CHAUDHRY07
Posts: 44 +0
ComboFix 11-11-01.04 - Administrator 11/02/2011 8:09.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.246 [GMT 5:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\help\tours\htmltour\unlock_playing.htm
.
.
((((((((((((((((((((((((( Files Created from 2011-10-02 to 2011-11-02 )))))))))))))))))))))))))))))))
.
.
2011-11-01 11:02 . 2011-10-06 15:48 6668624 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-10-31 11:43 . 2011-10-31 11:43 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2011-10-31 11:42 . 2011-08-31 12:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-31 11:42 . 2011-10-31 11:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malwar
2011-10-30 17:11 . 2011-11-01 12:51 -------- d-----w- c:\program files\Microsoft Security Client
2011-10-29 12:42 . 2011-10-06 15:48 6668624 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-29 06:14 . 2011-10-30 17:18 -------- d-----w- c:\program files\Microsoft Security Essentials
2011-10-29 06:12 . 2011-10-29 06:12 -------- d--h--w- c:\windows\system32\GroupPolicy
2011-10-28 18:14 . 2011-10-28 18:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-10-28 04:52 . 2011-10-28 04:52 134 --sh--w- c:\documents and settings\Administrator\Application Data\per.bat
2011-10-28 04:29 . 2011-10-29 20:12 -------- d-sh--w- c:\documents and settings\Administrator\Local Settings\Application Data\d7afb588
2011-10-28 03:53 . 2011-06-03 20:56 330600 ----a-w- c:\windows\system32\HMIPCore.dll
2011-10-28 03:53 . 2011-10-28 16:24 -------- d-----w- c:\program files\Hide My IP
2011-10-22 05:08 . 2011-10-22 05:08 -------- d-----w- c:\documents and settings\All Users\Application Data\MaskMyIP
2011-10-22 04:59 . 2011-10-22 04:59 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\APN
2011-10-17 13:59 . 2011-10-29 20:38 -------- d-----w- C:\New Folder
2011-10-16 18:48 . 2011-10-16 18:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\MSNInstaller
2011-10-15 18:08 . 2011-10-15 18:08 -------- d-----w- c:\program files\7-Zip
2011-10-08 09:56 . 2011-10-08 09:56 -------- d-----w- c:\program files\Common Files\Symantec Shared
2011-10-08 09:56 . 2011-10-12 19:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2011-10-07 18:28 . 2011-10-07 18:28 -------- d-----w- c:\windows\system32\Adobe
2011-10-04 14:17 . 2008-04-13 18:45 10624 -c--a-w- c:\windows\system32\dllcache\gameenum.sys
2011-10-04 14:17 . 2008-04-13 18:45 10624 ----a-w- c:\windows\system32\drivers\gameenum.sys
2011-10-04 14:16 . 2001-08-17 08:28 907456 -c--a-w- c:\windows\system32\dllcache\hcf_msft.sys
2011-10-04 14:16 . 2001-08-17 08:28 907456 ----a-w- c:\windows\system32\drivers\HCF_MSFT.sys
2011-10-04 14:16 . 2001-08-17 07:19 30720 -c--a-w- c:\windows\system32\dllcache\rthwcls.sys
2011-10-04 14:16 . 2001-08-17 07:19 30720 ----a-w- c:\windows\system32\drivers\rthwcls.sys
2011-10-04 14:16 . 2001-08-17 07:19 3840 -c--a-w- c:\windows\system32\dllcache\rpfun.sys
2011-10-04 14:16 . 2001-08-17 07:19 3840 ----a-w- c:\windows\system32\drivers\rpfun.sys
2011-10-04 14:16 . 2001-08-17 07:19 42112 -c--a-w- c:\windows\system32\dllcache\crtaud.sys
2011-10-04 14:16 . 2001-08-17 07:19 42112 ----a-w- c:\windows\system32\drivers\crtaud.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-07 05:09 . 2011-06-03 09:13 414368 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-26 06:41 . 2008-07-29 14:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 06:41 . 2004-08-04 10:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 06:41 . 2004-08-04 10:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-09 09:12 . 2004-08-04 10:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20 . 2004-08-04 10:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-22 23:48 . 