here's the rsit log
Logfile of random's system information tool 1.06 (written by random/random)
Run by server2 at 2009-06-23 11:39:15
Microsoft Windows XP Professional Service Pack 2
System drive C: has 55 GB (72%) free of 76 GB
Total RAM: 1023 MB (35% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:39:23 AM, on 6/23/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\dllcache\Recycler.{645FF040-5081-101B-9F08-00AA002F954E}\Global.exe
C:\WINDOWS\system32\keyboard\services.exe
C:\WINDOWS\system32\dllcache\Recycler.{645FF040-5081-101B-9F08-00AA002F954E}\svchost.exe
C:\WINDOWS\VMSnap3.EXE
C:\WINDOWS\Domino.EXE
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
C:\WINDOWS\system32\dllcache\Recycler.{645FF040-5081-101B-9F08-00AA002F954E}\system.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\All Users\Application Data\Fearghus\lsass.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
D:\Cafezee2\Server.exe
D:\Cafezee2\czpinger.exe
\Pc08\my documents\My Pictures\My Pictures.exe
C:\WINDOWS\system32\cmd.exe
\Pc08\my documents\My Pictures\My Pictures.exe
C:\WINDOWS\system32\cmd.exe
\Pc08\my documents\My Pictures\My Pictures.exe
C:\WINDOWS\system32\cmd.exe
C:\DOCUME~1\server2\LOCALS~1\Temp\winyfwi.exe
C:\DOCUME~1\server2\LOCALS~1\Temp\pkgd.exe
C:\DOCUME~1\server2\LOCALS~1\Temp\winqgiiaf.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\server2\My Documents\Mozilla Downloads\RSIT.exe
C:\Program Files\trend micro\server2.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\keyboard\services.exe
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [VMSnap3] C:\WINDOWS\VMSnap3.EXE
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.EXE
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - HKLM\..\Run: [USB2.0] C:\Documents and Settings\All Users\Application Data\Microsoft\USB2.0\usb-hi.exe
O4 - HKLM\..\Run: [Keyboard] C:\Documents and Settings\All Users\Application Data\Fearghus\lsass.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [] C:\WINDOWS\system\KEYBOARD.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [] C:\WINDOWS\system32\dllcache\Default.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKCU\..\Run: [PowerBar] "C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" /AtBootTime
O4 - HKCU\..\Run: [Yahoo Messengger] C:\WINDOWS\system32\SSCVIHOST.exe
O4 - HKCU\..\RunOnce: [] C:\WINDOWS\system32\dllcache\Default.exe
O4 - HKLM\..\Policies\Explorer\Run: [1] C:\progra~1\micros~1\csrss.exe
O4 - HKLM\..\Policies\Explorer\Run: [sys] C:\WINDOWS\Fonts\Fonts.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: kbdrv16.com
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {B015B944-7316-49AE-AC84-ACCA9379EA32} (IPCamPlugIn Control) -
http://124.106.161.28/IPCamPluginMJPEG.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) -
http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F92C77EF-BBAC-4A56-9FAF-5A570D83C5B2}: NameServer = 192.168.2.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 8419 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll [2008-11-11 62728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2009-05-07 2403392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [2009-05-18 737776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28 160496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2009-05-07 2403392]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-08-24 13574144]
"VMSnap3"=C:\WINDOWS\VMSnap3.EXE [2006-08-30 131072]
"Domino"=C:\WINDOWS\Domino.EXE [2006-06-28 122880]
"EEventManager"=C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe [2006-03-17 172032]
"Shell23"= []
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-06-17 495616]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"BigDog303"=C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH) []
"USB2.0"=C:\Documents and Settings\All Users\Application Data\Microsoft\USB2.0\usb-hi.exe [2000-01-01 102400]
"Keyboard"=C:\Documents and Settings\All Users\Application Data\Fearghus\lsass.exe [2000-01-01 106496]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe [2008-11-11 206088]
""=C:\WINDOWS\system\KEYBOARD.exe [2009-06-17 307200]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 113520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
""=C:\WINDOWS\system32\dllcache\Default.exe [2009-06-17 307200]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"1"=C:\progra~1\micros~1\csrss.exe []
"sys"=C:\WINDOWS\Fonts\Fonts.exe [2009-06-17 307200]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-05-18 138488]
"Messenger (Yahoo!)"=C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2009-03-18 4441328]
"RegistryMechanic"=C:\Program Files\Registry Mechanic\RegMech.exe [2008-07-08 2897816]
"PowerBar"=C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe [2004-04-21 155648]
"Yahoo Messengger"=C:\WINDOWS\system32\SSCVIHOST.exe [2007-05-15 253661]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
""=C:\WINDOWS\system32\dllcache\Default.exe [2009-06-17 307200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
C:\WINDOWS\ALCMTR.EXE [2009-05-08 69632]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 108840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
C:\Program Files\Ahead\InCD\InCD.exe [2006-11-02 1397760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2009-01-06 359720]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU]
