I tried what you suggested and it worked! About one minute into its operation, ComboFix produced the following message:
ComboFix has detected the presence of rootkit activity and needs to reboot the machine.
Kindly note down on paper, the name of each file. We may need it later.
C:\Windows\system32\drivers\gxvxcsgfcbdcdiibomyqopqlvvvtlrxetrnxu.sys
C:\Windows\system32\gxvxcditltusswqqhfhcvimxewmfcvuwccbby.dll
C:\Windows\system32\gxvxceoubtxapdjtrtkepnaeaybsvrmbhmbgx.dll
After rebooting, ComboFix finished running and produced the following log:
ComboFix 09-06-10.02 - Majid 11/06/2009 16:51.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.44.1033.18.2429.1596 [GMT 1:00]
Running from: c:\users\Majid\Desktop\Combo-Fix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
SP: ESET NOD32 Antivirus 3.0 *disabled* (Updated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
SP: Windows Defender *disabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\windows\system32\drivers\gxvxcsgfcbdcdiibomyqopqlvvvtlrxetrnxu.sys
c:\windows\system32\gxvxccount
c:\windows\system32\gxvxcditltusswqqhfhcvimxewmfcvuwccbby.dll
c:\windows\system32\gxvxceoubtxapdjtrtkepnaeaybsvrmbhmbgx.dll
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
D:\Autorun.inf
F:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_GXVXCSERV.SYS
((((((((((((((((((((((((( Files Created from 2009-05-11 to 2009-06-11 )))))))))))))))))))))))))))))))
.
2009-06-11 15:56 . 2009-06-11 15:56 -------- d-----w- c:\users\Majid\AppData\Local\temp
2009-06-10 14:52 . 2009-06-10 14:52 -------- d-----w- c:\program files\ERUNT
2009-06-09 22:00 . 2009-04-21 11:39 2034688 ----a-w- c:\windows\system32\win32k.sys
2009-06-09 22:00 . 2009-04-23 12:14 623616 ----a-w- c:\windows\system32\localspl.dll
2009-06-09 21:59 . 2009-04-23 12:15 828416 ----a-w- c:\windows\system32\wininet.dll
2009-06-09 21:59 . 2009-04-24 16:02 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-09 21:59 . 2009-04-23 12:15 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-06-08 11:39 . 2009-06-08 11:39 -------- d-----w- c:\users\Majid\AppData\Local\ESET
2009-06-07 17:39 . 2009-06-07 17:39 -------- d-----w- c:\users\majid_riaz
2009-05-29 21:54 . 2009-05-29 21:54 -------- d-----w- c:\program files\DVD Decrypter
2009-05-27 02:39 . 2009-05-27 02:40 -------- d-----w- c:\windows\system32\ca-ES
2009-05-27 02:39 . 2009-05-27 02:40 -------- d-----w- c:\windows\system32\eu-ES
2009-05-27 02:39 . 2009-05-27 02:40 -------- d-----w- c:\windows\system32\vi-VN
2009-05-26 23:13 . 2009-05-26 23:13 -------- d-----w- c:\windows\system32\EventProviders
2009-05-26 23:10 . 2009-04-11 06:28 677376 ----a-w- c:\windows\system32\imapi2fs.dll
2009-05-26 23:09 . 2009-04-11 06:33 614376 ----a-w- c:\windows\system32\ci.dll
2009-05-26 23:08 . 2009-04-11 06:28 68096 ----a-w- c:\windows\system32\wlanhlp.dll
2009-05-24 20:27 . 2009-06-10 01:38 -------- d-----w- c:\users\Majid\AppData\Roaming\foobar2000
2009-05-24 20:27 . 2009-05-24 21:20 -------- d-----w- c:\program files\foobar2000
2009-05-18 17:56 . 2008-05-27 04:59 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
2009-05-18 16:25 . 2009-05-18 16:25 10134 ----a-r- c:\users\Majid\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-05-18 16:25 . 2009-05-18 16:25 -------- d-----w- c:\program files\Microsoft WSE
2009-05-18 16:25 . 2006-09-28 15:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2009-05-16 16:46 . 2009-05-16 16:46 -------- d-----w- C:\PerfLogs
2009-05-16 16:10 . 2008-01-19 07:29 705536 ----a-w- c:\windows\system32\imagesp1.dll
2009-05-16 16:10 . 2008-01-19 07:36 116736 ----a-w- c:\windows\system32\sstpsvc.dll
2009-05-16 16:10 . 2008-01-19 07:36 175104 ----a-w- c:\windows\system32\winrscmd.dll
2009-05-16 16:10 . 2008-01-19 07:34 69120 ----a-w- c:\windows\system32\iesetup.dll
2009-05-16 16:08 . 2008-01-19 07:42 56376 ----a-w- c:\windows\system32\drivers\dumpfve.sys
2009-05-16 16:07 . 2008-01-19 07:41 28216 ----a-w- c:\windows\system32\drivers\battc.sys