2006-03-04 03:33 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2004-08-04 10:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2004-08-04 10:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2004-08-04 10:00 385024 ----a-w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2004-08-04 10:00 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-10-06 04:40 . 2011-09-28 18:12 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2011-05-30 16:50 21864 ----a-w- c:\program files\Internet Download Manager\IDMShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2011-10-01 3425688]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-04-01 155648]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malwar\mbamgui.exe" [2011-08-31 449608]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2009-04-08 440736]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 07:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-06-06 07:55 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-01-20 09:20 1305408 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-12-13 12:18 136176 ----atw- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2006-04-01 09:31 126976 -c--a-r- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2011-06-15 10:16 997920 ----a-w- c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2006-04-01 09:33 77824 -c--a-r- c:\windows\SOUNDMAN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 09:49 249064 -c--a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)
"wuauserv"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"Spooler"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"e:\\documents\\New Folder\\bin\\java.exe"=
"c:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"d:\\most wanted\\rip Need.4.Spd.Most.Wanted kissme1\\speed.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\cs-1.6\\hl.exe"=
"c:\\WINDOWS\\system32\\msfeedssync.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\DW\\DW20.EXE"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
.
R0 Shadow;Shadow; [x]
R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [8/1/2011 7:28 PM 101616]
R3 crtaud;Conexant Riptide WDM Audio Driver;c:\windows\system32\drivers\crtaud.sys [10/4/2011 7:16 PM 42112]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [10/31/2011 4:42 PM 22216]
R3 rpfun;Conexant Riptide Dummy Driver;c:\windows\system32\drivers\rpfun.sys [10/4/2011 7:16 PM 3840]
R3 rthwcls;Conexant Riptide Bus / Firmware Downloader;c:\windows\system32\drivers\rthwcls.sys [10/4/2011 7:16 PM 30720]
S1 bvgffrex;bvgffrex;\??\c:\windows\system32\drivers\bvgffrex.sys --> c:\windows\system32\drivers\bvgffrex.sys [?]
S1 cwkxolyf;cwkxolyf;\??\c:\windows\system32\drivers\cwkxolyf.sys --> c:\windows\system32\drivers\cwkxolyf.sys [?]
S1 eifckibx;eifckibx;\??\c:\windows\system32\drivers\eifckibx.sys --> c:\windows\system32\drivers\eifckibx.sys [?]
S1 fnsvyqmu;fnsvyqmu;\??\c:\windows\system32\drivers\fnsvyqmu.sys --> c:\windows\system32\drivers\fnsvyqmu.sys [?]
S1 goimqobt;goimqobt;\??\c:\windows\system32\drivers\goimqobt.sys --> c:\windows\system32\drivers\goimqobt.sys [?]
S1 hnybtrdy;hnybtrdy;\??\c:\windows\system32\drivers\hnybtrdy.sys --> c:\windows\system32\drivers\hnybtrdy.sys [?]
S1 hvltatax;hvltatax;\??\c:\windows\system32\drivers\hvltatax.sys --> c:\windows\system32\drivers\hvltatax.sys [?]
S1 jmrujfpm;jmrujfpm;\??\c:\windows\system32\drivers\jmrujfpm.sys --> c:\windows\system32\drivers\jmrujfpm.sys [?]
S1 kqyacfcv;kqyacfcv;\??\c:\windows\system32\drivers\kqyacfcv.sys --> c:\windows\system32\drivers\kqyacfcv.sys [?]
S1 MpKsl014b491c;MpKsl014b491c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9BED1359-6570-4AE1-9CCC-0BB1D58B483F}\MpKsl014b491c.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9BED1359-6570-4AE1-9CCC-0BB1D58B483F}\MpKsl014b491c.sys [?]
S1 MpKsl0395a3c6;MpKsl0395a3c6;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{498CA44B-AED4-4E97-A50D-AC0B93D0A86E}\MpKsl0395a3c6.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{498CA44B-AED4-4E97-A50D-AC0B93D0A86E}\MpKsl0395a3c6.sys [?]
S1 MpKsl0845343d;MpKsl0845343d;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6920ADBB-9A6E-41AF-AE88-9DB4AF6D3FC8}\MpKsl0845343d.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6920ADBB-9A6E-41AF-AE88-9DB4AF6D3FC8}\MpKsl0845343d.sys [?]
S1 MpKsl0fd6a622;MpKsl0fd6a622;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{10AAA116-81D5-48E1-A7AB-DA769B1E27EC}\MpKsl0fd6a622.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{10AAA116-81D5-48E1-A7AB-DA769B1E27EC}\MpKsl0fd6a622.sys [?]
S1 MpKsl131968d2;MpKsl131968d2;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B7070CA8-CBEE-465C-B7BC-8C1E8BCC9174}\MpKsl131968d2.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B7070CA8-CBEE-465C-B7BC-8C1E8BCC9174}\MpKsl131968d2.sys [?]
S1 MpKsl15018fc3;MpKsl15018fc3;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BFC9705D-D9D3-4CCD-A6CE-333745FF92AB}\MpKsl15018fc3.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BFC9705D-D9D3-4CCD-A6CE-333745FF92AB}\MpKsl15018fc3.sys [?]
S1 MpKsl16bc91dd;MpKsl16bc91dd;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{83F52D38-1E48-4640-B368-6C88F60FFE21}\MpKsl16bc91dd.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{83F52D38-1E48-4640-B368-6C88F60FFE21}\MpKsl16bc91dd.sys [?]
S1 MpKsl174314f9;MpKsl174314f9;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{209FD8D9-1A2B-4449-ABD0-70B2074CA88F}\MpKsl174314f9.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{209FD8D9-1A2B-4449-ABD0-70B2074CA88F}\MpKsl174314f9.sys [?]
S1 MpKsl2129bbdf;MpKsl2129bbdf;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9BED1359-6570-4AE1-9CCC-0BB1D58B483F}\MpKsl2129bbdf.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9BED1359-6570-4AE1-9CCC-0BB1D58B483F}\MpKsl2129bbdf.sys [?]
S1 MpKsl219535dc;MpKsl219535dc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4B1A8529-A86A-4240-B0B3-E215F33871ED}\MpKsl219535dc.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4B1A8529-A86A-4240-B0B3-E215F33871ED}\MpKsl219535dc.sys [?]
S1 MpKsl28f8f0fc;MpKsl28f8f0fc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D07AFDC4-AEFD-4A77-8E0B-B3BF0564CA1D}\MpKsl28f8f0fc.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D07AFDC4-AEFD-4A77-8E0B-B3BF0564CA1D}\MpKsl28f8f0fc.sys [?]
S1 MpKsl294132d9;MpKsl294132d9;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1A24D885-34C1-427B-935F-AF5A7C3EBB11}\MpKsl294132d9.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1A24D885-34C1-427B-935F-AF5A7C3EBB11}\MpKsl294132d9.sys [?]
S1 MpKsl29e04e22;MpKsl29e04e22;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E46AA488-DF3C-415F-B9D4-0259F596493B}\MpKsl29e04e22.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E46AA488-DF3C-415F-B9D4-0259F596493B}\MpKsl29e04e22.sys [?]
S1 MpKsl2acb356a;MpKsl2acb356a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AA6A44FD-B59A-410F-80C0-2A2617FE7A27}\MpKsl2acb356a.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AA6A44FD-B59A-410F-80C0-2A2617FE7A27}\MpKsl2acb356a.sys [?]
S1 MpKsl2e51ff07;MpKsl2e51ff07;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{89E65EAC-F7EA-498C-B903-FA813694C95F}\MpKsl2e51ff07.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{89E65EAC-F7EA-498C-B903-FA813694C95F}\MpKsl2e51ff07.sys [?]
