ok, please take your time. I appreciate you patience and persistence with this rootkit. It's easily the nastiest infection I have ever had on a computer of mine.
I found something that may help you… I ran a dr web cureit scan and it found evidence of the rootkit running inside of explorer.exe, but it did not successfully remove it as on reboot it picked it up again. It is the infamous TDSS 565. Here is a picture of what it found.
OK that tells me it is running in memory - so it is injecting explorer on reboot. Could you run Dr Web again and let it remove it but do not reboot. Immediately try to run either combofix or TDSSKiller - I am still running over the entire thread looking for anything that I may have missed
Ok. I will try that. So do you mean immediately after it detects and "erradicates" it to attempt to run of those programs? Or wait till the entire scan finishes?
As soon as it has erradicated the memory component stop the scan and then try either of the other two tools
Ughhh. Still not going. I have some information that might help you. TDSS Killer was terminated after a few seconds. Combofix crashes to a BSOD saying to "Run the driver verifier blah blah" The specific STOP was
0x000000C5 (0x0000000, 0x00000002, 0x00000001, 0x825197AE)
On attempting to boot into safe mode, the BSOD says
0x0000007B (0x80699BBD, 0xC0000034, 0x00000000, 0x00000000)
Thanks for that - Still reviewing the logs - may take a tad longer
Ok, please take your time. No rush.
The error code states that it is a driver crashing - so I would like two quick programme runs to see what is evident. They are both quite fast
Please
RIGHT-CLICK HERE and Save As (in IE it's "Save Target As", in FF it's "Save Link As") to download Silent Runners.
Save it to the desktop. Run Silent Runner's by doubleclicking the "Silent Runners" icon on your desktop. You will receive a prompt:
Do you want to skip supplementary searches?
click NO If you receive an error just click OK and double-click it to run it again - sometimes it won't run as it's supposed to the first time but will in subsequent runs. You will see a text file appear on the desktop - it's not done, let it run (it won't appear to be doing anything!) Once you receive the prompt All Done! , open the text file on the desktop, copy that entire log, and paste it here. *NOTE* If you receive any warning message about scripts, please choose to allow the script to run.
THEN
Download RootRepeal from the following location and save it to your desktop.
Zip Mirrors (Recommended)
Rar Mirrors - Only if you know what a RAR is and can extract it.
Extract RootRepeal.exe from the archive. Open [external image: Posted Image] on your desktop. Click the [external image: Posted Image] tab. Click the [external image: Posted Image] button. Check all seven boxes: [external image: Posted Image] Push Ok Check the box for your main system drive (Usually C:), and press Ok. Allow RootRepeal to run a scan of your system. This may take some time. Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.
Here is the log from Silent Runners. Rootkit Repeal is currently scanning. It's taking a loooooooooong time to scan the "\windows\winsxs\Manifests" folder and its using over 1gb of my memory. Is this normal? It kind of sounds like a memory leak.
"Silent Runners.vbs", revision 63, http://www.silentrunners.org/
Operating System: Windows Vista SP1
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
———————————
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"ehTray.exe" = "C:\Windows\ehome\ehTray.exe" [MS]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"Windows Defender" = "%ProgramFiles%\Windows Defender\MSASCui.exe -hide" [MS]
"PWRISOVM.EXE" = "C:\Program Files\PowerISO\PWRISOVM.EXE" ["PowerISO Computing, Inc."]
"QuickTime Task" = ""C:\Program Files\QuickTime\QTTask.exe" -atboottime" ["Apple Inc."]
"iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Inc."]
"BCSSync" = ""C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices" [MS]
"Grid Service" = ""C:\Program Files\GridService\peer.exe" -n Grid" ["FS2YOU"]
"TkBellExe" = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."]
"UnlockerAssistant" = ""C:\Program Files\Unlocker\UnlockerAssistant.exe"" [null data]
"avast5" = ""C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui" ["AVAST Software"]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM…CLSID} = "Adobe PDF Reader Link Helper"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{0A0DDBD3-6641-40B9-873F-BBDD26D6C14E}\(Default) = (no title provided)
-> {HKLM…CLSID} = "IE2EMBHO Class"
\InProcServer32\(Default) = "C:\Program Files\easyMule\modules\IE2EM.dll" ["VeryCD.com"]
{3049C3E9-B461-4BC5-8870-4C09146192CA}\(Default) = (no title provided)
-> {HKLM…CLSID} = "RealPlayer Download and Record Plugin for Internet Explorer"
\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll" ["RealPlayer"]
{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\(Default) = (no title provided)
-> {HKLM…CLSID} = "Groove GFS Browser Helper"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
{9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided)
-> {HKLM…CLSID} = "Windows Live Sign-in Helper"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" [MS]
{B4F3A835-0E21-4959-BA22-42B3008E02FF}\(Default) = "URLRedirectionBHO"
-> {HKLM…CLSID} = "Office Document Cache Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL" [MS]
{bf00e119-21a3-4fd1-b178-3b8537e75c92}\(Default) = "MegaIEMn"
-> {HKLM…CLSID} = "IeMonitorBho Class"
\InProcServer32\(Default) = "C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll" ["Megaupload Limited"]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\
Groove Explorer Icon Overlay 1 (GFS Unread Stub)\(Default) = "{99FD978C-D287-4F50-827F-B2C658EDA8E7}"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 1 (GFS Unread Stub)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
Groove Explorer Icon Overlay 2 (GFS Stub)\(Default) = "{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 2 (GFS Stub)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)\(Default) = "{920E6DB1-9907-4370-B3A0-BAFC03D81399}"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
Groove Explorer Icon Overlay 3 (GFS Folder)\(Default) = "{16F3DD56-1AF5-4347-846D-7C10C4192619}"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 3 (GFS Folder)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
Groove Explorer Icon Overlay 4 (GFS Unread Mark)\(Default) = "{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 4 (GFS Unread Mark)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}" = "InternetShortcut"
-> {HKCU…CLSID} = "Internet Shortcut"
\InProcServer32\(Default) = "shdocvw.dll" [MS]
"{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
"{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
"{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
"{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
"{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}" = "PowerISO"
-> {HKLM…CLSID} = "PowerISO"
\InProcServer32\(Default) = "C:\Program Files\PowerISO\PWRISOSH.DLL" ["PowerISO Computing, Inc."]
"{23170F69-40C1-278A-1000-000100020000}" = "7-Zip Shell Extension"
-> {HKLM…CLSID} = "7-Zip Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\7-Zip\7-zip.dll" ["Igor Pavlov"]
"{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
-> {HKLM…CLSID} = "DesktopContext Class"
\InProcServer32\(Default) = "C:\Windows\system32\nvcpl.dll" ["NVIDIA Corporation"]
"{4ADF8C01-0AC7-4403-888C-012E6EA2F67E}" = "Sims2Pack Clean Installer Shell Extension"
-> {HKLM…CLSID} = "S2PCISE.S2PCISE"
\InProcServer32\(Default) = "mscoree.dll" [MS]
"{0563DB41-F538-4B37-A92D-4659049B7766}" = "WLMD Message Handler"
-> {HKLM…CLSID} = "CLSID_WLMCMimeFilter"
\InProcServer32\(Default) = "C:\Program Files\Windows Live\Mail\mailcomm.dll" [MS]
"{0E223B1F-FF38-452A-AC36-E2A6E8561F8B}" = "iPhone"
-> {HKLM…CLSID} = "iPhone"
\InProcServer32\(Default) = "C:\Program Files\ImTOO\iPod Computer Transfer\IPhoneExplorer.dll" [null data]
"{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}" = "UnlockerShellExtension"
-> {HKLM…CLSID} = "UnlockerShellExtension"
\InProcServer32\(Default) = "C:\Program Files\Unlocker\UnlockerCOM.dll" [null data]
"{D9D587F5-8284-45CC-AA5C-D2123D8852D9}" = "iPhone filesystem view"
-> {HKLM…CLSID} = "iPhone folders"
\InProcServer32\(Default) = "C:\Program Files\iPhone Folders\\iPhoneNSE.dll" ["Artem Redart Bozhenov"]
"{89EE4B92-EA79-4414-9BF9-CFCA8922C6F7}" = "iPhoneFolders Property Sheet"
-> {HKLM…CLSID} = "iPhoneFolders Property Sheet"
\InProcServer32\(Default) = "C:\Program Files\iPhone Folders\\iPhoneNSE.dll" ["Artem Redart Bozhenov"]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {HKLM…CLSID} = "RealOne Player Context Menu Class"
\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"
-> {HKLM…CLSID} = "iTunes"
\InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Inc."]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKCU…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\msohevi.dll" [file not found]
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office14\msohevi.dll" [MS]
"{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}" = "Microsoft Office Metadata Handler"
-> {HKLM…CLSID} = "Microsoft Office Metadata Handler"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll" [MS]
"{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}" = "Microsoft Office Thumbnail Handler"
-> {HKLM…CLSID} = "Microsoft Office Thumbnail Handler"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll" [MS]
"{3D60EDA7-9AB4-4DA8-864C-D9B5F2E7281D}" = "Groove Namespace Extension"
-> {HKLM…CLSID} = "Workspaces"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
"{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}" = "Microsoft OneNote Namespace Extension for Windows Desktop Search"
-> {HKLM…CLSID} = "Microsoft OneNote Namespace Extension for Windows Desktop Search"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office14\ONFILTER.DLL" [MS]
"{506F4668-F13E-4AA1-BB04-B43203AB3CC0}" = "{506F4668-F13E-4AA1-BB04-B43203AB3CC0}"
-> {HKLM…CLSID} = "ImageExtractorShellExt Class"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office14\VISSHE.DLL" [MS]
"{D66DC78C-4F61-447F-942B-3FB6980118CF}" = "{D66DC78C-4F61-447F-942B-3FB6980118CF}"
-> {HKLM…CLSID} = "CInfoTipShellExt Class"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office14\VISSHE.DLL" [MS]
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}" = "Groove GFS Browser Helper"
-> {HKLM…CLSID} = "Groove GFS Browser Helper"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
"{6C467336-8281-4E60-8204-430CED96822D}" = "Groove GFS Context Menu Handler"
-> {HKLM…CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}" = "Groove GFS Explorer Bar"
-> {HKLM…CLSID} = "Groove Folder Synchronization"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
"{16F3DD56-1AF5-4347-846D-7C10C4192619}" = "Groove Explorer Icon Overlay 3 (GFS Folder)"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 3 (GFS Folder)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" = "Groove GFS Stub Execution Hook"
-> {HKLM…CLSID} = "Groove GFS Stub Execution Hook"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
"{A449600E-1DC6-4232-B948-9BD794D62056}" = "Groove GFS Stub Icon Handler"
-> {HKLM…CLSID} = "Groove GFS Stub Icon Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
