I have a rootkit that I can't remove. I ran sdfix, combofix and gmer. I ran gmer and ran a scan but it disappears before finishing. If I stop it when I see typing in red I can delete or disable the service. Here's a log file from gmer. See line with
" \\?\globalroot\Device\__ma
x++>\61146
290.x86.dl
l " in them.
I put the combofix log below gmer too.
GMER 1.0.15.14972 -
http://www.gmer.netRootkit scan 2009-08-19 14:21:58
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT 89AE8420 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Dr
ivers\SYME
VENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0x9D3B6350]
SSDT \??\C:\WINDOWS\system32\Dr
ivers\SYME
VENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0x9D3B6580]
---- Kernel code sections - GMER 1.0.15 ----
? win32k.sys:1 The system cannot find the file specified. !
? win32k.sys:2 The system cannot find the file specified. !
? C:\WINDOWS\system32\Driver
s\PROCEXP1
00.SYS The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[61
2] SHELL32.dll!SHFileOperatio
nW 7CA70924 5 Bytes JMP 00BD1102 C:\Program Files\Unlocker\UnlockerHoo
k.dll
.text C:\WINDOWS\system32\winlog
on.exe[118
0] USER32.dll!CallNextHookEx + 4A 7E42B410 7 Bytes CALL 35672D96 \\?\globalroot\Device\__ma
x++>\61146
290.x86.dl
l
.text C:\WINDOWS\system32\winlog
on.exe[118
0] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__ma
x++>\61146
290.x86.dl
l
.text C:\WINDOWS\system32\winlog
on.exe[118
0] GDI32.dll!GetTextExtentPoi
nt32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__ma
x++>\61146
290.x86.dl
l
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\winlog
on.exe[118
0] @ C:\WINDOWS\system32\kernel
32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__ma
x++>\61146
290.x86.dl
l
IAT C:\WINDOWS\system32\winlog
on.exe[118
0] @ C:\WINDOWS\system32\kernel
32.dll [ntdll.dll!LdrGetProcedure
Address] [35672A1E] \\?\globalroot\Device\__ma
x++>\61146
290.x86.dl
l
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio)
---- Processes - GMER 1.0.15 ----
Library \\?\globalroot\Device\__ma
x++>\61146
290.x86.dl
l (*** hidden *** ) @ C:\PROGRA~1\SYMANT~1\VPTra
y.exe [876] 0x35670000
Library \\?\globalroot\Device\__ma
x++>\61146
290.x86.dl
l (*** hidden *** ) @ C:\Program Files\LogMeIn\x86\LogMeInS
ystray.exe
[924] 0x35670000
Library \\?\globalroot\Device\__ma
x++>\61146
290.x86.dl
l (*** hidden *** ) @ C:\Program Files\Symantec AntiVirus\SavRoam.exe [988] 0x35670000
Library \\?\globalroot\Device\__ma
x++>\61146
290.x86.dl
l (*** hidden *** ) @ C:\Program Files\Intel\AMT\UNS.exe [1088] 0x35670000
Library \\?\globalroot\Device\__ma
x++>\61146
290.x86.dl
l (*** hidden *** ) @ C:\WINDOWS\system32\winlog
on.exe [1180] 0x35670000
Library \\?\globalroot\Device\__ma
x++>\61146
290.x86.dl
l (*** hidden *** ) @ C:\WINDOWS\System32\svchos
t.exe [1512] 0x35670000
Library \\?\globalroot\Device\__ma
x++>\61146
290.x86.dl
l (*** hidden *** ) @ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe [1808] 0x35670000
Library \\?\globalroot\Device\__ma
x++>\61146
290.x86.dl
l (*** hidden *** ) @ C:\Program Files\Bonjour\mDNSResponde
r.exe [1840] 0x35670000
Library \\?\globalroot\Device\__ma
x++>\61146
290.x86.dl
l (*** hidden *** ) @ C:\Program Files\Intel\AMT\LMS.exe [1936] 0x35670000
---- Files - GMER 1.0.15 ----
ADS C:\System Volume Information\_restore{0ED51
6BE-6065-4
47F-9729-C
55486FD6F5
E}\RP547\A
0039131.sy
s:1 8192 bytes executable
ADS C:\System Volume Information\_restore{0ED51
6BE-6065-4
47F-9729-C
55486FD6F5
E}\RP547\A
0039759.sy
s:1 8192 bytes executable
ADS C:\System Volume Information\_restore{0ED51
6BE-6065-4
47F-9729-C
55486FD6F5
E}\RP547\A
0039808.sy
s:1 8192 bytes executable
ADS C:\System Volume Information\_restore{0ED51
6BE-6065-4
47F-9729-C
55486FD6F5
E}\RP547\A
0039834.sy
s:1 8192 bytes executable
ADS C:\System Volume Information\_restore{0ED51
6BE-6065-4
47F-9729-C
55486FD6F5
E}\RP547\A
0039839.sy
s:1 8192 bytes executable
ADS C:\System Volume Information\_restore{0ED51
6BE-6065-4
47F-9729-C
55486FD6F5
E}\RP547\A
0039850.sy
s:1 8192 bytes executable
ComboFix 09-08-18.04 - Administrator 08/19/2009 15:26.3.2 - NTFSx86
Running from: c:\install\spyware\ComboFi
x.exe
.
((((((((((((((((((((((((((
((((((((((
((( Other Deletions ))))))))))))))))))))))))))
))))))))))
))))))))))
)))
.
.
((((((((((((((((((((((((((
((((((((((
((( Drivers/Services ))))))))))))))))))))))))))
))))))))))
))))))))))
)))
.
-------\Legacy_{79007602-0
CDB-4405-9
DBF-1257BB
3226ED}
-------\Legacy_{79007602-0
CDB-4405-9
DBF-1257BB
3226EE}
((((((((((((((((((((((((( Files Created from 2009-07-19 to 2009-08-19 ))))))))))))))))))))))))))
)))))
.
2009-08-19 17:55 . 2008-04-14 00:12 14336 ----a-w- c:\windows\system32\svchos
t.exe
2009-08-19 17:21 . 2009-08-19 17:21 -------- d-----w- c:\documents and settings\administrator.SNP
D\Applicat
ion Data\Research In Motion
2009-08-19 16:41 . 2009-08-19 16:41 3942048 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwareb
ytes' Anti-Malware\mbam-setup.ex
e
2009-08-19 16:35 . 2009-08-19 16:35 -------- d-----w- c:\program files\Unlocker
2009-08-19 16:20 . 2009-08-19 16:20 578560 -c--a-w- c:\windows\system32\dllcac
he\user32.
dll
2009-08-19 16:19 . 2009-08-19 16:19 -------- d-----w- c:\windows\ERUNT
2009-08-19 16:18 . 2009-08-19 16:18 -------- d-----w- c:\documents and settings\Administrator\Loc
al Settings\Application Data\GHISLER
2009-08-19 16:12 . 2009-08-19 16:12 -------- d-----w- c:\documents and settings\dave\Application Data\Malwarebytes
2009-08-19 16:12 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\driver
s\mbamswis
sarmy.sys
2009-08-19 16:12 . 2009-08-19 19:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-19 16:12 . 2009-08-19 16:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-19 16:12 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\driver
s\mbam.sys
2009-08-19 13:23 . 2009-08-19 13:23 -------- d-----w- c:\documents and settings\robert\Applicatio
n Data\Research In Motion
2009-08-17 12:20 . 2009-08-17 12:20 -------- d-----w- c:\documents and settings\brent\Application
Data\Research In Motion
2009-08-16 01:33 . 2009-08-16 01:33 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd
2e1e03.vdb
\NAVEX32A.
DLL
2009-08-16 01:33 . 2009-08-16 01:33 87888 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd
2e1e03.vdb
\NAVENG.SY
S
2009-08-16 01:33 . 2009-08-16 01:33 875728 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd
2e1e03.vdb
\NAVEX15.S
YS
2009-08-16 01:33 . 2009-08-16 01:33 371248 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd
2e1e03.vdb
\EECTRL.SY
S
2009-08-16 01:33 . 2009-08-16 01:33 259368 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd
2e1e03.vdb
\ECMSVR32.
DLL
2009-08-16 01:33 . 2009-08-16 01:33 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd
2e1e03.vdb
\CCERASER.
DLL
2009-08-16 01:33 . 2009-08-16 01:33 177520 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd
2e1e03.vdb
\NAVENG32.
DLL
2009-08-16 01:33 . 2009-08-16 01:33 101936 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd
2e1e03.vdb
\ERASER.SY
S
2009-08-05 03:10 . 2009-08-05 03:10 -------- d-----w- c:\documents and settings\dave\Local Settings\Application Data\Temp
2009-07-23 13:25 . 2009-07-23 13:25 -------- d-----w- c:\program files\Jetcast
.
((((((((((((((((((((((((((
((((((((((
(((( Find3M Report ))))))))))))))))))))))))))
))))))))))
))))))))))
))))))
.
2009-08-19 17:02 . 2008-05-01 01:04 -------- d-----w- c:\program files\Symantec AntiVirus
2009-08-19 16:40 . 2009-05-29 14:25 256 ----a-w- c:\windows\system32\pool.b
in
2009-08-18 05:37 . 2009-03-21 04:39 117760 ----a-w- c:\documents and settings\police\Applicatio
n Data\SUPERAntiSpyware.com\
SUPERAntiS
pyware\SDD
LLS\UIREPA
IR.DLL
2009-08-17 20:42 . 2009-03-13 19:23 -------- d-----w- c:\program files\DYMO Label
2009-08-17 12:09 . 2008-05-01 15:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-16 17:20 . 2008-01-24 20:23 107208 -c--a-w- c:\documents and settings\Judge\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-11 05:09 . 2008-05-01 01:26 -------- d-----w- c:\documents and settings\police\Applicatio
n Data\InstallShield
2009-08-11 05:08 . 2008-02-21 16:24 -------- d-----w- c:\program files\Common Files\Roxio Shared
2009-08-11 05:08 . 2008-02-21 16:24 -------- d-----w- c:\program files\Roxio
2009-08-11 05:07 . 2009-05-29 14:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Roxio
2009-08-11 05:03 . 2008-02-21 16:25 -------- d-----w- c:\program files\Common Files\Sonic Shared
2009-08-11 04:57 . 2009-04-22 19:41 -------- d-----w- c:\program files\Common Files\Research In Motion
2009-08-11 04:42 . 2008-04-30 23:40 -------- d-----w- c:\program files\LogMeIn
2009-08-11 04:22 . 2009-03-07 23:56 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-08-06 19:10 . 2008-04-30 22:36 -------- d-----w- c:\program files\Microsoft Money
2009-07-18 21:25 . 2009-05-21 17:40 -------- d-----w- c:\program files\SJS
2009-06-25 14:59 . 2009-03-23 18:51 117760 ----a-w- c:\documents and settings\dave\Application Data\SUPERAntiSpyware.com\
SUPERAntiS
pyware\SDD
LLS\UIREPA
IR.DLL
2009-06-15 14:50 . 2009-06-15 14:50 390664 -c--a-w- c:\documents and settings\dave\Application Data\Real\RealPlayer\Updat
e\realplay
er11gold.e
xe
2009-05-21 19:37 . 2009-06-19 17:33 55 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\p
rtact.bat
2008-03-06 20:35 . 2008-02-21 18:51 952 --sha-w- c:\windows\system32\KGyGaA
vL.sys
.
