tfm_master
2009-07-22, 15:50
Logfile of random's system information tool 1.06 (written by random/random)
Run by XPPRESP3 at 2009-07-22 21:51:10
Microsoft Windows XP Professional Service Pack 2
System drive C: has 9 GB (30%) free of 30 GB
Total RAM: 959 MB (47% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:51:42 PM, on 7/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
F:\source\فلاشه\BTNtService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\SweetIM\Messenger\SweetIM.exe
F:\source\DAEMON Tools Lite\daemon.exe
F:\source\فلاشه\BlueSoleil.exe
F:\source\Orbitdownloader youtube\orbitdm.exe
F:\source\Orbitdownloader youtube\orbitnet.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
F:\source\Winamp new player\winamp.exe
C:\Documents and Settings\XPPRESP3\Desktop\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\XPPRESP3.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.orbitdownloader.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favorites
R3 - URLSearchHook: Gossiper Toolbar - {0a452a47-c5a8-4854-a237-4b9b06b376f0} - C:\Program Files\Gossiper\tbGoss.dll
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
R3 - URLSearchHook: gamesfree Toolbar - {7ac1cacf-43d3-4b2b-861c-219bda77ecf1} - C:\Program Files\gamesfree\tbgame.dll
R3 - URLSearchHook: Freez Online TV Toolbar - {a4d09ede-8a9c-4090-a54d-5ada4f7fff35} - C:\Program Files\Freez_Online_TV\tbFree.dll
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - F:\source\Orbitdownloader youtube\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Gossiper Toolbar - {0a452a47-c5a8-4854-a237-4b9b06b376f0} - C:\Program Files\Gossiper\tbGoss.dll
O2 - BHO: XBTP02799 - {45CE3BD4-4C94-4c17-8067-769902BDE550} - C:\PROGRA~1\COMMON~1\System\xp\xp.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: gamesfree Toolbar - {7ac1cacf-43d3-4b2b-861c-219bda77ecf1} - C:\Program Files\gamesfree\tbgame.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Freez Online TV Toolbar - {a4d09ede-8a9c-4090-a54d-5ada4f7fff35} - C:\Program Files\Freez_Online_TV\tbFree.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - F:\source\Orbitdownloader youtube\GrabPro.dll
O3 - Toolbar: Gossiper Toolbar - {0a452a47-c5a8-4854-a237-4b9b06b376f0} - C:\Program Files\Gossiper\tbGoss.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: xp - {2367DE4F-065D-4638-8C41-4682D7969BAD} - C:\Program Files\Common Files\System\xp\xp.dll
O3 - Toolbar: gamesfree Toolbar - {7ac1cacf-43d3-4b2b-861c-219bda77ecf1} - C:\Program Files\gamesfree\tbgame.dll
O3 - Toolbar: Freez Online TV Toolbar - {a4d09ede-8a9c-4090-a54d-5ada4f7fff35} - C:\Program Files\Freez_Online_TV\tbFree.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [3PMmUpdate] rundll32 "C:\WINDOWS\Update.dll",Main
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [mvload32] C:\Program Files\Internet Explorer\PLUGINS\cxsrrs.exe
O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\msupdte.exe
O4 - HKLM\..\Run: [StormCodec_Helper] "F:\source\??I??CE\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [Adobe Photo Downloader] "F:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\Run: [3c550a27] rundll32.exe "C:\WINDOWS\system32\dgaxbxps.dll",b
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "F:\source\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [DAEMON Tools Lite] "F:\source\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [AdVantage] "C:\Program Files\AdVantage\AdVantage.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] ~"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\eHome" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Srchasst" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Help\Tours" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_05] cmd.exe /c md "%USERPROFILE%\Local Settings\Temp" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_06] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_07] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_08] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\eHome" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: Orbit.lnk = F:\source\Orbitdownloader youtube\orbitdm.exe
