ComboFix 08-09-01.05 - Drum 2008-09-04 16:33:55.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1038.18.581 [GMT 2:00]
Running from: E:\Documents and Settings\Drum\Asztal\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-08-04 to 2008-09-04 )))))))))))))))))))))))))))))))
.
2008-09-04 16:01 . 2008-09-04 16:02 <DIR> d-------- E:\Program Files\HJK
2008-09-04 13:02 . 2008-09-04 13:02 <DIR> d-------- E:\Documents and Settings\Drum\Application Data\gtopala
2008-09-04 11:42 . 2008-09-04 11:42 <DIR> d-------- E:\Program Files\Guitar Pro 5
2008-09-04 01:42 . 2008-09-04 01:42 <DIR> d-------- E:\Documents and Settings\Drum\Application Data\HEXelon
2008-09-04 01:42 . 2006-01-13 14:00 15,872 --a------ E:\WINDOWS\system32\drivers\vd_filedisk.sys
2008-09-04 01:41 . 2008-09-04 12:47 <DIR> d-------- E:\Program Files\TC UP
2008-09-04 01:25 . 2008-09-04 01:25 <DIR> d-------- E:\Program Files\Vodafone
2008-09-04 01:25 . 2008-09-04 01:25 <DIR> d-------- E:\Program Files\Common Files\InstallShield
2008-09-04 01:25 . 2008-09-04 01:25 <DIR> d-------- E:\Documents and Settings\LocalService\Application Data\Vodafone
2008-09-04 01:25 . 2008-09-04 01:25 <DIR> d-------- E:\Documents and Settings\Drum\Application Data\Vodafone
2008-09-04 01:25 . 2008-09-04 01:25 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Vodafone
2008-09-04 01:25 . 2008-09-04 01:25 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\InstallShield
2008-09-04 01:24 . 2008-09-04 01:24 <DIR> d-------- E:\Program Files\CCleaner
2008-09-04 01:19 . 2004-08-03 23:08 26,496 --a--c--- E:\WINDOWS\system32\dllcache\usbstor.sys
2008-09-04 01:17 . 2008-09-04 01:17 <DIR> d-------- E:\Documents and Settings\Drum\Application Data\ESET
2008-09-04 01:16 . 2008-09-04 01:16 <DIR> d-------- E:\Program Files\ESET
2008-09-04 01:16 . 2008-09-04 01:16 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\ESET
2008-09-04 01:11 . 2008-09-04 01:11 <DIR> d---s---- E:\WINDOWS\system32\Microsoft
2008-09-04 01:05 . 2008-09-04 01:14 316,640 --a------ E:\WINDOWS\WMSysPr9.prx
2008-09-04 01:03 . 2008-09-04 01:03 <DIR> d-------- E:\WINDOWS\ServicePackFiles
2008-09-04 01:01 . 2004-07-17 11:40 19,528 --a------ E:\WINDOWS\
002197_.tmp
2008-09-04 01:00 . 2004-08-03 22:43 15,872 --a------ E:\WINDOWS\system32\spupdsvc.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-03 22:52 558,142 ----a-w E:\WINDOWS\java\Packages\5JXFDR5Z.ZIP
2008-09-03 22:52 155,995 ----a-w E:\WINDOWS\java\Packages\DNZ7Z5VV.ZIP
2008-09-03 22:52 --------- d-----w E:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((( snapshot@2008-09-04_13.27.59.15 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-09-04 14:09:57 26,624 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\d1ccc7cbc4e442439a5673fa182ebe14\Accessibility.ni.dll
+ 2008-09-04 14:10:04 860,160 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\8af1e39c53e0114b8d8bee960865169c\AspNetMMCExt.ni.dll
+ 2008-09-04 14:10:05 237,568 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\44bb3517b6193b47b20d477ef3929b62\CustomMarshalers.ni.dll
+ 2008-09-04 14:10:05 15,360 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\dfsvc\4d364c9dbfc3684f8be8f22480a73438\dfsvc.ni.exe
+ 2008-09-04 14:10:11 880,640 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\6c6e8bec76ea6a4f81548cdd7696dc13\Microsoft.Build.Engine.ni.dll