2009-05-16 16:06 . 2008-01-19 07:37 153600 ----a-w- c:\windows\system32\wmvdspa.dll
2009-05-16 16:05 . 2008-01-19 07:35 35328 ----a-w- c:\windows\system32\mspatcha.dll
2009-05-16 16:05 . 2008-01-19 07:34 305152 ----a-w- c:\windows\system32\msdelta.dll
2009-05-16 16:05 . 2008-01-19 07:34 258560 ----a-w- c:\windows\system32\dpx.dll
2009-05-16 16:05 . 2006-11-02 09:39 6656 ----a-w- c:\windows\system32\kbd106.dll
2009-05-16 14:56 . 2009-05-16 14:56 -------- d-----w- c:\program files\Combined Community Codec Pack
2009-05-16 14:44 . 2009-05-16 14:44 -------- d-----w- c:\users\Majid\AppData\Roaming\Apple Computer
2009-05-16 14:44 . 2009-06-10 18:09 -------- dc----w- c:\windows\system32\DRVSTORE
2009-05-16 14:44 . 2009-05-16 14:44 -------- d-----w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-16 14:34 . 2009-05-16 14:44 -------- d-----w- c:\users\Majid\AppData\Local\Apple Computer
2009-05-16 14:31 . 2009-05-16 14:44 -------- d-----w- c:\programdata\Apple Computer
2009-05-16 14:31 . 2009-05-16 14:32 -------- d-----w- c:\program files\QuickTime
2009-05-16 14:31 . 2009-05-16 14:31 -------- d-----w- c:\users\Majid\AppData\Local\Apple
2009-05-16 14:30 . 2009-05-16 14:30 -------- d-----w- c:\program files\QuickTime Pro 7.60.92 Windows XPVista
2009-05-16 13:53 . 2009-05-16 13:53 -------- d-----w- c:\users\Majid\AppData\Local\ACD Systems
2009-05-16 13:53 . 2009-05-16 13:53 -------- d-----w- c:\users\Majid\AppData\Roaming\ACD Systems
2009-05-16 13:52 . 2009-05-16 13:52 -------- d-----w- c:\programdata\ACD Systems
2009-05-16 13:52 . 2009-05-16 13:52 -------- d-----w- c:\program files\Common Files\ACD Systems
2009-05-16 13:52 . 2009-05-16 13:52 -------- d-----w- c:\program files\ACD Systems
2009-05-16 13:50 . 2009-05-16 13:50 -------- d-----w- c:\users\Majid\AppData\Local\Downloaded Installations
2009-05-16 13:40 . 2009-05-16 13:41 -------- d-----w- c:\users\Majid\AppData\Local\Adobe
2009-05-16 13:39 . 2009-05-16 13:39 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-05-16 13:38 . 2009-05-16 13:39 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-16 13:21 . 2009-05-16 13:21 6656 ----a-w- c:\windows\system32\kbd106n.dll
2009-05-16 13:14 . 2009-05-16 15:28 -------- d-----w- c:\program files\Microsoft Works
2009-05-16 13:11 . 2009-05-16 13:11 -------- d-----w- c:\program files\Microsoft.NET
2009-05-16 13:07 . 2009-05-16 13:07 -------- d-----w- c:\users\Majid\AppData\Local\Microsoft Help
2009-05-16 13:07 . 2009-06-10 13:57 -------- d-----w- c:\programdata\Microsoft Help
2009-05-16 13:02 . 2009-05-16 13:02 -------- d--h--r- C:\MSOCache
2009-05-16 12:54 . 2009-05-16 12:54 -------- d-----w- c:\programdata\DAEMON Tools Lite
2009-05-16 12:54 . 2009-05-16 12:54 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-05-16 12:54 . 2009-05-16 12:54 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-05-16 12:51 . 2009-05-16 12:51 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-05-16 12:51 . 2009-05-16 12:57 -------- d-----w- c:\users\Majid\AppData\Roaming\DAEMON Tools Lite
2009-05-16 07:54 . 2009-06-11 14:45 -------- d-----w- c:\users\Majid\Tracing
2009-05-16 07:53 . 2009-05-16 07:53 -------- d-----w- c:\program files\Microsoft
2009-05-16 07:53 . 2009-05-16 07:53 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-05-16 07:53 . 2009-05-16 07:53 -------- d-----w- c:\program files\Windows Live
2009-05-16 07:52 . 2009-05-16 07:52 -------- d-----w- c:\windows\PCHEALTH
2009-05-16 03:30 . 2009-05-16 03:30 61440 ----a-w- c:\windows\system32\winipsec.dll
2009-05-16 03:30 . 2009-05-16 03:30 272896 ----a-w- c:\windows\system32\polstore.dll
2009-05-16 03:05 . 2009-05-16 03:05 2048 ----a-w- c:\windows\system32\msxml3r.dll
2009-05-16 02:45 . 2008-01-19 07:34 15872 ----a-w- c:\windows\system32\hcrstco.dll
2009-05-16 02:45 . 2006-11-02 09:46 8704 ----a-w- c:\windows\system32\hccoin.dll
2009-05-16 02:31 . 2009-05-16 02:31 9728 ----a-w- c:\windows\system32\lsass.exe
