsOnCD"
"InvokeVerb" = "import"
HKLM\SOFTWARE\Classes\iTunes.ImportSongsOnCD\shell\import\command\(Default) = ""C:\Program Files\iTunes\iTunes.exe" /AutoPlayImportSongs "%L"" ["Apple Inc."]

iTunesPlaySongsOnArrival\
"Provider" = "iTunes"
"InvokeProgID" = "iTunes.PlaySongsOnCD"
"InvokeVerb" = "play"
HKLM\SOFTWARE\Classes\iTunes.PlaySongsOnCD\shell\play\command\(Default) = ""C:\Program Files\iTunes\iTunes.exe" /playCD "%L"" ["Apple Inc."]

iTunesShowSongsOnArrival\
"Provider" = "iTunes"
"InvokeProgID" = "iTunes.ShowSongsOnCD"
"InvokeVerb" = "showsongs"
HKLM\SOFTWARE\Classes\iTunes.ShowSongsOnCD\shell\showsongs\command\(Default) = ""C:\Program Files\iTunes\iTunes.exe" /AutoPlayShowSongs "%L"" ["Apple Inc."]

MMVerizonApp\
"Provider" = "V CAST Media Manager"
"ProgID" = "MediaManager.Verizon"
"InitCmdLine" = "C:\Program Files\V CAST Media Manager\VCASTMediaManager.exe"
HKLM\SOFTWARE\Classes\MediaManager.Verizon\CLSID\(Default) = "{F62AD501-DFDC-4f9e-80F3-A5640C0FAE72}"
-> {HKLM…CLSID} = "V CAST Media manager"
\LocalServer32\(Default) = "VCASTMediaManager.exe" [file not found]

MPCPlayCDAudioOnArrival\
"Provider" = "Media Player Classic"
"InvokeProgID" = "MediaPlayerClassic.Autorun"
"InvokeVerb" = "PlayCDAudio"
HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayCDAudio\command\(Default) = ""C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe" %1 /cd" ["Gabest"]

MPCPlayDVDMovieOnArrival\
"Provider" = "Media Player Classic"
"InvokeProgID" = "MediaPlayerClassic.Autorun"
"InvokeVerb" = "PlayDVDMovie"
HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayDVDMovie\command\(Default) = ""C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe" %1 /dvd" ["Gabest"]

MPCPlayMusicFilesOnArrival\
"Provider" = "Media Player Classic"
"InvokeProgID" = "MediaPlayerClassic.Autorun"
"InvokeVerb" = "PlayMusicFiles"
HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayMusicFiles\command\(Default) = ""C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe" %1" ["Gabest"]

MPCPlayVideoFilesOnArrival\
"Provider" = "Media Player Classic"
"InvokeProgID" = "MediaPlayerClassic.Autorun"
"InvokeVerb" = "PlayVideoFiles"
HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayVideoFiles\command\(Default) = ""C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe" %1" ["Gabest"]

NeroAutoPlay9AudioToNeroDigital\
"Provider" = "Nero SoundTrax"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "AudioToNeroDigital_PlayCDAudioOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\AudioToNeroDigital_PlayCDAudioOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero SoundTrax\SoundTrax.exe /" [file not found]

NeroAutoPlay9CDAudio\
"Provider" = "Nero Express"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "CDAudio_HandleCDBurningOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\CDAudio_HandleCDBurningOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero Express\NeroExpress.exe -w /New:AudioCD" [file not found]

NeroAutoPlay9CopyCD\
"Provider" = "Nero Express"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "CopyCD_PlayMusicFilesOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\CopyCD_PlayMusicFilesOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero Express\NeroExpress.exe -w /Dialog:DiscCopy" [file not found]

NeroAutoPlay9DataDisc\
"Provider" = "Nero Express"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "DataDisc_HandleCDBurningOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\DataDisc_HandleCDBurningOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero Express\NeroExpress.exe -w /New:ISODisc" [file not found]

NeroAutoPlay9DVDVideoToNeroDigital\
"Provider" = "Nero Recode"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "DVDVideoToNeroDigital_PlayDVDMovieOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\DVDVideoToNeroDigital_PlayDVDMovieOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero Recode\Recode.exe /New:ReAuthorNeroDigital" [file not found]

NeroAutoPlay9LaunchNeroStartSmart\
"Provider" = "Nero StartSmart"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "LaunchNeroStartSmart_HandleCDBurningOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\LaunchNeroStartSmart_HandleCDBurningOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero StartSmart\NeroStartSmart.exe /AutoPlay" [file not found]

NeroAutoPlay9PlayAudioCD\
"Provider" = "Nero ShowTime"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "PlayAudioCD_PlayMusicFilesOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\PlayAudioCD_PlayMusicFilesOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero ShowTime\ShowTime.exe /Play %L" [file not found]

NeroAutoPlay9PlayDVD\
"Provider" = "Nero ShowTime"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "PlayDVD_PlayVideoFilesOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\PlayDVD_PlayVideoFilesOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero ShowTime\ShowTime.exe /Play %L" [file not found]

NeroAutoPlay9RipCD\
"Provider" = "Nero Burning ROM"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "RipCD_PlayCDAudioOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\RipCD_PlayCDAudioOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero Burning ROM\Nero.exe /Dialog:SaveTracks %L" [file not found]

NeroAutoPlay9TranscodeVideo\
"Provider" = "Nero Recode"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "TranscodeVideo_PlayDVDMovieOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\TranscodeVideo_PlayDVDMovieOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero Recode\Recode.exe /New:CopyDVDVideo" [file not found]

NeroAutoPlay9VideoCapture\
"Provider" = "Nero Vision"
"ProgID" = "Shell.HWEventHandlerShellExecute"
"InitCmdLine" = ""C:\Program Files\Nero\Nero 9\Nero Vision\NeroVision.exe" /New:VideoCapture"
HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}"
-> {HKLM…CLSID} = "Shell Execute Hardware Event Handler"
\LocalServer32\(Default) = "C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]

NeroAutoPlay9ViewPhotos\
"Provider" = "Nero PhotoSnap Viewer"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "ViewPhotos_ShowPicturesOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\ViewPhotos_ShowPicturesOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero PhotoSnap\PhotoSnapViewer.exe /" [file not found]

RPCDBurningOnArrival\
"Provider" = "RealPlayer"
"InvokeProgID" = "RealPlayer.CDBurn.6"
"InvokeVerb" = "open"
HKCU\Software\Classes\RealPlayer.CDBurn.6\shell\open\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /burn "%1"" ["RealNetworks, Inc."]

RPDeviceOnArrival\
"Provider" = "RealPlayer"
"ProgID" = "RealPlayer.HWEventHandler"
HKLM\SOFTWARE\Classes\RealPlayer.HWEventHandler\CLSID\(Default) = "{67E76F1D-BDE2-4052-913C-2752366192D2}"
-> {HKLM…CLSID} = "RealNetworks Scheduler"
\LocalServer32\(Default) = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -autoplay" ["RealNetworks, Inc."]

RPPlayCDAudioOnArrival\
"Provider" = "RealPlayer"
"InvokeProgID" = "RealPlayer.AudioCD.6"
"InvokeVerb" = "play"
HKCU\Software\Classes\RealPlayer.AudioCD.6\shell\play\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /play %1 " ["RealNetworks, Inc."]

RPPlayDVDMovieOnArrival\
"Provider" = "RealPlayer"
"InvokeProgID" = "RealPlayer.DVD.6"
"InvokeVerb" = "play"
HKCU\Software\Classes\RealPlayer.DVD.6\shell\play\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /dvd %1 " ["RealNetworks, Inc."]