O8 - Extra context menu item: &Download by Orbit - res://F:\source\Orbitdownloader youtube\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://F:\source\Orbitdownloader youtube\orbitmxt.dll/204
O8 - Extra context menu item: + &Mass Downloader: تحميل هذا الملف - g:\Program Files\Mass Downloader\Add_Url.htm
O8 - Extra context menu item: + Mass Downloader: تحميل &كافة الملفات - g:\Program Files\Mass Downloader\Add_All.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Do&wnload selected by Orbit - res://F:\source\Orbitdownloader youtube\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://F:\source\Orbitdownloader youtube\orbitmxt.dll/202
O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\bin\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\bin\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\bin\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Translate with &Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Mass Downloader - {0FD01980-CCCB-11D3-80D4-0000E80E2EDE} - g:\Program Files\Mass Downloader\massdown.exe (file missing)
O9 - Extra 'Tools' menuitem: &Mass Downloader - {0FD01980-CCCB-11D3-80D4-0000E80E2EDE} - g:\Program Files\Mass Downloader\massdown.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.google.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{609E47E4-8026-43CD-827B-A5D15FCF92A9}: NameServer = 163.121.128.134 163.121.128.135
O17 - HKLM\System\CCS\Services\Tcpip\..\{7F97A107-5036-4717-9BF7-A2F6BE5436A7}: NameServer = 163.121.128.134,163.121.128.135
O17 - HKLM\System\CCS\Services\Tcpip\..\{8654ABC6-CFFA-42BC-83B2-AA8717D1FD3A}: NameServer = 163.121.128.134,163.121.128.135
O17 - HKLM\System\CCS\Services\Tcpip\..\{8CCE1487-7F06-4D61-9936-A6C99EE92E20}: NameServer = 163.121.128.134,163.121.128.135
O21 - SSODL: msnmsg - {DA191DE0-AA86-4ED0-4B87-293D48B2AE99} - C:\Program Files\Messenger\msgmr.dll (file missing)
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - F:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - F:\source\??CO?\BTNtService.exe (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Contrl Center of Storm Media (ccosm) - Unknown owner - F:\source\??I??CE\Storm Codec\stormliv.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MBAMService - Malwarebytes Corporation - F:\source\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Windows Driver Foundation - User-mode Driver Framework (WudfSvc) - Unknown owner - hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00 (file missing)
--
End of file - 14054 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Google Software Updater.job
C:\WINDOWS\tasks\gwmvtjws.job
C:\WINDOWS\tasks\XoftSpySE.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - F:\source\Orbitdownloader youtube\orbitcth.dll [2009-06-09 179400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-13 63128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0a452a47-c5a8-4854-a237-4b9b06b376f0}]
Gossiper Toolbar - C:\Program Files\Gossiper\tbGoss.dll [2008-09-15 1784856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45CE3BD4-4C94-4c17-8067-769902BDE550}]
XBTP02799 Class - C:\PROGRA~1\COMMON~1\System\xp\xp.dll [2006-07-11 544768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2008-12-04 92504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll [2006-05-03 434279]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7ac1cacf-43d3-4b2b-861c-219bda77ecf1}]