2009-05-16 02:26 . 2009-05-16 02:26 37888 ----a-w- c:\windows\system32\printcom.dll
2009-05-16 02:25 . 2009-05-16 02:25 14848 ----a-w- c:\windows\system32\wshrm.dll
2009-05-16 02:02 . 2009-05-16 02:02 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-05-16 01:48 . 2009-05-16 01:48 -------- d-----w- c:\program files\Common Files\Windows Live
2009-05-16 01:47 . 2009-05-16 01:47 84480 ----a-w- c:\windows\system32\INETRES.dll
2009-05-16 01:46 . 2009-06-10 14:56 -------- d-----w- c:\users\Majid\AppData\Roaming\uTorrent
2009-05-16 01:43 . 2009-05-16 01:43 -------- d-----w- c:\windows\system32\Macromed
2009-05-16 01:40 . 2009-05-16 01:40 2048 ----a-w- c:\windows\system32\msxml6r.dll
2009-05-16 01:39 . 2009-05-16 01:39 72704 ----a-w- c:\windows\system32\admparse.dll
2009-05-16 01:39 . 2009-05-16 01:39 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-05-16 01:26 . 2009-05-16 01:26 -------- d-----w- c:\users\Majid\AppData\Local\Cooliris
2009-05-16 01:17 . 2009-05-16 01:17 -------- d-----w- c:\program files\CCleaner
2009-05-16 01:12 . 2009-06-10 14:49 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-05-16 01:07 . 2005-08-25 18:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2009-05-16 01:07 . 2009-06-10 14:03 -------- d-----w- c:\program files\SpywareBlaster
2009-05-16 01:03 . 2009-05-16 01:03 -------- d-----w- c:\users\Majid\AppData\Roaming\Outertech
2009-05-16 01:02 . 2009-05-16 01:03 -------- d-----w- c:\program files\GetDiz
2009-05-16 00:59 . 2009-05-16 00:59 0 ----a-w- c:\windows\nsreg.dat
2009-05-16 00:59 . 2009-05-16 00:59 -------- d-----w- c:\users\Majid\AppData\Local\Mozilla
2009-05-16 00:38 . 2009-05-16 00:38 51224 ----a-w- c:\windows\system32\wuauclt.exe
2009-05-16 00:38 . 2009-05-16 00:38 43544 ----a-w- c:\windows\system32\wups2.dll
2009-05-16 00:38 . 2009-05-16 00:38 1524736 ----a-w- c:\windows\system32\wucltux.dll
2009-05-16 00:38 . 2009-05-16 00:38 1809944 ----a-w- c:\windows\system32\wuaueng.dll
2009-05-16 00:37 . 2009-05-16 00:37 83456 ----a-w- c:\windows\system32\wudriver.dll
2009-05-16 00:37 . 2009-05-16 00:37 561688 ----a-w- c:\windows\system32\wuapi.dll
2009-05-16 00:37 . 2009-05-16 00:37 34328 ----a-w- c:\windows\system32\wups.dll
2009-05-16 00:37 . 2009-05-16 00:37 31232 ----a-w- c:\windows\system32\wuapp.exe
2009-05-16 00:37 . 2009-05-16 00:37 162064 ----a-w- c:\windows\system32\wuwebv.dll
2009-05-16 00:32 . 2008-03-03 17:21 568 ---ha-w- c:\windows\nod32fixtemdono.reg
2009-05-16 00:32 . 2008-03-03 13:25 5702 ---ha-w- c:\windows\nod32restoretemdono.reg
2009-05-16 00:25 . 2009-05-16 00:31 -------- d-----w- c:\program files\ESET
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-11 15:11 . 2009-05-16 01:25 169936 ----a-w- c:\users\Majid\AppData\Roaming\Mozilla\Firefox\Profiles\fzwe655r.default\FlashGot.exe
2009-06-10 15:56 . 2009-06-10 15:56 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-10 15:56 . 2009-06-10 15:56 -------- d-----w- c:\program files\Java
2009-05-27 02:41 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2009-05-27 02:41 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-27 02:41 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2009-05-27 02:41 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration
2009-05-27 02:41 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Journal
2009-05-27 02:41 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery
2009-05-27 02:41 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2009-05-27 02:39 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-05-19 13:14 . 2009-05-19 13:14 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-05-16 23:59 . 2009-05-16 23:59 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-05-16 18:19 . 2008-09-24 13:42 99864 ----a-w- c:\users\Majid\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-16 16:35 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2009-05-16 16:35 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2009-04-17 15:58 . 2009-05-16 01:25 103424 ----a-w- c:\users\Majid\AppData\Roaming\Mozilla\Firefox\Profiles\fzwe655r.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2009-04-17 15:58 . 2009-05-16 01:25 954368 ----a-w- c:\users\Majid\AppData\Roaming\Mozilla\Firefox\Profiles\fzwe655r.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2009-04-17 15:58 . 2009-05-16 01:25 344064 ----a-w- c:\users\Majid\AppData\Roaming\Mozilla\Firefox\Profiles\fzwe655r.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2009-04-17 15:58 . 2009-05-16 01:25 71652 ----a-w- c:\users\Majid\AppData\Roaming\Mozilla\Firefox\Profiles\fzwe655r.default\extensions\piclens@cooliris.com\libs\avutil-49.dll
2009-04-17 15:58 . 2009-05-16 01:25 4579328 ----a-w- c:\users\Majid\AppData\Roaming\Mozilla\Firefox\Profiles\fzwe655r.default\extensions\piclens@cooliris.com\libs\cooliris18.dll
2009-04-17 15:58 . 2009-05-16 01:25 4534272 ----a-w- c:\users\Majid\AppData\Roaming\Mozilla\Firefox\Profiles\fzwe655r.default\extensions\piclens@cooliris.com\libs\cooliris19.dll
2009-04-17 15:58 . 2009-05-16 01:25 131868 ----a-w- c:\users\Majid\AppData\Roaming\Mozilla\Firefox\Profiles\fzwe655r.default\extensions\piclens@cooliris.com\libs\avformat-52.dll
2009-04-17 15:58 . 2009-05-16 01:25 65536 ----a-w- c:\users\Majid\AppData\Roaming\Mozilla\Firefox\Profiles\fzwe655r.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2009-04-17 15:58 . 2009-05-16 01:25 1161626 ----a-w- c:\users\Majid\AppData\Roaming\Mozilla\Firefox\Profiles\fzwe655r.default\extensions\piclens@cooliris.com\libs\avcodec-51.dll
2009-04-11 06:33 . 2009-05-26 23:10 986600 ----a-w- c:\windows\system32\winload.exe
2009-04-11 06:33 . 2009-05-26 23:09 926184 ----a-w- c:\windows\system32\winresume.exe
2009-04-11 06:33 . 2009-05-26 23:09 292840 ----a-w- c:\windows\system32\drivers\volmgrx.sys
2009-04-11 06:33 . 2009-05-26 23:10 897000 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-04-11 06:28 . 2009-05-26 23:09 56320 ----a-w- c:\windows\system32\xmlfilter.dll
2009-04-11 06:27 . 2009-05-26 23:10 441344 ----a-w- c:\windows\system32\SearchIndexer.exe
2009-04-11 06:22 . 2009-05-26 23:08 7168 ----a-w- c:\windows\system32\f3ahvoas.dll
2009-04-11 06:21 . 2009-05-26 23:08 37376 ----a-w- c:\windows\system32\cdd.dll
2009-04-11 05:42 . 2009-05-26 23:08 93696 ----a-w- c:\windows\system32\drivers\bridge.sys
2009-04-11 05:03 . 2009-05-26 23:11 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-04-11 05:03 . 2009-05-26 23:11 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2009-04-11 04:57 . 2009-05-26 23:08 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-04-11 04:54 . 2009-05-26 23:08 2048 ----a-w- c:\windows\system32\mferror.dll
2009-04-11 04:52 . 2009-05-26 23:08 248320 ----a-w- c:\windows\system32\drivers\rdpdr.sys
2009-04-11 04:51 . 2009-05-26 23:08 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2009-04-11 04:47 . 2009-05-26 23:08 273920 ----a-w- c:\windows\system32\drivers\afd.sys
2009-04-11 04:46 . 2009-05-26 23:08 69120 ----a-w- c:\windows\system32\drivers\rassstp.sys
2009-04-11 04:46 . 2009-05-26 23:08 121344 ----a-w- c:\windows\system32\drivers\ndiswan.sys
2009-04-11 04:46 . 2009-05-26 23:08 41472 ----a-w- c:\windows\system32\drivers\raspppoe.sys
2009-04-11 04:46 . 2009-05-26 23:08 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2009-04-11 04:46 . 2009-05-26 23:08 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2009-04-11 04:46 . 2009-05-26 23:08 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-04-11 04:45 . 2009-05-26 23:08 72192 ----a-w- c:\windows\system32\drivers\tdx.sys
2009-04-11 04:45 . 2009-05-26 23:08 72192 ----a-w- c:\windows\system32\drivers\pacer.sys
2009-04-11 04:45 . 2009-05-26 23:09 185856 ----a-w- c:\windows\system32\drivers\netbt.sys
2009-04-11 04:45 . 2009-05-26 23:09 401408 ----a-w- c:\windows\system32\drivers\http.sys
2009-04-11 04:45 . 2009-05-26 23:08 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2009-04-11 04:45 . 2009-05-26 23:08 66560 ----a-w- c:\windows\system32\drivers\smb.sys