------- Sigcheck -------
[-] 2004-08-04 04:56 14336 8F078AE4ED187AAABC0A305146
DE6716 c:\windows\$NtServicePackU
ninstall$\
svchost.ex
e
[-] 2008-04-14 00:12 14336 27C6D03BCDB8CFEB96B716F3D8
BE3E18 c:\windows\ServicePackFile
s\i386\svc
host.exe
[-] 2008-04-14 00:12 14336 27C6D03BCDB8CFEB96B716F3D8
BE3E18 c:\windows\system32\svchos
t.exe
[-] 2007-03-08 15:48 578048 7AA4F6C00405DFC4B70ED4214E
7D687B c:\windows\$NtServicePackU
ninstall$\
user32.dll
[-] 2008-04-14 00:12 578560 B26B135FF1B9F60C9388B4A7D1
6F600B c:\windows\ServicePackFile
s\i386\use
r32.dll
[-] 2008-04-14 00:12 578560 B26B135FF1B9F60C9388B4A7D1
6F600B c:\windows\system32\user32
.dll
[-] 2009-08-19 16:20 578560 !HASH: COULD NOT OPEN FILE !!!!! c:\windows\system32\dllcac
he\user32.
dll
[-] 2004-08-04 04:56 82944 2ED0B7F12A60F90092081C50FA
0EC2B2 c:\windows\$NtServicePackU
ninstall$\
ws2_32.dll
[-] 2008-04-14 00:12 82432 2CCC474EB85CEAA3E1FA172658
0A3E5A c:\windows\ServicePackFile
s\i386\ws2
_32.dll
[-] 2008-04-14 00:12 82432 2CCC474EB85CEAA3E1FA172658
0A3E5A c:\windows\system32\ws2_32
.dll
[-] 2008-03-01 13:03 827392 6316C2F0C61271C8ABDFF74291
74879E c:\windows\$hf_mig$\KB9478
64-IE7\SP2
QFE\winine
t.dll
[-] 2008-04-23 03:35 827392 41546B396A526918DA7995A02E
A04E51 c:\windows\$hf_mig$\KB9507
59-IE7\SP2
QFE\winine
t.dll
[-] 2008-06-23 16:01 827904 C66402A06B83B036C195242C0C
8CF83C c:\windows\$hf_mig$\KB9538
38-IE7\SP2
QFE\winine
t.dll
[-] 2008-08-26 09:08 827904 77C192FE56A70D7FA0247BA0A6
201C32 c:\windows\$hf_mig$\KB9563
90-IE7\SP2
QFE\winine
t.dll
[-] 2008-10-16 20:24 827904 0D5B75171FF51775B630A431B6
C667E8 c:\windows\$hf_mig$\KB9582
15-IE7\SP2
QFE\winine
t.dll
[-] 2008-12-20 23:56 827904 044E0A4E9FE97C0FB9AFE9C89E
2A82E6 c:\windows\$hf_mig$\KB9612
60-IE7\SP2
QFE\winine
t.dll
[-] 2009-03-03 00:17 828416 C8667854873938CA13C986F16B
0CD183 c:\windows\$hf_mig$\KB9630
27-IE7\SP3
QFE\winine
t.dll
[-] 2009-04-29 04:49 828928 62CCA075F44015147B8971DAFF
BCFF76 c:\windows\$hf_mig$\KB9698
97-IE7\SP3
QFE\winine
t.dll
[-] 2006-10-19 20:12 664576 64CE26DB72810B30F7855EA51E
1DF836 c:\windows\ie7\wininet.dll
[-] 2007-08-13 23:54 818688 A4A0FC92358F39538A6494C42E
F99FE9 c:\windows\ie7updates\KB94
2615-IE7\w
ininet.dll
[-] 2007-10-10 23:56 824832 30C1E0F34AD2972C72A01DB5C7
4AB065 c:\windows\ie7updates\KB94
4533-IE7\w
ininet.dll
[-] 2007-12-07 02:21 824832 806D274C9A6C3AAEA5EAE8E4AF
841E04 c:\windows\ie7updates\KB94
7864-IE7\w
ininet.dll
[-] 2008-03-01 13:06 826368 AD21461AEF8244EDEC2EF18E55
E1DCF3 c:\windows\ie7updates\KB95
0759-IE7\w
ininet.dll
[-] 2008-04-23 04:16 826368 F6589BE784647CFDBC22EA51CC
B1A57A c:\windows\ie7updates\KB95
3838-IE7\w
ininet.dll
[-] 2008-06-23 16:57 826368 8C13D4A7479FA0A026EDA8ABCE
82C0ED c:\windows\ie7updates\KB95
6390-IE7\w
ininet.dll
[-] 2008-08-26 07:24 826368 EF8EBA98145BFA44E80D17A3B3
453300 c:\windows\ie7updates\KB95
8215-IE7\w
ininet.dll
[-] 2008-10-16 20:38 826368 6741EAF7B7F110E803A6E38F6E
5FA6B0 c:\windows\ie7updates\KB96
1260-IE7\w
ininet.dll
[-] 2008-12-20 23:15 826368 A82935D32D0672E8FF4E91AE39
8E901C c:\windows\ie7updates\KB96
3027-IE7\w
ininet.dll
[-] 2009-03-03 00:18 826368 28775945CCD53DEE280EF58DEA
1A94C4 c:\windows\ie7updates\KB96
9897-IE7\w
ininet.dll
[-] 2008-04-14 00:12 666112 7A4F775ABB2F1C97DEF3E73AFA
2FAEDD c:\windows\ServicePackFile
s\i386\win
inet.dll
[-] 2009-04-29 04:56 827392 8E2D471157B0DF329D8D0EA5D8
3B0DDB c:\windows\SoftwareDistrib
ution\Down
load\82c73
8ec00f0f07
f8ea182bc9
5439593\sp
3gdr\winin
et.dll
[-] 2009-04-29 04:49 828928 62CCA075F44015147B8971DAFF
BCFF76 c:\windows\SoftwareDistrib
ution\Down
load\82c73
8ec00f0f07
f8ea182bc9
5439593\sp
3qfe\winin
et.dll
[-] 2007-10-10 23:56 824832 30C1E0F34AD2972C72A01DB5C7
4AB065 c:\windows\SoftwareDistrib
ution\Down
load\e3709
fbfd9557a7
d083f543d5
1d38612\SP
2GDR\winin
et.dll
[-] 2007-10-10 23:47 825344 0E5D918F87EFA7D2424D66B499
C7EB04 c:\windows\SoftwareDistrib
ution\Down
load\e3709
fbfd9557a7
d083f543d5
1d38612\SP
2QFE\winin
et.dll
[-] 2007-10-11 05:57 666112 80D660A49E0D118144423099B2
A9F5DA c:\windows\SoftwareDistrib
ution\Down
load\fa582
43222bcfe3
5e5467668d
f396003\sp
2qfe\winin
et.dll
[-] 2009-04-29 04:56 827392 8E2D471157B0DF329D8D0EA5D8
3B0DDB c:\windows\system32\winine
t.dll
[-] 2009-04-29 04:56 827392 8E2D471157B0DF329D8D0EA5D8
3B0DDB c:\windows\system32\dllcac
he\wininet
.dll
[-] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F
436D3D c:\windows\$hf_mig$\KB9517
48\SP3GDR\
tcpip.sys
[-] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B
666C8E c:\windows\$hf_mig$\KB9517
48\SP3QFE\
tcpip.sys
[-] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B
918F48 c:\windows\$NtServicePackU
ninstall$\
tcpip.sys
[-] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB88059
88F733 c:\windows\$NtUninstallKB9
51748$\tcp
ip.sys
[-] 2007-10-30 16:53 360832 64798ECFA43D78C7178375FCDD
16D8C8 c:\windows\$NtUninstallKB9
51748_0$\t
cpip.sys
[-] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB88059
88F733 c:\windows\ServicePackFile
s\i386\tcp
ip.sys
[-] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F
436D3D c:\windows\system32\dllcac
he\tcpip.s
ys
[-] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F
436D3D c:\windows\system32\driver
s\tcpip.sy
s
[-] 2004-08-04 04:56 502272 01C3346C241652F43AED8E2149
881BFE c:\windows\$NtServicePackU
ninstall$\
winlogon.e
xe
[-] 2008-04-14 00:12 507904 ED0EF0A136DEC83DF69F041188
70003E c:\windows\ServicePackFile
s\i386\win
logon.exe
[-] 2008-04-14 00:12 507904 ED0EF0A136DEC83DF69F041188
70003E c:\windows\system32\winlog
on.exe
[-] 2004-08-04 03:14 182912 558635D3AF1C7546D26067D5D9
B6959E c:\windows\$NtServicePackU
ninstall$\
ndis.sys
[-] 2008-04-13 19:20 182656 1DF7F42665C94B825322FAE717
21130D c:\windows\ServicePackFile
s\i386\ndi
s.sys
[-] 2008-04-13 19:20 182656 1DF7F42665C94B825322FAE717
21130D c:\windows\system32\driver
s\ndis.sys
[-] 2004-08-04 03:00 29056 4448006B6BC60E6C027932CFC3
8D6855 c:\windows\$NtServicePackU
ninstall$\
ip6fw.sys
[-] 2008-04-13 18:53 36608 3BB22519A194418D5FEC05D800
A19AD0 c:\windows\ServicePackFile
s\i386\ip6
fw.sys
[-] 2008-04-13 18:53 36608 3BB22519A194418D5FEC05D800
A19AD0 c:\windows\system32\driver
s\ip6fw.sy
s
[-] 2009-02-06 10:30 2066176 607352B9CB3D708C67F6039097
801B5A c:\windows\$hf_mig$\KB9565
72\SP3QFE\
ntkrnlpa.e
xe
[-] 2008-08-14 19:39 2066048 A25E9B86EFFB2AF33BF51E676B
68BFB0 c:\windows\$hf_mig$\KB9568
41\SP3QFE\
ntkrnlpa.e
xe
[-] 2007-02-28 09:15 2017280 2DFB215E291E3D9B1CF9A6739B
3BF16C c:\windows\$NtServicePackU
ninstall$\
ntkrnlpa.e
xe
[-] 2008-08-14 09:33 2023936 8206B5F94A6A9450E934029420
C1693F c:\windows\$NtUninstallKB9
56572$\ntk
rnlpa.exe
[-] 2008-04-13 18:31 2023936 7F653A89F6E89E3AE0D49830EE
CE35D4 c:\windows\$NtUninstallKB9
56841$\ntk
rnlpa.exe
[-] 2009-02-07 23:02 2066048 5BA7F2141BC6DB06100D0E5A73
2C617A c:\windows\Driver Cache\i386\ntkrnlpa.exe
[-] 2008-04-13 18:31 2065792 109F8E3E3C82E337BB71B6BC9B
895D61 c:\windows\ServicePackFile
s\i386\ntk
rnlpa.exe
[-] 2009-02-06 10:32 2023936 65D4220799E6FC2CB079070A63
93CC0E c:\windows\system32\ntkrnl
pa.exe
[-] 2009-02-07 23:02 2066048 5BA7F2141BC6DB06100D0E5A73
2C617A c:\windows\system32\dllcac
he\ntkrnlp
a.exe
[-] 2009-02-07 23:35 2189184 EFE8EACE83EAAD5849A7A548FB
75B584 c:\windows\$hf_mig$\KB9565
72\SP3QFE\
ntoskrnl.e
xe
[-] 2008-08-14 20:11 2189184 31914172342BFF330063F343AC
6958FE c:\windows\$hf_mig$\KB9568
41\SP3QFE\
ntoskrnl.e
xe
[-] 2007-02-28 09:53 2137600 E6679C3023B17D8B78946BC5DF
53FA20 c:\windows\$NtServicePackU
ninstall$\
ntoskrnl.e
xe
[-] 2008-08-14 10:09 2145280 F6F8245B3A2E9CA834DD318E7A
E0C6D0 c:\windows\$NtUninstallKB9
56572$\nto
skrnl.exe
[-] 2008-04-13 19:24 2145280 40F8880122A030A7E9E1FEDEA8
33B33D c:\windows\$NtUninstallKB9
56841$\nto
skrnl.exe
[-] 2009-02-06 11:08 2189056 7A95B10A73737EBF24139AAA63
F5212B c:\windows\Driver Cache\i386\ntoskrnl.exe
[-] 2008-04-13 19:27 2188928 0C89243C7C3EE199B96FCC1699
0E0679 c:\windows\ServicePackFile
s\i386\nto
skrnl.exe
[-] 2009-02-06 11:06 2145280 0CBA44D0938D57F334C0862424
148B70 c:\windows\system32\ntoskr
nl.exe
[-] 2009-02-06 11:08 2189056 7A95B10A73737EBF24139AAA63
F5212B c:\windows\system32\dllcac
he\ntoskrn
l.exe
[-] 2008-04-14 00:12 1033728 12896823FB95BFB3DC9B46BCAE
DC9923 c:\windows\explorer.exe
[-] 2007-06-13 10:23 1033216 97BD6515465659FF8F3B7BE375
B2EA87 c:\windows\$NtServicePackU
ninstall$\
explorer.e
xe
[-] 2008-04-14 00:12 1033728 12896823FB95BFB3DC9B46BCAE
DC9923 c:\windows\ServicePackFile
s\i386\exp
lorer.exe
[-] 2009-02-06 11:06 110592 020CEAAEDC8EB655B6506B8C70
D53BB6 c:\windows\$hf_mig$\KB9565
72\SP3QFE\
services.e
xe
[-] 2004-08-04 04:56 108032 C6CE6EEC82F187615D1002BB3B
B50ED4 c:\windows\$NtServicePackU
ninstall$\
services.e
xe
[-] 2008-04-14 00:12 108544 0E776ED5F7CC9F94299E70461B
7B8185 c:\windows\$NtUninstallKB9
56572$\ser
vices.exe
[-] 2008-04-14 00:12 108544 0E776ED5F7CC9F94299E70461B
7B8185 c:\windows\ServicePackFile
s\i386\ser
vices.exe
[-] 2009-02-06 11:11 110592 65DF52F5B8B6E9BBD183505225
C37315 c:\windows\system32\servic
es.exe
[-] 2009-02-06 11:11 110592 65DF52F5B8B6E9BBD183505225
C37315 c:\windows\system32\dllcac
he\service
s.exe
[-] 2004-08-04 04:56 13312 84885F9B82F4D55C6146EBF606
5D75D2 c:\windows\$NtServicePackU
ninstall$\
lsass.exe
[-] 2008-04-14 00:12 13312 BF2466B3E18E970D8A976FB95F
C1CA85 c:\windows\ServicePackFile
s\i386\lsa
ss.exe
[-] 2008-04-14 00:12 13312 BF2466B3E18E970D8A976FB95F
C1CA85 c:\windows\system32\lsass.
exe
[-] 2004-08-04 04:56 15360 24232996A38C0B0CF151C2140A
E29FC8 c:\windows\$NtServicePackU
ninstall$\
ctfmon.exe
[-] 2008-04-14 00:12 15360 5F1D5F88303D4A4DBC8E5F97BA
967CC3 c:\windows\ServicePackFile
s\i386\ctf
mon.exe
[-] 2008-04-14 00:12 15360 5F1D5F88303D4A4DBC8E5F97BA
967CC3 c:\windows\system32\ctfmon
.exe
[-] 2006-10-19 20:08 57856 AD3D9D191AEA7B5445FE1D82FF
BB4788 c:\windows\$NtServicePackU
ninstall$\
spoolsv.ex
e
[-] 2008-04-14 00:12 57856 D8E14A61ACC1D4A6CD0D38AEBA
C7FA3B c:\windows\ServicePackFile
s\i386\spo
olsv.exe
[-] 2008-04-14 00:12 57856 D8E14A61ACC1D4A6CD0D38AEBA
C7FA3B c:\windows\system32\spools
v.exe
[-] 2004-08-04 04:56 24576 39B1FFB03C2296323832ACBAE5
0D2AFF c:\windows\$NtServicePackU
ninstall$\
userinit.e
xe
[-] 2008-04-14 00:12 26112 A93AEE1928A9D7CE3E16D24EC7
380F89 c:\windows\ServicePackFile
s\i386\use
rinit.exe
[-] 2008-04-14 00:12 26112 A93AEE1928A9D7CE3E16D24EC7
380F89 c:\windows\system32\userin
it.exe
[-] 2004-08-04 04:56 295424 B60C877D16D9C880B952FDA04A
DF16E6 c:\windows\$NtServicePackU
ninstall$\
termsrv.dl
l
[-] 2008-04-14 00:12 295424 FF3477C03BE7201C294C35F684
B3479F c:\windows\ServicePackFile
s\i386\ter
msrv.dll
[-] 2008-04-14 00:12 295424 FF3477C03BE7201C294C35F684
B3479F c:\windows\system32\termsr
v.dll
[-] 2009-03-21 13:59 991744 DA11D9D6ECBDF0F93436A4B7C1
3F7BEC c:\windows\$hf_mig$\KB9594
26\SP3QFE\
kernel32.d
ll
[-] 2007-04-16 16:07 986112 09F7CB3687F86EDAA4CA081F7A
B66C03 c:\windows\$NtServicePackU
ninstall$\
kernel32.d
ll
[-] 2008-04-14 00:11 989696 C24B983D211C34DA8FCC1AC384
77971D c:\windows\$NtUninstallKB9
59426$\ker
nel32.dll
[-] 2008-04-14 00:11 989696 C24B983D211C34DA8FCC1AC384
77971D c:\windows\ServicePackFile
s\i386\ker
nel32.dll
[-] 2009-03-21 14:06 989696 B921FB870C9AC0D509B2CCABBB
BE95F3 c:\windows\system32\kernel
32.dll
[-] 2009-03-21 14:06 989696 B921FB870C9AC0D509B2CCABBB
BE95F3 c:\windows\system32\dllcac
he\kernel3
2.dll
[-] 2004-08-04 04:56 17408 1B5F6923ABB450692E9FE0672C
897AED c:\windows\$NtServicePackU
ninstall$\
powrprof.d
ll
[-] 2008-04-14 00:12 17408 50A166237A0FA771261275A405
646CC0 c:\windows\ServicePackFile
s\i386\pow
rprof.dll
[-] 2008-04-14 00:12 17408 50A166237A0FA771261275A405
646CC0 c:\windows\system32\powrpr
of.dll
[-] 2004-08-04 04:56 110080 87CA7CE6469577F059297B9D65
56D66D c:\windows\$NtServicePackU
ninstall$\
imm32.dll
[-] 2008-04-14 00:11 110080 0DA85218E92526972A821587E6
A8BF8F c:\windows\ServicePackFile
s\i386\imm
32.dll
[-] 2008-04-14 00:11 110080 0DA85218E92526972A821587E6
A8BF8F c:\windows\system32\imm32.
dll
[-] 2008-03-01 13:03 3593216 4EE273E2B09317C1217EF0DB91
F93534 c:\windows\$hf_mig$\KB9478
64-IE7\SP2
QFE\mshtml
.dll
[-] 2008-04-23 03:35 3593728 4D612FF5D3B7EEF200595AE6F9
5D5E68 c:\windows\$hf_mig$\KB9507
59-IE7\SP2
QFE\mshtml
.dll
[-] 2008-06-23 16:01 3594240 28B8231CA8D55FC85E027A57C9
0F5C88 c:\windows\$hf_mig$\KB9538
38-IE7\SP2
QFE\mshtml
.dll
[-] 2008-08-26 09:08 3594752 25CC085720EE3617FD1F8AB9E2
F7CAB2 c:\windows\$hf_mig$\KB9563
90-IE7\SP2
QFE\mshtml
.dll
[-] 2008-10-16 20:24 3595264 B74F31A4BD83797D7A083F9221
69287D c:\windows\$hf_mig$\KB9582
15-IE7\SP2
QFE\mshtml
.dll
[-] 2008-12-13 06:26 3594752 C79FAD61CD4A26ED5AA8C16D99
1C6FBD c:\windows\$hf_mig$\KB9607
14-IE7\SP2
QFE\mshtml
.dll
[-] 2009-01-16 16:24 3596288 CC9D001B7370B292C35B366CA0
5B12B4 c:\windows\$hf_mig$\KB9612
60-IE7\SP2
QFE\mshtml
.dll
[-] 2009-02-21 07:39 3596800 1BB754AB47B327DE8DBF2FA18C
36357C c:\windows\$hf_mig$\KB9630
27-IE7\SP3
QFE\mshtml
.dll
[-] 2009-04-29 04:49 3598336 C6FD770D518FB024245A0EE217
D72BC1 c:\windows\$hf_mig$\KB9698
97-IE7\SP3
QFE\mshtml
.dll
[-] 2006-10-19 20:12 3058176 D251679BD9EF0250201FB899EC
40FD32 c:\windows\ie7\mshtml.dll
[-] 2007-08-13 23:54 3578368 C6EC2493346ED8888A549F5921
0A8ED3 c:\windows\ie7updates\KB94
2615-IE7\m
shtml.dll
[-] 2007-10-31 10:12 3590656 8AB7ECF59D6EBBE986277B65ED
4A40A1 c:\windows\ie7updates\KB94
4533-IE7\m
shtml.dll
[-] 2007-12-08 05:21 3592192 A097C36412455F0C7E42377FAF
8809B7 c:\windows\ie7updates\KB94
7864-IE7\m
shtml.dll
[-] 2008-03-01 22:36 3591680 AB2C88167D78D71D93558ACECB
24CC7A c:\windows\ie7updates\KB95
0759-IE7\m
shtml.dll
[-] 2008-04-24 02:16 3591680 8976CAB317105F7431B08EA32A
B73C65 c:\windows\ie7updates\KB95
3838-IE7\m
shtml.dll
[-] 2008-06-24 14:57 3592192 EC936148284F557F19C3331787
68109B c:\windows\ie7updates\KB95
6390-IE7\m
shtml.dll
[-] 2008-08-27 08:24 3593216 1AD035E04A7068EC2820B055A3
131ED8 c:\windows\ie7updates\KB95
8215-IE7\m
shtml.dll
[-] 2008-10-17 07:08 3593216 EACAEDEF6FA2A969DE5B36190D
45396F c:\windows\ie7updates\KB96
0714-IE7\m
shtml.dll
[-] 2008-12-13 06:40 3593216 121EC39A64D64205A88C2C45B0
34B455 c:\windows\ie7updates\KB96
1260-IE7\m
shtml.dll
[-] 2009-01-17 02:35 3594752 3B413267DA8AE71C20E5EF3E54
F74728 c:\windows\ie7updates\KB96
3027-IE7\m
shtml.dll
[-] 2009-02-20 18:09 3595264 C7C3E41CC2F6EB4A629FE21841
36C098 c:\windows\ie7updates\KB96
9897-IE7\m
shtml.dll
[-] 2008-04-14 00:11 3066880 A706E122B398FE1AB85CB9B75D
044223 c:\windows\ServicePackFile
s\i386\msh
tml.dll
[-] 2009-04-29 04:56 3596288 2B4315EC9E3124408A2A5074C4
B97700 c:\windows\SoftwareDistrib
ution\Down
load\82c73
8ec00f0f07
f8ea182bc9
5439593\sp
3gdr\mshtm
l.dll
[-] 2009-04-29 04:49 3598336 C6FD770D518FB024245A0EE217
D72BC1 c:\windows\SoftwareDistrib
ution\Down
load\82c73
8ec00f0f07
f8ea182bc9
5439593\sp
3qfe\mshtm
l.dll
[-] 2007-10-31 10:12 3590656 8AB7ECF59D6EBBE986277B65ED
4A40A1 c:\windows\SoftwareDistrib
ution\Down
load\e3709
fbfd9557a7
d083f543d5
1d38612\SP
2GDR\mshtm
l.dll
[-] 2007-10-30 23:48 3593216 54D8B404F17AA74C666F7F3AEF
2AE459 c:\windows\SoftwareDistrib
ution\Down
load\e3709
fbfd9557a7
d083f543d5
1d38612\SP
2QFE\mshtm
l.dll
[-] 2007-10-30 09:55 3065856 79314A0A6B0DA78AFE491FF2D8
B117BA c:\windows\SoftwareDistrib
ution\Down
load\fa582
43222bcfe3
5e5467668d
f396003\sp
2qfe\mshtm
l.dll
[-] 2009-04-29 04:56 3596288 2B4315EC9E3124408A2A5074C4
B97700 c:\windows\system32\mshtml
.dll
[-] 2009-04-29 04:56 3596288 2B4315EC9E3124408A2A5074C4
B97700 c:\windows\system32\dllcac
he\mshtml.
dll
[-] 2004-08-04 02:58 24576 EBDEE8A2EE5393890A1ACEE971
C4C246 c:\windows\$NtServicePackU
ninstall$\
kbdclass.s
ys
[-] 2008-04-13 18:39 24576 463C1EC80CD17420A542B7F36A
36F128 c:\windows\ServicePackFile
s\i386\kbd
class.sys
[-] 2008-04-13 18:39 24576 463C1EC80CD17420A542B7F36A
36F128 c:\windows\system32\driver
s\kbdclass
.sys
[-] 2004-08-04 04:56 792064 6728270CB7DBB776ED086F5AC4
C82310 c:\windows\$NtServicePackU
ninstall$\
comres.dll
[-] 2008-04-14 00:11 792064 1280A158C722FA95A80FB7AEBE
78FA7D c:\windows\ServicePackFile
s\i386\com
res.dll
[-] 2008-04-14 00:11 792064 1280A158C722FA95A80FB7AEBE
78FA7D c:\windows\system32\comres
.dll
[-] 2004-08-04 04:56 22016 74D66B3DE265E8789153414E75
175F26 c:\windows\$NtServicePackU
ninstall$\
lpk.dll
[-] 2008-04-14 00:11 22016 012DF358CEBAA23ACB26D82077
820817 c:\windows\ServicePackFile
s\i386\lpk
.dll
[-] 2008-04-14 00:11 22016 012DF358CEBAA23ACB26D82077
820817 c:\windows\system32\lpk.dl
l
[-] 2001-08-23 12:00 4224 DA1F27D85E0D1525F6621372E7
B685E9 c:\windows\system32\dllcac
he\beep.sy
s
[-] 2001-08-23 12:00 4224 DA1F27D85E0D1525F6621372E7
B685E9 c:\windows\system32\driver
s\beep.sys
[-] 2001-08-23 12:00 2944 73C1E1F395918BC2C6DD67AF75
91A3AD c:\windows\system32\dllcac
he\null.sy
s
[-] 2001-08-23 12:00 2944 73C1E1F395918BC2C6DD67AF75
91A3AD c:\windows\system32\driver
s\null.sys
[-] 2006-02-15 00:22 142464 1EE7B434BA961EF845DE136224
C30FEC c:\windows\$NtServicePackU
ninstall$\
aec.sys
[-] 2008-04-13 16:39 142592 8BED39E3C35D6A489438B81417
17A557 c:\windows\ServicePackFile
s\i386\aec
.sys
[-] 2008-04-13 16:39 142592 8BED39E3C35D6A489438B81417
17A557 c:\windows\system32\driver
s\aec.sys
[-] 2006-11-01 19:17 927504 925F8B61ED301A317BA850EBEE
CBDAA0 c:\windows\$NtServicePackU
ninstall$\
mfc40u.dll
[-] 2008-04-14 00:11 927504 CDDD4416B2B4C7295FE3FDB6DD
E57E4E c:\windows\ServicePackFile
s\i386\mfc
40u.dll
[-] 2008-04-14 00:11 927504 CDDD4416B2B4C7295FE3FDB6DD
E57E4E c:\windows\system32\mfc40u
.dll
[-] 2009-02-09 10:56 401408 9222562D44021B988B9F9F6220
7FB6F2 c:\windows\$hf_mig$\KB9565
72\SP3QFE\
rpcss.dll
[-] 2006-10-19 20:09 398336 C369DF215D352B6F3A0B8C3469
AA34F8 c:\windows\$NtServicePackU
ninstall$\
rpcss.dll
[-] 2008-04-14 00:12 399360 2589FE6015A316C0F5D5112B4D
A7B509 c:\windows\$NtUninstallKB9
56572$\rpc
ss.dll
[-] 2008-04-14 00:12 399360 2589FE6015A316C0F5D5112B4D
A7B509 c:\windows\ServicePackFile
s\i386\rpc
ss.dll
[-] 2009-02-09 12:10 401408 6B27A5C03DFB94B42457390654
31322C c:\windows\system32\rpcss.
dll
[-] 2009-02-09 12:10 401408 6B27A5C03DFB94B42457390654
31322C c:\windows\system32\dllcac
he\rpcss.d
ll
[-] 2004-08-04 04:56 33792 95FD808E4AC22ABA025A7B3EAC
0375D2 c:\windows\$NtServicePackU
ninstall$\
msgsvc.dll
[-] 2008-04-14 00:11 33792 986B1FF5814366D71E0AC5755C
88F2D3 c:\windows\ServicePackFile
s\i386\msg
svc.dll
[-] 2008-04-14 00:11 33792 986B1FF5814366D71E0AC5755C
88F2D3 c:\windows\system32\msgsvc
.dll
[-] 2006-10-19 20:13 617472 B0124CB21D28B1C9F678B566B6
B57D92 c:\windows\$NtServicePackU
ninstall$\
comctl32.d
ll
[-] 2008-04-14 00:11 617472 06F247492BC786CE5C24A23E17
8C711A c:\windows\ServicePackFile
s\i386\com
ctl32.dll
[-] 2008-04-14 00:11 617472 06F247492BC786CE5C24A23E17
8C711A c:\windows\system32\comctl
32.dll
[-] 2001-08-23 12:00 921088 AEF3D788DBF40C7C4D204EA45E
B0C505 c:\windows\WinSxS\x86_Micr
osoft.Wind
ows.Common
-Controls_
6595b64144
ccf1df_6.0
.0.0_x-ww_
1382d70a\c
omctl32.dl
l
[-] 2004-08-04 04:57 1050624 5AF68A5E44734A082442668E9C
787743 c:\windows\WinSxS\x86_Micr
osoft.Wind
ows.Common
-Controls_
6595b64144
ccf1df_6.0
.2600.2180
_x-ww_a84f
1ff9\comct
l32.dll
[-] 2008-04-14 00:12 1054208 BD38D1EBE24A46BD3EDA059560
AFBA12 c:\windows\WinSxS\x86_Micr
osoft.Wind
ows.Common
-Controls_
6595b64144
ccf1df_6.0
.2600.5512
_x-ww_35d4
ce83\comct
l32.dll
[-] 2001-08-23 12:00 11648 9859C0F6936E723E4892D7141B
1327D5 c:\windows\system32\driver
s\acpiec.s
ys
[-] 2004-08-04 04:56 5120 E8A12A12EA9088B4327D49EDCA
3ADD3E c:\windows\$NtServicePackU
ninstall$\
sfc.dll
[-] 2008-04-14 00:12 5120 96E1C926F22EE1BFBAE82901A3
5F6BF3 c:\windows\ServicePackFile
s\i386\sfc
.dll
[-] 2008-04-14 00:12 5120 96E1C926F22EE1BFBAE82901A3
5F6BF3 c:\windows\system32\sfc.dl
l
[-] 2004-08-04 04:56 407040 96353FCECBA774BB8DA74A1C65
07015A c:\windows\$NtServicePackU
ninstall$\
netlogon.d
ll
[-] 2008-04-14 00:12 407040 1B7F071C51B77C272875C3A23E
1E4550 c:\windows\ServicePackFile
s\i386\net
logon.dll
[-] 2008-04-14 00:12 407040 1B7F071C51B77C272875C3A23E
1E4550 c:\windows\system32\netlog
on.dll
[-] 2004-08-04 04:56 382464 2C69EC7E5A311334D10DD95F33
8FCCEA c:\windows\$NtServicePackU
ninstall$\
qmgr.dll
[-] 2008-04-14 00:12 409088 574738F61FCA2935F5265DC4E5
691314 c:\windows\ServicePackFile
s\i386\qmg
r.dll
[-] 2008-04-14 00:12 409088 574738F61FCA2935F5265DC4E5
691314 c:\windows\system32\qmgr.d
ll
[-] 2008-04-14 00:12 409088 574738F61FCA2935F5265DC4E5
691314 c:\windows\system32\bits\q
mgr.dll
[-] 2004-08-04 04:56 180224 0F78E27F563F2AAF74B91A49E2
ABF19A c:\windows\$NtServicePackU
ninstall$\
scecli.dll
[-] 2008-04-14 00:12 181248 A86BB5E61BF3E39B62AB4C7E70
85A084 c:\windows\ServicePackFile
s\i386\sce
cli.dll
[-] 2008-04-14 00:12 181248 A86BB5E61BF3E39B62AB4C7E70
85A084 c:\windows\system32\scecli
.dll
[-] 2004-08-04 04:56 55808 82B24CB70E5944E6E34662205A
2A5B78 c:\windows\$NtServicePackU
ninstall$\
eventlog.d
ll
[-] 2008-04-14 00:11 56320 6D4FEB43EE538FC5428CC7F056
5AA656 c:\windows\ServicePackFile
s\i386\eve
ntlog.dll
[-] 2008-04-14 00:11 60928 !HASH: COULD NOT OPEN FILE !!!!! c:\windows\system32\eventl
og.dll
[-] 2004-08-04 03:05 14336 02000ABF34AF4C218C35D25702
4807D6 c:\windows\$NtServicePackU
ninstall$\
asyncmac.s
ys
[-] 2008-04-13 18:57 14336 B153AFFAC761E7F5FCFA822B9C
4E97BC c:\windows\ServicePackFile
s\i386\asy
ncmac.sys
[-] 2008-04-13 18:57 14336 B153AFFAC761E7F5FCFA822B9C
4E97BC c:\windows\system32\driver
s\asyncmac
.sys
[-] 2007-02-09 11:10 574464 19A811EF5F1ED5C926A028CE10
7FF1AF c:\windows\$NtServicePackU
ninstall$\
ntfs.sys
[-] 2008-04-13 19:15 574976 78A08DD6A8D65E697C18E1DB01
C5CDCA c:\windows\ServicePackFile
s\i386\ntf
s.sys
[-] 2008-04-13 19:15 574976 78A08DD6A8D65E697C18E1DB01
C5CDCA c:\windows\system32\driver
s\ntfs.sys
[-] 2005-01-28 18:44 25088 140EF97B64F560FD78643CAE2C
DAD838 c:\windows\RegisteredPacka
ges\{30C72
34B-6482-4
A55-A11D-E
CD9030313F
2}\MsPMSNS
v.dll
[-] 2004-08-04 04:56 52224 C086483E3DBA8C1C0A687EC8D5
B3D4C1 c:\windows\RegisteredPacka
ges\{30C72
34B-6482-4
A55-A11D-E
CD9030313F
2}$BACKUP$
\System\Ms
PMSNSv.dll
[-] 2006-10-19 02:47 27136 C51B4A5C05A5475708E3C81C77
65B71D c:\windows\system32\mspmsn
sv.dll
[-] 2006-10-19 02:47 27136 C51B4A5C05A5475708E3C81C77
65B71D c:\windows\system32\dllcac
he\mspmsns
v.dll
[-] 2004-08-04 04:56 129536 EEF46DAB68229A14DA3D8E73C9
9E2959 c:\windows\$NtServicePackU
ninstall$\
xmlprov.dl
l
[-] 2008-04-14 00:12 129024 295D21F14C335B53CB8154E5B1
F892B9 c:\windows\ServicePackFile
s\i386\xml
prov.dll
[-] 2008-04-14 00:12 129024 295D21F14C335B53CB8154E5B1
F892B9 c:\windows\system32\xmlpro
v.dll
[-] 2004-08-04 04:56 60416 10654F9DDCEA9C46CFB7755423
1BE73B c:\windows\$NtServicePackU
ninstall$\
cryptsvc.d
ll
[-] 2008-04-14 00:11 62464 3D4E199942E29207970E04315D
02AD3B c:\windows\ServicePackFile
s\i386\cry
ptsvc.dll
[-] 2008-04-14 00:11 62464 3D4E199942E29207970E04315D
02AD3B c:\windows\system32\crypts
vc.dll
[-] 2004-08-04 04:56 77312 E3CFCCDDA4EDD1D0DC9168B2E1
8F27B8 c:\windows\$NtServicePackU
ninstall$\
browser.dl
l
[-] 2008-04-14 00:11 77824 A06CE3399D16DB864F55FAEB1F
1927A9 c:\windows\ServicePackFile
s\i386\bro
wser.dll
[-] 2008-04-14 00:11 77824 A06CE3399D16DB864F55FAEB1F
1927A9 c:\windows\system32\browse
r.dll
[-] 2006-10-19 20:07 249344 1418A3A6E76E5A2E3F5E43866E
793A8B c:\windows\$NtServicePackU
ninstall$\
tapisrv.dl
l
[-] 2008-04-14 00:12 249856 3CB78C17BB664637787C9A1C98
F79C38 c:\windows\ServicePackFile
s\i386\tap
isrv.dll
[-] 2008-04-14 00:12 249856 3CB78C17BB664637787C9A1C98
F79C38 c:\windows\system32\tapisr
v.dll
[-] 2008-06-20 17:46 245248 832E4DD8964AB7ACC880B2837C
B1ED20 c:\windows\$hf_mig$\KB9517
48\SP3GDR\
mswsock.dl
l
[-] 2008-06-20 17:43 245248 FCEE5FCB99F7C724593365C706
D28388 c:\windows\$hf_mig$\KB9517
48\SP3QFE\
mswsock.dl
l
[-] 2008-06-20 17:36 245248 1DFCA7713EA5A70D5D93B436AE
A0317A c:\windows\$NtServicePackU
ninstall$\
mswsock.dl
l
[-] 2008-04-14 00:12 245248 B4138E99236F0F57D4CF49BAE9
8A0746 c:\windows\$NtUninstallKB9
51748$\msw
sock.dll
[-] 2004-08-04 04:56 245248 4E74AF063C3271FBEA20DD940C
FD1184 c:\windows\$NtUninstallKB9
51748_0$\m
swsock.dll
[-] 2008-04-14 00:12 245248 B4138E99236F0F57D4CF49BAE9
8A0746 c:\windows\ServicePackFile
s\i386\msw
sock.dll
[-] 2008-06-20 17:46 245248 832E4DD8964AB7ACC880B2837C
B1ED20 c:\windows\system32\mswsoc
k.dll
[-] 2008-06-20 17:46 245248 832E4DD8964AB7ACC880B2837C
B1ED20 c:\windows\system32\dllcac
he\mswsock
.dll
[-] 2006-10-19 20:10 197632 3516D8A18B36784B1005B950B8
4232E1 c:\windows\$NtServicePackU
ninstall$\
netman.dll
[-] 2008-04-14 00:12 198144 13E67B55B3ABD7BF3FE7AAE5A0
F9A9DE c:\windows\ServicePackFile
s\i386\net
man.dll
[-] 2008-04-14 00:12 198144 13E67B55B3ABD7BF3FE7AAE5A0
F9A9DE c:\windows\system32\netman
.dll
[-] 2008-07-07 20:26 253952 D4991D98F2DB73C60D042F1AEF
79EFAE c:\windows\$hf_mig$\KB9509
74\SP3GDR\
es.dll
[-] 2008-07-07 20:23 253952 F17F6226BDC0CD5F0BEF0DAF84
D29BEC c:\windows\$hf_mig$\KB9509
74\SP3QFE\
es.dll
[-] 2008-07-07 20:06 253952 A4AB3DCA4A383F0DF4988ABDEB
84F9A4 c:\windows\$NtServicePackU
ninstall$\
es.dll
[-] 2008-04-14 00:11 246272 19A799805B24990867B00C120D
300C3A c:\windows\$NtUninstallKB9
50974$\es.
dll
[-] 2006-10-19 20:09 243200 95F5FEA4C6DE2C3F28784D0DCC
8F0DD3 c:\windows\$NtUninstallKB9
50974_0$\e
s.dll
[-] 2008-04-14 00:11 246272 19A799805B24990867B00C120D
300C3A c:\windows\ServicePackFile
s\i386\es.
dll
[-] 2008-07-07 20:26 253952 D4991D98F2DB73C60D042F1AEF
79EFAE c:\windows\system32\es.dll
[-] 2008-07-07 20:26 253952 D4991D98F2DB73C60D042F1AEF
79EFAE c:\windows\system32\dllcac
he\es.dll
[-] 2004-08-04 04:56 170496 92BDF74F12D6CBEC43C94D4B7F
804838 c:\windows\$NtServicePackU
ninstall$\
srsvc.dll
[-] 2008-04-14 00:12 171008 3805DF0AC4296A34BA4BF93B34
6CC378 c:\windows\ServicePackFile
s\i386\srs
vc.dll
[-] 2008-04-14 00:12 171008 3805DF0AC4296A34BA4BF93B34
6CC378 c:\windows\system32\srsvc.
dll
[-] 2004-08-04 04:56 13824 49911DD39E023BB6C45E4E436C
FBD297 c:\windows\$NtServicePackU
ninstall$\
wscntfy.ex
e
[-] 2008-04-14 00:12 13824 F92E1076C42FCD6DB3D72D8CFE
9816D5 c:\windows\ServicePackFile
s\i386\wsc
ntfy.exe
[-] 2008-04-14 00:12 13824 F92E1076C42FCD6DB3D72D8CFE
9816D5 c:\windows\system32\wscntf
y.exe
[-] 2004-08-04 04:56 435200 B62F29C00AC55A761B2E45877D
85EA0F c:\windows\$NtServicePackU
ninstall$\
ntmssvc.dl
l
[-] 2008-04-14 00:12 435200 156F64A3345BD23C600655FB4D
10BC08 c:\windows\ServicePackFile
s\i386\ntm
ssvc.dll
[-] 2008-04-14 00:12 435200 156F64A3345BD23C600655FB4D
10BC08 c:\windows\system32\ntmssv
c.dll
[-] 2004-08-04 04:56 89088 44DB7A9BDD2FB58747D123FBF1
D35ADB c:\windows\$NtServicePackU
ninstall$\
rasauto.dl
l
[-] 2008-04-14 00:12 88576 AD188BE7BDF94E8DF4CA0A55C0
0A5073 c:\windows\ServicePackFile
s\i386\ras
auto.dll
[-] 2008-04-14 00:12 88576 AD188BE7BDF94E8DF4CA0A55C0
0A5073 c:\windows\system32\rasaut
o.dll
[-] 2004-08-04 04:56 1580544 30A609E00BD1D4FFC49D6B5A43
2BE7F2 c:\windows\$NtServicePackU
ninstall$\
sfcfiles.d
ll
[-] 2008-04-14 00:12 1614848 9DD07AF82244867CA36681EA2D
29CE79 c:\windows\ServicePackFile
s\i386\sfc
files.dll
[-] 2008-04-14 00:12 1614848 9DD07AF82244867CA36681EA2D
29CE79 c:\windows\system32\sfcfil
es.dll
[-] 2004-08-04 04:56 190976 92360854316611F6CC47161221
3C3D92 c:\windows\$NtServicePackU
ninstall$\
schedsvc.d
ll
[-] 2008-04-14 00:12 192512 0A9A7365A1CA4319AA7C1D6CD8
E4EAFA c:\windows\ServicePackFile
s\i386\sch
edsvc.dll
[-] 2008-04-14 00:12 192512 0A9A7365A1CA4319AA7C1D6CD8
E4EAFA c:\windows\system32\scheds
vc.dll
[-] 2004-08-04 04:56 59904 3151427DB7D87107D1C5BE58FA
C53960 c:\windows\$NtServicePackU
ninstall$\
regsvc.dll
[-] 2008-04-14 00:12 59904 5B19B557B0C188210A56A6B699
D90B8F c:\windows\ServicePackFile
s\i386\reg
svc.dll
[-] 2008-04-14 00:12 59904 5B19B557B0C188210A56A6B699
D90B8F c:\windows\system32\regsvc
.dll
[-] 2004-08-04 04:56 71680 4B8D61792F7175BED48859CC18
CE4E38 c:\windows\$NtServicePackU
ninstall$\
ssdpsrv.dl
l
[-] 2008-04-14 00:12 71680 0A5679B3714EDAB99E357057EE
88FCA6 c:\windows\ServicePackFile
s\i386\ssd
psrv.dll
[-] 2008-04-14 00:12 71680 0A5679B3714EDAB99E357057EE
88FCA6 c:\windows\system32\ssdpsr
v.dll
[-] 2007-02-05 20:17 185344 ACA5D98663D879C6BAAFCEA7E2
F1B710 c:\windows\$NtServicePackU
ninstall$\
upnphost.d
ll
[-] 2008-04-14 00:12 185856 1EBAFEB9A3FBDC41B8D9C7F0F6
87AD91 c:\windows\ServicePackFile
s\i386\upn
phost.dll
[-] 2008-04-14 00:12 185856 1EBAFEB9A3FBDC41B8D9C7F0F6
87AD91 c:\windows\system32\upnpho
st.dll
[-] 2006-12-19 21:50 135168 53D9184A21C5CBF600D918E51E
F3A7E5 c:\windows\$NtServicePackU
ninstall$\
shsvcs.dll
[-] 2008-04-14 00:12 135168 1926899BF9FFE2602B63074971
700412 c:\windows\ServicePackFile
s\i386\shs
vcs.dll
[-] 2008-04-14 00:12 135168 1926899BF9FFE2602B63074971
700412 c:\windows\system32\shsvcs
.dll
.
((((((((((((((((((((((((((
((( SnapShot@2009-08-19_18.43.
34 ))))))))))))))))))))))))))
))))))))))
)))))
.
+ 2009-08-19 19:06 . 2009-08-19 19:06 8192 c:\windows\ERUNT\SDFIX\Use
rs\0000000
2\UsrClass
.dat
- 2009-08-19 16:19 . 2009-08-19 16:19 8192 c:\windows\ERUNT\SDFIX\Use
rs\0000000
2\UsrClass
.dat
+ 2009-08-19 19:06 . 2009-08-19 19:06 1028096 c:\windows\ERUNT\SDFIX\Use
rs\0000000
1\NTUSER.D
AT
.
((((((((((((((((((((((((((
((((((((((
( Reg Loading Points ))))))))))))))))))))))))))
))))))))))
))))))))))
))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR
E\Microsof
t\Windows\
CurrentVer
sion\Run]
"ctfmon.exe"="c:\windows\s
ystem32\ct
fmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWA
RE\Microso
ft\Windows
\CurrentVe
rsion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-12 178712]
"RoxioDragToDisc"="c:\prog
ram files\Roxio\Drag-to-Disc\D
rgToDsc.ex
e" [2006-08-17 1116920]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInS
ystray.exe
" [2007-08-03 63048]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 52840]
"vptray"="c:\progra~1\SYMA
NT~1\VPTra
y.exe" [2007-03-14 125632]
"Client Access Service"="c:\program files\IBM\Client Access\cwbsvstr.exe" [2005-06-08 20530]
"Client Access Help Update"="c:\program files\IBM\Client Access\cwbinhlp.exe" [2005-06-08 24626]
"Client Access Check Version"="c:\program files\IBM\Client Access\cwbckver.exe" [2005-06-08 45106]
"Client Access Express Welcome"="c:\program files\IBM\Client Access\cwbwlwiz.exe" [2005-06-08 20480]
"Client Access PC5250 Sound"="c:\program files\IBM\Client Access\Emulator\pcssnd.exe
" [2005-06-08 40960]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe
" [2008-09-06 413696]
"JobHisInit"="c:\program files\RDS\RMClient\JobHisI
nit.exe" [2005-11-01 151552]
"MplSetUp"="c:\program files\RDS\RMClient\MplSetU
p.exe" [2005-06-01 40960]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\reals
ched.exe" [2009-03-16 198160]
"BlackBerryAutoUpdate"="c:
\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-07-02 623960]
"RoxWatchTray"="c:\program
files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWa
tchTray9.e
xe" [2009-04-11 236016]
"UnlockerAssistant"="c:\pr
ogram files\Unlocker\UnlockerAss
istant.exe
" [2006-09-07 15872]
[hkey_local_machine\softwa
re\microso
ft\windows
\currentve
rsion\expl
orer\Shell
ExecuteHoo
ks]
"{5AE067D3-9AFB-48E0-853A-
EBB7F4A000
DA}"= "c:\program files\SUPERAntiSpyware\SAS
SEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
nt\currentversion\winlogon
\notify\!S
ASWinLogon
]
2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SAS
WINLO.dll
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
nt\currentversion\winlogon
\notify\Go
ToAssist Express Customer]
2008-12-17 14:34 46392 ----a-w- c:\program files\Citrix\GoToAssist Express Customer\136\g2ax_winlogon
.dll
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
nt\currentversion\winlogon
\notify\LM
Iinit]
2008-10-20 19:58 87352 ----a-w- c:\windows\system32\LMIini
t.dll
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\securit
y center\Monitoring\Symantec
AntiVirus]
"DisableMonitoring"=dword:
00000001
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
standardpr
ofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
standardpr
ofile\Auth
orizedAppl
ications\L
ist]
"%windir%\\system32\\sessm
gr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"
=
"c:\\WINDOWS\\system32\\sp
ool\\drive
rs\\w32x86
\\3\\HP100
6MC.EXE"=
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
standardpr
ofile\Glob
allyOpenPo
rts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22
009
R2 gupdate1c9a5f289928a3c;Goo
gle Update Service (gupdate1c9a5f289928a3c);c
:\program files\Google\Update\Google
Update.exe
[2009-03-16 133104]
R3 GoToAssist Express Customer;GoToAssist Express Customer;c:\program files\Citrix\GoToAssist Express Customer\136\g2ax_service.
exe Start=service [x]
R3 HBMW;HBMW;c:\docume~1\dave
\LOCALS~1\
Temp\HBMW.
exe [x]
R3 SASENUM;SASENUM;c:\program
files\SUPERAntiSpyware\SAS
ENUM.SYS [2009-02-17 7408]
R4 LMIRfsClientNP;LMIRfsClien
tNP; [x]
S1 SASDIFSV;SASDIFSV;c:\progr
am files\SUPERAntiSpyware\SAS
DIFSV.SYS [2009-04-09 9968]
S1 SASKUTIL;SASKUTIL;c:\progr
am files\SUPERAntiSpyware\SAS
KUTIL.sys [2009-08-11 74480]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.s
ys [2008-02-28 12856]
S2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32
\drivers\L
MIRfsDrive
r.sys [2008-10-20 47640]
S2 SavRoam;SavRoam;c:\program
files\Symantec AntiVirus\SavRoam.exe [2007-03-14 116416]
S2 UNS;Intel(R) Active Management Technology User Notification Service;c:\program files\Intel\AMT\UNS.exe [2007-06-12 2521880]
S3 EraserUtilRebootDrv;Eraser
UtilReboot
Drv;c:\pro
gram files\Common Files\Symantec Shared\EENGINE\EraserUtilR
ebootDrv.s
ys [2009-03-01 101936]
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Contents of the 'Scheduled Tasks' folder
2009-08-19 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe [2008-05-01 12:43]
2009-08-19 c:\windows\Tasks\GoogleUpd
ateTaskMac
hineCore.j
ob
- c:\program files\Google\Update\Google
Update.exe
[2009-03-16 04:49]
2009-08-19 c:\windows\Tasks\GoogleUpd
ateTaskMac
hineUA.job
- c:\program files\Google\Update\Google
Update.exe
[2009-03-16 04:49]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://nycourts.gov/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Offic
e10\EXCEL.
EXE/3000
IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta
Trusted Zone: complusdata.com\citrix
TCP: {F4334BEC-3891-471B-8EE9-D
36C1D11BAA
2} = 10.24.190.162,213.174.139.
72
.
**************************
**********
**********
**********
**********
********
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-19 15:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
**********
**********
**********
**********
********
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Cpqarr
ay]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\CryptS
vc]
"ServiceDll"="%SystemRoot%
\System32\
cryptsvc.d
ll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Cwbnet
nt]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Cwbrxd
]
"ImagePath"="c:\windows\CW
BRXD.EXE"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\dac2w2
k]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\dac960
nt]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\DcomLa
unch]
"ServiceDll"="%SystemRoot%
\system32\
rpcss.dll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\DefWat
ch]
"ImagePath"="\"c:\program files\Symantec AntiVirus\DefWatch.exe\""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Dhcp]
"ServiceDll"="%SystemRoot%
\System32\
dhcpcsvc.d
ll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Disk]
"ImagePath"="system32\DRIV
ERS\disk.s
ys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\DLABMF
SM]
"ImagePath"="System32\DLA\
DLABMFSM.S
YS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\DLABOI
OM]
"ImagePath"="System32\DLA\
DLABOIOM.S
YS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\DLACDB
HM]
"ImagePath"="System32\Driv
ers\DLACDB
HM.SYS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\DLADRe
sM]
"ImagePath"="System32\DLA\
DLADResM.S
YS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\DLAIFS
_M]
"ImagePath"="System32\DLA\
DLAIFS_M.S
YS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\DLAOPI
OM]
"ImagePath"="System32\DLA\
DLAOPIOM.S
YS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\DLAPoo
lM]
"ImagePath"="System32\DLA\
DLAPoolM.S
YS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\DLARTL
_M]
"ImagePath"="System32\Driv
ers\DLARTL
_M.SYS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\DLAUDF
AM]
"ImagePath"="System32\DLA\
DLAUDFAM.S
YS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\DLAUDF
_M]
"ImagePath"="System32\DLA\
DLAUDF_M.S
YS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\dmadmi
n]
"ImagePath"="%SystemRoot%\
System32\d
madmin.exe
/com"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\dmboot
]
"ImagePath"="System32\driv
ers\dmboot
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\dmio]
"ImagePath"="System32\driv
ers\dmio.s
ys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\dmload
]
"ImagePath"="System32\driv
ers\dmload
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\dmserv
er]
"ServiceDll"="%SystemRoot%
\System32\
dmserver.d
ll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\DMusic
]
"ImagePath"="system32\driv
ers\DMusic
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Dnscac
he]
"ServiceDll"="%SystemRoot%
\System32\
dnsrslvr.d
ll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Dot3sv
c]
"ServiceDll"="%SystemRoot%
\System32\
dot3svc.dl
l"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Dot4]
"ImagePath"="system32\DRIV
ERS\Dot4.s
ys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Dot4Pr
int]
"ImagePath"="system32\DRIV
ERS\Dot4Pr
t.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Dot4Sc
an]
"ImagePath"="system32\DRIV
ERS\Dot4Sc
an.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\dot4uf
d]
"ImagePath"="system32\DRIV
ERS\hppauf
d0.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\dpti2o
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\drmkau
d]
"ImagePath"="system32\driv
ers\drmkau
d.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\DRVMCD
B]
"ImagePath"="System32\Driv
ers\DRVMCD
B.SYS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\DRVNDD
M]
"ImagePath"="System32\Driv
ers\DRVNDD
M.SYS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\e1expr
ess]
"ImagePath"="system32\DRIV
ERS\e1e513
2.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\EapHos
t]
"ServiceDll"="%SystemRoot%
\System32\
eapsvc.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\eeCtrl
]
"ImagePath"="\??\c:\progra
m files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Eraser
UtilReboot
Drv]
"ImagePath"="\??\c:\progra
m files\Common Files\Symantec Shared\EENGINE\EraserUtilR
ebootDrv.s
ys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ERSvc]
"ServiceDll"="%SystemRoot%
\System32\
ersvc.dll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Eventl
og]
"ImagePath"="%SystemRoot%\
system32\s
ervices.ex
e"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\EventS
ystem]
"ServiceDll"="c:\windows\s
ystem32\es
.dll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Fastfa
t]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\FastUs
erSwitchin
gCompatibi
lity]
"ServiceDll"="%SystemRoot%
\System32\
shsvcs.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Fdc]
"ImagePath"="system32\DRIV
ERS\fdc.sy
s"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Fips]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Flpydi
sk]
"ImagePath"="system32\DRIV
ERS\flpydi
sk.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\FltMgr
]
"ImagePath"="system32\driv
ers\fltmgr
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\FontCa
che3.0.0.0
]
"ImagePath"="c:\windows\Mi
crosoft.Ne
t\Framewor
k\v3.0\WPF
\Presentat
ionFontCac
he.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Fs_Rec
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Ftdisk
]
"ImagePath"="system32\DRIV
ERS\ftdisk
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\GoToAs
sist Express Customer]
"ImagePath"="\"c:\program files\Citrix\GoToAssist Express Customer\136\g2ax_service.
exe\" Start=service"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Gpc]
"ImagePath"="system32\DRIV
ERS\msgpc.
sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\gupdat
e1c9a5f289
928a3c]
"ImagePath"="\"c:\program files\Google\Update\Google
Update.exe
\" /svc"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\gusvc]
"ImagePath"="\"c:\program files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe\""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\HBMW]
"ImagePath"="c:\docume~1\d
ave\LOCALS
~1\Temp\HB
MW.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\HDAudB
us]
"ImagePath"="system32\DRIV
ERS\HDAudB
us.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\HECI]
"ImagePath"="system32\DRIV
ERS\HECI.s
ys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\helpsv
c]
"ServiceDll"="%WINDIR%\PCH
ealth\Help
Ctr\Binari
es\pchsvc.
dll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\HidSer
v]
"ServiceDll"="%SystemRoot%
\System32\
hidserv.dl
l"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\hidusb
]
"ImagePath"="system32\DRIV
ERS\hidusb
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\hkmsvc
]
"ServiceDll"="%SystemRoot%
\System32\
kmsvc.dll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\HP Port Resolver]
"ImagePath"="c:\windows\Sy
stem32\spo
ol\DRIVERS
\W32X86\3\
HPBPRO.EXE
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\HP Status Server]
"ImagePath"="c:\windows\Sy
stem32\spo
ol\DRIVERS
\W32X86\3\
HPBOID.EXE
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\HPFXBU
LK]
"ImagePath"="system32\driv
ers\hpfxbu
lk.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\hpn]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\hpqcxs
08]
"ServiceDll"="c:\program files\HP\Digital Imaging\bin\hpqcxs08.dll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\HPZid4
12]
"ImagePath"="system32\DRIV
ERS\HPZid4
12.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\HPZipr
12]
"ImagePath"="system32\DRIV
ERS\HPZipr
12.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\HPZius
12]
"ImagePath"="system32\DRIV
ERS\HPZius
12.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\HSF_DP
V]
"ImagePath"="system32\DRIV
ERS\HSX_DP
V.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\HSXHWB
S2]
"ImagePath"="system32\DRIV
ERS\HSXHWB
S2.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\HTTP]
"ImagePath"="System32\Driv
ers\HTTP.s
ys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\HTTPFi
lter]
"ServiceDll"="%SystemRoot%
\System32\
w3ssl.dll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\i2omgm
t]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\i2omp]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\i8042p
rt]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\IAANTM
ON]
"ImagePath"="c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ialm]
"ImagePath"="system32\DRIV
ERS\igxpmp
32.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\iaStor
]
"ImagePath"="system32\driv
ers\iaStor
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\IDrive
rT]
"ImagePath"="\"c:\program files\Common Files\InstallShield\Driver
\1050\Inte
l 32\IDriverT.exe\""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\idsvc]
"ImagePath"="\"c:\windows\
Microsoft.
NET\Framew
ork\v3.0\W
indows Communication Foundation\infocard.exe\""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Imapi]
"ImagePath"="system32\DRIV
ERS\imapi.
sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ImapiS
ervice]
"ImagePath"="%systemroot%\
system32\i
mapi.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\inetac
cs]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ini910
u]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Inport
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\IntelI
de]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\intelp
pm]
"ImagePath"="system32\DRIV
ERS\intelp
pm.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Ip6Fw]
"ImagePath"="system32\driv
ers\ip6fw.
sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\IpFilt
erDriver]
"ImagePath"="system32\DRIV
ERS\ipfltd
rv.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\IpInIp
]
"ImagePath"="system32\DRIV
ERS\ipinip
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\IpNat]
"ImagePath"="system32\DRIV
ERS\ipnat.
sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\IPSec]
"ImagePath"="system32\DRIV
ERS\ipsec.
sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\IRENUM
]
"ImagePath"="system32\DRIV
ERS\irenum
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ISAPIS
earch]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\isapnp
]
"ImagePath"="system32\DRIV
ERS\isapnp
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Kbdcla
ss]
"ImagePath"="system32\DRIV
ERS\kbdcla
ss.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\kbdhid
]
"ImagePath"="system32\DRIV
ERS\kbdhid
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\kmixer
]
"ImagePath"="system32\driv
ers\kmixer
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\KSecDD
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\lanman
server]
"ServiceDll"="%SystemRoot%
\System32\
srvsvc.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\lanman
workstatio
n]
"ServiceDll"="%SystemRoot%
\System32\
wkssvc.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\lbrtfd
c]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ldap]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Licens
eService]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\LiveUp
date]
"ImagePath"="\"c:\progra~1
\Symantec\
LIVEUP~1\L
UCOMS~1.EX
E\""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\LmHost
s]
"ServiceDll"="%SystemRoot%
\System32\
lmhsvc.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\LMIInf
o]
"ImagePath"="\??\c:\progra
m files\LogMeIn\x86\RaInfo.s
ys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\LMIMai
nt]
"ImagePath"="\"c:\program files\LogMeIn\x86\RaMaint.
exe\""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\lmimir
r]
"ImagePath"="system32\DRIV
ERS\lmimir
r.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\LMIRfs
ClientNP]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\LMIRfs
Driver]
"ImagePath"="\??\c:\window
s\system32
\drivers\L
MIRfsDrive
r.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\LMS]
"ImagePath"="c:\program files\Intel\AMT\LMS.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\LogMeI
n]
"ImagePath"="\"c:\program files\LogMeIn\x86\LogMeIn.
exe\""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\MDM]
"ImagePath"="\"c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe\""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\mdmxsd
k]
"ImagePath"="system32\DRIV
ERS\mdmxsd
k.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Messen
ger]
"ServiceDll"="%SystemRoot%
\System32\
msgsvc.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\mnmdd]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\mnmsrv
c]
"ImagePath"="c:\windows\sy
stem32\mnm
srvc.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Modem]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Moucla
ss]
"ImagePath"="system32\DRIV
ERS\moucla
ss.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\mouhid
]
"ImagePath"="system32\DRIV
ERS\mouhid
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\MountM
gr]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\mraid3
5x]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\MRxDAV
]
"ImagePath"="system32\DRIV
ERS\mrxdav
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\MRxSmb
]
"ImagePath"="system32\DRIV
ERS\mrxsmb
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\MSDTC]
"ImagePath"="c:\windows\sy
stem32\msd
tc.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\MSDTC Bridge 3.0.0.0]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Msfs]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\MSISer
ver]
"ImagePath"="%systemroot%\
system32\m
siexec.exe
/V"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\MSKSSR
V]
"ImagePath"="system32\driv
ers\MSKSSR
V.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\MSPCLO
CK]
"ImagePath"="system32\driv
ers\MSPCLO
CK.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\MSPQM]
"ImagePath"="system32\driv
ers\MSPQM.
sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\mssmbi
os]
"ImagePath"="system32\DRIV
ERS\mssmbi
os.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Mup]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\napage
nt]
"ServiceDll"="%SystemRoot%
\System32\
qagentrt.d
ll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\NAVENG
]
"ImagePath"="\??\c:\progra
~1\COMMON~
1\SYMANT~1
\VIRUSD~1\
20090815.0
03\naveng.
sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\NAVEX1
5]
"ImagePath"="\??\c:\progra
~1\COMMON~
1\SYMANT~1
\VIRUSD~1\
20090815.0
03\navex15
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\NDIS]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\NdisTa
pi]
"ImagePath"="system32\DRIV
ERS\ndista
pi.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Ndisui
o]
"ImagePath"="system32\DRIV
ERS\ndisui
o.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\NdisWa
n]
"ImagePath"="system32\DRIV
ERS\ndiswa
n.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\NDProx
y]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Net Driver HPZ12]
"ServiceDll"="c:\windows\s
ystem32\HP
Zinw12.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\NetBIO
S]
"ImagePath"="system32\DRIV
ERS\netbio
s.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\NetBT]
"ImagePath"="system32\DRIV
ERS\netbt.
sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\NetDDE
]
"ImagePath"="%SystemRoot%\
system32\n
etdde.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\NetDDE
dsdm]
"ImagePath"="%SystemRoot%\
system32\n
etdde.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Netlog
on]
"ImagePath"="%SystemRoot%\
system32\l
sass.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Netman
]
"ServiceDll"="%SystemRoot%
\System32\
netman.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\NetTcp
PortSharin
g]
"ImagePath"="\"c:\windows\
Microsoft.
NET\Framew
ork\v3.0\W
indows Communication Foundation\SMSvcHost.exe\"
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Nla]
"ServiceDll"="%SystemRoot%
\System32\
mswsock.dl
l"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Npfs]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Ntfs]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\NtLmSs
p]
"ImagePath"="%SystemRoot%\
system32\l
sass.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\NtmsSv
c]
"ServiceDll"="%SystemRoot%
\system32\
ntmssvc.dl
l"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Null]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\NwlnkF
lt]
"ImagePath"="system32\DRIV
ERS\nwlnkf
lt.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\NwlnkF
wd]
"ImagePath"="system32\DRIV
ERS\nwlnkf
wd.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ose]
"ImagePath"="\"c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE\""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Parpor
t]
"ImagePath"="system32\DRIV
ERS\parpor
t.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\PartMg
r]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ParVdm
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\PCI]
"ImagePath"="system32\DRIV
ERS\pci.sy
s"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\PCIDum
p]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\PCIIde
]
"ImagePath"="system32\DRIV
ERS\pciide
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Pcmcia
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\PDCOMP
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\PDFRAM
E]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\PDRELI
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\PDRFRA
ME]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\perc2]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\perc2h
ib]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\PerfDi
sk]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\PerfNe
t]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\PerfOS
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\PerfPr
oc]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\PlugPl
ay]
"ImagePath"="%SystemRoot%\
system32\s
ervices.ex
e"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Pml Driver HPZ12]
"ServiceDll"="c:\windows\s
ystem32\HP
Zipm12.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Policy
Agent]
"ImagePath"="%SystemRoot%\
system32\l
sass.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\PptpMi
niport]
"ImagePath"="system32\DRIV
ERS\rasppt
p.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Protec
tedStorage
]
"ImagePath"="%SystemRoot%\
system32\l
sass.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Protex
isLicensin
g]
"ImagePath"="c:\windows\sy
stem32\PSI
Service.ex
e"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\PSched
]
"ImagePath"="system32\DRIV
ERS\psched
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Ptilin
k]
"ImagePath"="system32\DRIV
ERS\ptilin
k.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\PxHelp
20]
"ImagePath"="System32\Driv
ers\PxHelp
20.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ql1080
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Ql10wn
t]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ql1216
0]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ql1240
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ql1280
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RasAcd
]
"ImagePath"="system32\DRIV
ERS\rasacd
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RasAut
o]
"ServiceDll"="%SystemRoot%
\System32\
rasauto.dl
l"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Rasl2t
p]
"ImagePath"="system32\DRIV
ERS\rasl2t
p.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RasMan
]
"ServiceDll"="%SystemRoot%
\System32\
rasmans.dl
l"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RasPpp
oe]
"ImagePath"="system32\DRIV
ERS\rasppp
oe.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Raspti
]
"ImagePath"="system32\DRIV
ERS\raspti
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Rdbss]
"ImagePath"="system32\DRIV
ERS\rdbss.
sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RDPCDD
]
"ImagePath"="System32\DRIV
ERS\RDPCDD
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RDPDD]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\rdpdr]
"ImagePath"="system32\DRIV
ERS\rdpdr.
sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RDPNP]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RDPWD]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RDSess
Mgr]
"ImagePath"="c:\windows\sy
stem32\ses
smgr.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\redboo
k]
"ImagePath"="system32\DRIV
ERS\redboo
k.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Remote
Access]
"ServiceDll"="%SystemRoot%
\System32\
mprdim.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Remote
Registry]
"ServiceDll"="%SystemRoot%
\system32\
regsvc.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RimUsb
]
"ImagePath"="System32\Driv
ers\RimUsb
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RimVSe
rPort]
"ImagePath"="system32\DRIV
ERS\RimSer
ial.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ROOTMO
DEM]
"ImagePath"="System32\Driv
ers\RootMd
m.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Roxio UPnP Renderer 9]
"ImagePath"="\"c:\program files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe\"
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Roxio Upnp Server 9]
"ImagePath"="\"c:\program files\Roxio\Digital Home 9\RoxioUpnpService9.exe\""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RoxLiv
eShare9]
"ImagePath"="\"c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLi
veShare9.e
xe\""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RoxMed
iaDB9]
"ImagePath"="\"c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMe
diaDB9.exe
\""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RoxWat
ch9]
"ImagePath"="\"c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWa
tch9.exe\"
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RpcLoc
ator]
"ImagePath"="%SystemRoot%\
system32\l
ocator.exe
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RpcSs]
"ServiceDll"="%SystemRoot%
\System32\
rpcss.dll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\RSVP]
"ImagePath"="%SystemRoot%\
system32\r
svp.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SamSs]
"ImagePath"="%SystemRoot%\
system32\l
sass.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SASDIF
SV]
"ImagePath"="\??\c:\progra
m files\SUPERAntiSpyware\SAS
DIFSV.SYS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SASENU
M]
"ImagePath"="\??\c:\progra
m files\SUPERAntiSpyware\SAS
ENUM.SYS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SASKUT
IL]
"ImagePath"="\??\c:\progra
m files\SUPERAntiSpyware\SAS
KUTIL.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SavRoa
m]
"ImagePath"="\"c:\program files\Symantec AntiVirus\SavRoam.exe\""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SAVRT]
"ImagePath"="\??\c:\progra
m files\Symantec AntiVirus\savrt.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SAVRTP
EL]
"ImagePath"="\??\c:\progra
m files\Symantec AntiVirus\Savrtpel.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SCardS
vr]
"ImagePath"="%SystemRoot%\
System32\S
CardSvr.ex
e"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Schedu
le]
"ServiceDll"="%SystemRoot%
\system32\
schedsvc.d
ll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ScsiPo
rt]
"ImagePath"="%SystemRoot%\
system32\d
rivers\scs
iport.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Secdrv
]
"ImagePath"="system32\DRIV
ERS\secdrv
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\seclog
on]
"ServiceDll"="%SystemRoot%
\System32\
seclogon.d
ll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SenFil
tService]
"ImagePath"="system32\driv
ers\Senfil
t.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SENS]
"ServiceDll"="%SystemRoot%
\system32\
sens.dll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\serenu
m]
"ImagePath"="system32\DRIV
ERS\serenu
m.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Serial
]
"ImagePath"="system32\DRIV
ERS\serial
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Servic
eModelEndp
oint 3.0.0.0]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Servic
eModelOper
ation 3.0.0.0]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Servic
eModelServ
ice 3.0.0.0]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Sflopp
y]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Shared
Access]
"ServiceDll"="%SystemRoot%
\System32\
ipnathlp.d
ll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ShellH
WDetection
]
"ServiceDll"="%SystemRoot%
\System32\
shsvcs.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Simbad
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SMSvcH
ost 3.0.0.0]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SNDSrv
c]
"ImagePath"="\"c:\program files\Common Files\Symantec Shared\SNDSrvc.exe\""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Sparro
w]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SPBBCD
rv]
"ImagePath"="\??\c:\progra
m files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SPBBCS
vc]
"ImagePath"="\"c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe\
""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\splitt
er]
"ImagePath"="system32\driv
ers\splitt
er.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Spoole
r]
"ImagePath"="%SystemRoot%\
system32\s
poolsv.exe
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\sr]
"ImagePath"="system32\DRIV
ERS\sr.sys
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\srserv
ice]
"ServiceDll"="%SystemRoot%
\system32\
srsvc.dll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Srv]
"ImagePath"="system32\DRIV
ERS\srv.sy
s"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SSDPSR
V]
"ServiceDll"="%SystemRoot%
\System32\
ssdpsrv.dl
l"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\stisvc
]
"ServiceDll"="%SystemRoot%
\system32\
wiaservc.d
ll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\swenum
]
"ImagePath"="system32\DRIV
ERS\swenum
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\swmidi
]
"ImagePath"="system32\driv
ers\swmidi
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SwPrv]
"ImagePath"="c:\windows\sy
stem32\dll
host.exe /Processid:{32FA57BF-B0F8-
469E-9C45-
18A3E337D4
96}"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\swwd]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Symant
ec AntiVirus]
"ImagePath"="\"c:\program files\Symantec AntiVirus\Rtvscan.exe\""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\symc81
0]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\symc8x
x]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SymEve
nt]
"ImagePath"="\??\c:\window
s\system32
\Drivers\S
YMEVENT.SY
S"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SYMRED
RV]
"ImagePath"="\SystemRoot\S
ystem32\Dr
ivers\SYMR
EDRV.SYS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\SYMTDI
]
"ImagePath"="\SystemRoot\S
ystem32\Dr
ivers\SYMT
DI.SYS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\sym_hi
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\sym_u3
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\sysaud
io]
"ImagePath"="system32\driv
ers\sysaud
io.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Sysmon
Log]
"ImagePath"="%SystemRoot%\
system32\s
mlogsvc.ex
e"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\TapiSr
v]
"ServiceDll"="%SystemRoot%
\System32\
tapisrv.dl
l"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Tcpip]
"ImagePath"="system32\DRIV
ERS\tcpip.
sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\TDPIPE
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\TDTCP]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\TermDD
]
"ImagePath"="system32\DRIV
ERS\termdd
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\TermSe
rvice]
"ServiceDll"="%SystemRoot%
\System32\
termsrv.dl
l"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Themes
]
"ServiceDll"="%SystemRoot%
\System32\
shsvcs.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\TlntSv
r]
"ImagePath"="c:\windows\sy
stem32\tln
tsvr.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\TosIde
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\TrkWks
]
"ServiceDll"="%SystemRoot%
\system32\
trkwks.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\TSDDD]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Udfs]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ultra]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\UNS]
"ImagePath"="c:\program files\Intel\AMT\UNS.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Update
]
"ImagePath"="system32\DRIV
ERS\update
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\upnpho
st]
"ServiceDll"="%SystemRoot%
\System32\
upnphost.d
ll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\UPS]
"ImagePath"="%SystemRoot%\
System32\u
ps.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\USB]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\usbccg
p]
"ImagePath"="system32\DRIV
ERS\usbccg
p.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\usbehc
i]
"ImagePath"="system32\DRIV
ERS\usbehc
i.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\usbhub
]
"ImagePath"="system32\DRIV
ERS\usbhub
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\usbpri
nt]
"ImagePath"="system32\DRIV
ERS\usbpri
nt.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\usbsca
n]
"ImagePath"="system32\DRIV
ERS\usbsca
n.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\USBSTO
R]
"ImagePath"="system32\DRIV
ERS\USBSTO
R.SYS"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\usbuhc
i]
"ImagePath"="system32\DRIV
ERS\usbuhc
i.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\VgaSav
e]
"ImagePath"="\SystemRoot\S
ystem32\dr
ivers\vga.
sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\ViaIde
]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\VolSna
p]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\VSS]
"ImagePath"="%SystemRoot%\
System32\v
ssvc.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\W32Tim
e]
"ServiceDll"="%systemroot%
\system32\
w32time.dl
l"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\W3SVC]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Wanarp
]
"ImagePath"="system32\DRIV
ERS\wanarp
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\wceusb
sh]
"ImagePath"="system32\DRIV
ERS\wceusb
sh.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\WDICA]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\wdmaud
]
"ImagePath"="system32\driv
ers\wdmaud
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\WebCli
ent]
"ServiceDll"="%SystemRoot%
\System32\
webclnt.dl
l"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\winach
sf]
"ImagePath"="system32\DRIV
ERS\HSX_CN
XT.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Window
s Workflow Foundation 3.0.0.0]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\winmgm
t]
"ServiceDll"="%SystemRoot%
\system32\
wbem\WMIsv
c.dll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Winsoc
k]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\WinSoc
k2]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\WinTru
st]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\WmdmPm
SN]
"ServiceDll"="c:\windows\s
ystem32\Ms
PMSNSv.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\Wmi]
"ServiceDll"="%SystemRoot%
\System32\
advapi32.d
ll"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\WmiApR
pl]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\WmiApS
rv]
"ImagePath"="c:\windows\sy
stem32\wbe
m\wmiapsrv
.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\WMPNet
workSvc]
"ImagePath"="\"c:\program files\Windows Media Player\WMPNetwk.exe\""
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\WS2IFS
L]
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\wscsvc
]
"ServiceDll"="%SYSTEMROOT%
\system32\
wscsvc.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\wuause
rv]
"ServiceDll"="c:\windows\s
ystem32\wu
auserv.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\WudfPf
]
"ImagePath"="system32\DRIV
ERS\WudfPf
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\WudfRd
]
"ImagePath"="system32\DRIV
ERS\wudfrd
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\WudfSv
c]
"ServiceDll"="%SystemRoot%
\System32\
WUDFSvc.dl
l"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\WZCSVC
]
"ServiceDll"="%SystemRoot%
\System32\
wzcsvc.dll
"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\XAudio
]
"ImagePath"="system32\DRIV
ERS\xaudio
.sys"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\XAudio
Service]
"ImagePath"="%SystemRoot%\
system32\D
RIVERS\xau
dio.exe"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\xmlpro
v]
"ServiceDll"="%SystemRoot%
\System32\
xmlprov.dl
l"
[HKEY_LOCAL_MACHINE\System
\ControlSe
t001\Servi
ces\{F4334
BEC-3891-4
71B-8EE9-D
36C1D11BAA
2}]
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1180)
c:\program files\SUPERAntiSpyware\SAS
WINLO.dll
c:\program files\Citrix\GoToAssist Express Customer\136\g2ax_winlogon
.dll
c:\windows\system32\LMIini
t.dll
c:\windows\system32\LMIRfs
ClientNP.d
ll
B7A97EBC.x86.dll 35670000 53248 \\?\globalroot\Device\__ma
x++>\B7A97
EBC.x86.dl
l
- - - - - - - > 'lsass.exe'(1236)
c:\program files\Bonjour\mdnsNSP.dll
- - - - - - - > 'explorer.exe'(744)
c:\program files\Unlocker\UnlockerHoo
k.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
c:\program files\Intel\AMT\atchksrv.e
xe
c:\program files\Bonjour\mDNSResponde
r.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\LogMeIn\x86\LMIGuard
ian.exe
c:\program files\Research In Motion\BlackBerry\DesktopM
gr.exe
c:\program files\RDS\PLTBar.exe
c:\program files\PrintKey2000\Printke
y2000.exe
c:\program files\RDS\RMClient\PMCTray
.exe
.
**************************
**********
**********
**********
**********
********
.
Completion time: 2009-08-19 15:37 - machine was rebooted
ComboFix-quarantined-files
.txt 2009-08-19 19:37
ComboFix2.txt 2009-08-19 18:57
ComboFix3.txt 2009-08-19 18:47
Pre-Run: 140,658,302,976 bytes free
Post-Run: 140,647,583,744 bytes free
1014 --- E O F --- 2009-06-11 16:03