RPPlayMediaOnArrival\
"Provider" = "RealPlayer"
"InvokeProgID" = "RealPlayer.AutoPlay.6"
"InvokeVerb" = "open"
HKCU\Software\Classes\RealPlayer.AutoPlay.6\shell\open\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /autoplay "%1"" ["RealNetworks, Inc."]

VCASTMediaManagerAutoPlay_1500906\
"Provider" = "V CAST Media Manager"
"InvokeProgID" = "VCASTMediaManagerAutoPlay"
"InvokeVerb" = "VCASTMediaManagerAutoPlay_1500906"
HKLM\SOFTWARE\Classes\VCASTMediaManagerAutoPlay\shell\VCASTMediaManagerAutoPlay_1500906\command\(Default) = ""C:\Program Files\V CAST Media Manager\VCASTMediaManager.exe"" ["Smith Micro, Inc."]

VerizonMediaManagerBurnCDOnArrival\
"Provider" = "V CAST Media Manager"
"InvokeProgID" = "MMVerizon.VolAutoPlay"
"InvokeVerb" = "HandleCDBurningOnArrival_CDAudio"
HKLM\SOFTWARE\Classes\MMVerizon.VolAutoPlay\shell\HandleCDBurningOnArrival_CDAudio\command\(Default) = "C:\Program Files\V CAST Media Manager\VCASTMediaManager.exe /BurnCD /Drive:%L" ["Smith Micro, Inc."]

VerizonMediaManagerRipCDOnArrival\
"Provider" = "V CAST Media Manager"
"InvokeProgID" = "MMVerizon.VolAutoPlay"
"InvokeVerb" = "PlayCDAudioOnArrival_RipCD"
HKLM\SOFTWARE\Classes\MMVerizon.VolAutoPlay\shell\PlayCDAudioOnArrival_RipCD\command\(Default) = "C:\Program Files\V CAST Media Manager\VCASTMediaManager.exe /RipCD /Drive:%L" ["Smith Micro, Inc."]

VLCPlayCDAudioOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.CDAudio"
"InvokeVerb" = "Open"
HKLM\SOFTWARE\Classes\VLC.CDAudio\shell\Open\command\(Default) = ""C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file cdda://%1" ["the VideoLAN Team"]

VLCPlayDVDAudioOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.OPENFolder"
"InvokeVerb" = "Open"
HKLM\SOFTWARE\Classes\VLC.OPENFolder\shell\Open\command\(Default) = ""C:\Program Files\VideoLAN\VLC\vlc.exe" %1" ["the VideoLAN Team"]

VLCPlayDVDMovieOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.DVDMovie"
"InvokeVerb" = "Open"
HKLM\SOFTWARE\Classes\VLC.DVDMovie\shell\Open\command\(Default) = ""C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file dvd://%1" ["the VideoLAN Team"]

VLCPlayMusicFilesOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.OPENFolder"
"InvokeVerb" = "Open"
HKLM\SOFTWARE\Classes\VLC.OPENFolder\shell\Open\command\(Default) = ""C:\Program Files\VideoLAN\VLC\vlc.exe" %1" ["the VideoLAN Team"]

VLCPlaySVCDMovieOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.SVCDMovie"
"InvokeVerb" = "Open"
HKLM\SOFTWARE\Classes\VLC.SVCDMovie\shell\Open\command\(Default) = ""C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file vcd://%1" ["the VideoLAN Team"]

VLCPlayVCDMovieOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.VCDMovie"
"InvokeVerb" = "Open"
HKLM\SOFTWARE\Classes\VLC.VCDMovie\shell\Open\command\(Default) = ""C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file vcd://%1" ["the VideoLAN Team"]

VLCPlayVideoFilesOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.OPENFolder"
"InvokeVerb" = "Open"
HKLM\SOFTWARE\Classes\VLC.OPENFolder\shell\Open\command\(Default) = ""C:\Program Files\VideoLAN\VLC\vlc.exe" %1" ["the VideoLAN Team"]

WIA_{240305C3-650B-4890-B6DB-D793280B607B}\
"Provider" = "Microsoft Word"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = "/WiaCmd;C:\Program Files\Microsoft Office\Office14\WINWORD.EXE /IMG_WIA;"
-> {HKLM…CLSID} = "WPDShextAutoplay"
\LocalServer32\(Default) = "C:\Windows\system32\WPDShextAutoplay.exe" [MS]

WIA_{2E2B1F10-DEB5-46A1-8F92-45E3F1A86158}\
"Provider" = "Microsoft Office OneNote"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = "/WiaCmd;C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE /IMG_WIA;"
-> {HKLM…CLSID} = "WPDShextAutoplay"
\LocalServer32\(Default) = "C:\Windows\system32\WPDShextAutoplay.exe" [MS]

WIA_{764F0264-903E-4F56-8D70-1729B01A3689}\
"Provider" = "Microsoft Office Word"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = "/WiaCmd;C:\Program Files\Microsoft Office\Office12\WINWORD.EXE /IMG_WIA;"
-> {HKLM…CLSID} = "WPDShextAutoplay"
\LocalServer32\(Default) = "C:\Windows\system32\WPDShextAutoplay.exe" [MS]

WIA_{BDE0F132-D47D-4BA1-86C2-F2BEAA2BDF6B}\
"Provider" = "Microsoft OneNote"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = "/WiaCmd;C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE /IMG_WIA;"
-> {HKLM…CLSID} = "WPDShextAutoplay"
\LocalServer32\(Default) = "C:\Windows\system32\WPDShextAutoplay.exe" [MS]

WIA_{D4C017B9-854E-4BC3-A931-71F01C388187}\
"Provider" = "Photoshop"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = "/WiaCmd;C:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe /StiDevice:%1 /StiEvent:%2;"
-> {HKLM…CLSID} = "WPDShextAutoplay"
\LocalServer32\(Default) = "C:\Windows\system32\WPDShextAutoplay.exe" [MS]


Startup items in "Buddy" & "All Users" startup folders:
——————————————————-

C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
"OneNote 2010 Screen Clipper and Launcher" -> shortcut to: "C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE /tsr" [MS]
"V CAST Media Monitor" -> shortcut to: "C:\Program Files\V CAST Media Manager\MEMonitor.exe -m" ["Smith Micro, Inc."]


Windows Sidebar Gadgets:
————————

C:\Users\Buddy\AppData\Local\Microsoft\Windows Sidebar\Settings.ini
%PROGRAMFILES%\windows sidebar\gadgets\SlideShow.Gadget
"C:%5CProgram%20Files%5CWindows%20Sidebar%5CGadgets%5CCPU.Gadget"
"C:%5CProgram%20Files%5CWindows%20Sidebar%5CGadgets%5CWeather.Gadget"
"C:%5CProgram%20Files%5CWindows%20Sidebar%5CGadgets%5CStocks.Gadget"
"C:%5CProgram%20Files%5CWindows%20Sidebar%5CGadgets%5CRSSFeeds.Gadget"
"C:%5CUsers%5CBuddy%5CAppData%5CLocal%5CMicrosoft%5CWindows%20Sidebar%5CGadgets%5Cclockr.gadget"
"C:%5CUsers%5CBuddy%5CAppData%5CLocal%5CMicrosoft%5CWindows%20Sidebar%5CGadgets%5Cred.gadget"
"C:%5CUsers%5CBuddy%5CAppData%5CLocal%5CMicrosoft%5CWindows%20Sidebar%5CGadgets%5Ccalendar.gadget"