gamesfree Toolbar - C:\Program Files\gamesfree\tbgame.dll [2009-04-01 2086936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-11-18 408952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4d09ede-8a9c-4090-a54d-5ada4f7fff35}]
Freez Online TV Toolbar - C:\Program Files\Freez_Online_TV\tbFree.dll [2009-05-20 2085400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-03-28 668656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetIM Toolbar Helper - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2009-05-20 1258808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
Ask Toolbar BHO - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL [2008-10-30 262144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{C55BBCD6-41AD-48AD-9953-3609C48EACC7} - Grab Pro - F:\source\Orbitdownloader youtube\GrabPro.dll [2009-06-09 658552]
{0a452a47-c5a8-4854-a237-4b9b06b376f0} - Gossiper Toolbar - C:\Program Files\Gossiper\tbGoss.dll [2008-09-15 1784856]
{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - Ask Toolbar - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL [2008-10-30 262144]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetIM Toolbar for Internet Explorer - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2009-05-20 1258808]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]
{2367DE4F-065D-4638-8C41-4682D7969BAD} - xp - C:\Program Files\Common Files\System\xp\xp.dll [2006-07-11 544768]
{7ac1cacf-43d3-4b2b-861c-219bda77ecf1} - gamesfree Toolbar - C:\Program Files\gamesfree\tbgame.dll [2009-04-01 2086936]
{a4d09ede-8a9c-4090-a54d-5ada4f7fff35} - Freez Online TV Toolbar - C:\Program Files\Freez_Online_TV\tbFree.dll [2009-05-20 2085400]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"=C:\Program Files\Eset\nod32kui.exe [2008-10-20 921600]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-02-25 8491008]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-02-25 81920]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe [2006-05-03 36975]
"3PMmUpdate"=rundll32 C:\WINDOWS\Update.dll,Main []
"Babylon Client"=C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart []
"UserFaultCheck"=C:\WINDOWS\system32\dumprep 0 -u []
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-04-10 16861184]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"mvload32"=C:\Program Files\Internet Explorer\PLUGINS\cxsrrs.exe [2008-11-16 80896]
"Microsoft WinUpdate"=C:\WINDOWS\system32\msupdte.exe []
"StormCodec_Helper"=F:\source\كوديكات\Storm Codec\StormSet.exe [2006-09-30 96984]
"Adobe Photo Downloader"=F:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe [2007-09-11 67488]
"3c550a27"=C:\WINDOWS\system32\dgaxbxps.dll,b []
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"SweetIM"=C:\Program Files\SweetIM\Messenger\SweetIM.exe [2009-05-20 111928]
"Malwarebytes' Anti-Malware"=F:\source\Malwarebytes' Anti-Malware\mbamgui.exe [2009-07-13 414992]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"googletalk"=C:\Program Files\Google\Google Talk\googletalk.exe [2007-01-02 3739648]
"DAEMON Tools Lite"=F:\source\DAEMON Tools Lite\daemon.exe [2008-01-17 486856]
"AdVantage"=C:\Program Files\AdVantage\AdVantage.exe [2008-07-14 884176]
"Messenger (Yahoo!)"=~C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -quiet []
"cdoosoft"=C:\WINDOWS\system32\olhrwef.exe [2009-05-15 102664]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
BlueSoleil.lnk - F:\source\فلاشه\BlueSoleil.exe
Orbit.lnk - F:\source\Orbitdownloader youtube\orbitdm.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2006-05-31 52224]
msnmsg - {DA191DE0-AA86-4ED0-4B87-293D48B2AE99} - C:\Program Files\Messenger\msgmr.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{DE02F764-C51A-4788-9597-D78ECC2AC08F}"=DE02F764.dll []
"{43ACDCC5-9009-4AF4-B80A-93BC656EF298}"=43ACDCC5.dll []
"{58FF3024-8A83-4B1A-88E9-302F47646EEE}"=58FF3024.dll []
"{D91BC61E-7D78-4A2A-A336-7B97E8E52F0B}"=D91BC61E.dll []
"{A8FC611B-71F6-4B4D-BD3A-BFBCCDE96F57}"=A8FC611B.dll []
"{4D023DE9-F4B5-4BE0-99C6-7C7AD0CF5426}"=4D023DE9.dll []
"{DA63E650-537C-4042-87BB-9D19D844680B}"=DA63E650.dll []
"{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}"=08223B03.dll []
"{9F684DE8-3E87-4174-9033-E02A3DFD8B61}"=9F684DE8.dll []
"{4BF9CBA3-8DEE-41A1-8BDB-FC28D30E949F}"=4BF9CBA3.dll []
"{12B02216-AC3F-42A7-8313-449771237061}"=12B02216.dll []
"{9CA963CA-107C-4089-B0AB-31380F90D7E3}"=9CA963CA.dll []
"{CABA599D-5089-4865-9420-E41FA3C1F55F}"=CABA599D.dll []
"{495271CA-D0C6-4052-ABE6-5B01C73CDFB0}"=495271CA.dll []
"{3474A8C2-BEF9-46C8-983A-A26A0030EC30}"=3474A8C2.dll []
"{E3367679-4775-4244-A62E-4CFE58FC850B}"=E3367679.dll []
"{4F34C688-FD49-42FC-97F7-87D2F5791612}"=4F34C688.dll []
"{B3721C07-62B3-411A-9DC7-F5F27E3E21FF}"=B3721C07.dll []
"{E0D39066-96D7-4891-8527-488ADAFCD60F}"=E0D39066.dll []
"{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}"=122B901E.dll []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\urqOIaaW
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoSMHelp"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceClassicControlPanel"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Google\Google Talk\googletalk.exe"="C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Internet Explorer\PLUGINS\cxsrrs.exe"="C:\Program Files\Internet Explorer\PLUGINS\cxsrrs.exe:*:Enabled:IE updater"
"C:\WINDOWS\jsgjhfekis.exe"="C:\WINDOWS\jsgjhfekis.exe:*:Enabled:utorrent7"
"F:\source\F056~1\STORMC~1\Stormser.exe"="F:\source\F056~1\STORMC~1\Stormser.exe:*:Enabled:@xpsp2res.dll,-22008"
"F:\source\كوديكات\Storm Codec\Storm.exe"="F:\source\كوديكات\Storm Codec\Storm.exe:*:Enabled:±©·çس°زô"
"F:\source\كوديكات\Storm Codec\stormliv.exe"="F:\source\كوديكات\Storm Codec\stormliv.exe:*:Enabled:±©·çس°زôأ½جه؟طضئضذذؤ"
"F:\source\كوديكات\Storm Codec\Stormser.exe"="F:\source\كوديكات\Storm Codec\Stormser.exe:*:Enabled:@xpsp2res.dll,-22008"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"G:\games\zootycoon\zt2\zt.exe"="G:\games\zootycoon\zt2\zt.exe:*:Enabled:Zoo Tycoon 2 Executable"
"G:\games\zootycoon\zoo2\zt.exe"="G:\games\zootycoon\zoo2\zt.exe:*:Enabled:Zoo Tycoon 2 Executable"
"F:\source\Orbitdownloader youtube\orbitdm.exe"="F:\source\Orbitdownloader youtube\orbitdm.exe:*:Enabled:Orbit"
"F:\source\Orbitdownloader youtube\orbitnet.exe"="F:\source\Orbitdownloader youtube\orbitnet.exe:*:Enabled:Orbit"
"C:\Documents and Settings\XPPRESP3\Application Data\Facebook\facebook.exe"="C:\Documents and Settings\XPPRESP3\Application Data\Facebook\facebook.exe:127.0.0.1/255.255.255.255:Enabled:Facebook"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4ce0787f-f340-11dd-95f7-101111111111}]
shell\AutoRun\command - J:\sv8c2bjw.bat
shell\open\command - J:\sv8c2bjw.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{54b0224f-9e6c-11dd-b6f6-806d6172696f}]
shell\AutoRun\command - D:\Setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{54b02251-9e6c-11dd-b6f6-806d6172696f}]
shell\AutoRun\command - C:\sv8c2bjw.bat
shell\open\command - C:\sv8c2bjw.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{54b02252-9e6c-11dd-b6f6-806d6172696f}]
shell\AutoRun\command - E:\sv8c2bjw.bat
shell\open\command - E:\sv8c2bjw.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{54b02253-9e6c-11dd-b6f6-806d6172696f}]
shell\AutoRun\command - F:\sv8c2bjw.bat
shell\open\command - F:\sv8c2bjw.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{54b02254-9e6c-11dd-b6f6-806d6172696f}]
shell\AutoRun\command - G:\sv8c2bjw.bat
shell\open\command - G:\sv8c2bjw.bat
======List of files/folders created in the last 1 months======
2009-07-22 21:51:10 ----D---- C:\rsit
2009-07-22 21:51:10 ----D---- C:\Program Files\trend micro
2009-07-16 20:38:21 ----D---- C:\Documents and Settings\XPPRESP3\Application Data\Facebook
