I understand Im taking risks with P2P software, and Im sure thats where this infection has come from. I just need to be much more careful with them than I am.
As far as the ActiveX related policy settings; I have no idea what that even means, so no.
ComboFixComboFix 09-05-25.03 - Eric 05/25/2009 17:43.5 - NTFSx86
Running from: c:\users\Eric\Downloads\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\users\Eric\AppData\Local\Temp\tmpA844.tmp
c:\users\Eric\AppData\Local\Temp\tmpA855.tmp
c:\windows\system32\drivers\gxvxcserv.sys
M:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gxvxcserv.sys
((((((((((((((((((((((((( Files Created from 2009-04-25 to 2009-05-25 )))))))))))))))))))))))))))))))
.
2009-05-25 21:45 . 2009-05-25 21:50 -------- d-----w c:\users\Eric\AppData\Local\temp
2009-05-25 19:41 . 2009-05-25 19:41 -------- d-----w c:\users\Eric\AppData\Local\AOL
2009-05-25 18:11 . 2009-05-25 18:11 -------- d-----w c:\users\Eric\AppData\Local\Adobe
2009-05-24 02:59 . 2009-05-25 21:45 -------- d-----w c:\users\Eric\AppData\Local\PMB Files
2009-05-24 02:59 . 2009-05-24 03:02 -------- d-----w c:\programdata\PMB Files
2009-05-24 02:59 . 2009-05-24 02:59 -------- d-----w c:\program files\Pando Networks
2009-05-22 02:40 . 2009-05-06 18:06 4784464 ----a-w c:\programdata\Microsoft\Windows Defender\Definition Updates\{9567BEB5-808E-42A7-A96C-61FBC60FE03E}\mpengine.dll
2009-05-21 23:19 . 2009-05-21 23:19 -------- d-----w c:\users\Eric\AppData\Local\Apple
2009-05-21 01:00 . 2009-05-21 01:00 -------- d-----w c:\users\Eric\AppData\Local\AOL OCP
2009-05-17 15:14 . 2009-05-17 15:30 -------- d-----w C:\Rooter$
2009-05-12 09:51 . 2009-05-12 09:52 -------- d-----w c:\temp\P90X+ Documents
2009-05-12 09:51 . 2009-05-12 09:52 -------- d-----w c:\temp\P90X Documents
2009-05-12 09:51 . 2009-05-12 09:51 -------- d-----w C:\temp
2009-05-10 19:43 . 2009-05-10 19:43 -------- d-----w c:\program files\Common Files\Windows Live
2009-05-06 02:13 . 2009-05-06 02:59 -------- d-----w c:\users\Eric\AppData\Local\FullTiltPoker.NET
2009-05-06 02:12 . 2009-05-24 03:39 -------- d-----w c:\program files\Full Tilt Poker.Net
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-24 03:26 . 2008-07-26 22:32 98304 ----a-w c:\programdata\NexonUS\NGM\nxgameus.dll
2009-05-24 03:26 . 2008-07-26 22:32 81920 ----a-w c:\programdata\NexonUS\NGM\npNxGameUS.dll
2009-05-24 03:26 . 2008-07-26 22:32 335872 ----a-w c:\programdata\NexonUS\NGM\NGMResource.dll
2009-05-24 03:26 . 2008-07-26 22:32 258352 ----a-w c:\programdata\NexonUS\NGM\unicows.dll
2009-05-24 03:26 . 2008-07-26 22:32 520192 ----a-w c:\programdata\NexonUS\NGM\NGMDll.dll
2009-05-24 03:26 . 2008-07-26 22:32 167936 ----a-w c:\programdata\NexonUS\NGM\NGM.exe
2009-05-21 02:47 . 2009-02-09 22:13 -------- d-----w c:\program files\Free Easy Burner
2009-05-21 01:26 . 2009-03-28 15:27 -------- d-----w c:\programdata\Google Updater
2009-05-21 01:25 . 2009-03-28 15:27 -------- d-----w c:\program files\Google
2009-05-13 07:01 . 2009-02-26 22:16 -------- d-----w c:\programdata\Microsoft Help
2009-05-13 07:00 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-05-11 01:39 . 2007-02-23 00:37 116608 ----a-w c:\users\Eric\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-10 19:45 . 2009-02-26 22:28 -------- d-----w c:\program files\Microsoft Works
2009-05-06 02:12 . 2007-02-23 01:00 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-26 01:45 . 2007-02-24 00:25 -------- d-----w c:\program files\Security
2009-04-23 20:41 . 2009-04-23 20:41 -------- d-----w c:\program files\Common Files\Adobe AIR
2009-04-23 20:37 . 2009-04-19 16:23 -------- d-----w c:\programdata\Lavasoft
2009-04-23 20:36 . 2007-07-16 20:37 -------- d-----w c:\program files\Common Files\Adobe
2009-03-17 03:16 . 2009-04-14 23:29 14848 ----a-w c:\windows\system32\apilogen.dll
2009-03-17 03:16 . 2009-04-14 23:29 25600 ----a-w c:\windows\system32\amxread.dll
2009-03-06 02:18 . 2009-03-06 02:18 108544 ----a-w c:\windows\system32\drivers\SaiK0728.sys
2009-03-03 04:24 . 2009-04-14 23:29 3503584 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:24 . 2009-04-14 23:29 3469280 ----a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:20 . 2009-04-14 23:28 826368 ----a-w c:\windows\system32\wininet.dll
2009-03-03 04:19 . 2009-04-14 23:29 158720 ----a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:19 . 2009-04-14 23:29 549888 ----a-w c:\windows\system32\rpcss.dll
2009-03-03 04:19 . 2009-04-14 23:29 24576 ----a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:16 . 2009-04-14 23:28 56320 ----a-w c:\windows\system32\iesetup.dll
2009-03-03 04:16 . 2009-04-14 23:29 97280 ----a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:16 . 2009-04-14 23:29 53248 ----a-w c:\windows\system32\iasads.dll
2009-03-03 04:16 . 2009-04-14 23:29 37888 ----a-w c:\windows\system32\iasdatastore.dll
2009-03-03 04:16 . 2009-04-14 23:28 78336 ----a-w c:\windows\system32\ieencode.dll
2009-03-03 04:15 . 2009-04-14 23:28 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-03 02:40 . 2009-04-14 23:29 654336 ----a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:08 . 2009-04-14 23:28 26624 ----a-w c:\windows\system32\ieUnatt.exe
2009-03-03 00:44 . 2009-04-14 23:28 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-02-28 00:26 . 2009-02-28 00:26 48590 ----a-r c:\users\Eric\AppData\Roaming\Microsoft\Installer\{8042EB50-42AA-4975-BBED-ED5AE9912D3B}\ApplicationIcon.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-05-17_15.00.44 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-19 14:44 . 2009-04-11 06:28 51712 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\wrpint.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 83968 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\wmiutils.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 30208 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\wbemprox.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 35328 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\mspatcha.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 22016 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\CbsMsg.dll