Non-disabled Scheduled Tasks:
—————————–

C:\Windows\System32\Tasks
"GoogleUpdateTaskMachineCore" -> launches: "C:\Program Files\Google\Update\GoogleUpdate.exe /c" ["Google Inc."]
"GoogleUpdateTaskMachineUA" -> launches: "C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler" ["Google Inc."]
"Orb Index when idle" -> launches: ""C:\Program Files\Orb Networks\Orb\bin\Orblauncher.exe" –indexing" ["Orb Networks"]
"Orb Startup" -> launches: "C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" [file not found]
"RunAsStdUser Task for VeohWebPlayer" -> launches: "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe /VistaRunAsStdUser" [file not found]
"User_Feed_Synchronization-{E2DCF500-2AE9-4C71-A2E6-0B1861D91A9F}" -> (HIDDEN!) launches: "C:\Windows\system32\msfeedssync.exe sync" [MS]
"{01B3561F-4010-405C-9912-8507D411B2AC}" -> launches: "C:\Windows\system32\pcalua.exe -a C:\Users\Buddy\Downloads\install.exe -d C:\Users\Buddy\Downloads" [MS]
"{0750C419-FCB0-4A8F-AF2F-9A11C103705B}" -> launches: "C:\Windows\system32\pcalua.exe -a "C:\Users\Buddy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\397ZIWAY\Orb20SetupUs[1].exe" -d C:\Windows\system32" [MS]
"{4E676937-7E50-49AE-BDDF-6C4EAF0BBE46}" -> launches: "C:\Windows\system32\pcalua.exe -a L:\setup.exe -d L:\" [MS]
"{DC20B544-684B-49B5-8DF7-544653BE7CA2}" -> launches: "C:\Windows\system32\pcalua.exe -a "C:\Program Files\Rapidown\rapidown.exe" -c rapcmd.uninstall" [MS]
"{E66C8D7E-4B1C-44A2-96E2-4DB9957CF29A}" -> launches: "C:\Windows\system32\pcalua.exe -a "C:\Users\Buddy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NGFU1XM6\GetFile[1].exe" -d C:\Users\Buddy\Desktop" [MS]
"{E6EAEF96-E1EB-484C-8A16-AF04C2832794}" -> launches: "C:\Windows\system32\pcalua.exe -a M:\start.exe -d M:\" [MS]
"{F5AC8376-20AB-40C6-A918-52AFC59BFC97}" -> launches: "C:\Windows\system32\pcalua.exe -a G:\setup.exe -d G:\" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client
"AD RMS Rights Policy Template Management (Manual)" -> launches: "{BF5CB148-7C77-4d8a-A53E-D81C70CF743C}"
-> {HKLM…CLSID} = "AD RMS Rights Policy Template Management (Manual) Task Handler"
\InProcServer32\(Default) = "C:\Windows\system32\msdrm.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Bluetooth
"UninstallDeviceTask" -> launches: "BthUdTask.exe $(Arg0)" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\CertificateServicesClient
"SystemTask" -> launches: "{58fb76b9-ac85-4e55-ac04-427593b1d060}"
-> {HKLM…CLSID} = "Certificate Services Client Task Handler"
\InProcServer32\(Default) = "C:\Windows\system32\dimsjob.dll" [MS]
"UserTask" -> launches: "{58fb76b9-ac85-4e55-ac04-427593b1d060}"
-> {HKLM…CLSID} = "Certificate Services Client Task Handler"
\InProcServer32\(Default) = "C:\Windows\system32\dimsjob.dll" [MS]
"UserTask-Roam" -> launches: "{58fb76b9-ac85-4e55-ac04-427593b1d060}"
-> {HKLM…CLSID} = "Certificate Services Client Task Handler"
\InProcServer32\(Default) = "C:\Windows\system32\dimsjob.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program
"Consolidator" -> launches: "%SystemRoot%\System32\wsqmcons.exe" [MS]
"OptinNotification" -> launches: "%SystemRoot%\System32\wsqmcons.exe -n 0x1C577FA2B69CAD0" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Defrag
"ManualDefrag" -> launches: "%windir%\system32\defrag.exe -c" [MS]
"ScheduledDefrag" -> launches: "%windir%\system32\defrag.exe -c -i" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Media Center
"ehDRMInit" -> launches: "%SystemRoot%\ehome\ehPrivJob.exe /DRMInit" [MS]
"mcupdate" -> launches: "%SystemRoot%\ehome\mcupdate $(Arg0) -gc" [MS]
"OCURActivate" -> launches: "%SystemRoot%\ehome\ehPrivJob.exe /OCURActivate" [MS]
"OCURDiscovery" -> launches: "%SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery" [MS]
"UpdateRecordPath" -> launches: "%SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\MobilePC
"HotStart" -> launches: "{06DA0625-9701-43da-BFD7-FBEEA2180A1E}"
-> {HKLM…CLSID} = "HotStart User Agent"
\InProcServer32\(Default) = "C:\Windows\System32\HotStartUserAgent.dll" [MS]
"TMM" -> launches: "{35EF4182-F900-4632-B072-8639E4478A61}"
-> {HKLM…CLSID} = "Transient Multi-Monitor Manager"
\InProcServer32\(Default) = "C:\Windows\System32\TMM.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\MUI
"LPRemove" -> launches: "%windir%\system32\lpremove.exe" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia
"SystemSoundsService" -> launches: "{2DEA658F-54C1-4227-AF9B-260AB5FC3543}"
-> {HKLM…CLSID} = "Microsoft PlaySoundService Class"
\InProcServer32\(Default) = "C:\Windows\System32\PlaySndSrv.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\NetworkAccessProtection
"NAPStatus UI" -> launches: "{f09878a1-4652-4292-aa63-8c7d4fd7648f}"
-> {HKLM…CLSID} = "Nap ITask Handler Implementation"
\InProcServer32\(Default) = "C:\Windows\System32\QAgent.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\RAC
"RACAgent" -> (HIDDEN!) launches: "%windir%\system32\RacAgent.exe" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\RemoteAssistance
"RemoteAssistanceTask" -> (HIDDEN!) launches: "%windir%\system32\RAServer.exe /offerraupdate" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Shell
"CrawlStartPages" -> launches: "{51653423-e62d-4ff7-894a-dabb2b8e21e2}"
-> {HKLM…CLSID} = "CrawlStartPages Task Handler"
\InProcServer32\(Default) = "C:\Windows\System32\srchadmin.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\SideShow
"GadgetManager" -> launches: "{FF87090D-4A9A-4f47-879B-29A80C355D61}"
-> {HKLM…CLSID} = "GadgetsManager Class"
\InProcServer32\(Default) = "C:\Windows\System32\AuxiliaryDisplayServices.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\SystemRestore
"SR" -> launches: "%windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Tcpip
"IpAddressConflict1" -> launches: "rundll32 ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem" [MS]
"IpAddressConflict2" -> launches: "rundll32 ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\TextServicesFramework
"MsCtfMonitor" -> (HIDDEN!) launches: "{01575cfe-9a55-4003-a5e1-f38d1ebdcbe1}"
-> {HKLM…CLSID} = "MsCtfMonitor task handler"
\InProcServer32\(Default) = "C:\Windows\system32\MsCtfMonitor.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\UPnP
"UPnPHostConfig" -> launches: "sc.exe config upnphost start= auto" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\WDI
"ResolutionHost" -> (HIDDEN!) launches: "{900be39d-6be8-461a-bc4d-b0fa71f5ecb1}"
-> {HKLM…CLSID} = "DiagnosticInfrastructureCustomHandler"
\InProcServer32\(Default) = "C:\Windows\System32\wdi.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Windows Error Reporting
"QueueReporting" -> launches: "%windir%\system32\wermgr.exe -queuereporting" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Wired
"GatherWiredInfo" -> launches: "%windir%\system32\gatherWiredInfo.vbs" [null data]

C:\Windows\System32\Tasks\Microsoft\Windows\Wireless
"GatherWirelessInfo" -> launches: "%windir%\system32\gatherWirelessInfo.vbs" [null data]

C:\Windows\System32\Tasks\Microsoft\Windows Defender
"MP Scheduled Scan" -> (HIDDEN!) launches: "c:\program files\windows defender\MpCmdRun.exe Scan -RestrictPrivileges" [MS]
"MP Scheduled Signature Update" -> (HIDDEN!) launches: "c:\program files\windows defender\MpCmdRun.exe SignatureUpdate" [MS]


Winsock2 Service Provider DLLs:
——————————-

Namespace Service Providers

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\system32\NLAapi.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\system32\napinsp.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
000000000004\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
000000000005\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000006\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000007\LibraryPath = "C:\Program Files\Bonjour\mdnsNSP.dll" ["Apple Inc."]