"{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}" = "Groove Explorer Icon Overlay 2 (GFS Stub)"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 2 (GFS Stub)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
"{920E6DB1-9907-4370-B3A0-BAFC03D81399}" = "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
"{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}" = "Groove Explorer Icon Overlay 4 (GFS Unread Mark)"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 4 (GFS Unread Mark)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
"{99FD978C-D287-4F50-827F-B2C658EDA8E7}" = "Groove Explorer Icon Overlay 1 (GFS Unread Stub)"
-> {HKLM…CLSID} = "Groove Explorer Icon Overlay 1 (GFS Unread Stub)"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
"{387E725D-DC16-4D76-B310-2C93ED4752A0}" = "Groove XML Icon Handler"
-> {HKLM…CLSID} = "Groove XML Icon Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
"{00020D75-0000-0000-C000-000000000046}" = "Microsoft Outlook Desktop Icon Handler"
-> {HKLM…CLSID} = "Microsoft Outlook"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\MLSHEXT.DLL" [MS]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {HKLM…CLSID} = "Outlook File Icon Extension"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office14\OLKFSTUB.DLL" [MS]
"{0561EC90-CE54-4f0c-9C55-E226110A740C}" = "Haali Column Provider"
-> {HKLM…CLSID} = "Haali Column Provider"
\InProcServer32\(Default) = "C:\Windows\system32\mmfinfo.dll" [null data]
"{5574006C-28F5-4a65-A28C-74DE6BFBE0BB}" = "Haali Matroska Shell Property Page"
-> {HKLM…CLSID} = "Haali Matroska Shell Property Page"
\InProcServer32\(Default) = "C:\Windows\system32\mmfinfo.dll" [null data]
"{327669A0-59A7-4be9-B99E-1C9F3A57611A}" = "Haali Matroska Thumbnail Extractor"
-> {HKLM…CLSID} = "Haali Matroska Thumbnail Extractor"
\InProcServer32\(Default) = "C:\Windows\system32\mmfinfo.dll" [null data]
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
-> {HKLM…CLSID} = "NVIDIA CPL Extension"
\InProcServer32\(Default) = "C:\Windows\system32\nvcpl.dll" ["NVIDIA Corporation"]
"{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9}" = "NVIDIA Play On My TV Context Menu Extension"
-> {HKLM…CLSID} = "NVIDIA CPL Context Menu Extension"
\InProcServer32\(Default) = "C:\Windows\system32\nvshext.dll" ["NVIDIA Corporation"]
"{3FCEF010-09A4-11D4-8D3B-D12F9D3D8B02}" = "TIShelEx Shell Extension"
-> {HKLM…CLSID} = "FileTimeShlExt Class"
\InProcServer32\(Default) = "C:\PROGRA~2\COMMON~1\TISHAR~1\TICONN~1\TIShlExt.dll" ["Texas Instruments Incorporated"]
"{FC6ABB6A-36E7-4622-841B-23687F423AE8}" = "ZipScanEval"
-> {HKLM…CLSID} = "FindMenuEval Class"
\InProcServer32\(Default) = "C:\Program Files\ZipScan Evaluation\zscom.dll" ["Adrian Bhagat"]
"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
-> {HKLM…CLSID} = "avast"
\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast5\ashShell.dll" ["AVAST Software"]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<> "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" = "Groove GFS Stub Execution Hook"
-> {HKLM…CLSID} = "Groove GFS Stub Execution Hook"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\
<> text/xml\CLSID = "{807573E5-5146-11D5-A672-00B0D022E945}"
-> {HKLM…CLSID} = "Microsoft Office InfoPath XML Mime Filter"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL" [MS]
HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\
<> ms-help\CLSID = "{314111c7-a502-11d2-bbca-00c04f8ec294}"
-> {HKLM…CLSID} = "HxProtocol Class"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll" [MS]
<> msnim\CLSID = "{828030A1-22C1-4009-854F-8E305202313F}"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = ""C:\PROGRA~2\MSNMES~1\msgrapp.dll"" [MS]
<> wlmailhtml\CLSID = "{03C514A3-1EFB-4856-9F99-10D7BE1653C0}"
-> {HKLM…CLSID} = "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler"
\InProcServer32\(Default) = "C:\Program Files\Windows Live\Mail\mailcomm.dll" [MS]
HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
7-Zip\(Default) = "{23170F69-40C1-278A-1000-000100020000}"
-> {HKLM…CLSID} = "7-Zip Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\7-Zip\7-zip.dll" ["Igor Pavlov"]
avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM…CLSID} = "avast"
\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast5\ashShell.dll" ["AVAST Software"]
PowerISO\(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
-> {HKLM…CLSID} = "PowerISO"
\InProcServer32\(Default) = "C:\Program Files\PowerISO\PWRISOSH.DLL" ["PowerISO Computing, Inc."]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
-> {HKLM…CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
ZipScanEval\(Default) = "{FC6ABB6A-36E7-4622-841B-23687F423AE8}"
-> {HKLM…CLSID} = "FindMenuEval Class"
\InProcServer32\(Default) = "C:\Program Files\ZipScan Evaluation\zscom.dll" ["Adrian Bhagat"]
HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\
MBAMShlExt\(Default) = "{57CE581A-0CB6-4266-9CA0-19364C90A0B3}"
-> {HKLM…CLSID} = "MBAMShlExt Class"
\InProcServer32\(Default) = "C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll" ["Malwarebytes Corporation"]
UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"
-> {HKLM…CLSID} = "UnlockerShellExtension"
\InProcServer32\(Default) = "C:\Program Files\Unlocker\UnlockerCOM.dll" [null data]
XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
-> {HKLM…CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\
7-Zip\(Default) = "{23170F69-40C1-278A-1000-000100020000}"
-> {HKLM…CLSID} = "7-Zip Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\7-Zip\7-zip.dll" ["Igor Pavlov"]
PowerISO\(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
-> {HKLM…CLSID} = "PowerISO"
\InProcServer32\(Default) = "C:\Program Files\PowerISO\PWRISOSH.DLL" ["PowerISO Computing, Inc."]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
-> {HKLM…CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
ZipScanEval\(Default) = "{FC6ABB6A-36E7-4622-841B-23687F423AE8}"
-> {HKLM…CLSID} = "FindMenuEval Class"
\InProcServer32\(Default) = "C:\Program Files\ZipScan Evaluation\zscom.dll" ["Adrian Bhagat"]
HKLM\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\
FileZilla3CopyHook\(Default) = "{DB70412E-EEC9-479C-BBA9-BE36BFDDA41B}"
-> {HKLM…CLSID} = "FileZilla 3 Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\FileZilla FTP Client\fzshellext.dll" [null data]
HKLM\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\
7-Zip\(Default) = "{23170F69-40C1-278A-1000-000100020000}"
-> {HKLM…CLSID} = "7-Zip Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\7-Zip\7-zip.dll" ["Igor Pavlov"]
WinZip\(Default) = "{E0D79305-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
HKLM\SOFTWARE\Classes\Directory\Background\shellex\ContextMenuHandlers\
aZipScanEval\(Default) = "{FC6ABB6A-36E7-4622-841B-23687F423AE8}"
-> {HKLM…CLSID} = "FindMenuEval Class"
\InProcServer32\(Default) = "C:\Program Files\ZipScan Evaluation\zscom.dll" ["Adrian Bhagat"]
NvCplDesktopContext\(Default) = "{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9}"
-> {HKLM…CLSID} = "NVIDIA CPL Context Menu Extension"
\InProcServer32\(Default) = "C:\Windows\system32\nvshext.dll" ["NVIDIA Corporation"]
XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
-> {HKLM…CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\
{04DAAD08-70EF-450E-834A-DCFAF9B48748}\(Default) = "Folder Size column"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\FolderSize\FolderSizeColumn.dll" ["Brio"]
{0561EC90-CE54-4f0c-9C55-E226110A740C}\(Default) = "Haali Column Provider"
-> {HKLM…CLSID} = "Haali Column Provider"
\InProcServer32\(Default) = "C:\Windows\system32\mmfinfo.dll" [null data]
{140B30F3-E361-409F-8461-95C795AE09F9}\(Default) = (no title provided)
-> {HKLM…CLSID} = "ColHandler Class"
\InProcServer32\(Default) = "C:\Windows\system32\dirsize.dll" [empty string]
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
-> {HKLM…CLSID} = "PDF Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]
HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM…CLSID} = "avast"
\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast5\ashShell.dll" ["AVAST Software"]
MBAMShlExt\(Default) = "{57CE581A-0CB6-4266-9CA0-19364C90A0B3}"
-> {HKLM…CLSID} = "MBAMShlExt Class"
\InProcServer32\(Default) = "C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll" ["Malwarebytes Corporation"]
PowerISO\(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
-> {HKLM…CLSID} = "PowerISO"
\InProcServer32\(Default) = "C:\Program Files\PowerISO\PWRISOSH.DLL" ["PowerISO Computing, Inc."]
S2PCI\(Default) = "{4ADF8C01-0AC7-4403-888C-012E6EA2F67E}"
-> {HKLM…CLSID} = "S2PCISE.S2PCISE"
\InProcServer32\(Default) = "mscoree.dll" [MS]
UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"
-> {HKLM…CLSID} = "UnlockerShellExtension"
\InProcServer32\(Default) = "C:\Program Files\Unlocker\UnlockerCOM.dll" [null data]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
-> {HKLM…CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\
WinZip\(Default) = "{E0D79305-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
Default executables:
——————–
<> HKCU\Software\Classes\.bat\(Default) = "batfile"
<> HKCU\Software\Classes\.cmd\(Default) = "cmdfile"
<> HKCU\Software\Classes\.com\(Default) = "comfile"
<> HKCU\Software\Classes\.exe\(Default) = "exefile"
HKCU\Software\Classes\.exe\shell\open\command\(Default) = (value not set)
<> HKCU\Software\Classes\.pif\(Default) = "piffile"
Group Policies {GPedit.msc branch and setting}:
———————————————–
Note: detected settings may not have any effect.
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\
"LowRiskFileTypes" = (REG_SZ) /{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:
{unrecognized setting}
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\
"SaveZoneInformation" = (REG_DWORD) dword:0x00000001
{User Configuration|Administrative Templates|Windows Components|Attachment Manager|
Do not preserve zone information in file attachments}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\
"AllowLegacyWebView" = (REG_DWORD) dword:0x00000001
{unrecognized setting}
"AllowUnhashedWebView" = (REG_DWORD) dword:0x00000001
{unrecognized setting}
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\
"disableregistrytools" = (REG_DWORD) dword:0x00000000
{User Configuration|Administrative Templates|System|
Prevent access to registry editing tools}
"DisableTaskMgr" = (REG_DWORD) dword:0x00000000
{unrecognized setting}
HKCU\Software\Policies\Microsoft\Windows\System\
"disablecmd" = (REG_DWORD) dword:0x00000000
{User Configuration|Administrative Templates|System|
Prevent access to the command prompt}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\
"EnableLUA" = (REG_DWORD) dword:0x00000000
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Run All Administrators In Admin Approval Mode}
Active Desktop and Wallpaper:
—————————–
Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\Windows\system32\config\systemprofile\Pictures\thanksgiving.jpg"
Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Users\Buddy\Pictures\thanksgiving.jpg"
Enabled Screen Saver:
———————
HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\Windows\system32\Bubbles.scr" [MS]
Windows Portable Device AutoPlay Handlers
—————————————–
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\
BridgeCS3ImportMediaOnArrival\
"Provider" = "Adobe Bridge CS3"
"InvokeProgID" = "Adobe.adobebridge"
"InvokeVerb" = "launch"
HKLM\SOFTWARE\Classes\Adobe.adobebridge\shell\launch\command\(Default) = "C:\Program Files\Adobe\Adobe Bridge CS3\bridgeproxy.exe -v %1" ["Adobe Systems, Inc."]
