ComboFix Log:
ComboFix 09-04-17.01 - Student 04/16/2009 14:12.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.447.161 [GMT -7:00]
Running from: c:\documents and settings\Student\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Student\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\jurj.exe
c:\windows\Cfagazuyufom.dat
c:\windows\instsp2.exe
c:\windows\system32\boguwuhu.exe
c:\windows\system32\huvagobi.exe
c:\windows\system32\jazoloya.exe
c:\windows\system32\kivifivu.dll.vir
c:\windows\Xwofiwam.bin
C:\xnfd.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Seekapp
c:\documents and settings\All Users\Application Data\Seekapp\seekapp131.exe
c:\documents and settings\Student\Local Settings\Application Data\{BEF2BB6F-0B50-4738-9E57-DF0B826A7C0E}
c:\documents and settings\Student\Local Settings\Application Data\{BEF2BB6F-0B50-4738-9E57-DF0B826A7C0E}\chrome.manifest
c:\documents and settings\Student\Local Settings\Application Data\{BEF2BB6F-0B50-4738-9E57-DF0B826A7C0E}\chrome\content\_cfg.js
c:\documents and settings\Student\Local Settings\Application Data\{BEF2BB6F-0B50-4738-9E57-DF0B826A7C0E}\chrome\content\c.js
c:\documents and settings\Student\Local Settings\Application Data\{BEF2BB6F-0B50-4738-9E57-DF0B826A7C0E}\chrome\content\overlay.xul
c:\documents and settings\Student\Local Settings\Application Data\{BEF2BB6F-0B50-4738-9E57-DF0B826A7C0E}\install.rdf
C:\jurj.exe
c:\program files\Seekapp
c:\program files\Seekapp\readme.html
c:\program files\Seekapp\seekapp.dll
c:\program files\Seekapp\seekapp.exe
c:\program files\Seekapp\uninstall.exe
c:\windows\Cfagazuyufom.dat
c:\windows\instsp2.exe
c:\windows\system32\boguwuhu.exe
c:\windows\system32\huvagobi.exe
c:\windows\system32\jazoloya.exe
c:\windows\system32\kivifivu.dll.vir
c:\windows\Xwofiwam.bin
C:\xnfd.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FCI
-------\Legacy_SEEKAPP_SERVICE
-------\Service_FCI
-------\Service_Seekapp Service
((((((((((((((((((((((((( Files Created from 2009-03-16 to 2009-04-16 )))))))))))))))))))))))))))))))
.
2009-04-16 21:17 . 2009-04-16 21:17 -------- d-----w c:\documents and settings\Student\Local Settings\Application Data\{AF69389A-FCD4-4ADE-AA55-2047887F4793}
2009-04-16 08:04 . 2009-04-16 08:04 -------- d-----w c:\program files\Dragon UnPACKer 5
2009-04-15 08:03 . 2009-04-15 08:03 -------- d-----w c:\documents and settings\Student\Application Data\Stardock
2009-04-15 08:03 . 2009-04-15 08:03 -------- dc-h--w c:\documents and settings\All Users\Application Data\{62902F53-D725-44F9-B385-979CC0E00E8A}
2009-04-15 08:02 . 2009-04-15 08:04 -------- d-----w c:\program files\Stardock
2009-04-15 08:02 . 2009-04-15 08:02 -------- d-----w c:\documents and settings\All Users\Application Data\Stardock
2009-04-13 05:18 . 2009-04-13 05:18 -------- d-----w c:\program files\ffdshow
2009-04-13 05:18 . 2009-04-14 00:45 -------- d-----w c:\documents and settings\Student\Application Data\Sp4rkMod
2009-04-12 02:23 . 2009-04-12 02:23 -------- d-----w C:\VundoFix Backups
2009-04-12 01:50 . 2009-04-12 01:50 -------- d-----w c:\program files\Common Files\Adobe AIR
2009-04-11 21:36 . 2009-04-15 08:06 -------- d-----w c:\documents and settings\Student\Local Settings\Application Data\Stardock
2009-04-11 21:29 . 2009-04-11 21:29 56 ----a-w c:\windows\wb.ini
2009-04-11 21:29 . 2009-04-11 21:29 -------- d-----w c:\program files\Common Files\Stardock
2009-04-11 21:29 . 2003-02-27 05:27 36864 ----a-w c:\windows\system32\wbsys.dll
2009-04-11 21:29 . 2009-04-16 07:23 -------- d-----w c:\program files\AlienGUIse
2009-04-11 19:49 . 2009-04-11 19:49 -------- d-----w c:\program files\Crytek
2009-04-11 06:01 . 2009-04-11 06:01 -------- d-----w c:\documents and settings\Student\Application Data\Thinking Minds Budiling Bytes
2009-04-10 01:41 . 2009-04-10 01:41 73 ----a-w c:\windows\EurekaLog.ini
2009-04-10 01:18 . 2009-04-10 01:18 -------- d-----w c:\documents and settings\Student\Application Data\URSoft
2009-04-10 01:18 . 2009-04-11 20:15 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-10 01:18 . 2009-04-11 21:42 -------- d-----w c:\program files\Your Uninstaller 2008
2009-04-10 00:01 . 2009-04-10 00:05 -------- d-----w c:\program files\SystemRequirementsLab
2009-04-10 00:01 . 2009-04-10 00:01 -------- d-----w c:\documents and settings\Student\Application Data\SystemRequirementsLab
2009-04-09 02:37 . 2009-04-09 02:37 6144 --sha-w c:\windows\system32\Thumbs.db
2009-04-08 05:40 . 2009-04-08 05:40 4096 ----a-w c:\windows\d3dx.dat
2009-04-07 19:13 . 2009-04-07 19:13 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-04-07 05:09 . 2009-04-07 05:09 -------- d-----w c:\windows\system32\Adobe
2009-04-04 22:42 . 2009-04-04 22:42 -------- d-----w c:\program files\JanSoft
2009-04-04 22:33 . 2004-01-08 18:38 208896 ----a-w c:\windows\system\lame_enc.dll
2009-04-04 21:42 . 2009-04-04 21:42 -------- d-----w c:\documents and settings\Student\Application Data\dvdcss
2009-04-04 18:55 . 2007-06-29 21:47 34304 ----a-w c:\windows\system32\drivers\AmdLLD.sys
2009-04-04 18:55 . 2009-04-04 18:55 -------- d-----w c:\program files\AMD
2009-04-04 18:50 . 2009-04-04 18:51 -------- d-----w c:\windows\system32\The Future Is Fusion dir
2009-04-04 18:50 . 2009-04-04 18:50 520192 ----a-w c:\windows\system32\The Future Is Fusion.scr
2009-04-04 02:12 . 2009-04-04 02:12 -------- d-----w c:\program files\Ubisoft
2009-04-03 06:51 . 2004-08-04 07:56 21504 -c--a-w c:\windows\system32\dllcache\hidserv.dll
2009-04-03 06:51 . 2004-08-04 07:56 21504 ----a-w c:\windows\system32\hidserv.dll
2009-04-02 23:01 . 2009-04-04 02:01 -------- d-----w c:\program files\the Rosenrot Screensaver
2009-03-31 21:42 . 2009-03-31 21:51 -------- d-----w c:\documents and settings\Student\Application Data\vlc
2009-03-31 21:41 . 2009-03-31 21:41 -------- d-----w c:\program files\VideoLAN
2009-03-31 21:18 . 2008-12-20 23:15 52224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll
2009-03-31 21:18 . 2008-12-20 23:15 459264 -c----w c:\windows\system32\dllcache\msfeeds.dll
2009-03-31 21:18 . 2008-12-20 23:15 267776 -c----w c:\windows\system32\dllcache\iertutil.dll
2009-03-31 21:18 . 2008-12-20 23:15 6066688 -c----w c:\windows\system32\dllcache\ieframe.dll
2009-03-31 21:18 . 2008-12-20 23:15 383488 -c----w c:\windows\system32\dllcache\ieapfltr.dll
2009-03-31 21:18 . 2008-12-19 09:10 13824 -c----w c:\windows\system32\dllcache\ieudinit.exe
2009-03-31 21:18 . 2007-03-08 05:10 991232 -c----w c:\windows\system32\dllcache\ieframe.dll.mui
2009-03-31 21:18 . 2008-12-20 23:15 63488 -c----w c:\windows\system32\dllcache\icardie.dll
2009-03-31 21:18 . 2007-04-17 09:32 2455488 -c----w c:\windows\system32\dllcache\ieapfltr.dat
2009-03-31 20:30 . 2009-03-31 20:30 253688 ----a-w c:\windows\system32\cssdll32.dll.vir
2009-03-31 20:30 . 2009-04-01 08:07 -------- d-----w c:\program files\AskBarDis
2009-03-31 20:26 . 2009-03-31 23:47 -------- d-----w c:\documents and settings\All Users\Application Data\Comodo
2009-03-31 20:26 . 2009-03-31 23:50 -------- d-----w c:\program files\COMODO
2009-03-31 20:24 . 2009-03-31 20:24 -------- d-----w c:\windows\system32\CatRoot_bak
2009-03-31 00:33 . 2009-03-31 00:33 -------- d-----w c:\program files\PQDVD
2009-03-30 22:36 . 2009-03-30 22:36 -------- d-----w c:\program files\Xiph.Org
2009-03-29 02:25 . 2009-03-31 22:15 -------- d-----w c:\program files\Peretek
2009-03-29 00:18 . 2009-03-29 00:18 -------- d-----w c:\documents and settings\Student\Local Settings\Application Data\SRS Labs
2009-03-29 00:18 . 2009-03-29 00:18 -------- d-----w c:\documents and settings\All Users\Application Data\SRS Labs
2009-03-29 00:16 . 2007-07-26 16:25 39808 ----a-r c:\windows\system32\drivers\SRS_SSCFilter_i386.sys
2009-03-29 00:16 . 2007-07-26 16:25 42112 ----a-r c:\windows\system32\drivers\csiidecoder_kern_i386.sys
2009-03-29 00:16 . 2007-07-26 16:25 47360 ----a-r c:\windows\system32\drivers\Surroundhp_kern_i386.sys
2009-03-29 00:16 . 2007-07-26 16:25 47104 ----a-r c:\windows\system32\drivers\tshd4_kern_i386.sys
2009-03-29 00:16 . 2007-07-26 16:25 32000 ----a-r c:\windows\system32\drivers\wowhd_kern_i386.sys
2009-03-29 00:16 . 2009-03-29 00:16 -------- d-----w c:\program files\SRS Labs
2009-03-25 09:12 . 2009-04-02 22:58 818753 ----a-w c:\windows\system32\the FarCry River Screensaver.scr
2009-03-25 09:10 . 2009-04-13 05:54 -------- d-----w c:\program files\the FarCry River Screensaver
2009-03-25 09:08 . 2009-03-31 22:15 -------- d-----w c:\program files\the FarCry Slideshow
2009-03-25 09:06 . 2009-03-25 09:06 818753 ----a-w c:\windows\system32\My Screensaver.scr
2009-03-25 02:41 . 2009-03-25 02:41 -------- d-----w c:\program files\Audacity
2009-03-22 06:04 . 2009-03-25 06:31 -------- d-----w c:\documents and settings\Student\Application Data\IGN_DLM
2009-03-21 06:18 . 2009-03-21 06:18 -------- d-----w c:\program files\Common Files\DirectX
2009-03-21 06:16 . 2009-04-11 20:33 -------- d-----w c:\program files\SCi Games
2009-03-21 02:56 . 2009-03-21 02:56 -------- d-----w c:\program files\Trend Micro
2009-03-21 01:57 . 2009-03-21 02:03 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-21 01:57 . 2009-03-21 02:03 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-21 01:56 . 2009-03-21 01:56 -------- d-----w c:\documents and settings\Student\Application Data\Uniblue
2009-03-21 01:55 . 2009-04-11 20:18 -------- dc-h--w c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-03-21 01:35 . 2009-03-21 01:35 -------- d-----w c:\documents and settings\Student\Application Data\Simply Super Software
2009-03-20 19:07 . 2009-04-16 05:07 7680 --sha-w c:\windows\Thumbs.db
2009-03-20 04:00 . 2009-04-10 07:21 -------- d-----w c:\program files\OgreDemo
2009-03-19 20:57 . 2009-03-19 20:57 -------- d-----w c:\documents and settings\Student\Application Data\.ZMatrix
2009-03-19 20:57 . 2009-03-20 06:24 -------- d-----w c:\program files\ZMatrix
2009-03-19 20:57 . 2009-03-19 20:57 68 ----a-w c:\windows\ZMatrixSS.ini
2009-03-19 20:54 . 2009-03-19 20:54 -------- d-----w c:\program files\KellySoftware
2009-03-19 00:00 . 2009-03-19 01:18 -------- d-----w c:\program files\MyBot
2009-03-18 23:56 . 2009-03-18 23:57 -------- d-----w c:\program files\Buddy Icon Maker
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-16 21:17 . 2007-06-08 21:46 -------- d-----w c:\program files\OfficeScan NT
2009-04-16 16:34 . 2009-03-17 08:24 -------- d-----w c:\program files\Isotope244 Graphics
2009-04-14 08:46 . 2006-02-28 12:00 182912 ----a-w c:\windows\system32\drivers\ndis.sys
2009-04-13 02:10 . 2006-07-11 05:47 -------- d-----w c:\program files\Java
2009-04-12 20:08 . 2006-02-28 12:00 14336 ----a-w c:\windows\system32\svchost.exe
2009-04-12 02:41 . 2009-04-12 02:23 136 ----a-w C:\VundoFix.txt
2009-04-11 20:31 . 2006-07-11 05:39 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-10 07:13 . 2009-03-14 05:54 -------- d-----w c:\program files\Extension Changer
2009-04-10 01:24 . 2009-03-14 01:39 -------- d-----w c:\program files\Common Files\Apple
2009-04-07 01:23 . 2009-03-13 03:56 45680 ----a-w c:\documents and settings\Student\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-21 02:05 . 2009-03-14 01:42 -------- d-----w c:\program files\Bonjour
2009-03-21 01:28 . 2009-03-14 01:40 -------- d-----w c:\program files\QuickTime
2009-03-18 06:11 . 2009-03-15 02:47 -------- d-----w c:\program files\YouTube Downloader
2009-03-18 06:11 . 2009-03-13 02:12 -------- d-----w c:\program files\Windows Media Connect 2
2009-03-17 23:27 . 2009-03-17 08:24 -------- d-----w c:\documents and settings\Student\Application Data\Isotope 244
2009-03-16 09:36 . 2009-03-16 09:18 103509 ----a-w c:\windows\hpoins04.dat
2009-03-16 09:36 . 2009-03-16 09:36 -------- d-----w c:\program files\Common Files\Hewlett-Packard
2009-03-16 09:36 . 2006-07-11 05:39 -------- d-----w c:\program files\Hewlett-Packard
2009-03-16 09:34 . 2006-07-11 05:56 -------- d-----w c:\program files\Hp
2009-03-15 00:30 . 2009-03-15 00:30 98304 ----a-w c:\windows\system32\CmdLineExt.dll
2009-03-14 23:55 . 2009-03-14 23:55 -------- d-----w c:\program files\Rockstar Games
2009-03-14 04:09 . 2009-03-14 04:08 -------- d-----w c:\program files\Paint.NET
2009-03-14 01:49 . 2009-03-14 01:43 -------- d-----w c:\documents and settings\Student\Application Data\Apple Computer
2009-03-14 01:43 . 2009-03-14 01:42 -------- d-----w c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-14 01:42 . 2009-03-14 01:40 -------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-03-14 01:40 . 2009-03-14 01:40 -------- d-----w c:\program files\Apple Software Update
2009-03-14 01:39 . 2009-03-14 01:39 -------- d-----w c:\documents and settings\All Users\Application Data\Apple
2009-03-13 17:42 . 2009-03-13 17:42 -------- d-----w c:\documents and settings\Student\Application Data\Sonic
2009-03-13 17:42 . 2009-03-13 17:42 -------- d-----w c:\documents and settings\Student\Application Data\Leadertech
2009-03-13 03:55 . 2009-03-13 03:55 -------- d-----w c:\documents and settings\All Users\Application Data\ATI
2009-03-13 03:55 . 2007-06-15 02:11 -------- d-----w c:\documents and settings\Student\Application Data\ATI
2009-03-13 02:09 . 2006-07-11 06:10 -------- d-----w c:\program files\Windows Media Connect
2009-03-13 02:02 . 2009-03-13 02:01 -------- d-----w c:\documents and settings\All Users\Application Data\AOL OCP
2009-03-13 02:01 . 2009-03-13 02:01 -------- d-----w c:\documents and settings\Student\Application Data\acccore
2009-03-13 02:01 . 2009-03-12 23:00 461 ---ha-w C:\IPH.PH
2009-03-13 02:01 . 2009-03-13 02:00 -------- d-----w c:\program files\AIM6
2009-03-13 02:01 . 2009-03-13 02:01 -------- d-----w c:\program files\Viewpoint
2009-03-13 02:01 . 2009-03-13 02:01 -------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-03-13 02:01 . 2009-03-13 02:01 -------- d-----w c:\documents and settings\All Users\Application Data\acccore
2009-03-13 02:01 . 2009-03-13 02:01 -------- d-----w c:\documents and settings\All Users\Application Data\AOL
2009-03-13 02:00 . 2009-03-13 02:00 -------- d-----w c:\program files\Common Files\AOL
2009-03-12 22:29 . 2006-07-11 05:54 -------- d-----w c:\program files\ATI Technologies
2009-03-12 22:19 . 2007-05-17 22:57 -------- d-----w c:\documents and settings\Administrator\Application Data\ATI
2009-03-12 22:19 . 2007-05-10 00:16 -------- d-----w c:\documents and settings\admin\Application Data\ATI
2009-03-12 22:07 . 2009-03-12 21:32 -------- d-----w c:\program files\Microsoft Games
2009-03-12 21:40 . 2009-03-12 21:40 109208 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-03-12 21:39 . 2009-03-12 21:39 -------- d-----w c:\program files\MSBuild
2009-03-12 21:39 . 2009-03-12 21:39 -------- d-----w c:\program files\Reference Assemblies
2009-03-12 21:34 . 2009-03-12 21:34 -------- d-----w c:\program files\MSXML 6.0
2009-03-12 21:19 . 2009-03-12 21:19 -------- d-----w c:\program files\RADVideo
2009-03-12 21:19 . 2009-03-12 21:19 -------- d-----w c:\program files\Opera
2009-03-09 12:19 . 2009-03-16 22:56 410984 ----a-w c:\windows\system32\deploytk.dll
2009-02-10 07:46 . 2009-02-10 07:46 3013120 ----a-w c:\windows\Matrix_ks.SCR
2009-02-09 10:19 . 2006-02-28 12:00 1846272 ----a-w c:\windows\system32\win32k.sys
2009-02-04 05:03 . 2009-02-04 05:03 290816 ----a-w c:\windows\system32\atiok3x2.dll
2009-02-04 04:56 . 2009-02-04 04:56 442368 ----a-w c:\windows\system32\ATIDEMGX.dll
2009-02-04 04:44 . 2009-02-04 04:44 155648 ----a-w c:\windows\system32\Oemdspif.dll
2009-02-04 04:13 . 2009-02-04 04:13 887724 ----a-w c:\windows\system32\ativva6x.dat
2009-02-04 04:13 . 2009-02-04 04:13 3107788 ----a-w c:\windows\system32\ativva5x.dat
2009-02-04 04:05 . 2009-03-12 22:17 593920 ------w c:\windows\system32\ati2sgag.exe
2009-02-04 03:58 . 2009-02-04 03:58 49664 ----a-w c:\windows\system32\amdpcom32.dll
2009-02-04 03:53 . 2009-02-04 03:53 122880 ----a-w c:\windows\system32\atiadlxx.dll
2009-02-04 02:43 . 2009-02-04 02:43 45056 ----a-w c:\windows\system32\aticalrt.dll
2009-02-04 02:42 . 2009-02-04 02:42 45056 ----a-w c:\windows\system32\aticalcl.dll
2009-02-04 02:40 . 2009-02-04 02:40 3244032 ----a-w c:\windows\system32\aticaldd.dll
2007-06-26 00:53 . 2007-06-26 00:53 33456 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2007-06-15 02:16 . 2007-06-15 02:11 130 ----a-w c:\documents and settings\Student\Local Settings\Application Data\fusioncache.dat
2007-06-08 02:33 . 2007-05-17 22:57 136 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2007-05-10 00:18 . 2007-05-10 00:16 128 ----a-w c:\documents and settings\admin\Local Settings\Application Data\fusioncache.dat
2009-01-11 20:08 . 2009-01-11 20:08 71680 --sha-w c:\windows\system32\watekaho.dll.vir
.
((((((((((((((((((((((((((((( SnapShot@2009-04-12_18.49.35.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-16 21:17 . 2009-04-16 21:17 16384 c:\windows\Temp\Perflib_Perfdata_678.dat
- 2009-04-04 02:13 . 2009-04-04 02:13 40960 c:\windows\Installer\{471BB1D9-6F59-4093-B46D-373772D5C111}\PlayFarCryShortcut_5D5785608EA2413A81BC34862580C935.exe
+ 2009-04-15 22:29 . 2009-04-15 22:29 40960 c:\windows\Installer\{471BB1D9-6F59-4093-B46D-373772D5C111}\PlayFarCryShortcut_5D5785608EA2413A81BC34862580C935.exe
- 2009-04-04 02:13 . 2009-04-04 02:13 40960 c:\windows\Installer\{471BB1D9-6F59-4093-B46D-373772D5C111}\FarCryDesktopShortcu_5D5785608EA2413A81BC34862580C935.exe
+ 2009-04-15 22:29 . 2009-04-15 22:29 40960 c:\windows\Installer\{471BB1D9-6F59-4093-B46D-373772D5C111}\FarCryDesktopShortcu_5D5785608EA2413A81BC34862580C935.exe
+ 2009-04-15 08:05 . 2009-04-15 08:05 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\WBOCXLib\4ab8d146645c38200663578f909d1412\WBOCXLib.ni.dll
+ 2009-04-15 08:05 . 2009-04-15 08:05 73728 c:\windows\assembly\NativeImages_v2.0.50727_32\StardockCentralDSkin\e42dd94dbccbafc11a9de0f980027210\StardockCentralDSkin.ni.dll
+ 2009-04-15 08:03 . 2009-04-15 08:03 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Stardock.Central.Se#\2f47bba10e7be4921155b60df8f6b1c1\Stardock.Central.Security.ni.dll
+ 2009-04-15 08:03 . 2009-04-15 08:03 17920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\cd0730694ba5927a6efd32129783e1b4\Microsoft.VisualC.ni.dll
- 2009-04-04 02:13 . 2009-04-04 02:13 2238 c:\windows\Installer\{471BB1D9-6F59-4093-B46D-373772D5C111}\ARPPRODUCTICON.exe
+ 2009-04-15 22:29 . 2009-04-15 22:29 2238 c:\windows\Installer\{471BB1D9-6F59-4093-B46D-373772D5C111}\ARPPRODUCTICON.exe
+ 2006-08-31 19:34 . 2006-08-31 19:34 516161 c:\windows\system32\ss244tie.scr
+ 2004-01-12 21:52 . 2004-01-12 21:52 606280 c:\windows\system32\ss244ld.scr
- 2009-03-16 22:56 . 2009-03-16 22:55 148888 c:\windows\system32\javaws.exe
+ 2009-04-13 02:10 . 2009-03-09 12:19 148888 c:\windows\system32\javaws.exe
- 2009-03-16 22:56 . 2009-03-16 22:55 144792 c:\windows\system32\javaw.exe
+ 2009-04-13 02:10 . 2009-03-09 12:19 144792 c:\windows\system32\javaw.exe
+ 2009-04-13 02:10 . 2009-03-09 12:19 144792 c:\windows\system32\java.exe
- 2009-03-16 22:56 . 2009-03-16 22:55 144792 c:\windows\system32\java.exe
+ 2005-11-02 15:35 . 2005-11-02 15:35 162304 c:\windows\system32\fmod.dll
+ 2006-02-28 12:00 . 2009-04-14 08:46 182912 c:\windows\system32\dllcache\ndis.sys
+ 2009-04-15 08:04 . 2009-04-15 08:04 282624 c:\windows\assembly\NativeImages_v2.0.50727_32\VistaBridgeLibrary\c6e1dd3086ade6ca4527a09892616618\VistaBridgeLibrary.ni.dll
+ 2009-04-15 08:04 . 2009-04-15 08:04 499712 c:\windows\assembly\NativeImages_v2.0.50727_32\VDialog\67a74495a83ad45cdb19d1a5a78a5e3a\VDialog.ni.dll
+ 2009-04-15 08:03 . 2009-04-15 08:03 815104 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\
0898f6c1de8cb89413d206e3d6a3ce1d\System.Runtime.Remoting.ni.dll
+ 2009-04-15 08:05 . 2009-04-15 08:05 229376 c:\windows\assembly\NativeImages_v2.0.50727_32\SharpBITS.Base\7c5adebe6d676d54766dc1e6be41928f\SharpBITS.Base.ni.dll
+ 2009-04-15 08:04 . 2009-04-15 08:04 229376 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd\c34911272b8fd42f8a97b9759e037cbb\Sd.ni.dll
+ 2009-04-15 08:05 . 2009-04-15 08:05 450560 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Zip\750b105dcb921d1c86dcc43660525dc7\Sd.Zip.ni.dll
+ 2009-04-15 08:05 . 2009-04-15 08:05 770048 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Web\45cddd9816b79bff2ec0ad9f44e8591e\Sd.Web.ni.dll
+ 2009-04-15 08:05 . 2009-04-15 08:05 102400 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Uninstall\59e3c46bdc127231e538240d83b29cf7\Sd.Uninstall.ni.dll
+ 2009-04-15 08:04 . 2009-04-15 08:04 167936 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.UI\f20b33e8d0a3cc6771e5558bc1d6e609\Sd.UI.ni.dll
+ 2009-04-15 08:04 . 2009-04-15 08:04 843776 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Irc\edc16d7bc521ec79faea73fa13aeaac5\Sd.Irc.ni.dll
+ 2009-04-15 08:05 . 2009-04-15 08:05 303104 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.InstallManager\ecefd9763e06f3c8ada4bf99ed914a75\Sd.InstallManager.ni.dll
+ 2009-04-15 08:05 . 2009-04-15 08:05 569344 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Common.XmlSerial#\
0c6544996cf191972c3386fed5fe528d\Sd.Common.XmlSerializers.ni.dll
+ 2009-04-15 08:05 . 2009-04-15 08:05 643072 c:\windows\assembly\NativeImages_v2.0.50727_32\sd.central.cvp.serv#\7f4c0711a0e144e38f984efccaf447b2\sd.central.cvp.server.ni.dll
+ 2009-04-15 08:05 . 2009-04-15 08:05 147456 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Central.Archive\fc6a6ef8f2ee10b48038f91b95bdb693\Sd.Central.Archive.ni.dll
+ 2009-04-15 08:05 . 2009-04-15 08:05 335872 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Central.Archive.#\b6e50462fae9a8a4ef3620177e71b19f\Sd.Central.Archive.XmlSerializers.ni.dll
+ 2009-04-15 08:05 . 2009-04-15 08:05 331776 c:\windows\assembly\NativeImages_v2.0.50727_32\MyDock.Util\98e03556d9e4c3cc42e58229ab312217\MyDock.Util.ni.dll
+ 2009-04-15 08:05 . 2009-04-15 08:05 118784 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.IWshRuntime#\a3b00a471b21a87bbd11d8646a134b94\Interop.IWshRuntimeLibrary.ni.dll
+ 2009-04-15 08:03 . 2009-04-15 08:03 700416 c:\windows\assembly\NativeImages_v2.0.50727_32\ICSharpCode.SharpZi#\9ecc5b644b392cf96b88a9b9a5f7f1e6\ICSharpCode.SharpZipLib.ni.dll
+ 2009-04-15 08:03 . 2009-04-15 08:03 1183744 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\1abdb47765d0696a2fc0a1095bac0249\System.Data.OracleClient.ni.dll
+ 2009-04-15 08:03 . 2009-04-15 08:03 1282048 c:\windows\assembly\NativeImages_v2.0.50727_32\Sd.Common\582738e89f90221677ad8b1d501acb0c\Sd.Common.ni.dll
+ 2009-04-15 08:05 . 2009-04-15 08:05 5959680 c:\windows\assembly\NativeImages_v2.0.50727_32\Impulse\b8b2a17619c4c2e0ee2309cc22a3661d\Impulse.ni.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4c39ece2-e0cf-4110-affc-c119de4ce517}]
c:\windows\system32\duputiva.dll [BU]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B2BA40A2-74F3-42BD-F434-2604812C8954}]
c:\windows\system32\hsf73ikmdf3f.dll [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
c:\documents and settings\Student\Start Menu\Programs\Startup\
ImpulseNow.lnk - c:\program files\Stardock\Impulse\Now\ImpulseNow.exe [2009-4-7 323584]
Stardock ObjectDock.lnk - c:\program files\Stardock\Object Desktop\ObjectDock\ObjectDock.exe [2009-4-15 3446512]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-2-15 581693]
DVD Check.lnk - c:\program files\InterVideo\DVD Check\DVDCheck.exe [2007-5-9 184320]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableChangePassword"= 1 (0x1)
"DisableLockWorkstation"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
"NoNetConnectDisconnect"= 1 (0x1)
"NoManageMyComputerVerb"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoStartMenuNetworkPlaces"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoThemesTab"= 1 (0x1)
"NoPropertiesRecycleBin"= 1 (0x1)
"NoFolderOptions"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{B2BA40A2-74F3-42BD-F434-2604812C8954}"= "c:\windows\system32\hsf73ikmdf3f.dll" [BU]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "c:\windows\system32\zesiyaza.dll" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\zesiyaza.dll [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 06:34 24576 ----a-w c:\program files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli mshpoce.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Microsoft Games\\Halo Custom Edition\\haloce.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Games\\Halo Trial\\halo.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Student\\Desktop\\Black & White\\Black and White\\runblack.exe"=
"c:\\Program Files\\Internet Explorer\\iexplore.exe"=
"c:\\WINDOWS\\explorer.exe"=
"c:\\WINDOWS\\system32\\logonui.exe"=
"c:\\WINDOWS\\system32\\winlogon.exe"=
"c:\\Documents and Settings\\Student\\Application Data\\Sp4rkMod\\armorsurf.exe"=
S2 TmFilter;Trend Micro Filter;c:\program files\OfficeScan NT\TmXPFlt.sys [2008-11-27 205328]
S2 TmPreFilter;Trend Micro PreFilter;c:\program files\OfficeScan NT\TmPreFlt.sys [2008-11-27 36368]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 IFXTPM;IFXTPM;c:\windows\system32\DRIVERS\IFXTPM.SYS [2005-10-21 36352]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1003ad07-1bb1-11de-949c-0017a4e3bc5c}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\ntldr.com g:
\Shell\Open\command - f:\resycled\ntldr.com g:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4191f182-22ea-11de-94a3-0017a4e3bc5c}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\ntldr.com g:
\Shell\Open\command - f:\resycled\ntldr.com g:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6ae2a78f-10f2-11de-9491-0017a4e3bc5c}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\ntldr.com g:
\Shell\Open\command - e:\resycled\ntldr.com g:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9094bbc2-12c4-11de-9493-0017a4e3bc5c}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\ntldr.com e:
\Shell\Open\command - g:\resycled\ntldr.com e:
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://schools.connectionsacademy.com/
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: aim.com\www
Trusted Zone: aol.com\iknowthat.school
Trusted Zone: aolatschool.com\www
Trusted Zone: atwola.com\ar
Trusted Zone: atwola.com\
www.ar
Trusted Zone: brainpop.com\www
Trusted Zone: connectionsacademy.com\schools
Trusted Zone: D
Trusted Zone: edgate.com\www
Trusted Zone: letsgolearn.com\www
Trusted Zone: msnbc.com
Trusted Zone: passport.net\login
Trusted Zone: schoolnotes.com
Trusted Zone: teacherweb.com
Trusted Zone: worldbookonline.com\www
FF - ProfilePath - c:\documents and settings\Student\Application Data\Mozilla\Firefox\Profiles\qhfqqwfy.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.isotope244.com/
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-16 14:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????,?@? ????Z??????R?@?????,?@
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET CLR Data]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET CLR Networking]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET Data Provider for Oracle]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET Data Provider for SqlServer]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NETFramework]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Abiosdsk]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\abp480n5]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ACPI]
"ImagePath"="system32\DRIVERS\ACPI.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ACPIEC]
"ImagePath"="system32\DRIVERS\ACPIEC.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ADIHdAudAddService]
"ImagePath"="system32\drivers\ADIHdAud.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\adpu160m]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AEAudioService]
"ImagePath"="system32\drivers\AEAudio.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aec]
"ImagePath"="system32\drivers\aec.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AFD]
"ImagePath"="\SystemRoot\System32\drivers\afd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Aha154x]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aic78u2]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aic78xx]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Alerter]
"ServiceDll"="%SystemRoot%\system32\alrsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ALG]
"ImagePath"="%SystemRoot%\System32\alg.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AliIde]
"ImagePath"="system32\DRIVERS\aliide.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AmdK8]
"ImagePath"="system32\DRIVERS\AmdK8.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AmdLLD]
"ImagePath"="system32\DRIVERS\AmdLLD.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\amsint]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AppMgmt]
"ServiceDll"="%SystemRoot%\System32\appmgmts.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Arp1394]
"ImagePath"="system32\DRIVERS\arp1394.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc3350p]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc3550]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET_1.1.4322]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET_2.0.50727]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aspnet_state]
"ImagePath"="%SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AsyncMac]
"ImagePath"="system32\DRIVERS\asyncmac.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\atapi]
"ImagePath"="system32\DRIVERS\atapi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Atdisk]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ati HotKey Poller]
"ImagePath"="%SystemRoot%\system32\Ati2evxx.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ATI Smart]
"ImagePath"="c:\windows\system32\ati2sgag.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ati2mtag]
"ImagePath"="system32\DRIVERS\ati2mtag.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Atierecord]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Atmarpc]
"ImagePath"="system32\DRIVERS\atmarpc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ATSWPDRV]
"ImagePath"="system32\DRIVERS\ATSwpDrv.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AudioSrv]
"ServiceDll"="%SystemRoot%\System32\audiosrv.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\audstub]
"ImagePath"="system32\DRIVERS\audstub.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\b57w2k]
"ImagePath"="system32\DRIVERS\b57xp32.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BattC]
"MofImagePath"="System32\Drivers\battc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BCM43XX]
"ImagePath"="system32\DRIVERS\bcmwl5.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Beep]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BITS]
"ServiceDll"="c:\windows\system32\qmgr.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Bonjour Service]
"ImagePath"="\"c:\program files\Bonjour\mDNSResponder.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Browser]
"ServiceDll"="%SystemRoot%\System32\browser.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BTKRNL]
"ImagePath"="system32\DRIVERS\btkrnl.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\btwdins]
"ImagePath"="c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BTWUSB]
"ImagePath"="System32\Drivers\btwusb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CA561]
"ImagePath"="System32\Drivers\SPCA561.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\catchme]
"ImagePath"="\??\c:\docume~1\Student\LOCALS~1\Temp\catchme.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cbidf2k]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CCDECODE]
"ImagePath"="system32\DRIVERS\CCDECODE.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cd20xrnt]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdaudio]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdfs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdrom]
"ImagePath"="system32\DRIVERS\cdrom.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Changer]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CiSvc]
"ImagePath"="%SystemRoot%\system32\cisvc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ClipSrv]
"ImagePath"="%SystemRoot%\system32\clipsrv.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\clr_optimization_v2.0.50727_32]
"ImagePath"="c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CmBatt]
"ImagePath"="system32\DRIVERS\CmBatt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CmdIde]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Compbatt]
"ImagePath"="system32\DRIVERS\compbatt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\COMSysApp]
"ImagePath"="c:\windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ContentFilter]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ContentIndex]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cpqarray]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CryptSvc]
"ServiceDll"="%SystemRoot%\System32\cryptsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dac2w2k]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dac960nt]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DcomLaunch]
"ServiceDll"="%SystemRoot%\system32\rpcss.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dhcp]
"ServiceDll"="%SystemRoot%\System32\dhcpcsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Disk]
"ImagePath"="system32\DRIVERS\disk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLABOIOM]
"ImagePath"="System32\DLA\DLABOIOM.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLACDBHM]
"ImagePath"="System32\Drivers\DLACDBHM.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLADResN]
"ImagePath"="System32\DLA\DLADResN.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLAIFS_M]
"ImagePath"="System32\DLA\DLAIFS_M.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLAOPIOM]
"ImagePath"="System32\DLA\DLAOPIOM.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLAPoolM]
"ImagePath"="System32\DLA\DLAPoolM.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLARTL_N]