Transport Service Providers

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 10, 13 - 34
C:\Program Files\VMware\VMware Workstation\vsocklib.dll ["VMware, Inc."], 11 - 12


Toolbars, Explorer Bars, Extensions:
————————————

Explorer Bars

HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\

HKLM\SOFTWARE\Classes\CLSID\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}\(Default) = "Groove Folder Synchronization"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\
{2670000A-7350-4F3C-8081-5663EE0C6C49}\
"ButtonText" = "Send to OneNote"
"MenuText" = "Se&nd to OneNote"
"CLSIDExtension" = "{48E73304-E1D6-4330-914C-F5F514E3486C}"
-> {HKLM…CLSID} = "Send to OneNote from Internet Explorer button"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll" [MS]

{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\
"ButtonText" = "OneNote Lin&ked Notes"
"MenuText" = "OneNote Lin&ked Notes"
"CLSIDExtension" = "{FFFDC614-B694-4AE6-AB38-5D6374584B52}"
-> {HKLM…CLSID} = "Linked Notes button"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll" [MS]


HOSTS file
———-

C:\Windows\System32\drivers\etc\HOSTS

maps: 2 domain names to IP addresses,
2 of the IP addresses are *not* localhost!


Running Services (Display Name, Service Name, Path {Service DLL}):
——————————————————————

Apple Mobile Device, Apple Mobile Device, ""C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"" ["Apple Inc."]
avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"" ["AVAST Software"]
Bonjour Service, Bonjour Service, ""C:\Program Files\Bonjour\mDNSResponder.exe"" ["Apple Inc."]
CNG Key Isolation, KeyIso, "C:\Windows\system32\lsass.exe" [MS]
COM+ System Application, COMSysApp, "C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}" [MS]
Computer Browser, Browser, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\browser.dll" [MS]}
Debug Diagnostic Service, DbgSvc, ""C:\Program Files\DebugDiag\DbgSvc.exe"" [MS]
Diagnostic Service Host, WdiServiceHost, "C:\Windows\System32\svchost.exe -k wdisvc" {"C:\Windows\system32\wdi.dll" [MS]}
Distributed Transaction Coordinator, MSDTC, "C:\Windows\System32\msdtc.exe" [MS]
Extensible Authentication Protocol, EapHost, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\eapsvc.dll" [MS]}
Human Interface Device Access, hidserv, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\system32\hidserv.dll" [MS]}
iPod Service, iPod Service, ""C:\Program Files\iPod\bin\iPodService.exe"" ["Apple Inc."]
Machine Debug Manager, MDM, ""C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"" [MS]
NVIDIA Display Driver Service, nvsvc, "C:\Windows\system32\nvvsvc.exe" ["NVIDIA Corporation"]
Pml Driver HPZ12, Pml Driver HPZ12, "C:\Windows\System32\svchost.exe -k HPZ12" {"C:\Windows\system32\HPZipm12.dll" ["Hewlett-Packard"]}
VMware Authorization Service, VMAuthdService, ""C:\Program Files\VMware\VMware Workstation\vmware-authd.exe"" ["VMware, Inc."]
VMware DHCP Service, VMnetDHCP, "C:\Windows\system32\vmnetdhcp.exe" ["VMware, Inc."]
VMware NAT Service, VMware NAT Service, "C:\Windows\system32\vmnat.exe" ["VMware, Inc."]
VMware USB Arbitration Service, VMUSBArbService, "C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe" ["VMware, Inc."]
VMware Virtual Mount Manager Extended, vmount2, ""C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe"" ["VMware, Inc."]
Windows Driver Foundation - User-mode Driver Framework, wudfsvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\WUDFSvc.dll" [MS]}
Windows Image Acquisition (WIA), stisvc, "C:\Windows\system32\svchost.exe -k imgsvc" {"C:\Windows\System32\wiaservc.dll" [MS]}
Windows Media Center Receiver Service, ehRecvr, "C:\Windows\ehome\ehRecvr.exe" [MS]
WLAN AutoConfig, Wlansvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\wlansvc.dll" [MS]}
XAudioService, XAudioService, "C:\Windows\system32\DRIVERS\xaudio.exe" ["Conexant Systems, Inc."]


Safe Mode Drivers & Services (subkey name, subkey default value):
—————————————————————–

HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\

<> PEVSystemStart, "Service"
<> procexp90.Sys, "Driver"

HKLM\System\CurrentControlSet\Control\SafeBoot\Network\

<> hitmanpro35, (null value)
<> hitmanpro35.sys, (null value)
<> HitmanPro35Crusader, (null value)
<> PEVSystemStart, "Service"
<> procexp90.Sys, "Driver"


Accessibility Tools:
——————–

HKCU\Software\Microsoft\Windows NT\CurrentVersion\AccessibilityTemp\
"narrator" = dword:0x00000000

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\ATs\Narrator\
"Description" = "Screen Reader"
"StartExe" = "C:\Windows\System32\Narrator.exe" [MS]


Keyboard Driver Filters:
————————

HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\
<> "UpperFilters" = "kbdclass" [MS],<> "vmkbd" ["VMware, Inc."]


Print Monitors:
—————

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\
CutePDF Writer Monitor\Driver = "cpwmon2k.dll" [null data]
PCL hpz3l4v2\Driver = "hpz3l4v2.dll" ["Hewlett-Packard Company"]