C:\Program Files\lg_fwupdate\fwupdate.exe [2005-04-12 311296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2009-05-08 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2008-08-24 13574144]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2008-08-24 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-06-17 495616]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe [2004-11-02 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2007-08-20 16384512]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
C:\WINDOWS\SkyTel.EXE [2009-05-08 1826816]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
kbdrv16.com
C:\Documents and Settings\server2\Start Menu\Programs\Startup
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\WINDOWS\system32\klogon.dll [2008-11-11 218376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=1
"DisableRegistryTools"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0
"DisableStatusMessages"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=223
"HideClock"=0
"NofolderOptions"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"CZ_RESTRICTEDUSER"=
"HideClock"=
"Run"=
"NoDesktop"=
"NoActiveDesktop"=
"NoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"F:\Intaller\WinRar_4[1].1.65.exe"="F:\Intaller\WinRar_4[1].1.65.exe:*:Enabled:ipsec"
"C:\WINDOWS\Explorer.EXE"="C:\WINDOWS\Explorer.exe:*:Enabled:ipsec"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\WINDOWS\SkyTel.EXE"="C:\WINDOWS\SkyTel.EXE:*:Enabled:ipsec"
"C:\WINDOWS\system32\RUNDLL32.EXE"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:ipsec"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\QuickTime\QTTask.exe"="C:\Program Files\QuickTime\QTTask.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\nwiz.exe"="C:\WINDOWS\system32\nwiz.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\userinit.exe"="C:\WINDOWS\system32\userinit.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winsvydl.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winsvydl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\wintybg.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\wintybg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\wshbup.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\wshbup.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\rwehl.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\rwehl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winoelbkk.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winoelbkk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winqhcdrh.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winqhcdrh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winptqbu.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winptqbu.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winkvpqll.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winkvpqll.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\nhtsj.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\nhtsj.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winqkbfsr.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winqkbfsr.exe:*:Enabled:ipsec"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:ipsec"
"C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe"="C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe:*:Enabled:Sony Ericsson Media Manager 1.2"
"H:\MS-DOS.com"="H:\MS-DOS.com:*:Enabled:ipsec"
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"="C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:ipsec"
"H:\CONTACT LENSE.exe"="H:\CONTACT LENSE.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\dllcache\Recycler.{645FF040-5081-101B-9F08-00AA002F954E}\svchost.exe"="C:\WINDOWS\system32\dllcache\Recycler.{645FF040-5081-101B-9F08-00AA002F954E}\svchost.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winlofa.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winlofa.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winmkvao.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winmkvao.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winwsxom.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winwsxom.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winfkcy.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winfkcy.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\vhdau.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\vhdau.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\wegr.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\wegr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winrcyeqh.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winrcyeqh.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\dllcache\Default.exe"="C:\WINDOWS\system32\dllcache\Default.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winulnce.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winulnce.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\gbtyjv.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\gbtyjv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winbywaw.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winbywaw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\jupnt.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\jupnt.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\hwfo.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\hwfo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\bbix.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\bbix.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winwjgljj.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winwjgljj.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\nfaj.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\nfaj.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winiiwd.