2009-07-16 08:48:27 ----A---- C:\WINDOWS\ntbtlog.txt
2009-07-16 08:34:08 ----RSH---- C:\sv8c2bjw.bat
2009-07-16 08:25:32 ----D---- C:\Documents and Settings\XPPRESP3\Application Data\Malwarebytes
2009-07-16 08:25:27 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-07-15 13:39:56 ----RSH---- C:\WINDOWS\system32\nmdfgds0.dll
2009-07-15 13:39:55 ----RSH---- C:\WINDOWS\system32\olhrwef.exe
2009-07-15 12:37:30 ----D---- C:\Documents and Settings\XPPRESP3\Application Data\Winamp
2009-07-15 12:37:29 ----D---- C:\Documents and Settings\All Users\Application Data\DFX
2009-07-15 12:37:27 ----D---- C:\Program Files\Common Files\DFX
2009-07-11 00:10:01 ----D---- C:\Documents and Settings\All Users\Application Data\InstallShield
2009-07-11 00:07:58 ----D---- C:\Documents and Settings\XPPRESP3\Application Data\InstallShield
2009-07-07 07:21:23 ----A---- C:\WINDOWS\WaterIllusion.ini
2009-07-07 07:19:18 ----D---- C:\Program Files\Nufsoft
2009-06-27 12:24:46 ----D---- C:\tmp
======List of files/folders modified in the last 1 months======
2009-07-22 21:51:10 ----RD---- C:\Program Files
2009-07-22 21:04:32 ----D---- C:\Program Files\Mozilla Firefox
2009-07-22 21:03:55 ----D---- C:\WINDOWS\system32\drivers
2009-07-22 21:03:41 ----D---- C:\Documents and Settings\XPPRESP3\Application Data\Orbit
2009-07-22 21:02:55 ----D---- C:\WINDOWS\system32
2009-07-22 21:02:36 ----SD---- C:\WINDOWS\Tasks
2009-07-22 21:02:19 ----SHD---- C:\WINDOWS\CSC
2009-07-22 02:58:06 ----D---- C:\Documents and Settings\XPPRESP3\Application Data\Azureus
2009-07-22 02:21:39 ----A---- C:\WINDOWS\NeroDigital.ini
2009-07-22 00:08:22 ----D---- C:\WINDOWS\Prefetch
2009-07-21 23:40:17 ----D---- C:\WINDOWS\system32\CatRoot2
2009-07-21 21:05:51 ----D---- C:\Program Files\AdVantage
2009-07-20 17:31:22 ----D---- C:\Documents and Settings\All Users\Application Data\Google Updater
2009-07-19 17:31:25 ----D---- C:\WINDOWS
2009-07-16 19:29:56 ----D---- C:\Documents and Settings\XPPRESP3\Application Data\Winamp new player
2009-07-16 09:05:40 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-07-16 00:18:58 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-07-15 13:45:07 ----D---- C:\WINDOWS\system32\temp
2009-07-15 12:37:30 ----D---- C:\Documents and Settings
2009-07-15 12:37:27 ----D---- C:\Program Files\Common Files
2009-07-15 08:48:58 ----A---- C:\WINDOWS\PhotoSnapViewer.INI
2009-07-14 12:45:04 ----D---- C:\WINDOWS\Temp
2009-07-14 12:44:54 ----HD---- C:\WINDOWS\inf
2009-07-11 00:08:17 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-07-11 00:08:16 ----D---- C:\Program Files\Common Files\InstallShield
2009-07-11 00:08:15 ----HD---- C:\Program Files\InstallShield Installation Information
2009-07-07 07:02:05 ----RSD---- C:\WINDOWS\Fonts
2009-06-30 00:36:20 ----SHD---- C:\WINDOWS\Installer
2009-06-30 00:36:20 ----HD---- C:\Config.Msi
2009-06-30 00:36:19 ----D---- C:\Program Files\SweetIM
2009-06-23 06:53:13 ----D---- C:\Documents and Settings\XPPRESP3\Application Data\PlayFirst
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 AMON;AMON; \??\C:\WINDOWS\system32\drivers\amon.sys []
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2008-10-23 271360]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2008-10-23 18048]
R2 Vcs;Vcs support; \??\C:\WINDOWS\system32\Drivers\Vcs.sys []
R3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [2005-05-31 20480]
R3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2005-04-30 10804]
R3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2005-05-31 23000]
R3 BTHidEnum;Bluetooth HID Enumerator; C:\WINDOWS\system32\DRIVERS\vbtenum.sys [2005-04-30 11860]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-10-14 138752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-04-17 4707328]