———- (launch time: 2011-02-16 14:57:11)
<>: Suspicious data at a malware launch point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 618 seconds.
———- (total run time: 701 seconds)
Ok, here's what I did. I selected each of the tabs in rootrepeal and hit scanned, saved report. It is pasted. I then hit the files tab then scan, one again it hangs on scanning the manifests folder and eats up all my RAM but I PrtScn the window to show you what it did find files wise. ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2011/02/16 15:40 Program Version: Version 1.3.5.0 Windows Version: Windows Vista SP1 ================================================== Drivers ——————- Name: dump_iaStorV.sys Image Path: C:\Windows\System32\Drivers\dump_iaStorV.sys Address: 0x8F721000 Size: 659456 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\Windows\system32\drivers\rootrepeal.sys Address: 0x9FE29000 Size: 49152 File Visible: No Signed: - Status: - Processes ——————- Path: System PID: 4 Status: Locked to the Windows API! Path: C:\Windows\System32\audiodg.exe PID: 1360 Status: Locked to the Windows API! SSDT ——————- #: 000 Function Name: NtAcceptConnectPort Status: Not hooked #: 001 Function Name: NtAccessCheck Status: Not hooked #: 002 Function Name: NtAccessCheckAndAuditAlarm Status: Not hooked #: 003 Function Name: NtAccessCheckByType Status: Not hooked #: 004 Function Name: NtAccessCheckByTypeAndAuditAlarm Status: Not hooked #: 005 Function Name: NtAccessCheckByTypeResultList Status: Not hooked #: 006 Function Name: NtAccessCheckByTypeResultListAndAuditAlarm Status: Not hooked #: 007 Function Name: NtAccessCheckByTypeResultListAndAuditAlarmByHandle Status: Not hooked #: 008 Function Name: NtAddAtom Status: Not hooked #: 009 Function Name: NtAddBootEntry Status: Not hooked #: 010 Function Name: NtAddDriverEntry Status: Not hooked #: 011 Function Name: NtAdjustGroupsToken Status: Not hooked #: 012 Function Name: NtAdjustPrivilegesToken Status: Not hooked #: 013 Function Name: NtAlertResumeThread Status: Not hooked #: 014 Function Name: NtAlertThread Status: Not hooked #: 015 Function Name: NtAllocateLocallyUniqueId Status: Not hooked #: 016 Function Name: NtAllocateUserPhysicalPages Status: Not hooked #: 017 Function Name: NtAllocateUuids Status: Not hooked #: 018 Function Name: NtAllocateVirtualMemory Status: Not hooked #: 019 Function Name: NtAlpcAcceptConnectPort Status: Not hooked #: 020 Function Name: NtAlpcCancelMessage Status: Not hooked #: 021 Function Name: NtAlpcConnectPort Status: Not hooked #: 022 Function Name: NtAlpcCreatePort Status: Not hooked #: 023 Function Name: NtAlpcCreatePortSection Status: Not hooked #: 024 Function Name: NtAlpcCreateResourceReserve Status: Not hooked #: 025 Function Name: NtAlpcCreateSectionView Status: Not hooked #: 026 Function Name: NtAlpcCreateSecurityContext Status: Not hooked #: 027 Function Name: NtAlpcDeletePortSection Status: Not hooked #: 028 Function Name: NtAlpcDeleteResourceReserve Status: Not hooked #: 029 Function Name: NtAlpcDeleteSectionView Status: Not hooked #: 030 Function Name: NtAlpcDeleteSecurityContext Status: Not hooked #: 031 Function Name: NtAlpcDisconnectPort Status: Not hooked #: 032 Function Name: NtAlpcImpersonateClientOfPort Status: Not hooked #: 033 Function Name: NtAlpcOpenSenderProcess Status: Not hooked #: 034 Function Name: NtAlpcOpenSenderThread Status: Not hooked #: 035 Function Name: NtAlpcQueryInformation Status: Not hooked #: 036 Function Name: NtAlpcQueryInformationMessage Status: Not hooked #: 037 Function Name: NtAlpcRevokeSecurityContext Status: Not hooked #: 038 Function Name: NtAlpcSendWaitReceivePort Status: Not hooked #: 039 Function Name: NtAlpcSetInformation Status: Not hooked #: 040 Function Name: NtApphelpCacheControl Status: Not hooked #: 041 Function Name: NtAreMappedFilesTheSame Status: Not hooked #: 042 Function Name: NtAssignProcessToJobObject Status: Not hooked #: 043 Function Name: NtCallbackReturn Status: Not hooked #: 044 Function Name: NtRequestDeviceWakeup Status: Not hooked #: 045 Function Name: NtCancelIoFile Status: Not hooked #: 046 Function Name: NtCancelTimer Status: Not hooked #: 047 Function Name: NtClearEvent Status: Not hooked #: 048 Function Name: NtClose Status: Not hooked #: 049 Function Name: NtCloseObjectAuditAlarm Status: Not hooked #: 050 Function Name: NtCompactKeys Status: Not hooked #: 051 Function Name: NtCompareTokens Status: Not hooked #: 052 Function Name: NtCompleteConnectPort Status: Not hooked #: 053 Function Name: NtCompressKey Status: Not hooked #: 054 Function Name: NtConnectPort Status: Not hooked #: 055 Function Name: NtContinue Status: Not hooked #: 056 Function Name: NtCreateDebugObject Status: Not hooked #: 057 Function Name: NtCreateDirectoryObject Status: Not hooked #: 058 Function Name: NtCreateEvent Status: Not hooked #: 059 Function Name: NtCreateEventPair Status: Not hooked #: 060 Function Name: NtCreateFile Status: Not hooked #: 061 Function Name: NtCreateIoCompletion Status: Not hooked #: 062 Function Name: NtCreateJobObject Status: Not hooked #: 063 Function Name: NtCreateJobSet Status: Not hooked #: 064 Function Name: NtCreateKey Status: Not hooked #: 065 Function Name: NtCreateKeyTransacted Status: Not hooked #: 066 Function Name: NtCreateMailslotFile Status: Not hooked #: 067 Function Name: NtCreateMutant Status: Not hooked #: 068 Function Name: NtCreateNamedPipeFile Status: Not hooked #: 069 Function Name: NtCreatePrivateNamespace Status: Not hooked #: 070 Function Name: NtCreatePagingFile Status: Not hooked #: 071 Function Name: NtCreatePort Status: Not hooked #: 072 Function Name: NtCreateProcess Status: Not hooked #: 073 Function Name: NtCreateProcessEx Status: Not hooked #: 074 Function Name: NtCreateProfile Status: Not hooked #: 075 Function Name: NtCreateSection Status: Not hooked #: 076 Function Name: NtCreateSemaphore Status: Not hooked #: 077 Function Name: NtCreateSymbolicLinkObject Status: Not hooked #: 078 Function Name: NtCreateThread Status: Not hooked #: 079 Function Name: NtCreateTimer Status: Not hooked #: 080 Function Name: NtCreateToken Status: Not hooked #: 081 Function Name: NtCreateTransaction Status: Not hooked #: 082 Function Name: NtOpenTransaction Status: Not hooked #: 083 Function Name: NtQueryInformationTransaction Status: Not hooked #: 084 Function Name: NtQueryInformationTransactionManager Status: Not hooked #: 085 Function Name: NtPrePrepareEnlistment Status: Not hooked #: 086 Function Name: NtPrepareEnlistment Status: Not hooked #: 087 Function Name: NtCommitEnlistment Status: Not hooked #: 088 Function Name: NtReadOnlyEnlistment Status: Not hooked #: 089 Function Name: NtRollbackComplete Status: Not hooked #: 090 Function Name: NtRollbackEnlistment Status: Not hooked #: 091 Function Name: NtCommitTransaction Status: Not hooked #: 092 Function Name: NtRollbackTransaction Status: Not hooked #: 093 Function Name: NtPrePrepareComplete Status: Not hooked #: 094 Function Name: NtPrepareComplete Status: Not hooked #: 095 Function Name: NtCommitComplete Status: Not hooked #: 096 Function Name: NtSinglePhaseReject Status: Not hooked #: 097 Function Name: NtSetInformationTransaction Status: Not hooked #: 098 Function Name: NtSetInformationTransactionManager Status: Not hooked #: 099 Function Name: NtSetInformationResourceManager Status: Not hooked #: 100 Function Name: NtCreateTransactionManager Status: Not hooked #: 101 Function Name: NtOpenTransactionManager Status: Not hooked #: 102 Function Name: NtRenameTransactionManager Status: Not hooked #: 103 Function Name: NtRollforwardTransactionManager Status: Not hooked #: 104 Function Name: NtRecoverEnlistment Status: Not hooked #: 105 Function Name: NtRecoverResourceManager Status: Not hooked #: 106 Function Name: NtRecoverTransactionManager Status: Not hooked #: 107 Function Name: NtCreateResourceManager Status: Not hooked #: 108 Function Name: NtOpenResourceManager Status: Not hooked #: 109 Function Name: NtGetNotificationResourceManager Status: Not hooked #: 110 Function Name: NtQueryInformationResourceManager Status: Not hooked #: 111 Function Name: NtCreateEnlistment Status: Not hooked #: 112 Function Name: NtOpenEnlistment Status: Not hooked #: 113 Function Name: NtSetInformationEnlistment Status: Not hooked #: 114 Function Name: NtQueryInformationEnlistment Status: Not hooked #: 115 Function Name: NtCreateWaitablePort Status: Not hooked #: 116 Function Name: NtDebugActiveProcess Status: Not hooked #: 117 Function Name: NtDebugContinue Status: Not hooked #: 118 Function Name: NtDelayExecution