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winiiwd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winaeric.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winaeric.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winyalb.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winyalb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winabftf.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winabftf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winrgve.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winrgve.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\windgnfmy.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\windgnfmy.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\atmbtl.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\atmbtl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winreavo.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winreavo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winmdlrb.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winmdlrb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\wingkaunm.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\wingkaunm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winceikku.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winceikku.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\kuxoj.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\kuxoj.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\fdaumh.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\fdaumh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winbhabyk.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winbhabyk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\jmwo.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\jmwo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\opol.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\opol.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winpappe.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winpappe.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winnxbckp.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winnxbckp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\laet.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\laet.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winaoyix.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winaoyix.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\wineaukp.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\wineaukp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winxpmigi.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winxpmigi.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winepfobp.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winepfobp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\irfacx.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\irfacx.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\basmgw.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\basmgw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\xlfmi.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\xlfmi.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\wpwq.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\wpwq.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\kgtiji.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\kgtiji.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\hexxr.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\hexxr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winmbhwbl.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winmbhwbl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\qyegf.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\qyegf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winsqrsqn.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winsqrsqn.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\wineatv.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\wineatv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\bgbc.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\bgbc.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\icgg.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\icgg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\uljhaw.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\uljhaw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winbpme.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winbpme.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\wtelo.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\wtelo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winbsxdyn.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winbsxdyn.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\savdl.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\savdl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\windgcmns.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\windgcmns.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winthwhqy.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winthwhqy.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\jnbyp.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\jnbyp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winoxcb.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winoxcb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winubpuwy.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winubpuwy.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\gnrrk.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\gnrrk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\bnjjw.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\bnjjw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winaaul.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winaaul.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\winysmvr.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\winysmvr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\attmbi.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\attmbi.exe:*:Enabled:ipsec"
