[Resolved] Virus/Spyware problems, plz help
82 min read
ComboFix 09-02-05.01 - Bret 2009-02-05 15:38:05.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1014.553 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\c++.exe
c:\windows\system32\userinit.exe . . . is infected!!
c:\windows\system32\spoolsv.exe . . . is infected!!
c:\windows\explorer.exe . . . is infected!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_Passthru
((((((((((((((((((((((((( Files Created from 2009-01-05 to 2009-02-05 )))))))))))))))))))))))))))))))
.
2009-02-05 14:01 . 2009-02-05 14:02 d——– c:\windows\ERUNT
2009-02-05 13:56 . 2009-02-05 14:18 d——– C:\SDFix
2009-02-05 13:55 . 2009-02-05 13:55 33,920 –a—— c:\windows\system32\drivers\ojwgrhlr.sys
2009-02-05 13:44 . 2009-02-05 13:44 33,920 –a—— c:\windows\system32\drivers\crxysodg.sys
2009-02-05 13:40 . 2009-02-05 13:40 3,584 –a—— c:\windows\lfzfweiu.exe
2009-02-05 12:14 . 2009-02-05 12:14 33,920 –a—— c:\windows\system32\drivers\miegjyix.sys
2009-02-05 12:06 . 2009-02-05 12:06 64,512 –a—— c:\windows\system32\gcc.exe
2009-02-05 12:06 . 2009-02-05 12:06 3,584 –a—— c:\windows\nttakbit.exe
2009-02-05 08:54 . 2009-02-05 08:54 d——– C:\_OTListIt
2009-02-05 08:52 . 2009-02-05 08:52 38,400 –a—— c:\windows\system32\mlJCRKeE.dll
2009-02-03 23:47 . 2009-02-05 12:14 d——– C:\HJT
2009-02-03 21:20 . 2009-02-03 21:20 32,768 –ah—– c:\documents and settings\Bret\fpxlnac.exe
2009-02-03 21:18 . 2009-02-03 21:20 66,560 —h—– c:\windows\system32\secupdat.dat
2009-02-03 21:18 . 2009-02-03 21:18 32,768 –ah—– c:\documents and settings\Bret\vhc.exe
2009-02-03 16:20 . 2009-02-04 20:32 53,248 –a—— c:\windows\system32\drivers\ndisio.sys
2009-02-02 22:38 . 2009-02-02 22:38 0 –a—— c:\windows\system32\F5.tmp
2009-01-09 09:02 . 2009-01-09 09:03 d——– c:\documents and settings\All Users\Application Data\Juniper Networks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-05 18:55 90,112 —-a-w c:\windows\DUMP6c56.tmp
2009-02-05 16:02 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-02-05 03:31 90,112 —-a-w c:\windows\DUMP65ed.tmp
2009-02-05 01:00 90,112 —-a-w c:\windows\DUMP608e.tmp
2009-02-04 05:43 90,112 —-a-w c:\windows\DUMP5a16.tmp
2009-02-04 04:42 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-04 04:16 90,112 —-a-w c:\windows\DUMP8414.tmp
2009-01-31 16:31 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-31 16:31 107,272 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-01-18 19:36 ——— d—–w c:\program files\Common Files\Intuit
2009-01-09 16:05 ——— d—–w c:\documents and settings\Barron\Application Data\Juniper Networks
2009-01-08 22:00 ——— d—–w c:\documents and settings\Barron\Application Data\Apple Computer
2009-01-07 02:21 ——— d—–w c:\program files\Google
2008-12-27 08:13 ——— d—–w c:\program files\QuickTime
2008-12-27 08:07 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-27 08:07 ——— d—–w c:\program files\eMusic Download Manager
2008-12-21 22:29 ——— d—–w c:\program files\Bonjour
2008-12-21 22:28 ——— d—–w c:\program files\iTunes
2008-12-21 22:28 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-21 22:27 ——— d—–w c:\program files\iPod
2008-12-21 22:27 ——— d—–w c:\program files\Common Files\Apple
2008-12-17 19:59 ——— d—–w c:\documents and settings\Barron\Application Data\Tibia
2008-12-17 04:12 ——— d—–w c:\documents and settings\Bret\Application Data\Tibia
2008-12-16 03:47 ——— d—–w c:\documents and settings\Karen\Application Data\Tibia
2008-12-16 02:28 ——— d—–w c:\program files\Tibia
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
2008-08-07 01:56 236 —-a-w c:\documents and settings\Karen\jobq.dat
2007-06-06 16:10 110 —-a-w c:\documents and settings\All Users\Application Data\MostFunGameId.bin
2007-04-09 20:46 32 —-a-r c:\documents and settings\All Users\hash.dat
2007-11-09 22:10 30,288 —-a-w c:\program files\mozilla firefox\plugins\cgpcfg.dll
2007-11-09 22:10 79,440 —-a-w c:\program files\mozilla firefox\plugins\CgpCore.dll
2007-11-09 22:10 75,344 —-a-w c:\program files\mozilla firefox\plugins\confmgr.dll
2007-11-09 22:10 140,880 —-a-w c:\program files\mozilla firefox\plugins\ctxmui.dll
2007-11-09 22:10 42,576 —-a-w c:\program files\mozilla firefox\plugins\icafile.dll
2007-11-09 22:10 50,768 —-a-w c:\program files\mozilla firefox\plugins\icalogon.dll
2007-11-09 22:10 34,384 —-a-w c:\program files\mozilla firefox\plugins\logging.dll
2007-11-09 22:11 685,648 —-a-w c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2007-11-09 22:11 30,288 —-a-w c:\program files\mozilla firefox\plugins\TcpPServ.dll
.
——- Sigcheck ——-
2007-06-13 03:23 1050624 7875eb7fd202cd02ba8681389e69ebe5 c:\windows\explorer.exe
2007-06-13 04:26 1050624 22465e01808f9e8a5298f6e7bea5b91c c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-04 04:00 1049600 60615f381e0eb852a34939cf5abd2f86 c:\windows\$NtUninstallKB938828$\explorer.exe
2008-04-13 17:12 1051136 eb141f45e0b25358c4ea6b28cace6273 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
2007-06-13 03:23 1050624 6fdd173169483d0f3979a6518b189367 c:\windows\system32\dllcache\explorer.exe
2008-04-13 17:12 32768 065cef212f0621e845f7de84905bc8f6 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ctfmon.exe
2004-08-04 04:00 32768 9b8f5c51c5058cb6c137dd08405b59af c:\windows\system32\ctfmon.exe
2005-06-10 17:17 75264 b5e2f01a55c89adc8b861bde35de7d4a c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2008-04-13 17:12 75264 bfde361bc7c53505778e16df5201e308 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\spoolsv.exe
2005-06-10 16:53 75264 30bc53621c3f7acf331c48e8cf69b047 c:\windows\system32\spoolsv.exe
2008-04-13 17:12 43520 ddda8f6d02c591cb34f7ad74de6224ac c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
2004-08-04 04:00 41984 cc3acccb2c3c9a72e504a00ccb351db2 c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 40961]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-08-28 413184]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1711616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-06 196608]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 98304]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 139264]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-22 1413120]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-06-29 1052672]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 69632]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 434176]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 c:\windows\stsystra.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"nttakbit.exe"="c:\windows\nttakbit.exe" [2009-02-05 3584]
"lfzfweiu.exe"="c:\windows\lfzfweiu.exe" [2009-02-05 3584]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-02-06 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\explorer.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-31 09:31 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Juniper Networks\\Secure Application Manager\\dsSamProxy.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"4000:TCP"= 4000:TCP:Blizzard
"6113:TCP"= 6113:TCP:Blizzard
"6112:TCP"= 6112:TCP:Blizzard
"6114:TCP"= 6114:TCP:Blizzard
"6115:TCP"= 6115:TCP:Blizzard
"6116:TCP"= 6116:TCP:Blizzard
"6117:TCP"= 6117:TCP:Blizzard
"6118:TCP"= 6118:TCP:Blizzard
"6119:TCP"= 6119:TCP:Blizzard
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-08-17 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-08-17 107272]
R1 NEOFLTR_550_11965;Juniper Networks TDI Filter Driver (NEOFLTR_550_11965);c:\windows\system32\drivers\NEOFLTR_550_11965.sys [2007-07-16 63008]
R1 NEOFLTR_620_13525;Juniper Networks TDI Filter Driver (NEOFLTR_620_13525);c:\windows\system32\drivers\NEOFLTR_620_13525.sys [2008-08-28 64480]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-08-17 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-17 298264]
S1 ethyigge;ethyigge;c:\windows\system32\drivers\ethyigge.sys –> c:\windows\system32\drivers\ethyigge.sys [?]
S3 adbkwvzx;adbkwvzx;\??\c:\windows\System32\Drivers\adbkwvzx.sys –> c:\windows\System32\Drivers\adbkwvzx.sys [?]
S3 agyzvxmh;agyzvxmh;\??\c:\windows\System32\Drivers\agyzvxmh.sys –> c:\windows\System32\Drivers\agyzvxmh.sys [?]
S3 ahmzkppr;ahmzkppr;\??\c:\windows\System32\Drivers\ahmzkppr.sys –> c:\windows\System32\Drivers\ahmzkppr.sys [?]
S3 alcqazmk;alcqazmk;\??\c:\windows\System32\Drivers\alcqazmk.sys –> c:\windows\System32\Drivers\alcqazmk.sys [?]
S3 aqlztezp;aqlztezp;\??\c:\windows\System32\Drivers\aqlztezp.sys –> c:\windows\System32\Drivers\aqlztezp.sys [?]
S3 atpmjoyk;atpmjoyk;\??\c:\windows\System32\Drivers\atpmjoyk.sys –> c:\windows\System32\Drivers\atpmjoyk.sys [?]
S3 awhsjsmg;awhsjsmg;\??\c:\windows\System32\Drivers\awhsjsmg.sys –> c:\windows\System32\Drivers\awhsjsmg.sys [?]
S3 bfwxlkxq;bfwxlkxq;\??\c:\windows\System32\Drivers\bfwxlkxq.sys –> c:\windows\System32\Drivers\bfwxlkxq.sys [?]
S3 bhirqjsk;bhirqjsk;\??\c:\windows\System32\Drivers\bhirqjsk.sys –> c:\windows\System32\Drivers\bhirqjsk.sys [?]
S3 bndpohvk;bndpohvk;\??\c:\windows\System32\Drivers\bndpohvk.sys –> c:\windows\System32\Drivers\bndpohvk.sys [?]
S3 bzmgnrua;bzmgnrua;\??\c:\windows\System32\Drivers\bzmgnrua.sys –> c:\windows\System32\Drivers\bzmgnrua.sys [?]
S3 bzthitdx;bzthitdx;\??\c:\windows\System32\Drivers\bzthitdx.sys –> c:\windows\System32\Drivers\bzthitdx.sys [?]
S3 ccagpfak;ccagpfak;\??\c:\windows\System32\Drivers\ccagpfak.sys –> c:\windows\System32\Drivers\ccagpfak.sys [?]
S3 ceepgpls;ceepgpls;\??\c:\windows\System32\Drivers\ceepgpls.sys –> c:\windows\System32\Drivers\ceepgpls.sys [?]
S3 cgajerdn;cgajerdn;\??\c:\windows\System32\Drivers\cgajerdn.sys –> c:\windows\System32\Drivers\cgajerdn.sys [?]
S3 ckfymirf;ckfymirf;\??\c:\windows\System32\Drivers\ckfymirf.sys –> c:\windows\System32\Drivers\ckfymirf.sys [?]
S3 comazqkd;comazqkd;\??\c:\windows\System32\Drivers\comazqkd.sys –> c:\windows\System32\Drivers\comazqkd.sys [?]
S3 cppugygq;cppugygq;\??\c:\windows\System32\Drivers\cppugygq.sys –> c:\windows\System32\Drivers\cppugygq.sys [?]
S3 cquntych;cquntych;\??\c:\windows\System32\Drivers\cquntych.sys –> c:\windows\System32\Drivers\cquntych.sys [?]
S3 crxysodg;crxysodg;c:\windows\system32\drivers\crxysodg.sys [2009-02-05 33920]
S3 cxtzxbyw;cxtzxbyw;\??\c:\windows\System32\Drivers\cxtzxbyw.sys –> c:\windows\System32\Drivers\cxtzxbyw.sys [?]
S3 dcqoqzqk;dcqoqzqk;\??\c:\windows\System32\Drivers\dcqoqzqk.sys –> c:\windows\System32\Drivers\dcqoqzqk.sys [?]
S3 deqgwxjs;deqgwxjs;\??\c:\windows\System32\Drivers\deqgwxjs.sys –> c:\windows\System32\Drivers\deqgwxjs.sys [?]
S3 diihfegw;diihfegw;\??\c:\windows\System32\Drivers\diihfegw.sys –> c:\windows\System32\Drivers\diihfegw.sys [?]
S3 dlztawbb;dlztawbb;\??\c:\windows\System32\Drivers\dlztawbb.sys –> c:\windows\System32\Drivers\dlztawbb.sys [?]
S3 dofwwvrh;dofwwvrh;\??\c:\windows\System32\Drivers\dofwwvrh.sys –> c:\windows\System32\Drivers\dofwwvrh.sys [?]
S3 dpircxuz;dpircxuz;\??\c:\windows\System32\Drivers\dpircxuz.sys –> c:\windows\System32\Drivers\dpircxuz.sys [?]
S3 dplpdibp;dplpdibp;\??\c:\windows\System32\Drivers\dplpdibp.sys –> c:\windows\System32\Drivers\dplpdibp.sys [?]
S3 dqgnyfne;dqgnyfne;\??\c:\windows\System32\Drivers\dqgnyfne.sys –> c:\windows\System32\Drivers\dqgnyfne.sys [?]
S3 dzaygihl;dzaygihl;\??\c:\windows\System32\Drivers\dzaygihl.sys –> c:\windows\System32\Drivers\dzaygihl.sys [?]
S3 euketgec;euketgec;\??\c:\windows\System32\Drivers\euketgec.sys –> c:\windows\System32\Drivers\euketgec.sys [?]
S3 exbosxxc;exbosxxc;\??\c:\windows\System32\Drivers\exbosxxc.sys –> c:\windows\System32\Drivers\exbosxxc.sys [?]
S3 faitxavy;faitxavy;\??\c:\windows\System32\Drivers\faitxavy.sys –> c:\windows\System32\Drivers\faitxavy.sys [?]
S3 fdihkvxe;fdihkvxe;\??\c:\windows\System32\Drivers\fdihkvxe.sys –> c:\windows\System32\Drivers\fdihkvxe.sys [?]
S3 febzlklr;febzlklr;\??\c:\windows\System32\Drivers\febzlklr.sys –> c:\windows\System32\Drivers\febzlklr.sys [?]
S3 fgvtayet;fgvtayet;\??\c:\windows\System32\Drivers\fgvtayet.sys –> c:\windows\System32\Drivers\fgvtayet.sys [?]
S3 fhpntvti;fhpntvti;\??\c:\windows\System32\Drivers\fhpntvti.sys –> c:\windows\System32\Drivers\fhpntvti.sys [?]
S3 fjhmalir;fjhmalir;\??\c:\windows\System32\Drivers\fjhmalir.sys –> c:\windows\System32\Drivers\fjhmalir.sys [?]
S3 fkaqmowk;fkaqmowk;\??\c:\windows\System32\Drivers\fkaqmowk.sys –> c:\windows\System32\Drivers\fkaqmowk.sys [?]
S3 fnfohlsh;fnfohlsh;\??\c:\windows\System32\Drivers\fnfohlsh.sys –> c:\windows\System32\Drivers\fnfohlsh.sys [?]
S3 ftizlanf;ftizlanf;\??\c:\windows\System32\Drivers\ftizlanf.sys –> c:\windows\System32\Drivers\ftizlanf.sys [?]
S3 ftpmieju;ftpmieju;\??\c:\windows\System32\Drivers\ftpmieju.sys –> c:\windows\System32\Drivers\ftpmieju.sys [?]
S3 ftsjcwpm;ftsjcwpm;\??\c:\windows\System32\Drivers\ftsjcwpm.sys –> c:\windows\System32\Drivers\ftsjcwpm.sys [?]
S3 fuqajqjm;fuqajqjm;\??\c:\windows\System32\Drivers\fuqajqjm.sys –> c:\windows\System32\Drivers\fuqajqjm.sys [?]
S3 fuuyfewv;fuuyfewv;\??\c:\windows\System32\Drivers\fuuyfewv.sys –> c:\windows\System32\Drivers\fuuyfewv.sys [?]
S3 fvptrayk;fvptrayk;\??\c:\windows\System32\Drivers\fvptrayk.sys –> c:\windows\System32\Drivers\fvptrayk.sys [?]
S3 fyssvwph;fyssvwph;\??\c:\windows\System32\Drivers\fyssvwph.sys –> c:\windows\System32\Drivers\fyssvwph.sys [?]
S3 fzhbocbf;fzhbocbf;\??\c:\windows\System32\Drivers\fzhbocbf.sys –> c:\windows\System32\Drivers\fzhbocbf.sys [?]
S3 gacjfhui;gacjfhui;\??\c:\windows\System32\Drivers\gacjfhui.sys –> c:\windows\System32\Drivers\gacjfhui.sys [?]
S3 gbvvnfea;gbvvnfea;\??\c:\windows\System32\Drivers\gbvvnfea.sys –> c:\windows\System32\Drivers\gbvvnfea.sys [?]
S3 gktzahlx;gktzahlx;\??\c:\windows\System32\Drivers\gktzahlx.sys –> c:\windows\System32\Drivers\gktzahlx.sys [?]
S3 gqhxgjct;gqhxgjct;\??\c:\windows\System32\Drivers\gqhxgjct.sys –> c:\windows\System32\Drivers\gqhxgjct.sys [?]
S3 gznoqfls;gznoqfls;\??\c:\windows\System32\Drivers\gznoqfls.sys –> c:\windows\System32\Drivers\gznoqfls.sys [?]
S3 gzrkxewd;gzrkxewd;\??\c:\windows\System32\Drivers\gzrkxewd.sys –> c:\windows\System32\Drivers\gzrkxewd.sys [?]
S3 hsenitvc;hsenitvc;\??\c:\windows\System32\Drivers\hsenitvc.sys –> c:\windows\System32\Drivers\hsenitvc.sys [?]
S3 hsjvpafb;hsjvpafb;\??\c:\windows\System32\Drivers\hsjvpafb.sys –> c:\windows\System32\Drivers\hsjvpafb.sys [?]
S3 hsqcilte;hsqcilte;\??\c:\windows\System32\Drivers\hsqcilte.sys –> c:\windows\System32\Drivers\hsqcilte.sys [?]
S3 hxcbcnay;hxcbcnay;\??\c:\windows\System32\Drivers\hxcbcnay.sys –> c:\windows\System32\Drivers\hxcbcnay.sys [?]
S3 hzkmtgti;hzkmtgti;\??\c:\windows\System32\Drivers\hzkmtgti.sys –> c:\windows\System32\Drivers\hzkmtgti.sys [?]
S3 iivqqfob;iivqqfob;\??\c:\windows\System32\Drivers\iivqqfob.sys –> c:\windows\System32\Drivers\iivqqfob.sys [?]
S3 ikywixiy;ikywixiy;\??\c:\windows\System32\Drivers\ikywixiy.sys –> c:\windows\System32\Drivers\ikywixiy.sys [?]
S3 inrvkgpo;inrvkgpo;\??\c:\windows\System32\Drivers\inrvkgpo.sys –> c:\windows\System32\Drivers\inrvkgpo.sys [?]
S3 iqejlwdg;iqejlwdg;\??\c:\windows\System32\Drivers\iqejlwdg.sys –> c:\windows\System32\Drivers\iqejlwdg.sys [?]
S3 iqgptswa;iqgptswa;\??\c:\windows\System32\Drivers\iqgptswa.sys –> c:\windows\System32\Drivers\iqgptswa.sys [?]
S3 iwrpxzgg;iwrpxzgg;\??\c:\windows\System32\Drivers\iwrpxzgg.sys –> c:\windows\System32\Drivers\iwrpxzgg.sys [?]
S3 jhosrlvn;jhosrlvn;\??\c:\windows\System32\Drivers\jhosrlvn.sys –> c:\windows\System32\Drivers\jhosrlvn.sys [?]
S3 jiiuacwq;jiiuacwq;\??\c:\windows\System32\Drivers\jiiuacwq.sys –> c:\windows\System32\Drivers\jiiuacwq.sys [?]
S3 jkqwlzgt;jkqwlzgt;\??\c:\windows\System32\Drivers\jkqwlzgt.sys –> c:\windows\System32\Drivers\jkqwlzgt.sys [?]
S3 jljhbqgk;jljhbqgk;\??\c:\windows\System32\Drivers\jljhbqgk.sys –> c:\windows\System32\Drivers\jljhbqgk.sys [?]
S3 jmcfzuta;jmcfzuta;\??\c:\windows\System32\Drivers\jmcfzuta.sys –> c:\windows\System32\Drivers\jmcfzuta.sys [?]
S3 jnjmxipc;jnjmxipc;\??\c:\windows\System32\Drivers\jnjmxipc.sys –> c:\windows\System32\Drivers\jnjmxipc.sys [?]
S3 jtdpfsbk;jtdpfsbk;\??\c:\windows\System32\Drivers\jtdpfsbk.sys –> c:\windows\System32\Drivers\jtdpfsbk.sys [?]
S3 jtoeajuw;jtoeajuw;\??\c:\windows\System32\Drivers\jtoeajuw.sys –> c:\windows\System32\Drivers\jtoeajuw.sys [?]
S3 junvyxwx;junvyxwx;\??\c:\windows\System32\Drivers\junvyxwx.sys –> c:\windows\System32\Drivers\junvyxwx.sys [?]
S3 jxihztde;jxihztde;\??\c:\windows\System32\Drivers\jxihztde.sys –> c:\windows\System32\Drivers\jxihztde.sys [?]
S3 kbuokmrp;kbuokmrp;\??\c:\windows\System32\Drivers\kbuokmrp.sys –> c:\windows\System32\Drivers\kbuokmrp.sys [?]
S3 kbuvmejq;kbuvmejq;\??\c:\windows\System32\Drivers\kbuvmejq.sys –> c:\windows\System32\Drivers\kbuvmejq.sys [?]
S3 kdgwecas;kdgwecas;\??\c:\windows\System32\Drivers\kdgwecas.sys –> c:\windows\System32\Drivers\kdgwecas.sys [?]
S3 kqwcjnrl;kqwcjnrl;\??\c:\windows\System32\Drivers\kqwcjnrl.sys –> c:\windows\System32\Drivers\kqwcjnrl.sys [?]
S3 krlynxqh;krlynxqh;\??\c:\windows\System32\Drivers\krlynxqh.sys –> c:\windows\System32\Drivers\krlynxqh.sys [?]
S3 kxiknqej;kxiknqej;\??\c:\windows\System32\Drivers\kxiknqej.sys –> c:\windows\System32\Drivers\kxiknqej.sys [?]
S3 lcahnbte;lcahnbte;\??\c:\windows\System32\Drivers\lcahnbte.sys –> c:\windows\System32\Drivers\lcahnbte.sys [?]
S3 lfnjvuqd;lfnjvuqd;\??\c:\windows\System32\Drivers\lfnjvuqd.sys –> c:\windows\System32\Drivers\lfnjvuqd.sys [?]
S3 lnxmzfgo;lnxmzfgo;\??\c:\windows\System32\Drivers\lnxmzfgo.sys –> c:\windows\System32\Drivers\lnxmzfgo.sys [?]
S3 lpbrguiz;lpbrguiz;\??\c:\windows\System32\Drivers\lpbrguiz.sys –> c:\windows\System32\Drivers\lpbrguiz.sys [?]
S3 lqzedbnl;lqzedbnl;\??\c:\windows\System32\Drivers\lqzedbnl.sys –> c:\windows\System32\Drivers\lqzedbnl.sys [?]
S3 miegjyix;miegjyix;c:\windows\system32\drivers\miegjyix.sys [2009-02-05 33920]
S3 mjlonwqm;mjlonwqm;\??\c:\windows\System32\Drivers\mjlonwqm.sys –> c:\windows\System32\Drivers\mjlonwqm.sys [?]
S3 mkgjieic;mkgjieic;\??\c:\windows\System32\Drivers\mkgjieic.sys –> c:\windows\System32\Drivers\mkgjieic.sys [?]
S3 mlqpkcll;mlqpkcll;\??\c:\windows\System32\Drivers\mlqpkcll.sys –> c:\windows\System32\Drivers\mlqpkcll.sys [?]
S3 mmhaaety;mmhaaety;\??\c:\windows\System32\Drivers\mmhaaety.sys –> c:\windows\System32\Drivers\mmhaaety.sys [?]
S3 mvquqacv;mvquqacv;\??\c:\windows\System32\Drivers\mvquqacv.sys –> c:\windows\System32\Drivers\mvquqacv.sys [?]
S3 mxyqsrew;mxyqsrew;\??\c:\windows\System32\Drivers\mxyqsrew.sys –> c:\windows\System32\Drivers\mxyqsrew.sys [?]
S3 mzjledhd;mzjledhd;\??\c:\windows\System32\Drivers\mzjledhd.sys –> c:\windows\System32\Drivers\mzjledhd.sys [?]
S3 nbmvlzqh;nbmvlzqh;\??\c:\windows\System32\Drivers\nbmvlzqh.sys –> c:\windows\System32\Drivers\nbmvlzqh.sys [?]
S3 neqiiyvo;neqiiyvo;\??\c:\windows\System32\Drivers\neqiiyvo.sys –> c:\windows\System32\Drivers\neqiiyvo.sys [?]
S3 ngandykz;ngandykz;\??\c:\windows\System32\Drivers\ngandykz.sys –> c:\windows\System32\Drivers\ngandykz.sys [?]
S3 nnkltjrt;nnkltjrt;\??\c:\windows\System32\Drivers\nnkltjrt.sys –> c:\windows\System32\Drivers\nnkltjrt.sys [?]
S3 nqhvuqgb;nqhvuqgb;\??\c:\windows\System32\Drivers\nqhvuqgb.sys –> c:\windows\System32\Drivers\nqhvuqgb.sys [?]
S3 nxmjrrob;nxmjrrob;\??\c:\windows\System32\Drivers\nxmjrrob.sys –> c:\windows\System32\Drivers\nxmjrrob.sys [?]
S3 nxqvxzrq;nxqvxzrq;\??\c:\windows\System32\Drivers\nxqvxzrq.sys –> c:\windows\System32\Drivers\nxqvxzrq.sys [?]
S3 oeyrcqyw;oeyrcqyw;\??\c:\windows\System32\Drivers\oeyrcqyw.sys –> c:\windows\System32\Drivers\oeyrcqyw.sys [?]
S3 ohsaxaoh;ohsaxaoh;\??\c:\windows\System32\Drivers\ohsaxaoh.sys –> c:\windows\System32\Drivers\ohsaxaoh.sys [?]
S3 ojwgrhlr;ojwgrhlr;c:\windows\system32\drivers\ojwgrhlr.sys [2009-02-05 33920]
S3 okwxfzld;okwxfzld;\??\c:\windows\System32\Drivers\okwxfzld.sys –> c:\windows\System32\Drivers\okwxfzld.sys [?]
S3 olsabzgp;olsabzgp;\??\c:\windows\System32\Drivers\olsabzgp.sys –> c:\windows\System32\Drivers\olsabzgp.sys [?]
S3 opsnzhgw;opsnzhgw;\??\c:\windows\System32\Drivers\opsnzhgw.sys –> c:\windows\System32\Drivers\opsnzhgw.sys [?]
S3 ostrnyzx;ostrnyzx;\??\c:\windows\System32\Drivers\ostrnyzx.sys –> c:\windows\System32\Drivers\ostrnyzx.sys [?]
S3 pdxvgtgc;pdxvgtgc;\??\c:\windows\System32\Drivers\pdxvgtgc.sys –> c:\windows\System32\Drivers\pdxvgtgc.sys [?]
S3 pehqmkrh;pehqmkrh;\??\c:\windows\System32\Drivers\pehqmkrh.sys –> c:\windows\System32\Drivers\pehqmkrh.sys [?]
S3 pfjlatun;pfjlatun;\??\c:\windows\System32\Drivers\pfjlatun.sys –> c:\windows\System32\Drivers\pfjlatun.sys [?]
S3 pfrpnppv;pfrpnppv;\??\c:\windows\System32\Drivers\pfrpnppv.sys –> c:\windows\System32\Drivers\pfrpnppv.sys [?]
S3 phsympze;phsympze;\??\c:\windows\System32\Drivers\phsympze.sys –> c:\windows\System32\Drivers\phsympze.sys [?]
S3 pioeoxci;pioeoxci;\??\c:\windows\System32\Drivers\pioeoxci.sys –> c:\windows\System32\Drivers\pioeoxci.sys [?]
S3 pkbwrhxl;pkbwrhxl;\??\c:\windows\System32\Drivers\pkbwrhxl.sys –> c:\windows\System32\Drivers\pkbwrhxl.sys [?]
S3 pkxfeeww;pkxfeeww;\??\c:\windows\System32\Drivers\pkxfeeww.sys –> c:\windows\System32\Drivers\pkxfeeww.sys [?]
S3 plgdnhwy;plgdnhwy;\??\c:\windows\System32\Drivers\plgdnhwy.sys –> c:\windows\System32\Drivers\plgdnhwy.sys [?]
S3 pxkcrmnw;pxkcrmnw;\??\c:\windows\System32\Drivers\pxkcrmnw.sys –> c:\windows\System32\Drivers\pxkcrmnw.sys [?]
S3 qctmjpjg;qctmjpjg;\??\c:\windows\System32\Drivers\qctmjpjg.sys –> c:\windows\System32\Drivers\qctmjpjg.sys [?]
S3 qfxguylt;qfxguylt;\??\c:\windows\System32\Drivers\qfxguylt.sys –> c:\windows\System32\Drivers\qfxguylt.sys [?]
S3 qlsnxoir;qlsnxoir;\??\c:\windows\System32\Drivers\qlsnxoir.sys –> c:\windows\System32\Drivers\qlsnxoir.sys [?]
S3 qpzaqdek;qpzaqdek;\??\c:\windows\System32\Drivers\qpzaqdek.sys –> c:\windows\System32\Drivers\qpzaqdek.sys [?]
S3 quelmaeo;quelmaeo;\??\c:\windows\System32\Drivers\quelmaeo.sys –> c:\windows\System32\Drivers\quelmaeo.sys [?]
S3 qyvgszwe;qyvgszwe;\??\c:\windows\System32\Drivers\qyvgszwe.sys –> c:\windows\System32\Drivers\qyvgszwe.sys [?]
S3 rcbfdixx;rcbfdixx;\??\c:\windows\System32\Drivers\rcbfdixx.sys –> c:\windows\System32\Drivers\rcbfdixx.sys [?]
S3 rfnxliit;rfnxliit;\??\c:\windows\System32\Drivers\rfnxliit.sys –> c:\windows\System32\Drivers\rfnxliit.sys [?]
S3 rfoyzykx;rfoyzykx;\??\c:\windows\System32\Drivers\rfoyzykx.sys –> c:\windows\System32\Drivers\rfoyzykx.sys [?]
S3 rfuqkent;rfuqkent;\??\c:\windows\System32\Drivers\rfuqkent.sys –> c:\windows\System32\Drivers\rfuqkent.sys [?]
S3 rfvxdlva;rfvxdlva;\??\c:\windows\System32\Drivers\rfvxdlva.sys –> c:\windows\System32\Drivers\rfvxdlva.sys [?]
S3 ropjxhty;ropjxhty;\??\c:\windows\System32\Drivers\ropjxhty.sys –> c:\windows\System32\Drivers\ropjxhty.sys [?]
S3 rpwwwkju;rpwwwkju;\??\c:\windows\System32\Drivers\rpwwwkju.sys –> c:\windows\System32\Drivers\rpwwwkju.sys [?]
S3 rrtkqhqn;rrtkqhqn;\??\c:\windows\System32\Drivers\rrtkqhqn.sys –> c:\windows\System32\Drivers\rrtkqhqn.sys [?]
S3 rshjgnsc;rshjgnsc;\??\c:\windows\System32\Drivers\rshjgnsc.sys –> c:\windows\System32\Drivers\rshjgnsc.sys [?]
S3 rtgyqied;rtgyqied;\??\c:\windows\System32\Drivers\rtgyqied.sys –> c:\windows\System32\Drivers\rtgyqied.sys [?]
S3 rwmrodfw;rwmrodfw;\??\c:\windows\System32\Drivers\rwmrodfw.sys –> c:\windows\System32\Drivers\rwmrodfw.sys [?]
S3 rxipgeya;rxipgeya;\??\c:\windows\System32\Drivers\rxipgeya.sys –> c:\windows\System32\Drivers\rxipgeya.sys [?]
S3 rylzihqo;rylzihqo;\??\c:\windows\System32\Drivers\rylzihqo.sys –> c:\windows\System32\Drivers\rylzihqo.sys [?]
S3 rzajfdty;rzajfdty;\??\c:\windows\System32\Drivers\rzajfdty.sys –> c:\windows\System32\Drivers\rzajfdty.sys [?]
S3 sbuqifos;sbuqifos;\??\c:\windows\System32\Drivers\sbuqifos.sys –> c:\windows\System32\Drivers\sbuqifos.sys [?]
S3 sgogdmms;sgogdmms;\??\c:\windows\System32\Drivers\sgogdmms.sys –> c:\windows\System32\Drivers\sgogdmms.sys [?]
S3 shcvsnmd;shcvsnmd;\??\c:\windows\System32\Drivers\shcvsnmd.sys –> c:\windows\System32\Drivers\shcvsnmd.sys [?]
S3 shutcxbx;shutcxbx;\??\c:\windows\System32\Drivers\shutcxbx.sys –> c:\windows\System32\Drivers\shutcxbx.sys [?]
S3 sitarzwa;sitarzwa;\??\c:\windows\System32\Drivers\sitarzwa.sys –> c:\windows\System32\Drivers\sitarzwa.sys [?]
S3 sjuveiah;sjuveiah;\??\c:\windows\System32\Drivers\sjuveiah.sys –> c:\windows\System32\Drivers\sjuveiah.sys [?]
S3 sljjaafq;sljjaafq;\??\c:\windows\System32\Drivers\sljjaafq.sys –> c:\windows\System32\Drivers\sljjaafq.sys [?]
S3 sltyysxp;sltyysxp;\??\c:\windows\System32\Drivers\sltyysxp.sys –> c:\windows\System32\Drivers\sltyysxp.sys [?]
S3 svyxsynq;svyxsynq;\??\c:\windows\System32\Drivers\svyxsynq.sys –> c:\windows\System32\Drivers\svyxsynq.sys [?]
S3 swragxrb;swragxrb;\??\c:\windows\System32\Drivers\swragxrb.sys –> c:\windows\System32\Drivers\swragxrb.sys [?]
S3 szwzksge;szwzksge;\??\c:\windows\System32\Drivers\szwzksge.sys –> c:\windows\System32\Drivers\szwzksge.sys [?]
S3 tavtvdwb;tavtvdwb;\??\c:\windows\System32\Drivers\tavtvdwb.sys –> c:\windows\System32\Drivers\tavtvdwb.sys [?]
S3 tdmtspva;tdmtspva;\??\c:\windows\System32\Drivers\tdmtspva.sys –> c:\windows\System32\Drivers\tdmtspva.sys [?]
S3 tiwyfltq;tiwyfltq;\??\c:\windows\System32\Drivers\tiwyfltq.sys –> c:\windows\System32\Drivers\tiwyfltq.sys [?]
S3 tsdtagpg;tsdtagpg;\??\c:\windows\System32\Drivers\tsdtagpg.sys –> c:\windows\System32\Drivers\tsdtagpg.sys [?]
S3 ubekgqmj;ubekgqmj;\??\c:\windows\System32\Drivers\ubekgqmj.sys –> c:\windows\System32\Drivers\ubekgqmj.sys [?]
S3 udfajfgv;udfajfgv;\??\c:\windows\System32\Drivers\udfajfgv.sys –> c:\windows\System32\Drivers\udfajfgv.sys [?]
S3 udyhxfkh;udyhxfkh;\??\c:\windows\System32\Drivers\udyhxfkh.sys –> c:\windows\System32\Drivers\udyhxfkh.sys [?]
S3 uffdnpvs;uffdnpvs;\??\c:\windows\System32\Drivers\uffdnpvs.sys –> c:\windows\System32\Drivers\uffdnpvs.sys [?]
S3 uhfgbujf;uhfgbujf;\??\c:\windows\System32\Drivers\uhfgbujf.sys –> c:\windows\System32\Drivers\uhfgbujf.sys [?]
S3 uiqdhgxk;uiqdhgxk;\??\c:\windows\System32\Drivers\uiqdhgxk.sys –> c:\windows\System32\Drivers\uiqdhgxk.sys [?]
S3 urpxhreo;urpxhreo;\??\c:\windows\System32\Drivers\urpxhreo.sys –> c:\windows\System32\Drivers\urpxhreo.sys [?]
S3 uwisbtmd;uwisbtmd;\??\c:\windows\System32\Drivers\uwisbtmd.sys –> c:\windows\System32\Drivers\uwisbtmd.sys [?]
S3 uztucmji;uztucmji;\??\c:\windows\System32\Drivers\uztucmji.sys –> c:\windows\System32\Drivers\uztucmji.sys [?]
S3 vdhqpffb;vdhqpffb;\??\c:\windows\System32\Drivers\vdhqpffb.sys –> c:\windows\System32\Drivers\vdhqpffb.sys [?]
S3 vfwbldii;vfwbldii;\??\c:\windows\System32\Drivers\vfwbldii.sys –> c:\windows\System32\Drivers\vfwbldii.sys [?]
S3 vgmzviic;vgmzviic;\??\c:\windows\System32\Drivers\vgmzviic.sys –> c:\windows\System32\Drivers\vgmzviic.sys [?]
S3 vihzenod;vihzenod;\??\c:\windows\System32\Drivers\vihzenod.sys –> c:\windows\System32\Drivers\vihzenod.sys [?]
S3 vikvhapk;vikvhapk;\??\c:\windows\System32\Drivers\vikvhapk.sys –> c:\windows\System32\Drivers\vikvhapk.sys [?]
S3 wckauwdf;wckauwdf;\??\c:\windows\System32\Drivers\wckauwdf.sys –> c:\windows\System32\Drivers\wckauwdf.sys [?]
S3 wenpfpjl;wenpfpjl;\??\c:\windows\System32\Drivers\wenpfpjl.sys –> c:\windows\System32\Drivers\wenpfpjl.sys [?]
S3 wgqjosrb;wgqjosrb;\??\c:\windows\System32\Drivers\wgqjosrb.sys –> c:\windows\System32\Drivers\wgqjosrb.sys [?]
S3 wibvehix;wibvehix;\??\c:\windows\System32\Drivers\wibvehix.sys –> c:\windows\System32\Drivers\wibvehix.sys [?]
S3 wlnkrcid;wlnkrcid;\??\c:\windows\System32\Drivers\wlnkrcid.sys –> c:\windows\System32\Drivers\wlnkrcid.sys [?]
S3 wpsoxqah;wpsoxqah;\??\c:\windows\System32\Drivers\wpsoxqah.sys –> c:\windows\System32\Drivers\wpsoxqah.sys [?]
S3 wptoksfa;wptoksfa;\??\c:\windows\System32\Drivers\wptoksfa.sys –> c:\windows\System32\Drivers\wptoksfa.sys [?]
S3 wuenpqxi;wuenpqxi;\??\c:\windows\System32\Drivers\wuenpqxi.sys –> c:\windows\System32\Drivers\wuenpqxi.sys [?]
S3 wunyxsoh;wunyxsoh;\??\c:\windows\System32\Drivers\wunyxsoh.sys –> c:\windows\System32\Drivers\wunyxsoh.sys [?]
S3 wvixnoju;wvixnoju;\??\c:\windows\System32\Drivers\wvixnoju.sys –> c:\windows\System32\Drivers\wvixnoju.sys [?]
S3 wvqyjvwd;wvqyjvwd;\??\c:\windows\System32\Drivers\wvqyjvwd.sys –> c:\windows\System32\Drivers\wvqyjvwd.sys [?]
S3 wvrsdazn;wvrsdazn;\??\c:\windows\System32\Drivers\wvrsdazn.sys –> c:\windows\System32\Drivers\wvrsdazn.sys [?]
S3 xoyekbme;xoyekbme;\??\c:\windows\System32\Drivers\xoyekbme.sys –> c:\windows\System32\Drivers\xoyekbme.sys [?]
S3 xqsqtodw;xqsqtodw;\??\c:\windows\System32\Drivers\xqsqtodw.sys –> c:\windows\System32\Drivers\xqsqtodw.sys [?]
S3 xsgvutjj;xsgvutjj;\??\c:\windows\System32\Drivers\xsgvutjj.sys –> c:\windows\System32\Drivers\xsgvutjj.sys [?]
S3 ycgqdkpd;ycgqdkpd;\??\c:\windows\System32\Drivers\ycgqdkpd.sys –> c:\windows\System32\Drivers\ycgqdkpd.sys [?]
S3 ydvnkqgi;ydvnkqgi;\??\c:\windows\System32\Drivers\ydvnkqgi.sys –> c:\windows\System32\Drivers\ydvnkqgi.sys [?]
S3 yisegzxj;yisegzxj;\??\c:\windows\System32\Drivers\yisegzxj.sys –> c:\windows\System32\Drivers\yisegzxj.sys [?]
S3 yrwfyroh;yrwfyroh;\??\c:\windows\System32\Drivers\yrwfyroh.sys –> c:\windows\System32\Drivers\yrwfyroh.sys [?]
S3 yttyathl;yttyathl;\??\c:\windows\System32\Drivers\yttyathl.sys –> c:\windows\System32\Drivers\yttyathl.sys [?]
S3 zapkrcqf;zapkrcqf;\??\c:\windows\System32\Drivers\zapkrcqf.sys –> c:\windows\System32\Drivers\zapkrcqf.sys [?]
S3 zfjdobyc;zfjdobyc;\??\c:\windows\System32\Drivers\zfjdobyc.sys –> c:\windows\System32\Drivers\zfjdobyc.sys [?]
S3 ztsaafed;ztsaafed;\??\c:\windows\System32\Drivers\ztsaafed.sys –> c:\windows\System32\Drivers\ztsaafed.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-01-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -
HKU-Default-Run-tezrtsjhfr84iusjfo84f - c:\windows\TEMP\csrssc.exe
HKU-Default-Run-services - c:\windows\services.exe
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.dell.com
mSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=3070206
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\documents and settings\Bret\Application Data\Mozilla\Firefox\Profiles\5kyh3eaj.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPSFDMGR.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-05 15:45:05
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(408)
c:\program files\Juniper Networks\Secure Application Manager\samnsp.dll
c:\program files\Bonjour\mdnsNSP.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Juniper Networks\Common Files\dsNcService.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Apoint\hidfind.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-02-05 15:47:40 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-05 22:47:36
Pre-Run: 20,689,956,864 bytes free
Post-Run: 21,450,190,848 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
420 — E O F — 2009-01-15 09:04:13
Also I got a Threat detection just a second ago by my AVG and it didn't have an option to block it or move it.
Also, I just got a notification that there are more virus's (trojans) on my pc from my "Spyware Protect 2009" and when I went to my Task Manager I found 47.tmp running and csrssc.exe (again).
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:
file::
c:\windows\system32\drivers\ojwgrhlr.sys
c:\windows\system32\drivers\crxysodg.sys
c:\windows\lfzfweiu.exe
c:\windows\system32\drivers\miegjyix.sys
c:\windows\system32\gcc.exe
c:\windows\nttakbit.exe
c:\windows\system32\mlJCRKeE.dll
c:\documents and settings\Bret\fpxlnac.exe
c:\windows\system32\secupdat.dat
c:\documents and settings\Bret\vhc.exe
c:\windows\system32\drivers\ndisio.sys
c:\windows\system32\F5.tmp
c:\documents and settings\Karen\jobq.dat
Folder::
Registry::
Driver::
Save this as CFScript.txt, in the same location as ComboFix.exe
[external image: Posted Image]
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Alrighty, I got a lucky break and it let me log on. I ran ComboFix but now there is some program that wont let me surf the Web, meaning I can't get to these forums without it redirecting to the URL http://browser-security.microsoft.com/block/php?r=1.0 and says "Oops! This link appears broken, DNS error - cannot find server." but I know that it works because it lets me load other web pages for a few seconds but then redirects there. I'm currently looking for a program on Task Manager that isn't supposed to be there and maybe I can stop it…. any tips till then?
Found it!! It was sysgaurd.exe (I think that's the exact spelling but may not be) it's a spyware prog. from a false virus protect program. Here is the ComboFix log:
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1014.575 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Bret\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
c:\documents and settings\Bret\fpxlnac.exe
c:\documents and settings\Bret\vhc.exe
c:\documents and settings\Karen\jobq.dat
c:\windows\lfzfweiu.exe
c:\windows\nttakbit.exe
c:\windows\system32\drivers\crxysodg.sys
c:\windows\system32\drivers\miegjyix.sys
c:\windows\system32\drivers\ndisio.sys
c:\windows\system32\drivers\ojwgrhlr.sys
c:\windows\system32\F5.tmp
c:\windows\system32\gcc.exe
c:\windows\system32\mlJCRKeE.dll
c:\windows\system32\secupdat.dat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Bret\fpxlnac.exe
c:\documents and settings\Bret\vhc.exe
c:\documents and settings\Karen\jobq.dat
c:\program files\Microsoft Common
c:\program files\Microsoft Common\svchost.exe
c:\windows\lfzfweiu.exe
c:\windows\nttakbit.exe
c:\windows\services.exe
c:\windows\system32\3.tmp
c:\windows\system32\5.tmp
c:\windows\system32\actcontroller.exe
c:\windows\system32\drivers\crxysodg.sys
c:\windows\system32\drivers\miegjyix.sys
c:\windows\system32\drivers\ndisio.sys
c:\windows\system32\drivers\ojwgrhlr.sys
c:\windows\system32\F5.tmp
c:\windows\system32\gcc.exe
c:\windows\system32\iehelper.dll
c:\windows\system32\mlJCRKeE.dll
c:\windows\system32\rah3b8ffdnd.dll
c:\windows\system32\secupdat.dat
c:\windows\system32\userinit.exe . . . is infected!!
c:\windows\system32\spoolsv.exe . . . is infected!!
c:\windows\explorer.exe . . . is infected!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_Passthru
((((((((((((((((((((((((( Files Created from 2009-01-06 to 2009-02-06 )))))))))))))))))))))))))))))))
.
2009-02-06 11:51 . 2009-02-06 11:51 137,856 –a—— c:\windows\system32\drivers\ethqiwkd.sys
2009-02-06 11:51 . 2009-02-06 11:51 137,856 –a—— c:\windows\system32\drivers\ethequsx.sys
2009-02-05 20:12 . 2009-02-05 20:12 168 –a—— c:\windows\system32\4.tmp
2009-02-05 20:11 . 2009-02-05 20:11 46,080 –a—— c:\windows\system32\i386kd.exe
2009-02-05 20:11 . 2009-02-05 20:11 3,584 –a—— c:\windows\zzjuepim.exe
2009-02-05 20:11 . 2009-02-06 11:41 128 –a—— c:\windows\adobe.bat
2009-02-05 20:11 . 2009-02-05 20:11 0 –a—— c:\windows\_id.dat
2009-02-05 20:03 . 2009-02-05 20:03 168 –a—— c:\windows\system32\2.tmp
2009-02-05 19:25 . 2009-02-05 19:25 134,144 –a—— c:\windows\ecoyicubucamot.dll
2009-02-05 19:24 . 2009-02-05 20:11 136,992 –a—— c:\windows\system32\drivers\ethvzsog.sys
2009-02-05 19:24 . 2009-02-05 20:11 136,992 –a—— c:\windows\system32\drivers\ethvojit.sys
2009-02-05 19:24 . 2009-02-05 20:11 136,992 –a—— c:\windows\system32\drivers\ethmuine.sys
2009-02-05 19:23 . 2009-02-05 20:11 136,992 –a—— c:\windows\system32\drivers\ethzxigv.sys
2009-02-05 19:23 . 2009-02-05 20:11 136,992 –a—— c:\windows\system32\drivers\ethqtkqt.sys
2009-02-05 19:23 . 2009-02-05 20:11 136,992 –a—— c:\windows\system32\drivers\ethpdfnr.sys
2009-02-05 19:23 . 2009-02-05 20:11 136,992 –a—— c:\windows\system32\drivers\ethhyzyx.sys
2009-02-05 19:23 . 2009-02-05 20:11 136,992 –a—— c:\windows\system32\drivers\ethhjgbm.sys
2009-02-05 19:23 . 2009-02-05 20:11 136,992 –a—— c:\windows\system32\drivers\ethgmyly.sys
2009-02-05 19:23 . 2009-02-05 20:11 136,992 –a—— c:\windows\system32\drivers\ethdpozi.sys
2009-02-05 19:23 . 2009-02-05 20:11 136,992 –a—— c:\windows\system32\drivers\ethbzlan.sys
2009-02-05 19:23 . 2009-02-05 20:11 136,992 –a—— c:\windows\system32\drivers\ethbnhqa.sys
2009-02-05 19:21 . 2009-02-05 19:21 137,856 –a—— c:\windows\system32\drivers\vfwbldii.sys
2009-02-05 19:20 . 2009-02-05 19:20 137,856 –a—— c:\windows\system32\drivers\rwmrodfw.sys
2009-02-05 19:19 . 2009-02-05 19:19 137,856 –a—— c:\windows\system32\drivers\okwxfzld.sys
2009-02-05 19:18 . 2009-02-05 19:18 137,856 –a—— c:\windows\system32\drivers\junvyxwx.sys
2009-02-05 19:17 . 2009-02-05 19:17 137,856 –a—— c:\windows\system32\drivers\fuqajqjm.sys
2009-02-05 19:16 . 2009-02-05 19:16 137,856 –a—— c:\windows\system32\drivers\cgajerdn.sys
2009-02-05 19:16 . 2009-02-05 19:16 32,768 –ah—– c:\documents and settings\Bret\jkd.exe
2009-02-05 19:14 . 2009-02-05 19:14 398,340 –a—— c:\windows\sysguard.exe
2009-02-05 19:13 . 2009-02-05 19:16 163,716 –a—— c:\windows\system32\47.tmp
2009-02-05 19:13 . 2009-02-05 19:13 41,984 –a—— c:\windows\Snakefedahe.dll
2009-02-05 19:13 . 2009-02-05 19:13 168 –a—— c:\windows\system32\46.tmp
2009-02-05 14:01 . 2009-02-05 14:02 d——– c:\windows\ERUNT
2009-02-05 13:56 . 2009-02-05 14:18 d——– C:\SDFix
2009-02-05 08:54 . 2009-02-05 08:54 d——– C:\_OTListIt
2009-02-03 23:47 . 2009-02-05 12:14 d——– C:\HJT
2009-01-09 09:02 . 2009-01-09 09:03 d——– c:\documents and settings\All Users\Application Data\Juniper Networks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-06 03:11 136,992 —-a-w c:\windows\system32\drivers\ethyigge.sys
2009-02-06 03:11 136,992 —-a-w c:\windows\system32\drivers\ethqwfhd.sys
2009-02-06 02:21 137,856 —-a-w c:\windows\system32\drivers\vdhqpffb.sys
2009-02-06 02:20 137,856 —-a-w c:\windows\system32\drivers\rtgyqied.sys
2009-02-06 02:19 137,856 —-a-w c:\windows\system32\drivers\ohsaxaoh.sys
2009-02-06 02:18 137,856 —-a-w c:\windows\system32\drivers\jtoeajuw.sys
2009-02-06 02:17 137,856 —-a-w c:\windows\system32\drivers\ftsjcwpm.sys
2009-02-06 02:16 3,584 —-a-w c:\windows\fpthhlrm.exe
2009-02-05 18:55 90,112 —-a-w c:\windows\DUMP6c56.tmp
2009-02-05 16:02 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-02-05 03:31 90,112 —-a-w c:\windows\DUMP65ed.tmp
2009-02-05 01:00 90,112 —-a-w c:\windows\DUMP608e.tmp
2009-02-04 05:43 90,112 —-a-w c:\windows\DUMP5a16.tmp
2009-02-04 04:42 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-04 04:16 90,112 —-a-w c:\windows\DUMP8414.tmp
2009-01-31 16:31 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-31 16:31 107,272 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-01-18 19:36 ——— d—–w c:\program files\Common Files\Intuit
2009-01-09 16:05 ——— d—–w c:\documents and settings\Barron\Application Data\Juniper Networks
2009-01-08 22:00 ——— d—–w c:\documents and settings\Barron\Application Data\Apple Computer
2009-01-07 02:21 ——— d—–w c:\program files\Google
2008-12-27 08:13 ——— d—–w c:\program files\QuickTime
2008-12-27 08:07 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-27 08:07 ——— d—–w c:\program files\eMusic Download Manager
2008-12-21 22:29 ——— d—–w c:\program files\Bonjour
2008-12-21 22:28 ——— d—–w c:\program files\iTunes
2008-12-21 22:28 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-21 22:27 ——— d—–w c:\program files\iPod
2008-12-21 22:27 ——— d—–w c:\program files\Common Files\Apple
2008-12-17 19:59 ——— d—–w c:\documents and settings\Barron\Application Data\Tibia
2008-12-17 04:12 ——— d—–w c:\documents and settings\Bret\Application Data\Tibia
2008-12-16 03:47 ——— d—–w c:\documents and settings\Karen\Application Data\Tibia
2008-12-16 02:28 ——— d—–w c:\program files\Tibia
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
2007-06-06 16:10 110 —-a-w c:\documents and settings\All Users\Application Data\MostFunGameId.bin
2007-04-09 20:46 32 —-a-r c:\documents and settings\All Users\hash.dat
2007-11-09 22:10 30,288 —-a-w c:\program files\mozilla firefox\plugins\cgpcfg.dll
2007-11-09 22:10 79,440 —-a-w c:\program files\mozilla firefox\plugins\CgpCore.dll
2007-11-09 22:10 75,344 —-a-w c:\program files\mozilla firefox\plugins\confmgr.dll
2007-11-09 22:10 140,880 —-a-w c:\program files\mozilla firefox\plugins\ctxmui.dll
2007-11-09 22:10 42,576 —-a-w c:\program files\mozilla firefox\plugins\icafile.dll
2007-11-09 22:10 50,768 —-a-w c:\program files\mozilla firefox\plugins\icalogon.dll
2007-11-09 22:10 34,384 —-a-w c:\program files\mozilla firefox\plugins\logging.dll
2007-11-09 22:11 685,648 —-a-w c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2007-11-09 22:11 30,288 —-a-w c:\program files\mozilla firefox\plugins\TcpPServ.dll
.
——- Sigcheck ——-
2007-06-13 03:23 1050624 7875eb7fd202cd02ba8681389e69ebe5 c:\windows\explorer.exe
2007-06-13 04:26 1050624 22465e01808f9e8a5298f6e7bea5b91c c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-04 04:00 1049600 60615f381e0eb852a34939cf5abd2f86 c:\windows\$NtUninstallKB938828$\explorer.exe
2008-04-13 17:12 1051136 eb141f45e0b25358c4ea6b28cace6273 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
2007-06-13 03:23 1050624 6fdd173169483d0f3979a6518b189367 c:\windows\system32\dllcache\explorer.exe
2008-04-13 17:12 32768 065cef212f0621e845f7de84905bc8f6 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ctfmon.exe
2004-08-04 04:00 32768 9b8f5c51c5058cb6c137dd08405b59af c:\windows\system32\ctfmon.exe
2005-06-10 17:17 75264 b5e2f01a55c89adc8b861bde35de7d4a c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2008-04-13 17:12 75264 bfde361bc7c53505778e16df5201e308 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\spoolsv.exe
2005-06-10 16:53 75264 30bc53621c3f7acf331c48e8cf69b047 c:\windows\system32\spoolsv.exe
2008-04-13 17:12 43520 ddda8f6d02c591cb34f7ad74de6224ac c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
2004-08-04 04:00 41984 cc3acccb2c3c9a72e504a00ccb351db2 c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-02-05_15.46.55.32 )))))))))))))))))))))))))))))))))))))))))
.
- 2006-11-22 23:30:48 89,088 —-a-w c:\windows\system32\ATL71.DLL
+ 2006-11-01 19:48:02 89,088 —-a-w c:\windows\system32\ATL71.DLL
- 2006-11-22 23:30:58 757,760 —-a-w c:\windows\system32\bcm1xsup.dll
+ 2006-11-01 19:48:02 757,760 —-a-w c:\windows\system32\bcm1xsup.dll
- 2006-11-22 23:31:08 770,048 —-a-w c:\windows\system32\BCMLogon.dll
+ 2006-11-01 19:48:02 770,048 —-a-w c:\windows\system32\BCMLogon.dll
- 2006-11-22 23:32:32 69,632 —-a-w c:\windows\system32\bcmwlpkt.dll
+ 2006-11-01 19:48:10 69,632 —-a-w c:\windows\system32\bcmwlpkt.dll
- 2006-11-22 23:32:58 1,273,856 —-a-w c:\windows\system32\BCMWLTRY.EXE
+ 2006-11-01 19:48:10 1,273,856 —-a-w c:\windows\system32\BCMWLTRY.EXE
- 2006-11-22 23:33:06 274,432 —-a-w c:\windows\system32\bcmwlu00.exe
+ 2006-11-01 19:48:10 274,432 —-a-w c:\windows\system32\bcmwlu00.exe
- 2009-02-05 22:44:44 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-06 18:51:50 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-06 02:15:48 16,384 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT
- 2009-02-05 22:44:44 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-06 18:51:50 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-06 02:48:48 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009020520090206\index.dat
- 2009-02-05 22:44:44 49,152 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-06 18:51:50 49,152 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-06 02:16:28 137,856 —-a-w c:\windows\system32\drivers\adbkwvzx.sys
+ 2009-02-06 02:16:32 137,856 —-a-w c:\windows\system32\drivers\agyzvxmh.sys
+ 2009-02-06 02:16:34 137,856 —-a-w c:\windows\system32\drivers\ahmzkppr.sys
+ 2009-02-06 02:16:36 137,856 —-a-w c:\windows\system32\drivers\alcqazmk.sys
+ 2009-02-06 02:16:38 137,856 —-a-w c:\windows\system32\drivers\aqlztezp.sys
+ 2009-02-06 02:16:40 137,856 —-a-w c:\windows\system32\drivers\atpmjoyk.sys
+ 2009-02-06 02:16:42 137,856 —-a-w c:\windows\system32\drivers\awhsjsmg.sys
- 2006-11-22 23:34:36 604,928 —-a-w c:\windows\system32\drivers\BCMWL5.SYS
+ 2006-10-12 22:28:42 604,928 —-a-w c:\windows\system32\drivers\BCMWL5.SYS
- 2006-11-22 23:32:22 33,664 —-a-w c:\windows\system32\drivers\BCMWLNPF.SYS
+ 2006-11-01 19:48:10 33,664 —-a-w c:\windows\system32\drivers\BCMWLNPF.SYS
+ 2009-02-06 02:16:44 137,856 —-a-w c:\windows\system32\drivers\bfwxlkxq.sys
+ 2009-02-06 02:16:46 137,856 —-a-w c:\windows\system32\drivers\bhirqjsk.sys
+ 2009-02-06 02:16:48 137,856 —-a-w c:\windows\system32\drivers\bndpohvk.sys
+ 2009-02-06 02:16:50 137,856 —-a-w c:\windows\system32\drivers\bzmgnrua.sys
+ 2009-02-06 02:16:52 137,856 —-a-w c:\windows\system32\drivers\bzthitdx.sys
+ 2009-02-06 02:16:55 137,856 —-a-w c:\windows\system32\drivers\ccagpfak.sys
+ 2009-02-06 02:16:57 137,856 —-a-w c:\windows\system32\drivers\ceepgpls.sys
+ 2009-02-06 02:17:01 137,856 —-a-w c:\windows\system32\drivers\ckfymirf.sys
+ 2009-02-06 02:17:03 137,856 —-a-w c:\windows\system32\drivers\comazqkd.sys
+ 2009-02-06 02:17:05 137,856 —-a-w c:\windows\system32\drivers\cppugygq.sys
+ 2009-02-06 02:17:07 137,856 —-a-w c:\windows\system32\drivers\cquntych.sys
+ 2009-02-06 02:17:09 137,856 —-a-w c:\windows\system32\drivers\cxtzxbyw.sys
+ 2009-02-06 02:17:11 137,856 —-a-w c:\windows\system32\drivers\dcqoqzqk.sys
+ 2009-02-06 02:17:13 137,856 —-a-w c:\windows\system32\drivers\deqgwxjs.sys
+ 2009-02-06 02:17:15 137,856 —-a-w c:\windows\system32\drivers\diihfegw.sys
+ 2009-02-06 02:17:17 137,856 —-a-w c:\windows\system32\drivers\dlztawbb.sys
+ 2009-02-06 02:17:19 137,856 —-a-w c:\windows\system32\drivers\dofwwvrh.sys
+ 2009-02-06 02:17:21 137,856 —-a-w c:\windows\system32\drivers\dpircxuz.sys
+ 2009-02-06 02:17:23 137,856 —-a-w c:\windows\system32\drivers\dplpdibp.sys
+ 2009-02-06 02:17:25 137,856 —-a-w c:\windows\system32\drivers\dqgnyfne.sys
+ 2009-02-06 02:17:27 137,856 —-a-w c:\windows\system32\drivers\dzaygihl.sys
+ 2009-02-06 02:17:31 137,856 —-a-w c:\windows\system32\drivers\euketgec.sys
+ 2009-02-06 02:17:33 137,856 —-a-w c:\windows\system32\drivers\exbosxxc.sys
+ 2009-02-06 02:17:35 137,856 —-a-w c:\windows\system32\drivers\faitxavy.sys
+ 2009-02-06 02:17:37 137,856 —-a-w c:\windows\system32\drivers\fdihkvxe.sys
+ 2009-02-06 02:17:39 137,856 —-a-w c:\windows\system32\drivers\febzlklr.sys
+ 2009-02-06 02:17:42 137,856 —-a-w c:\windows\system32\drivers\fgvtayet.sys
+ 2009-02-06 02:17:44 137,856 —-a-w c:\windows\system32\drivers\fhpntvti.sys
+ 2009-02-06 02:17:46 137,856 —-a-w c:\windows\system32\drivers\fjhmalir.sys
+ 2009-02-06 02:17:48 137,856 —-a-w c:\windows\system32\drivers\fkaqmowk.sys
+ 2009-02-06 02:17:50 137,856 —-a-w c:\windows\system32\drivers\fnfohlsh.sys
+ 2009-02-06 02:17:52 137,856 —-a-w c:\windows\system32\drivers\ftizlanf.sys
+ 2009-02-06 02:17:54 137,856 —-a-w c:\windows\system32\drivers\ftpmieju.sys
+ 2009-02-06 02:18:00 137,856 —-a-w c:\windows\system32\drivers\fuuyfewv.sys
+ 2009-02-06 02:18:02 137,856 —-a-w c:\windows\system32\drivers\fvptrayk.sys
+ 2009-02-06 02:18:04 137,856 —-a-w c:\windows\system32\drivers\fyssvwph.sys
+ 2009-02-06 02:18:06 137,856 —-a-w c:\windows\system32\drivers\fzhbocbf.sys
+ 2009-02-06 02:18:08 137,856 —-a-w c:\windows\system32\drivers\gacjfhui.sys
+ 2009-02-06 02:18:10 137,856 —-a-w c:\windows\system32\drivers\gbvvnfea.sys
+ 2009-02-06 02:18:12 137,856 —-a-w c:\windows\system32\drivers\gktzahlx.sys
+ 2009-02-06 02:18:14 137,856 —-a-w c:\windows\system32\drivers\gqhxgjct.sys
+ 2009-02-06 02:18:16 137,856 —-a-w c:\windows\system32\drivers\gznoqfls.sys
+ 2009-02-06 02:18:18 137,856 —-a-w c:\windows\system32\drivers\gzrkxewd.sys
+ 2009-02-06 02:18:20 137,856 —-a-w c:\windows\system32\drivers\hsenitvc.sys
+ 2009-02-06 02:18:22 137,856 —-a-w c:\windows\system32\drivers\hsjvpafb.sys
+ 2009-02-06 02:18:24 137,856 —-a-w c:\windows\system32\drivers\hsqcilte.sys
+ 2009-02-06 02:18:26 137,856 —-a-w c:\windows\system32\drivers\hxcbcnay.sys
+ 2009-02-06 02:18:28 137,856 —-a-w c:\windows\system32\drivers\hzkmtgti.sys
+ 2009-02-06 02:18:30 137,856 —-a-w c:\windows\system32\drivers\iivqqfob.sys
+ 2009-02-06 02:18:32 137,856 —-a-w c:\windows\system32\drivers\ikywixiy.sys
+ 2009-02-06 02:18:34 137,856 —-a-w c:\windows\system32\drivers\inrvkgpo.sys
+ 2009-02-06 02:18:37 137,856 —-a-w c:\windows\system32\drivers\iqejlwdg.sys
+ 2009-02-06 02:18:39 137,856 —-a-w c:\windows\system32\drivers\iqgptswa.sys
+ 2009-02-06 02:18:41 137,856 —-a-w c:\windows\system32\drivers\iwrpxzgg.sys
+ 2009-02-06 02:18:43 137,856 —-a-w c:\windows\system32\drivers\jhosrlvn.sys
+ 2009-02-06 02:18:45 137,856 —-a-w c:\windows\system32\drivers\jiiuacwq.sys
+ 2009-02-06 02:18:47 137,856 —-a-w c:\windows\system32\drivers\jkqwlzgt.sys
+ 2009-02-06 02:18:49 137,856 —-a-w c:\windows\system32\drivers\jljhbqgk.sys
+ 2009-02-06 02:18:51 137,856 —-a-w c:\windows\system32\drivers\jmcfzuta.sys
+ 2009-02-06 02:18:53 137,856 —-a-w c:\windows\system32\drivers\jnjmxipc.sys
+ 2009-02-06 02:18:55 137,856 —-a-w c:\windows\system32\drivers\jtdpfsbk.sys
+ 2009-02-06 02:19:01 137,856 —-a-w c:\windows\system32\drivers\jxihztde.sys
+ 2009-02-06 02:19:03 137,856 —-a-w c:\windows\system32\drivers\kbuokmrp.sys
+ 2009-02-06 02:19:05 137,856 —-a-w c:\windows\system32\drivers\kbuvmejq.sys
+ 2009-02-06 02:19:07 137,856 —-a-w c:\windows\system32\drivers\kdgwecas.sys
+ 2009-02-06 02:19:09 137,856 —-a-w c:\windows\system32\drivers\kqwcjnrl.sys
+ 2009-02-06 02:19:11 137,856 —-a-w c:\windows\system32\drivers\krlynxqh.sys
+ 2009-02-06 02:19:13 137,856 —-a-w c:\windows\system32\drivers\kxiknqej.sys
+ 2009-02-06 02:19:15 137,856 —-a-w c:\windows\system32\drivers\lcahnbte.sys
+ 2009-02-06 02:19:17 137,856 —-a-w c:\windows\system32\drivers\lfnjvuqd.sys
+ 2009-02-06 02:19:19 137,856 —-a-w c:\windows\system32\drivers\lnxmzfgo.sys
+ 2009-02-06 02:19:21 137,856 —-a-w c:\windows\system32\drivers\lpbrguiz.sys
+ 2009-02-06 02:19:23 137,856 —-a-w c:\windows\system32\drivers\lqzedbnl.sys
+ 2009-02-06 02:19:25 137,856 —-a-w c:\windows\system32\drivers\mjlonwqm.sys
+ 2009-02-06 02:19:27 137,856 —-a-w c:\windows\system32\drivers\mkgjieic.sys
+ 2009-02-06 02:19:29 137,856 —-a-w c:\windows\system32\drivers\mlqpkcll.sys
+ 2009-02-06 02:19:31 137,856 —-a-w c:\windows\system32\drivers\mmhaaety.sys
+ 2009-02-06 02:19:34 137,856 —-a-w c:\windows\system32\drivers\mvquqacv.sys
+ 2009-02-06 02:19:36 137,856 —-a-w c:\windows\system32\drivers\mxyqsrew.sys
+ 2009-02-06 02:19:38 137,856 —-a-w c:\windows\system32\drivers\mzjledhd.sys
+ 2009-02-06 02:19:40 137,856 —-a-w c:\windows\system32\drivers\nbmvlzqh.sys
+ 2009-02-06 02:19:42 137,856 —-a-w c:\windows\system32\drivers\neqiiyvo.sys
+ 2009-02-06 02:19:44 137,856 —-a-w c:\windows\system32\drivers\ngandykz.sys
+ 2009-02-06 02:19:46 137,856 —-a-w c:\windows\system32\drivers\nnkltjrt.sys
+ 2009-02-06 02:19:48 137,856 —-a-w c:\windows\system32\drivers\nqhvuqgb.sys
+ 2009-02-06 02:19:50 137,856 —-a-w c:\windows\system32\drivers\nxmjrrob.sys
+ 2009-02-06 02:19:52 137,856 —-a-w c:\windows\system32\drivers\nxqvxzrq.sys
+ 2009-02-06 02:19:54 137,856 —-a-w c:\windows\system32\drivers\oeyrcqyw.sys
+ 2009-02-06 02:20:00 137,856 —-a-w c:\windows\system32\drivers\olsabzgp.sys
+ 2009-02-06 02:20:02 137,856 —-a-w c:\windows\system32\drivers\opsnzhgw.sys
+ 2009-02-06 02:20:04 137,856 —-a-w c:\windows\system32\drivers\ostrnyzx.sys
+ 2009-02-06 02:20:06 137,856 —-a-w c:\windows\system32\drivers\pdxvgtgc.sys
+ 2009-02-06 02:20:08 137,856 —-a-w c:\windows\system32\drivers\pehqmkrh.sys
+ 2009-02-06 02:20:10 137,856 —-a-w c:\windows\system32\drivers\pfjlatun.sys
+ 2009-02-06 02:20:12 137,856 —-a-w c:\windows\system32\drivers\pfrpnppv.sys
+ 2009-02-06 02:20:14 137,856 —-a-w c:\windows\system32\drivers\phsympze.sys
+ 2009-02-06 02:20:16 137,856 —-a-w c:\windows\system32\drivers\pioeoxci.sys
+ 2009-02-06 02:20:18 137,856 —-a-w c:\windows\system32\drivers\pkbwrhxl.sys
+ 2009-02-06 02:20:20 137,856 —-a-w c:\windows\system32\drivers\pkxfeeww.sys
+ 2009-02-06 02:20:23 137,856 —-a-w c:\windows\system32\drivers\plgdnhwy.sys
+ 2009-02-06 02:20:25 137,856 —-a-w c:\windows\system32\drivers\pxkcrmnw.sys
+ 2009-02-06 02:20:27 137,856 —-a-w c:\windows\system32\drivers\qctmjpjg.sys
+ 2009-02-06 02:20:29 137,856 —-a-w c:\windows\system32\drivers\qfxguylt.sys
+ 2009-02-06 02:20:31 137,856 —-a-w c:\windows\system32\drivers\qlsnxoir.sys
+ 2009-02-06 02:20:33 137,856 —-a-w c:\windows\system32\drivers\qpzaqdek.sys
+ 2009-02-06 02:20:35 137,856 —-a-w c:\windows\system32\drivers\quelmaeo.sys
+ 2009-02-06 02:20:37 137,856 —-a-w c:\windows\system32\drivers\qyvgszwe.sys
+ 2009-02-06 02:20:39 137,856 —-a-w c:\windows\system32\drivers\rcbfdixx.sys
+ 2009-02-06 02:20:41 137,856 —-a-w c:\windows\system32\drivers\rfnxliit.sys
+ 2009-02-06 02:20:43 137,856 —-a-w c:\windows\system32\drivers\rfoyzykx.sys
+ 2009-02-06 02:20:45 137,856 —-a-w c:\windows\system32\drivers\rfuqkent.sys
+ 2009-02-06 02:20:47 137,856 —-a-w c:\windows\system32\drivers\rfvxdlva.sys
+ 2009-02-06 02:20:49 137,856 —-a-w c:\windows\system32\drivers\ropjxhty.sys
+ 2009-02-06 02:20:51 137,856 —-a-w c:\windows\system32\drivers\rpwwwkju.sys
+ 2009-02-06 02:20:53 137,856 —-a-w c:\windows\system32\drivers\rrtkqhqn.sys
+ 2009-02-06 02:20:55 137,856 —-a-w c:\windows\system32\drivers\rshjgnsc.sys
+ 2009-02-06 02:21:01 137,856 —-a-w c:\windows\system32\drivers\rxipgeya.sys
+ 2009-02-06 02:21:04 137,856 —-a-w c:\windows\system32\drivers\rylzihqo.sys
+ 2009-02-06 02:21:06 137,856 —-a-w c:\windows\system32\drivers\rzajfdty.sys
+ 2009-02-06 02:21:08 137,856 —-a-w c:\windows\system32\drivers\sbuqifos.sys
+ 2009-02-06 02:21:10 137,856 —-a-w c:\windows\system32\drivers\sgogdmms.sys
+ 2009-02-06 02:21:12 137,856 —-a-w c:\windows\system32\drivers\shcvsnmd.sys
+ 2009-02-06 02:21:14 137,856 —-a-w c:\windows\system32\drivers\shutcxbx.sys
+ 2009-02-06 02:21:16 137,856 —-a-w c:\windows\system32\drivers\sitarzwa.sys
+ 2009-02-06 02:21:18 137,856 —-a-w c:\windows\system32\drivers\sjuveiah.sys
+ 2009-02-06 02:21:20 137,856 —-a-w c:\windows\system32\drivers\sljjaafq.sys
+ 2009-02-06 02:21:22 137,856 —-a-w c:\windows\system32\drivers\sltyysxp.sys
+ 2009-02-06 02:21:24 137,856 —-a-w c:\windows\system32\drivers\svyxsynq.sys
+ 2009-02-06 02:21:26 137,856 —-a-w c:\windows\system32\drivers\swragxrb.sys
+ 2009-02-06 02:21:28 137,856 —-a-w c:\windows\system32\drivers\szwzksge.sys
+ 2009-02-06 02:21:30 137,856 —-a-w c:\windows\system32\drivers\tavtvdwb.sys
+ 2009-02-06 02:21:32 137,856 —-a-w c:\windows\system32\drivers\tdmtspva.sys
+ 2009-02-06 02:21:34 137,856 —-a-w c:\windows\system32\drivers\tiwyfltq.sys
+ 2009-02-06 02:21:36 137,856 —-a-w c:\windows\system32\drivers\tsdtagpg.sys
+ 2009-02-06 02:21:38 137,856 —-a-w c:\windows\system32\drivers\ubekgqmj.sys
+ 2009-02-06 02:21:40 137,856 —-a-w c:\windows\system32\drivers\udfajfgv.sys
+ 2009-02-06 02:21:42 137,856 —-a-w c:\windows\system32\drivers\udyhxfkh.sys
+ 2009-02-06 02:21:44 137,856 —-a-w c:\windows\system32\drivers\uffdnpvs.sys
+ 2009-02-06 02:21:46 137,856 —-a-w c:\windows\system32\drivers\uhfgbujf.sys
+ 2009-02-06 02:21:48 137,856 —-a-w c:\windows\system32\drivers\uiqdhgxk.sys
+ 2009-02-06 02:21:50 137,856 —-a-w c:\windows\system32\drivers\urpxhreo.sys
+ 2009-02-06 02:21:52 137,856 —-a-w c:\windows\system32\drivers\uwisbtmd.sys
+ 2009-02-06 02:21:54 137,856 —-a-w c:\windows\system32\drivers\uztucmji.sys
+ 2009-02-06 02:22:01 137,856 —-a-w c:\windows\system32\drivers\vgmzviic.sys
+ 2009-02-06 02:22:03 137,856 —-a-w c:\windows\system32\drivers\vihzenod.sys
+ 2009-02-06 02:22:05 137,856 —-a-w c:\windows\system32\drivers\vikvhapk.sys
+ 2009-02-06 02:22:07 137,856 —-a-w c:\windows\system32\drivers\wckauwdf.sys
+ 2009-02-06 02:22:09 137,856 —-a-w c:\windows\system32\drivers\wenpfpjl.sys
+ 2009-02-06 02:22:11 137,856 —-a-w c:\windows\system32\drivers\wgqjosrb.sys
+ 2009-02-06 02:22:13 137,856 —-a-w c:\windows\system32\drivers\wibvehix.sys
+ 2009-02-06 02:22:15 137,856 —-a-w c:\windows\system32\drivers\wlnkrcid.sys
+ 2009-02-06 02:22:17 137,856 —-a-w c:\windows\system32\drivers\wpsoxqah.sys
+ 2009-02-06 02:22:19 137,856 —-a-w c:\windows\system32\drivers\wptoksfa.sys
+ 2009-02-06 02:22:21 137,856 —-a-w c:\windows\system32\drivers\wuenpqxi.sys
+ 2009-02-06 02:22:23 137,856 —-a-w c:\windows\system32\drivers\wunyxsoh.sys
+ 2009-02-06 02:22:25 137,856 —-a-w c:\windows\system32\drivers\wvixnoju.sys
+ 2009-02-06 02:22:27 137,856 —-a-w c:\windows\system32\drivers\wvqyjvwd.sys
+ 2009-02-06 02:22:29 137,856 —-a-w c:\windows\system32\drivers\wvrsdazn.sys
+ 2009-02-06 02:22:31 137,856 —-a-w c:\windows\system32\drivers\xoyekbme.sys
+ 2009-02-06 02:22:33 137,856 —-a-w c:\windows\system32\drivers\xqsqtodw.sys
+ 2009-02-06 02:22:35 137,856 —-a-w c:\windows\system32\drivers\xsgvutjj.sys
+ 2009-02-06 02:22:37 137,856 —-a-w c:\windows\system32\drivers\ycgqdkpd.sys
+ 2009-02-06 02:22:40 137,856 —-a-w c:\windows\system32\drivers\ydvnkqgi.sys
+ 2009-02-06 02:22:42 137,856 —-a-w c:\windows\system32\drivers\yisegzxj.sys
+ 2009-02-06 02:22:44 137,856 —-a-w c:\windows\system32\drivers\yrwfyroh.sys
+ 2009-02-06 02:22:46 137,856 —-a-w c:\windows\system32\drivers\yttyathl.sys
+ 2009-02-06 02:22:48 137,856 —-a-w c:\windows\system32\drivers\zapkrcqf.sys
+ 2009-02-06 02:22:50 137,856 —-a-w c:\windows\system32\drivers\zfjdobyc.sys
+ 2009-02-06 02:22:52 137,856 —-a-w c:\windows\system32\drivers\ztsaafed.sys
- 2006-11-22 23:35:34 1,060,864 —-a-w c:\windows\system32\MFC71.DLL
+ 2006-11-01 19:48:12 1,060,864 —-a-w c:\windows\system32\MFC71.DLL
- 2006-11-22 23:35:44 499,712 —-a-w c:\windows\system32\MSVCP71.DLL
+ 2006-11-01 19:48:12 499,712 —-a-w c:\windows\system32\MSVCP71.DLL
- 2006-11-22 23:35:44 348,160 —-a-w c:\windows\system32\MSVCR71.DLL
+ 2006-11-01 19:48:12 348,160 —-a-w c:\windows\system32\MSVCR71.DLL
- 2009-02-05 21:14:50 64,602 —-a-w c:\windows\system32\perfc009.dat
+ 2009-02-06 18:45:39 64,602 —-a-w c:\windows\system32\perfc009.dat
- 2009-02-05 21:14:50 408,238 —-a-w c:\windows\system32\perfh009.dat
+ 2009-02-06 18:45:39 408,238 —-a-w c:\windows\system32\perfh009.dat
- 2006-11-22 23:35:44 86,016 —-a-w c:\windows\system32\preflib.dll
+ 2006-11-01 19:48:12 86,016 —-a-w c:\windows\system32\preflib.dll
- 2006-11-22 23:35:48 2,129,920 —-a-w c:\windows\system32\WLBCGCBPRO731.DLL
+ 2006-11-01 19:48:12 2,129,920 —-a-w c:\windows\system32\WLBCGCBPRO731.DLL
- 2006-11-22 23:35:50 1,413,120 —-a-w c:\windows\system32\WLTRAY.EXE
+ 2006-11-01 19:48:12 1,413,120 —-a-w c:\windows\system32\WLTRAY.EXE
- 2006-11-22 23:35:50 44,032 —-a-w c:\windows\system32\wltrynt.dll
+ 2006-11-01 19:48:12 44,032 —-a-w c:\windows\system32\wltrynt.dll
- 2006-11-22 23:35:50 37,888 —-a-w c:\windows\system32\WLTRYSVC.EXE
+ 2006-11-01 19:48:12 37,888 —-a-w c:\windows\system32\WLTRYSVC.EXE
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C9C42510-9B21-41c1-9DCD-8382A2D07C61}]
2009-02-06 11:52 9216 –a—— c:\windows\system32\iehelper.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 40961]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-08-28 413184]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1711616]
"sysguard"="c:\windows\sysguard.exe" [2009-02-05 398340]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-06 196608]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 98304]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 139264]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-01 1413120]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-06-29 1052672]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 69632]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 434176]
"Bciqipiq"="c:\windows\Snakefedahe.dll" [2009-02-05 41984]
"Ysocorerew"="c:\windows\ecoyicubucamot.dll" [2009-02-05 134144]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 c:\windows\stsystra.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"fpthhlrm.exe"="c:\windows\fpthhlrm.exe" [2009-02-05 3584]
"zzjuepim.exe"="c:\windows\zzjuepim.exe" [2009-02-05 3584]
"services"="c:\windows\services.exe" [BU]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-02-06 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\explorer.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-31 09:31 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Juniper Networks\\Secure Application Manager\\dsSamProxy.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"4000:TCP"= 4000:TCP:Blizzard
"6113:TCP"= 6113:TCP:Blizzard
"6112:TCP"= 6112:TCP:Blizzard
"6114:TCP"= 6114:TCP:Blizzard
"6115:TCP"= 6115:TCP:Blizzard
"6116:TCP"= 6116:TCP:Blizzard
"6117:TCP"= 6117:TCP:Blizzard
"6118:TCP"= 6118:TCP:Blizzard
"6119:TCP"= 6119:TCP:Blizzard
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-08-17 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-08-17 107272]
R1 NEOFLTR_550_11965;Juniper Networks TDI Filter Driver (NEOFLTR_550_11965);c:\windows\system32\drivers\NEOFLTR_550_11965.sys [2007-07-16 63008]
R1 NEOFLTR_620_13525;Juniper Networks TDI Filter Driver (NEOFLTR_620_13525);c:\windows\system32\drivers\NEOFLTR_620_13525.sys [2008-08-28 64480]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-08-17 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-17 298264]
S1 ethbnhqa;ethbnhqa;c:\windows\system32\drivers\ethbnhqa.sys [2009-02-05 136992]
S1 ethbzlan;ethbzlan;c:\windows\system32\drivers\ethbzlan.sys [2009-02-05 136992]
S1 ethdpozi;ethdpozi;c:\windows\system32\drivers\ethdpozi.sys [2009-02-05 136992]
S1 ethgmyly;ethgmyly;c:\windows\system32\drivers\ethgmyly.sys [2009-02-05 136992]
S1 ethhjgbm;ethhjgbm;c:\windows\system32\drivers\ethhjgbm.sys [2009-02-05 136992]
S1 ethhyzyx;ethhyzyx;c:\windows\system32\drivers\ethhyzyx.sys [2009-02-05 136992]
S1 ethmuine;ethmuine;c:\windows\system32\drivers\ethmuine.sys [2009-02-05 136992]
S1 ethpdfnr;ethpdfnr;c:\windows\system32\drivers\ethpdfnr.sys [2009-02-05 136992]
S1 ethqtkqt;ethqtkqt;c:\windows\system32\drivers\ethqtkqt.sys [2009-02-05 136992]
S1 ethqwfhd;ethqwfhd;c:\windows\system32\drivers\ethqwfhd.sys [2009-02-05 136992]
S1 ethvojit;ethvojit;c:\windows\system32\drivers\ethvojit.sys [2009-02-05 136992]
S1 ethvzsog;ethvzsog;c:\windows\system32\drivers\ethvzsog.sys [2009-02-05 136992]
S1 ethyigge;ethyigge;c:\windows\system32\drivers\ethyigge.sys [2009-02-05 136992]
S1 ethzxigv;ethzxigv;c:\windows\system32\drivers\ethzxigv.sys [2009-02-05 136992]
S3 adbkwvzx;adbkwvzx;c:\windows\system32\drivers\adbkwvzx.sys [2009-02-05 137856]
S3 agyzvxmh;agyzvxmh;c:\windows\system32\drivers\agyzvxmh.sys [2009-02-05 137856]
S3 ahmzkppr;ahmzkppr;c:\windows\system32\drivers\ahmzkppr.sys [2009-02-05 137856]
S3 alcqazmk;alcqazmk;c:\windows\system32\drivers\alcqazmk.sys [2009-02-05 137856]
S3 aqlztezp;aqlztezp;c:\windows\system32\drivers\aqlztezp.sys [2009-02-05 137856]
S3 atpmjoyk;atpmjoyk;c:\windows\system32\drivers\atpmjoyk.sys [2009-02-05 137856]
S3 awhsjsmg;awhsjsmg;c:\windows\system32\drivers\awhsjsmg.sys [2009-02-05 137856]
S3 bfwxlkxq;bfwxlkxq;c:\windows\system32\drivers\bfwxlkxq.sys [2009-02-05 137856]
S3 bhirqjsk;bhirqjsk;c:\windows\system32\drivers\bhirqjsk.sys [2009-02-05 137856]
S3 bndpohvk;bndpohvk;c:\windows\system32\drivers\bndpohvk.sys [2009-02-05 137856]
S3 bzmgnrua;bzmgnrua;c:\windows\system32\drivers\bzmgnrua.sys [2009-02-05 137856]
S3 bzthitdx;bzthitdx;c:\windows\system32\drivers\bzthitdx.sys [2009-02-05 137856]
S3 ccagpfak;ccagpfak;c:\windows\system32\drivers\ccagpfak.sys [2009-02-05 137856]
S3 ceepgpls;ceepgpls;c:\windows\system32\drivers\ceepgpls.sys [2009-02-05 137856]
S3 cgajerdn;cgajerdn;c:\windows\system32\drivers\cgajerdn.sys [2009-02-05 137856]
S3 ckfymirf;ckfymirf;c:\windows\system32\drivers\ckfymirf.sys [2009-02-05 137856]
S3 comazqkd;comazqkd;c:\windows\system32\drivers\comazqkd.sys [2009-02-05 137856]
S3 cppugygq;cppugygq;c:\windows\system32\drivers\cppugygq.sys [2009-02-05 137856]
S3 cquntych;cquntych;c:\windows\system32\drivers\cquntych.sys [2009-02-05 137856]
S3 crxysodg;crxysodg;\??\c:\windows\System32\Drivers\crxysodg.sys –> c:\windows\System32\Drivers\crxysodg.sys [?]
S3 cxtzxbyw;cxtzxbyw;c:\windows\system32\drivers\cxtzxbyw.sys [2009-02-05 137856]
S3 dcqoqzqk;dcqoqzqk;c:\windows\system32\drivers\dcqoqzqk.sys [2009-02-05 137856]
S3 deqgwxjs;deqgwxjs;c:\windows\system32\drivers\deqgwxjs.sys [2009-02-05 137856]
S3 diihfegw;diihfegw;c:\windows\system32\drivers\diihfegw.sys [2009-02-05 137856]
S3 dlztawbb;dlztawbb;c:\windows\system32\drivers\dlztawbb.sys [2009-02-05 137856]
S3 dofwwvrh;dofwwvrh;c:\windows\system32\drivers\dofwwvrh.sys [2009-02-05 137856]
S3 dpircxuz;dpircxuz;c:\windows\system32\drivers\dpircxuz.sys [2009-02-05 137856]
S3 dplpdibp;dplpdibp;c:\windows\system32\drivers\dplpdibp.sys [2009-02-05 137856]
S3 dqgnyfne;dqgnyfne;c:\windows\system32\drivers\dqgnyfne.sys [2009-02-05 137856]
S3 dzaygihl;dzaygihl;c:\windows\system32\drivers\dzaygihl.sys [2009-02-05 137856]
S3 euketgec;euketgec;c:\windows\system32\drivers\euketgec.sys [2009-02-05 137856]
S3 exbosxxc;exbosxxc;c:\windows\system32\drivers\exbosxxc.sys [2009-02-05 137856]
S3 faitxavy;faitxavy;c:\windows\system32\drivers\faitxavy.sys [2009-02-05 137856]
S3 fdihkvxe;fdihkvxe;c:\windows\system32\drivers\fdihkvxe.sys [2009-02-05 137856]
S3 febzlklr;febzlklr;c:\windows\system32\drivers\febzlklr.sys [2009-02-05 137856]
S3 fgvtayet;fgvtayet;c:\windows\system32\drivers\fgvtayet.sys [2009-02-05 137856]
S3 fhpntvti;fhpntvti;c:\windows\system32\drivers\fhpntvti.sys [2009-02-05 137856]
S3 fjhmalir;fjhmalir;c:\windows\system32\drivers\fjhmalir.sys [2009-02-05 137856]
S3 fkaqmowk;fkaqmowk;c:\windows\system32\drivers\fkaqmowk.sys [2009-02-05 137856]
S3 fnfohlsh;fnfohlsh;c:\windows\system32\drivers\fnfohlsh.sys [2009-02-05 137856]
S3 ftizlanf;ftizlanf;c:\windows\system32\drivers\ftizlanf.sys [2009-02-05 137856]
S3 ftpmieju;ftpmieju;c:\windows\system32\drivers\ftpmieju.sys [2009-02-05 137856]
S3 ftsjcwpm;ftsjcwpm;c:\windows\system32\drivers\ftsjcwpm.sys [2009-02-05 137856]
S3 fuqajqjm;fuqajqjm;c:\windows\system32\drivers\fuqajqjm.sys [2009-02-05 137856]
S3 fuuyfewv;fuuyfewv;c:\windows\system32\drivers\fuuyfewv.sys [2009-02-05 137856]
S3 fvptrayk;fvptrayk;c:\windows\system32\drivers\fvptrayk.sys [2009-02-05 137856]
S3 fyssvwph;fyssvwph;c:\windows\system32\drivers\fyssvwph.sys [2009-02-05 137856]
S3 fzhbocbf;fzhbocbf;c:\windows\system32\drivers\fzhbocbf.sys [2009-02-05 137856]
S3 gacjfhui;gacjfhui;c:\windows\system32\drivers\gacjfhui.sys [2009-02-05 137856]
S3 gbvvnfea;gbvvnfea;c:\windows\system32\drivers\gbvvnfea.sys [2009-02-05 137856]
S3 gktzahlx;gktzahlx;c:\windows\system32\drivers\gktzahlx.sys [2009-02-05 137856]
S3 gqhxgjct;gqhxgjct;c:\windows\system32\drivers\gqhxgjct.sys [2009-02-05 137856]
S3 gznoqfls;gznoqfls;c:\windows\system32\drivers\gznoqfls.sys [2009-02-05 137856]
S3 gzrkxewd;gzrkxewd;c:\windows\system32\drivers\gzrkxewd.sys [2009-02-05 137856]
S3 hsenitvc;hsenitvc;c:\windows\system32\drivers\hsenitvc.sys [2009-02-05 137856]
S3 hsjvpafb;hsjvpafb;c:\windows\system32\drivers\hsjvpafb.sys [2009-02-05 137856]
S3 hsqcilte;hsqcilte;c:\windows\system32\drivers\hsqcilte.sys [2009-02-05 137856]
S3 hxcbcnay;hxcbcnay;c:\windows\system32\drivers\hxcbcnay.sys [2009-02-05 137856]
S3 hzkmtgti;hzkmtgti;c:\windows\system32\drivers\hzkmtgti.sys [2009-02-05 137856]
S3 iivqqfob;iivqqfob;c:\windows\system32\drivers\iivqqfob.sys [2009-02-05 137856]
S3 ikywixiy;ikywixiy;c:\windows\system32\drivers\ikywixiy.sys [2009-02-05 137856]
S3 inrvkgpo;inrvkgpo;c:\windows\system32\drivers\inrvkgpo.sys [2009-02-05 137856]
S3 iqejlwdg;iqejlwdg;c:\windows\system32\drivers\iqejlwdg.sys [2009-02-05 137856]
S3 iqgptswa;iqgptswa;c:\windows\system32\drivers\iqgptswa.sys [2009-02-05 137856]
S3 iwrpxzgg;iwrpxzgg;c:\windows\system32\drivers\iwrpxzgg.sys [2009-02-05 137856]
S3 jhosrlvn;jhosrlvn;c:\windows\system32\drivers\jhosrlvn.sys [2009-02-05 137856]
S3 jiiuacwq;jiiuacwq;c:\windows\system32\drivers\jiiuacwq.sys [2009-02-05 137856]
S3 jkqwlzgt;jkqwlzgt;c:\windows\system32\drivers\jkqwlzgt.sys [2009-02-05 137856]
S3 jljhbqgk;jljhbqgk;c:\windows\system32\drivers\jljhbqgk.sys [2009-02-05 137856]
S3 jmcfzuta;jmcfzuta;c:\windows\system32\drivers\jmcfzuta.sys [2009-02-05 137856]
S3 jnjmxipc;jnjmxipc;c:\windows\system32\drivers\jnjmxipc.sys [2009-02-05 137856]
S3 jtdpfsbk;jtdpfsbk;c:\windows\system32\drivers\jtdpfsbk.sys [2009-02-05 137856]
S3 jtoeajuw;jtoeajuw;c:\windows\system32\drivers\jtoeajuw.sys [2009-02-05 137856]
S3 junvyxwx;junvyxwx;c:\windows\system32\drivers\junvyxwx.sys [2009-02-05 137856]
S3 jxihztde;jxihztde;c:\windows\system32\drivers\jxihztde.sys [2009-02-05 137856]
S3 kbuokmrp;kbuokmrp;c:\windows\system32\drivers\kbuokmrp.sys [2009-02-05 137856]
S3 kbuvmejq;kbuvmejq;c:\windows\system32\drivers\kbuvmejq.sys [2009-02-05 137856]
S3 kdgwecas;kdgwecas;c:\windows\system32\drivers\kdgwecas.sys [2009-02-05 137856]
S3 kqwcjnrl;kqwcjnrl;c:\windows\system32\drivers\kqwcjnrl.sys [2009-02-05 137856]
S3 krlynxqh;krlynxqh;c:\windows\system32\drivers\krlynxqh.sys [2009-02-05 137856]
S3 kxiknqej;kxiknqej;c:\windows\system32\drivers\kxiknqej.sys [2009-02-05 137856]
S3 lcahnbte;lcahnbte;c:\windows\system32\drivers\lcahnbte.sys [2009-02-05 137856]
S3 lfnjvuqd;lfnjvuqd;c:\windows\system32\drivers\lfnjvuqd.sys [2009-02-05 137856]
S3 lnxmzfgo;lnxmzfgo;c:\windows\system32\drivers\lnxmzfgo.sys [2009-02-05 137856]
S3 lpbrguiz;lpbrguiz;c:\windows\system32\drivers\lpbrguiz.sys [2009-02-05 137856]
S3 lqzedbnl;lqzedbnl;c:\windows\system32\drivers\lqzedbnl.sys [2009-02-05 137856]
S3 miegjyix;miegjyix;\??\c:\windows\System32\Drivers\miegjyix.sys –> c:\windows\System32\Drivers\miegjyix.sys [?]
S3 mjlonwqm;mjlonwqm;c:\windows\system32\drivers\mjlonwqm.sys [2009-02-05 137856]
S3 mkgjieic;mkgjieic;c:\windows\system32\drivers\mkgjieic.sys [2009-02-05 137856]
S3 mlqpkcll;mlqpkcll;c:\windows\system32\drivers\mlqpkcll.sys [2009-02-05 137856]
S3 mmhaaety;mmhaaety;c:\windows\system32\drivers\mmhaaety.sys [2009-02-05 137856]
S3 mvquqacv;mvquqacv;c:\windows\system32\drivers\mvquqacv.sys [2009-02-05 137856]
S3 mxyqsrew;mxyqsrew;c:\windows\system32\drivers\mxyqsrew.sys [2009-02-05 137856]
S3 mzjledhd;mzjledhd;c:\windows\system32\drivers\mzjledhd.sys [2009-02-05 137856]
S3 nbmvlzqh;nbmvlzqh;c:\windows\system32\drivers\nbmvlzqh.sys [2009-02-05 137856]
S3 neqiiyvo;neqiiyvo;c:\windows\system32\drivers\neqiiyvo.sys [2009-02-05 137856]
S3 ngandykz;ngandykz;c:\windows\system32\drivers\ngandykz.sys [2009-02-05 137856]
S3 nnkltjrt;nnkltjrt;c:\windows\system32\drivers\nnkltjrt.sys [2009-02-05 137856]
S3 nqhvuqgb;nqhvuqgb;c:\windows\system32\drivers\nqhvuqgb.sys [2009-02-05 137856]
S3 nxmjrrob;nxmjrrob;c:\windows\system32\drivers\nxmjrrob.sys [2009-02-05 137856]
S3 nxqvxzrq;nxqvxzrq;c:\windows\system32\drivers\nxqvxzrq.sys [2009-02-05 137856]
S3 oeyrcqyw;oeyrcqyw;c:\windows\system32\drivers\oeyrcqyw.sys [2009-02-05 137856]
S3 ohsaxaoh;ohsaxaoh;c:\windows\system32\drivers\ohsaxaoh.sys [2009-02-05 137856]
S3 ojwgrhlr;ojwgrhlr;\??\c:\windows\System32\Drivers\ojwgrhlr.sys –> c:\windows\System32\Drivers\ojwgrhlr.sys [?]
S3 okwxfzld;okwxfzld;c:\windows\system32\drivers\okwxfzld.sys [2009-02-05 137856]
S3 olsabzgp;olsabzgp;c:\windows\system32\drivers\olsabzgp.sys [2009-02-05 137856]
S3 opsnzhgw;opsnzhgw;c:\windows\system32\drivers\opsnzhgw.sys [2009-02-05 137856]
S3 ostrnyzx;ostrnyzx;c:\windows\system32\drivers\ostrnyzx.sys [2009-02-05 137856]
S3 pdxvgtgc;pdxvgtgc;c:\windows\system32\drivers\pdxvgtgc.sys [2009-02-05 137856]
S3 pehqmkrh;pehqmkrh;c:\windows\system32\drivers\pehqmkrh.sys [2009-02-05 137856]
S3 pfjlatun;pfjlatun;c:\windows\system32\drivers\pfjlatun.sys [2009-02-05 137856]
S3 pfrpnppv;pfrpnppv;c:\windows\system32\drivers\pfrpnppv.sys [2009-02-05 137856]
S3 phsympze;phsympze;c:\windows\system32\drivers\phsympze.sys [2009-02-05 137856]
S3 pioeoxci;pioeoxci;c:\windows\system32\drivers\pioeoxci.sys [2009-02-05 137856]
S3 pkbwrhxl;pkbwrhxl;c:\windows\system32\drivers\pkbwrhxl.sys [2009-02-05 137856]
S3 pkxfeeww;pkxfeeww;c:\windows\system32\drivers\pkxfeeww.sys [2009-02-05 137856]
S3 plgdnhwy;plgdnhwy;c:\windows\system32\drivers\plgdnhwy.sys [2009-02-05 137856]
S3 pxkcrmnw;pxkcrmnw;c:\windows\system32\drivers\pxkcrmnw.sys [2009-02-05 137856]
S3 qctmjpjg;qctmjpjg;c:\windows\system32\drivers\qctmjpjg.sys [2009-02-05 137856]
S3 qfxguylt;qfxguylt;c:\windows\system32\drivers\qfxguylt.sys [2009-02-05 137856]
S3 qlsnxoir;qlsnxoir;c:\windows\system32\drivers\qlsnxoir.sys [2009-02-05 137856]
S3 qpzaqdek;qpzaqdek;c:\windows\system32\drivers\qpzaqdek.sys [2009-02-05 137856]
S3 quelmaeo;quelmaeo;c:\windows\system32\drivers\quelmaeo.sys [2009-02-05 137856]
S3 qyvgszwe;qyvgszwe;c:\windows\system32\drivers\qyvgszwe.sys [2009-02-05 137856]
S3 rcbfdixx;rcbfdixx;c:\windows\system32\drivers\rcbfdixx.sys [2009-02-05 137856]
S3 rfnxliit;rfnxliit;c:\windows\system32\drivers\rfnxliit.sys [2009-02-05 137856]
S3 rfoyzykx;rfoyzykx;c:\windows\system32\drivers\rfoyzykx.sys [2009-02-05 137856]
S3 rfuqkent;rfuqkent;c:\windows\system32\drivers\rfuqkent.sys [2009-02-05 137856]
S3 rfvxdlva;rfvxdlva;c:\windows\system32\drivers\rfvxdlva.sys [2009-02-05 137856]
S3 ropjxhty;ropjxhty;c:\windows\system32\drivers\ropjxhty.sys [2009-02-05 137856]
S3 rpwwwkju;rpwwwkju;c:\windows\system32\drivers\rpwwwkju.sys [2009-02-05 137856]
S3 rrtkqhqn;rrtkqhqn;c:\windows\system32\drivers\rrtkqhqn.sys [2009-02-05 137856]
S3 rshjgnsc;rshjgnsc;c:\windows\system32\drivers\rshjgnsc.sys [2009-02-05 137856]
S3 rtgyqied;rtgyqied;c:\windows\system32\drivers\rtgyqied.sys [2009-02-05 137856]
S3 rwmrodfw;rwmrodfw;c:\windows\system32\drivers\rwmrodfw.sys [2009-02-05 137856]
S3 rxipgeya;rxipgeya;c:\windows\system32\drivers\rxipgeya.sys [2009-02-05 137856]
S3 rylzihqo;rylzihqo;c:\windows\system32\drivers\rylzihqo.sys [2009-02-05 137856]
S3 rzajfdty;rzajfdty;c:\windows\system32\drivers\rzajfdty.sys [2009-02-05 137856]
S3 sbuqifos;sbuqifos;c:\windows\system32\drivers\sbuqifos.sys [2009-02-05 137856]
S3 sgogdmms;sgogdmms;c:\windows\system32\drivers\sgogdmms.sys [2009-02-05 137856]
S3 shcvsnmd;shcvsnmd;c:\windows\system32\drivers\shcvsnmd.sys [2009-02-05 137856]
S3 shutcxbx;shutcxbx;c:\windows\system32\drivers\shutcxbx.sys [2009-02-05 137856]
S3 sitarzwa;sitarzwa;c:\windows\system32\drivers\sitarzwa.sys [2009-02-05 137856]
S3 sjuveiah;sjuveiah;c:\windows\system32\drivers\sjuveiah.sys [2009-02-05 137856]
S3 sljjaafq;sljjaafq;c:\windows\system32\drivers\sljjaafq.sys [2009-02-05 137856]
S3 sltyysxp;sltyysxp;c:\windows\system32\drivers\sltyysxp.sys [2009-02-05 137856]
S3 svyxsynq;svyxsynq;c:\windows\system32\drivers\svyxsynq.sys [2009-02-05 137856]
S3 swragxrb;swragxrb;c:\windows\system32\drivers\swragxrb.sys [2009-02-05 137856]
S3 szwzksge;szwzksge;c:\windows\system32\drivers\szwzksge.sys [2009-02-05 137856]
S3 tavtvdwb;tavtvdwb;c:\windows\system32\drivers\tavtvdwb.sys [2009-02-05 137856]
S3 tdmtspva;tdmtspva;c:\windows\system32\drivers\tdmtspva.sys [2009-02-05 137856]
S3 tiwyfltq;tiwyfltq;c:\windows\system32\drivers\tiwyfltq.sys [2009-02-05 137856]
S3 tsdtagpg;tsdtagpg;c:\windows\system32\drivers\tsdtagpg.sys [2009-02-05 137856]
S3 ubekgqmj;ubekgqmj;c:\windows\system32\drivers\ubekgqmj.sys [2009-02-05 137856]
S3 udfajfgv;udfajfgv;c:\windows\system32\drivers\udfajfgv.sys [2009-02-05 137856]
S3 udyhxfkh;udyhxfkh;c:\windows\system32\drivers\udyhxfkh.sys [2009-02-05 137856]
S3 uffdnpvs;uffdnpvs;c:\windows\system32\drivers\uffdnpvs.sys [2009-02-05 137856]
S3 uhfgbujf;uhfgbujf;c:\windows\system32\drivers\uhfgbujf.sys [2009-02-05 137856]
S3 uiqdhgxk;uiqdhgxk;c:\windows\system32\drivers\uiqdhgxk.sys [2009-02-05 137856]
S3 urpxhreo;urpxhreo;c:\windows\system32\drivers\urpxhreo.sys [2009-02-05 137856]
S3 uwisbtmd;uwisbtmd;c:\windows\system32\drivers\uwisbtmd.sys [2009-02-05 137856]
S3 uztucmji;uztucmji;c:\windows\system32\drivers\uztucmji.sys [2009-02-05 137856]
S3 vdhqpffb;vdhqpffb;c:\windows\system32\drivers\vdhqpffb.sys [2009-02-05 137856]
S3 vfwbldii;vfwbldii;c:\windows\system32\drivers\vfwbldii.sys [2009-02-05 137856]
S3 vgmzviic;vgmzviic;c:\windows\system32\drivers\vgmzviic.sys [2009-02-05 137856]
S3 vihzenod;vihzenod;c:\windows\system32\drivers\vihzenod.sys [2009-02-05 137856]
S3 vikvhapk;vikvhapk;c:\windows\system32\drivers\vikvhapk.sys [2009-02-05 137856]
S3 wckauwdf;wckauwdf;c:\windows\system32\drivers\wckauwdf.sys [2009-02-05 137856]
S3 wenpfpjl;wenpfpjl;c:\windows\system32\drivers\wenpfpjl.sys [2009-02-05 137856]
S3 wgqjosrb;wgqjosrb;c:\windows\system32\drivers\wgqjosrb.sys [2009-02-05 137856]
S3 wibvehix;wibvehix;c:\windows\system32\drivers\wibvehix.sys [2009-02-05 137856]
S3 wlnkrcid;wlnkrcid;c:\windows\system32\drivers\wlnkrcid.sys [2009-02-05 137856]
S3 wpsoxqah;wpsoxqah;c:\windows\system32\drivers\wpsoxqah.sys [2009-02-05 137856]
S3 wptoksfa;wptoksfa;c:\windows\system32\drivers\wptoksfa.sys [2009-02-05 137856]
S3 wuenpqxi;wuenpqxi;c:\windows\system32\drivers\wuenpqxi.sys [2009-02-05 137856]
S3 wunyxsoh;wunyxsoh;c:\windows\system32\drivers\wunyxsoh.sys [2009-02-05 137856]
S3 wvixnoju;wvixnoju;c:\windows\system32\drivers\wvixnoju.sys [2009-02-05 137856]
S3 wvqyjvwd;wvqyjvwd;c:\windows\system32\drivers\wvqyjvwd.sys [2009-02-05 137856]
S3 wvrsdazn;wvrsdazn;c:\windows\system32\drivers\wvrsdazn.sys [2009-02-05 137856]
S3 xoyekbme;xoyekbme;c:\windows\system32\drivers\xoyekbme.sys [2009-02-05 137856]
S3 xqsqtodw;xqsqtodw;c:\windows\system32\drivers\xqsqtodw.sys [2009-02-05 137856]
S3 xsgvutjj;xsgvutjj;c:\windows\system32\drivers\xsgvutjj.sys [2009-02-05 137856]
S3 ycgqdkpd;ycgqdkpd;c:\windows\system32\drivers\ycgqdkpd.sys [2009-02-05 137856]
S3 ydvnkqgi;ydvnkqgi;c:\windows\system32\drivers\ydvnkqgi.sys [2009-02-05 137856]
S3 yisegzxj;yisegzxj;c:\windows\system32\drivers\yisegzxj.sys [2009-02-05 137856]
S3 yrwfyroh;yrwfyroh;c:\windows\system32\drivers\yrwfyroh.sys [2009-02-05 137856]
S3 yttyathl;yttyathl;c:\windows\system32\drivers\yttyathl.sys [2009-02-05 137856]
S3 zapkrcqf;zapkrcqf;c:\windows\system32\drivers\zapkrcqf.sys [2009-02-05 137856]
S3 zfjdobyc;zfjdobyc;c:\windows\system32\drivers\zfjdobyc.sys [2009-02-05 137856]
S3 ztsaafed;ztsaafed;c:\windows\system32\drivers\ztsaafed.sys [2009-02-05 137856]
.
Contents of the 'Scheduled Tasks' folder
2009-01-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-lrijh8s73jhbfgfd - c:\windows\TEMP\winlognn.exe
HKU-Default-Run-nttakbit.exe - c:\windows\nttakbit.exe
HKU-Default-Run-lfzfweiu.exe - c:\windows\lfzfweiu.exe
HKLM-Explorer_Run-services - c:\windows\services.exe
HKU-Default-Explorer_Run-services - c:\windows\services.exe
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.dell.com
mSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\documents and settings\Bret\Application Data\Mozilla\Firefox\Profiles\5kyh3eaj.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPSFDMGR.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-06 11:52:13
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\windows\system32\iehelper.dll 9216 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(3720)
c:\program files\Juniper Networks\Secure Application Manager\samnsp.dll
c:\program files\Bonjour\mdnsNSP.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Juniper Networks\Common Files\dsNcService.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\rundll32.exe
c:\program files\Apoint\hidfind.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-02-06 11:54:53 - machine was rebooted [Bret]
ComboFix-quarantined-files.txt 2009-02-06 18:54:50
ComboFix2.txt 2009-02-05 22:47:41
Pre-Run: 21,302,853,632 bytes free
Post-Run: 21,287,579,648 bytes free
726 — E O F — 2009-01-15 09:04:13
Open notepad and copy/paste the text in the quotebox below into it:
http://forums.whatthetech.com/Virus_Spywar…15&start=15
Collect::
c:\windows\system32\drivers\ethqiwkd.sys
c:\windows\system32\drivers\ethequsx.sys
c:\windows\system32\4.tmp
c:\windows\system32\i386kd.exe
c:\windows\zzjuepim.exe
c:\windows\adobe.bat
c:\windows\_id.dat
c:\windows\system32\2.tmp
c:\windows\ecoyicubucamot.dll
c:\windows\system32\drivers\ethvzsog.sys
c:\windows\system32\drivers\ethvojit.sys
c:\windows\system32\drivers\ethmuine.sys
c:\windows\system32\drivers\ethzxigv.sys
c:\windows\system32\drivers\ethqtkqt.sys
c:\windows\system32\drivers\ethpdfnr.sys
c:\windows\system32\drivers\ethhyzyx.sys
c:\windows\system32\drivers\ethhjgbm.sys
c:\windows\system32\drivers\ethgmyly.sys
c:\windows\system32\drivers\ethdpozi.sys
c:\windows\system32\drivers\ethbzlan.sys
c:\windows\system32\drivers\ethbnhqa.sys
c:\windows\system32\drivers\vfwbldii.sys
c:\windows\system32\drivers\rwmrodfw.sys
c:\windows\system32\drivers\okwxfzld.sys
c:\windows\system32\drivers\junvyxwx.sys
c:\windows\system32\drivers\fuqajqjm.sys
c:\windows\system32\drivers\cgajerdn.sys
c:\documents and settings\Bret\jkd.exe
c:\windows\sysguard.exe
c:\windows\system32\47.tmp
c:\windows\Snakefedahe.dll
c:\windows\system32\46.tmp
c:\windows\system32\drivers\ethyigge.sys
c:\windows\system32\drivers\ethqwfhd.sys
c:\windows\system32\drivers\vdhqpffb.sys
c:\windows\system32\drivers\rtgyqied.sys
c:\windows\system32\drivers\ohsaxaoh.sys
c:\windows\system32\drivers\jtoeajuw.sys
c:\windows\system32\drivers\ftsjcwpm.sys
c:\windows\fpthhlrm.exe
Suspect::
Save this as CFScript.txt
[external image: Posted Image]
Refering to the picture above, drag CFScript.txt into ComboFix.exe
When finished, it shall produce a log for you. Post that log in your next reply.
**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
- Ensure you are connected to the internet and click OK on the message box.
ComboFix 09-02-05.01 - Bret 2009-02-06 13:01:04.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1014.573 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Bret\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Bret\jkd.exe
c:\windows\_id.dat
c:\windows\adobe.bat
c:\windows\ecoyicubucamot.dll
c:\windows\fpthhlrm.exe
c:\windows\Snakefedahe.dll
c:\windows\sysguard.exe
c:\windows\system32\2.tmp
c:\windows\system32\4.tmp
c:\windows\system32\46.tmp
c:\windows\system32\47.tmp
c:\windows\system32\drivers\cgajerdn.sys
c:\windows\system32\drivers\ethbnhqa.sys
c:\windows\system32\drivers\ethbzlan.sys
c:\windows\system32\drivers\ethdpozi.sys
c:\windows\system32\drivers\ethequsx.sys
c:\windows\system32\drivers\ethgmyly.sys
c:\windows\system32\drivers\ethhjgbm.sys
c:\windows\system32\drivers\ethhyzyx.sys
c:\windows\system32\drivers\ethmuine.sys
c:\windows\system32\drivers\ethpdfnr.sys
c:\windows\system32\drivers\ethqiwkd.sys
c:\windows\system32\drivers\ethqtkqt.sys
c:\windows\system32\drivers\ethqwfhd.sys
c:\windows\system32\drivers\ethvojit.sys
c:\windows\system32\drivers\ethvzsog.sys
c:\windows\system32\drivers\ethyigge.sys
c:\windows\system32\drivers\ethzxigv.sys
c:\windows\system32\drivers\ftsjcwpm.sys
c:\windows\system32\drivers\fuqajqjm.sys
c:\windows\system32\drivers\jtoeajuw.sys
c:\windows\system32\drivers\junvyxwx.sys
c:\windows\system32\drivers\ohsaxaoh.sys
c:\windows\system32\drivers\okwxfzld.sys
c:\windows\system32\drivers\rtgyqied.sys
c:\windows\system32\drivers\rwmrodfw.sys
c:\windows\system32\drivers\vdhqpffb.sys
c:\windows\system32\drivers\vfwbldii.sys
c:\windows\system32\i386kd.exe
c:\windows\system32\iehelper.dll
c:\windows\zzjuepim.exe
c:\windows\system32\userinit.exe . . . is infected!!
c:\windows\system32\spoolsv.exe . . . is infected!!
c:\windows\explorer.exe . . . is infected!!
.
((((((((((((((((((((((((( Files Created from 2009-01-06 to 2009-02-06 )))))))))))))))))))))))))))))))
.
2009-02-05 19:21 . 2009-02-05 19:21 137,856 –a—— c:\windows\system32\drivers\uztucmji.sys
2009-02-05 19:20 . 2009-02-05 19:20 137,856 –a—— c:\windows\system32\drivers\rshjgnsc.sys
2009-02-05 19:19 . 2009-02-05 19:19 137,856 –a—— c:\windows\system32\drivers\oeyrcqyw.sys
2009-02-05 19:18 . 2009-02-05 19:18 137,856 –a—— c:\windows\system32\drivers\jtdpfsbk.sys
2009-02-05 19:17 . 2009-02-05 19:17 137,856 –a—— c:\windows\system32\drivers\ftpmieju.sys
2009-02-05 19:16 . 2009-02-05 19:16 137,856 –a—— c:\windows\system32\drivers\ceepgpls.sys
2009-02-05 14:01 . 2009-02-05 14:02 d——– c:\windows\ERUNT
2009-02-05 13:56 . 2009-02-05 14:18 d——– C:\SDFix
2009-02-05 08:54 . 2009-02-05 08:54 d——– C:\_OTListIt
2009-02-03 23:47 . 2009-02-05 12:14 d——– C:\HJT
2009-01-09 09:02 . 2009-01-09 09:03 d——– c:\documents and settings\All Users\Application Data\Juniper Networks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-06 02:21 137,856 —-a-w c:\windows\system32\drivers\uwisbtmd.sys
2009-02-06 02:20 137,856 —-a-w c:\windows\system32\drivers\rrtkqhqn.sys
2009-02-06 02:19 137,856 —-a-w c:\windows\system32\drivers\nxqvxzrq.sys
2009-02-06 02:18 137,856 —-a-w c:\windows\system32\drivers\jnjmxipc.sys
2009-02-06 02:17 137,856 —-a-w c:\windows\system32\drivers\ftizlanf.sys
2009-02-06 02:16 137,856 —-a-w c:\windows\system32\drivers\ccagpfak.sys
2009-02-06 02:16 137,856 —-a-w c:\windows\system32\drivers\bzthitdx.sys
2009-02-06 02:16 137,856 —-a-w c:\windows\system32\drivers\bzmgnrua.sys
2009-02-06 02:16 137,856 —-a-w c:\windows\system32\drivers\bndpohvk.sys
2009-02-06 02:16 137,856 —-a-w c:\windows\system32\drivers\bhirqjsk.sys
2009-02-06 02:16 137,856 —-a-w c:\windows\system32\drivers\bfwxlkxq.sys
2009-02-06 02:16 137,856 —-a-w c:\windows\system32\drivers\awhsjsmg.sys
2009-02-06 02:16 137,856 —-a-w c:\windows\system32\drivers\atpmjoyk.sys
2009-02-06 02:16 137,856 —-a-w c:\windows\system32\drivers\aqlztezp.sys
2009-02-06 02:16 137,856 —-a-w c:\windows\system32\drivers\alcqazmk.sys
2009-02-06 02:16 137,856 —-a-w c:\windows\system32\drivers\ahmzkppr.sys
2009-02-06 02:16 137,856 —-a-w c:\windows\system32\drivers\agyzvxmh.sys
2009-02-06 02:16 137,856 —-a-w c:\windows\system32\drivers\adbkwvzx.sys
2009-02-05 18:55 90,112 —-a-w c:\windows\DUMP6c56.tmp
2009-02-05 16:02 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-02-05 03:31 90,112 —-a-w c:\windows\DUMP65ed.tmp
2009-02-05 01:00 90,112 —-a-w c:\windows\DUMP608e.tmp
2009-02-04 05:43 90,112 —-a-w c:\windows\DUMP5a16.tmp
2009-02-04 04:42 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-04 04:16 90,112 —-a-w c:\windows\DUMP8414.tmp
2009-01-31 16:31 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-31 16:31 107,272 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-01-18 19:36 ——— d—–w c:\program files\Common Files\Intuit
2009-01-09 16:05 ——— d—–w c:\documents and settings\Barron\Application Data\Juniper Networks
2009-01-08 22:00 ——— d—–w c:\documents and settings\Barron\Application Data\Apple Computer
2009-01-07 02:21 ——— d—–w c:\program files\Google
2008-12-27 08:13 ——— d—–w c:\program files\QuickTime
2008-12-27 08:07 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-27 08:07 ——— d—–w c:\program files\eMusic Download Manager
2008-12-21 22:29 ——— d—–w c:\program files\Bonjour
2008-12-21 22:28 ——— d—–w c:\program files\iTunes
2008-12-21 22:28 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-21 22:27 ——— d—–w c:\program files\iPod
2008-12-21 22:27 ——— d—–w c:\program files\Common Files\Apple
2008-12-17 19:59 ——— d—–w c:\documents and settings\Barron\Application Data\Tibia
2008-12-17 04:12 ——— d—–w c:\documents and settings\Bret\Application Data\Tibia
2008-12-16 03:47 ——— d—–w c:\documents and settings\Karen\Application Data\Tibia
2008-12-16 02:28 ——— d—–w c:\program files\Tibia
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
2007-06-06 16:10 110 —-a-w c:\documents and settings\All Users\Application Data\MostFunGameId.bin
2007-04-09 20:46 32 —-a-r c:\documents and settings\All Users\hash.dat
2007-11-09 22:10 30,288 —-a-w c:\program files\mozilla firefox\plugins\cgpcfg.dll
2007-11-09 22:10 79,440 —-a-w c:\program files\mozilla firefox\plugins\CgpCore.dll
2007-11-09 22:10 75,344 —-a-w c:\program files\mozilla firefox\plugins\confmgr.dll
2007-11-09 22:10 140,880 —-a-w c:\program files\mozilla firefox\plugins\ctxmui.dll
2007-11-09 22:10 42,576 —-a-w c:\program files\mozilla firefox\plugins\icafile.dll
2007-11-09 22:10 50,768 —-a-w c:\program files\mozilla firefox\plugins\icalogon.dll
2007-11-09 22:10 34,384 —-a-w c:\program files\mozilla firefox\plugins\logging.dll
2007-11-09 22:11 685,648 —-a-w c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2007-11-09 22:11 30,288 —-a-w c:\program files\mozilla firefox\plugins\TcpPServ.dll
.
——- Sigcheck ——-
2007-06-13 03:23 1050624 7875eb7fd202cd02ba8681389e69ebe5 c:\windows\explorer.exe
2007-06-13 04:26 1050624 22465e01808f9e8a5298f6e7bea5b91c c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-04 04:00 1049600 60615f381e0eb852a34939cf5abd2f86 c:\windows\$NtUninstallKB938828$\explorer.exe
2008-04-13 17:12 1051136 eb141f45e0b25358c4ea6b28cace6273 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
2007-06-13 03:23 1050624 6fdd173169483d0f3979a6518b189367 c:\windows\system32\dllcache\explorer.exe
2008-04-13 17:12 32768 065cef212f0621e845f7de84905bc8f6 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ctfmon.exe
2004-08-04 04:00 32768 9b8f5c51c5058cb6c137dd08405b59af c:\windows\system32\ctfmon.exe
2005-06-10 17:17 75264 b5e2f01a55c89adc8b861bde35de7d4a c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2008-04-13 17:12 75264 bfde361bc7c53505778e16df5201e308 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\spoolsv.exe
2005-06-10 16:53 75264 30bc53621c3f7acf331c48e8cf69b047 c:\windows\system32\spoolsv.exe
2008-04-13 17:12 43520 ddda8f6d02c591cb34f7ad74de6224ac c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
2004-08-04 04:00 41984 cc3acccb2c3c9a72e504a00ccb351db2 c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((( SnapShot_2009-02-06_11.54.04.90 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-06 18:51:50 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-06 20:04:51 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-06 18:51:50 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-06 20:04:51 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-02-06 18:51:50 49,152 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-06 20:04:51 49,152 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-02-06 18:45:39 64,602 —-a-w c:\windows\system32\perfc009.dat
+ 2009-02-06 18:56:11 64,602 —-a-w c:\windows\system32\perfc009.dat
- 2009-02-06 18:45:39 408,238 —-a-w c:\windows\system32\perfh009.dat
+ 2009-02-06 18:56:11 408,238 —-a-w c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 40961]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-08-28 413184]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1711616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-06 196608]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 98304]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 139264]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-01 1413120]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-06-29 1052672]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 69632]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 434176]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 c:\windows\stsystra.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"services"="c:\windows\services.exe" [BU]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-02-06 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\explorer.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-31 09:31 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Juniper Networks\\Secure Application Manager\\dsSamProxy.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"4000:TCP"= 4000:TCP:Blizzard
"6113:TCP"= 6113:TCP:Blizzard
"6112:TCP"= 6112:TCP:Blizzard
"6114:TCP"= 6114:TCP:Blizzard
"6115:TCP"= 6115:TCP:Blizzard
"6116:TCP"= 6116:TCP:Blizzard
"6117:TCP"= 6117:TCP:Blizzard
"6118:TCP"= 6118:TCP:Blizzard
"6119:TCP"= 6119:TCP:Blizzard
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-08-17 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-08-17 107272]
R1 NEOFLTR_550_11965;Juniper Networks TDI Filter Driver (NEOFLTR_550_11965);c:\windows\system32\drivers\NEOFLTR_550_11965.sys [2007-07-16 63008]
R1 NEOFLTR_620_13525;Juniper Networks TDI Filter Driver (NEOFLTR_620_13525);c:\windows\system32\drivers\NEOFLTR_620_13525.sys [2008-08-28 64480]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-08-17 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-17 298264]
S1 ethbnhqa;ethbnhqa;c:\windows\system32\drivers\ethbnhqa.sys –> c:\windows\system32\drivers\ethbnhqa.sys [?]
S1 ethbzlan;ethbzlan;c:\windows\system32\drivers\ethbzlan.sys –> c:\windows\system32\drivers\ethbzlan.sys [?]
S1 ethdpozi;ethdpozi;c:\windows\system32\drivers\ethdpozi.sys –> c:\windows\system32\drivers\ethdpozi.sys [?]
S1 ethequsx;ethequsx;c:\windows\system32\drivers\ethequsx.sys –> c:\windows\system32\drivers\ethequsx.sys [?]
S1 ethgmyly;ethgmyly;c:\windows\system32\drivers\ethgmyly.sys –> c:\windows\system32\drivers\ethgmyly.sys [?]
S1 ethhjgbm;ethhjgbm;c:\windows\system32\drivers\ethhjgbm.sys –> c:\windows\system32\drivers\ethhjgbm.sys [?]
S1 ethhyzyx;ethhyzyx;c:\windows\system32\drivers\ethhyzyx.sys –> c:\windows\system32\drivers\ethhyzyx.sys [?]
S1 ethmuine;ethmuine;c:\windows\system32\drivers\ethmuine.sys –> c:\windows\system32\drivers\ethmuine.sys [?]
S1 ethpdfnr;ethpdfnr;c:\windows\system32\drivers\ethpdfnr.sys –> c:\windows\system32\drivers\ethpdfnr.sys [?]
S1 ethqiwkd;ethqiwkd;c:\windows\system32\drivers\ethqiwkd.sys –> c:\windows\system32\drivers\ethqiwkd.sys [?]
S1 ethqtkqt;ethqtkqt;c:\windows\system32\drivers\ethqtkqt.sys –> c:\windows\system32\drivers\ethqtkqt.sys [?]
S1 ethqwfhd;ethqwfhd;c:\windows\system32\drivers\ethqwfhd.sys –> c:\windows\system32\drivers\ethqwfhd.sys [?]
S1 ethvojit;ethvojit;c:\windows\system32\drivers\ethvojit.sys –> c:\windows\system32\drivers\ethvojit.sys [?]
S1 ethvzsog;ethvzsog;c:\windows\system32\drivers\ethvzsog.sys –> c:\windows\system32\drivers\ethvzsog.sys [?]
S1 ethyigge;ethyigge;c:\windows\system32\drivers\ethyigge.sys –> c:\windows\system32\drivers\ethyigge.sys [?]
S1 ethzxigv;ethzxigv;c:\windows\system32\drivers\ethzxigv.sys –> c:\windows\system32\drivers\ethzxigv.sys [?]
S3 adbkwvzx;adbkwvzx;c:\windows\system32\drivers\adbkwvzx.sys [2009-02-05 137856]
S3 agyzvxmh;agyzvxmh;c:\windows\system32\drivers\agyzvxmh.sys [2009-02-05 137856]
S3 ahmzkppr;ahmzkppr;c:\windows\system32\drivers\ahmzkppr.sys [2009-02-05 137856]
S3 alcqazmk;alcqazmk;c:\windows\system32\drivers\alcqazmk.sys [2009-02-05 137856]
S3 aqlztezp;aqlztezp;c:\windows\system32\drivers\aqlztezp.sys [2009-02-05 137856]
S3 atpmjoyk;atpmjoyk;c:\windows\system32\drivers\atpmjoyk.sys [2009-02-05 137856]
S3 awhsjsmg;awhsjsmg;c:\windows\system32\drivers\awhsjsmg.sys [2009-02-05 137856]
S3 bfwxlkxq;bfwxlkxq;c:\windows\system32\drivers\bfwxlkxq.sys [2009-02-05 137856]
S3 bhirqjsk;bhirqjsk;c:\windows\system32\drivers\bhirqjsk.sys [2009-02-05 137856]
S3 bndpohvk;bndpohvk;c:\windows\system32\drivers\bndpohvk.sys [2009-02-05 137856]
S3 bzmgnrua;bzmgnrua;c:\windows\system32\drivers\bzmgnrua.sys [2009-02-05 137856]
S3 bzthitdx;bzthitdx;c:\windows\system32\drivers\bzthitdx.sys [2009-02-05 137856]
S3 ccagpfak;ccagpfak;c:\windows\system32\drivers\ccagpfak.sys [2009-02-05 137856]
S3 ceepgpls;ceepgpls;c:\windows\system32\drivers\ceepgpls.sys [2009-02-05 137856]
S3 cgajerdn;cgajerdn;\??\c:\windows\System32\Drivers\cgajerdn.sys –> c:\windows\System32\Drivers\cgajerdn.sys [?]
S3 ckfymirf;ckfymirf;c:\windows\system32\drivers\ckfymirf.sys [2009-02-05 137856]
S3 comazqkd;comazqkd;c:\windows\system32\drivers\comazqkd.sys [2009-02-05 137856]
S3 cppugygq;cppugygq;c:\windows\system32\drivers\cppugygq.sys [2009-02-05 137856]
S3 cquntych;cquntych;c:\windows\system32\drivers\cquntych.sys [2009-02-05 137856]
S3 crxysodg;crxysodg;\??\c:\windows\System32\Drivers\crxysodg.sys –> c:\windows\System32\Drivers\crxysodg.sys [?]
S3 cxtzxbyw;cxtzxbyw;c:\windows\system32\drivers\cxtzxbyw.sys [2009-02-05 137856]
S3 dcqoqzqk;dcqoqzqk;c:\windows\system32\drivers\dcqoqzqk.sys [2009-02-05 137856]
S3 deqgwxjs;deqgwxjs;c:\windows\system32\drivers\deqgwxjs.sys [2009-02-05 137856]
S3 diihfegw;diihfegw;c:\windows\system32\drivers\diihfegw.sys [2009-02-05 137856]
S3 dlztawbb;dlztawbb;c:\windows\system32\drivers\dlztawbb.sys [2009-02-05 137856]
S3 dofwwvrh;dofwwvrh;c:\windows\system32\drivers\dofwwvrh.sys [2009-02-05 137856]
S3 dpircxuz;dpircxuz;c:\windows\system32\drivers\dpircxuz.sys [2009-02-05 137856]
S3 dplpdibp;dplpdibp;c:\windows\system32\drivers\dplpdibp.sys [2009-02-05 137856]
S3 dqgnyfne;dqgnyfne;c:\windows\system32\drivers\dqgnyfne.sys [2009-02-05 137856]
S3 dzaygihl;dzaygihl;c:\windows\system32\drivers\dzaygihl.sys [2009-02-05 137856]
S3 euketgec;euketgec;c:\windows\system32\drivers\euketgec.sys [2009-02-05 137856]
S3 exbosxxc;exbosxxc;c:\windows\system32\drivers\exbosxxc.sys [2009-02-05 137856]
S3 faitxavy;faitxavy;c:\windows\system32\drivers\faitxavy.sys [2009-02-05 137856]
S3 fdihkvxe;fdihkvxe;c:\windows\system32\drivers\fdihkvxe.sys [2009-02-05 137856]
S3 febzlklr;febzlklr;c:\windows\system32\drivers\febzlklr.sys [2009-02-05 137856]
S3 fgvtayet;fgvtayet;c:\windows\system32\drivers\fgvtayet.sys [2009-02-05 137856]
S3 fhpntvti;fhpntvti;c:\windows\system32\drivers\fhpntvti.sys [2009-02-05 137856]
S3 fjhmalir;fjhmalir;c:\windows\system32\drivers\fjhmalir.sys [2009-02-05 137856]
S3 fkaqmowk;fkaqmowk;c:\windows\system32\drivers\fkaqmowk.sys [2009-02-05 137856]
S3 fnfohlsh;fnfohlsh;c:\windows\system32\drivers\fnfohlsh.sys [2009-02-05 137856]
S3 ftizlanf;ftizlanf;c:\windows\system32\drivers\ftizlanf.sys [2009-02-05 137856]
S3 ftpmieju;ftpmieju;c:\windows\system32\drivers\ftpmieju.sys [2009-02-05 137856]
S3 ftsjcwpm;ftsjcwpm;\??\c:\windows\System32\Drivers\ftsjcwpm.sys –> c:\windows\System32\Drivers\ftsjcwpm.sys [?]
S3 fuqajqjm;fuqajqjm;\??\c:\windows\System32\Drivers\fuqajqjm.sys –> c:\windows\System32\Drivers\fuqajqjm.sys [?]
S3 fuuyfewv;fuuyfewv;c:\windows\system32\drivers\fuuyfewv.sys [2009-02-05 137856]
S3 fvptrayk;fvptrayk;c:\windows\system32\drivers\fvptrayk.sys [2009-02-05 137856]
S3 fyssvwph;fyssvwph;c:\windows\system32\drivers\fyssvwph.sys [2009-02-05 137856]
S3 fzhbocbf;fzhbocbf;c:\windows\system32\drivers\fzhbocbf.sys [2009-02-05 137856]
S3 gacjfhui;gacjfhui;c:\windows\system32\drivers\gacjfhui.sys [2009-02-05 137856]
S3 gbvvnfea;gbvvnfea;c:\windows\system32\drivers\gbvvnfea.sys [2009-02-05 137856]
S3 gktzahlx;gktzahlx;c:\windows\system32\drivers\gktzahlx.sys [2009-02-05 137856]
S3 gqhxgjct;gqhxgjct;c:\windows\system32\drivers\gqhxgjct.sys [2009-02-05 137856]
S3 gznoqfls;gznoqfls;c:\windows\system32\drivers\gznoqfls.sys [2009-02-05 137856]
S3 gzrkxewd;gzrkxewd;c:\windows\system32\drivers\gzrkxewd.sys [2009-02-05 137856]
S3 hsenitvc;hsenitvc;c:\windows\system32\drivers\hsenitvc.sys [2009-02-05 137856]
S3 hsjvpafb;hsjvpafb;c:\windows\system32\drivers\hsjvpafb.sys [2009-02-05 137856]
S3 hsqcilte;hsqcilte;c:\windows\system32\drivers\hsqcilte.sys [2009-02-05 137856]
S3 hxcbcnay;hxcbcnay;c:\windows\system32\drivers\hxcbcnay.sys [2009-02-05 137856]
S3 hzkmtgti;hzkmtgti;c:\windows\system32\drivers\hzkmtgti.sys [2009-02-05 137856]
S3 iivqqfob;iivqqfob;c:\windows\system32\drivers\iivqqfob.sys [2009-02-05 137856]
S3 ikywixiy;ikywixiy;c:\windows\system32\drivers\ikywixiy.sys [2009-02-05 137856]
S3 inrvkgpo;inrvkgpo;c:\windows\system32\drivers\inrvkgpo.sys [2009-02-05 137856]
S3 iqejlwdg;iqejlwdg;c:\windows\system32\drivers\iqejlwdg.sys [2009-02-05 137856]
S3 iqgptswa;iqgptswa;c:\windows\system32\drivers\iqgptswa.sys [2009-02-05 137856]
S3 iwrpxzgg;iwrpxzgg;c:\windows\system32\drivers\iwrpxzgg.sys [2009-02-05 137856]
S3 jhosrlvn;jhosrlvn;c:\windows\system32\drivers\jhosrlvn.sys [2009-02-05 137856]
S3 jiiuacwq;jiiuacwq;c:\windows\system32\drivers\jiiuacwq.sys [2009-02-05 137856]
S3 jkqwlzgt;jkqwlzgt;c:\windows\system32\drivers\jkqwlzgt.sys [2009-02-05 137856]
S3 jljhbqgk;jljhbqgk;c:\windows\system32\drivers\jljhbqgk.sys [2009-02-05 137856]
S3 jmcfzuta;jmcfzuta;c:\windows\system32\drivers\jmcfzuta.sys [2009-02-05 137856]
S3 jnjmxipc;jnjmxipc;c:\windows\system32\drivers\jnjmxipc.sys [2009-02-05 137856]
S3 jtdpfsbk;jtdpfsbk;c:\windows\system32\drivers\jtdpfsbk.sys [2009-02-05 137856]
S3 jtoeajuw;jtoeajuw;\??\c:\windows\System32\Drivers\jtoeajuw.sys –> c:\windows\System32\Drivers\jtoeajuw.sys [?]
S3 junvyxwx;junvyxwx;\??\c:\windows\System32\Drivers\junvyxwx.sys –> c:\windows\System32\Drivers\junvyxwx.sys [?]
S3 jxihztde;jxihztde;c:\windows\system32\drivers\jxihztde.sys [2009-02-05 137856]
S3 kbuokmrp;kbuokmrp;c:\windows\system32\drivers\kbuokmrp.sys [2009-02-05 137856]
S3 kbuvmejq;kbuvmejq;c:\windows\system32\drivers\kbuvmejq.sys [2009-02-05 137856]
S3 kdgwecas;kdgwecas;c:\windows\system32\drivers\kdgwecas.sys [2009-02-05 137856]
S3 kqwcjnrl;kqwcjnrl;c:\windows\system32\drivers\kqwcjnrl.sys [2009-02-05 137856]
S3 krlynxqh;krlynxqh;c:\windows\system32\drivers\krlynxqh.sys [2009-02-05 137856]
S3 kxiknqej;kxiknqej;c:\windows\system32\drivers\kxiknqej.sys [2009-02-05 137856]
S3 lcahnbte;lcahnbte;c:\windows\system32\drivers\lcahnbte.sys [2009-02-05 137856]
S3 lfnjvuqd;lfnjvuqd;c:\windows\system32\drivers\lfnjvuqd.sys [2009-02-05 137856]
S3 lnxmzfgo;lnxmzfgo;c:\windows\system32\drivers\lnxmzfgo.sys [2009-02-05 137856]
S3 lpbrguiz;lpbrguiz;c:\windows\system32\drivers\lpbrguiz.sys [2009-02-05 137856]
S3 lqzedbnl;lqzedbnl;c:\windows\system32\drivers\lqzedbnl.sys [2009-02-05 137856]
S3 miegjyix;miegjyix;\??\c:\windows\System32\Drivers\miegjyix.sys –> c:\windows\System32\Drivers\miegjyix.sys [?]
S3 mjlonwqm;mjlonwqm;c:\windows\system32\drivers\mjlonwqm.sys [2009-02-05 137856]
S3 mkgjieic;mkgjieic;c:\windows\system32\drivers\mkgjieic.sys [2009-02-05 137856]
S3 mlqpkcll;mlqpkcll;c:\windows\system32\drivers\mlqpkcll.sys [2009-02-05 137856]
S3 mmhaaety;mmhaaety;c:\windows\system32\drivers\mmhaaety.sys [2009-02-05 137856]
S3 mvquqacv;mvquqacv;c:\windows\system32\drivers\mvquqacv.sys [2009-02-05 137856]
S3 mxyqsrew;mxyqsrew;c:\windows\system32\drivers\mxyqsrew.sys [2009-02-05 137856]
S3 mzjledhd;mzjledhd;c:\windows\system32\drivers\mzjledhd.sys [2009-02-05 137856]
S3 nbmvlzqh;nbmvlzqh;c:\windows\system32\drivers\nbmvlzqh.sys [2009-02-05 137856]
S3 neqiiyvo;neqiiyvo;c:\windows\system32\drivers\neqiiyvo.sys [2009-02-05 137856]
S3 ngandykz;ngandykz;c:\windows\system32\drivers\ngandykz.sys [2009-02-05 137856]
S3 nnkltjrt;nnkltjrt;c:\windows\system32\drivers\nnkltjrt.sys [2009-02-05 137856]
S3 nqhvuqgb;nqhvuqgb;c:\windows\system32\drivers\nqhvuqgb.sys [2009-02-05 137856]
S3 nxmjrrob;nxmjrrob;c:\windows\system32\drivers\nxmjrrob.sys [2009-02-05 137856]
S3 nxqvxzrq;nxqvxzrq;c:\windows\system32\drivers\nxqvxzrq.sys [2009-02-05 137856]
S3 oeyrcqyw;oeyrcqyw;c:\windows\system32\drivers\oeyrcqyw.sys [2009-02-05 137856]
S3 ohsaxaoh;ohsaxaoh;\??\c:\windows\System32\Drivers\ohsaxaoh.sys –> c:\windows\System32\Drivers\ohsaxaoh.sys [?]
S3 ojwgrhlr;ojwgrhlr;\??\c:\windows\System32\Drivers\ojwgrhlr.sys –> c:\windows\System32\Drivers\ojwgrhlr.sys [?]
S3 okwxfzld;okwxfzld;\??\c:\windows\System32\Drivers\okwxfzld.sys –> c:\windows\System32\Drivers\okwxfzld.sys [?]
S3 olsabzgp;olsabzgp;c:\windows\system32\drivers\olsabzgp.sys [2009-02-05 137856]
S3 opsnzhgw;opsnzhgw;c:\windows\system32\drivers\opsnzhgw.sys [2009-02-05 137856]
S3 ostrnyzx;ostrnyzx;c:\windows\system32\drivers\ostrnyzx.sys [2009-02-05 137856]
S3 pdxvgtgc;pdxvgtgc;c:\windows\system32\drivers\pdxvgtgc.sys [2009-02-05 137856]
S3 pehqmkrh;pehqmkrh;c:\windows\system32\drivers\pehqmkrh.sys [2009-02-05 137856]
S3 pfjlatun;pfjlatun;c:\windows\system32\drivers\pfjlatun.sys [2009-02-05 137856]
S3 pfrpnppv;pfrpnppv;c:\windows\system32\drivers\pfrpnppv.sys [2009-02-05 137856]
S3 phsympze;phsympze;c:\windows\system32\drivers\phsympze.sys [2009-02-05 137856]
S3 pioeoxci;pioeoxci;c:\windows\system32\drivers\pioeoxci.sys [2009-02-05 137856]
S3 pkbwrhxl;pkbwrhxl;c:\windows\system32\drivers\pkbwrhxl.sys [2009-02-05 137856]
S3 pkxfeeww;pkxfeeww;c:\windows\system32\drivers\pkxfeeww.sys [2009-02-05 137856]
S3 plgdnhwy;plgdnhwy;c:\windows\system32\drivers\plgdnhwy.sys [2009-02-05 137856]
S3 pxkcrmnw;pxkcrmnw;c:\windows\system32\drivers\pxkcrmnw.sys [2009-02-05 137856]
S3 qctmjpjg;qctmjpjg;c:\windows\system32\drivers\qctmjpjg.sys [2009-02-05 137856]
S3 qfxguylt;qfxguylt;c:\windows\system32\drivers\qfxguylt.sys [2009-02-05 137856]
S3 qlsnxoir;qlsnxoir;c:\windows\system32\drivers\qlsnxoir.sys [2009-02-05 137856]
S3 qpzaqdek;qpzaqdek;c:\windows\system32\drivers\qpzaqdek.sys [2009-02-05 137856]
S3 quelmaeo;quelmaeo;c:\windows\system32\drivers\quelmaeo.sys [2009-02-05 137856]
S3 qyvgszwe;qyvgszwe;c:\windows\system32\drivers\qyvgszwe.sys [2009-02-05 137856]
S3 rcbfdixx;rcbfdixx;c:\windows\system32\drivers\rcbfdixx.sys [2009-02-05 137856]
S3 rfnxliit;rfnxliit;c:\windows\system32\drivers\rfnxliit.sys [2009-02-05 137856]
S3 rfoyzykx;rfoyzykx;c:\windows\system32\drivers\rfoyzykx.sys [2009-02-05 137856]
S3 rfuqkent;rfuqkent;c:\windows\system32\drivers\rfuqkent.sys [2009-02-05 137856]
S3 rfvxdlva;rfvxdlva;c:\windows\system32\drivers\rfvxdlva.sys [2009-02-05 137856]
S3 ropjxhty;ropjxhty;c:\windows\system32\drivers\ropjxhty.sys [2009-02-05 137856]
S3 rpwwwkju;rpwwwkju;c:\windows\system32\drivers\rpwwwkju.sys [2009-02-05 137856]
S3 rrtkqhqn;rrtkqhqn;c:\windows\system32\drivers\rrtkqhqn.sys [2009-02-05 137856]
S3 rshjgnsc;rshjgnsc;c:\windows\system32\drivers\rshjgnsc.sys [2009-02-05 137856]
S3 rtgyqied;rtgyqied;\??\c:\windows\System32\Drivers\rtgyqied.sys –> c:\windows\System32\Drivers\rtgyqied.sys [?]
S3 rwmrodfw;rwmrodfw;\??\c:\windows\System32\Drivers\rwmrodfw.sys –> c:\windows\System32\Drivers\rwmrodfw.sys [?]
S3 rxipgeya;rxipgeya;c:\windows\system32\drivers\rxipgeya.sys [2009-02-05 137856]
S3 rylzihqo;rylzihqo;c:\windows\system32\drivers\rylzihqo.sys [2009-02-05 137856]
S3 rzajfdty;rzajfdty;c:\windows\system32\drivers\rzajfdty.sys [2009-02-05 137856]
S3 sbuqifos;sbuqifos;c:\windows\system32\drivers\sbuqifos.sys [2009-02-05 137856]
S3 sgogdmms;sgogdmms;c:\windows\system32\drivers\sgogdmms.sys [2009-02-05 137856]
S3 shcvsnmd;shcvsnmd;c:\windows\system32\drivers\shcvsnmd.sys [2009-02-05 137856]
S3 shutcxbx;shutcxbx;c:\windows\system32\drivers\shutcxbx.sys [2009-02-05 137856]
S3 sitarzwa;sitarzwa;c:\windows\system32\drivers\sitarzwa.sys [2009-02-05 137856]
S3 sjuveiah;sjuveiah;c:\windows\system32\drivers\sjuveiah.sys [2009-02-05 137856]
S3 sljjaafq;sljjaafq;c:\windows\system32\drivers\sljjaafq.sys [2009-02-05 137856]
S3 sltyysxp;sltyysxp;c:\windows\system32\drivers\sltyysxp.sys [2009-02-05 137856]
S3 svyxsynq;svyxsynq;c:\windows\system32\drivers\svyxsynq.sys [2009-02-05 137856]
S3 swragxrb;swragxrb;c:\windows\system32\drivers\swragxrb.sys [2009-02-05 137856]
S3 szwzksge;szwzksge;c:\windows\system32\drivers\szwzksge.sys [2009-02-05 137856]
S3 tavtvdwb;tavtvdwb;c:\windows\system32\drivers\tavtvdwb.sys [2009-02-05 137856]
S3 tdmtspva;tdmtspva;c:\windows\system32\drivers\tdmtspva.sys [2009-02-05 137856]
S3 tiwyfltq;tiwyfltq;c:\windows\system32\drivers\tiwyfltq.sys [2009-02-05 137856]
S3 tsdtagpg;tsdtagpg;c:\windows\system32\drivers\tsdtagpg.sys [2009-02-05 137856]
S3 ubekgqmj;ubekgqmj;c:\windows\system32\drivers\ubekgqmj.sys [2009-02-05 137856]
S3 udfajfgv;udfajfgv;c:\windows\system32\drivers\udfajfgv.sys [2009-02-05 137856]
S3 udyhxfkh;udyhxfkh;c:\windows\system32\drivers\udyhxfkh.sys [2009-02-05 137856]
S3 uffdnpvs;uffdnpvs;c:\windows\system32\drivers\uffdnpvs.sys [2009-02-05 137856]
S3 uhfgbujf;uhfgbujf;c:\windows\system32\drivers\uhfgbujf.sys [2009-02-05 137856]
S3 uiqdhgxk;uiqdhgxk;c:\windows\system32\drivers\uiqdhgxk.sys [2009-02-05 137856]
S3 urpxhreo;urpxhreo;c:\windows\system32\drivers\urpxhreo.sys [2009-02-05 137856]
S3 uwisbtmd;uwisbtmd;c:\windows\system32\drivers\uwisbtmd.sys [2009-02-05 137856]
S3 uztucmji;uztucmji;c:\windows\system32\drivers\uztucmji.sys [2009-02-05 137856]
S3 vdhqpffb;vdhqpffb;\??\c:\windows\System32\Drivers\vdhqpffb.sys –> c:\windows\System32\Drivers\vdhqpffb.sys [?]
S3 vfwbldii;vfwbldii;\??\c:\windows\System32\Drivers\vfwbldii.sys –> c:\windows\System32\Drivers\vfwbldii.sys [?]
S3 vgmzviic;vgmzviic;c:\windows\system32\drivers\vgmzviic.sys [2009-02-05 137856]
S3 vihzenod;vihzenod;c:\windows\system32\drivers\vihzenod.sys [2009-02-05 137856]
S3 vikvhapk;vikvhapk;c:\windows\system32\drivers\vikvhapk.sys [2009-02-05 137856]
S3 wckauwdf;wckauwdf;c:\windows\system32\drivers\wckauwdf.sys [2009-02-05 137856]
S3 wenpfpjl;wenpfpjl;c:\windows\system32\drivers\wenpfpjl.sys [2009-02-05 137856]
S3 wgqjosrb;wgqjosrb;c:\windows\system32\drivers\wgqjosrb.sys [2009-02-05 137856]
S3 wibvehix;wibvehix;c:\windows\system32\drivers\wibvehix.sys [2009-02-05 137856]
S3 wlnkrcid;wlnkrcid;c:\windows\system32\drivers\wlnkrcid.sys [2009-02-05 137856]
S3 wpsoxqah;wpsoxqah;c:\windows\system32\drivers\wpsoxqah.sys [2009-02-05 137856]
S3 wptoksfa;wptoksfa;c:\windows\system32\drivers\wptoksfa.sys [2009-02-05 137856]
S3 wuenpqxi;wuenpqxi;c:\windows\system32\drivers\wuenpqxi.sys [2009-02-05 137856]
S3 wunyxsoh;wunyxsoh;c:\windows\system32\drivers\wunyxsoh.sys [2009-02-05 137856]
S3 wvixnoju;wvixnoju;c:\windows\system32\drivers\wvixnoju.sys [2009-02-05 137856]
S3 wvqyjvwd;wvqyjvwd;c:\windows\system32\drivers\wvqyjvwd.sys [2009-02-05 137856]
S3 wvrsdazn;wvrsdazn;c:\windows\system32\drivers\wvrsdazn.sys [2009-02-05 137856]
S3 xoyekbme;xoyekbme;c:\windows\system32\drivers\xoyekbme.sys [2009-02-05 137856]
S3 xqsqtodw;xqsqtodw;c:\windows\system32\drivers\xqsqtodw.sys [2009-02-05 137856]
S3 xsgvutjj;xsgvutjj;c:\windows\system32\drivers\xsgvutjj.sys [2009-02-05 137856]
S3 ycgqdkpd;ycgqdkpd;c:\windows\system32\drivers\ycgqdkpd.sys [2009-02-05 137856]
S3 ydvnkqgi;ydvnkqgi;c:\windows\system32\drivers\ydvnkqgi.sys [2009-02-05 137856]
S3 yisegzxj;yisegzxj;c:\windows\system32\drivers\yisegzxj.sys [2009-02-05 137856]
S3 yrwfyroh;yrwfyroh;c:\windows\system32\drivers\yrwfyroh.sys [2009-02-05 137856]
S3 yttyathl;yttyathl;c:\windows\system32\drivers\yttyathl.sys [2009-02-05 137856]
S3 zapkrcqf;zapkrcqf;c:\windows\system32\drivers\zapkrcqf.sys [2009-02-05 137856]
S3 zfjdobyc;zfjdobyc;c:\windows\system32\drivers\zfjdobyc.sys [2009-02-05 137856]
S3 ztsaafed;ztsaafed;c:\windows\system32\drivers\ztsaafed.sys [2009-02-05 137856]
.
Contents of the 'Scheduled Tasks' folder
2009-01-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{C9C42510-9B21-41c1-9DCD-8382A2D07C61} - c:\windows\system32\iehelper.dll
HKCU-Run-sysguard - c:\windows\sysguard.exe
HKLM-Run-Bciqipiq - c:\windows\Snakefedahe.dll
HKLM-Run-Ysocorerew - c:\windows\ecoyicubucamot.dll
HKU-Default-Run-fpthhlrm.exe - c:\windows\fpthhlrm.exe
HKU-Default-Run-zzjuepim.exe - c:\windows\zzjuepim.exe
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.dell.com
mSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\documents and settings\Bret\Application Data\Mozilla\Firefox\Profiles\5kyh3eaj.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPSFDMGR.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-06 13:05:23
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(580)
c:\program files\Juniper Networks\Secure Application Manager\samnsp.dll
c:\program files\Bonjour\mdnsNSP.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Juniper Networks\Common Files\dsNcService.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\Apoint\hidfind.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-02-06 13:08:31 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-06 20:08:27
ComboFix2.txt 2009-02-06 18:54:54
ComboFix3.txt 2009-02-05 22:47:41
Pre-Run: 21,275,938,816 bytes free
Post-Run: 21,248,950,272 bytes free
496 — E O F — 2009-01-15 09:04:13
Download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.
- Open the OTScanIt2 folder and double-click on OTScanIt.exe to start the program. Make sure you close all other programs and don't use the PC while the scan runs.
- Under File Age at the top, change it from 30 days to 90 days
- Under Additional Scans check the boxes beside Reg - ActiveX StubPath, Reg - App Paths, Reg - ColumnHandlers, Reg - Desktop Components, Reg - Disabled MS Config Items, Reg - File Associations, Reg - ICQ Agent, Reg - NetSvcs, Reg - Print Monitors, Reg - Protocol Filters, Reg - Protocol Handlers, Reg - SafeBoot Minimal, Reg - SafeBoot Network, Reg - Session Manager Settings, Reg - Winsock2 Catalogs, File - Lop Check, File - Purity Scan, Files - Signature Check, and Evnt - EventViewer Logs ( Last 10 Errors).
- Under Rootkit Search change it to Yes
- Under the Custom Scans box at the bottom left paste the following in
%systemroot%\Prefetch\*.* /s
%systemroot%\system32\drivers\*.dat
%systemroot%\system32\*aef
%systemroot%\system32\drivers\*aef
%systemroot%\Temp\bca4e2da.$$$
%systemroot%\Temp\ed47fa.$
%systemroot%\Temp\fa56d7ec.$$$
%systemroot%\Temp\*.$$$
%systemroot%\System32\antiwpa.dll
%systemroot%\SYSTEM32\wpa.dll
%systemroot%\setup\scripts\biestart.exe
%System%\AcroIeHelpe.dll
%SYSTEMDRIVE%\*.epk
%systemroot%\*.epk
%systemroot%\system32\*.epk
%systemroot%\system32\bb*.dat
%systemroot%\system32\cookie*.dat
%systemroot%\system32\kaxs.dat
%systemroot%\system32\ps*.dat
%systemroot%\system32\*32.sys
%systemroot%\*.dr
%SYSTEMDRIVE%\*.dr
%systemroot%\system32\*.dr
%systemroot%\system32\nods32.dll
%systemroot%\*.res
%SYSTEMDRIVE%\*.res
%systemroot%\system32\*.res
%systemroot%\system32\sockins32.dll
%systemroot%\system32\Spool\*.*
%systemroot%\system32\Spool\*.exe
%systemroot%\system32\Spool\*.rar /s
%systemroot%\system32\Spool\*.zip /s
%systemroot%\system32\Spool\*.dat /s
%ProgramFiles%\MSN Messenger\*.zip
%ProgramFiles%\MSN Messenger\*.exe
%ProgramFiles%\MSN Messenger\*.rar.
%SYSTEMDRIVE%\*.zip
%SYSTEMDRIVE%\*.rar
%SYSTEMDRIVE%\*.exe
%SYSTEMDRIVE%\*.dll
%systemroot%\*.zip
%systemroot%\*.rar
%systemroot%\system32\*.zip
%systemroot%\system32\*.rar
%PROGRAMFILES%\*.*
%DESKTOP%\*.zip
%DESKTOP%\*.rar
%DESKTOP%\*.exe
%PROGRAMFILES%\Common Files\*.*
%PROGRAMFILES%\Common Files\*bak*.
%systemroot%\SYSTEM32\*bak*.
%PROGRAMFILES%\*bak*.
%systemroot%\ime\imjp8_1\*bak*.
%PROGRAMFILES%\QuickTime\*bak*.
%PROGRAMFILES%\Viewpoint\Viewpoint Manager\*bak*.
%PROGRAMFILES%\Analog Devices\Core\*bak*.
%SYSTEMDRIVE%\hp\KBD\*bak*.
%PROGRAMFILES%\Adobe\Photoshop Album Starter Edition\3.2\Apps\*bak*.
%PROGRAMFILES%\BillP Studios\WinPatrol\*bak*.
%PROGRAMFILES%\BroadJump\Client Foundation\*bak*.
%PROGRAMFILES%\Common Files\Real\Update_OB\*bak*.
%PROGRAMFILES%\Common Files\Sonic\Update Manager\*bak*.
%PROGRAMFILES%\\Google\GoogleToolbarNotifier\*bak*.
%PROGRAMFILES%\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\*bak*.
%PROGRAMFILES%\Yahoo!\Messenger\*bak*.
%USERNAME%\*.zip
%USERNAME%\*.rar
%USERNAME%\*.exe
%USERPROFILE%\*.zip
%USERPROFILE%\*.rar
%USERPROFILE%\*.exe
%ALLUSERSPROFILE%\*.zip
%ALLUSERSPROFILE%\*.rar
%ALLUSERSPROFILE%\*.exe
%APPDATA%\*.zip
%APPDATA%\*.rar
%APPDATA%\*.exe
%ALLUSERSSTARTMENU%\*.zip
%ALLUSERSSTARTMENU%\*.rar
%ALLUSERSSTARTMENU%\*.exe
%ALLUSERSSTARTUP%\*.zip
%ALLUSERSSTARTUP%\*.rar
%ALLUSERSSTARTUP%\*.exe
%ALLUSERSPROGRAMS%\*.zip
%ALLUSERSPROGRAMS%\*.rar
%ALLUSERSPROGRAMS%\*.exe
%ALLUSERSAPPDATA%\*.zip
%ALLUSERSAPPDATA%\*.rar
%ALLUSERSAPPDATA%\*.exe
%APPDATA%\*.zip
%APPDATA%\*.rar
%APPDATA%\*.exe
%APPDATA%\*.dat
%APPDATA%\*.dll
%QUICKLAUNCH%\*.zip
%QUICKLAUNCH%\*.rar
%QUICKLAUNCH%\*.exe
%STARTUP%\*.zip
%STARTUP%\*.rar
%STARTUP%\*.exe
%STARTMENU%\*.zip
%STARTMENU%\*.rar
%STARTMENU%\*.exe
%MYDOCUMENTS%\*.zip
%MYDOCUMENTS%\*.rar
%MYDOCUMENTS%\*.exe
%MYDOCUMENTS%\*crack*.
%MYDOCUMENTS%\*keygen*.
%PROGRAMFILES%\Mozilla Firefox\plugins\*.*
%PROGRAMFILES%\Internet Explorer\*.*
%PROGRAMFILES%\Internet Explorer\PLUGINS\*.*
%PROGRAMFILES%\Mozilla Firefox\*.zip /s
%PROGRAMFILES%\Mozilla Firefox\*.rar /s
%PROGRAMFILES%\Mozilla Firefox\*.exe /s
%PROGRAMFILES%\Internet Explorer\*.zip /s
%PROGRAMFILES%\Internet Explorer\*.rar /s
%PROGRAMFILES%\Internet Explorer\*.exe /s
%SYSTEMDRIVE%\*.dat
%SYSTEMDRIVE%\*.sys
%SYSTEMROOT%\*.dat
%SYSTEMROOT%\*.sys
%systemroot%\system32\drivers\*.exe /s
%systemroot%\system32\drivers\*.zip /s
%systemroot%\system32\drivers\*.rar /s
%systemroot%\system\*.exe /s
%systemroot%\system\*.zip /s
%systemroot%\system\*.rar /s
%systemroot%\AppPatch\*.exe /s
%systemroot%\AppPatch\*.zip /s
%systemroot%\AppPatch\*.rar /s
%systemroot%\Cache\*.*
%systemroot%\Downloaded Program Files\*.*
%systemroot%\Fonts\*.exe /s
%systemroot%\Fonts\*.zip /s
%systemroot%\Fonts\*.rar /s
%systemroot%\Fonts\*.dll /s
%systemroot%\Help\*.exe /s
%systemroot%\Help\*.zip /s
%systemroot%\Help\*.rar /s
%systemroot%\Tasks\*.*
%APPDATA%\*.sys
%APPDATA%\Google\*.*
%systemroot%\system32\serauth1.dll
%systemroot%\system32\serauth2.dll
%systemroot%\system32\sysaudio.sys
%systemroot%\system32\wdmaud.sys
%systemroot%\system32\aeaudio.sys
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\serauth1.dll /rs
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\serauth2.dll /rs
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\sysaudio.sys /rs
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\aeaudio.sys /rs
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\wdmaud.sys /rs
%PROGRAMFILES%\*TinyProxy*.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla|extensions /rs
%systemroot%\system32\inf\*.exe /s
%systemroot%\system32\inf\*.zip /s
%systemroot%\system32\inf\*.rar /s
%systemroot%\system32\inf\*.dll /s
%APPDATA%\Opera\Opera\profile\widgets\*.*
%PROGRAMFILES%\Opera\program\plugins\*.* /s
%APPDATA%\Opera\Opera\profile\toolbar\*.* /s
%systemroot%\Web\*.exe /s
%systemroot%\Web\*.dat /s
%systemroot%\Web\*.dll /s
%systemroot%\Web\*.sys /s
%systemroot%\Web\*.zip /s
%systemroot%\Web\*.rar /s
%systemroot%\Wbem\*.exe /s
%systemroot%\Wbem\*.rar /s
%systemroot%\Wbem\*.zip /s
%systemroot%\Wbem\*.dll /s
%systemroot%\Wbem\*.sys /s
%systemroot%\Wbem\*.dat /s
%systemroot%\twain_32\*.exe
%systemroot%\twain_32\*.dat
%systemroot%\twain_32\*.dll
%systemroot%\twain_32\*.sys /s
%systemroot%\twain_32\*.zip /s
%systemroot%\twain_32\*.rar /s
%systemroot%\system\*.sys /s
%systemroot%\system\*.dat /s
%systemroot%\WinSxS\*.exe /s
%systemroot%\WinSxS\*.dat /s
%systemroot%\WinSxS\*.sys /s
%systemroot%\WinSxS\*.zip /s
%systemroot%\WinSxS\*.rar /s
%systemroot%\Sun\*.dll /s
%systemroot%\Sun\*.rar /s
%systemroot%\Sun\*.zip /s
%systemroot%\Sun\*.exe /s
%systemroot%\Sun\*.sys /s
%systemroot%\Sun\*.dat /s
%systemroot%\srchasst\*.rar /s
%systemroot%\srchasst\*.zip /s
%systemroot%\srchasst\*.exe /s
%systemroot%\srchasst\*.dat /s
%systemroot%\srchasst\*.sys /s
%systemroot%\Shellnew\*.rar /s
%systemroot%\Shellnew\*.zip /s
%systemroot%\Shellnew\*.dat /s
%systemroot%\Shellnew\*.exe /s
%systemroot%\Shellnew\*.sys /s
%systemroot%\Shellnew\*.dll /s
%systemroot%\Security\*.rar /s
%systemroot%\Security\*.zip /s
%systemroot%\Security\*.dat /s
%systemroot%\Security\*.exe /s
%systemroot%\Security\*.sys /s
%systemroot%\Security\*.dll /s
%systemroot%\Resources\*.rar /s
%systemroot%\Resources\*.zip /s
%systemroot%\Resources\*.dat /s
%systemroot%\Resources\*.exe /s
%systemroot%\Resources\*.sys /s
%systemroot%\Repair\*.sys /s
%systemroot%\Repair\*.exe /s
%systemroot%\Repair\*.dll /s
%systemroot%\Repair\*.zip /s
%systemroot%\Repair\*.rar /s
%systemroot%\Registration\*.exe /s
%systemroot%\Registration\*.dat /s
%systemroot%\Registration\*.zip /s
%systemroot%\Registration\*.rar /s
%systemroot%\Registration\*.dll /s
%systemroot%\Registration\*.sys /s
%systemroot%\RegisteredPackages\*.rar /s
%systemroot%\RegisteredPackages\*.zip /s
%systemroot%\pss\*.rar /s
%systemroot%\pss\*.zip /s
%systemroot%\pss\*.exe /s
%systemroot%\pss\*.dll /s
%systemroot%\pss\*.dat /s
%systemroot%\pss\*.sys /s
%systemroot%\Provisioning\*.rar /s
%systemroot%\Provisioning\*.zip /s
%systemroot%\Provisioning\*.exe /s
%systemroot%\Provisioning\*.sys /s
%systemroot%\Provisioning\*.dat /s
%systemroot%\Provisioning\*.dll /s
%systemroot%\PIF\*.*
%systemroot%\PeerNet\*.rar /s
%systemroot%\PeerNet\*.zip /s
%systemroot%\PeerNet\*.dat /s
%systemroot%\PeerNet\*.sys /s
%systemroot%\PeerNet\*.exe /s
%systemroot%\PcTel\*.rar /s
%systemroot%\PcTel\*.zip /s
%systemroot%\Offline Web Pages\*.exe /s
%systemroot%\Offline Web Pages\*.zip /s
%systemroot%\Offline Web Pages\*.rar /s
%systemroot%\Offline Web Pages\*.sys /s
%systemroot%\Offline Web Pages\*.dat /s
%systemroot%\network diagnostic\*.sys /s
%systemroot%\network diagnostic\*.rar /s
%systemroot%\network diagnostic\*.zip /s
%systemroot%\network diagnostic\*.dat /s
%systemroot%\mui\*.*
%systemroot%\msapps\*.*
%systemroot%\msagent\*.zip /s
%systemroot%\msagent\*.rar /s
%systemroot%\msagent\*.sys /s
%systemroot%\msagent\*.dat /s
%systemroot%\minidump\*.*
%systemroot%\media\*.sys /s
%systemroot%\media\*.dat /s
%systemroot%\media\*.rar /s
%systemroot%\media\*.zip /s
%systemroot%\media\*.exe /s
%systemroot%\media\*.dll /s
%systemroot%\Help\*.sys /s
%systemroot%\Help\*.dat /s
%systemroot%\ie7\*.sys /s
%systemroot%\ie7\*.zip /s
%systemroot%\ie7\*.rar /s
%systemroot%\ie7\*.dat /s
%systemroot%\ie7updates\*.sys /s
%systemroot%\ie7updates\*.zip /s
%systemroot%\ie7updates\*.rar /s
%systemroot%\ime\*.sys /s
%systemroot%\ime\*.zip /s
%systemroot%\ime\*.rar /s
%systemroot%\inf\*.sys /s
%systemroot%\inf\*.dat /s
%systemroot%\installer\*.sys /s
%systemroot%\installer\*.zip /s
%systemroot%\installer\*.rar /s
%systemroot%\installer\*.dat /s
%systemroot%\internet logs\*.sys /s
%systemroot%\Cursors\*.rar /s
%systemroot%\Cursors\*.sys /s
%systemroot%\Cursors\*.exe /s
%systemroot%\Cursors\*.dat /s
%systemroot%\Cursors\*.zip /s
%systemroot%\Cursors\*.vbs /s
%systemroot%\Cursors\*.dll /s
%systemroot%\Config\*.*
%systemroot%\Config\*.rar /s
%systemroot%\Config\*.sys /s
%systemroot%\Config\*.exe /s
%systemroot%\Config\*.dat /s
%systemroot%\internet logs\*.dat /s
%systemroot%\Assembly\*sys /s
%systemroot%\Assembly\*.rar /s
%systemroot%\internet logs\*.rar /s
%systemroot%\AppPatch\*.sys
%systemroot%\AppPatch\*.dat
%systemroot%\internet logs\*.zip /s
%systemroot%\internet logs\*.exe /s
%systemroot%\internet logs\*.dll /s
%systemroot%\l2schemas\*.sys /s
%systemroot%\l2schemas\*.dat /s
%systemroot%\l2schemas\*.rar /s
%systemroot%\l2schemas\*.zip /s
%systemroot%\l2schemas\*.exe /s
%systemroot%\l2schemas\*.dll /s
%systemroot%\Fonts\*.dat /s
%systemroot%\Fonts\*.sys /s
%systemroot%\Debug\*.rar /s
%systemroot%\Debug\*.sys /s
%systemroot%\Debug\*.exe /s
%systemroot%\Debug\*.dat /s
%systemroot%\Debug\*.zip /s
%systemroot%\Debug\*.dll /s
%systemroot%\ehome\*.dll /s
%systemroot%\ehome\*.sys /s
%systemroot%\ehome\*.rar /s
%systemroot%\ehome\*.dat /s
%systemroot%\ehome\*.zip /s
%systemroot%\Connection Wizard\*.dat /s
%systemroot%\Connection Wizard\*.exe /s
%systemroot%\Connection Wizard\*.sys /s
%systemroot%\Connection Wizard\*.rar /s
%systemroot%\Connection Wizard\*.zip /s
%systemroot%\Connection Wizard\*.*
%systemroot%\system32\1025\*.*
%systemroot%\system32\1028\*.*
%systemroot%\system32\1031\*.*
%systemroot%\system32\1033\*.exe
%systemroot%\system32\1033\*.sys
%systemroot%\system32\1033\*.zip
%systemroot%\system32\1033\*.rar
%systemroot%\system32\1033\*.dat
%systemroot%\system32\1037\*.*
%systemroot%\system32\1041\*.*
%systemroot%\system32\1042\*.*
%systemroot%\system32\1054\*.*
%systemroot%\system32\2052\*.*
%systemroot%\system32\3076\*.*
%systemroot%\system32\appmgmt\*.exe /s
%systemroot%\system32\appmgmt\*.sys /s
%systemroot%\system32\appmgmt\*.dll /s
%systemroot%\system32\appmgmt\*.dat /s
%systemroot%\system32\appmgmt\*.zip /s
%systemroot%\system32\appmgmt\*.rar /s
%systemroot%\system32\bits\*.rar /s
%systemroot%\system32\bits\*.zip /s
%systemroot%\system32\bits\*.exe /s
%systemroot%\system32\bits\*.dat /s
%systemroot%\system32\bits\*.sys /s
%systemroot%\system32\catroot\*.rar /s
%systemroot%\system32\catroot\*.zip /s
%systemroot%\system32\catroot\*.dll /s
%systemroot%\system32\catroot\*.sys /s
%systemroot%\system32\catroot\*.exe /s
%systemroot%\system32\catroot\*.dat /s
%systemroot%\system32\catroot2\*.rar /s
%systemroot%\system32\catroot2\*.zip /s
%systemroot%\system32\catroot2\*.exe /s
%systemroot%\system32\catroot2\*.dat /s
%systemroot%\system32\catroot2\*.dll /s
%systemroot%\system32\catroot2\*.sys /s
%systemroot%\system32\com\*.sys /s
%systemroot%\system32\com\*.zip /s
%systemroot%\system32\com\*.rar /s
%systemroot%\system32\config\*.rar /s
%systemroot%\system32\config\*.zip /s
%systemroot%\system32\config\*.sys /s
%systemroot%\system32\config\*.dll /s
%systemroot%\system32\config\*.exe /s
%systemroot%\system32\dhcp\*.*
%systemroot%\system32\DirectX\*.rar /s
%systemroot%\system32\DirectX\*.zip /s
%systemroot%\system32\DirectX\*.sys /s
%systemroot%\system32\DirectX\*.dll /s
%systemroot%\system32\DirectX\*.exe /s
%systemroot%\system32\DirectX\*.dat /s
%systemroot%\system32\Dllcache\*.zip /s
%systemroot%\system32\Dllcache\*.rar /s
%systemroot%\system32\drivers\*.dat
%systemroot%\system32\drivers\*.exe /s
%systemroot%\system32\drivers\*.zip /s
%systemroot%\system32\drivers\*.rar /s
%systemroot%\system32\drvstore\*.dat
%systemroot%\system32\drvstore\*.exe /s
%systemroot%\system32\drvstore\*.zip /s
%systemroot%\system32\drvstore\*.rar /s
%systemroot%\system32\en\*.dat /s
%systemroot%\system32\en\*.exe /s
%systemroot%\system32\en\*.zip /s
%systemroot%\system32\en\*.rar /s
%systemroot%\system32\en\*.sys /s
%systemroot%\system32\en\*.sys /s
%systemroot%\system32\en\*.dat /s
%systemroot%\system32\en-us\*.exe /s
%systemroot%\system32\en-us\*.zip /s
%systemroot%\system32\en-us\*.rar /s
%systemroot%\system32\en-us\*.dll /s
%systemroot%\system32\export\*.*
%systemroot%\system32\GroupPolicy\*.sys /s
%systemroot%\system32\GroupPolicy\*.dat /s
%systemroot%\system32\GroupPolicy\*.exe /s
%systemroot%\system32\GroupPolicy\*.zip /s
%systemroot%\system32\GroupPolicy\*.rar /s
%systemroot%\system32\GroupPolicy\*.dll /s
%systemroot%\system32\ias\*.sys /s
%systemroot%\system32\ias\*.dat /s
%systemroot%\system32\ias\*.exe /s
%systemroot%\system32\ias\*.zip /s
%systemroot%\system32\ias\*.rar /s
%systemroot%\system32\ias\*.dll /s
%systemroot%\system32\icsxml\*.sys /s
%systemroot%\system32\icsxml\*.dat /s
%systemroot%\system32\icsxml\*.exe /s
%systemroot%\system32\icsxml\*.zip /s
%systemroot%\system32\icsxml\*.rar /s
%systemroot%\system32\icsxml\*.dll /s
%systemroot%\system32\ime\*.sys /s
%systemroot%\system32\ime\*.dat /s
%systemroot%\system32\ime\*.zip /s
%systemroot%\system32\ime\*.rar /s
%systemroot%\system32\inetsrv\*.sys /s
%systemroot%\system32\inetsrv\*.dat /s
%systemroot%\system32\inetsrv\*.exe /s
%systemroot%\system32\inetsrv\*.zip /s
%systemroot%\system32\inetsrv\*.rar /s
%systemroot%\system32\LogFiles\*.sys /s
%systemroot%\system32\LogFiles\*.dat /s
%systemroot%\system32\LogFiles\*.exe /s
%systemroot%\system32\LogFiles\*.zip /s
%systemroot%\system32\LogFiles\*.rar /s
%systemroot%\system32\LogFiles\*.dll /s
%systemroot%\system32\Macromed\*.sys /s
%systemroot%\system32\Macromed\*.dat /s
%systemroot%\system32\Macromed\*.zip /s
%systemroot%\system32\Macromed\*.rar /s
%systemroot%\system32\Microsoft\*.sys /s
%systemroot%\system32\Microsoft\*.dat /s
%systemroot%\system32\Microsoft\*.exe /s
%systemroot%\system32\Microsoft\*.zip /s
%systemroot%\system32\Microsoft\*.rar /s
%systemroot%\system32\Microsoft\*.dll /s
%systemroot%\system32\Msdtc\*.sys /s
%systemroot%\system32\Msdtc\*.dat /s
%systemroot%\system32\Msdtc\*.exe /s
%systemroot%\system32\Msdtc\*.zip /s
%systemroot%\system32\Msdtc\*.rar /s
%systemroot%\system32\Msdtc\*.dll /s
%systemroot%\system32\Mui\*.sys /s
%systemroot%\system32\Mui\*.dat /s
%systemroot%\system32\Mui\*.exe /s
%systemroot%\system32\Mui\*.zip /s
%systemroot%\system32\Mui\*.rar /s
%systemroot%\system32\npp\*.sys /s
%systemroot%\system32\npp\*.dat /s
%systemroot%\system32\npp\*.zip /s
%systemroot%\system32\npp\*.rar /s
%systemroot%\system32\NtMsData\*.sys /s
%systemroot%\system32\NtMsData\*.dat /s
%systemroot%\system32\NtMsData\*.exe /s
%systemroot%\system32\NtMsData\*.zip /s
%systemroot%\system32\NtMsData\*.rar /s
%systemroot%\system32\NtMsData\*.dll /s
%systemroot%\system32\oobe\*.sys /s
%systemroot%\system32\oobe\*.dat /s
%systemroot%\system32\oobe\*.zip /s
%systemroot%\system32\oobe\*.rar /s
%systemroot%\system32\PreInstall\*.sys /s
%systemroot%\system32\PreInstall\*.dat /s
%systemroot%\system32\PreInstall\*.exe /s
%systemroot%\system32\PreInstall\*.zip /s
%systemroot%\system32\PreInstall\*.rar /s
%systemroot%\system32\PreInstall\*.dll /s
%systemroot%\system32\ras\*.sys /s
%systemroot%\system32\ras\*.dat /s
%systemroot%\system32\ras\*.exe /s
%systemroot%\system32\ras\*.zip /s
%systemroot%\system32\ras\*.rar /s
%systemroot%\system32\ras\*.dll /s
%systemroot%\system32\ReInstallBackups\*.dat /s
%systemroot%\system32\ReInstallBackups\*.zip /s
%systemroot%\system32\ReInstallBackups\*.rar /s
%systemroot%\system32\Restore\*.sys /s
%systemroot%\system32\Restore\*.zip /s
%systemroot%\system32\Restore\*.rar /s
%systemroot%\system32\Restore\*.dll /s
%systemroot%\system32\Scripting\*.sys /s
%systemroot%\system32\Scripting\*.dat /s
%systemroot%\system32\Scripting\*.exe /s
%systemroot%\system32\Scripting\*.zip /s
%systemroot%\system32\Scripting\*.rar /s
%systemroot%\system32\Scripting\*.dll /s
%systemroot%\system32\Setup\*.sys /s
%systemroot%\system32\Setup\*.dat /s
%systemroot%\system32\Setup\*.exe /s
%systemroot%\system32\Setup\*.zip /s
%systemroot%\system32\Setup\*.rar /s
%systemroot%\system32\ShellExt\*.*
%systemroot%\system32\SoftwareDistribution\*.sys /s
%systemroot%\system32\SoftwareDistribution\*.dat /s
%systemroot%\system32\SoftwareDistribution\*.exe /s
%systemroot%\system32\SoftwareDistribution\*.zip /s
%systemroot%\system32\SoftwareDistribution\*.rar /s
%systemroot%\system32\URTTEmp\*.sys /s
%systemroot%\system32\URTTEmp\*.dat /s
%systemroot%\system32\URTTEmp\*.zip /s
%systemroot%\system32\URTTEmp\*.rar /s
%systemroot%\system32\USMT\*.sys /s
%systemroot%\system32\USMT\*.dat /s
%systemroot%\system32\USMT\*.zip /s
%systemroot%\system32\USMT\*.rar /s
%systemroot%\system32\Wbem\*.sys /s
%systemroot%\system32\Wbem\*.zip /s
%systemroot%\system32\Wbem\*.rar /s
%systemroot%\system32\Wins\*.*
%systemroot%\system32\Xircom\*.*
%systemroot%\system32\XPSViewer\*.sys /s
%systemroot%\system32\XPSViewer\*.dat /s
%systemroot%\system32\XPSViewer\*.zip /s
%systemroot%\system32\XPSViewer\*.rar /s
%systemroot%\system32\XPSViewer\*.dll /s
%COMMONPROGRAMFILES%\*.sys /s
%COMMONPROGRAMFILES%\*.zip /s
%COMMONPROGRAMFILES%\*.rar /s
%COMMONPROGRAMFILES%\*.*
%ProgramFiles%\Movie Maker\*.dll
%DriveLetter%\RECYCLER\*S-%d-%d-%d-%d%d%d-%d%d%d-%d%d%d-%d*.
%systemroot%\java\apps\*.*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
%systemroot%\winstart.bat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Runonce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunonceEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VxD
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System\Scripts|Startup /rs
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MPRServices
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Option
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Monitors
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AeDebug
%systemroot%\system32\basequu32.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BootVerificationProgram
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\ChkDskPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\cleanuppath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\DefragPath
- Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
- When the scan is complete Notepad will open with the report file loaded in it.
- Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Make sure you attach the report in your reply. If it is too big to upload, then zip the text file and upload it that way
Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
- Double-click GooredFix.exe to run it.
- Select 1. Find Goored (no fix) by typing 1 and pressing Enter.
- A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).
Start OTScanIt2. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.
[Kill Explorer]
[Unregister Dlls]
[Driver Services - Safe List]
YY -> (adbkwvzx) adbkwvzx [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\adbkwvzx.sys
YY -> (agyzvxmh) agyzvxmh [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\agyzvxmh.sys
YY -> (ahmzkppr) ahmzkppr [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ahmzkppr.sys
YY -> (alcqazmk) alcqazmk [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\alcqazmk.sys
YY -> (aqlztezp) aqlztezp [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\aqlztezp.sys
YY -> (atpmjoyk) atpmjoyk [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\atpmjoyk.sys
YY -> (awhsjsmg) awhsjsmg [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\awhsjsmg.sys
YY -> (bcm4sbxp) Broadcom 440x 10/100 Integrated Controller XP Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\bcm4sbxp.sys
YY -> (bfwxlkxq) bfwxlkxq [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\bfwxlkxq.sys
YY -> (bhirqjsk) bhirqjsk [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\bhirqjsk.sys
YY -> (bndpohvk) bndpohvk [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\bndpohvk.sys
YY -> (bzmgnrua) bzmgnrua [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\bzmgnrua.sys
YY -> (bzthitdx) bzthitdx [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\bzthitdx.sys
YY -> (ccagpfak) ccagpfak [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ccagpfak.sys
YY -> (ceepgpls) ceepgpls [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ceepgpls.sys
YY -> (ckfymirf) ckfymirf [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ckfymirf.sys
YY -> (comazqkd) comazqkd [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\comazqkd.sys
YY -> (cppugygq) cppugygq [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\cppugygq.sys
YY -> (cquntych) cquntych [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\cquntych.sys
YY -> (cxtzxbyw) cxtzxbyw [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\cxtzxbyw.sys
YY -> (dcqoqzqk) dcqoqzqk [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\dcqoqzqk.sys
YY -> (deqgwxjs) deqgwxjs [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\deqgwxjs.sys
YY -> (diihfegw) diihfegw [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\diihfegw.sys
YY -> (dlztawbb) dlztawbb [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\dlztawbb.sys
YY -> (dofwwvrh) dofwwvrh [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\dofwwvrh.sys
YY -> (dpircxuz) dpircxuz [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\dpircxuz.sys
YY -> (dplpdibp) dplpdibp [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\dplpdibp.sys
YY -> (dqgnyfne) dqgnyfne [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\dqgnyfne.sys
YY -> (dzaygihl) dzaygihl [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\dzaygihl.sys
YY -> (euketgec) euketgec [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\euketgec.sys
YY -> (exbosxxc) exbosxxc [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\exbosxxc.sys
YY -> (faitxavy) faitxavy [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\faitxavy.sys
YY -> (fdihkvxe) fdihkvxe [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\fdihkvxe.sys
YY -> (febzlklr) febzlklr [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\febzlklr.sys
YY -> (fgvtayet) fgvtayet [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\fgvtayet.sys
YY -> (fhpntvti) fhpntvti [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\fhpntvti.sys
YY -> (fjhmalir) fjhmalir [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\fjhmalir.sys
YY -> (fkaqmowk) fkaqmowk [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\fkaqmowk.sys
YY -> (fnfohlsh) fnfohlsh [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\fnfohlsh.sys
YY -> (ftizlanf) ftizlanf [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ftizlanf.sys
YY -> (ftpmieju) ftpmieju [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ftpmieju.sys
YY -> (fuuyfewv) fuuyfewv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\fuuyfewv.sys
YY -> (fvptrayk) fvptrayk [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\fvptrayk.sys
YY -> (fyssvwph) fyssvwph [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\fyssvwph.sys
YY -> (fzhbocbf) fzhbocbf [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\fzhbocbf.sys
YY -> (gacjfhui) gacjfhui [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\gacjfhui.sys
YY -> (gbvvnfea) gbvvnfea [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\gbvvnfea.sys
YY -> (gktzahlx) gktzahlx [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\gktzahlx.sys
YY -> (gqhxgjct) gqhxgjct [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\gqhxgjct.sys
YY -> (gznoqfls) gznoqfls [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\gznoqfls.sys
YY -> (gzrkxewd) gzrkxewd [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\gzrkxewd.sys
YY -> (hsenitvc) hsenitvc [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\hsenitvc.sys
YY -> (hsjvpafb) hsjvpafb [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\hsjvpafb.sys
YY -> (hsqcilte) hsqcilte [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\hsqcilte.sys
YY -> (hxcbcnay) hxcbcnay [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\hxcbcnay.sys
YY -> (hzkmtgti) hzkmtgti [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\hzkmtgti.sys
YY -> (iivqqfob) iivqqfob [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\iivqqfob.sys
YY -> (ikywixiy) ikywixiy [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ikywixiy.sys
YY -> (inrvkgpo) inrvkgpo [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\inrvkgpo.sys
YY -> (iqejlwdg) iqejlwdg [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\iqejlwdg.sys
YY -> (iqgptswa) iqgptswa [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\iqgptswa.sys
YY -> (iwrpxzgg) iwrpxzgg [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\iwrpxzgg.sys
YY -> (jhosrlvn) jhosrlvn [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\jhosrlvn.sys
YY -> (jiiuacwq) jiiuacwq [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\jiiuacwq.sys
YY -> (jkqwlzgt) jkqwlzgt [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\jkqwlzgt.sys
YY -> (jljhbqgk) jljhbqgk [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\jljhbqgk.sys
YY -> (jmcfzuta) jmcfzuta [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\jmcfzuta.sys
YY -> (jnjmxipc) jnjmxipc [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\jnjmxipc.sys
YY -> (jtdpfsbk) jtdpfsbk [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\jtdpfsbk.sys
YY -> (jxihztde) jxihztde [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\jxihztde.sys
YY -> (kbuokmrp) kbuokmrp [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\kbuokmrp.sys
YY -> (kbuvmejq) kbuvmejq [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\kbuvmejq.sys
YY -> (kdgwecas) kdgwecas [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\kdgwecas.sys
YY -> (kqwcjnrl) kqwcjnrl [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\kqwcjnrl.sys
YY -> (krlynxqh) krlynxqh [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\krlynxqh.sys
YY -> (kxiknqej) kxiknqej [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\kxiknqej.sys
YY -> (lcahnbte) lcahnbte [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\lcahnbte.sys
YY -> (lfnjvuqd) lfnjvuqd [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\lfnjvuqd.sys
YY -> (lnxmzfgo) lnxmzfgo [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\lnxmzfgo.sys
YY -> (lpbrguiz) lpbrguiz [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\lpbrguiz.sys
YY -> (lqzedbnl) lqzedbnl [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\lqzedbnl.sys
YY -> (mjlonwqm) mjlonwqm [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\mjlonwqm.sys
YY -> (mkgjieic) mkgjieic [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\mkgjieic.sys
YY -> (mlqpkcll) mlqpkcll [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\mlqpkcll.sys
YY -> (mmhaaety) mmhaaety [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\mmhaaety.sys
YY -> (mvquqacv) mvquqacv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\mvquqacv.sys
YY -> (mxyqsrew) mxyqsrew [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\mxyqsrew.sys
YY -> (mzjledhd) mzjledhd [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\mzjledhd.sys
YY -> (nbmvlzqh) nbmvlzqh [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nbmvlzqh.sys
YY -> (neqiiyvo) neqiiyvo [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\neqiiyvo.sys
YY -> (ngandykz) ngandykz [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ngandykz.sys
YY -> (nnkltjrt) nnkltjrt [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nnkltjrt.sys
YY -> (nqhvuqgb) nqhvuqgb [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nqhvuqgb.sys
YY -> (nxmjrrob) nxmjrrob [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nxmjrrob.sys
YY -> (nxqvxzrq) nxqvxzrq [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nxqvxzrq.sys
YY -> (oeyrcqyw) oeyrcqyw [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\oeyrcqyw.sys
YY -> (olsabzgp) olsabzgp [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\olsabzgp.sys
YY -> (opsnzhgw) opsnzhgw [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\opsnzhgw.sys
YY -> (ostrnyzx) ostrnyzx [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ostrnyzx.sys
YY -> (pdxvgtgc) pdxvgtgc [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\pdxvgtgc.sys
YY -> (pehqmkrh) pehqmkrh [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\pehqmkrh.sys
YY -> (pfjlatun) pfjlatun [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\pfjlatun.sys
YY -> (pfrpnppv) pfrpnppv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\pfrpnppv.sys
YY -> (phsympze) phsympze [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\phsympze.sys
YY -> (pioeoxci) pioeoxci [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\pioeoxci.sys
YY -> (pkbwrhxl) pkbwrhxl [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\pkbwrhxl.sys
YY -> (pkxfeeww) pkxfeeww [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\pkxfeeww.sys
YY -> (plgdnhwy) plgdnhwy [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\plgdnhwy.sys
YY -> (pxkcrmnw) pxkcrmnw [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\pxkcrmnw.sys
YY -> (qctmjpjg) qctmjpjg [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\qctmjpjg.sys
YY -> (qfxguylt) qfxguylt [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\qfxguylt.sys
YY -> (qlsnxoir) qlsnxoir [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\qlsnxoir.sys
YY -> (qpzaqdek) qpzaqdek [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\qpzaqdek.sys
YY -> (quelmaeo) quelmaeo [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\quelmaeo.sys
YY -> (qyvgszwe) qyvgszwe [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\qyvgszwe.sys
YY -> (rcbfdixx) rcbfdixx [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\rcbfdixx.sys
YY -> (rfnxliit) rfnxliit [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\rfnxliit.sys
YY -> (rfoyzykx) rfoyzykx [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\rfoyzykx.sys
YY -> (rfuqkent) rfuqkent [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\rfuqkent.sys
YY -> (rfvxdlva) rfvxdlva [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\rfvxdlva.sys
YY -> (ropjxhty) ropjxhty [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ropjxhty.sys
YY -> (rpwwwkju) rpwwwkju [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\rpwwwkju.sys
YY -> (rrtkqhqn) rrtkqhqn [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\rrtkqhqn.sys
YY -> (rshjgnsc) rshjgnsc [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\rshjgnsc.sys
YY -> (rxipgeya) rxipgeya [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\rxipgeya.sys
YY -> (rylzihqo) rylzihqo [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\rylzihqo.sys
YY -> (rzajfdty) rzajfdty [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\rzajfdty.sys
YY -> (sbuqifos) sbuqifos [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\sbuqifos.sys
YY -> (sgogdmms) sgogdmms [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\sgogdmms.sys
YY -> (shcvsnmd) shcvsnmd [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\shcvsnmd.sys
YY -> (shutcxbx) shutcxbx [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\shutcxbx.sys
YY -> (sitarzwa) sitarzwa [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\sitarzwa.sys
YY -> (sjuveiah) sjuveiah [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\sjuveiah.sys
YY -> (sljjaafq) sljjaafq [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\sljjaafq.sys
YY -> (sltyysxp) sltyysxp [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\sltyysxp.sys
YY -> (svyxsynq) svyxsynq [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\svyxsynq.sys
YY -> (swragxrb) swragxrb [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\swragxrb.sys
YY -> (szwzksge) szwzksge [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\szwzksge.sys
YY -> (tavtvdwb) tavtvdwb [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\tavtvdwb.sys
YY -> (tdmtspva) tdmtspva [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\tdmtspva.sys
YY -> (tiwyfltq) tiwyfltq [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\tiwyfltq.sys
YY -> (tsdtagpg) tsdtagpg [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\tsdtagpg.sys
YY -> (ubekgqmj) ubekgqmj [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ubekgqmj.sys
YY -> (udfajfgv) udfajfgv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\udfajfgv.sys
YY -> (udyhxfkh) udyhxfkh [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\udyhxfkh.sys
YY -> (uffdnpvs) uffdnpvs [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\uffdnpvs.sys
YY -> (uhfgbujf) uhfgbujf [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\uhfgbujf.sys
YY -> (uiqdhgxk) uiqdhgxk [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\uiqdhgxk.sys
YY -> (urpxhreo) urpxhreo [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\urpxhreo.sys
YY -> (uwisbtmd) uwisbtmd [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\uwisbtmd.sys
YY -> (uztucmji) uztucmji [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\uztucmji.sys
YY -> (vgmzviic) vgmzviic [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\vgmzviic.sys
YY -> (vihzenod) vihzenod [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\vihzenod.sys
YY -> (vikvhapk) vikvhapk [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\vikvhapk.sys
YY -> (wckauwdf) wckauwdf [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wckauwdf.sys
YY -> (wenpfpjl) wenpfpjl [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wenpfpjl.sys
YY -> (wgqjosrb) wgqjosrb [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wgqjosrb.sys
YY -> (wibvehix) wibvehix [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wibvehix.sys
YY -> (wlnkrcid) wlnkrcid [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wlnkrcid.sys
YY -> (wpsoxqah) wpsoxqah [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wpsoxqah.sys
YY -> (wptoksfa) wptoksfa [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wptoksfa.sys
YY -> (wuenpqxi) wuenpqxi [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wuenpqxi.sys
YY -> (wunyxsoh) wunyxsoh [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wunyxsoh.sys
YY -> (wvixnoju) wvixnoju [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wvixnoju.sys
YY -> (wvqyjvwd) wvqyjvwd [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wvqyjvwd.sys
YY -> (wvrsdazn) wvrsdazn [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wvrsdazn.sys
YY -> (xoyekbme) xoyekbme [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\xoyekbme.sys
YY -> (xqsqtodw) xqsqtodw [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\xqsqtodw.sys
YY -> (xsgvutjj) xsgvutjj [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\xsgvutjj.sys
YY -> (ycgqdkpd) ycgqdkpd [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ycgqdkpd.sys
YY -> (ydvnkqgi) ydvnkqgi [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ydvnkqgi.sys
YY -> (yisegzxj) yisegzxj [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\yisegzxj.sys
YY -> (yrwfyroh) yrwfyroh [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\yrwfyroh.sys
YY -> (yttyathl) yttyathl [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\yttyathl.sys
YY -> (zapkrcqf) zapkrcqf [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\zapkrcqf.sys
YY -> (zfjdobyc) zfjdobyc [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\zfjdobyc.sys
YY -> (ztsaafed) ztsaafed [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ztsaafed.sys
[Registry - Safe List]
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "DellSupport" -> ["C:\Program Files\Dell Support\DSAgnt.exe" /startup]
< Bret Startup Folder > -> C:\Documents and Settings\Bret\Start Menu\Programs\Startup
YN -> %UserProfile%\Start Menu\Programs\Startup\ClearPlay Easy Updates.lnk -> %ProgramFiles%\ClearPlay\ClearPlay Easy Updates\ClearPlayEasyUpdates.exe
YN -> %UserProfile%\Start Menu\Programs\Startup\MostFun.lnk -> %ProgramFiles%\MostFun\Bin\MostFun.exe
YN -> %UserProfile%\Start Menu\Programs\Startup\Xfire.lnk -> %ProgramFiles%\Xfire\Xfire.exe
[Files/Folders - Created Within 90 Days]
NY -> 5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> NIRCMD.exe -> %SystemRoot%\NIRCMD.exe
NY -> ztsaafed.sys -> %SystemRoot%\System32\drivers\ztsaafed.sys
NY -> zfjdobyc.sys -> %SystemRoot%\System32\drivers\zfjdobyc.sys
NY -> zapkrcqf.sys -> %SystemRoot%\System32\drivers\zapkrcqf.sys
NY -> yttyathl.sys -> %SystemRoot%\System32\drivers\yttyathl.sys
NY -> yrwfyroh.sys -> %SystemRoot%\System32\drivers\yrwfyroh.sys
NY -> yisegzxj.sys -> %SystemRoot%\System32\drivers\yisegzxj.sys
NY -> ydvnkqgi.sys -> %SystemRoot%\System32\drivers\ydvnkqgi.sys
NY -> ycgqdkpd.sys -> %SystemRoot%\System32\drivers\ycgqdkpd.sys
NY -> xsgvutjj.sys -> %SystemRoot%\System32\drivers\xsgvutjj.sys
NY -> xqsqtodw.sys -> %SystemRoot%\System32\drivers\xqsqtodw.sys
NY -> xoyekbme.sys -> %SystemRoot%\System32\drivers\xoyekbme.sys
NY -> wvrsdazn.sys -> %SystemRoot%\System32\drivers\wvrsdazn.sys
NY -> wvqyjvwd.sys -> %SystemRoot%\System32\drivers\wvqyjvwd.sys
NY -> wvixnoju.sys -> %SystemRoot%\System32\drivers\wvixnoju.sys
NY -> wunyxsoh.sys -> %SystemRoot%\System32\drivers\wunyxsoh.sys
NY -> wuenpqxi.sys -> %SystemRoot%\System32\drivers\wuenpqxi.sys
NY -> wptoksfa.sys -> %SystemRoot%\System32\drivers\wptoksfa.sys
NY -> wpsoxqah.sys -> %SystemRoot%\System32\drivers\wpsoxqah.sys
NY -> wlnkrcid.sys -> %SystemRoot%\System32\drivers\wlnkrcid.sys
NY -> wibvehix.sys -> %SystemRoot%\System32\drivers\wibvehix.sys
NY -> wgqjosrb.sys -> %SystemRoot%\System32\drivers\wgqjosrb.sys
NY -> wenpfpjl.sys -> %SystemRoot%\System32\drivers\wenpfpjl.sys
NY -> wckauwdf.sys -> %SystemRoot%\System32\drivers\wckauwdf.sys
NY -> vikvhapk.sys -> %SystemRoot%\System32\drivers\vikvhapk.sys
NY -> vihzenod.sys -> %SystemRoot%\System32\drivers\vihzenod.sys
NY -> vgmzviic.sys -> %SystemRoot%\System32\drivers\vgmzviic.sys
NY -> uztucmji.sys -> %SystemRoot%\System32\drivers\uztucmji.sys
NY -> uwisbtmd.sys -> %SystemRoot%\System32\drivers\uwisbtmd.sys
NY -> urpxhreo.sys -> %SystemRoot%\System32\drivers\urpxhreo.sys
NY -> uiqdhgxk.sys -> %SystemRoot%\System32\drivers\uiqdhgxk.sys
NY -> uhfgbujf.sys -> %SystemRoot%\System32\drivers\uhfgbujf.sys
NY -> uffdnpvs.sys -> %SystemRoot%\System32\drivers\uffdnpvs.sys
NY -> udyhxfkh.sys -> %SystemRoot%\System32\drivers\udyhxfkh.sys
NY -> udfajfgv.sys -> %SystemRoot%\System32\drivers\udfajfgv.sys
NY -> ubekgqmj.sys -> %SystemRoot%\System32\drivers\ubekgqmj.sys
NY -> tsdtagpg.sys -> %SystemRoot%\System32\drivers\tsdtagpg.sys
NY -> tiwyfltq.sys -> %SystemRoot%\System32\drivers\tiwyfltq.sys
NY -> tdmtspva.sys -> %SystemRoot%\System32\drivers\tdmtspva.sys
NY -> tavtvdwb.sys -> %SystemRoot%\System32\drivers\tavtvdwb.sys
NY -> szwzksge.sys -> %SystemRoot%\System32\drivers\szwzksge.sys
NY -> swragxrb.sys -> %SystemRoot%\System32\drivers\swragxrb.sys
NY -> svyxsynq.sys -> %SystemRoot%\System32\drivers\svyxsynq.sys
NY -> sltyysxp.sys -> %SystemRoot%\System32\drivers\sltyysxp.sys
NY -> sljjaafq.sys -> %SystemRoot%\System32\drivers\sljjaafq.sys
NY -> sjuveiah.sys -> %SystemRoot%\System32\drivers\sjuveiah.sys
NY -> sitarzwa.sys -> %SystemRoot%\System32\drivers\sitarzwa.sys
NY -> shutcxbx.sys -> %SystemRoot%\System32\drivers\shutcxbx.sys
NY -> shcvsnmd.sys -> %SystemRoot%\System32\drivers\shcvsnmd.sys
NY -> sgogdmms.sys -> %SystemRoot%\System32\drivers\sgogdmms.sys
NY -> sbuqifos.sys -> %SystemRoot%\System32\drivers\sbuqifos.sys
NY -> rzajfdty.sys -> %SystemRoot%\System32\drivers\rzajfdty.sys
NY -> rylzihqo.sys -> %SystemRoot%\System32\drivers\rylzihqo.sys
NY -> rxipgeya.sys -> %SystemRoot%\System32\drivers\rxipgeya.sys
NY -> rshjgnsc.sys -> %SystemRoot%\System32\drivers\rshjgnsc.sys
NY -> rrtkqhqn.sys -> %SystemRoot%\System32\drivers\rrtkqhqn.sys
NY -> rpwwwkju.sys -> %SystemRoot%\System32\drivers\rpwwwkju.sys
NY -> ropjxhty.sys -> %SystemRoot%\System32\drivers\ropjxhty.sys
NY -> rfvxdlva.sys -> %SystemRoot%\System32\drivers\rfvxdlva.sys
NY -> rfuqkent.sys -> %SystemRoot%\System32\drivers\rfuqkent.sys
NY -> rfoyzykx.sys -> %SystemRoot%\System32\drivers\rfoyzykx.sys
NY -> rfnxliit.sys -> %SystemRoot%\System32\drivers\rfnxliit.sys
NY -> rcbfdixx.sys -> %SystemRoot%\System32\drivers\rcbfdixx.sys
NY -> qyvgszwe.sys -> %SystemRoot%\System32\drivers\qyvgszwe.sys
NY -> quelmaeo.sys -> %SystemRoot%\System32\drivers\quelmaeo.sys
NY -> qpzaqdek.sys -> %SystemRoot%\System32\drivers\qpzaqdek.sys
NY -> qlsnxoir.sys -> %SystemRoot%\System32\drivers\qlsnxoir.sys
NY -> qfxguylt.sys -> %SystemRoot%\System32\drivers\qfxguylt.sys
NY -> qctmjpjg.sys -> %SystemRoot%\System32\drivers\qctmjpjg.sys
NY -> pxkcrmnw.sys -> %SystemRoot%\System32\drivers\pxkcrmnw.sys
NY -> plgdnhwy.sys -> %SystemRoot%\System32\drivers\plgdnhwy.sys
NY -> pkxfeeww.sys -> %SystemRoot%\System32\drivers\pkxfeeww.sys
NY -> pkbwrhxl.sys -> %SystemRoot%\System32\drivers\pkbwrhxl.sys
NY -> pioeoxci.sys -> %SystemRoot%\System32\drivers\pioeoxci.sys
NY -> phsympze.sys -> %SystemRoot%\System32\drivers\phsympze.sys
NY -> pfrpnppv.sys -> %SystemRoot%\System32\drivers\pfrpnppv.sys
NY -> pfjlatun.sys -> %SystemRoot%\System32\drivers\pfjlatun.sys
NY -> pehqmkrh.sys -> %SystemRoot%\System32\drivers\pehqmkrh.sys
NY -> pdxvgtgc.sys -> %SystemRoot%\System32\drivers\pdxvgtgc.sys
NY -> ostrnyzx.sys -> %SystemRoot%\System32\drivers\ostrnyzx.sys
NY -> opsnzhgw.sys -> %SystemRoot%\System32\drivers\opsnzhgw.sys
NY -> olsabzgp.sys -> %SystemRoot%\System32\drivers\olsabzgp.sys
NY -> oeyrcqyw.sys -> %SystemRoot%\System32\drivers\oeyrcqyw.sys
NY -> nxqvxzrq.sys -> %SystemRoot%\System32\drivers\nxqvxzrq.sys
NY -> nxmjrrob.sys -> %SystemRoot%\System32\drivers\nxmjrrob.sys
NY -> nqhvuqgb.sys -> %SystemRoot%\System32\drivers\nqhvuqgb.sys
NY -> nnkltjrt.sys -> %SystemRoot%\System32\drivers\nnkltjrt.sys
NY -> ngandykz.sys -> %SystemRoot%\System32\drivers\ngandykz.sys
NY -> neqiiyvo.sys -> %SystemRoot%\System32\drivers\neqiiyvo.sys
NY -> nbmvlzqh.sys -> %SystemRoot%\System32\drivers\nbmvlzqh.sys
NY -> mzjledhd.sys -> %SystemRoot%\System32\drivers\mzjledhd.sys
NY -> mxyqsrew.sys -> %SystemRoot%\System32\drivers\mxyqsrew.sys
NY -> mvquqacv.sys -> %SystemRoot%\System32\drivers\mvquqacv.sys
NY -> mmhaaety.sys -> %SystemRoot%\System32\drivers\mmhaaety.sys
NY -> mlqpkcll.sys -> %SystemRoot%\System32\drivers\mlqpkcll.sys
NY -> mkgjieic.sys -> %SystemRoot%\System32\drivers\mkgjieic.sys
NY -> mjlonwqm.sys -> %SystemRoot%\System32\drivers\mjlonwqm.sys
NY -> lqzedbnl.sys -> %SystemRoot%\System32\drivers\lqzedbnl.sys
NY -> lpbrguiz.sys -> %SystemRoot%\System32\drivers\lpbrguiz.sys
NY -> lnxmzfgo.sys -> %SystemRoot%\System32\drivers\lnxmzfgo.sys
NY -> lfnjvuqd.sys -> %SystemRoot%\System32\drivers\lfnjvuqd.sys
NY -> lcahnbte.sys -> %SystemRoot%\System32\drivers\lcahnbte.sys
NY -> kxiknqej.sys -> %SystemRoot%\System32\drivers\kxiknqej.sys
NY -> krlynxqh.sys -> %SystemRoot%\System32\drivers\krlynxqh.sys
NY -> kqwcjnrl.sys -> %SystemRoot%\System32\drivers\kqwcjnrl.sys
NY -> kdgwecas.sys -> %SystemRoot%\System32\drivers\kdgwecas.sys
NY -> kbuvmejq.sys -> %SystemRoot%\System32\drivers\kbuvmejq.sys
NY -> kbuokmrp.sys -> %SystemRoot%\System32\drivers\kbuokmrp.sys
NY -> jxihztde.sys -> %SystemRoot%\System32\drivers\jxihztde.sys
NY -> jtdpfsbk.sys -> %SystemRoot%\System32\drivers\jtdpfsbk.sys
NY -> jnjmxipc.sys -> %SystemRoot%\System32\drivers\jnjmxipc.sys
NY -> jmcfzuta.sys -> %SystemRoot%\System32\drivers\jmcfzuta.sys
NY -> jljhbqgk.sys -> %SystemRoot%\System32\drivers\jljhbqgk.sys
NY -> jkqwlzgt.sys -> %SystemRoot%\System32\drivers\jkqwlzgt.sys
NY -> jiiuacwq.sys -> %SystemRoot%\System32\drivers\jiiuacwq.sys
NY -> jhosrlvn.sys -> %SystemRoot%\System32\drivers\jhosrlvn.sys
NY -> iwrpxzgg.sys -> %SystemRoot%\System32\drivers\iwrpxzgg.sys
NY -> iqgptswa.sys -> %SystemRoot%\System32\drivers\iqgptswa.sys
NY -> iqejlwdg.sys -> %SystemRoot%\System32\drivers\iqejlwdg.sys
NY -> inrvkgpo.sys -> %SystemRoot%\System32\drivers\inrvkgpo.sys
NY -> ikywixiy.sys -> %SystemRoot%\System32\drivers\ikywixiy.sys
NY -> iivqqfob.sys -> %SystemRoot%\System32\drivers\iivqqfob.sys
NY -> hzkmtgti.sys -> %SystemRoot%\System32\drivers\hzkmtgti.sys
NY -> hxcbcnay.sys -> %SystemRoot%\System32\drivers\hxcbcnay.sys
NY -> hsqcilte.sys -> %SystemRoot%\System32\drivers\hsqcilte.sys
NY -> hsjvpafb.sys -> %SystemRoot%\System32\drivers\hsjvpafb.sys
NY -> hsenitvc.sys -> %SystemRoot%\System32\drivers\hsenitvc.sys
NY -> gzrkxewd.sys -> %SystemRoot%\System32\drivers\gzrkxewd.sys
NY -> gznoqfls.sys -> %SystemRoot%\System32\drivers\gznoqfls.sys
NY -> gqhxgjct.sys -> %SystemRoot%\System32\drivers\gqhxgjct.sys
NY -> gktzahlx.sys -> %SystemRoot%\System32\drivers\gktzahlx.sys
NY -> gbvvnfea.sys -> %SystemRoot%\System32\drivers\gbvvnfea.sys
NY -> gacjfhui.sys -> %SystemRoot%\System32\drivers\gacjfhui.sys
NY -> fzhbocbf.sys -> %SystemRoot%\System32\drivers\fzhbocbf.sys
NY -> fyssvwph.sys -> %SystemRoot%\System32\drivers\fyssvwph.sys
NY -> fvptrayk.sys -> %SystemRoot%\System32\drivers\fvptrayk.sys
NY -> fuuyfewv.sys -> %SystemRoot%\System32\drivers\fuuyfewv.sys
NY -> ftpmieju.sys -> %SystemRoot%\System32\drivers\ftpmieju.sys
NY -> ftizlanf.sys -> %SystemRoot%\System32\drivers\ftizlanf.sys
NY -> fnfohlsh.sys -> %SystemRoot%\System32\drivers\fnfohlsh.sys
NY -> fkaqmowk.sys -> %SystemRoot%\System32\drivers\fkaqmowk.sys
NY -> fjhmalir.sys -> %SystemRoot%\System32\drivers\fjhmalir.sys
NY -> fhpntvti.sys -> %SystemRoot%\System32\drivers\fhpntvti.sys
NY -> fgvtayet.sys -> %SystemRoot%\System32\drivers\fgvtayet.sys
NY -> febzlklr.sys -> %SystemRoot%\System32\drivers\febzlklr.sys
NY -> fdihkvxe.sys -> %SystemRoot%\System32\drivers\fdihkvxe.sys
NY -> faitxavy.sys -> %SystemRoot%\System32\drivers\faitxavy.sys
NY -> exbosxxc.sys -> %SystemRoot%\System32\drivers\exbosxxc.sys
NY -> euketgec.sys -> %SystemRoot%\System32\drivers\euketgec.sys
NY -> dzaygihl.sys -> %SystemRoot%\System32\drivers\dzaygihl.sys
NY -> dqgnyfne.sys -> %SystemRoot%\System32\drivers\dqgnyfne.sys
NY -> dplpdibp.sys -> %SystemRoot%\System32\drivers\dplpdibp.sys
NY -> dpircxuz.sys -> %SystemRoot%\System32\drivers\dpircxuz.sys
NY -> dofwwvrh.sys -> %SystemRoot%\System32\drivers\dofwwvrh.sys
NY -> dlztawbb.sys -> %SystemRoot%\System32\drivers\dlztawbb.sys
NY -> diihfegw.sys -> %SystemRoot%\System32\drivers\diihfegw.sys
NY -> deqgwxjs.sys -> %SystemRoot%\System32\drivers\deqgwxjs.sys
NY -> dcqoqzqk.sys -> %SystemRoot%\System32\drivers\dcqoqzqk.sys
NY -> cxtzxbyw.sys -> %SystemRoot%\System32\drivers\cxtzxbyw.sys
NY -> cquntych.sys -> %SystemRoot%\System32\drivers\cquntych.sys
NY -> cppugygq.sys -> %SystemRoot%\System32\drivers\cppugygq.sys
NY -> comazqkd.sys -> %SystemRoot%\System32\drivers\comazqkd.sys
NY -> ckfymirf.sys -> %SystemRoot%\System32\drivers\ckfymirf.sys
NY -> ceepgpls.sys -> %SystemRoot%\System32\drivers\ceepgpls.sys
NY -> ccagpfak.sys -> %SystemRoot%\System32\drivers\ccagpfak.sys
NY -> bzthitdx.sys -> %SystemRoot%\System32\drivers\bzthitdx.sys
NY -> bzmgnrua.sys -> %SystemRoot%\System32\drivers\bzmgnrua.sys
NY -> bndpohvk.sys -> %SystemRoot%\System32\drivers\bndpohvk.sys
NY -> bhirqjsk.sys -> %SystemRoot%\System32\drivers\bhirqjsk.sys
NY -> bfwxlkxq.sys -> %SystemRoot%\System32\drivers\bfwxlkxq.sys
NY -> awhsjsmg.sys -> %SystemRoot%\System32\drivers\awhsjsmg.sys
NY -> atpmjoyk.sys -> %SystemRoot%\System32\drivers\atpmjoyk.sys
NY -> aqlztezp.sys -> %SystemRoot%\System32\drivers\aqlztezp.sys
NY -> alcqazmk.sys -> %SystemRoot%\System32\drivers\alcqazmk.sys
NY -> ahmzkppr.sys -> %SystemRoot%\System32\drivers\ahmzkppr.sys
NY -> agyzvxmh.sys -> %SystemRoot%\System32\drivers\agyzvxmh.sys
NY -> adbkwvzx.sys -> %SystemRoot%\System32\drivers\adbkwvzx.sys
NY -> SWREG.exe -> %SystemRoot%\SWREG.exe
NY -> sed.exe -> %SystemRoot%\sed.exe
NY -> fdsv.exe -> %SystemRoot%\fdsv.exe
NY -> grep.exe -> %SystemRoot%\grep.exe
NY -> zip.exe -> %SystemRoot%\zip.exe
NY -> VFIND.exe -> %SystemRoot%\VFIND.exe
NY -> SWXCACLS.exe -> %SystemRoot%\SWXCACLS.exe
NY -> SWSC.exe -> %SystemRoot%\SWSC.exe
NY -> Qoobox -> %SystemDrive%\Qoobox
NY -> ERDNT -> %SystemRoot%\ERDNT
NY -> ComboFix.exe -> %UserProfile%\Desktop\ComboFix.exe
NY -> SDFix -> %SystemDrive%\SDFix
NY -> SDFix.exe -> %UserProfile%\Desktop\SDFix.exe
NY -> _OTListIt -> %SystemDrive%\_OTListIt
NY -> OTListIt22.exe -> %UserProfile%\Desktop\OTListIt22.exe
NY -> HJTsetup.exe -> %UserProfile%\Desktop\HJTsetup.exe
[Custom Scans]
YY -> 2507303324.EXE-109C1C78.pf -> C:\WINDOWS\Prefetch\2507303324.EXE
YY -> 2706834574.EXE-2FB1B84B.pf -> C:\WINDOWS\Prefetch\2706834574.EXE
[Empty Temp Folders]
[Start Explorer]
[Reboot]
The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here
I will review the information when it comes back in.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI