ComboFix 10-05-03.03 - Travis Kenyon 05/04/2010 0:17.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.596 [GMT -5:00]
Running from: c:\documents and settings\Travis Kenyon\My Documents\Downloads\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2010-04-04 to 2010-05-04 )))))))))))))))))))))))))))))))
.
2010-05-04 04:11 . 2010-05-04 04:11 388096 ----a-r- c:\documents and settings\Travis Kenyon\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-05-04 04:11 . 2010-05-04 04:11 -------- d-----w- c:\program files\Trend Micro
2010-05-04 01:01 . 2010-05-04 01:01 -------- d-----w- c:\program files\Lame for Audacity
2010-05-03 23:13 . 2010-05-03 23:13 -------- d-----w- c:\documents and settings\Travis Kenyon\Local Settings\Application Data\WMTools Downloaded Files
2010-05-03 21:09 . 2010-05-03 21:10 -------- d-----w- c:\documents and settings\Travis Kenyon\Local Settings\Application Data\NFS Underground 2
2010-05-03 21:07 . 2010-05-03 21:07 -------- d-----w- c:\program files\Common Files\EasyInfo
2010-05-03 20:57 . 2010-05-03 20:57 -------- d-----w- c:\program files\EA GAMES
2010-05-03 20:52 . 2010-05-03 20:52 -------- d-----w- c:\program files\Common Files\DirectX
2010-04-29 02:37 . 2008-02-14 21:21 180224 ----a-w- c:\documents and settings\Travis Kenyon\Application Data\Mozilla\Firefox\Profiles\6o8gvmob.default\extensions\{077a24e9-0db5-435f-9010-5261c53e5925}\plugins\npmabiwebframe.dll
2010-04-24 20:50 . 2010-05-04 03:00 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\Audacity
2010-04-24 20:43 . 2010-04-24 20:43 -------- d-----w- c:\program files\CONEXANT
2010-04-24 20:42 . 2003-11-17 20:59 212224 ----a-w- c:\windows\system32\drivers\HSFHWBS2.sys
2010-04-24 20:42 . 2003-11-17 20:58 680704 ----a-w- c:\windows\system32\drivers\HSF_CNXT.sys
2010-04-24 20:42 . 2003-11-17 20:56 1042432 ----a-w- c:\windows\system32\drivers\HSF_DP.sys
2010-04-24 20:42 . 2003-04-09 19:01 90112 ----a-w- c:\windows\system32\mdmxsdk.dll
2010-04-24 20:42 . 2003-04-09 18:48 11043 ----a-w- c:\windows\system32\drivers\mdmxsdk.sys
2010-04-24 20:42 . 2010-04-24 20:42 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\ATI
2010-04-24 20:38 . 2010-04-24 20:38 10134 ----a-r- c:\documents and settings\Travis Kenyon\Application Data\Microsoft\Installer\{F16DCA31-4DB4-F8F6-5ED1-6FAFB7228FFF}\ARPPRODUCTICON.exe
2010-04-24 20:19 . 2010-04-24 20:19 53248 ----a-r- c:\documents and settings\Travis Kenyon\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2010-04-24 20:18 . 2010-04-24 20:18 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2010-04-24 20:17 . 2010-04-24 20:19 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\LogiShrd
2010-04-24 20:12 . 2010-04-24 20:19 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\Logitech
2010-04-24 20:12 . 2010-04-24 20:13 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\Logishrd
2010-04-24 19:55 . 2010-04-24 19:55 -------- d-----w- c:\program files\Activision
2010-04-24 18:45 . 2010-04-24 18:45 697328 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-04-24 18:45 . 2010-05-03 20:46 -------- d-----w- c:\program files\DAEMON Tools Pro
2010-04-24 18:45 . 2010-05-03 20:47 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\DAEMON Tools Pro
2010-04-24 18:45 . 2010-05-03 20:47 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\DAEMON Tools Pro
2010-04-06 20:12 . 2010-04-06 20:12 119808 ----a-w- c:\documents and settings\Travis Kenyon\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com\components\FFTextLinks.dll
2010-04-06 02:59 . 2010-04-06 02:59 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\Broad Intelligence
2010-04-06 02:59 . 2010-04-06 02:59 -------- d-----w- c:\program files\MediaCoder Audio Edition
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-04 05:15 . 2010-03-23 08:58 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\uTorrent
2010-05-04 04:03 . 2010-03-29 02:31 -------- d-----w- c:\program files\HyperCam Toolbar
2010-05-03 17:39 . 2010-02-14 21:34 -------- d-----w- c:\program files\uTorrent