"C:\WINDOWS\system\KEYBOARD.exe"="C:\WINDOWS\system\KEYBOARD.exe:*:Enabled:ipsec"
"C:\WINDOWS\pchealth\helpctr\binaries\HelpHost.com"="C:\WINDOWS\pchealth\helpctr\binaries\HelpHost.com:*:Enabled:ipsec"
"C:\WINDOWS\Fonts\tskmgr.exe"="C:\WINDOWS\Fonts\tskmgr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\server2\LOCALS~1\Temp\kljju.exe"="C:\DOCUME~1\server2\LOCALS~1\Temp\kljju.exe:*:Enabled:ipsec"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e1a6e6b-3ddc-11de-b362-00248cb8a964}]
shell\auto\command - Scrap
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Scrap
shell\explore\command - Scrap
shell\open\command - Scrap
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17d86e34-4cd4-11de-b38d-00248cb8a964}]
shell\auto\command - I:\Scrap
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Scrap
shell\explore\command - I:\Scrap
shell\open\command - I:\Scrap
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1bc47a62-5ae7-11de-b3b9-00248cb8a964}]
shell\AutoRun\command - H:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
shell\open\command - H:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1bc47a63-5ae7-11de-b3b9-00248cb8a964}]
shell\AutoRun\command - I:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
shell\open\command - I:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1fd2e252-4420-11de-b36d-00248cb8a964}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe voda.dll.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1fd2e254-4420-11de-b36d-00248cb8a964}]
shell\AutoRun\command - H:\RECYCLER\k-1-3542-4232123213-7676767-8888886\r00t.exe
shell\open\command - H:\RECYCLER\k-1-3542-4232123213-7676767-8888886\r00t.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{202d4bbc-5563-11de-b3a4-00248cb8a964}]
shell\AutoPlay\command - vmxi.pif
shell\AutoRun\command - vmxi.pif
shell\explOre\command - vmxi.pif
shell\OpeN\command - vmxi.pif
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{202d4bbd-5563-11de-b3a4-00248cb8a964}]
shell\AutoPlay\command - H:\InnocentFile.exe
shell\AutoRun\command - H:\InnocentFile.exe
shell\Explore\command - H:\InnocentFile.exe
shell\Open\command - H:\InnocentFile.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{202d4bbe-5563-11de-b3a4-00248cb8a964}]
shell\AutoRun\command - asneg.com
shell\explore\command - asneg.com
shell\open\command - asneg.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23dc7c10-5248-11de-b39b-00248cb8a964}]
shell\auto\command - Scrap
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Scrap
shell\explore\command - Scrap
shell\open\command - Scrap
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23dc7c11-5248-11de-b39b-00248cb8a964}]
shell\AutoRun\command - I:\USBNB.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3cbfa88e-4042-11de-b367-00248cb8a964}]
shell\AutoRun\command - H:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
shell\open\command - H:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3ee1be31-598c-11de-b3b7-00248cb8a964}]
shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{45572e5d-4e57-11de-b392-00248cb8a964}]
shell\AutoRun\command - H:\2a.exe
shell\open\command - H:\2a.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4a528ea9-4fe8-11de-b396-00248cb8a964}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe winconfig.dll.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4a528eab-4fe8-11de-b396-00248cb8a964}]
shell\AutoRun\command - wscript.exe system32.dll.vbs
shell\explore\command - wscript.exe system32.dll.vbs
shell\open\command - wscript.exe system32.dll.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4a623600-3d16-11de-b361-00248cb8a964}]
shell\AutoRun\command - I:\flnm.cmd
shell\open\command - I:\flnm.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4ee8019c-48ee-11de-b381-00248cb8a964}]
shell\auto\command - H:\Scrap
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Scrap
shell\explore\command - H:\Scrap
shell\open\command - H:\Scrap
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{51c5f67f-50ac-11de-b398-00248cb8a964}]
shell\autOpLAy\command - delim.pif
shell\AutoRun\command - delim.pif
shell\eXPloRe\command - delim.pif
shell\open\command - delim.pif
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{51c5f681-50ac-11de-b398-00248cb8a964}]
shell\AutoRun\command - wscript.exe sowar.vbs
shell\Open\command - wscript.exe sowar.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{51c5f687-50ac-11de-b398-00248cb8a964}]
shell\AutoRun\command - RESTORE\k-1-3542-4232123213-7676767-8888886\Ogard.exe
shell\open\command - RESTORE\k-1-3542-4232123213-7676767-8888886\Ogard.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{586d7266-562b-11de-b3a5-00248cb8a964}]
shell\AutoRun\command - H:\rousan.exe
shell\explore\command - H:\rousan.exe
shell\open\command - H:\rousan.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{58f63fbb-4299-11de-b36b-00248cb8a964}]
shell\auto\command - H:\Scrap
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Scrap
shell\explore\command - H:\Scrap
shell\open\command - H:\Scrap
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5cc443a7-3eb5-11de-b364-00248cb8a964}]