Status: Not hooked #: 119 Function Name: NtDeleteAtom Status: Not hooked #: 120 Function Name: NtDeleteBootEntry Status: Not hooked #: 121 Function Name: NtDeleteDriverEntry Status: Not hooked #: 122 Function Name: NtDeleteFile Status: Not hooked #: 123 Function Name: NtDeleteKey Status: Not hooked #: 124 Function Name: NtDeletePrivateNamespace Status: Not hooked #: 125 Function Name: NtDeleteObjectAuditAlarm Status: Not hooked #: 126 Function Name: NtDeleteValueKey Status: Not hooked #: 127 Function Name: NtDeviceIoControlFile Status: Not hooked #: 128 Function Name: NtDisplayString Status: Not hooked #: 129 Function Name: NtDuplicateObject Status: Not hooked #: 130 Function Name: NtDuplicateToken Status: Not hooked #: 131 Function Name: NtEnumerateBootEntries Status: Not hooked #: 132 Function Name: NtEnumerateDriverEntries Status: Not hooked #: 133 Function Name: NtEnumerateKey Status: Not hooked #: 134 Function Name: NtEnumerateSystemEnvironmentValuesEx Status: Not hooked #: 135 Function Name: NtEnumerateTransactionObject Status: Not hooked #: 136 Function Name: NtEnumerateValueKey Status: Not hooked #: 137 Function Name: NtExtendSection Status: Not hooked #: 138 Function Name: NtFilterToken Status: Not hooked #: 139 Function Name: NtFindAtom Status: Not hooked #: 140 Function Name: NtFlushBuffersFile Status: Not hooked #: 141 Function Name: NtFlushInstructionCache Status: Not hooked #: 142 Function Name: NtFlushKey Status: Not hooked #: 143 Function Name: NtFlushProcessWriteBuffers Status: Not hooked #: 144 Function Name: NtFlushVirtualMemory Status: Not hooked #: 145 Function Name: NtFlushWriteBuffer Status: Not hooked #: 146 Function Name: NtFreeUserPhysicalPages Status: Not hooked #: 147 Function Name: NtFreeVirtualMemory Status: Not hooked #: 148 Function Name: NtFreezeRegistry Status: Not hooked #: 149 Function Name: NtFreezeTransactions Status: Not hooked #: 150 Function Name: NtFsControlFile Status: Not hooked #: 151 Function Name: NtGetContextThread Status: Not hooked #: 152 Function Name: NtGetDevicePowerState Status: Not hooked #: 153 Function Name: NtGetNlsSectionPtr Status: Not hooked #: 154 Function Name: NtGetPlugPlayEvent Status: Not hooked #: 155 Function Name: NtGetWriteWatch Status: Not hooked #: 156 Function Name: NtImpersonateAnonymousToken Status: Not hooked #: 157 Function Name: NtImpersonateClientOfPort Status: Not hooked #: 158 Function Name: NtImpersonateThread Status: Not hooked #: 159 Function Name: NtInitializeNlsFiles Status: Not hooked #: 160 Function Name: NtInitializeRegistry Status: Not hooked #: 161 Function Name: NtInitiatePowerAction Status: Not hooked #: 162 Function Name: NtIsProcessInJob Status: Not hooked #: 163 Function Name: NtIsSystemResumeAutomatic Status: Not hooked #: 164 Function Name: NtListenPort Status: Not hooked #: 165 Function Name: NtLoadDriver Status: Not hooked #: 166 Function Name: NtLoadKey Status: Not hooked #: 167 Function Name: NtLoadKey2 Status: Not hooked #: 168 Function Name: NtLoadKeyEx Status: Not hooked #: 169 Function Name: NtLockFile Status: Not hooked #: 170 Function Name: NtLockProductActivationKeys Status: Not hooked #: 171 Function Name: NtLockRegistryKey Status: Not hooked #: 172 Function Name: NtLockVirtualMemory Status: Not hooked #: 173 Function Name: NtMakePermanentObject Status: Not hooked #: 174 Function Name: NtMakeTemporaryObject Status: Not hooked #: 175 Function Name: NtMapUserPhysicalPages Status: Not hooked #: 176 Function Name: NtMapUserPhysicalPagesScatter Status: Not hooked #: 177 Function Name: NtMapViewOfSection Status: Not hooked #: 178 Function Name: NtModifyBootEntry Status: Not hooked #: 179 Function Name: NtModifyDriverEntry Status: Not hooked #: 180 Function Name: NtNotifyChangeDirectoryFile Status: Not hooked #: 181 Function Name: NtNotifyChangeKey Status: Not hooked #: 182 Function Name: NtNotifyChangeMultipleKeys Status: Not hooked #: 183 Function Name: NtOpenDirectoryObject Status: Not hooked #: 184 Function Name: NtOpenEvent Status: Not hooked #: 185 Function Name: NtOpenEventPair Status: Not hooked #: 186 Function Name: NtOpenFile Status: Not hooked #: 187 Function Name: NtOpenIoCompletion Status: Not hooked #: 188 Function Name: NtOpenJobObject Status: Not hooked #: 189 Function Name: NtOpenKey Status: Not hooked #: 190 Function Name: NtOpenKeyTransacted Status: Not hooked #: 191 Function Name: NtOpenMutant Status: Not hooked #: 192 Function Name: NtOpenPrivateNamespace Status: Not hooked #: 193 Function Name: NtOpenObjectAuditAlarm Status: Not hooked #: 194 Function Name: NtOpenProcess Status: Not hooked #: 195 Function Name: NtOpenProcessToken Status: Not hooked #: 196 Function Name: NtOpenProcessTokenEx Status: Not hooked #: 197 Function Name: NtOpenSection Status: Not hooked #: 198 Function Name: NtOpenSemaphore Status: Not hooked #: 199 Function Name: NtOpenSession Status: Not hooked #: 200 Function Name: NtOpenSymbolicLinkObject Status: Not hooked #: 201 Function Name: NtOpenThread Status: Not hooked #: 202 Function Name: NtOpenThreadToken Status: Not hooked #: 203 Function Name: NtOpenThreadTokenEx Status: Not hooked #: 204 Function Name: NtOpenTimer Status: Not hooked #: 205 Function Name: NtPlugPlayControl Status: Not hooked #: 206 Function Name: NtPowerInformation Status: Not hooked #: 207 Function Name: NtPrivilegeCheck Status: Not hooked #: 208 Function Name: NtPrivilegeObjectAuditAlarm Status: Not hooked #: 209 Function Name: NtPrivilegedServiceAuditAlarm Status: Not hooked #: 210 Function Name: NtProtectVirtualMemory Status: Not hooked #: 211 Function Name: NtPulseEvent Status: Not hooked #: 212 Function Name: NtQueryAttributesFile Status: Not hooked #: 213 Function Name: NtQueryBootEntryOrder Status: Not hooked #: 214 Function Name: NtQueryBootOptions Status: Not hooked #: 215 Function Name: NtQueryDebugFilterState Status: Not hooked #: 216 Function Name: NtQueryDefaultLocale Status: Not hooked #: 217 Function Name: NtQueryDefaultUILanguage Status: Not hooked #: 218 Function Name: NtQueryDirectoryFile Status: Not hooked #: 219 Function Name: NtQueryDirectoryObject Status: Not hooked #: 220 Function Name: NtQueryDriverEntryOrder Status: Not hooked #: 221 Function Name: NtQueryEaFile Status: Not hooked #: 222 Function Name: NtQueryEvent Status: Not hooked #: 223 Function Name: NtQueryFullAttributesFile Status: Not hooked #: 224 Function Name: NtQueryInformationAtom Status: Not hooked #: 225 Function Name: NtQueryInformationFile Status: Not hooked #: 226 Function Name: NtQueryInformationJobObject Status: Not hooked #: 227 Function Name: NtQueryInformationPort Status: Not hooked #: 228 Function Name: NtQueryInformationProcess Status: Not hooked #: 229 Function Name: NtQueryInformationThread Status: Not hooked #: 230 Function Name: NtQueryInformationToken Status: Not hooked #: 231 Function Name: NtQueryInstallUILanguage Status: Not hooked #: 232 Function Name: NtQueryIntervalProfile Status: Not hooked #: 233 Function Name: NtQueryIoCompletion Status: Not hooked #: 234 Function Name: NtQueryKey Status: Not hooked #: 235 Function Name: NtQueryMultipleValueKey Status: Not hooked #: 236 Function Name: NtQueryMutant Status: Not hooked #: 237 Function Name: NtQueryObject Status: Not hooked #: 238 Function Name: NtQueryOpenSubKeys Status: Not hooked #: 239 Function Name: NtQueryOpenSubKeysEx Status: Not hooked #: 240 Function Name: NtQueryPerformanceCounter Status: Not hooked #: 241 Function Name: NtQueryQuotaInformationFile Status: Not hooked #: 242 Function Name: NtQuerySection Status: Not hooked #: 243 Function Name: NtQuerySecurityObject Status: Not hooked #: 244 Function Name: NtQuerySemaphore Status: Not hooked #: 245 Function Name: NtQuerySymbolicLinkObject Status: Not hooked #: 246 Function Name: NtQuerySystemEnvironmentValue Status: Not hooked #: 247 Function Name: NtQuerySystemEnvironmentValueEx Status: Not hooked #: 248 Function Name: NtQuerySystemInformation Status: Not hooked #: 249 Function Name: NtQuerySystemTime Status: Not hooked #: 250 Function Name: NtQueryTimer Status: Not hooked #: 251 Function Name: NtQueryTimerResolution Status: Not hooked #: 252 Function Name: NtQueryValueKey Status: Not hooked #: 253 Function Name: NtQueryVirtualMemory Status: Not hooked #: 254 Function Name: NtQueryVolumeInformationFile Status: Not hooked #: 255 Function Name: NtQueueApcThread Status: Not hooked #: 256 Function Name: NtRaiseException Status: Not hooked #: 257 Function Name: NtRaiseHardError Status: Not hooked #: 258 Function Name: NtReadFile Status: Not hooked #: 259 Function Name: NtReadFileScatter