2010-05-02 21:17 . 2010-03-11 00:35 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-05-02 21:17 . 2010-03-11 00:34 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2010-05-02 05:59 . 2009-02-24 04:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-02 05:59 . 2010-04-02 05:06 6153352 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-05-02 05:57 . 2009-08-31 03:23 -------- d-----w- c:\program files\Replay Media Catcher
2010-05-02 05:40 . 2010-03-23 08:48 237568 ----a-w- c:\windows\system32\rmc_rtspdl.dll
2010-05-02 05:40 . 2010-03-23 08:48 156672 ----a-w- c:\windows\system32\rmc_fixasf.exe
2010-05-02 05:40 . 2010-03-23 09:01 323584 ----a-w- c:\windows\system32\AUDIOGENIE2.DLL
2010-05-01 00:34 . 2010-04-01 22:26 41 ----a-w- c:\documents and settings\Travis Kenyon\jagex_runescape_preferences.dat
2010-05-01 00:34 . 2010-04-01 22:28 75 ----a-w- c:\documents and settings\Travis Kenyon\jagex_runescape_preferences2.dat
2010-04-29 20:39 . 2010-03-07 08:49 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 20:39 . 2010-03-07 08:49 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-28 23:45 . 2010-03-17 02:33 -------- d-----w- c:\program files\Sandboxie
2010-04-25 15:27 . 2010-03-11 00:15 -------- d-----w- c:\program files\ATI
2010-04-24 20:50 . 2009-02-24 23:49 -------- d-----w- c:\program files\Audacity 1.3 Beta (Unicode)
2010-04-24 20:39 . 2010-03-07 09:27 -------- d-----w- c:\program files\ATI Technologies
2010-04-24 20:19 . 2010-01-09 21:09 -------- d-----w- c:\program files\Common Files\LogiShrd
2010-04-24 20:18 . 2010-01-09 21:08 -------- d-----w- c:\program files\Logitech
2010-04-24 20:16 . 2009-02-22 20:03 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-04-13 23:40 . 2009-06-17 22:10 -------- d-----w- c:\program files\SpeedFan
2010-04-01 22:28 . 2010-04-01 22:28 0 ----a-w- c:\documents and settings\Travis Kenyon\jagex__preferences3.dat
2010-03-30 20:29 . 2010-03-30 20:29 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-03-30 20:29 . 2010-03-30 20:29 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_nielprt_01007.Wdf
2010-03-30 20:25 . 2010-03-30 20:25 -------- d-----w- c:\program files\NetRatingsNetSight
2010-03-29 21:16 . 2010-03-24 00:17 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\Vso
2010-03-29 06:17 . 2010-03-29 06:17 3774 ----a-r- c:\documents and settings\Travis Kenyon\Application Data\Microsoft\Installer\{DB939A96-0B1A-4588-91E9-2133236D1E8B}\_CF12D5CBF38FEF7C0C142A.exe
2010-03-29 06:17 . 2010-03-29 06:17 3774 ----a-r- c:\documents and settings\Travis Kenyon\Application Data\Microsoft\Installer\{DB939A96-0B1A-4588-91E9-2133236D1E8B}\_2C07D269DB1C9A6B21A80F.exe
2010-03-29 06:17 . 2010-03-29 06:17 10134 ----a-r- c:\documents and settings\Travis Kenyon\Application Data\Microsoft\Installer\{DB939A96-0B1A-4588-91E9-2133236D1E8B}\_3E2FFC67266DB5651EAE44.exe
2010-03-29 06:17 . 2010-03-29 06:17 -------- d-----w- c:\program files\ppr
2010-03-29 02:31 . 2010-03-29 02:31 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\Toolbar4
2010-03-29 02:31 . 2010-02-02 22:12 -------- d-----w- c:\program files\HyCam2
2010-03-28 05:45 . 2010-03-28 05:45 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\Publish Providers
2010-03-28 05:45 . 2010-03-28 05:16 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\Sony
2010-03-28 05:31 . 2010-03-28 05:31 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Sony
2010-03-28 05:15 . 2009-03-08 23:57 -------- d-----w- c:\program files\Sony
2010-03-27 16:48 . 2010-03-27 09:48 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\DivX
2010-03-27 09:49 . 2010-03-27 09:44 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX
2010-03-27 09:47 . 2010-03-27 09:47 56969 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-03-27 09:45 . 2010-03-27 09:48 754984 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Setup\Resource.dll
2010-03-27 09:44 . 2010-03-27 09:48 986904 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Setup\DivXSetup.exe
2010-03-26 21:42 . 2009-02-25 11:13 -------- d-----w- c:\program files\CCleaner