+ 2008-09-04 14:10:12 81,920 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\ca1c429664d53f42b2af00c42a80030b\Microsoft.Build.Framework.ni.dll
+ 2008-09-04 14:23:01 1,691,648 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\ae8c1cd441de144394649370c69115b7\Microsoft.Build.Tasks.ni.dll
+ 2008-09-04 14:23:02 163,840 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\
01a4126a0cbb5041b55ca1679498ec81\Microsoft.Build.Utilities.ni.dll
+ 2008-09-04 14:23:06 1,724,416 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\c57081acfcdfd34581c1f34bda759ee2\Microsoft.VisualBasic.ni.dll
+ 2008-09-04 14:23:08 962,560 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\69d6cd1455dbcc44a081d108e2798abb\System.Configuration.ni.dll
+ 2008-09-04 14:23:10 1,712,128 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment\9a6d82fac4ff3742ae6b327ae77c31d4\System.Deployment.ni.dll
+ 2008-09-04 14:23:13 512,000 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\
04edfcf86bf9a84c8f60cc0886f9f72b\System.DirectoryServices.Protocols.ni.dll
+ 2008-09-04 14:23:12 1,220,608 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\e73515ce7fd2ce438c014a89940e8a51\System.DirectoryServices.ni.dll
+ 2008-09-04 14:23:15 659,456 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\33550cf915c02c48a10d3a6521adf1f1\System.EnterpriseServices.ni.dll
+ 2008-09-04 14:23:15 294,912 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\33550cf915c02c48a10d3a6521adf1f1\System.EnterpriseServices.Wrapper.dll
+ 2008-09-04 14:23:16 729,088 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\cc4cda6f43cf624d867998c0c81e2a0a\System.Security.ni.dll
+ 2008-09-04 14:23:18 684,032 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\3c1e1627eb5b9f4fb5f89f45a3e41585\System.Transactions.ni.dll
+ 2008-09-04 14:23:46 2,310,144 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\454715277a3b364b9ddf36a6f7574b31\System.Web.Mobile.ni.dll
+ 2008-09-04 14:23:47 237,568 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\a4025d8657522f46b1e7cd6c917eeaa3\System.Web.RegularExpressions.ni.dll
+ 2008-09-04 14:23:50 1,945,600 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\3a49f459ad60924da0bb70c73a5acde0\System.Web.Services.ni.dll
+ 2008-09-04 14:23:40 11,808,768 ----a-w E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\
032f6c21f7ec4644b7593c95a46c3b71\System.Web.ni.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"F:\\ccsetup211.exe"=
"E:\\Program Files\\TC UP\\TOTALCMD.EXE"=
"E:\\Program Files\\TC UP\\Plugins\\Media\\Hasla\\hasla.exe"=
"E:\\Program Files\\HJK\\HijackThis.exe"=
"E:\\Documents and Settings\\Drum\\Asztal\\mbr.exe"=
"E:\\Documents and Settings\\Drum\\Asztal\\ComboFix.exe"=
"E:\\WINDOWS\\system32\\CF30463.exe"=
R1 VD_FileDisk;VD_FileDisk;E:\WINDOWS\system32\drivers\VD_FileDisk.sys [2006-01-13 15872]
R2 VMCService;Vodafone Mobile Connect Service;E:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [2008-05-28 14336]
R3 dac970nt;dac970nt;E:\WINDOWS\system32\drivers\rkghon.sys [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f91bba4-7a0e-11dd-a157-fe610eb61a35}]
\Shell\AutoRun\command - I:\setup_vmc_lite.exe /checkApplicationPresence
.
.
------- Supplementary Scan -------
.