ImgBurnBDBurningOnArrival_BuildImage\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "HandleBDBurningOnArrival_BuildImage"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\HandleBDBurningOnArrival_BuildImage\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE BUILD /OUTPUTMODE DEVICE /DEST "%1"" ["LIGHTNING UK!"]
ImgBurnBDBurningOnArrival_BurnImage\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "HandleBDBurningOnArrival_BurnImage"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\HandleBDBurningOnArrival_BurnImage\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE WRITE /DEST "%1"" ["LIGHTNING UK!"]
ImgBurnCDBurningOnArrival_BuildImage\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "HandleCDBurningOnArrival_BuildImage"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\HandleCDBurningOnArrival_BuildImage\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE BUILD /OUTPUTMODE DEVICE /DEST "%1"" ["LIGHTNING UK!"]
ImgBurnCDBurningOnArrival_BurnImage\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "HandleCDBurningOnArrival_BurnImage"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\HandleCDBurningOnArrival_BurnImage\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE WRITE /DEST "%1"" ["LIGHTNING UK!"]
ImgBurnDVDBurningOnArrival_BuildImage\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "HandleDVDBurningOnArrival_BuildImage"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\HandleDVDBurningOnArrival_BuildImage\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE BUILD /OUTPUTMODE DEVICE /DEST "%1"" ["LIGHTNING UK!"]
ImgBurnDVDBurningOnArrival_BurnImage\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "HandleDVDBurningOnArrival_BurnImage"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\HandleDVDBurningOnArrival_BurnImage\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE WRITE /DEST "%1"" ["LIGHTNING UK!"]
ImgBurnHDDVDBurningOnArrival_BuildImage\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "HandleHDDVDBurningOnArrival_BuildImage"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\HandleHDDVDBurningOnArrival_BuildImage\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE BUILD /OUTPUTMODE DEVICE /DEST "%1"" ["LIGHTNING UK!"]
ImgBurnHDDVDBurningOnArrival_BurnImage\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "HandleHDDVDBurningOnArrival_BurnImage"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\HandleHDDVDBurningOnArrival_BurnImage\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE WRITE /DEST "%1"" ["LIGHTNING UK!"]
ImgBurnPlayBluRayOnArrival_ReadDisc\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "PlayBluRayOnArrival_ReadDisc"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\PlayBluRayOnArrival_ReadDisc\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE READ /SRC "%1"" ["LIGHTNING UK!"]
ImgBurnPlayCDAudioOnArrival_ReadDisc\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "PlayCDAudioOnArrival_ReadDisc"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\PlayCDAudioOnArrival_ReadDisc\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE READ /SRC "%1"" ["LIGHTNING UK!"]
ImgBurnPlayDVDMovieOnArrival_ReadDisc\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "PlayDVDMovieOnArrival_ReadDisc"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\PlayDVDMovieOnArrival_ReadDisc\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE READ /SRC "%1"" ["LIGHTNING UK!"]
ImgBurnPlayHDDVDOnArrival_ReadDisc\
"Provider" = "ImgBurn"
"InvokeProgID" = "ImgBurn.AutoPlay.1"
"InvokeVerb" = "PlayHDDVDOnArrival_ReadDisc"
HKLM\SOFTWARE\Classes\ImgBurn.AutoPlay.1\shell\PlayHDDVDOnArrival_ReadDisc\command\(Default) = ""C:\Program Files\ImgBurn\ImgBurn.exe" /MODE READ /SRC "%1"" ["LIGHTNING UK!"]
iTunesBurnCDOnArrival\
"Provider" = "iTunes"
"InvokeProgID" = "iTunes.BurnCD"
"InvokeVerb" = "burn"
HKLM\SOFTWARE\Classes\iTunes.BurnCD\shell\burn\command\(Default) = ""C:\Program Files\iTunes\iTunes.exe" /AutoPlayBurn "%L"" ["Apple Inc."]
iTunesImportSongsOnArrival\
"Provider" = "iTunes"
"InvokeProgID" = "iTunes.ImportSongsOnCD"
"InvokeVerb" = "import"
HKLM\SOFTWARE\Classes\iTunes.ImportSongsOnCD\shell\import\command\(Default) = ""C:\Program Files\iTunes\iTunes.exe" /AutoPlayImportSongs "%L"" ["Apple Inc."]
iTunesPlaySongsOnArrival\
"Provider" = "iTunes"
"InvokeProgID" = "iTunes.PlaySongsOnCD"
"InvokeVerb" = "play"
HKLM\SOFTWARE\Classes\iTunes.PlaySongsOnCD\shell\play\command\(Default) = ""C:\Program Files\iTunes\iTunes.exe" /playCD "%L"" ["Apple Inc."]
iTunesShowSongsOnArrival\
"Provider" = "iTunes"
"InvokeProgID" = "iTunes.ShowSongsOnCD"
"InvokeVerb" = "showsongs"
HKLM\SOFTWARE\Classes\iTunes.ShowSongsOnCD\shell\showsongs\command\(Default) = ""C:\Program Files\iTunes\iTunes.exe" /AutoPlayShowSongs "%L"" ["Apple Inc."]
MMVerizonApp\
"Provider" = "V CAST Media Manager"
"ProgID" = "MediaManager.Verizon"
"InitCmdLine" = "C:\Program Files\V CAST Media Manager\VCASTMediaManager.exe"
HKLM\SOFTWARE\Classes\MediaManager.Verizon\CLSID\(Default) = "{F62AD501-DFDC-4f9e-80F3-A5640C0FAE72}"
-> {HKLM…CLSID} = "V CAST Media manager"
\LocalServer32\(Default) = "VCASTMediaManager.exe" [file not found]
MPCPlayCDAudioOnArrival\
"Provider" = "Media Player Classic"
"InvokeProgID" = "MediaPlayerClassic.Autorun"
"InvokeVerb" = "PlayCDAudio"
HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayCDAudio\command\(Default) = ""C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe" %1 /cd" ["Gabest"]
MPCPlayDVDMovieOnArrival\
"Provider" = "Media Player Classic"
"InvokeProgID" = "MediaPlayerClassic.Autorun"
"InvokeVerb" = "PlayDVDMovie"
HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayDVDMovie\command\(Default) = ""C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe" %1 /dvd" ["Gabest"]
MPCPlayMusicFilesOnArrival\
"Provider" = "Media Player Classic"
"InvokeProgID" = "MediaPlayerClassic.Autorun"
"InvokeVerb" = "PlayMusicFiles"
HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayMusicFiles\command\(Default) = ""C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe" %1" ["Gabest"]
MPCPlayVideoFilesOnArrival\
"Provider" = "Media Player Classic"
"InvokeProgID" = "MediaPlayerClassic.Autorun"
"InvokeVerb" = "PlayVideoFiles"
HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayVideoFiles\command\(Default) = ""C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe" %1" ["Gabest"]
NeroAutoPlay9AudioToNeroDigital\
"Provider" = "Nero SoundTrax"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "AudioToNeroDigital_PlayCDAudioOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\AudioToNeroDigital_PlayCDAudioOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero SoundTrax\SoundTrax.exe /" [file not found]
NeroAutoPlay9CDAudio\
"Provider" = "Nero Express"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "CDAudio_HandleCDBurningOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\CDAudio_HandleCDBurningOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero Express\NeroExpress.exe -w /New:AudioCD" [file not found]
NeroAutoPlay9CopyCD\
"Provider" = "Nero Express"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "CopyCD_PlayMusicFilesOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\CopyCD_PlayMusicFilesOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero Express\NeroExpress.exe -w /Dialog:DiscCopy" [file not found]
NeroAutoPlay9DataDisc\
"Provider" = "Nero Express"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "DataDisc_HandleCDBurningOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\DataDisc_HandleCDBurningOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero Express\NeroExpress.exe -w /New:ISODisc" [file not found]
NeroAutoPlay9DVDVideoToNeroDigital\
"Provider" = "Nero Recode"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "DVDVideoToNeroDigital_PlayDVDMovieOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\DVDVideoToNeroDigital_PlayDVDMovieOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero Recode\Recode.exe /New:ReAuthorNeroDigital" [file not found]
NeroAutoPlay9LaunchNeroStartSmart\
"Provider" = "Nero StartSmart"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "LaunchNeroStartSmart_HandleCDBurningOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\LaunchNeroStartSmart_HandleCDBurningOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero StartSmart\NeroStartSmart.exe /AutoPlay" [file not found]
NeroAutoPlay9PlayAudioCD\
"Provider" = "Nero ShowTime"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "PlayAudioCD_PlayMusicFilesOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\PlayAudioCD_PlayMusicFilesOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero ShowTime\ShowTime.exe /Play %L" [file not found]
NeroAutoPlay9PlayDVD\
"Provider" = "Nero ShowTime"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "PlayDVD_PlayVideoFilesOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\PlayDVD_PlayVideoFilesOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero ShowTime\ShowTime.exe /Play %L" [file not found]
NeroAutoPlay9RipCD\
"Provider" = "Nero Burning ROM"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "RipCD_PlayCDAudioOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\RipCD_PlayCDAudioOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero Burning ROM\Nero.exe /Dialog:SaveTracks %L" [file not found]
NeroAutoPlay9TranscodeVideo\
"Provider" = "Nero Recode"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "TranscodeVideo_PlayDVDMovieOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\TranscodeVideo_PlayDVDMovieOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero Recode\Recode.exe /New:CopyDVDVideo" [file not found]
NeroAutoPlay9VideoCapture\
"Provider" = "Nero Vision"
"ProgID" = "Shell.HWEventHandlerShellExecute"
"InitCmdLine" = ""C:\Program Files\Nero\Nero 9\Nero Vision\NeroVision.exe" /New:VideoCapture"
HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}"
-> {HKLM…CLSID} = "Shell Execute Hardware Event Handler"
\LocalServer32\(Default) = "C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]
NeroAutoPlay9ViewPhotos\
"Provider" = "Nero PhotoSnap Viewer"
"InvokeProgID" = "Nero.AutoPlay8"
"InvokeVerb" = "ViewPhotos_ShowPicturesOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay8\shell\ViewPhotos_ShowPicturesOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 9\Nero PhotoSnap\PhotoSnapViewer.exe /" [file not found]
RPCDBurningOnArrival\
"Provider" = "RealPlayer"
"InvokeProgID" = "RealPlayer.CDBurn.6"
"InvokeVerb" = "open"
HKCU\Software\Classes\RealPlayer.CDBurn.6\shell\open\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /burn "%1"" ["RealNetworks, Inc."]