S1 MpKsl3101b836;MpKsl3101b836;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6284F307-2E70-40CB-A255-C451E25607B7}\MpKsl3101b836.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6284F307-2E70-40CB-A255-C451E25607B7}\MpKsl3101b836.sys [?]
S1 MpKsl33fcbcbc;MpKsl33fcbcbc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6920ADBB-9A6E-41AF-AE88-9DB4AF6D3FC8}\MpKsl33fcbcbc.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6920ADBB-9A6E-41AF-AE88-9DB4AF6D3FC8}\MpKsl33fcbcbc.sys [?]
S1 MpKsl38b72036;MpKsl38b72036;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B7070CA8-CBEE-465C-B7BC-8C1E8BCC9174}\MpKsl38b72036.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B7070CA8-CBEE-465C-B7BC-8C1E8BCC9174}\MpKsl38b72036.sys [?]
S1 MpKsl39944cce;MpKsl39944cce;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{74092516-3141-420C-B726-68B9A0FA17CA}\MpKsl39944cce.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{74092516-3141-420C-B726-68B9A0FA17CA}\MpKsl39944cce.sys [?]
S1 MpKsl3a9f99a6;MpKsl3a9f99a6;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{42F014E0-1C8C-4B58-9574-ABF5086E4D16}\MpKsl3a9f99a6.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{42F014E0-1C8C-4B58-9574-ABF5086E4D16}\MpKsl3a9f99a6.sys [?]
S1 MpKsl3c2d4d10;MpKsl3c2d4d10;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5E1A22E4-2B1F-46A4-8E90-233EB4CF2184}\MpKsl3c2d4d10.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5E1A22E4-2B1F-46A4-8E90-233EB4CF2184}\MpKsl3c2d4d10.sys [?]
S1 MpKsl3f35a265;MpKsl3f35a265;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0893F1DD-D032-4120-B604-AB279EE4AD63}\MpKsl3f35a265.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0893F1DD-D032-4120-B604-AB279EE4AD63}\MpKsl3f35a265.sys [?]
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.246 [GMT 5:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\help\tours\htmltour\unlock_playing.htm
.
.
((((((((((((((((((((((((( Files Created from 2011-10-02 to 2011-11-02 )))))))))))))))))))))))))))))))
.
.
2011-11-01 11:02 . 2011-10-06 15:48 6668624 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-10-31 11:43 . 2011-10-31 11:43 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2011-10-31 11:42 . 2011-08-31 12:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-31 11:42 . 2011-10-31 11:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malwar
2011-10-30 17:11 . 2011-11-01 12:51 -------- d-----w- c:\program files\Microsoft Security Client
2011-10-29 12:42 . 2011-10-06 15:48 6668624 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-29 06:14 . 2011-10-30 17:18 -------- d-----w- c:\program files\Microsoft Security Essentials
2011-10-29 06:12 . 2011-10-29 06:12 -------- d--h--w- c:\windows\system32\GroupPolicy
2011-10-28 18:14 . 2011-10-28 18:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-10-28 04:52 . 2011-10-28 04:52 134 --sh--w- c:\documents and settings\Administrator\Application Data\per.bat
2011-10-28 04:29 . 2011-10-29 20:12 -------- d-sh--w- c:\documents and settings\Administrator\Local Settings\Application Data\d7afb588
2011-10-28 03:53 . 2011-06-03 20:56 330600 ----a-w- c:\windows\system32\HMIPCore.dll
2011-10-28 03:53 . 2011-10-28 16:24 -------- d-----w- c:\program files\Hide My IP
2011-10-22 05:08 . 2011-10-22 05:08 -------- d-----w- c:\documents and settings\All Users\Application Data\MaskMyIP
2011-10-22 04:59 . 2011-10-22 04:59 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\APN
2011-10-17 13:59 . 2011-10-29 20:38 -------- d-----w- C:\New Folder
2011-10-16 18:48 . 2011-10-16 18:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\MSNInstaller
2011-10-15 18:08 . 2011-10-15 18:08 -------- d-----w- c:\program files\7-Zip
2011-10-08 09:56 . 2011-10-08 09:56 -------- d-----w- c:\program files\Common Files\Symantec Shared
2011-10-08 09:56 . 2011-10-12 19:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2011-10-07 18:28 . 2011-10-07 18:28 -------- d-----w- c:\windows\system32\Adobe
2011-10-04 14:17 . 2008-04-13 18:45 10624 -c--a-w- c:\windows\system32\dllcache\gameenum.sys
2011-10-04 14:17 . 2008-04-13 18:45 10624 ----a-w- c:\windows\system32\drivers\gameenum.sys
2011-10-04 14:16 . 2001-08-17 08:28 907456 -c--a-w- c:\windows\system32\dllcache\hcf_msft.sys
2011-10-04 14:16 . 2001-08-17 08:28 907456 ----a-w- c:\windows\system32\drivers\HCF_MSFT.sys
2011-10-04 14:16 . 2001-08-17 07:19 30720 -c--a-w- c:\windows\system32\dllcache\rthwcls.sys
2011-10-04 14:16 . 2001-08-17 07:19 30720 ----a-w- c:\windows\system32\drivers\rthwcls.sys
2011-10-04 14:16 . 2001-08-17 07:19 3840 -c--a-w- c:\windows\system32\dllcache\rpfun.sys
2011-10-04 14:16 . 2001-08-17 07:19 3840 ----a-w- c:\windows\system32\drivers\rpfun.sys
2011-10-04 14:16 . 2001-08-17 07:19 42112 -c--a-w- c:\windows\system32\dllcache\crtaud.sys
2011-10-04 14:16 . 2001-08-17 07:19 42112 ----a-w- c:\windows\system32\drivers\crtaud.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-07 05:09 . 2011-06-03 09:13 414368 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-26 06:41 . 2008-07-29 14:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 06:41 . 2004-08-04 10:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 06:41 . 2004-08-04 10:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-09 09:12 . 2004-08-04 10:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20 . 2004-08-04 10:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-22 23:48 . 2006-03-04 03:33 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2004-08-04 10:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2004-08-04 10:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2004-08-04 10:00 385024 ----a-w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2004-08-04 10:00 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-10-06 04:40 . 2011-09-28 18:12 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2011-05-30 16:50 21864 ----a-w- c:\program files\Internet Download Manager\IDMShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2011-10-01 3425688]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-04-01 155648]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malwar\mbamgui.exe" [2011-08-31 449608]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2009-04-08 440736]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 07:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-06-06 07:55 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-01-20 09:20 1305408 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-12-13 12:18 136176 ----atw- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2006-04-01 09:31 126976 -c--a-r- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2011-06-15 10:16 997920 ----a-w- c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2006-04-01 09:33 77824 -c--a-r- c:\windows\SOUNDMAN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 09:49 249064 -c--a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)
"wuauserv"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"Spooler"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"e:\\documents\\New Folder\\bin\\java.exe"=
"c:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"d:\\most wanted\\rip Need.4.Spd.Most.Wanted kissme1\\speed.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\cs-1.6\\hl.exe"=
"c:\\WINDOWS\\system32\\msfeedssync.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\DW\\DW20.EXE"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
.
R0 Shadow;Shadow; [x]
R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [8/1/2011 7:28 PM 101616]
R3 crtaud;Conexant Riptide WDM Audio Driver;c:\windows\system32\drivers\crtaud.sys [10/4/2011 7:16 PM 42112]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [10/31/2011 4:42 PM 22216]
R3 rpfun;Conexant Riptide Dummy Driver;c:\windows\system32\drivers\rpfun.sys [10/4/2011 7:16 PM 3840]
R3 rthwcls;Conexant Riptide Bus / Firmware Downloader;c:\windows\system32\drivers\rthwcls.sys [10/4/2011 7:16 PM 30720]
S1 bvgffrex;bvgffrex;\??\c:\windows\system32\drivers\bvgffrex.sys --> c:\windows\system32\drivers\bvgffrex.sys [?]
S1 cwkxolyf;cwkxolyf;\??\c:\windows\system32\drivers\cwkxolyf.sys --> c:\windows\system32\drivers\cwkxolyf.sys [?]
S1 eifckibx;eifckibx;\??\c:\windows\system32\drivers\eifckibx.sys --> c:\windows\system32\drivers\eifckibx.sys [?]
S1 fnsvyqmu;fnsvyqmu;\??\c:\windows\system32\drivers\fnsvyqmu.sys --> c:\windows\system32\drivers\fnsvyqmu.sys [?]
S1 goimqobt;goimqobt;\??\c:\windows\system32\drivers\goimqobt.sys --> c:\windows\system32\drivers\goimqobt.sys [?]
S1 hnybtrdy;hnybtrdy;\??\c:\windows\system32\drivers\hnybtrdy.sys --> c:\windows\system32\drivers\hnybtrdy.sys [?]
S1 hvltatax;hvltatax;\??\c:\windows\system32\drivers\hvltatax.sys --> c:\windows\system32\drivers\hvltatax.sys [?]
S1 jmrujfpm;jmrujfpm;\??\c:\windows\system32\drivers\jmrujfpm.sys --> c:\windows\system32\drivers\jmrujfpm.sys [?]
S1 kqyacfcv;kqyacfcv;\??\c:\windows\system32\drivers\kqyacfcv.sys --> c:\windows\system32\drivers\kqyacfcv.sys [?]
S1 MpKsl014b491c;MpKsl014b491c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9BED1359-6570-4AE1-9CCC-0BB1D58B483F}\MpKsl014b491c.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9BED1359-6570-4AE1-9CCC-0BB1D58B483F}\MpKsl014b491c.sys [?]
S1 MpKsl0395a3c6;MpKsl0395a3c6;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{498CA44B-AED4-4E97-A50D-AC0B93D0A86E}\MpKsl0395a3c6.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{498CA44B-AED4-4E97-A50D-AC0B93D0A86E}\MpKsl0395a3c6.sys [?]
S1 MpKsl0845343d;MpKsl0845343d;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6920ADBB-9A6E-41AF-AE88-9DB4AF6D3FC8}\MpKsl0845343d.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6920ADBB-9A6E-41AF-AE88-9DB4AF6D3FC8}\MpKsl0845343d.sys [?]
S1 MpKsl0fd6a622;MpKsl0fd6a622;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{10AAA116-81D5-48E1-A7AB-DA769B1E27EC}\MpKsl0fd6a622.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{10AAA116-81D5-48E1-A7AB-DA769B1E27EC}\MpKsl0fd6a622.sys [?]
S1 MpKsl131968d2;MpKsl131968d2;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B7070CA8-CBEE-465C-B7BC-8C1E8BCC9174}\MpKsl131968d2.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B7070CA8-CBEE-465C-B7BC-8C1E8BCC9174}\MpKsl131968d2.sys [?]
S1 MpKsl15018fc3;MpKsl15018fc3;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BFC9705D-D9D3-4CCD-A6CE-333745FF92AB}\MpKsl15018fc3.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BFC9705D-D9D3-4CCD-A6CE-333745FF92AB}\MpKsl15018fc3.sys [?]
S1 MpKsl16bc91dd;MpKsl16bc91dd;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{83F52D38-1E48-4640-B368-6C88F60FFE21}\MpKsl16bc91dd.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{83F52D38-1E48-4640-B368-6C88F60FFE21}\MpKsl16bc91dd.sys [?]
S1 MpKsl174314f9;MpKsl174314f9;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{209FD8D9-1A2B-4449-ABD0-70B2074CA88F}\MpKsl174314f9.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{209FD8D9-1A2B-4449-ABD0-70B2074CA88F}\MpKsl174314f9.sys [?]
S1 MpKsl2129bbdf;MpKsl2129bbdf;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9BED1359-6570-4AE1-9CCC-0BB1D58B483F}\MpKsl2129bbdf.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9BED1359-6570-4AE1-9CCC-0BB1D58B483F}\MpKsl2129bbdf.sys [?]
S1 MpKsl219535dc;MpKsl219535dc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4B1A8529-A86A-4240-B0B3-E215F33871ED}\MpKsl219535dc.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4B1A8529-A86A-4240-B0B3-E215F33871ED}\MpKsl219535dc.sys [?]
S1 MpKsl28f8f0fc;MpKsl28f8f0fc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D07AFDC4-AEFD-4A77-8E0B-B3BF0564CA1D}\MpKsl28f8f0fc.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D07AFDC4-AEFD-4A77-8E0B-B3BF0564CA1D}\MpKsl28f8f0fc.sys [?]
S1 MpKsl294132d9;MpKsl294132d9;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1A24D885-34C1-427B-935F-AF5A7C3EBB11}\MpKsl294132d9.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1A24D885-34C1-427B-935F-AF5A7C3EBB11}\MpKsl294132d9.sys [?]
S1 MpKsl29e04e22;MpKsl29e04e22;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E46AA488-DF3C-415F-B9D4-0259F596493B}\MpKsl29e04e22.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E46AA488-DF3C-415F-B9D4-0259F596493B}\MpKsl29e04e22.sys [?]
S1 MpKsl2acb356a;MpKsl2acb356a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AA6A44FD-B59A-410F-80C0-2A2617FE7A27}\MpKsl2acb356a.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AA6A44FD-B59A-410F-80C0-2A2617FE7A27}\MpKsl2acb356a.sys [?]
S1 MpKsl2e51ff07;MpKsl2e51ff07;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{89E65EAC-F7EA-498C-B903-FA813694C95F}\MpKsl2e51ff07.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{89E65EAC-F7EA-498C-B903-FA813694C95F}\MpKsl2e51ff07.sys [?]
S1 MpKsl3101b836;MpKsl3101b836;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6284F307-2E70-40CB-A255-C451E25607B7}\MpKsl3101b836.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6284F307-2E70-40CB-A255-C451E25607B7}\MpKsl3101b836.sys [?]
S1 MpKsl33fcbcbc;MpKsl33fcbcbc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6920ADBB-9A6E-41AF-AE88-9DB4AF6D3FC8}\MpKsl33fcbcbc.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6920ADBB-9A6E-41AF-AE88-9DB4AF6D3FC8}\MpKsl33fcbcbc.sys [?]
S1 MpKsl38b72036;MpKsl38b72036;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B7070CA8-CBEE-465C-B7BC-8C1E8BCC9174}\MpKsl38b72036.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B7070CA8-CBEE-465C-B7BC-8C1E8BCC9174}\MpKsl38b72036.sys [?]
S1 MpKsl39944cce;MpKsl39944cce;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{74092516-3141-420C-B726-68B9A0FA17CA}\MpKsl39944cce.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{74092516-3141-420C-B726-68B9A0FA17CA}\MpKsl39944cce.sys [?]
S1 MpKsl3a9f99a6;MpKsl3a9f99a6;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{42F014E0-1C8C-4B58-9574-ABF5086E4D16}\MpKsl3a9f99a6.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{42F014E0-1C8C-4B58-9574-ABF5086E4D16}\MpKsl3a9f99a6.sys [?]
S1 MpKsl3c2d4d10;MpKsl3c2d4d10;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5E1A22E4-2B1F-46A4-8E90-233EB4CF2184}\MpKsl3c2d4d10.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5E1A22E4-2B1F-46A4-8E90-233EB4CF2184}\MpKsl3c2d4d10.sys [?]
S1 MpKsl3f35a265;MpKsl3f35a265;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0893F1DD-D032-4120-B604-AB279EE4AD63}\MpKsl3f35a265.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0893F1DD-D032-4120-B604-AB279EE4AD63}\MpKsl3f35a265.sys [?]