"ImagePath"="System32\Drivers\DLARTL_N.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLAUDFAM]
"ImagePath"="System32\DLA\DLAUDFAM.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLAUDF_M]
"ImagePath"="System32\DLA\DLAUDF_M.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmadmin]
"ImagePath"="%SystemRoot%\System32\dmadmin.exe /com"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmboot]
"ImagePath"="System32\drivers\dmboot.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmio]
"ImagePath"="system32\DRIVERS\dmio.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmload]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmserver]
"ServiceDll"="%SystemRoot%\System32\dmserver.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DMusic]
"ImagePath"="system32\drivers\DMusic.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dnscache]
"ServiceDll"="%SystemRoot%\System32\dnsrslvr.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dpti2o]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\drmkaud]
"ImagePath"="system32\drivers\drmkaud.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DRVMCDB]
"ImagePath"="System32\Drivers\DRVMCDB.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DRVNDDM]
"ImagePath"="System32\Drivers\DRVNDDM.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\eabfiltr]
"ImagePath"="system32\DRIVERS\eabfiltr.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\eabusb]
"ImagePath"="system32\DRIVERS\eabusb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ERSvc]
"ServiceDll"="%SystemRoot%\System32\ersvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Eventlog]
"ImagePath"="%SystemRoot%\system32\services.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EventSystem]
"ServiceDll"="c:\windows\system32\es.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fastfat]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FastUserSwitchingCompatibility]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FCI]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fdc]
"ImagePath"="system32\DRIVERS\fdc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fips]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Flpydisk]
"ImagePath"="system32\DRIVERS\flpydisk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FltMgr]
"ImagePath"="system32\DRIVERS\fltMgr.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FontCache3.0.0.0]
"ImagePath"="c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fs_Rec]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ftdisk]
"ImagePath"="system32\DRIVERS\ftdisk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GEARAspiWDM]
"ImagePath"="system32\DRIVERS\GEARAspiWDM.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Gpc]
"ImagePath"="system32\DRIVERS\msgpc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HBtnKey]
"ImagePath"="system32\DRIVERS\cpqbttn.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HDAudBus]
"ImagePath"="system32\DRIVERS\HDAudBus.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\helpsvc]
"ServiceDll"="%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HidServ]
"ServiceDll"="%SystemRoot%\System32\hidserv.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HidUsb]
"ImagePath"="system32\DRIVERS\hidusb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hpn]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hpqwmiex]
"ImagePath"="c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HPZid412]
"ImagePath"="system32\DRIVERS\HPZid412.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HPZipr12]
"ImagePath"="system32\DRIVERS\HPZipr12.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HPZius12]
"ImagePath"="system32\DRIVERS\HPZius12.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HSFHWAZL]
"ImagePath"="system32\DRIVERS\HSFHWAZL.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HSF_DPV]
"ImagePath"="system32\DRIVERS\HSF_DPV.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HTTP]
"ImagePath"="System32\Drivers\HTTP.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HTTPFilter]
"ServiceDll"="%SystemRoot%\System32\w3ssl.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i2omgmt]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i2omp]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i8042prt]
"ImagePath"="system32\DRIVERS\i8042prt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IDriverT]
"ImagePath"="\"c:\program files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\idsvc]
"ImagePath"="\"c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IFXTPM]
"ImagePath"="system32\DRIVERS\IFXTPM.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Imapi]
"ImagePath"="system32\DRIVERS\imapi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ImapiService]
"ImagePath"="c:\windows\system32\imapi.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\inetaccs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ini910u]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Inport]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IntelIde]
"ImagePath"="system32\DRIVERS\intelide.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ip6Fw]
"ImagePath"="system32\DRIVERS\Ip6Fw.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpFilterDriver]
"ImagePath"="system32\DRIVERS\ipfltdrv.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpInIp]
"ImagePath"="system32\DRIVERS\ipinip.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpNat]
"ImagePath"="system32\DRIVERS\ipnat.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iPod Service]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IPSec]
"ImagePath"="system32\DRIVERS\ipsec.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IRENUM]