RPDeviceOnArrival\
"Provider" = "RealPlayer"
"ProgID" = "RealPlayer.HWEventHandler"
HKLM\SOFTWARE\Classes\RealPlayer.HWEventHandler\CLSID\(Default) = "{67E76F1D-BDE2-4052-913C-2752366192D2}"
-> {HKLM…CLSID} = "RealNetworks Scheduler"
\LocalServer32\(Default) = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -autoplay" ["RealNetworks, Inc."]
RPPlayCDAudioOnArrival\
"Provider" = "RealPlayer"
"InvokeProgID" = "RealPlayer.AudioCD.6"
"InvokeVerb" = "play"
HKCU\Software\Classes\RealPlayer.AudioCD.6\shell\play\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /play %1 " ["RealNetworks, Inc."]
RPPlayDVDMovieOnArrival\
"Provider" = "RealPlayer"
"InvokeProgID" = "RealPlayer.DVD.6"
"InvokeVerb" = "play"
HKCU\Software\Classes\RealPlayer.DVD.6\shell\play\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /dvd %1 " ["RealNetworks, Inc."]
RPPlayMediaOnArrival\
"Provider" = "RealPlayer"
"InvokeProgID" = "RealPlayer.AutoPlay.6"
"InvokeVerb" = "open"
HKCU\Software\Classes\RealPlayer.AutoPlay.6\shell\open\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /autoplay "%1"" ["RealNetworks, Inc."]
VCASTMediaManagerAutoPlay_1500906\
"Provider" = "V CAST Media Manager"
"InvokeProgID" = "VCASTMediaManagerAutoPlay"
"InvokeVerb" = "VCASTMediaManagerAutoPlay_1500906"
HKLM\SOFTWARE\Classes\VCASTMediaManagerAutoPlay\shell\VCASTMediaManagerAutoPlay_1500906\command\(Default) = ""C:\Program Files\V CAST Media Manager\VCASTMediaManager.exe"" ["Smith Micro, Inc."]
VerizonMediaManagerBurnCDOnArrival\
"Provider" = "V CAST Media Manager"
"InvokeProgID" = "MMVerizon.VolAutoPlay"
"InvokeVerb" = "HandleCDBurningOnArrival_CDAudio"
HKLM\SOFTWARE\Classes\MMVerizon.VolAutoPlay\shell\HandleCDBurningOnArrival_CDAudio\command\(Default) = "C:\Program Files\V CAST Media Manager\VCASTMediaManager.exe /BurnCD /Drive:%L" ["Smith Micro, Inc."]
VerizonMediaManagerRipCDOnArrival\
"Provider" = "V CAST Media Manager"
"InvokeProgID" = "MMVerizon.VolAutoPlay"
"InvokeVerb" = "PlayCDAudioOnArrival_RipCD"
HKLM\SOFTWARE\Classes\MMVerizon.VolAutoPlay\shell\PlayCDAudioOnArrival_RipCD\command\(Default) = "C:\Program Files\V CAST Media Manager\VCASTMediaManager.exe /RipCD /Drive:%L" ["Smith Micro, Inc."]
VLCPlayCDAudioOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.CDAudio"
"InvokeVerb" = "Open"
HKLM\SOFTWARE\Classes\VLC.CDAudio\shell\Open\command\(Default) = ""C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file cdda://%1" ["the VideoLAN Team"]
VLCPlayDVDAudioOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.OPENFolder"
"InvokeVerb" = "Open"
HKLM\SOFTWARE\Classes\VLC.OPENFolder\shell\Open\command\(Default) = ""C:\Program Files\VideoLAN\VLC\vlc.exe" %1" ["the VideoLAN Team"]
VLCPlayDVDMovieOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.DVDMovie"
"InvokeVerb" = "Open"
HKLM\SOFTWARE\Classes\VLC.DVDMovie\shell\Open\command\(Default) = ""C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file dvd://%1" ["the VideoLAN Team"]
VLCPlayMusicFilesOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.OPENFolder"
"InvokeVerb" = "Open"
HKLM\SOFTWARE\Classes\VLC.OPENFolder\shell\Open\command\(Default) = ""C:\Program Files\VideoLAN\VLC\vlc.exe" %1" ["the VideoLAN Team"]
VLCPlaySVCDMovieOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.SVCDMovie"
"InvokeVerb" = "Open"
HKLM\SOFTWARE\Classes\VLC.SVCDMovie\shell\Open\command\(Default) = ""C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file vcd://%1" ["the VideoLAN Team"]
VLCPlayVCDMovieOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.VCDMovie"
"InvokeVerb" = "Open"
HKLM\SOFTWARE\Classes\VLC.VCDMovie\shell\Open\command\(Default) = ""C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file vcd://%1" ["the VideoLAN Team"]
VLCPlayVideoFilesOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.OPENFolder"
"InvokeVerb" = "Open"
HKLM\SOFTWARE\Classes\VLC.OPENFolder\shell\Open\command\(Default) = ""C:\Program Files\VideoLAN\VLC\vlc.exe" %1" ["the VideoLAN Team"]
WIA_{240305C3-650B-4890-B6DB-D793280B607B}\
"Provider" = "Microsoft Word"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = "/WiaCmd;C:\Program Files\Microsoft Office\Office14\WINWORD.EXE /IMG_WIA;"
-> {HKLM…CLSID} = "WPDShextAutoplay"
\LocalServer32\(Default) = "C:\Windows\system32\WPDShextAutoplay.exe" [MS]
WIA_{2E2B1F10-DEB5-46A1-8F92-45E3F1A86158}\
"Provider" = "Microsoft Office OneNote"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = "/WiaCmd;C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE /IMG_WIA;"
-> {HKLM…CLSID} = "WPDShextAutoplay"
\LocalServer32\(Default) = "C:\Windows\system32\WPDShextAutoplay.exe" [MS]
WIA_{764F0264-903E-4F56-8D70-1729B01A3689}\
"Provider" = "Microsoft Office Word"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = "/WiaCmd;C:\Program Files\Microsoft Office\Office12\WINWORD.EXE /IMG_WIA;"
-> {HKLM…CLSID} = "WPDShextAutoplay"
\LocalServer32\(Default) = "C:\Windows\system32\WPDShextAutoplay.exe" [MS]
WIA_{BDE0F132-D47D-4BA1-86C2-F2BEAA2BDF6B}\
"Provider" = "Microsoft OneNote"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = "/WiaCmd;C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE /IMG_WIA;"
-> {HKLM…CLSID} = "WPDShextAutoplay"
\LocalServer32\(Default) = "C:\Windows\system32\WPDShextAutoplay.exe" [MS]
WIA_{D4C017B9-854E-4BC3-A931-71F01C388187}\
"Provider" = "Photoshop"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = "/WiaCmd;C:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe /StiDevice:%1 /StiEvent:%2;"
-> {HKLM…CLSID} = "WPDShextAutoplay"
\LocalServer32\(Default) = "C:\Windows\system32\WPDShextAutoplay.exe" [MS]
Startup items in "Buddy" & "All Users" startup folders:
——————————————————-
C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
"OneNote 2010 Screen Clipper and Launcher" -> shortcut to: "C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE /tsr" [MS]
"V CAST Media Monitor" -> shortcut to: "C:\Program Files\V CAST Media Manager\MEMonitor.exe -m" ["Smith Micro, Inc."]
Windows Sidebar Gadgets:
————————
C:\Users\Buddy\AppData\Local\Microsoft\Windows Sidebar\Settings.ini
%PROGRAMFILES%\windows sidebar\gadgets\SlideShow.Gadget
"C:%5CProgram%20Files%5CWindows%20Sidebar%5CGadgets%5CCPU.Gadget"
"C:%5CProgram%20Files%5CWindows%20Sidebar%5CGadgets%5CWeather.Gadget"
"C:%5CProgram%20Files%5CWindows%20Sidebar%5CGadgets%5CStocks.Gadget"
"C:%5CProgram%20Files%5CWindows%20Sidebar%5CGadgets%5CRSSFeeds.Gadget"
"C:%5CUsers%5CBuddy%5CAppData%5CLocal%5CMicrosoft%5CWindows%20Sidebar%5CGadgets%5Cclockr.gadget"
"C:%5CUsers%5CBuddy%5CAppData%5CLocal%5CMicrosoft%5CWindows%20Sidebar%5CGadgets%5Cred.gadget"
"C:%5CUsers%5CBuddy%5CAppData%5CLocal%5CMicrosoft%5CWindows%20Sidebar%5CGadgets%5Ccalendar.gadget"
Non-disabled Scheduled Tasks:
—————————–
C:\Windows\System32\Tasks
"GoogleUpdateTaskMachineCore" -> launches: "C:\Program Files\Google\Update\GoogleUpdate.exe /c" ["Google Inc."]
"GoogleUpdateTaskMachineUA" -> launches: "C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler" ["Google Inc."]