shell\auto\command - I:\Scrap
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Scrap
shell\explore\command - I:\Scrap
shell\open\command - I:\Scrap
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{62523903-5348-11de-b3a0-00248cb8a964}]
shell\AutoRun\command - system~1\_resto~1\RP09.exe
shell\explore\command - system~1\_resto~1\RP09.exe
shell\open\command - system~1\_resto~1\RP09.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6e39419f-4daa-11de-b390-00248cb8a964}]
shell\AutoRun\command - RESTORE\k-1-3542-4232123213-7676767-8888886\Ogard.exe
shell\open\command - RESTORE\k-1-3542-4232123213-7676767-8888886\Ogard.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f978348-4f23-11de-b394-00248cb8a964}]
shell\AutoRun\command - hni.cmd
shell\explore\command - hni.cmd
shell\open\command - hni.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f978349-4f23-11de-b394-00248cb8a964}]
shell\AutoRun\command - I:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{88c01138-45e3-11de-b371-00248cb8a964}]
shell\AutoRun\command - H:\SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\sys.exe
shell\open\command - H:\SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\sys.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8dd68ed6-481d-11de-b37c-00248cb8a964}]
shell\AutoRun\command - I:\password_viewer.exe %1
shell\Explore\command - I:\password_viewer.exe %1
shell\Open\command - I:\password_viewer.exe %1
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8df7ff24-4a64-11de-b386-00248cb8a964}]
shell\AutoplAY\command - I:\pbgtfi.pif
shell\AutoRun\command - I:\pbgtfi.pif
shell\explOrE\command - I:\pbgtfi.pif
shell\oPEn\command - I:\pbgtfi.pif
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8ede0908-46a6-11de-b376-00248cb8a964}]
shell\AutoRun\command - H:\uulaqvl.cmd
shell\explore\command - H:\uulaqvl.cmd
shell\open\command - H:\uulaqvl.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97b70556-4b2f-11de-b387-00248cb8a964}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe voda.dll.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b76ecf5c-597e-11de-b3b6-00248cb8a964}]
shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b76ecf5d-597e-11de-b3b6-00248cb8a964}]
shell\AutoRun\command - I:\password_viewer.exe %1
shell\Explore\command - I:\password_viewer.exe %1
shell\Open\command - I:\password_viewer.exe %1
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bbdd64d4-53d1-11de-b3a1-00248cb8a964}]
shell\AutoRun\command - H:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
shell\open\command - H:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bbdd64d8-53d1-11de-b3a1-00248cb8a964}]
shell\Autoplay\command - H:\smss.exe
shell\AutoRun\command - H:\smss.exe
shell\Explore\command - H:\smss.exe
shell\Open\command - H:\smss.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bbdd64da-53d1-11de-b3a1-00248cb8a964}]
shell\AutoRun\command - hyetn1i.exe
shell\open\command - hyetn1i.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bbdd64db-53d1-11de-b3a1-00248cb8a964}]
shell\AutopLAy\command - H:\vkor.exe
shell\AutoRun\command - H:\vkor.exe
shell\expLoRe\command - H:\vkor.exe
shell\opeN\command - H:\vkor.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be27b248-3f61-11de-b365-00248cb8a964}]
shell\AutoRun\command - H:\lhylec9x.cmd
shell\open\command - H:\lhylec9x.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be27b24e-3f61-11de-b365-00248cb8a964}]
shell\1\command - I:\Recycle.exe
shell\2\command - I:\Recycle.exe
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycle.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c2bdb641-5a2b-11de-b3b8-00248cb8a964}]
shell\AutoRun\command - I:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
shell\open\command - I:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c2bdb642-5a2b-11de-b3b8-00248cb8a964}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MS-DOS.com
shell\Explore\command - H:\MS-DOS.com
shell\Open\command - H:\MS-DOS.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c2bdb643-5a2b-11de-b3b8-00248cb8a964}]
shell\AutoRun\command - H:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
shell\open\command - H:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c2bdb645-5a2b-11de-b3b8-00248cb8a964}]
shell\AutoRun\command - H:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
shell\open\command - H:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c2bdb646-5a2b-11de-b3b8-00248cb8a964}]
shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c2bdb647-5a2b-11de-b3b8-00248cb8a964}]
shell\AutoRun\command - I:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
shell\open\command - I:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Drive13.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c63fe42f-41ca-11de-b36a-00248cb8a964}]
shell\auto\command - H:\Scrap
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Scrap
shell\explore\command - H:\Scrap
shell\open\command - H:\Scrap
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c63fe431-41ca-11de-b36a-00248cb8a964}]
shell\AutOpLaY\command - I:\aphhu.cmd
shell\AutoRun\command - I:\aphhu.cmd
shell\eXplORE\command - I:\aphhu.cmd
shell\Open\command - I:\aphhu.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c6d814c6-588e-11de-b3b0-00248cb8a964}]
shell\AutoRun\command - I:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d15eba52-45ac-11de-b370-00248cb8a964}]
shell\AutoRun\command - password_viewer.exe %1
shell\Explore\command - password_viewer.exe %1
shell\Open\command - password_viewer.exe %1
