MBRCHECK
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: (build 7600), 64-bit
Base Board Manufacturer: ASUSTeK Computer INC.
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: System manufacturer
System Product Name: System Product Name
Logical Drives Mask: 0x000003d5
Kernel Drivers (total 184):
0x02A4B000 \SystemRoot\system32\ntoskrnl.exe
0x02A02000 \SystemRoot\system32\hal.dll
0x00BD2000 \SystemRoot\system32\kdcom.dll
0x00C2C000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00C70000 \SystemRoot\system32\PSHED.dll
0x00C84000 \SystemRoot\system32\CLFS.SYS
0x00CE2000 \SystemRoot\system32\CI.dll
0x00EA6000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00F4A000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00F59000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x00FB0000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x00FB9000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x00FC3000 \SystemRoot\system32\DRIVERS\pci.sys
0x00E00000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x00E0D000 \SystemRoot\System32\drivers\partmgr.sys
0x00E22000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x00E37000 \SystemRoot\System32\drivers\volmgrx.sys
0x00E93000 \SystemRoot\system32\DRIVERS\pciide.sys
0x00DA2000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x00DB2000 \SystemRoot\System32\drivers\mountmgr.sys
0x00E9A000 \SystemRoot\system32\DRIVERS\atapi.sys
0x00DCC000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x00C00000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x0108E000 \SystemRoot\system32\drivers\fltmgr.sys
0x010DA000 \SystemRoot\system32\drivers\fileinfo.sys
0x01215000 \SystemRoot\System32\Drivers\Ntfs.sys
0x010EE000 \SystemRoot\System32\Drivers\msrpc.sys
0x013B8000 \SystemRoot\System32\Drivers\ksecdd.sys
0x0114C000 \SystemRoot\System32\Drivers\cng.sys
0x013D2000 \SystemRoot\System32\drivers\pcw.sys
0x013E3000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x01499000 \SystemRoot\system32\drivers\ndis.sys
0x0158B000 \SystemRoot\system32\drivers\NETIO.SYS
0x01400000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x01602000 \SystemRoot\System32\drivers\tcpip.sys
0x0142B000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x01000000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x01475000 \SystemRoot\System32\Drivers\spldr.sys
0x0104C000 \SystemRoot\System32\drivers\rdyboost.sys
0x0147D000 \SystemRoot\System32\Drivers\mup.sys
0x0148F000 \SystemRoot\System32\drivers\hwpolicy.sys
0x011BF000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x00C0B000 \SystemRoot\system32\DRIVERS\disk.sys
0x01813000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x01879000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x018A3000 \SystemRoot\System32\Drivers\Null.SYS
0x018AC000 \SystemRoot\System32\Drivers\Beep.SYS
0x018B3000 \SystemRoot\System32\drivers\vga.sys
0x018C1000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x018E6000 \SystemRoot\System32\drivers\watchdog.sys
0x018F6000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x018FF000 \SystemRoot\system32\drivers\rdpencdd.sys
0x01908000 \SystemRoot\system32\drivers\rdprefmp.sys
0x01911000 \SystemRoot\System32\Drivers\Msfs.SYS
0x0191C000 \SystemRoot\System32\Drivers\Npfs.SYS
0x0192D000 \SystemRoot\system32\DRIVERS\tdx.sys
0x0194B000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x01958000 \SystemRoot\system32\drivers\afd.sys
0x02C15000 \SystemRoot\System32\DRIVERS\netbt.sys
0x02C5A000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x02C63000 \SystemRoot\system32\DRIVERS\pacer.sys
0x02C89000 \SystemRoot\system32\DRIVERS\netbios.sys
0x02C98000 \SystemRoot\system32\DRIVERS\serial.sys
0x02CB5000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x02CD0000 \SystemRoot\system32\DRIVERS\termdd.sys
0x02CE4000 \SystemRoot\System32\Drivers\SCDEmu.SYS
0x02CFE000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
0x02D08000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
0x02D12000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x02D63000 \SystemRoot\system32\drivers\nsiproxy.sys
0x02D6F000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x02D7A000 \SystemRoot\System32\drivers\discache.sys
0x02D89000 \SystemRoot\System32\Drivers\dfsc.sys
0x02DA7000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x02DB8000 \SystemRoot\system32\DRIVERS\avipbb.sys
0x02DDA000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x019E2000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x0481B000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x053F5000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
0x03CDA000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x03C00000 \SystemRoot\System32\drivers\dxgmms1.sys
0x03C46000 \SystemRoot\system32\DRIVERS\serenum.sys
0x03C52000 \SystemRoot\system32\DRIVERS\fdc.sys
0x03C5F000 \SystemRoot\system32\DRIVERS\parport.sys
0x03C7C000 \SystemRoot\system32\DRIVERS\ASACPI.sys
0x03C84000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x03CA2000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x03CB1000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x03CC0000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x03CCD000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x0407C000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x040D2000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x040E3000 \SystemRoot\system32\DRIVERS\SiSG664.sys
0x040F6000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x0411A000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x0412A000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x04140000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x04164000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x04170000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x0419F000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x041BA000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x041DB000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x041F5000 \SystemRoot\system32\DRIVERS\swenum.sys
0x04000000 \SystemRoot\system32\DRIVERS\ks.sys
0x04043000 \SystemRoot\system32\DRIVERS\umbus.sys
0x04055000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0x03EB8000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x03F12000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x03F27000 \SystemRoot\system32\drivers\HdAudio.sys
0x03F83000 \SystemRoot\system32\drivers\portcls.sys
0x03FC0000 \SystemRoot\system32\drivers\drmk.sys
0x03FE2000 \SystemRoot\system32\drivers\ksthunk.sys
0x00060000 \SystemRoot\System32\win32k.sys
0x03FE8000 \SystemRoot\System32\drivers\Dxapi.sys
0x03E00000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x03E1D000 \SystemRoot\System32\Drivers\crashdmp.sys
0x03E2B000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x03E37000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x03E40000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x03E53000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x03E6E000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x03E70000 \SystemRoot\system32\DRIVERS\monitor.sys
0x004F0000 \SystemRoot\System32\TSDDD.dll
0x006D0000 \SystemRoot\System32\cdd.dll
0x03E7E000 \SystemRoot\system32\drivers\luafv.sys
0x03DCE000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0x01843000 \SystemRoot\system32\drivers\WudfPf.sys
0x03EA1000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x04060000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x03478000 \SystemRoot\system32\drivers\HTTP.sys
0x03540000 \SystemRoot\system32\DRIVERS\bowser.sys