"Orb Index when idle" -> launches: ""C:\Program Files\Orb Networks\Orb\bin\Orblauncher.exe" –indexing" ["Orb Networks"]
"Orb Startup" -> launches: "C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" [file not found]
"RunAsStdUser Task for VeohWebPlayer" -> launches: "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe /VistaRunAsStdUser" [file not found]
"User_Feed_Synchronization-{E2DCF500-2AE9-4C71-A2E6-0B1861D91A9F}" -> (HIDDEN!) launches: "C:\Windows\system32\msfeedssync.exe sync" [MS]
"{01B3561F-4010-405C-9912-8507D411B2AC}" -> launches: "C:\Windows\system32\pcalua.exe -a C:\Users\Buddy\Downloads\install.exe -d C:\Users\Buddy\Downloads" [MS]
"{0750C419-FCB0-4A8F-AF2F-9A11C103705B}" -> launches: "C:\Windows\system32\pcalua.exe -a "C:\Users\Buddy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\397ZIWAY\Orb20SetupUs[1].exe" -d C:\Windows\system32" [MS]
"{4E676937-7E50-49AE-BDDF-6C4EAF0BBE46}" -> launches: "C:\Windows\system32\pcalua.exe -a L:\setup.exe -d L:\" [MS]
"{DC20B544-684B-49B5-8DF7-544653BE7CA2}" -> launches: "C:\Windows\system32\pcalua.exe -a "C:\Program Files\Rapidown\rapidown.exe" -c rapcmd.uninstall" [MS]
"{E66C8D7E-4B1C-44A2-96E2-4DB9957CF29A}" -> launches: "C:\Windows\system32\pcalua.exe -a "C:\Users\Buddy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NGFU1XM6\GetFile[1].exe" -d C:\Users\Buddy\Desktop" [MS]
"{E6EAEF96-E1EB-484C-8A16-AF04C2832794}" -> launches: "C:\Windows\system32\pcalua.exe -a M:\start.exe -d M:\" [MS]
"{F5AC8376-20AB-40C6-A918-52AFC59BFC97}" -> launches: "C:\Windows\system32\pcalua.exe -a G:\setup.exe -d G:\" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client
"AD RMS Rights Policy Template Management (Manual)" -> launches: "{BF5CB148-7C77-4d8a-A53E-D81C70CF743C}"
-> {HKLM…CLSID} = "AD RMS Rights Policy Template Management (Manual) Task Handler"
\InProcServer32\(Default) = "C:\Windows\system32\msdrm.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Bluetooth
"UninstallDeviceTask" -> launches: "BthUdTask.exe $(Arg0)" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\CertificateServicesClient
"SystemTask" -> launches: "{58fb76b9-ac85-4e55-ac04-427593b1d060}"
-> {HKLM…CLSID} = "Certificate Services Client Task Handler"
\InProcServer32\(Default) = "C:\Windows\system32\dimsjob.dll" [MS]
"UserTask" -> launches: "{58fb76b9-ac85-4e55-ac04-427593b1d060}"
-> {HKLM…CLSID} = "Certificate Services Client Task Handler"
\InProcServer32\(Default) = "C:\Windows\system32\dimsjob.dll" [MS]
"UserTask-Roam" -> launches: "{58fb76b9-ac85-4e55-ac04-427593b1d060}"
-> {HKLM…CLSID} = "Certificate Services Client Task Handler"
\InProcServer32\(Default) = "C:\Windows\system32\dimsjob.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program
"Consolidator" -> launches: "%SystemRoot%\System32\wsqmcons.exe" [MS]
"OptinNotification" -> launches: "%SystemRoot%\System32\wsqmcons.exe -n 0x1C577FA2B69CAD0" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Defrag
"ManualDefrag" -> launches: "%windir%\system32\defrag.exe -c" [MS]
"ScheduledDefrag" -> launches: "%windir%\system32\defrag.exe -c -i" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center
"ehDRMInit" -> launches: "%SystemRoot%\ehome\ehPrivJob.exe /DRMInit" [MS]
"mcupdate" -> launches: "%SystemRoot%\ehome\mcupdate $(Arg0) -gc" [MS]
"OCURActivate" -> launches: "%SystemRoot%\ehome\ehPrivJob.exe /OCURActivate" [MS]
"OCURDiscovery" -> launches: "%SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery" [MS]
"UpdateRecordPath" -> launches: "%SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\MobilePC
"HotStart" -> launches: "{06DA0625-9701-43da-BFD7-FBEEA2180A1E}"
-> {HKLM…CLSID} = "HotStart User Agent"
\InProcServer32\(Default) = "C:\Windows\System32\HotStartUserAgent.dll" [MS]
"TMM" -> launches: "{35EF4182-F900-4632-B072-8639E4478A61}"
-> {HKLM…CLSID} = "Transient Multi-Monitor Manager"
\InProcServer32\(Default) = "C:\Windows\System32\TMM.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\MUI
"LPRemove" -> launches: "%windir%\system32\lpremove.exe" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia
"SystemSoundsService" -> launches: "{2DEA658F-54C1-4227-AF9B-260AB5FC3543}"
-> {HKLM…CLSID} = "Microsoft PlaySoundService Class"
\InProcServer32\(Default) = "C:\Windows\System32\PlaySndSrv.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\NetworkAccessProtection
"NAPStatus UI" -> launches: "{f09878a1-4652-4292-aa63-8c7d4fd7648f}"
-> {HKLM…CLSID} = "Nap ITask Handler Implementation"
\InProcServer32\(Default) = "C:\Windows\System32\QAgent.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\RAC
"RACAgent" -> (HIDDEN!) launches: "%windir%\system32\RacAgent.exe" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\RemoteAssistance
"RemoteAssistanceTask" -> (HIDDEN!) launches: "%windir%\system32\RAServer.exe /offerraupdate" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Shell
"CrawlStartPages" -> launches: "{51653423-e62d-4ff7-894a-dabb2b8e21e2}"
-> {HKLM…CLSID} = "CrawlStartPages Task Handler"
\InProcServer32\(Default) = "C:\Windows\System32\srchadmin.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\SideShow
"GadgetManager" -> launches: "{FF87090D-4A9A-4f47-879B-29A80C355D61}"
-> {HKLM…CLSID} = "GadgetsManager Class"
\InProcServer32\(Default) = "C:\Windows\System32\AuxiliaryDisplayServices.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\SystemRestore
"SR" -> launches: "%windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Tcpip
"IpAddressConflict1" -> launches: "rundll32 ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem" [MS]
"IpAddressConflict2" -> launches: "rundll32 ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\TextServicesFramework
"MsCtfMonitor" -> (HIDDEN!) launches: "{01575cfe-9a55-4003-a5e1-f38d1ebdcbe1}"
-> {HKLM…CLSID} = "MsCtfMonitor task handler"
\InProcServer32\(Default) = "C:\Windows\system32\MsCtfMonitor.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\UPnP
"UPnPHostConfig" -> launches: "sc.exe config upnphost start= auto" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\WDI
"ResolutionHost" -> (HIDDEN!) launches: "{900be39d-6be8-461a-bc4d-b0fa71f5ecb1}"
-> {HKLM…CLSID} = "DiagnosticInfrastructureCustomHandler"
\InProcServer32\(Default) = "C:\Windows\System32\wdi.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Error Reporting
"QueueReporting" -> launches: "%windir%\system32\wermgr.exe -queuereporting" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Wired
"GatherWiredInfo" -> launches: "%windir%\system32\gatherWiredInfo.vbs" [null data]
C:\Windows\System32\Tasks\Microsoft\Windows\Wireless
"GatherWirelessInfo" -> launches: "%windir%\system32\gatherWirelessInfo.vbs" [null data]
C:\Windows\System32\Tasks\Microsoft\Windows Defender
"MP Scheduled Scan" -> (HIDDEN!) launches: "c:\program files\windows defender\MpCmdRun.exe Scan -RestrictPrivileges" [MS]
"MP Scheduled Signature Update" -> (HIDDEN!) launches: "c:\program files\windows defender\MpCmdRun.exe SignatureUpdate" [MS]
Winsock2 Service Provider DLLs:
——————————-
Namespace Service Providers
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\system32\NLAapi.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\system32\napinsp.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
000000000004\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
000000000005\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000006\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000007\LibraryPath = "C:\Program Files\Bonjour\mdnsNSP.dll" ["Apple Inc."]
Transport Service Providers
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 10, 13 - 34
C:\Program Files\VMware\VMware Workstation\vsocklib.dll ["VMware, Inc."], 11 - 12
Toolbars, Explorer Bars, Extensions:
————————————
Explorer Bars
HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\
HKLM\SOFTWARE\Classes\CLSID\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}\(Default) = "Groove Folder Synchronization"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL" [MS]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\
{2670000A-7350-4F3C-8081-5663EE0C6C49}\
"ButtonText" = "Send to OneNote"
"MenuText" = "Se&nd to OneNote"
"CLSIDExtension" = "{48E73304-E1D6-4330-914C-F5F514E3486C}"
-> {HKLM…CLSID} = "Send to OneNote from Internet Explorer button"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll" [MS]
{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\
"ButtonText" = "OneNote Lin&ked Notes"
"MenuText" = "OneNote Lin&ked Notes"
"CLSIDExtension" = "{FFFDC614-B694-4AE6-AB38-5D6374584B52}"
-> {HKLM…CLSID} = "Linked Notes button"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll" [MS]
HOSTS file
———-
C:\Windows\System32\drivers\etc\HOSTS
maps: 2 domain names to IP addresses,
2 of the IP addresses are *not* localhost!
Running Services (Display Name, Service Name, Path {Service DLL}):
——————————————————————
Apple Mobile Device, Apple Mobile Device, ""C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"" ["Apple Inc."]
avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"" ["AVAST Software"]
Bonjour Service, Bonjour Service, ""C:\Program Files\Bonjour\mDNSResponder.exe"" ["Apple Inc."]
CNG Key Isolation, KeyIso, "C:\Windows\system32\lsass.exe" [MS]
COM+ System Application, COMSysApp, "C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}" [MS]
Computer Browser, Browser, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\browser.dll" [MS]}
Debug Diagnostic Service, DbgSvc, ""C:\Program Files\DebugDiag\DbgSvc.exe"" [MS]
Diagnostic Service Host, WdiServiceHost, "C:\Windows\System32\svchost.exe -k wdisvc" {"C:\Windows\system32\wdi.dll" [MS]}
Distributed Transaction Coordinator, MSDTC, "C:\Windows\System32\msdtc.exe" [MS]
Extensible Authentication Protocol, EapHost, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\eapsvc.dll" [MS]}
Human Interface Device Access, hidserv, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\system32\hidserv.dll" [MS]}
iPod Service, iPod Service, ""C:\Program Files\iPod\bin\iPodService.exe"" ["Apple Inc."]
Machine Debug Manager, MDM, ""C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"" [MS]
NVIDIA Display Driver Service, nvsvc, "C:\Windows\system32\nvvsvc.exe" ["NVIDIA Corporation"]
Pml Driver HPZ12, Pml Driver HPZ12, "C:\Windows\System32\svchost.exe -k HPZ12" {"C:\Windows\system32\HPZipm12.dll" ["Hewlett-Packard"]}
VMware Authorization Service, VMAuthdService, ""C:\Program Files\VMware\VMware Workstation\vmware-authd.exe"" ["VMware, Inc."]
VMware DHCP Service, VMnetDHCP, "C:\Windows\system32\vmnetdhcp.exe" ["VMware, Inc."]
VMware NAT Service, VMware NAT Service, "C:\Windows\system32\vmnat.exe" ["VMware, Inc."]
VMware USB Arbitration Service, VMUSBArbService, "C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe" ["VMware, Inc."]
VMware Virtual Mount Manager Extended, vmount2, ""C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe"" ["VMware, Inc."]
Windows Driver Foundation - User-mode Driver Framework, wudfsvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\WUDFSvc.dll" [MS]}
Windows Image Acquisition (WIA), stisvc, "C:\Windows\system32\svchost.exe -k imgsvc" {"C:\Windows\System32\wiaservc.dll" [MS]}
Windows Media Center Receiver Service, ehRecvr, "C:\Windows\ehome\ehRecvr.exe" [MS]
WLAN AutoConfig, Wlansvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\wlansvc.dll" [MS]}
XAudioService, XAudioService, "C:\Windows\system32\DRIVERS\xaudio.exe" ["Conexant Systems, Inc."]
Safe Mode Drivers & Services (subkey name, subkey default value):
—————————————————————–
HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\
<> PEVSystemStart, "Service"
<> procexp90.Sys, "Driver"
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\
<> hitmanpro35, (null value)
<> hitmanpro35.sys, (null value)
<> HitmanPro35Crusader, (null value)
<> PEVSystemStart, "Service"
<> procexp90.Sys, "Driver"
Accessibility Tools:
——————–
HKCU\Software\Microsoft\Windows NT\CurrentVersion\AccessibilityTemp\
"narrator" = dword:0x00000000
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\ATs\Narrator\
"Description" = "Screen Reader"
"StartExe" = "C:\Windows\System32\Narrator.exe" [MS]
Keyboard Driver Filters:
————————
HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\
<> "UpperFilters" = "kbdclass" [MS],<> "vmkbd" ["VMware, Inc."]
Print Monitors:
—————
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\
CutePDF Writer Monitor\Driver = "cpwmon2k.dll" [null data]
PCL hpz3l4v2\Driver = "hpz3l4v2.dll" ["Hewlett-Packard Company"]
———- (launch time: 2011-02-16 14:57:11)
<>: Suspicious data at a malware launch point.
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 618 seconds.
———- (total run time: 701 seconds)
Ok, here's what I did. I selected each of the tabs in rootrepeal and hit scanned, saved report. It is pasted. I then hit the files tab then scan, one again it hangs on scanning the manifests folder and eats up all my RAM but I PrtScn the window to show you what it did find files wise.
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2011/02/16 15:40
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP1
==================================================
Drivers
——————-
Name: dump_iaStorV.sys
Image Path: C:\Windows\System32\Drivers\dump_iaStorV.sys
Address: 0x8F721000 Size: 659456 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x9FE29000 Size: 49152 File Visible: No Signed: -
Status: -
Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1360 Status: Locked to the Windows API!
SSDT
——————-
#: 000 Function Name: NtAcceptConnectPort
Status: Not hooked
#: 001 Function Name: NtAccessCheck
Status: Not hooked
#: 002 Function Name: NtAccessCheckAndAuditAlarm
Status: Not hooked
#: 003 Function Name: NtAccessCheckByType
Status: Not hooked
#: 004 Function Name: NtAccessCheckByTypeAndAuditAlarm
Status: Not hooked
#: 005 Function Name: NtAccessCheckByTypeResultList
Status: Not hooked
#: 006 Function Name: NtAccessCheckByTypeResultListAndAuditAlarm
Status: Not hooked
#: 007 Function Name: NtAccessCheckByTypeResultListAndAuditAlarmByHandle
Status: Not hooked
#: 008 Function Name: NtAddAtom
Status: Not hooked
#: 009 Function Name: NtAddBootEntry
Status: Not hooked
#: 010 Function Name: NtAddDriverEntry
Status: Not hooked
#: 011 Function Name: NtAdjustGroupsToken
Status: Not hooked
#: 012 Function Name: NtAdjustPrivilegesToken
Status: Not hooked
#: 013 Function Name: NtAlertResumeThread
Status: Not hooked
#: 014 Function Name: NtAlertThread
Status: Not hooked
#: 015 Function Name: NtAllocateLocallyUniqueId
Status: Not hooked
#: 016 Function Name: NtAllocateUserPhysicalPages
Status: Not hooked
#: 017 Function Name: NtAllocateUuids
Status: Not hooked
#: 018 Function Name: NtAllocateVirtualMemory
Status: Not hooked
#: 019 Function Name: NtAlpcAcceptConnectPort
Status: Not hooked
#: 020 Function Name: NtAlpcCancelMessage
Status: Not hooked
#: 021 Function Name: NtAlpcConnectPort
Status: Not hooked
#: 022 Function Name: NtAlpcCreatePort
Status: Not hooked
#: 023 Function Name: NtAlpcCreatePortSection
Status: Not hooked
#: 024 Function Name: NtAlpcCreateResourceReserve
Status: Not hooked
#: 025 Function Name: NtAlpcCreateSectionView
Status: Not hooked
#: 026 Function Name: NtAlpcCreateSecurityContext
Status: Not hooked
#: 027 Function Name: NtAlpcDeletePortSection
Status: Not hooked
#: 028 Function Name: NtAlpcDeleteResourceReserve
Status: Not hooked
#: 029 Function Name: NtAlpcDeleteSectionView
Status: Not hooked
#: 030 Function Name: NtAlpcDeleteSecurityContext
Status: Not hooked
#: 031 Function Name: NtAlpcDisconnectPort
Status: Not hooked
#: 032 Function Name: NtAlpcImpersonateClientOfPort
Status: Not hooked
#: 033 Function Name: NtAlpcOpenSenderProcess
Status: Not hooked
#: 034 Function Name: NtAlpcOpenSenderThread
Status: Not hooked
#: 035 Function Name: NtAlpcQueryInformation
Status: Not hooked
#: 036 Function Name: NtAlpcQueryInformationMessage
Status: Not hooked
#: 037 Function Name: NtAlpcRevokeSecurityContext
Status: Not hooked
#: 038 Function Name: NtAlpcSendWaitReceivePort
Status: Not hooked
#: 039 Function Name: NtAlpcSetInformation
Status: Not hooked
#: 040 Function Name: NtApphelpCacheControl
Status: Not hooked
#: 041 Function Name: NtAreMappedFilesTheSame
Status: Not hooked
#: 042 Function Name: NtAssignProcessToJobObject
Status: Not hooked
#: 043 Function Name: NtCallbackReturn
Status: Not hooked
#: 044 Function Name: NtRequestDeviceWakeup
Status: Not hooked
#: 045 Function Name: NtCancelIoFile
Status: Not hooked
#: 046 Function Name: NtCancelTimer
Status: Not hooked
#: 047 Function Name: NtClearEvent
Status: Not hooked
#: 048 Function Name: NtClose
Status: Not hooked
#: 049 Function Name: NtCloseObjectAuditAlarm
Status: Not hooked
#: 050 Function Name: NtCompactKeys
Status: Not hooked
#: 051 Function Name: NtCompareTokens
Status: Not hooked
#: 052 Function Name: NtCompleteConnectPort
Status: Not hooked
#: 053 Function Name: NtCompressKey
Status: Not hooked
#: 054 Function Name: NtConnectPort
Status: Not hooked
#: 055 Function Name: NtContinue
Status: Not hooked
#: 056 Function Name: NtCreateDebugObject
Status: Not hooked
#: 057 Function Name: NtCreateDirectoryObject
Status: Not hooked
#: 058 Function Name: NtCreateEvent
Status: Not hooked
#: 059 Function Name: NtCreateEventPair
Status: Not hooked
#: 060 Function Name: NtCreateFile
Status: Not hooked
#: 061 Function Name: NtCreateIoCompletion
Status: Not hooked
#: 062 Function Name: NtCreateJobObject
Status: Not hooked
#: 063 Function Name: NtCreateJobSet
Status: Not hooked
#: 064 Function Name: NtCreateKey
Status: Not hooked
#: 065 Function Name: NtCreateKeyTransacted
Status: Not hooked
#: 066 Function Name: NtCreateMailslotFile
Status: Not hooked
#: 067 Function Name: NtCreateMutant
Status: Not hooked
#: 068 Function Name: NtCreateNamedPipeFile
Status: Not hooked
#: 069 Function Name: NtCreatePrivateNamespace
Status: Not hooked
#: 070 Function Name: NtCreatePagingFile
Status: Not hooked
#: 071 Function Name: NtCreatePort
Status: Not hooked
#: 072 Function Name: NtCreateProcess
Status: Not hooked
#: 073 Function Name: NtCreateProcessEx
Status: Not hooked
#: 074 Function Name: NtCreateProfile
Status: Not hooked
#: 075 Function Name: NtCreateSection
Status: Not hooked
#: 076 Function Name: NtCreateSemaphore
Status: Not hooked
#: 077 Function Name: NtCreateSymbolicLinkObject
Status: Not hooked
#: 078 Function Name: NtCreateThread
Status: Not hooked
#: 079 Function Name: NtCreateTimer
Status: Not hooked
#: 080 Function Name: NtCreateToken
Status: Not hooked
#: 081 Function Name: NtCreateTransaction
Status: Not hooked
#: 082 Function Name: NtOpenTransaction
Status: Not hooked
#: 083 Function Name: NtQueryInformationTransaction
Status: Not hooked
#: 084 Function Name: NtQueryInformationTransactionManager
Status: Not hooked
#: 085 Function Name: NtPrePrepareEnlistment
Status: Not hooked
#: 086 Function Name: NtPrepareEnlistment
Status: Not hooked
#: 087 Function Name: NtCommitEnlistment
Status: Not hooked
#: 088 Function Name: NtReadOnlyEnlistment
Status: Not hooked
#: 089 Function Name: NtRollbackComplete
Status: Not hooked
#: 090 Function Name: NtRollbackEnlistment
Status: Not hooked
#: 091 Function Name: NtCommitTransaction
Status: Not hooked
#: 092 Function Name: NtRollbackTransaction
Status: Not hooked
#: 093 Function Name: NtPrePrepareComplete
Status: Not hooked
#: 094 Function Name: NtPrepareComplete
Status: Not hooked
#: 095 Function Name: NtCommitComplete
Status: Not hooked
#: 096 Function Name: NtSinglePhaseReject
Status: Not hooked
#: 097 Function Name: NtSetInformationTransaction
Status: Not hooked
#: 098 Function Name: NtSetInformationTransactionManager
Status: Not hooked
#: 099 Function Name: NtSetInformationResourceManager
Status: Not hooked
#: 100 Function Name: NtCreateTransactionManager
Status: Not hooked
#: 101 Function Name: NtOpenTransactionManager
Status: Not hooked
#: 102 Function Name: NtRenameTransactionManager
Status: Not hooked
#: 103 Function Name: NtRollforwardTransactionManager
Status: Not hooked
#: 104 Function Name: NtRecoverEnlistment
Status: Not hooked
#: 105 Function Name: NtRecoverResourceManager
Status: Not hooked
#: 106 Function Name: NtRecoverTransactionManager
Status: Not hooked
#: 107 Function Name: NtCreateResourceManager
Status: Not hooked
#: 108 Function Name: NtOpenResourceManager
Status: Not hooked
#: 109 Function Name: NtGetNotificationResourceManager
Status: Not hooked
#: 110 Function Name: NtQueryInformationResourceManager
Status: Not hooked
#: 111 Function Name: NtCreateEnlistment
Status: Not hooked
#: 112 Function Name: NtOpenEnlistment
Status: Not hooked
#: 113 Function Name: NtSetInformationEnlistment
Status: Not hooked
#: 114 Function Name: NtQueryInformationEnlistment
Status: Not hooked
#: 115 Function Name: NtCreateWaitablePort
Status: Not hooked
#: 116 Function Name: NtDebugActiveProcess
Status: Not hooked
#: 117 Function Name: NtDebugContinue
Status: Not hooked
#: 118 Function Name: NtDelayExecution
Status: Not hooked
#: 119 Function Name: NtDeleteAtom
Status: Not hooked
#: 120 Function Name: NtDeleteBootEntry
Status: Not hooked
#: 121 Function Name: NtDeleteDriverEntry
Status: Not hooked
#: 122 Function Name: NtDeleteFile
Status: Not hooked
#: 123 Function Name: NtDeleteKey
Status: Not hooked
#: 124 Function Name: NtDeletePrivateNamespace
Status: Not hooked
#: 125 Function Name: NtDeleteObjectAuditAlarm
Status: Not hooked
#: 126 Function Name: NtDeleteValueKey
Status: Not hooked
#: 127 Function Name: NtDeviceIoControlFile
Status: Not hooked
#: 128 Function Name: NtDisplayString
Status: Not hooked
#: 129 Function Name: NtDuplicateObject
Status: Not hooked
#: 130 Function Name: NtDuplicateToken
Status: Not hooked
#: 131 Function Name: NtEnumerateBootEntries
Status: Not hooked
#: 132 Function Name: NtEnumerateDriverEntries
Status: Not hooked
#: 133 Function Name: NtEnumerateKey
Status: Not hooked
#: 134 Function Name: NtEnumerateSystemEnvironmentValuesEx
Status: Not hooked