O16 -: DirectAnimation Java Classes -
file://E:\WINDOWS\Java\classes\dajava.cab
E:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java -
file://E:\WINDOWS\Java\classes\xmldso.cab
E:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-04 16:35:37
Windows 5.1.2600 Szervizcsomag 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\.NET CLR Data]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\.NET CLR Networking]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\.NET Data Provider for Oracle]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\.NET Data Provider for SqlServer]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\.NETFramework]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Abiosdsk]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\abp480n5]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ACPI]
"ImagePath"="System32\DRIVERS\ACPI.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ACPIEC]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\adpu160m]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\aec]
"ImagePath"="system32\drivers\aec.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\AFD]
"ImagePath"="\SystemRoot\System32\drivers\afd.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Aha154x]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\aic78u2]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\aic78xx]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Alerter]
"ServiceDll"="%SystemRoot%\system32\alrsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ALG]
"ImagePath"="%SystemRoot%\System32\alg.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\AliIde]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\AmdK7]
"ImagePath"="System32\DRIVERS\amdk7.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\amsint]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\AppMgmt]
"ServiceDll"="%SystemRoot%\System32\appmgmts.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\asc]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\asc3350p]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\asc3550]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ASP.NET]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ASP.NET_2.0.50727]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\aspnet_state]
"ImagePath"="%SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\AsyncMac]
"ImagePath"="system32\DRIVERS\asyncmac.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\atapi]
"ImagePath"="System32\DRIVERS\atapi.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Atdisk]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Atmarpc]
"ImagePath"="System32\DRIVERS\atmarpc.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\AudioSrv]
"ServiceDll"="%SystemRoot%\System32\audiosrv.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\audstub]
"ImagePath"="System32\DRIVERS\audstub.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\BattC]
"MofImagePath"="System32\Drivers\battc.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Beep]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\BITS]
"ServiceDll"="%systemroot%\system32\qmgr.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Browser]
"ServiceDll"="%SystemRoot%\System32\browser.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\catchme]
"ImagePath"="\??\E:\ComboFix\catchme.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\cbidf2k]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\cd20xrnt]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Cdaudio]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Cdfs]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Cdrom]
"ImagePath"="System32\DRIVERS\cdrom.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Changer]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\CiSvc]
"ImagePath"="%SystemRoot%\system32\cisvc.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ClipSrv]
"ImagePath"="%SystemRoot%\system32\clipsrv.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\clr_optimization_v2.0.50727_32]
"ImagePath"="E:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\CmdIde]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\COMSysApp]
"ImagePath"="E:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ContentFilter]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ContentIndex]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Cpqarray]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\CryptSvc]
"ServiceDll"="%SystemRoot%\System32\cryptsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\dac2w2k]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\dac960nt]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\dac970nt]
"ImagePath"="\??\E:\WINDOWS\system32\drivers\rkghon.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\DcomLaunch]
"ServiceDll"="%SystemRoot%\system32\rpcss.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Dhcp]
"ServiceDll"="%SystemRoot%\System32\dhcpcsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Disk]
"ImagePath"="System32\DRIVERS\disk.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\dmadmin]
"ImagePath"="%SystemRoot%\System32\dmadmin.exe /com"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\dmboot]
"ImagePath"="System32\drivers\dmboot.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\dmio]
"ImagePath"="System32\drivers\dmio.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\dmload]
"ImagePath"="System32\drivers\dmload.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\dmserver]
"ServiceDll"="%SystemRoot%\System32\dmserver.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\DMusic]
"ImagePath"="system32\drivers\DMusic.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Dnscache]
"ServiceDll"="%SystemRoot%\System32\dnsrslvr.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\dpti2o]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\drmkaud]
"ImagePath"="system32\drivers\drmkaud.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\eamon]
"ImagePath"="system32\DRIVERS\eamon.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\easdrv]
"ImagePath"="system32\DRIVERS\easdrv.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\EhttpSrv]
"ImagePath"="\"E:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe\""
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ekrn]
"ImagePath"="\"E:\Program Files\ESET\ESET Smart Security\ekrn.exe\""
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\epfw]
"ImagePath"="system32\DRIVERS\epfw.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Epfwndis]
"ImagePath"="system32\DRIVERS\Epfwndis.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\epfwtdi]
"ImagePath"="system32\DRIVERS\epfwtdi.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ERSvc]
"ServiceDll"="%SystemRoot%\System32\ersvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Eventlog]
"ImagePath"="%SystemRoot%\system32\services.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\EventSystem]
"ServiceDll"="E:\WINDOWS\System32\es.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Fastfat]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\FastUserSwitchingCompatibility]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Fdc]
"ImagePath"="System32\DRIVERS\fdc.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Fips]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Flpydisk]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\FltMgr]
"ImagePath"="system32\drivers\fltmgr.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Fs_Rec]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Ftdisk]
"ImagePath"="System32\DRIVERS\ftdisk.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\gameenum]
"ImagePath"="System32\DRIVERS\gameenum.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Gpc]
"ImagePath"="System32\DRIVERS\msgpc.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\helpsvc]
"ServiceDll"="%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\HidServ]
"ServiceDll"="%SystemRoot%\System32\hidserv.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\hidusb]
"ImagePath"="System32\DRIVERS\hidusb.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\hpn]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\HTTP]
"ImagePath"="System32\Drivers\HTTP.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\HTTPFilter]
"ServiceDll"="%SystemRoot%\System32\w3ssl.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\i2omgmt]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\i2omp]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\i8042prt]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Imapi]
"ImagePath"="System32\DRIVERS\imapi.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ImapiService]
"ImagePath"="%systemroot%\system32\imapi.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\inetaccs]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ini910u]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Inport]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\IntelIde]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ip6fw]
"ImagePath"="system32\drivers\ip6fw.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\IpFilterDriver]
"ImagePath"="System32\DRIVERS\ipfltdrv.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\IpInIp]
"ImagePath"="System32\DRIVERS\ipinip.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\IpNat]
"ImagePath"="System32\DRIVERS\ipnat.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\IPSec]
"ImagePath"="System32\DRIVERS\ipsec.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\IRENUM]
"ImagePath"="System32\DRIVERS\irenum.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ISAPISearch]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\isapnp]
"ImagePath"="System32\DRIVERS\isapnp.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Kbdclass]
"ImagePath"="System32\DRIVERS\kbdclass.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\kbdhid]
"ImagePath"="System32\DRIVERS\kbdhid.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\kmixer]
"ImagePath"="system32\drivers\kmixer.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\KSecDD]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\lanmanserver]
"ServiceDll"="%SystemRoot%\System32\srvsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\lanmanworkstation]
"ServiceDll"="%SystemRoot%\System32\wkssvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\lbrtfdc]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ldap]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\LicenseService]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\LmHosts]
"ServiceDll"="%SystemRoot%\System32\lmhsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mbr]
"ImagePath"="\??\E:\DOCUME~1\Drum\LOCALS~1\Temp\mbr.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Messenger]
"ServiceDll"="%SystemRoot%\System32\msgsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mnmdd]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mnmsrvc]
"ImagePath"="E:\WINDOWS\System32\mnmsrvc.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Modem]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Mouclass]
"ImagePath"="System32\DRIVERS\mouclass.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mouhid]
"ImagePath"="System32\DRIVERS\mouhid.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MountMgr]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mraid35x]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MRxDAV]
"ImagePath"="System32\DRIVERS\mrxdav.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MRxSmb]
"ImagePath"="System32\DRIVERS\mrxsmb.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MSDTC]
"ImagePath"="E:\WINDOWS\System32\msdtc.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Msfs]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MSIServer]
"ImagePath"="%systemroot%\system32\msiexec.exe /V"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MSKSSRV]
"ImagePath"="system32\drivers\MSKSSRV.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MSPCLOCK]
"ImagePath"="system32\drivers\MSPCLOCK.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MSPQM]
"ImagePath"="system32\drivers\MSPQM.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mssmbios]
"ImagePath"="System32\DRIVERS\mssmbios.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ms_mpu401]
"ImagePath"="system32\drivers\msmpu401.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Mup]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\NDIS]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\NdisTapi]
"ImagePath"="System32\DRIVERS\ndistapi.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Ndisuio]
"ImagePath"="System32\DRIVERS\ndisuio.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\NdisWan]
"ImagePath"="System32\DRIVERS\ndiswan.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\NDProxy]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\NetBIOS]
"ImagePath"="System32\DRIVERS\netbios.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\NetBT]
"ImagePath"="System32\DRIVERS\netbt.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\NetDDE]
"ImagePath"="%SystemRoot%\system32\netdde.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\NetDDEdsdm]
"ImagePath"="%SystemRoot%\system32\netdde.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Netlogon]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Netman]
"ServiceDll"="%SystemRoot%\System32\netman.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Nla]
"ServiceDll"="%SystemRoot%\System32\mswsock.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Npfs]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Ntfs]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\NtLmSsp]
"ImagePath"="%SystemRoot%\System32\lsass.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\NtmsSvc]
"ServiceDll"="%SystemRoot%\system32\ntmssvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Null]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\nv]
"ImagePath"="System32\DRIVERS\nv4_mini.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\NwlnkFlt]
"ImagePath"="System32\DRIVERS\nwlnkflt.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\NwlnkFwd]
"ImagePath"="System32\DRIVERS\nwlnkfwd.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Parport]
"ImagePath"="System32\DRIVERS\parport.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PartMgr]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ParVdm]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PCI]
"ImagePath"="System32\DRIVERS\pci.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PCIDump]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PCIIde]
"ImagePath"="System32\DRIVERS\pciide.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Pcmcia]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PDCOMP]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PDFRAME]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PDRELI]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PDRFRAME]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\perc2]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\perc2hib]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PerfDisk]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PerfNet]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PerfOS]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PerfProc]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PlugPlay]
"ImagePath"="%SystemRoot%\system32\services.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PolicyAgent]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PptpMiniport]
"ImagePath"="System32\DRIVERS\raspptp.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Processor]
"ImagePath"="System32\DRIVERS\processr.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ProtectedStorage]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PSched]
"ImagePath"="System32\DRIVERS\psched.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Ptilink]
"ImagePath"="System32\DRIVERS\ptilink.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ql1080]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Ql10wnt]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ql12160]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ql1240]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ql1280]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\RasAcd]
"ImagePath"="System32\DRIVERS\rasacd.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\RasAuto]
"ServiceDll"="%SystemRoot%\System32\rasauto.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Rasl2tp]
"ImagePath"="System32\DRIVERS\rasl2tp.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\RasMan]
"ServiceDll"="%SystemRoot%\System32\rasmans.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\RasPppoe]
"ImagePath"="System32\DRIVERS\raspppoe.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Raspti]
"ImagePath"="System32\DRIVERS\raspti.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Rdbss]
"ImagePath"="System32\DRIVERS\rdbss.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\RDPCDD]
"ImagePath"="System32\DRIVERS\RDPCDD.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\RDPDD]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\rdpdr]
"ImagePath"="System32\DRIVERS\rdpdr.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\RDPNP]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\RDPWD]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\RDSessMgr]
"ImagePath"="E:\WINDOWS\system32\sessmgr.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\redbook]
"ImagePath"="System32\DRIVERS\redbook.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\RemoteAccess]
"ServiceDll"="%SystemRoot%\System32\mprdim.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\RemoteRegistry]
"ServiceDll"="%SystemRoot%\system32\regsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\RpcLocator]
"ImagePath"="%SystemRoot%\System32\locator.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\RpcSs]
"ServiceDll"="%SystemRoot%\System32\rpcss.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\RSVP]
"ImagePath"="%SystemRoot%\System32\rsvp.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\SamSs]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\SCardSvr]
"ImagePath"="%SystemRoot%\System32\SCardSvr.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Schedule]
"ServiceDll"="%SystemRoot%\system32\schedsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ScsiPort]
"ImagePath"="%SystemRoot%\system32\drivers\scsiport.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Secdrv]
"ImagePath"="System32\DRIVERS\secdrv.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\seclogon]
"ServiceDll"="%SystemRoot%\System32\seclogon.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\SENS]
"ServiceDll"="%SystemRoot%\system32\sens.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\serenum]
"ImagePath"="System32\DRIVERS\serenum.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Serial]