Status: Not hooked #: 260 Function Name: NtReadRequestData Status: Not hooked #: 261 Function Name: NtReadVirtualMemory Status: Not hooked #: 262 Function Name: NtRegisterThreadTerminatePort Status: Not hooked #: 263 Function Name: NtReleaseMutant Status: Not hooked #: 264 Function Name: NtReleaseSemaphore Status: Not hooked #: 265 Function Name: NtRemoveIoCompletion Status: Not hooked #: 266 Function Name: NtRemoveProcessDebug Status: Not hooked #: 267 Function Name: NtRenameKey Status: Not hooked #: 268 Function Name: NtReplaceKey Status: Not hooked #: 269 Function Name: NtReplacePartitionUnit Status: Not hooked #: 270 Function Name: NtReplyPort Status: Not hooked #: 271 Function Name: NtReplyWaitReceivePort Status: Not hooked #: 272 Function Name: NtReplyWaitReceivePortEx Status: Not hooked #: 273 Function Name: NtReplyWaitReplyPort Status: Not hooked #: 274 Function Name: NtRequestDeviceWakeup Status: Not hooked #: 275 Function Name: NtRequestPort Status: Not hooked #: 276 Function Name: NtRequestWaitReplyPort Status: Not hooked #: 277 Function Name: NtRequestWakeupLatency Status: Not hooked #: 278 Function Name: NtResetEvent Status: Not hooked #: 279 Function Name: NtResetWriteWatch Status: Not hooked #: 280 Function Name: NtRestoreKey Status: Not hooked #: 281 Function Name: NtResumeProcess Status: Not hooked #: 282 Function Name: NtResumeThread Status: Not hooked #: 283 Function Name: NtSaveKey Status: Not hooked #: 284 Function Name: NtSaveKeyEx Status: Not hooked #: 285 Function Name: NtSaveMergedKeys Status: Not hooked #: 286 Function Name: NtSecureConnectPort Status: Not hooked #: 287 Function Name: NtSetBootEntryOrder Status: Not hooked #: 288 Function Name: NtSetBootOptions Status: Not hooked #: 289 Function Name: NtSetContextThread Status: Not hooked #: 290 Function Name: NtSetDebugFilterState Status: Not hooked #: 291 Function Name: NtSetDefaultHardErrorPort Status: Not hooked #: 292 Function Name: NtSetDefaultLocale Status: Not hooked #: 293 Function Name: NtSetDefaultUILanguage Status: Not hooked #: 294 Function Name: NtSetDriverEntryOrder Status: Not hooked #: 295 Function Name: NtSetEaFile Status: Not hooked #: 296 Function Name: NtSetEvent Status: Not hooked #: 297 Function Name: NtSetEventBoostPriority Status: Not hooked #: 298 Function Name: NtSetHighEventPair Status: Not hooked #: 299 Function Name: NtSetHighWaitLowEventPair Status: Not hooked #: 300 Function Name: NtSetInformationDebugObject Status: Not hooked #: 301 Function Name: NtSetInformationFile Status: Not hooked #: 302 Function Name: NtSetInformationJobObject Status: Not hooked #: 303 Function Name: NtSetInformationKey Status: Not hooked #: 304 Function Name: NtSetInformationObject Status: Not hooked #: 305 Function Name: NtSetInformationProcess Status: Not hooked #: 306 Function Name: NtSetInformationThread Status: Not hooked #: 307 Function Name: NtSetInformationToken Status: Not hooked #: 308 Function Name: NtSetIntervalProfile Status: Not hooked #: 309 Function Name: NtSetIoCompletion Status: Not hooked #: 310 Function Name: NtSetLdtEntries Status: Not hooked #: 311 Function Name: NtSetLowEventPair Status: Not hooked #: 312 Function Name: NtSetLowWaitHighEventPair Status: Not hooked #: 313 Function Name: NtSetQuotaInformationFile Status: Not hooked #: 314 Function Name: NtSetSecurityObject Status: Not hooked #: 315 Function Name: NtSetSystemEnvironmentValue Status: Not hooked #: 316 Function Name: NtSetSystemEnvironmentValueEx Status: Not hooked #: 317 Function Name: NtSetSystemInformation Status: Not hooked #: 318 Function Name: NtSetSystemPowerState Status: Not hooked #: 319 Function Name: NtSetSystemTime Status: Not hooked #: 320 Function Name: NtSetThreadExecutionState Status: Not hooked #: 321 Function Name: NtSetTimer Status: Not hooked #: 322 Function Name: NtSetTimerResolution Status: Not hooked #: 323 Function Name: NtSetUuidSeed Status: Not hooked #: 324 Function Name: NtSetValueKey Status: Not hooked #: 325 Function Name: NtSetVolumeInformationFile Status: Not hooked #: 326 Function Name: NtShutdownSystem Status: Not hooked #: 327 Function Name: NtSignalAndWaitForSingleObject Status: Not hooked #: 328 Function Name: NtStartProfile Status: Not hooked #: 329 Function Name: NtStopProfile Status: Not hooked #: 330 Function Name: NtSuspendProcess Status: Not hooked #: 331 Function Name: NtSuspendThread Status: Not hooked #: 332 Function Name: NtSystemDebugControl Status: Not hooked #: 333 Function Name: NtTerminateJobObject Status: Not hooked #: 334 Function Name: NtTerminateProcess Status: Not hooked #: 335 Function Name: NtTerminateThread Status: Not hooked #: 336 Function Name: NtTestAlert Status: Not hooked #: 337 Function Name: NtThawRegistry Status: Not hooked #: 338 Function Name: NtThawTransactions Status: Not hooked #: 339 Function Name: NtTraceEvent Status: Not hooked #: 340 Function Name: NtTraceControl Status: Not hooked #: 341 Function Name: NtTranslateFilePath Status: Not hooked #: 342 Function Name: NtUnloadDriver Status: Not hooked #: 343 Function Name: NtUnloadKey Status: Not hooked #: 344 Function Name: NtUnloadKey2 Status: Not hooked #: 345 Function Name: NtUnloadKeyEx Status: Not hooked #: 346 Function Name: NtUnlockFile Status: Not hooked #: 347 Function Name: NtUnlockVirtualMemory Status: Not hooked #: 348 Function Name: NtUnmapViewOfSection Status: Not hooked #: 349 Function Name: NtVdmControl Status: Not hooked #: 350 Function Name: NtWaitForDebugEvent Status: Not hooked #: 351 Function Name: NtWaitForMultipleObjects Status: Not hooked #: 352 Function Name: NtWaitForSingleObject Status: Not hooked #: 353 Function Name: NtWaitHighEventPair Status: Not hooked #: 354 Function Name: NtWaitLowEventPair Status: Not hooked #: 355 Function Name: NtWriteFile Status: Not hooked #: 356 Function Name: NtWriteFileGather Status: Not hooked #: 357 Function Name: NtWriteRequestData Status: Not hooked #: 358 Function Name: NtWriteVirtualMemory Status: Not hooked #: 359 Function Name: NtYieldExecution Status: Not hooked #: 360 Function Name: NtCreateKeyedEvent Status: Not hooked #: 361 Function Name: NtOpenKeyedEvent Status: Not hooked #: 362 Function Name: NtReleaseKeyedEvent Status: Not hooked #: 363 Function Name: NtWaitForKeyedEvent Status: Not hooked #: 364 Function Name: NtQueryPortInformationProcess Status: Not hooked #: 365 Function Name: NtGetCurrentProcessorNumber Status: Not hooked #: 366 Function Name: NtWaitForMultipleObjects32 Status: Not hooked #: 367 Function Name: NtGetNextProcess Status: Not hooked #: 368 Function Name: NtGetNextThread Status: Not hooked #: 369 Function Name: NtCancelIoFileEx Status: Not hooked #: 370 Function Name: NtCancelSynchronousIoFile Status: Not hooked #: 371 Function Name: NtRemoveIoCompletionEx Status: Not hooked #: 372 Function Name: NtRegisterProtocolAddressInformation Status: Not hooked #: 373 Function Name: NtPropagationComplete Status: Not hooked #: 374 Function Name: NtPropagationFailed Status: Not hooked #: 375 Function Name: NtCreateWorkerFactory Status: Not hooked #: 376 Function Name: NtReleaseWorkerFactoryWorker Status: Not hooked #: 377 Function Name: NtWaitForWorkViaWorkerFactory Status: Not hooked #: 378 Function Name: NtSetInformationWorkerFactory Status: Not hooked #: 379 Function Name: NtQueryInformationWorkerFactory Status: Not hooked #: 380 Function Name: NtWorkerFactoryWorkerReady Status: Not hooked #: 381 Function Name: NtShutdownWorkerFactory Status: Not hooked #: 382 Function Name: NtCreateThreadEx Status: Not hooked #: 383 Function Name: NtCreateUserProcess Status: Not hooked #: 384 Function Name: NtQueryLicenseValue Status: Not hooked #: 385 Function Name: NtMapCMFModule Status: Not hooked #: 386 Function Name: NtIsUILanguageComitted Status: Not hooked #: 387 Function Name: NtFlushInstallUILanguage Status: Not hooked #: 388 Function Name: NtGetMUIRegistryInfo Status: Not hooked #: 389 Function Name: NtAcquireCMFViewOwnership Status: Not hooked #: 390 Function Name: NtReleaseCMFViewOwnership Status: Not hooked Stealth Objects ——————- Object: Hidden Code [ETHREAD: 0x8686fd78] Process: System Address: 0x864cba05 Size: 1534 Object: Hidden Code [ETHREAD: 0x8654ed78] Process: System Address: 0x864cda24 Size: 603 ==EOF==
I can see the injection into explorer but I cannot see where it is coming from. At this stage we have two options, if you are happy to continue I will try some other tools to see if I can narrow it down, but this may take time. If you wish to see a speedy resolution then I would recommend a full reinstall and reformat. The choice is yours..