#: 135 Function Name: NtEnumerateTransactionObject
Status: Not hooked
#: 136 Function Name: NtEnumerateValueKey
Status: Not hooked
#: 137 Function Name: NtExtendSection
Status: Not hooked
#: 138 Function Name: NtFilterToken
Status: Not hooked
#: 139 Function Name: NtFindAtom
Status: Not hooked
#: 140 Function Name: NtFlushBuffersFile
Status: Not hooked
#: 141 Function Name: NtFlushInstructionCache
Status: Not hooked
#: 142 Function Name: NtFlushKey
Status: Not hooked
#: 143 Function Name: NtFlushProcessWriteBuffers
Status: Not hooked
#: 144 Function Name: NtFlushVirtualMemory
Status: Not hooked
#: 145 Function Name: NtFlushWriteBuffer
Status: Not hooked
#: 146 Function Name: NtFreeUserPhysicalPages
Status: Not hooked
#: 147 Function Name: NtFreeVirtualMemory
Status: Not hooked
#: 148 Function Name: NtFreezeRegistry
Status: Not hooked
#: 149 Function Name: NtFreezeTransactions
Status: Not hooked
#: 150 Function Name: NtFsControlFile
Status: Not hooked
#: 151 Function Name: NtGetContextThread
Status: Not hooked
#: 152 Function Name: NtGetDevicePowerState
Status: Not hooked
#: 153 Function Name: NtGetNlsSectionPtr
Status: Not hooked
#: 154 Function Name: NtGetPlugPlayEvent
Status: Not hooked
#: 155 Function Name: NtGetWriteWatch
Status: Not hooked
#: 156 Function Name: NtImpersonateAnonymousToken
Status: Not hooked
#: 157 Function Name: NtImpersonateClientOfPort
Status: Not hooked
#: 158 Function Name: NtImpersonateThread
Status: Not hooked
#: 159 Function Name: NtInitializeNlsFiles
Status: Not hooked
#: 160 Function Name: NtInitializeRegistry
Status: Not hooked
#: 161 Function Name: NtInitiatePowerAction
Status: Not hooked
#: 162 Function Name: NtIsProcessInJob
Status: Not hooked
#: 163 Function Name: NtIsSystemResumeAutomatic
Status: Not hooked
#: 164 Function Name: NtListenPort
Status: Not hooked
#: 165 Function Name: NtLoadDriver
Status: Not hooked
#: 166 Function Name: NtLoadKey
Status: Not hooked
#: 167 Function Name: NtLoadKey2
Status: Not hooked
#: 168 Function Name: NtLoadKeyEx
Status: Not hooked
#: 169 Function Name: NtLockFile
Status: Not hooked
#: 170 Function Name: NtLockProductActivationKeys
Status: Not hooked
#: 171 Function Name: NtLockRegistryKey
Status: Not hooked
#: 172 Function Name: NtLockVirtualMemory
Status: Not hooked
#: 173 Function Name: NtMakePermanentObject
Status: Not hooked
#: 174 Function Name: NtMakeTemporaryObject
Status: Not hooked
#: 175 Function Name: NtMapUserPhysicalPages
Status: Not hooked
#: 176 Function Name: NtMapUserPhysicalPagesScatter
Status: Not hooked
#: 177 Function Name: NtMapViewOfSection
Status: Not hooked
#: 178 Function Name: NtModifyBootEntry
Status: Not hooked
#: 179 Function Name: NtModifyDriverEntry
Status: Not hooked
#: 180 Function Name: NtNotifyChangeDirectoryFile
Status: Not hooked
#: 181 Function Name: NtNotifyChangeKey
Status: Not hooked
#: 182 Function Name: NtNotifyChangeMultipleKeys
Status: Not hooked
#: 183 Function Name: NtOpenDirectoryObject
Status: Not hooked
#: 184 Function Name: NtOpenEvent
Status: Not hooked
#: 185 Function Name: NtOpenEventPair
Status: Not hooked
#: 186 Function Name: NtOpenFile
Status: Not hooked
#: 187 Function Name: NtOpenIoCompletion
Status: Not hooked
#: 188 Function Name: NtOpenJobObject
Status: Not hooked
#: 189 Function Name: NtOpenKey
Status: Not hooked
#: 190 Function Name: NtOpenKeyTransacted
Status: Not hooked
#: 191 Function Name: NtOpenMutant
Status: Not hooked
#: 192 Function Name: NtOpenPrivateNamespace
Status: Not hooked
#: 193 Function Name: NtOpenObjectAuditAlarm
Status: Not hooked
#: 194 Function Name: NtOpenProcess
Status: Not hooked
#: 195 Function Name: NtOpenProcessToken
Status: Not hooked
#: 196 Function Name: NtOpenProcessTokenEx
Status: Not hooked
#: 197 Function Name: NtOpenSection
Status: Not hooked
#: 198 Function Name: NtOpenSemaphore
Status: Not hooked
#: 199 Function Name: NtOpenSession
Status: Not hooked
#: 200 Function Name: NtOpenSymbolicLinkObject
Status: Not hooked
#: 201 Function Name: NtOpenThread
Status: Not hooked
#: 202 Function Name: NtOpenThreadToken
Status: Not hooked
#: 203 Function Name: NtOpenThreadTokenEx
Status: Not hooked
#: 204 Function Name: NtOpenTimer
Status: Not hooked
#: 205 Function Name: NtPlugPlayControl
Status: Not hooked
#: 206 Function Name: NtPowerInformation
Status: Not hooked
#: 207 Function Name: NtPrivilegeCheck
Status: Not hooked
#: 208 Function Name: NtPrivilegeObjectAuditAlarm
Status: Not hooked
#: 209 Function Name: NtPrivilegedServiceAuditAlarm
Status: Not hooked
#: 210 Function Name: NtProtectVirtualMemory
Status: Not hooked
#: 211 Function Name: NtPulseEvent
Status: Not hooked
#: 212 Function Name: NtQueryAttributesFile
Status: Not hooked
#: 213 Function Name: NtQueryBootEntryOrder
Status: Not hooked
#: 214 Function Name: NtQueryBootOptions
Status: Not hooked
#: 215 Function Name: NtQueryDebugFilterState
Status: Not hooked
#: 216 Function Name: NtQueryDefaultLocale
Status: Not hooked
#: 217 Function Name: NtQueryDefaultUILanguage
Status: Not hooked
#: 218 Function Name: NtQueryDirectoryFile
Status: Not hooked
#: 219 Function Name: NtQueryDirectoryObject
Status: Not hooked
#: 220 Function Name: NtQueryDriverEntryOrder
Status: Not hooked
#: 221 Function Name: NtQueryEaFile
Status: Not hooked
#: 222 Function Name: NtQueryEvent
Status: Not hooked
#: 223 Function Name: NtQueryFullAttributesFile
Status: Not hooked
#: 224 Function Name: NtQueryInformationAtom
Status: Not hooked
#: 225 Function Name: NtQueryInformationFile
Status: Not hooked
#: 226 Function Name: NtQueryInformationJobObject
Status: Not hooked
#: 227 Function Name: NtQueryInformationPort
Status: Not hooked
#: 228 Function Name: NtQueryInformationProcess
Status: Not hooked
#: 229 Function Name: NtQueryInformationThread
Status: Not hooked
#: 230 Function Name: NtQueryInformationToken
Status: Not hooked
#: 231 Function Name: NtQueryInstallUILanguage
Status: Not hooked
#: 232 Function Name: NtQueryIntervalProfile
Status: Not hooked
#: 233 Function Name: NtQueryIoCompletion
Status: Not hooked
#: 234 Function Name: NtQueryKey
Status: Not hooked
#: 235 Function Name: NtQueryMultipleValueKey
Status: Not hooked
#: 236 Function Name: NtQueryMutant
Status: Not hooked
#: 237 Function Name: NtQueryObject
Status: Not hooked
#: 238 Function Name: NtQueryOpenSubKeys
Status: Not hooked
#: 239 Function Name: NtQueryOpenSubKeysEx
Status: Not hooked
#: 240 Function Name: NtQueryPerformanceCounter
Status: Not hooked
#: 241 Function Name: NtQueryQuotaInformationFile
Status: Not hooked
#: 242 Function Name: NtQuerySection
Status: Not hooked
#: 243 Function Name: NtQuerySecurityObject
Status: Not hooked
#: 244 Function Name: NtQuerySemaphore
Status: Not hooked
#: 245 Function Name: NtQuerySymbolicLinkObject
Status: Not hooked
#: 246 Function Name: NtQuerySystemEnvironmentValue
Status: Not hooked
#: 247 Function Name: NtQuerySystemEnvironmentValueEx
Status: Not hooked
#: 248 Function Name: NtQuerySystemInformation
Status: Not hooked
#: 249 Function Name: NtQuerySystemTime
Status: Not hooked
#: 250 Function Name: NtQueryTimer
Status: Not hooked
#: 251 Function Name: NtQueryTimerResolution
Status: Not hooked
#: 252 Function Name: NtQueryValueKey
Status: Not hooked
#: 253 Function Name: NtQueryVirtualMemory
Status: Not hooked
#: 254 Function Name: NtQueryVolumeInformationFile
Status: Not hooked
#: 255 Function Name: NtQueueApcThread
Status: Not hooked
#: 256 Function Name: NtRaiseException
Status: Not hooked
#: 257 Function Name: NtRaiseHardError
Status: Not hooked
#: 258 Function Name: NtReadFile
Status: Not hooked
#: 259 Function Name: NtReadFileScatter
Status: Not hooked
#: 260 Function Name: NtReadRequestData
Status: Not hooked
#: 261 Function Name: NtReadVirtualMemory
Status: Not hooked
#: 262 Function Name: NtRegisterThreadTerminatePort
Status: Not hooked
#: 263 Function Name: NtReleaseMutant
Status: Not hooked
#: 264 Function Name: NtReleaseSemaphore
Status: Not hooked
#: 265 Function Name: NtRemoveIoCompletion
Status: Not hooked
#: 266 Function Name: NtRemoveProcessDebug
Status: Not hooked
#: 267 Function Name: NtRenameKey
Status: Not hooked
#: 268 Function Name: NtReplaceKey
Status: Not hooked
#: 269 Function Name: NtReplacePartitionUnit
Status: Not hooked
#: 270 Function Name: NtReplyPort
Status: Not hooked
#: 271 Function Name: NtReplyWaitReceivePort
Status: Not hooked
#: 272 Function Name: NtReplyWaitReceivePortEx
Status: Not hooked
#: 273 Function Name: NtReplyWaitReplyPort
Status: Not hooked
#: 274 Function Name: NtRequestDeviceWakeup
Status: Not hooked
#: 275 Function Name: NtRequestPort
Status: Not hooked
#: 276 Function Name: NtRequestWaitReplyPort
Status: Not hooked
#: 277 Function Name: NtRequestWakeupLatency
Status: Not hooked
#: 278 Function Name: NtResetEvent
Status: Not hooked
#: 279 Function Name: NtResetWriteWatch
Status: Not hooked
#: 280 Function Name: NtRestoreKey
Status: Not hooked
#: 281 Function Name: NtResumeProcess
Status: Not hooked
#: 282 Function Name: NtResumeThread
Status: Not hooked
#: 283 Function Name: NtSaveKey
Status: Not hooked
#: 284 Function Name: NtSaveKeyEx
Status: Not hooked
#: 285 Function Name: NtSaveMergedKeys
Status: Not hooked
#: 286 Function Name: NtSecureConnectPort
Status: Not hooked
#: 287 Function Name: NtSetBootEntryOrder
Status: Not hooked
#: 288 Function Name: NtSetBootOptions
Status: Not hooked
#: 289 Function Name: NtSetContextThread
Status: Not hooked