2009-04-11 04:43 . 2009-05-26 23:08 148480 ----a-w- c:\windows\system32\drivers\nwifi.sys
2009-04-11 04:43 . 2009-05-26 23:09 196096 ----a-w- c:\windows\system32\drivers\usbhub.sys
2009-04-11 04:43 . 2009-05-26 23:08 62208 ----a-w- c:\windows\system32\drivers\ohci1394.sys
2009-04-11 04:43 . 2009-05-26 23:09 236544 ----a-w- c:\windows\system32\drivers\HdAudio.sys
2009-04-11 04:42 . 2009-05-26 23:09 226304 ----a-w- c:\windows\system32\drivers\usbport.sys
2009-04-11 04:42 . 2009-05-26 23:08 25856 ----a-w- c:\windows\system32\drivers\USBCAMD2.sys
2009-04-11 04:42 . 2009-05-26 23:08 25856 ----a-w- c:\windows\system32\drivers\USBCAMD.sys
2009-04-11 04:42 . 2009-05-26 23:08 73216 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2009-04-11 04:42 . 2009-05-26 23:09 39936 ----a-w- c:\windows\system32\drivers\usbehci.sys
2009-04-11 04:42 . 2009-05-26 23:08 19456 ----a-w- c:\windows\system32\drivers\usbohci.sys
2009-04-11 04:42 . 2009-05-26 23:08 167936 ----a-w- c:\windows\system32\drivers\portcls.sys
2009-04-11 04:42 . 2009-05-26 23:08 12800 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-04-11 04:42 . 2009-05-26 23:08 39424 ----a-w- c:\windows\system32\drivers\hidclass.sys
2009-04-11 04:42 . 2009-05-26 23:08 52992 ----a-w- c:\windows\system32\drivers\stream.sys
2009-04-11 04:42 . 2009-05-26 23:11 561152 ----a-w- c:\windows\system32\drivers\hdaudbus.sys
2009-04-11 04:39 . 2009-05-26 23:08 16384 ----a-w- c:\windows\system32\iscsilog.dll
2009-04-11 04:39 . 2009-05-26 23:08 67072 ----a-w- c:\windows\system32\drivers\cdrom.sys
2009-04-11 04:39 . 2009-05-26 23:08 19456 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2009-04-11 04:38 . 2009-05-26 23:09 149504 ----a-w- c:\windows\system32\drivers\ks.sys
2009-04-11 04:27 . 2009-05-26 23:08 2560 ----a-w- c:\windows\system32\msimsg.dll
2009-04-11 04:23 . 2009-05-26 23:10 626176 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-04-11 04:23 . 2009-05-26 23:08 76288 ----a-w- c:\windows\system32\drivers\dxg.sys
2009-04-11 04:23 . 2009-05-26 23:08 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-04-11 04:22 . 2009-05-26 23:08 33280 ----a-w- c:\windows\system32\drivers\watchdog.sys
2009-04-11 04:19 . 2009-05-26 23:08 89088 ----a-w- c:\windows\system32\drivers\sdbus.sys
2009-04-11 04:15 . 2009-05-26 23:09 288768 ----a-w- c:\windows\system32\drivers\srv.sys
2009-04-11 04:15 . 2009-05-26 23:09 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-04-11 04:15 . 2009-05-26 23:09 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2009-04-11 04:14 . 2009-05-26 23:09 351744 ----a-w- c:\windows\system32\drivers\csc.sys
2009-04-11 04:14 . 2009-05-26 23:09 114688 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2009-04-11 04:14 . 2009-05-26 23:09 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-04-11 04:14 . 2009-05-26 23:09 225280 ----a-w- c:\windows\system32\drivers\rdbss.sys
2009-04-11 04:14 . 2009-05-26 23:09 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2009-04-11 04:14 . 2009-05-26 23:09 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-04-11 04:14 . 2009-05-26 23:08 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2009-04-11 04:14 . 2009-05-26 23:08 35328 ----a-w- c:\windows\system32\drivers\npfs.sys
2009-04-11 04:13 . 2009-05-26 23:08 226816 ----a-w- c:\windows\system32\drivers\udfs.sys
2009-04-11 04:13 . 2009-05-26 23:08 136704 ----a-w- c:\windows\system32\drivers\exfat.sys
2009-04-11 04:13 . 2009-05-26 23:08 142848 ----a-w- c:\windows\system32\drivers\fastfat.sys
2009-04-11 04:12 . 2009-05-26 23:09 617984 ----a-w- c:\windows\system32\adtschema.dll
2009-04-11 02:52 . 2009-05-26 23:11 684032 ----a-w- c:\windows\system32\drivers\spsys.sys
2009-04-11 01:59 . 2009-05-26 23:10 107612 ----a-w- c:\windows\system32\StructuredQuerySchema.bin
2009-03-30 04:42 . 2009-05-26 23:10 278848 ----a-w- c:\windows\system32\mscoree.dll
2009-03-30 04:42 . 2009-05-26 23:09 93512 ----a-w- c:\windows\system32\dfshim.dll