2010-03-24 01:30 . 2010-03-24 01:30 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\vsosdk
2010-03-24 00:23 . 2010-03-24 00:17 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-03-24 00:23 . 2010-03-24 00:17 47360 ----a-w- c:\documents and settings\Travis Kenyon\Application Data\pcouffin.sys
2010-03-24 00:23 . 2010-03-24 00:17 47360 ----a-w- c:\documents and settings\Travis Kenyon\Application Data\pcouffin.sys
2010-03-24 00:23 . 2010-02-15 04:08 -------- d-----w- c:\program files\VSO
2010-03-23 10:49 . 2009-02-26 03:21 -------- d-----w- c:\program files\AVS4YOU
2010-03-23 10:49 . 2009-02-26 03:22 -------- d-----w- c:\program files\Common Files\AVSMedia
2010-03-23 10:17 . 2010-03-23 10:17 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\AVS4YOU
2010-03-23 10:17 . 2010-03-23 10:14 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\AVS4YOU
2010-03-23 08:48 . 2010-03-23 08:48 -------- d-----w- c:\program files\Applian Director
2010-03-11 00:36 . 2010-03-11 00:36 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\Leadertech
2010-03-11 00:29 . 2010-03-11 00:29 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2010-03-11 00:29 . 2010-03-11 00:29 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2010-03-11 00:29 . 2010-03-11 00:29 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-03-11 00:27 . 2009-02-24 03:38 -------- d-----w- c:\program files\Intel
2010-03-10 23:39 . 2010-03-10 23:39 -------- d-----w- c:\program files\Driver-Soft
2010-03-10 21:31 . 2010-03-10 21:31 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY\Application Data\McAfee
2010-03-10 06:15 . 2004-08-04 10:00 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-08 23:23 . 2010-03-08 23:17 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\GetRightToGo
2010-03-08 23:19 . 2010-03-08 23:19 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\PC Drivers HeadQuarters Inc
2010-03-08 17:59 . 2010-03-08 17:59 94208 ----a-w- c:\windows\system32\dpl100.dll
2010-03-07 17:15 . 2010-03-07 03:01 13104 ----a-w- c:\documents and settings\Travis Kenyon\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-07 10:39 . 2010-03-07 10:39 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\RoboForm
2010-03-07 09:35 . 2010-03-07 09:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\NexonUS
2010-03-07 09:34 . 2010-03-07 09:34 0 ----a-w- c:\windows\ativpsrm.bin
2010-03-07 09:30 . 2010-03-07 09:30 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\ATI
2010-03-07 09:27 . 2009-02-22 20:02 -------- d-----w- c:\program files\Common Files\InstallShield
2010-03-07 09:21 . 2010-03-07 08:38 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-03-07 09:20 . 2010-03-07 09:20 98304 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\NexonUS\NGM\npNxGameUS.dll
2010-03-07 09:20 . 2010-03-07 09:20 765952 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\NexonUS\NGM\NGMDll.dll
2010-03-07 09:20 . 2010-03-07 09:20 401408 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\NexonUS\NGM\NGMResource.dll
2010-03-07 09:20 . 2010-03-07 09:20 258352 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\NexonUS\NGM\unicows.dll
2010-03-07 09:20 . 2010-03-07 09:20 172032 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\NexonUS\NGM\NGM.exe
2010-03-07 09:20 . 2010-03-07 09:20 126976 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\NexonUS\NGM\nxgameus.dll
2010-03-07 09:01 . 2010-03-07 08:00 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\NOS
2010-03-07 08:49 . 2010-03-07 08:49 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\Malwarebytes
2010-03-07 08:49 . 2010-03-07 08:49 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2010-03-07 08:47 . 2010-03-07 08:35 -------- d-----w- c:\documents and settings\Travis Kenyon\Application Data\Systweak
2010-03-07 08:44 . 2010-03-07 08:44 1955472 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2010-03-07 08:38 . 2010-03-07 08:38 503808 ----a-w- c:\documents and settings\Travis Kenyon\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2bab434a-n\msvcp71.dll
2010-03-07 08:38 . 2010-03-07 08:38 499712 ----a-w- c:\documents and settings\Travis Kenyon\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2bab434a-n\jmc.dll
2010-03-07 08:38 . 2010-03-07 08:38 348160 ----a-w- c:\documents and settings\Travis Kenyon\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2bab434a-n\msvcr71.dll
2010-03-07 08:38 . 2010-03-07 08:38 61440 ----a-w- c:\documents and settings\Travis Kenyon\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-2bedfe8b-n\decora-sse.dll
2010-03-07 08:38 . 2010-03-07 08:38 12800 ----a-w- c:\documents and settings\Travis Kenyon\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-2bedfe8b-n\decora-d3d.dll
2010-03-07 08:38 . 2010-03-07 08:38 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-07 08:29 . 2010-03-07 08:29 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\PC Drivers HeadQuarters
2010-03-07 08:21 . 2010-03-07 08:21 1923768 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2010-03-07 08:17 . 2009-08-25 20:30 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-07 08:14 . 2010-03-07 08:14 38784 ----a-w- c:\documents and settings\Travis Kenyon\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-03-07 08:14 . 2010-03-07 08:14 38784 ----a-w- c:\documents and settings\Default User.WINDOWS\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-03-07 08:14 . 2010-03-07 08:00 15849560 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\NOS\Adobe_Downloads\selfextractor_air_1.5.3.exe
2010-03-07 08:01 . 2010-03-07 08:01 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\McAfee
2010-03-07 08:00 . 2010-03-07 08:00 86016 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\NOS\Adobe_Downloads\arh.exe
2010-03-07 07:37 . 2010-03-07 07:37 0 ----a-w- c:\windows\nsreg.dat
2010-03-07 07:00 . 2010-03-07 06:59 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\PMB Files
2010-03-07 06:31 . 2010-03-07 01:13 87263 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
.
Code:
<pre>
c:\program files\Java\jre6\bin\jusched .exe
c:\program files\Malwarebytes' Anti-Malware\iyt .exe
c:\program files\Pando Networks\Media Booster\pmb .exe
c:\program files\Siber Systems\AI RoboForm\robotaskbaricon .exe
c:\program files\Unlocker\unlockerassistant .exe
</pre>
((((((((((((((((((((((((((((( SnapShot@2010-05-04_04.05.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-05-04 05:17 . 2010-05-04 05:17 16384 c:\windows\Temp\Perflib_Perfdata_e8.dat
+ 2010-03-13 04:06 . 2010-05-04 05:17 203574 c:\windows\system32\inetsrv\MetaBase.bin
+ 2010-05-04 04:11 . 2010-05-04 04:11 1094656 c:\windows\Installer\60e5d.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2010-03-07 2937528]
"Logitech Vid"="c:\program files\Logitech\Logitech Vid\Vid.exe" [2010-02-13 5933912]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-05-03 321328]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2010-04-18 160328]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2010-04-17 394984]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"MsmqIntCert"="mqrt.dll" [2008-04-14 177152]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-03-05 1135912]
"RTHDCPL"="RTHDCPL.EXE" [2010-02-22 18791456]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-01-27 1312848]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-03-03 98304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-01-29 21:17 64592 ----a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users.WINDOWS\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58620:TCP"= 58620:TCP
ando Media Booster
"58620:UDP"= 58620:UDP
ando Media Booster
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [3/10/2010 7:29 PM 10384]
S0 nielprt;Nielsen Patch Service;c:\windows\system32\DRIVERS\nielprt.sys --> c:\windows\system32\DRIVERS\nielprt.sys [?]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4/24/2010 1:45 PM 697328]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [3/7/2010 4:00 AM 1691480]
S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys --> c:\windows\system32\drivers\nielgfx.sys [?]
.
.