+ 2007-02-23 02:21 . 2009-05-21 02:46 79652 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-05-21 02:46 70674 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2007-02-23 02:21 . 2009-05-21 02:46 21342 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-115471124-3787053657-583000757-1000_UserData.bin
+ 2008-05-27 14:12 . 2009-05-22 12:33 84661 c:\windows\System32\Macromed\Flash\uninstall_plugin.exe
+ 2006-11-02 13:02 . 2009-05-25 19:05 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:02 . 2009-05-11 22:11 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:02 . 2009-05-11 22:11 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:02 . 2009-05-25 19:05 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 13:02 . 2009-05-11 22:11 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 13:02 . 2009-05-25 19:05 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-05-17 14:56 . 2009-05-17 14:56 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-05-25 21:47 . 2009-05-25 21:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-17 14:56 . 2009-05-17 14:56 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-05-25 21:47 . 2009-05-25 21:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-05-19 14:44 . 2009-04-11 06:28 182784 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\xmllite.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 218624 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\wdscore.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 744448 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\wbemcore.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 357888 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\wbemcomn.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 116736 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\smipi.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 139264 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\SmiInstaller.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 705536 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\smiengine.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 126464 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\rescinst.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 265728 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\repdrvfs.dll
+ 2009-05-19 14:44 . 2009-04-11 06:27 119296 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe
+ 2009-05-19 14:44 . 2009-04-11 06:27 130560 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\PkgMgr.exe
+ 2009-05-19 14:44 . 2009-04-11 06:28 146432 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\OEMHelpIns.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 305152 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\msdelta.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 102400 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\mofinstall.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 189440 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\mofd.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 222720 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\locdrv.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 100352 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\helpcins.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 614912 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\fastprox.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 265728 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\esscli.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 247808 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\drvstore.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 100352 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\DrUpdate.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 258048 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\dpx.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 243712 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\CntrtextInstaller.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 271360 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\cmitrust.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 119808 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\cmiadapter.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 535040 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\CbsCore.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 199168 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\apss.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 222208 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\apircl.dll
+ 2006-11-02 10:33 . 2009-05-23 15:36 629642 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-05-17 14:38 629642 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-05-23 15:36 108352 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-05-17 14:38 108352 c:\windows\System32\perfc009.dat
+ 2009-02-03 02:15 . 2009-02-03 02:15 240544 c:\windows\System32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2006-11-02 12:47 . 2009-05-25 21:47 406368 c:\windows\System32\FNTCACHE.DAT
+ 2009-05-19 14:44 . 2009-04-11 06:28 1835520 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\wcp.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 2032640 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\cmiv2.dll
+ 2009-05-19 14:44 . 2009-04-11 06:28 1744384 c:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\apds.dll
+ 2006-11-02 10:22 . 2009-05-21 02:41 6291456 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2006-11-02 10:22 . 2009-05-13 19:47 6291456 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-02-03 02:15 . 2009-02-03 02:15 3771296 c:\windows\System32\Macromed\Flash\NPSWF32.dll
+ 2008-02-14 08:02 . 2009-05-19 14:43 145795574 c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-10 1232896]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="c:\program files\nVidia\nTune\nTune\nTuneCmd.exe" [2006-10-31 81920]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"ProfilerU"="c:\program files\Saitek\SD6\Software\ProfilerU.exe" [2008-12-17 237568]
"SaiMfd"="c:\program files\Saitek\SD6\Software\SaiMfd.exe" [2008-12-17 131072]
"SaiVolume"="c:\program files\Saitek\CyborgKeyboard\SaiVolume.exe" [2008-01-18 126976]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13683232]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-18 92704]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"CtxfiReg"="CTXFIREG.exe" - c:\windows\System32\CTxfiReg.exe [2008-10-08 47104]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\System32\Ctxfihlp.exe [2008-10-08 23552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DevconDefaultDB"="c:\windows\system32\READREG" [X]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SetDefaultMIDI"="MIDIDEF.EXE" - c:\windows\System32\mididef.exe [2008-02-21 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-115471124-3787053657-583000757-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{1858AA7C-5B8D-415F-A35A-5F8009D819F2}"= UDP:c:\games\Battlefield 2142\BF2142.exe:Battlefield 2
"{1765C9C5-5D86-4947-995F-5BF2B15EE005}"= TCP:c:\games\Battlefield 2142\BF2142.exe:Battlefield 2
"TCP Query User{0F629ABA-8F7B-4DDD-94B6-B1105DE7DFD8}c:\\program files\\steam\\steamapps\\v0lten\\dark messiah might and magic multi-player\\mm.exe"= UDP:c:\program files\steam\steamapps\v0lten\dark messiah might and magic multi-player\mm.exe:mm
"UDP Query User{E652FDB4-A62C-44E1-8276-7C27FBEA234B}c:\\program files\\steam\\steamapps\\v0lten\\dark messiah might and magic multi-player\\mm.exe"= TCP:c:\program files\steam\steamapps\v0lten\dark messiah might and magic multi-player\mm.exe:mm
"TCP Query User{EBF8B561-BBB5-49E8-9116-C7524B35F0F1}c:\\games\\ghost recon advanced warfighter\\graw.exe"= UDP:c:\games\ghost recon advanced warfighter\graw.exe:GRAW
"UDP Query User{D0F71F5C-0260-4DB1-A457-B080EF680822}c:\\games\\ghost recon advanced warfighter\\graw.exe"= TCP:c:\games\ghost recon advanced warfighter\graw.exe:GRAW
"TCP Query User{521FF922-31A2-465C-8A94-DA539475AE3B}c:\\stubinstaller.exe"= UDP:C:\stubinstaller.exe:LimeWire swarmed installer
"UDP Query User{6790D790-C8F1-48EE-8CF4-75AC8AE9FD2F}c:\\stubinstaller.exe"= TCP:C:\stubinstaller.exe:LimeWire swarmed installer
"{6917B97B-172D-4301-80E4-73E1CF13828E}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{2073FBB0-03EF-4200-944E-089D5098B3E9}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{CB871553-B25B-46E6-B121-DEDC7F613485}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{566979F8-306A-41F3-B624-82B3968A8CEF}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{A65AF07A-813E-4CAD-AC0F-8F9305E454FF}c:\\program files\\steam\\steamapps\\v0lten\\dark messiah might and magic multi-player\\mm.exe"= UDP:c:\program files\steam\steamapps\v0lten\dark messiah might and magic multi-player\mm.exe:mm
"UDP Query User{784E6521-E43F-4E3A-B12D-AC2ACE279E24}c:\\program files\\steam\\steamapps\\v0lten\\dark messiah might and magic multi-player\\mm.exe"= TCP:c:\program files\steam\steamapps\v0lten\dark messiah might and magic multi-player\mm.exe:mm
"TCP Query User{A2B4B649-FEA4-4CB6-A738-A26E5309B5FD}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{1BDF5E19-0A42-4A69-B8EE-966F8BA3A768}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{4AEEA7E5-EF16-41A8-AFCB-52E76BAC6CAD}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{F7D2AAF7-1D7C-4EF8-87EF-2C5C0354B2E4}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{1B003AA0-FB85-41C3-95E2-3A61B1E3E99A}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{006B8887-8410-420F-811F-2AC7741CB360}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{D607F963-5774-444E-A581-2B2F0ADD2056}c:\\program files\\morpheus\\morpheus.exe"= UDP:c:\program files\morpheus\morpheus.exe:Morpheus
"UDP Query User{21D6C2F7-EB1F-473D-9F15-F97FA5AD2DF7}c:\\program files\\morpheus\\morpheus.exe"= TCP:c:\program files\morpheus\morpheus.exe:Morpheus
"TCP Query User{CF3E637D-C2FB-438D-AD38-D4BA242EAE35}c:\\program files\\xfire\\xfire.exe"= UDP:c:\program files\xfire\xfire.exe:Xfire
"UDP Query User{284C6441-4922-4278-897F-BFD2EC6B88C8}c:\\program files\\xfire\\xfire.exe"= TCP:c:\program files\xfire\xfire.exe:Xfire
"TCP Query User{16EBB90D-4704-4BCC-A9B9-5FE6F062893B}c:\\users\\eric\\desktop\\starcraft2cinematictrailer_englishus-avi-downloader.exe"= UDP:c:\users\eric\desktop\starcraft2cinematictrailer_englishus-avi-downloader.exe:starcraft2cinematictrailer_englishus-avi-downloader.exe
"UDP Query User{7A46FF63-6BD6-4BB3-B13E-1707BEB3D87D}c:\\users\\eric\\desktop\\starcraft2cinematictrailer_englishus-avi-downloader.exe"= TCP:c:\users\eric\desktop\starcraft2cinematictrailer_englishus-avi-downloader.exe:starcraft2cinematictrailer_englishus-avi-downloader.exe
"TCP Query User{926B7757-E16D-4F4E-85CA-D557392CB53F}c:\\users\\eric\\desktop\\1280_starcraft2gameplayvideo_englishus2-avi-downloader.exe"= UDP:c:\users\eric\desktop\1280_starcraft2gameplayvideo_englishus2-avi-downloader.exe:1280_starcraft2gameplayvideo_englishus2-avi-downloader.exe
"UDP Query User{33F6AD5A-F7B9-46BC-8299-0543F2AE6F16}c:\\users\\eric\\desktop\\1280_starcraft2gameplayvideo_englishus2-avi-downloader.exe"= TCP:c:\users\eric\desktop\1280_starcraft2gameplayvideo_englishus2-avi-downloader.exe:1280_starcraft2gameplayvideo_englishus2-avi-downloader.exe
"TCP Query User{4080B449-F604-446E-9394-61708C552C2F}c:\\games\\starcraft bw\\starcraft.exe"= UDP:c:\games\starcraft bw\starcraft.exe:Starcraft
"UDP Query User{0F73D439-B05A-472A-971B-5A91B19BE389}c:\\games\\starcraft bw\\starcraft.exe"= TCP:c:\games\starcraft bw\starcraft.exe:Starcraft
"TCP Query User{996C1867-7BB3-4413-8B76-C2660F8BFDE3}c:\\program files\\steam\\steamapps\\v0lten84\\counter-strike source\\hl2.exe"= UDP:c:\program files\steam\steamapps\v0lten84\counter-strike source\hl2.exe:hl2
"UDP Query User{89FB6E5A-B763-4810-94EB-9051A40E22E5}c:\\program files\\steam\\steamapps\\v0lten84\\counter-strike source\\hl2.exe"= TCP:c:\program files\steam\steamapps\v0lten84\counter-strike source\hl2.exe:hl2
"{472F0D71-975D-4C01-8104-EBBD828F6060}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{9503AB14-F7A2-430C-A5C3-4FB49B17FE10}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{A55F1B7C-86E5-4980-A2FB-FCAAF1F90F26}c:\\program files\\bearshare applications\\bearshare\\bearshare.exe"= UDP:c:\program files\bearshare applications\bearshare\bearshare.exe:BearShare
"UDP Query User{2CE1833C-411A-42C7-BB1D-8CAF0E20F42E}c:\\program files\\bearshare applications\\bearshare\\bearshare.exe"= TCP:c:\program files\bearshare applications\bearshare\bearshare.exe:BearShare
"{C00862FE-51C4-4295-A298-84226B1421FA}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{582AE9DF-4B94-42C7-978A-0B40A6139CA5}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{81C01CAE-BD8C-46CA-8460-E9209C64048D}c:\\program files\\teamspeak2_rc2\\server_windows.exe"= UDP:c:\program files\teamspeak2_rc2\server_windows.exe:Server
"UDP Query User{16F3D28F-45F1-4AE1-A124-4146FE91AF5B}c:\\program files\\teamspeak2_rc2\\server_windows.exe"= TCP:c:\program files\teamspeak2_rc2\server_windows.exe:Server
"TCP Query User{41252F9A-72A5-4E05-B4B1-F61EB20D5059}c:\\games\\scrabble\\scrabble.exe"= UDP:c:\games\scrabble\scrabble.exe:SCRABBLE ®
"UDP Query User{BD793529-D58D-4FF7-A2C4-B3FF46A06768}c:\\games\\scrabble\\scrabble.exe"= TCP:c:\games\scrabble\scrabble.exe:SCRABBLE ®
"TCP Query User{DE662BDD-E853-46CD-8DFF-761184C00220}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{1D26B1B5-BAF0-4EC0-96E6-E9F70BF961E0}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"TCP Query User{0133FC21-058A-4175-B553-1E4AF72BFAE3}c:\\games\\america's army\\system\\armyops.exe"= UDP:c:\games\america's army\system\armyops.exe:ArmyOps
"UDP Query User{20730EDF-8DC0-4679-9343-13A91A122C10}c:\\games\\america's army\\system\\armyops.exe"= TCP:c:\games\america's army\system\armyops.exe:ArmyOps
"{F4E05073-D222-4630-A062-0FD8B908D9B9}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{53FA009B-AF13-4FDB-904C-9211789A3A8C}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{0E0BF150-EBC0-4C59-96A6-73F9B290D3A0}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{C448581D-6A82-4EAB-91C1-D9B271F91BCE}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{A93144F3-7C95-4FE2-B7C4-7B0F59A70100}c:\\program files\\gamespy\\comrade\\comrade.exe"= UDP:c:\program files\gamespy\comrade\comrade.exe:Comrade
"UDP Query User{16D61F8D-9F9E-409D-81BE-D1366202FEB0}c:\\program files\\gamespy\\comrade\\comrade.exe"= TCP:c:\program files\gamespy\comrade\comrade.exe:Comrade
"TCP Query User{2F5D4742-E74E-46A6-8336-2F978FEEB9DE}c:\\users\\eric\\desktop\\wow-burningcrusade-enus-installer-downloader.exe"= UDP:c:\users\eric\desktop\wow-burningcrusade-enus-installer-downloader.exe:Blizzard Downloader
"UDP Query User{A409B7A6-5684-40B3-AEA1-1931CCC8AC8E}c:\\users\\eric\\desktop\\wow-burningcrusade-enus-installer-downloader.exe"= TCP:c:\users\eric\desktop\wow-burningcrusade-enus-installer-downloader.exe:Blizzard Downloader
"TCP Query User{3F9BF024-E45B-46FF-AF0C-B19340732754}c:\\games\\world of warcraft\\repair.exe"= UDP:c:\games\world of warcraft\repair.exe:Blizzard Repair Utility
"UDP Query User{82C53B79-BE7C-4595-A9A9-3A87857BB6FA}c:\\games\\world of warcraft\\repair.exe"= TCP:c:\games\world of warcraft\repair.exe:Blizzard Repair Utility
"{2AF388F7-2CDD-4B74-AD52-6F2A36643ABE}"= UDP:c:\games\World of Warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{7FFB4106-E5BF-4531-A476-DB7E84E6E8E9}"= TCP:c:\games\World of Warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{F57008B1-212E-4FD4-8C64-FD4DFAB1EBC8}"= UDP:3724:Blizzard Downloader: 3724
"TCP Query User{A01C6A9C-36C9-4692-93ED-9519F88465A9}c:\\program files\\tortun\\gui.exe"= UDP:c:\program files\tortun\gui.exe:gui
"UDP Query User{DD6FE7B2-674C-4E5A-8C54-E8C25438558D}c:\\program files\\tortun\\gui.exe"= TCP:c:\program files\tortun\gui.exe:gui
"TCP Query User{4C8FC439-8E44-44D4-A965-748A977A21F4}c:\\program files\\bitpim\\bitpimw.exe"= UDP:c:\program files\bitpim\bitpimw.exe:Open Source Mobile Phone Tool
"UDP Query User{F7ACD0CF-E8F5-4043-BCF8-E954ACA195D3}c:\\program files\\bitpim\\bitpimw.exe"= TCP:c:\program files\bitpim\bitpimw.exe:Open Source Mobile Phone Tool
"{F1428DA6-7E84-43F2-A5F5-DD5DB76721AB}"= UDP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{6B43D872-B2FE-42EC-8296-BEBA661D03CE}"= TCP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{BA6FC82D-3D5E-4379-B3D0-548E54E9AD46}"= UDP:c:\games\Combat Arms\NMService.exe:Nexon Messenger Core
"{3DFF968D-69B6-465D-B930-717D572022D3}"= TCP:c:\games\Combat Arms\NMService.exe:Nexon Messenger Core
"TCP Query User{36D0EAB7-7B22-40F7-AD7E-7F28811796D3}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{58BB7684-4B00-454B-A724-524378DF9BA7}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"TCP Query User{DAB93A66-16F4-4D81-9E0F-2F114EE2B7DE}c:\\users\\eric\\desktop\\curseclient.exe"= UDP:c:\users\eric\desktop\curseclient.exe:CurseClient
"UDP Query User{6E1165D3-ABE8-42E9-A0EA-CF452465F058}c:\\users\\eric\\desktop\\curseclient.exe"= TCP:c:\users\eric\desktop\curseclient.exe:CurseClient
"{58B80C9E-EA30-403C-86E8-8F7BBED092DC}"= UDP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"{9ACEAFE6-FEE7-40BA-B8EF-4B70980C0E49}"= TCP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"{067CE6B4-3D29-4510-8744-01B9F8BACDA7}"= c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{64B59B77-198D-46AD-97B5-22C58110003F}"= c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{92CF0161-B220-4B62-AA51-6C83720DFBF0}"= c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{4B233258-FCE5-4531-86EF-F30EC9321981}"= c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{0D0DD278-90E5-4CAB-8E1B-060026779A0F}"= c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{D141BF29-401F-4FF7-891A-25B703E871C5}"= c:\program files\Common Files\HP\Digital Imaging\bin\hpqphotocrm.exe:hpqphotocrm.exe
"{F21F286D-2253-47E7-88B6-13589729C30B}"= c:\program files\HP\Digital Imaging\bin\hpqsudi.exe:hpqsudi.exe
"{75E3F28E-99AF-4D9D-94D3-A226C90C214F}"= c:\program files\HP\Digital Imaging\bin\hpqpsapp.exe:hpqpsapp.exe
"{A5636151-A6A1-412D-8183-F3C63F22EBCB}"= c:\program files\HP\Digital Imaging\bin\hpqcopy2.exe:hpqcopy2.exe
"{34CFB473-4E69-4C55-ADE8-EBE842B585DA}"= c:\program files\HP\Digital Imaging\bin\hpqpse.exe:hpqpse.exe
"{2F266AC6-A84D-4F7D-891A-D1BA4F702985}"= c:\program files\HP\Digital Imaging\bin\hpqgplgtupl.exe:hpqgplgtupl.exe
"{97FEC3ED-4B2D-4349-9D52-626F9B689C13}"= c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe:hpqgpc01.exe
"{4E328C6B-47F5-462B-84F5-D35A9A09A840}"= UDP:c:\games\Curse\CurseClient.exe:Curse Client
"{EC457520-B809-4544-AAFA-E7A6AF19F3EB}"= TCP:c:\games\Curse\CurseClient.exe:Curse Client
"{025E38E7-09E1-4817-B18E-5234C3E372AB}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{71FC4E3B-D04E-4FE4-A022-8B2EAB63489A}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"TCP Query User{BBBA934D-6BA1-475E-9401-A79821AB076F}c:\\games\\starcraft\\starcraft.exe"= UDP:c:\games\starcraft\starcraft.exe:Starcraft
"UDP Query User{A679D3EE-808D-4C32-BABC-B3418CFB60B8}c:\\games\\starcraft\\starcraft.exe"= TCP:c:\games\starcraft\starcraft.exe:Starcraft
"TCP Query User{FBCD87D3-85EE-4B64-BC96-52E7E192CE31}c:\\users\\eric\\downloads\\fogdownloaderen-runesofmagic.exe"= UDP:c:\users\eric\downloads\fogdownloaderen-runesofmagic.exe:FOG Downloader
"UDP Query User{774B917D-0F7F-4953-AFC5-8E1A5AA6E1B1}c:\\users\\eric\\downloads\\fogdownloaderen-runesofmagic.exe"= TCP:c:\users\eric\downloads\fogdownloaderen-runesofmagic.exe:FOG Downloader
"TCP Query User{B04EB91D-C1EF-4775-BCAE-34382D3B33A6}c:\\users\\eric\\downloads\\fogdownloaderen-runesofmagic(2).exe"= UDP:c:\users\eric\downloads\fogdownloaderen-runesofmagic(2).exe:FOG Downloader
"UDP Query User{727B5FAB-F323-429C-BC85-A9EC0F336617}c:\\users\\eric\\downloads\\fogdownloaderen-runesofmagic(2).exe"= TCP:c:\users\eric\downloads\fogdownloaderen-runesofmagic(2).exe:FOG Downloader
"{22F2A5E0-D225-4CD1-85FF-C91E3B19DC54}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{3B9E54E4-68F1-4361-A0A5-334E794E9710}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{61321207-3463-4951-BC6A-FD427CAD0E30}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{445898C9-5091-4370-9BEE-DD7AEDE6A8BC}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{28C55833-11E8-4169-9ECE-C6A3C8EE8FDC}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{D1705C51-B48F-4198-BC48-63F89FB0AB16}"= UDP:c:\program files\FrostWire\FrostWire.exe:FrostWire
"{D335ACC3-F07C-4F14-A3B5-C190C532A2AE}"= TCP:c:\program files\FrostWire\FrostWire.exe:FrostWire
"{6CAE478E-49A6-40BF-B865-702C3863B5C7}"= UDP:c:\program files\BitTorrent\BitTorrent.exe:BitTorrent (TCP-In)
"{0C1697D2-FAA6-4604-B9B3-AFEAB91C24DB}"= TCP:c:\program files\BitTorrent\BitTorrent.exe:BitTorrent (UDP-In)
"{06AD06EB-B6EB-4D22-A754-7B5E79757AB7}"= UDP:c:\program files\Pando Networks\Media Booster\PMB.exe:Pando Media Booster
"{D344BB5E-78A2-4EC5-89B7-CB07DA42959E}"= TCP:c:\program files\Pando Networks\Media Booster\PMB.exe:Pando Media Booster
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\River Past\\Audio Converter\\AudioConverter.exe"= c:\program files\River Past\Audio Converter\AudioConverter.exe:*:Enabled:River Past Audio Converter
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
"c:\\Games\\Combat Arms\\CombatArms.exe"= c:\games\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\\Games\\Combat Arms\\Engine.exe"= c:\games\Combat Arms\Engine.exe:*Enabled:Engine.exe
R2 gupdate1c9afb9d834c56e;Google Update Service (gupdate1c9afb9d834c56e);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-28 133104]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-02-04 79360]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2008-10-08 171032]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2008-10-08 1324056]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2008-10-08 72728]
R3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\DRIVERS\gan_adapter.sys [2006-08-29 10664]
R3 SaiH0728;SaiH0728;c:\windows\system32\DRIVERS\SaiH0728.sys [2007-10-30 136448]
S2 SBKUPNT;SBKUPNT;c:\windows\system32\Drivers\SBKUPNT.SYS [2001-07-13 14976]
S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2008-10-08 171032]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2008-10-08 1324056]
S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2008-10-08 72728]
S3 SaiK0728;SaiK0728;c:\windows\system32\DRIVERS\SaiK0728.sys [2009-03-06 108544]
S3 SaiK0CEA;SaiK0CEA;c:\windows\system32\DRIVERS\SaiK0CEA.sys [2008-01-14 104960]
S3 SaiU0CEA;SaiU0CEA;c:\windows\system32\DRIVERS\SaiU0CEA.sys [2008-01-14 28544]
--- Other Services/Drivers In Memory ---
*Deregistered* - AFD
*Deregistered* - Beep
*Deregistered* - bowser
*Deregistered* - cdfs
*Deregistered* - CLFS
*Deregistered* - crcdisk
*Deregistered* - CT20XUT.SYS
*Deregistered* - ctac32k
*Deregistered* - CTEXFIFX.SYS
*Deregistered* - CTHWIUT.SYS
*Deregistered* - ctprxy2k
*Deregistered* - ctsfm2k
*Deregistered* - DfsC
*Deregistered* - DXGKrnl
*Deregistered* - emupia
*Deregistered* - FileInfo
*Deregistered* - FltMgr
*Deregistered* - giveio
*Deregistered* - ha20x2k
*Deregistered* - HTTP
*Deregistered* - iScsiPrt
*Deregistered* - kbdclass
*Deregistered* - KSecDD
*Deregistered* - lltdio
*Deregistered* - luafv
*Deregistered* - mouclass
*Deregistered* - MountMgr
*Deregistered* - mpsdrv
*Deregistered* - MRxDAV
*Deregistered* - mrxsmb
*Deregistered* - mrxsmb10
*Deregistered* - mrxsmb20
*Deregistered* - Msfs
*Deregistered* - msisadrv
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - netbt
*Deregistered* - Npfs
*Deregistered* - nsiproxy
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - ossrv
*Deregistered* - Parvdm
*Deregistered* - PEAUTH
*Deregistered* - PptpMiniport
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - rdbss
*Deregistered* - RDPCDD
*Deregistered* - RDPENCDD
*Deregistered* - RMCAST
*Deregistered* - rspndr
*Deregistered* - SaiNtBus
*Deregistered* - SBKUPNT
*Deregistered* - SCDEmu
*Deregistered* - secdrv
*Deregistered* - Smb
*Deregistered* - speedfan
*Deregistered* - spldr
*Deregistered* - srv
*Deregistered* - srv2
*Deregistered* - srvnet
*Deregistered* - swenum
*Deregistered* - Tcpip
*Deregistered* - tcpipreg
*Deregistered* - tdx
*Deregistered* - tunmp
*Deregistered* - tunnel
*Deregistered* - umbus
*Deregistered* - VgaSave
*Deregistered* - volmgr
*Deregistered* - volmgrx
*Deregistered* - volsnap
*Deregistered* - Wanarpv6
*Deregistered* - Wdf01000
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-05-25 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-28 15:28]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = socks=
uInternet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
FF - ProfilePath - c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\7vjvur8h.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - plugin: c:\program files\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\programdata\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\7vjvur8h.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDCE08D86A-A41A-410A-943C-13BABB7DC474", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA9EDC9ED-603A-4F3F-BBEA-59C8853A3236", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID90D10942-D952-4863-9DD6-A2BDBBAD456E", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0ECEE744-7B69-4912-AB91-AE76D61ECB04", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF25635B2-1AB9-47B5-88D1-8877B22C86DE", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID27B7F812-4159-45B9-A389-B7A118A58DE4", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF849DF29-393B-4F8B-99D1-117A70D66FC7", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDBF1E9C3D-637C-4171-BD12-28A7360B879A", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDDE1C0601-7947-4D7F-A6E5-E68BF6BA1E37", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4EA0DCCE-4D98-4876-9C6A-E5C563D0820A", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID446462BA-2AAD-4C88-BC63-5210E2F31465", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0862E368-A40E-4E55-83EB-FBC5571BABA4", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDD2A96E3C-FFB3-4D38-9AC3-B127527BEA35", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4B05B39A-9DDC-4650-A7F8-D5B134E5FFE5", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDC8E2574A-7BCE-4B93-A22E-61831DFD6DB8", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID659796C0-8B5D-48D7-A4EB-7E6874E26274", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID78071AB5-E729-414E-8D02-9C1D034F82E7", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDCC3F71E1-17F3-4C5B-997D-44CA56943197", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE67D5C78-B2D4-4BA0-8D69-1C7AF4BB08B5", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFC5F3D7A-D321-412C-8A5D-9AD0C8041941", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6EC5CD16-81BC-4515-9EDD-9265C906F56E", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID67CFB2C5-E491-4395-977B-CD45E4124655", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID73600569-52E6-4760-8BAB-B68202937D98", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB02EBD42-6885-401A-9389-E089F7DDC872", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDBAE5CB8C-4075-4743-B2E4-78DA8D8CDC64", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID28B07B04-DA99-4FD3-BF27-4972F2B8142B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0D53448F-D12B-4102-8CE2-697DAE8D6643", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE3266A47-A141-47B8-AAA8-5F16FB4F8CCD", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB33AB7AF-76D7-4B1C-B709-5D6BF9E7B1C7", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID153B7451-0BB5-4B37-95C0-44D89E2F1F2B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID3BBE8E21-0D3D-4BAA-AC6F-C7BCEF750849", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID9B5B4F2D-A7D9-4329-B0FE-92B301A8CAAD", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA5C42921-8CD0-4924-97C3-01B5B0610BC6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID06969252-F90F-4CF2-9074-33772EB64859", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFBF37655-1236-4C0D-96C5-F94E1724841B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDC1A3F035-B68F-4B2B-9FD5-E36DAAAF26DD", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID368F3685-543E-4812-9FDE-96E097E453FC", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID43969873-56AA-4113-84CB-4AB2AEB9AA31", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA205DD80-63D4-4E41-B785-26EC3D90B97B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID068D43E7-7551-4A2F-AE96-4A38A9AD1953", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF443E9CB-9EEC-456E-8AE7-F3102D5CD47D", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE36A7B16-645D-4261-BFF8-3A7E69C5F7A5", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID379805E3-E0E2-40DC-B51B-6DC1AE5802AA", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF6240D69-A06D-44A1-8003-8496CCEF2C53", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID26C3113D-5A71-4F1B-A2CB-BE59E1279DDA", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID92B97F2B-7565-4CE9-9AC7-0598DFD731F8", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID2AA5E7CF-9696-42F0-B76A-8655296EADF2", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0AAACE0B-ACEF-4781-83F4-BFB52EEC995A", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0D56FF58-A39D-4E8C-A40B-2E3711251772", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID946121C2-11F1-49DD-A7E3-CF793DE827A4", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB853303D-1BAB-43F3-9D7D-101D0DA8E7A5", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID9E578247-FE29-4F8C-8202-A24A5688CF2A", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6D065A8F-FFC0-4A0F-B863-1D724B8C786B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4451D291-6940-42CE-9D3C-CA1D4C96549C", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID064B722D-079D-4EBB-B3CF-9FCBF64FFF5D", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID38F8AB0F-5DFB-43D9-889E-8717CC4AB59B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4EC68CD1-0EF1-4CB9-9EF1-3D64AB266149", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID44F96B27-CFAD-41E1-83A1-6B28040C3BDE", "AllAccess");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-25 17:49
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTxfiHlp = CTXFIHLP.EXE?
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-115471124-3787053657-583000757-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6598C917-055F-5A0E-E75A-51C32DA5ABE3}*]
"iaieolmbeicgnjdckb"=hex:6a,61,6b,65,6e,6c,63,62,6b,6b,62,62,65,66,64,65,68,63,
66,6b,00,00
"hagfiglkcjgjgaej"=hex:6a,61,6b,65,6e,6c,63,62,6b,6b,62,62,65,66,64,65,68,63,
66,6b,00,00
[HKEY_USERS\S-1-5-21-115471124-3787053657-583000757-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C9711532-B301-CB1A-3342-878D816F4D0C}*]
"oakieajbidgjfaiminakfgompipclo"=hex:6a,61,67,65,6d,69,69,62,6f,62,65,64,6f,61,
68,6f,6e,70,69,69,00,52
"naekkbngpcmockmafcleckdlgmfj"=hex:69,61,6b,64,6a,67,63,61,62,67,62,6a,6f,61,
62,63,6a,70,00,75
"oagkeoohfnghmpoapeaialhhlnbphm"=hex:64,61,67,65,68,66,70,6b,00,ff
"eackecglhn"=hex:66,61,6a,6f,6b,62,61,65,61,65,69,66,00,00
"cafkem"=hex:6b,62,6c,64,6f,69,66,61,65,62,64,68,6a,66,6c,6b,6c,70,67,6e,69,6c,
63,61,63,6d,6b,62,68,63,65,63,70,65,67,68,6e,65,6f,69,6e,65,65,63,61,63,70,\
[HKEY_USERS\S-1-5-21-115471124-3787053657-583000757-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:7d,c6,8e,3c,18,e0,d6,1f,7f,2e,9f,6e,e3,16,ae,86,44,8b,d9,4b,57,d2,79,
3c,20,6d,7c,49,5a,f6,97,a8,a7,d4,61,c5,70,bd,b1,ea,fe,49,14,32,f6,01,0a,14,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
[HKEY_USERS\S-1-5-21-115471124-3787053657-583000757-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:89,34,0c,3f,4d,cf,0b,2e,f4,22,6d,d7,ca,7f,7f,9f,80,50,72,3c,65,
db,b3,b3,40,2b,19,c4,fd,d1,28,48,94,f6,55,af,1d,32,89,fa,bf,0b,b2,4d,94,7a,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\CTSVCCDA.EXE
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\windows\System32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2009-05-25 17:51 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-25 21:51
ComboFix2.txt 2009-05-17 15:13
ComboFix3.txt 2009-05-17 15:02
Pre-Run: 20,446,109,696 bytes free
Post-Run: 20,160,966,656 bytes free
565 --- E O F --- 2009-05-22 02:40
DDSDDS (Ver_09-05-14.01) - NTFSx86
Run by Eric at 18:00:30.37 on Mon 05/25/2009
Internet Explorer: 7.0.6000.16830 BrowserJavaVersion: 1.6.0
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = socks=
uInternet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [NVIDIA nTune] "c:\program files\nvidia\ntune\ntune\nTuneCmd.exe" clear
mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [CtxfiReg] CTXFIREG.exe /FAIL0
mRun: [ProfilerU] c:\program files\saitek\sd6\software\ProfilerU.exe
mRun: [SaiMfd] c:\program files\saitek\sd6\software\SaiMfd.exe
mRun: [SaiVolume] c:\program files\saitek\cyborgkeyboard\SaiVolume.exe
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
dRun: [DevconDefaultDB] c:\windows\system32\READREG /SILENT /FAIL=1
dRunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy'
mPolicies-system: EnableLUA = 0 (0x0)
IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm
IE: {F4430FE8-2638-42e5-B849-800749B94EED} - c:\games\partypoker\partypokernet\RunPF.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\eric\appdata\roaming\mozilla\firefox\profiles\7vjvur8h.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - plugin: c:\program files\download manager\npfpdlm.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\programdata\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\users\eric\appdata\roaming\mozilla\firefox\profiles\7vjvur8h.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDCE08D86A-A41A-410A-943C-13BABB7DC474", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA9EDC9ED-603A-4F3F-BBEA-59C8853A3236", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID90D10942-D952-4863-9DD6-A2BDBBAD456E", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0ECEE744-7B69-4912-AB91-AE76D61ECB04", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF25635B2-1AB9-47B5-88D1-8877B22C86DE", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID27B7F812-4159-45B9-A389-B7A118A58DE4", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF849DF29-393B-4F8B-99D1-117A70D66FC7", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDBF1E9C3D-637C-4171-BD12-28A7360B879A", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDDE1C0601-7947-4D7F-A6E5-E68BF6BA1E37", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4EA0DCCE-4D98-4876-9C6A-E5C563D0820A", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID446462BA-2AAD-4C88-BC63-5210E2F31465", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0862E368-A40E-4E55-83EB-FBC5571BABA4", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDD2A96E3C-FFB3-4D38-9AC3-B127527BEA35", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4B05B39A-9DDC-4650-A7F8-D5B134E5FFE5", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDC8E2574A-7BCE-4B93-A22E-61831DFD6DB8", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID659796C0-8B5D-48D7-A4EB-7E6874E26274", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID78071AB5-E729-414E-8D02-9C1D034F82E7", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDCC3F71E1-17F3-4C5B-997D-44CA56943197", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE67D5C78-B2D4-4BA0-8D69-1C7AF4BB08B5", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFC5F3D7A-D321-412C-8A5D-9AD0C8041941", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6EC5CD16-81BC-4515-9EDD-9265C906F56E", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID67CFB2C5-E491-4395-977B-CD45E4124655", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID73600569-52E6-4760-8BAB-B68202937D98", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB02EBD42-6885-401A-9389-E089F7DDC872", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDBAE5CB8C-4075-4743-B2E4-78DA8D8CDC64", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID28B07B04-DA99-4FD3-BF27-4972F2B8142B", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0D53448F-D12B-4102-8CE2-697DAE8D6643", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE3266A47-A141-47B8-AAA8-5F16FB4F8CCD", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB33AB7AF-76D7-4B1C-B709-5D6BF9E7B1C7", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID153B7451-0BB5-4B37-95C0-44D89E2F1F2B", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID3BBE8E21-0D3D-4BAA-AC6F-C7BCEF750849", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID9B5B4F2D-A7D9-4329-B0FE-92B301A8CAAD", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA5C42921-8CD0-4924-97C3-01B5B0610BC6", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID06969252-F90F-4CF2-9074-33772EB64859", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFBF37655-1236-4C0D-96C5-F94E1724841B", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDC1A3F035-B68F-4B2B-9FD5-E36DAAAF26DD", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID368F3685-543E-4812-9FDE-96E097E453FC", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID43969873-56AA-4113-84CB-4AB2AEB9AA31", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA205DD80-63D4-4E41-B785-26EC3D90B97B", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID068D43E7-7551-4A2F-AE96-4A38A9AD1953", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF443E9CB-9EEC-456E-8AE7-F3102D5CD47D", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE36A7B16-645D-4261-BFF8-3A7E69C5F7A5", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID379805E3-E0E2-40DC-B51B-6DC1AE5802AA", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF6240D69-A06D-44A1-8003-8496CCEF2C53", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID26C3113D-5A71-4F1B-A2CB-BE59E1279DDA", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID92B97F2B-7565-4CE9-9AC7-0598DFD731F8", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID2AA5E7CF-9696-42F0-B76A-8655296EADF2", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0AAACE0B-ACEF-4781-83F4-BFB52EEC995A", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0D56FF58-A39D-4E8C-A40B-2E3711251772", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID946121C2-11F1-49DD-A7E3-CF793DE827A4", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB853303D-1BAB-43F3-9D7D-101D0DA8E7A5", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID9E578247-FE29-4F8C-8202-A24A5688CF2A", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6D065A8F-FFC0-4A0F-B863-1D724B8C786B", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4451D291-6940-42CE-9D3C-CA1D4C96549C", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID064B722D-079D-4EBB-B3CF-9FCBF64FFF5D", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID38F8AB0F-5DFB-43D9-889E-8717CC4AB59B", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4EC68CD1-0EF1-4CB9-9EF1-3D64AB266149", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID44F96B27-CFAD-41E1-83A1-6B28040C3BDE", "AllAccess");
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2009-05-25 17:51 <DIR> --dsh--- C:\$RECYCLE.BIN
2009-05-25 17:43 154,624 a------- c:\windows\PEV.exe
2009-05-23 22:59 <DIR> --d----- c:\programdata\PMB Files
2009-05-23 22:59 <DIR> --d----- c:\progra~2\PMB Files
2009-05-23 22:59 <DIR> --d----- c:\program files\Pando Networks
2009-05-17 11:14 <DIR> --d----- C:\Rooter$
2009-05-17 10:54 161,792 a------- c:\windows\SWREG.exe
2009-05-17 10:54 98,816 a------- c:\windows\sed.exe
2009-05-12 05:51 <DIR> --d----- c:\temp\P90X+ Documents
2009-05-12 05:51 <DIR> --d----- c:\temp\P90X Documents
2009-05-12 05:51 <DIR> --d----- C:\temp
2009-05-10 15:43 <DIR> --d----- c:\program files\common files\Windows Live
2009-05-05 22:12 <DIR> --d----- c:\program files\Full Tilt Poker.Net
==================== Find3M ====================
2009-05-10 15:46 143,360 a------- c:\windows\inf\infstrng.dat
2009-05-10 15:46 51,200 a------- c:\windows\inf\infpub.dat
2009-05-10 15:46 86,016 a------- c:\windows\inf\infstor.dat
2009-04-06 15:32 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 15:32 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-03-16 23:16 40,960 a------- c:\windows\apppatch\apihex86.dll
2009-03-16 23:16 14,848 a------- c:\windows\system32\apilogen.dll
2009-03-16 23:16 25,600 a------- c:\windows\system32\amxread.dll
2009-03-03 00:24 3,503,584 a------- c:\windows\system32\ntkrnlpa.exe
2009-03-03 00:24 3,469,280 a------- c:\windows\system32\ntoskrnl.exe
2009-03-03 00:20 826,368 a------- c:\windows\system32\wininet.dll
2009-03-03 00:19 158,720 a------- c:\windows\system32\sdohlp.dll
2009-03-03 00:19 549,888 a------- c:\windows\system32\rpcss.dll
2009-03-03 00:19 24,576 a------- c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 00:16 56,320 a------- c:\windows\system32\iesetup.dll
2009-03-03 00:16 97,280 a------- c:\windows\system32\iasrecst.dll
2009-03-03 00:16 78,336 a------- c:\windows\system32\ieencode.dll
2009-03-03 00:16 53,248 a------- c:\windows\system32\iasads.dll
2009-03-03 00:16 52,736 a------- c:\windows\apppatch\iebrshim.dll
2009-03-03 00:16 37,888 a------- c:\windows\system32\iasdatastore.dll
2009-03-03 00:15 72,704 a------- c:\windows\system32\admparse.dll
2009-03-02 22:40 654,336 a------- c:\windows\system32\printfilterpipelinesvc.exe
2009-03-02 22:08 26,624 a------- c:\windows\system32\ieUnatt.exe
2009-03-02 20:44 48,128 a------- c:\windows\system32\mshtmler.dll
2008-12-11 04:15 174 a--sh--- c:\program files\desktop.ini
2008-12-06 08:56 22,328 a------- c:\users\eric\appdata\roaming\PnkBstrK.sys
2008-06-11 03:07 665,600 a------- c:\windows\inf\drvindex.dat
2006-11-02 08:42 287,440 a------- c:\windows\inf\perflib409\perfi.dat
2006-11-02 08:42 287,440 a------- c:\windows\inf\perflib409\perfh.dat
2006-11-02 08:42 30,674 a------- c:\windows\inf\perflib409\perfd.dat
2006-11-02 08:42 30,674 a------- c:\windows\inf\perflib409\perfc.dat
2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib 00\perfi.dat
2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib 00\perfh.dat
2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib 00\perfd.dat
2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib 00\perfc.dat
2007-03-10 20:10 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2007-03-10 20:10 32,768 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2007-03-10 20:10 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat
============= FINISH: 18:00:49.31 ===============