R3 ip100Avista;Realtek RTL8139 Family PCI Fast Ethernet NIC NT Driver; C:\WINDOWS\system32\DRIVERS\ipfnd51.sys [2007-09-04 29824]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys []
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-02-25 6867360]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2008-01-29 22016]
R3 nvsmu;nvsmu; C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2008-02-15 14336]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
R3 SCREAMINGBDRIVER;Screaming Bee Audio; C:\WINDOWS\system32\drivers\ScreamingBAudio.sys [2006-09-27 21920]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2006-06-17 30080]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2006-03-05 57984]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2006-06-17 17152]
R3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2004-10-19 61312]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2005-03-25 82148]
S3 4901228;4901228; \??\C:\WINDOWS\system32\4901228.sys []
S3 5102a80;5102a80; \??\C:\WINDOWS\system32\5102a80.sys []
S3 9fd8db;9fd8db; \??\C:\WINDOWS\system32\9fd8db.sys []
S3 aqgfn408;aqgfn408; C:\WINDOWS\system32\drivers\aqgfn408.sys []
S3 AVPsys;AVPsys; \??\C:\WINDOWS\system32\drivers\cdaudio.sys []
S3 BTNetFilter;Bluetooth Network Filter; \??\C:\WINDOWS\system32\drivers\BTNetFilter.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 eth8023;eth8023; C:\WINDOWS\system32\drivers\eth8023.sys []
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 ISODrive;ISO CD-ROM Device Driver; \??\F:\source\UltraISO\UltraISO\drivers\ISODrive.sys []
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 nm;nm; C:\WINDOWS\system32\drivers\nm.sys []
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-01-25 42000]
S3 NTACCESS;NTACCESS; \??\D:\NTACCESS.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2008-01-29 54016]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\D:\NTGLM7X.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2005-06-16 31744]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 25856]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-12-28 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00 []
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00 []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;System Restore Filter Driver; C:\WINDOWS\system32\DRIVERS\sr.sys [2004-08-04 73472]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 BlueSoleil Hid Service;BlueSoleil Hid Service; F:\source\فلاشه\BTNtService.exe [2005-04-06 110592]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 FolderSize;Folder Size; C:\Program Files\FolderSize\FolderSizeSvc.exe [2006-03-25 98304]
R2 hpqddsvc;خدمة HP CUE DeviceDiscovery (الكشف على أجهزة CUE لـ HP); C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 NOD32krn;NOD32 Kernel Service; C:\Program Files\Eset\nod32krn.exe [2008-10-20 507904]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-02-25 155716]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-10-22 66872]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226640]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
S2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6; F:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
S2 ccosm;Contrl Center of Storm Media; F:\source\كوديكات\Storm Codec\stormliv.exe /asservice []
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-28 183280]
S2 MBAMService;MBAMService; F:\source\Malwarebytes' Anti-Malware\mbamservice.exe [2009-07-13 211216]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-03-05 654848]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-11-28 800040]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2005-07-25 89136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2007-01-25 93048]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00 []
-----------------EOF-----------------