2009-03-30 04:42 . 2009-05-26 23:09 80720 ----a-w- c:\windows\system32\mscories.dll
2009-03-30 04:42 . 2009-05-26 23:09 155456 ----a-w- c:\windows\system32\mscorier.dll
2006-11-22 14:58 . 2006-11-22 14:58 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnhancedStorageShell]
@="{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}"
[HKEY_CLASSES_ROOT\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}]
2009-04-11 06:28 114176 ----a-w- c:\windows\System32\EhStorShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 1443072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-10 148888]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"BindDirectlyToPropertySetStorage"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):33,2c,f5,7b,75,de,c9,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4201862066-2541551795-1737911188-1000]
"EnableNotificationsRef"=dword:00000002
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
R1 epfwtdir;epfwtdir;c:\windows\System32\drivers\epfwtdir.sys [20/02/2008 11:11 33800]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [20/02/2008 11:08 472320]
R3 b57nd60x;%SvcDispName%;c:\windows\System32\drivers\b57nd60x.sys [16/05/2009 17:09 179712]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\System32\regedt32.exe [02/11/2006 09:32 9216]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Majid\AppData\Roaming\Mozilla\Firefox\Profiles\fzwe655r.default\
FF - prefs.js: browser.search.selectedEngine - DramaWiki (en)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.ftp - proxy.sap.hokkyodai.ac.jp
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - proxy.sap.hokkyodai.ac.jp
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.socks - proxy.sap.hokkyodai.ac.jp
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - proxy.sap.hokkyodai.ac.jp
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 4
FF - component: c:\users\Majid\AppData\Roaming\Mozilla\Firefox\Profiles\fzwe655r.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-11 16:56
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.032"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.abr"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.ani"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.arw"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.bay"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.bmp"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.bw"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.cr2"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.crw"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.cs1"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.cur"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.dcr"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.dcx"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.dib"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.djv"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.djvu"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.dng"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.emf"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.eps"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.erf"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.fff"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.fpx"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.gif"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.hdr"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.icl"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.icn"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.iff"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.ilbm"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.int"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.inta"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.iw4"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.j2c"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.j2k"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jbr"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jfif"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jif"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jp2"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jpc"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jpe"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jpeg"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jpg"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jpk"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jpx"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.kdc"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.lbm"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.mef"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.mos"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.mrw"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.nef"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.orf"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pbm"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pbr"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pcd"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pct"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pcx"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pef"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pgm"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pic"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pict"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pix"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.png"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.ppm"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.psd"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.psp"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pspbrush"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pspimage"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.raf"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.ras"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.raw"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.rgb"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.rgba"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.rle"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.rsb"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.rw2"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.sgi"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.sr2"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.srf"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.tga"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.thm"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.tif"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.tiff"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.ttc"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.ttf"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v11o\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.v11o"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v11p\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.v11p"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v11pf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.v11pf"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.wbm"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.wbmp"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.wmf"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.xbm"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.xif"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.xmp"
[HKEY_USERS\S-1-5-21-4201862066-2541551795-1737911188-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.xpm"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(848)
c:\windows\system32\relog_ap.dll
.
Completion time: 2009-06-11 16:58
ComboFix-quarantined-files.txt 2009-06-11 15:57
Pre-Run: 5,709,209,600 bytes free
Post-Run: 5,633,122,304 bytes free
586 --- E O F --- 2009-06-10 13:58