"ImagePath"="System32\DRIVERS\serial.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Sfloppy]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\SharedAccess]
"ServiceDll"="%SystemRoot%\System32\ipnathlp.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ShellHWDetection]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Simbad]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Sparrow]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\splitter]
"ImagePath"="system32\drivers\splitter.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Spooler]
"ImagePath"="%SystemRoot%\system32\spoolsv.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\sr]
"ImagePath"="system32\DRIVERS\sr.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\srservice]
"ServiceDll"="E:\WINDOWS\System32\srsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Srv]
"ImagePath"="System32\DRIVERS\srv.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\SSDPSRV]
"ServiceDll"="%SystemRoot%\System32\ssdpsrv.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\stisvc]
"ServiceDll"="%SystemRoot%\system32\wiaservc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\swenum]
"ImagePath"="System32\DRIVERS\swenum.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\swmidi]
"ImagePath"="system32\drivers\swmidi.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\SwPrv]
"ImagePath"="E:\WINDOWS\System32\dllhost.exe /Processid:{5DFC26F6-83FC-42F3-8FA7-64439BEDDCC9}"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\swwd]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\symc810]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\symc8xx]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\sym_hi]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\sym_u3]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\sysaudio]
"ImagePath"="system32\drivers\sysaudio.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\SysmonLog]
"ImagePath"="%SystemRoot%\system32\smlogsvc.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\TapiSrv]
"ServiceDll"="%SystemRoot%\System32\tapisrv.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Tcpip]
"ImagePath"="System32\DRIVERS\tcpip.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\TDPIPE]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\TDTCP]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\TermDD]
"ImagePath"="System32\DRIVERS\termdd.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\TermService]
"ServiceDll"="%SystemRoot%\System32\termsrv.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Themes]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\TlntSvr]
"ImagePath"="E:\WINDOWS\System32\tlntsvr.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\TosIde]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\TrkWks]
"ServiceDll"="%SystemRoot%\system32\trkwks.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\TSDDD]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Udfs]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ultra]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Update]
"ImagePath"="System32\DRIVERS\update.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\upnphost]
"ServiceDll"="%SystemRoot%\System32\upnphost.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\UPS]
"ImagePath"="%SystemRoot%\System32\ups.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\usbccgp]
"ImagePath"="System32\DRIVERS\usbccgp.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\usbehci]
"ImagePath"="System32\DRIVERS\usbehci.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\usbhub]
"ImagePath"="System32\DRIVERS\usbhub.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\usbohci]
"ImagePath"="System32\DRIVERS\usbohci.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\USBSTOR]
"ImagePath"="system32\DRIVERS\USBSTOR.SYS"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\VD_FileDisk]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\VgaSave]
"ImagePath"="\SystemRoot\System32\drivers\vga.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\ViaIde]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\VMCService]
"ImagePath"="\"E:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe\""
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\VolSnap]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\VSS]
"ImagePath"="%SystemRoot%\System32\vssvc.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\W32Time]
"ServiceDll"="%systemroot%\system32\w32time.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\W3SVC]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Wanarp]
"ImagePath"="System32\DRIVERS\wanarp.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\WDICA]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\wdmaud]
"ImagePath"="system32\drivers\wdmaud.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\WebClient]
"ServiceDll"="%SystemRoot%\System32\webclnt.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\winmgmt]
"ServiceDll"="%SystemRoot%\system32\wbem\WMIsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Winsock]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\WinSock2]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\WinTrust]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\WmdmPmSN]
"ServiceDll"="E:\WINDOWS\System32\mspmsnsv.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Wmi]
"ServiceDll"="%SystemRoot%\System32\advapi32.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\WmiApRpl]
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\WmiApSrv]
"ImagePath"="E:\WINDOWS\System32\wbem\wmiapsrv.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\wscsvc]
"ServiceDll"="%SYSTEMROOT%\system32\wscsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\wuauserv]
"ServiceDll"="E:\WINDOWS\System32\wuauserv.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\WZCSVC]
"ServiceDll"="%SystemRoot%\System32\wzcsvc.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\xmlprov]
"ServiceDll"="%SystemRoot%\System32\xmlprov.dll"
.
Completion time: 2008-09-04 16:37:49
ComboFix-quarantined-files.txt 2008-09-04 14:37:44
ComboFix2.txt 2008-09-04 11:28:57
Pre-Run: 15,741,431,808 bájt szabad
Post-Run: 15,744,516,096 bájt szabad
589
keresés közben hibaüzenet vagy 15-szer: "az adatbázis szerkesztését a rendszergazda letiltotta"