0x0355E000 \SystemRoot\System32\drivers\mpsdrv.sys
0x03576000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x035A3000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x03400000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x04695000 \SystemRoot\system32\drivers\peauth.sys
0x0473B000 \SystemRoot\System32\Drivers\secdrv.SYS
0x04746000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x04773000 \SystemRoot\System32\drivers\tcpipreg.sys
0x04785000 \SystemRoot\system32\drivers\spsys.sys
0x04600000 \SystemRoot\System32\DRIVERS\srv2.sys
0x056EF000 \SystemRoot\System32\DRIVERS\srv.sys
0x05785000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0x057B6000 \SystemRoot\System32\Drivers\fastfat.SYS
0x77310000 \Windows\System32\ntdll.dll
0x47830000 \Windows\System32\smss.exe
0xFF630000 \Windows\System32\apisetschema.dll
0xFFFF0000 \Windows\System32\autochk.exe
0xFF510000 \Windows\System32\msctf.dll
0xFF4E0000 \Windows\System32\imm32.dll
0xFF4C0000 \Windows\System32\sechost.dll
0xFF4A0000 \Windows\System32\imagehlp.dll
0x77210000 \Windows\System32\user32.dll
0xFF420000 \Windows\System32\shlwapi.dll
0xFF1C0000 \Windows\System32\iertutil.dll
0x770F0000 \Windows\System32\kernel32.dll
0xFEFE0000 \Windows\System32\setupapi.dll
0xFEEB0000 \Windows\System32\rpcrt4.dll
0xFEE10000 \Windows\System32\clbcatq.dll
0xFED70000 \Windows\System32\msvcrt.dll
0xFED20000 \Windows\System32\ws2_32.dll
0xFDF90000 \Windows\System32\shell32.dll
0xFDF10000 \Windows\System32\difxapi.dll
0xFDE70000 \Windows\System32\comdlg32.dll
0xFDD40000 \Windows\System32\wininet.dll
0x774E0000 \Windows\System32\normaliz.dll
0xFDCF0000 \Windows\System32\Wldap32.dll
0xFDB70000 \Windows\System32\urlmon.dll
0x774D0000 \Windows\System32\psapi.dll
0xFDA90000 \Windows\System32\oleaut32.dll
0xFD880000 \Windows\System32\ole32.dll
0xFD7A0000 \Windows\System32\advapi32.dll
0xFD6D0000 \Windows\System32\usp10.dll
0xFD6C0000 \Windows\System32\lpk.dll
0xFD6B0000 \Windows\System32\nsi.dll
0xFD640000 \Windows\System32\gdi32.dll
0xFD4D0000 \Windows\System32\crypt32.dll
0xFD490000 \Windows\System32\cfgmgr32.dll
0xFD420000 \Windows\System32\KernelBase.dll
0xFD380000 \Windows\System32\comctl32.dll
0xFD360000 \Windows\System32\devobj.dll
0xFD320000 \Windows\System32\wintrust.dll
0xFD310000 \Windows\System32\msasn1.dll
0x75440000 \Windows\SysWOW64\normaliz.dll
Processes (total 65):
0 System Idle Process
4 System
360 C:\Windows\System32\smss.exe
452 csrss.exe
512 C:\Windows\System32\wininit.exe
524 csrss.exe
576 C:\Windows\System32\winlogon.exe
616 C:\Windows\System32\services.exe
624 C:\Windows\System32\lsass.exe
632 C:\Windows\System32\lsm.exe
748
ComboFix
ComboFix 10-12-11.06 - Omar al-Bashir 13/12/2010 14:36:05.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.61.1033.18.2047.1157 [GMT 11:00]
Running from: c:\users\Omar al-Bashir\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
c:\program files (x86)\Common Files\Java\Java Update\jusched.exe
c:\program files (x86)\iTunes\iTunesHelper.exe
c:\program files (x86)\PowerISO\PWRISOVM.EXE
c:\program files (x86)\QuickTime\QTTask.exe
c:\programdata\GQIhgV73.exe
c:\programdata\GQIhgV73.exe_
c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe . . . . Failed to delete
Code:
<pre>
c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl .exe ---^> c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM .exe ---^> c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier .exe ---^> c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
c:\program files (x86)\Common Files\Java\Java Update\jusched .exe ---^> c:\program files (x86)\Common Files\Java\Java Update\jusched.exe
</pre>
.
.
((((((((((((((((((((((((( Files Created from 2010-11-13 to 2010-12-13 )))))))))))))))))))))))))))))))
.