#: 290 Function Name: NtSetDebugFilterState
Status: Not hooked
#: 291 Function Name: NtSetDefaultHardErrorPort
Status: Not hooked
#: 292 Function Name: NtSetDefaultLocale
Status: Not hooked
#: 293 Function Name: NtSetDefaultUILanguage
Status: Not hooked
#: 294 Function Name: NtSetDriverEntryOrder
Status: Not hooked
#: 295 Function Name: NtSetEaFile
Status: Not hooked
#: 296 Function Name: NtSetEvent
Status: Not hooked
#: 297 Function Name: NtSetEventBoostPriority
Status: Not hooked
#: 298 Function Name: NtSetHighEventPair
Status: Not hooked
#: 299 Function Name: NtSetHighWaitLowEventPair
Status: Not hooked
#: 300 Function Name: NtSetInformationDebugObject
Status: Not hooked
#: 301 Function Name: NtSetInformationFile
Status: Not hooked
#: 302 Function Name: NtSetInformationJobObject
Status: Not hooked
#: 303 Function Name: NtSetInformationKey
Status: Not hooked
#: 304 Function Name: NtSetInformationObject
Status: Not hooked
#: 305 Function Name: NtSetInformationProcess
Status: Not hooked
#: 306 Function Name: NtSetInformationThread
Status: Not hooked
#: 307 Function Name: NtSetInformationToken
Status: Not hooked
#: 308 Function Name: NtSetIntervalProfile
Status: Not hooked
#: 309 Function Name: NtSetIoCompletion
Status: Not hooked
#: 310 Function Name: NtSetLdtEntries
Status: Not hooked
#: 311 Function Name: NtSetLowEventPair
Status: Not hooked
#: 312 Function Name: NtSetLowWaitHighEventPair
Status: Not hooked
#: 313 Function Name: NtSetQuotaInformationFile
Status: Not hooked
#: 314 Function Name: NtSetSecurityObject
Status: Not hooked
#: 315 Function Name: NtSetSystemEnvironmentValue
Status: Not hooked
#: 316 Function Name: NtSetSystemEnvironmentValueEx
Status: Not hooked
#: 317 Function Name: NtSetSystemInformation
Status: Not hooked
#: 318 Function Name: NtSetSystemPowerState
Status: Not hooked
#: 319 Function Name: NtSetSystemTime
Status: Not hooked
#: 320 Function Name: NtSetThreadExecutionState
Status: Not hooked
#: 321 Function Name: NtSetTimer
Status: Not hooked
#: 322 Function Name: NtSetTimerResolution
Status: Not hooked
#: 323 Function Name: NtSetUuidSeed
Status: Not hooked
#: 324 Function Name: NtSetValueKey
Status: Not hooked
#: 325 Function Name: NtSetVolumeInformationFile
Status: Not hooked
#: 326 Function Name: NtShutdownSystem
Status: Not hooked
#: 327 Function Name: NtSignalAndWaitForSingleObject
Status: Not hooked
#: 328 Function Name: NtStartProfile
Status: Not hooked
#: 329 Function Name: NtStopProfile
Status: Not hooked
#: 330 Function Name: NtSuspendProcess
Status: Not hooked
#: 331 Function Name: NtSuspendThread
Status: Not hooked
#: 332 Function Name: NtSystemDebugControl
Status: Not hooked
#: 333 Function Name: NtTerminateJobObject
Status: Not hooked
#: 334 Function Name: NtTerminateProcess
Status: Not hooked
#: 335 Function Name: NtTerminateThread
Status: Not hooked
#: 336 Function Name: NtTestAlert
Status: Not hooked
#: 337 Function Name: NtThawRegistry
Status: Not hooked
#: 338 Function Name: NtThawTransactions
Status: Not hooked
#: 339 Function Name: NtTraceEvent
Status: Not hooked
#: 340 Function Name: NtTraceControl
Status: Not hooked
#: 341 Function Name: NtTranslateFilePath
Status: Not hooked
#: 342 Function Name: NtUnloadDriver
Status: Not hooked
#: 343 Function Name: NtUnloadKey
Status: Not hooked
#: 344 Function Name: NtUnloadKey2
Status: Not hooked
#: 345 Function Name: NtUnloadKeyEx
Status: Not hooked
#: 346 Function Name: NtUnlockFile
Status: Not hooked
#: 347 Function Name: NtUnlockVirtualMemory
Status: Not hooked
#: 348 Function Name: NtUnmapViewOfSection
Status: Not hooked
#: 349 Function Name: NtVdmControl
Status: Not hooked
#: 350 Function Name: NtWaitForDebugEvent
Status: Not hooked
#: 351 Function Name: NtWaitForMultipleObjects
Status: Not hooked
#: 352 Function Name: NtWaitForSingleObject
Status: Not hooked
#: 353 Function Name: NtWaitHighEventPair
Status: Not hooked
#: 354 Function Name: NtWaitLowEventPair
Status: Not hooked
#: 355 Function Name: NtWriteFile
Status: Not hooked
#: 356 Function Name: NtWriteFileGather
Status: Not hooked
#: 357 Function Name: NtWriteRequestData
Status: Not hooked
#: 358 Function Name: NtWriteVirtualMemory
Status: Not hooked
#: 359 Function Name: NtYieldExecution
Status: Not hooked
#: 360 Function Name: NtCreateKeyedEvent
Status: Not hooked
#: 361 Function Name: NtOpenKeyedEvent
Status: Not hooked
#: 362 Function Name: NtReleaseKeyedEvent
Status: Not hooked
#: 363 Function Name: NtWaitForKeyedEvent
Status: Not hooked
#: 364 Function Name: NtQueryPortInformationProcess
Status: Not hooked
#: 365 Function Name: NtGetCurrentProcessorNumber
Status: Not hooked
#: 366 Function Name: NtWaitForMultipleObjects32
Status: Not hooked
#: 367 Function Name: NtGetNextProcess
Status: Not hooked
#: 368 Function Name: NtGetNextThread
Status: Not hooked
#: 369 Function Name: NtCancelIoFileEx
Status: Not hooked
#: 370 Function Name: NtCancelSynchronousIoFile
Status: Not hooked
#: 371 Function Name: NtRemoveIoCompletionEx
Status: Not hooked
#: 372 Function Name: NtRegisterProtocolAddressInformation
Status: Not hooked
#: 373 Function Name: NtPropagationComplete
Status: Not hooked
#: 374 Function Name: NtPropagationFailed
Status: Not hooked
#: 375 Function Name: NtCreateWorkerFactory
Status: Not hooked
#: 376 Function Name: NtReleaseWorkerFactoryWorker
Status: Not hooked
#: 377 Function Name: NtWaitForWorkViaWorkerFactory
Status: Not hooked
#: 378 Function Name: NtSetInformationWorkerFactory
Status: Not hooked
#: 379 Function Name: NtQueryInformationWorkerFactory
Status: Not hooked
#: 380 Function Name: NtWorkerFactoryWorkerReady
Status: Not hooked
#: 381 Function Name: NtShutdownWorkerFactory
Status: Not hooked
#: 382 Function Name: NtCreateThreadEx
Status: Not hooked
#: 383 Function Name: NtCreateUserProcess
Status: Not hooked
#: 384 Function Name: NtQueryLicenseValue
Status: Not hooked
#: 385 Function Name: NtMapCMFModule
Status: Not hooked
#: 386 Function Name: NtIsUILanguageComitted
Status: Not hooked
#: 387 Function Name: NtFlushInstallUILanguage
Status: Not hooked
#: 388 Function Name: NtGetMUIRegistryInfo
Status: Not hooked
#: 389 Function Name: NtAcquireCMFViewOwnership
Status: Not hooked
#: 390 Function Name: NtReleaseCMFViewOwnership
Status: Not hooked
Stealth Objects
——————-
Object: Hidden Code [ETHREAD: 0x8686fd78]
Process: System Address: 0x864cba05 Size: 1534
Object: Hidden Code [ETHREAD: 0x8654ed78]
Process: System Address: 0x864cda24 Size: 603
==EOF==
Ta will take me a bit to wade through this
Ok, I can wait. Thanks for your patience with this awful infection.
I can see the injection into explorer but I cannot see where it is coming from. At this stage we have two options, if you are happy to continue I will try some other tools to see if I can narrow it down, but this may take time. If you wish to see a speedy resolution then I would recommend a full reinstall and reformat. The choice is yours..
If you wish to continue we can try a clean boot next and remove all drivers from the equation apart from MS ones
Step 1: Start the System Configuration Utility
1. Click Start, click Run, type msconfig, and then click OK.
2. The System Configuration Utility dialog box is displayed.
Step 2: Configure selective startup options
1. In the System Configuration Utility dialog box, click the General tab, and then click Selective Startup.
2. Click to clear the Process SYSTEM.INI File check box.
3. Click to clear the Process WIN.INI File check box.
4. Click to clear the Load Startup Items check box. Verify that Load System Services and Use Original BOOT.INI are checked.
5. Click the Services tab.
6. Click to select the Hide All Microsoft Services check box.
7. Click Disable All, and then click OK.
When you are prompted, click Restart to restart the computer.
Step 3: Log on to Windows
If you are prompted, log on to Windows.
When you receive the following message, click to select the Don't show this message or launch the System Configuration Utility when Windows start check box, and then click OK.
You have used the System Configuration Utility to make changes to the way Windows starts.
The System Configuration Utility is currently in Diagnostic or Selective Startup mode, causing this message to be displayed and the utility to run every time Windows starts.
Once you are started with just the basics then try both programmes again - But download fresh copies and rename both files before saving (TDSSKiller and Combofix)
Hello again. I followed your steps, and its definitely a microsoft driver or the like that is causing problems, as disabling all of the 3rd party drivers ends up in the same result. But this time Combofix didnt crash to a bluescreen the computer just froze. Unfortunately, reformat and reinstall is not a practical option for me right now as the only external hard drive I have is 160Gb and as you can see my volume is 465gb so I can not feasibly backup all my important data at this time. I am willing to be patient with you in finding out why I can't boot into safe mode because I believe that once I can successfully get into safe mode i can run the good tools like combofix. I know combofix will likely fix or help reduce the problems Ive been having because it killed a similar rootkit in the past. I have confidence in you EssexBoy and it might take longer than we both may have thought but hopefully we can DESTROY this rootkit!!