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d15eba54-45ac-11de-b370-00248cb8a964}]
shell\AutoRun\command - 0o.com
shell\explore\command - 0o.com
shell\open\command - 0o.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e7ae8d34-3ba5-11de-b35a-00248cb8a964}]
shell\AutoRun\command - I:\ot8unvb.cmd
shell\explore\command - I:\ot8unvb.cmd
shell\open\command - I:\ot8unvb.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f3b51099-517a-11de-b399-00248cb8a964}]
shell\auto\command - H:\Scrap
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Scrap
shell\explore\command - H:\Scrap
shell\open\command - H:\Scrap
======File associations======
.reg - open - C:\WINDOWS\pchealth\Global.exe
======List of files/folders created in the last 1 months======
2009-06-23 11:39:16 ----D---- C:\Program Files\trend micro
2009-06-23 11:39:15 ----D---- C:\rsit
2009-06-23 10:54:18 ----RASH---- C:\WINDOWS\system32\SSCVIHOST.exe
2009-06-23 10:54:18 ----RASH---- C:\WINDOWS\system32\blastclnnn.exe
2009-06-23 10:54:18 ----A---- C:\WINDOWS\SSCVIHOST.exe
2009-06-19 17:12:37 ----SHD---- C:\Config.Msi
2009-06-19 17:09:30 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-06-19 17:08:29 ----D---- C:\Program Files\NOS
2009-06-19 17:08:29 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
2009-06-19 13:23:54 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-06-19 13:23:54 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-19 13:03:49 ----D---- C:\Program Files\Kaspersky Lab
2009-06-18 12:33:33 ----D---- C:\WINDOWS\system32\keyboard
2009-06-18 12:33:33 ----D---- C:\Documents and Settings\All Users\Application Data\Fearghus
2009-06-17 18:47:19 ----RASH---- C:\MS-DOS.com
2009-06-17 18:32:58 ----RASH---- C:\WINDOWS\system32\regedit.exe
2009-06-14 11:05:44 ----SHD---- C:\FOUND.007
2009-06-11 11:26:30 ----SHD---- C:\FOUND.006
2009-06-09 16:15:20 ----RSHD---- C:\RECYCLER
2009-06-09 14:56:23 ----RSHD---- C:\RESTORE
2009-06-09 10:04:44 ----SHD---- C:\FOUND.005
2009-06-07 19:29:46 ----A---- C:\WINDOWS\system32\wshirda.dll
2009-06-07 19:29:46 ----A---- C:\WINDOWS\system32\irmon.dll
2009-06-07 19:29:46 ----A---- C:\WINDOWS\system32\irftp.exe
2009-06-07 11:15:34 ----D---- C:\Program Files\HijackThis
2009-06-07 11:09:28 ----D---- C:\WINDOWS\system32\appmgmt
2009-06-03 15:12:36 ----SHD---- C:\FOUND.004
2009-06-03 11:59:49 ----RSH---- C:\system32.dll.vbs
2009-06-03 10:08:48 ----SHD---- C:\FOUND.003
2009-06-02 14:35:50 ----A---- C:\WINDOWS\ModemLog_ZTE Proprietary USB Modem.txt
2009-05-29 19:35:38 ----A---- C:\WINDOWS\system32\ap_i2p.ini
2009-05-29 19:35:35 ----D---- C:\Program Files\AdultPDF
2009-05-28 12:05:12 ----SHD---- C:\FOUND.002
======List of files/folders modified in the last 1 months======
2009-06-22 20:00:38 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-06-22 10:41:14 ----A---- C:\WINDOWS\NeroDigital.ini
2009-06-17 18:42:14 ----A---- C:\WINDOWS\system32\nvcplui.exe
2009-06-07 19:31:04 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-06-03 20:57:18 ----A---- C:\WINDOWS\win.ini
2009-05-27 12:29:30 ----A---- C:\avi_log.txt
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 InCDPass;InCDPass; C:\WINDOWS\System32\DRIVERS\InCDPass.sys [2005-07-08 29696]
R1 incdrm;InCD Reader; C:\WINDOWS\system32\drivers\incdrm.sys [2006-11-02 28672]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 36096]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
R1 PQNTDrv;PQNTDrv; C:\WINDOWS\system32\drivers\PQNTDrv.sys [2004-05-05 4228]
R3 dac970nt;dac970nt; \??\C:\WINDOWS\system32\drivers\njklm.sys []
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-08-28 4609024]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-08-24 6128352]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2006-10-02 10368]
R3 SiSGbeXP;SiS191/SiS190 Ethernet Device NDIS 5.1 Driver; C:\WINDOWS\system32\DRIVERS\SiSGbeXP.sys [2006-12-20 41600]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
R3 vmfilter303;vmfilter303; C:\WINDOWS\system32\drivers\vmfilter303.sys [2006-04-25 428160]
R3 ZSMC303;A4 TECH PC Camera H; C:\WINDOWS\System32\Drivers\usbVM303.sys [2006-12-01 392122]
R4 InCDfs;InCD File System; C:\WINDOWS\system32\drivers\InCDfs.sys [2005-07-08 99584]
S3 BthEnum;Bluetooth Request Block Driver; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2004-08-03 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2004-08-03 100992]
S3 BTHPORT;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2004-08-03 274304]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2004-08-03 18944]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2004-08-03 59648]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 ZTEusbmdm6k;ZTE Proprietary USB Driver; C:\WINDOWS\system32\DRIVERS\ZTEusbmdm6k.sys []
S3 ZTEusbnmea;ZTE NMEA Port; C:\WINDOWS\system32\DRIVERS\ZTEusbnmea.sys []
S3 ZTEusbser6k;ZTE Diagnostic Port; C:\WINDOWS\system32\DRIVERS\ZTEusbser6k.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 InCDsrv;InCD Helper; C:\Program Files\Ahead\InCD\InCDsrv.exe [2005-07-08 871424]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-10-19 61440]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-08-24 163908]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-05-08 150528]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-07 215992]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-01-06 610600]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 147744]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 523056]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 227104]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
-----------------EOF-----------------