2010-12-12 23:45 . 2010-12-12 23:45 -------- d-----w- c:\windows\SysWow64\wbem\Logs
2010-12-12 23:08 . 2010-12-12 23:08 -------- d-----w- c:\users\Omar al-Bashir\AppData\Roaming\SUPERAntiSpyware.com
2010-12-12 23:08 . 2010-12-12 23:08 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-12-12 23:08 . 2010-12-12 23:08 -------- d-----w- c:\programdata\!SASCORE
2010-12-12 23:08 . 2010-12-12 23:09 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-12-12 22:36 . 2010-12-13 03:55 -------- d-----w- c:\users\Omar al-Bashir\AppData\Local\Temp
2010-12-12 01:03 . 2010-11-10 05:35 8199504 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{54BC2105-53B8-4E80-9D45-7B9C4E5E6147}\mpengine.dll
2010-12-09 05:33 . 2010-12-09 05:33 -------- d-----w- c:\program files (x86)\Conduit
2010-12-09 05:33 . 2010-12-09 05:33 -------- d-----w- c:\program files (x86)\uTorrentBar
2010-12-09 05:33 . 2010-12-09 05:33 -------- d-----w- C:\extensions
2010-12-09 01:04 . 2010-12-09 01:04 -------- d-----w- c:\program files (x86)\MegaDev
2010-12-08 05:45 . 2010-12-12 22:20 -------- d-----w- c:\users\Admin
2010-12-07 11:23 . 2010-12-07 11:23 -------- d-----w- c:\windows\SysWow64\URTTEMP
2010-12-07 10:48 . 2010-12-07 10:48 -------- d-----w- c:\program files (x86)\Turbine
2010-12-07 05:49 . 2010-12-13 03:44 -------- d-----w- c:\programdata\NVIDIA
2010-12-07 05:48 . 2010-12-07 05:48 -------- d-----w- c:\programdata\NVIDIA Corporation
2010-12-07 05:46 . 2010-12-07 05:46 -------- d-----w- C:\NVIDIA
2010-12-07 04:04 . 2010-12-07 04:04 -------- d-----w- c:\users\Omar al-Bashir\AppData\Local\Apps
2010-12-07 04:04 . 2010-12-13 03:05 -------- d-----w- c:\users\Omar al-Bashir\AppData\Local\Deployment
2010-12-07 03:56 . 2010-12-07 04:04 -------- d-----w- c:\programdata\Blizzard Entertainment
2010-12-07 03:53 . 2010-12-07 03:54 -------- d-----w- c:\program files (x86)\ReducetheLag
2010-12-05 23:00 . 2010-12-05 23:00 -------- d-----w- c:\programdata\EA Core
2010-12-05 19:02 . 2008-07-11 21:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2010-12-05 14:11 . 2010-12-05 14:11 -------- d-----w- c:\programdata\Solidshield
2010-12-05 13:44 . 2010-12-05 13:44 -------- d-----w- c:\users\Omar al-Bashir\AppData\Roaming\Malwarebytes
2010-12-05 13:44 . 2010-11-29 06:42 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2010-12-05 13:44 . 2010-12-05 13:44 -------- d-----w- c:\programdata\Malwarebytes
2010-12-05 13:43 . 2010-12-12 22:57 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2010-12-05 13:43 . 2010-11-29 06:42 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-04 08:26 . 2010-12-04 08:26 -------- d-----w- c:\program files (x86)\Reality Pump
2010-12-04 08:24 . 2010-12-07 05:49 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2010-12-04 08:23 . 2010-12-04 08:23 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2010-12-04 07:01 . 2010-12-04 07:01 -------- d-----w- c:\users\Omar al-Bashir\AppData\Roaming\Childish Things
2010-12-04 07:01 . 2010-12-04 07:01 126976 ----a-w- c:\windows\lcmmfu.cpl
2010-12-04 07:01 . 2010-12-08 05:21 681 --sha-w- c:\windows\SysWow64\mmf.sys
2010-12-04 07:01 . 2010-12-04 07:01 48640 ----a-w- c:\windows\mmfs.dll
2010-12-04 07:01 . 2010-12-04 07:01 2560 ----a-w- c:\windows\Runservice.exe
2010-12-04 06:59 . 2008-03-04 09:38 348160 ----a-w- c:\windows\msvcr71.dll
2010-12-04 06:59 . 2010-12-04 06:59 -------- d-----w- c:\program files (x86)\Childish Things
2010-12-02 20:23 . 2010-12-07 09:00 -------- d-----w- c:\users\Omar al-Bashir\AppData\Roaming\My Battle for Middle-earth(tm) II Files
2010-12-02 08:41 . 2010-12-02 08:41 -------- d-----w- c:\program files\iPod
2010-12-02 08:41 . 2010-12-13 03:41 -------- d-----w- c:\program files (x86)\iTunes
2010-12-02 08:41 . 2010-12-02 08:41 -------- d-----w- c:\program files\iTunes
2010-12-02 08:38 . 2010-12-02 08:38 -------- d-----w- c:\program files (x86)\Safari
2010-12-02 03:53 . 2010-12-02 03:53 -------- d-----w- c:\program files (x86)\EA GAMES
2010-12-01 05:06 . 2010-12-01 10:13 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
2010-11-29 20:31 . 2010-12-02 00:24 -------- d-----w- c:\users\Omar al-Bashir\AppData\Roaming\My The Lord of the Rings, The Rise of the Witch-king Files
2010-11-25 06:53 . 2010-11-25 06:53 -------- d-----w- c:\users\Omar al-Bashir\AppData\Roaming\Mount&Blade Warband
2010-11-25 01:27 . 2010-11-25 01:27 -------- d-----w- c:\program files (x86)\Click Photobooks
2010-11-23 20:32 . 2010-10-19 08:47 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-11-23 20:32 . 2010-10-19 08:10 7680 ----a-w- c:\program files (x86)\Internet Explorer\iecompat.dll
2010-11-19 06:16 . 2010-12-07 03:57 -------- d-----w- c:\program files\PeerBlock
2010-11-15 12:30 . 2010-12-07 12:43 -------- d-----w- c:\users\Omar al-Bashir\AppData\Roaming\gtk-2.0
2010-11-15 12:30 . 2010-11-15 12:30 -------- d-----w- c:\users\Omar al-Bashir\.thumbnails
2010-11-15 12:22 . 2010-12-07 16:21 -------- d-----w- c:\users\Omar al-Bashir\.gimp-2.6
2010-11-15 12:16 . 2010-11-15 12:16 -------- d-----w- c:\program files (x86)\GIMP-2.0
2010-11-15 08:06 . 2010-11-15 08:06 -------- d-----w- c:\program files (x86)\Real Alternative
2010-11-14 16:00 . 2010-03-04 04:32 243712 ----a-w- c:\windows\system32\drivers\ks.sys
2010-11-13 23:41 . 2010-07-13 05:37 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2010-11-13 12:00 . 2010-12-13 03:55 -------- d-----w- c:\users\Omar al-Bashir\Tracing
2010-11-13 11:56 . 2010-11-13 11:56 -------- d-----w- c:\windows\en
2010-11-13 11:55 . 2010-11-13 11:55 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2010-11-13 11:53 . 2010-11-13 11:56 -------- d-----w- c:\program files (x86)\Windows Live
2010-11-13 11:53 . 2010-09-22 13:36 48488 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2010-11-13 11:52 . 2010-11-13 11:53 -------- d-----w- c:\program files\Windows Live
2010-11-13 11:52 . 2010-11-13 11:52 -------- d-----w- c:\program files (x86)\MSN Toolbar
2010-11-13 11:52 . 2010-11-13 11:52 -------- d-----w- c:\program files (x86)\Bing Bar Installer
2010-11-13 11:50 . 2010-11-13 23:35 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2010-11-13 11:50 . 2010-08-11 05:13 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2010-11-13 11:50 . 2010-08-11 04:35 1164800 ----a-w- c:\windows\SysWow64\UIRibbonRes.dll
2010-11-13 11:50 . 2010-08-11 05:19 3860992 ----a-w- c:\windows\system32\UIRibbon.dll
2010-11-13 11:50 . 2010-08-11 04:44 2983424 ----a-w- c:\windows\SysWow64\UIRibbon.dll
2010-11-13 11:49 . 2010-05-23 08:35 257024 ----a-w- c:\windows\system32\mfreadwrite.dll
2010-11-13 11:49 . 2010-05-23 08:35 206848 ----a-w- c:\windows\system32\mfps.dll
2010-11-13 11:49 . 2010-05-23 10:15 1619456 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2010-11-13 11:49 . 2010-05-23 10:11 196608 ----a-w- c:\windows\SysWow64\mfreadwrite.dll
2010-11-13 11:49 . 2010-05-23 08:37 1888256 ----a-w- c:\windows\system32\WMVDECOD.DLL
2010-11-13 11:49 . 2010-05-23 10:11 3181568 ----a-w- c:\windows\SysWow64\mf.dll
2010-11-13 11:49 . 2010-05-23 08:35 4068864 ----a-w- c:\windows\system32\mf.dll
2010-11-13 11:48 . 2010-12-13 00:24 -------- d-----w- c:\users\Omar al-Bashir\AppData\Local\Windows Live
2010-11-13 11:48 . 2010-11-13 11:48 -------- d-----w- c:\program files (x86)\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-22 21:53 . 2010-10-18 09:28 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-10-18 23:41 . 2010-10-18 09:13 270720 ------w- c:\windows\system32\MpSigStub.exe
2010-10-18 20:25 . 2010-10-18 20:26 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2010-10-18 08:57 . 2010-10-18 08:57 419840 ----a-w- c:\windows\system32\systemcpl.dll
2010-10-18 08:57 . 2009-07-13 23:52 14848 ----a-w- c:\windows\system32\slwga.dll
2010-10-18 08:57 . 2009-07-13 23:36 13824 ----a-w- c:\windows\SysWow64\slwga.dll
2010-10-16 18:55 . 2009-07-13 21:59 7491688 ----a-w- c:\windows\system32\nvwgf2umx.dll
2010-10-16 18:55 . 2009-07-13 21:59 5473896 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2010-10-16 18:55 . 2009-06-10 20:37 10023528 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2010-10-16 02:13 . 2010-10-16 02:13 5901416 ----a-w- c:\windows\system32\nvcpl.dll
2010-10-16 02:13 . 2010-10-16 02:13 989800 ----a-w- c:\windows\system32\nvvsvc.exe
2010-10-16 02:13 . 2010-10-16 02:13 61032 ----a-w- c:\windows\system32\nvshext.dll
2010-10-16 02:13 . 2010-10-16 02:13 2590824 ----a-w- c:\windows\system32\nvsvc64.dll
2010-10-16 02:13 . 2010-10-16 02:13 116328 ----a-w- c:\windows\system32\nvmctray.dll
2010-10-01 23:50 . 2010-10-18 08:41 90112 ----a-w- c:\windows\system32\drivers\MijXfilt.sys
2010-09-28 04:44 . 2010-09-28 04:44 51712 ----a-w- c:\windows\system32\drivers\usbaapl64.sys
2010-09-28 04:44 . 2010-09-28 04:44 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-09-22 13:47 . 2010-09-22 13:47 49016 ----a-w- c:\windows\SysWow64\sirenacm.dll
2010-09-22 13:32 . 2010-09-22 13:32 301936 ----a-w- c:\windows\WLXPGSS.SCR
2010-09-21 03:49 . 2010-09-21 03:49 252800 ----a-w- c:\windows\system32\LIVESSP.DLL
2010-09-21 03:03 . 2010-09-21 03:03 208768 ----a-w- c:\windows\SysWow64\LIVESSP.DLL
.
Code:
<pre>
c:\program files (x86)\Avira\AntiVir Desktop\avgnt .exe
c:\program files (x86)\iTunes\iTunesHelper .exe
c:\program files (x86)\PowerISO\PWRISOVM .exe
c:\program files (x86)\QuickTime\QTTask .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-11-29 04:26 3908192 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-11-29 04:26 3908192 ----a-w- c:\program files (x86)\uTorrentBar\tbuTor.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-11-29 3908192]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-11-29 3908192]
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-09-22 4240760]
"EA Core"="d:\games\FIFA 11\EADM\Core.exe" [N/A]
"DS3 Tool"="c:\program files\MotioninJoy\ds3\DS3_Tool.exe" [2010-10-02 92672]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-11-22 2988784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask .exe -atboottime" [X]
"PWRISOVM.EXE"="c:\program files (x86)\PowerISO\PWRISOVM.EXE" [N/A]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [N/A]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2010-12-12 42500]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-22 35760]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Wxumimelumor"="c:\windows\system32\config\systemprofile\AppData\Local\necsev.dll" [N/A]
c:\users\Omar al-Bashir\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
CurseClientStartup.ccip [2010-12-7 0]
GameRanger.lnk - c:\users\Omar al-Bashir\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe [2010-9-30 1248992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-24 51456888]
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys [2010-10-01 90112]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [2009-09-27 19544]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2010-09-28 51712]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-18 1255736]
R4 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-18 135664]
R4 LicCtrlService;LicCtrl Service;c:\windows\runservice.exe [2010-12-04 2560]
R4 ReduceTheLag-v3;ReduceTheLag-v3;c:\program files (x86)\ReducetheLag\reducethelag_v3_service.exe [2010-12-06 174080]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2010-11-04 135336]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
.
Contents of the 'Scheduled Tasks' folder
2010-12-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-18 20:26]
2010-12-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-18 20:26]
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com.au/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
AddRemove-$NtUninstallMTF197$ - c:\windows\$NtUninstallMTF197$\apUninstall.exe
AddRemove-Fallout New Vegas_is1 - d:\games\Fallout New Vegas\unins000.exe
AddRemove-Worms Reloaded_is1 - d:\games\Worms Reloaded\unins000.exe
AddRemove-{B931FB80-537A-4600-00AD-AC5DEDB6C25B} - c:\program files (x86)\Electronic Arts\The Lord of the Rings
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \9A6A5634BD3048B3]
"1"=hex:f2,dc,b8,ca,29,8b,06,04,aa,02,59,06,c2,ef,5d,4d,b0,17,3e,13,b8,98,f9,
10,0a,f2,16,5c,a8,1c,4f,a3
"2"=hex:e7,27,cf,42,f4,44,fe,c6,d8,f2,16,d1,8e,4d,81,a5,c1,5f,93,ef,b5,cb,1d,
04,36,ee,2f,8d,a7,5c,96,01
"3"=hex:f2,dc,b8,ca,29,8b,06,04,aa,02,59,06,c2,ef,5d,4d,7c,ee,b3,94,39,1d,bb,
5e,97,e6,9e,cf,eb,f2,94,ca,73,e6,d4,34,53,90,04,70,e8,7f,25,57,05,a4,49,dd,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \9A6A5634BD3048B3\B7DAAD172AA12168E008FD873A1BED58]
"1"=hex:15,c0,1b,ee,a2,cd,62,4d,d2,23,38,04,69,c0,07,cb,be,7f,03,af,a5,f1,05,
d0,1a,47,b5,40,b3,3c,2a,70,56,10,ce,bb,de,cc,2b,9c
"2"=hex:5c,c7,46,22,af,0f,12,bb
"3"=hex:81,20,8f,ab,28,6a,52,9c
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:bf,e5,23,7b,b0,66,d6,fc,bc,64,22,fb,7e,d3,39,3e,a3,00,33,13,c0,21,f4,
51,6c,4e,0c,96,e2,dd,ad,8a,b6,c4,05,e8,5a,bd,9a,e9,d4,1a,3d,68,9d,00,32,20
"7"=hex:f2,dc,b8,ca,29,8b,06,04,aa,02,59,06,c2,ef,5d,4d,3f,f3,42,c6,c3,65,02,
28,73,ee,9e,5f,dc,e9,7b,7f,2e,33,55,23,c0,bf,6f,0f,06,ce,de,e3,81,cf,0f,34,\
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,2a,be,8e,36,28,f4,02,
cb,1c,f8,37,0e,ea,aa,49,b6,53,77,3f,7e,31,6c,61,29,60,86,bb,06,4b,cb,4a,be,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:70,56,26,33,e3,20,f8,ab
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:81,20,8f,ab,28,6a,52,9c
"13"=hex:81,20,8f,ab,28,6a,52,9c
"14"=hex:81,20,8f,ab,28,6a,52,9c
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:81,20,8f,ab,28,6a,52,9c
"22"=hex:81,20,8f,ab,28,6a,52,9c
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Internet Explorer\iexplore.exe
c:\program files (x86)\Internet Explorer\iexplore.exe
c:\program files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
c:\program files (x86)\MSN Toolbar\Platform\6.3.2322.0\mswinext.exe
.
**************************************************************************
.
Completion time: 2010-12-13 15:00:02 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-13 04:00
Pre-Run: 53,181,263,872 bytes free
Post-Run: 52,872,437,760 bytes free
- - End Of File - - A06D2422B929454E0D1BA0DDE1AD6EBB