If you wish to continue we can try a clean boot next and remove all drivers from the equation apart from MS ones

Step 1: Start the System Configuration Utility
1. Click Start, click Run, type msconfig, and then click OK.
2. The System Configuration Utility dialog box is displayed.

Step 2: Configure selective startup options
1. In the System Configuration Utility dialog box, click the General tab, and then click Selective Startup.
2. Click to clear the Process SYSTEM.INI File check box.
3. Click to clear the Process WIN.INI File check box.
4. Click to clear the Load Startup Items check box. Verify that Load System Services and Use Original BOOT.INI are checked.
5. Click the Services tab.
6. Click to select the Hide All Microsoft Services check box.
7. Click Disable All, and then click OK.
When you are prompted, click Restart to restart the computer.

Step 3: Log on to Windows
If you are prompted, log on to Windows.
When you receive the following message, click to select the Don't show this message or launch the System Configuration Utility when Windows start check box, and then click OK.

You have used the System Configuration Utility to make changes to the way Windows starts.
The System Configuration Utility is currently in Diagnostic or Selective Startup mode, causing this message to be displayed and the utility to run every time Windows starts.


Once you are started with just the basics then try both programmes again - But download fresh copies and rename both files before saving (TDSSKiller and Combofix)
Hello again. I followed your steps, and its definitely a microsoft driver or the like that is causing problems, as disabling all of the 3rd party drivers ends up in the same result. But this time Combofix didnt crash to a bluescreen the computer just froze. Unfortunately, reformat and reinstall is not a practical option for me right now as the only external hard drive I have is 160Gb and as you can see my volume is 465gb so I can not feasibly backup all my important data at this time. I am willing to be patient with you in finding out why I can't boot into safe mode because I believe that once I can successfully get into safe mode i can run the good tools like combofix. I know combofix will likely fix or help reduce the problems Ive been having because it killed a similar rootkit in the past. I have confidence in you EssexBoy and it might take longer than we both may have thought but hopefully we can DESTROY this rootkit!! :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI