G25r8cer
Active Member
It seems I am still having issues with my pc. The cpu usage is often climbing to 100% and stays there for a bit and my system slows to a hault and then cpu usage dies down to normal. My only guess is that im still infected. Heres a combofix log for you guys. Much help is needed and appreciated. Srry guys I thought I was done here but i guess not. I am willing to do whatever it takes to get rid of it besides reformatting.
ComboFix 08-05-21.3 - Spicka 2008-05-25 22:00:17.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.631 [GMT -4:00]
Running from: C:\Users\Spicka\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-04-26 to 2008-05-26 )))))))))))))))))))))))))))))))
.
2008-05-25 00:16 . 2008-05-25 00:16 <DIR> d-------- C:\Users\Spicka\Roaming
2008-05-25 00:16 . 2008-05-25 00:16 <DIR> d-------- C:\Users\Spicka\AppData\Roaming\MySpace
2008-05-25 00:15 . 2008-05-25 00:15 <DIR> d-------- C:\Program Files\MySpace
2008-05-23 22:25 . 2008-05-23 22:27 <DIR> d-------- C:\Program Files\rFactorLexus
2008-05-22 18:59 . 2008-05-22 19:12 <DIR> d-------- C:\Program Files\rFactor
2008-05-21 19:37 . 2008-05-21 19:37 <DIR> d--h----- C:\Windows\PIF
2008-05-19 16:30 . 2008-05-19 16:30 <DIR> dr------- C:\Users\Public\Videos
2008-05-19 16:30 . 2008-05-22 20:15 <DIR> dr------- C:\Users\Public\Pictures
2008-05-18 12:14 . 2008-05-18 12:14 <DIR> dr------- C:\Users\Public\Documents
2008-05-17 21:38 . 2008-05-17 21:38 <DIR> dr------- C:\Users\Public\Music
2008-05-10 21:33 . 2008-05-10 21:33 <DIR> d-------- C:\Users\Spicka\AppData\Roaming\dvdcss
2008-05-10 18:49 . 2008-05-25 04:03 <DIR> d-------- C:\Program Files\DVDFab 5
2008-05-09 23:59 . 2008-05-09 23:59 <DIR> d-------- C:\Users\All Users\Codemasters
2008-05-09 23:59 . 2008-05-09 23:59 <DIR> d-------- C:\ProgramData\Codemasters
2008-05-09 23:57 . 2008-03-05 15:56 3,786,760 --a------ C:\Windows\System32\D3DX9_37.dll
2008-05-09 23:57 . 2008-03-05 15:56 1,420,824 --a------ C:\Windows\System32\D3DCompiler_37.dll
2008-05-09 23:57 . 2008-03-05 16:03 479,752 --a------ C:\Windows\System32\XAudio2_0.dll
2008-05-09 23:57 . 2008-02-05 23:07 462,864 --a------ C:\Windows\System32\d3dx10_37.dll
2008-05-09 23:57 . 2008-03-05 16:03 238,088 --a------ C:\Windows\System32\xactengine3_0.dll
2008-05-09 23:57 . 2008-03-05 16:00 25,608 --a------ C:\Windows\System32\X3DAudio1_3.dll
2008-05-09 19:19 . 2008-05-09 19:19 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-05-08 16:24 . 2008-05-08 16:25 <DIR> d-------- C:\Program Files\Clock Tray Skins
2008-05-07 21:28 . 2008-03-12 19:38 445,504 -ra------ C:\Windows\System32\vp6vfw.dll
2008-05-04 17:12 . 2008-05-04 17:13 <DIR> d-------- C:\Users\Spicka\AppData\Roaming\Off Road
2008-05-04 17:03 . 2008-05-04 17:03 <DIR> d-------- C:\Program Files\Xplosiv
2008-05-04 00:06 . 2008-05-04 00:06 <DIR> d-------- C:\Users\Spicka\AppData\Roaming\Ubisoft
2008-05-03 22:17 . 2008-05-03 22:17 <DIR> d-------- C:\Users\Spicka\AppData\Roaming\THQ
2008-05-03 22:13 . 2008-05-03 22:13 <DIR> d-------- C:\Users\All Users\InstallShield
2008-05-03 22:13 . 2008-05-03 22:13 <DIR> d-------- C:\ProgramData\InstallShield
2008-05-03 22:02 . 2006-05-16 10:58 73,728 --a------ C:\Windows\System32\ISUSPM.cpl
2008-05-03 11:57 . 2008-05-07 21:28 <DIR> d-------- C:\Program Files\EA GAMES
2008-05-01 20:04 . 2008-05-01 20:04 <DIR> d-------- C:\Program Files\Rockstar Games
2008-04-30 19:12 . 2008-04-30 19:12 319 --a------ C:\Windows\game.ini
2008-04-30 18:46 . 2008-04-30 18:46 <DIR> d-------- C:\Program Files\Activision
2008-04-30 17:32 . 2008-05-03 22:02 <DIR> d-------- C:\Program Files\THQ
2008-04-29 16:46 . 2008-04-29 16:46 <DIR> dr-h----- C:\Users\Spicka\AppData\Roaming\SecuROM
2008-04-29 16:46 . 2008-04-29 16:46 107,888 --a------ C:\Windows\System32\CmdLineExt.dll
2008-04-28 19:52 . 2008-05-03 00:46 <DIR> d-------- C:\Users\Spicka\AppData\Roaming\X-NetStat
2008-04-28 19:52 . 2008-04-28 19:52 <DIR> d-------- C:\Program Files\X-NetStat Professional
2008-04-28 17:00 . 2008-04-28 17:00 <DIR> d-------- C:\Program Files\AceLogix
2008-04-27 17:13 . 2008-05-19 15:14 <DIR> d-------- C:\Users\Spicka\AppData\Roaming\VMware
2008-04-27 17:08 . 2008-04-27 17:08 <DIR> d-------- C:\Program Files\VMware
2008-04-27 17:08 . 2008-04-27 17:08 <DIR> d-------- C:\Program Files\Common Files\VMware
2008-04-26 00:15 . 2008-04-26 00:15 <DIR> d-------- C:\Windows\System32\URTTEMP
2008-04-26 00:12 . 2008-04-26 00:12 <DIR> d-------- C:\Users\All Users\Media Center Programs
2008-04-26 00:12 . 2008-04-26 00:12 <DIR> d-------- C:\ProgramData\Media Center Programs
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-26 02:00 --------- d-----w C:\Users\Spicka\AppData\Roaming\uTorrent
2008-05-26 01:43 --------- d-----w C:\Users\Spicka\AppData\Roaming\Vso
2008-05-25 03:50 --------- d-----w C:\Program Files\Trillian
2008-05-24 15:57 --------- d---a-w C:\ProgramData\TEMP
2008-05-21 22:23 --------- d-----w C:\Users\Spicka\AppData\Roaming\Audacity
2008-05-19 18:00 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-05-19 17:56 --------- d-----w C:\ProgramData\Autodesk
2008-05-17 23:25 --------- d-----w C:\ProgramData\VMware
2008-05-17 02:49 --------- d-----w C:\Program Files\GPU-Z
2008-05-14 22:24 --------- d-----w C:\Program Files\Windows Mail
2008-05-10 03:57 444,952 ----a-w C:\Windows\System32\wrap_oal.dll
2008-05-10 03:57 109,080 ----a-w C:\Windows\System32\OpenAL32.dll
2008-05-10 03:49 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-10 03:49 --------- d-----w C:\Program Files\Codemasters
2008-05-08 15:00 --------- d-----w C:\Program Files\GTR2
2008-05-07 14:53 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-07 14:12 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-05-04 04:04 --------- d-----w C:\ProgramData\Ubisoft
2008-05-04 03:50 --------- d-----w C:\Program Files\Ubisoft
2008-05-02 00:17 --------- d-----w C:\Program Files\Microsoft Games
2008-04-29 00:29 --------- d-----w C:\ProgramData\Test Drive Unlimited
2008-04-27 03:53 --------- d-----w C:\Program Files\Grand Theft Auto San Andreas
2008-04-26 03:57 --------- d-----w C:\ProgramData\WindowsSearch
2008-04-26 03:46 --------- d-----w C:\Program Files\Electronic Arts
2008-04-23 00:41 --------- d-----w C:\Program Files\PowerISO
2008-04-22 19:37 --------- d-----w C:\Program Files\uTorrent
2008-04-21 20:02 --------- d-----w C:\Program Files\Atari
2008-04-21 00:21 --------- d-----w C:\Program Files\Easy Video Downloader
2008-04-15 22:48 --------- d-----w C:\Program Files\Fraps
2008-04-12 20:07 --------- d-----w C:\Program Files\VirtualDJ
2008-04-12 01:13 --------- d-----w C:\Program Files\DFX
2008-04-12 00:24 --------- d-----w C:\Users\Spicka\AppData\Roaming\Thinking Minds Budiling Bytes
2008-04-12 00:24 --------- d-----w C:\Program Files\CubeDesktop
2008-04-11 22:53 --------- d-----w C:\ProgramData\NVIDIA Corporation
2008-04-11 22:46 --------- d-----w C:\Program Files\Fast Explorer
2008-04-11 22:18 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-11 21:55 319,456 ----a-w C:\Windows\DIFxAPI.dll
2008-04-11 21:55 --------- d-----w C:\Program Files\Realtek
2008-04-11 02:04 --------- d-----w C:\ProgramData\Stardock
2008-04-11 01:38 --------- d-----w C:\Program Files\Foxit Software
2008-04-11 01:01 2,516 --sha-w C:\Windows\System32\KGyGaAvL.sys
2008-04-10 19:55 --------- d-----w C:\ProgramData\DFX
2008-04-10 19:54 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-10 18:19 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-04-10 06:22 --------- d-----w C:\Program Files\RocketDock
2008-04-10 03:18 --------- d-----w C:\Program Files\HyCam2
2008-04-10 01:03 --------- d-----w C:\Program Files\UltraISO
2008-04-10 01:02 --------- d-----w C:\Program Files\Common Files\EZB Systems
2008-04-07 03:07 --------- d-----w C:\ProgramData\vsosdk
2008-04-05 19:12 --------- d-----w C:\Program Files\Audacity 1.3 Beta (Unicode)
2008-04-05 00:45 47,360 ----a-w C:\Users\Spicka\AppData\Roaming\pcouffin.sys
2008-04-05 00:45 --------- d-----w C:\Program Files\VSO
2008-04-04 04:52 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-04 04:51 --------- d-----w C:\ProgramData\Messenger Plus!
2008-04-04 02:58 --------- d-----w C:\Program Files\RivaTuner v2.06
2008-03-31 23:15 --------- d-----w C:\Program Files\Rainbow Six Vegas
2008-03-30 23:00 --------- d-----w C:\Program Files\MagicISO
2008-03-29 21:03 --------- d-----w C:\ProgramData\Nero
2008-03-29 18:32 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
2008-03-29 16:19 716,272 ----a-w C:\Windows\system32\drivers\sptd.sys
2008-03-29 15:42 --------- d-----w C:\Program Files\Java
2008-03-29 15:41 --------- d-----w C:\Program Files\Common Files\Java
2008-03-29 15:29 --------- d-----w C:\ProgramData\SlySoft
2008-03-28 23:28 --------- d-----w C:\Program Files\Trojan Remover
2008-03-28 23:27 --------- d-----w C:\Users\Spicka\AppData\Roaming\Simply Super Software
2008-03-28 23:27 --------- d-----w C:\ProgramData\Simply Super Software
2008-03-28 20:59 --------- d-----w C:\Users\Spicka\AppData\Roaming\InstallShield
2008-03-27 23:03 --------- d-----w C:\ProgramData\FLEXnet
2008-03-27 22:14 --------- d-----w C:\Program Files\Image-Line
2008-03-27 22:12 --------- d-----w C:\Program Files\Steinberg
2008-03-26 23:41 --------- d-----w C:\ProgramData\Corel
2008-03-20 00:34 174 --sha-w C:\Program Files\desktop.ini
2008-03-20 00:11 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-03-20 00:11 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-03-04 22:30 98,304 ----a-w C:\Windows\system32CmdLineExt.dll
2008-02-29 07:14 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 07:11 988,216 ----a-w C:\Windows\System32\winload.exe
2008-02-29 07:11 927,288 ----a-w C:\Windows\System32\winresume.exe
2008-02-29 06:53 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll
2008-02-29 06:53 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:53 378,368 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 04:21 2,032,128 ----a-w C:\Windows\System32\win32k.sys
2008-02-29 04:12 318,464 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 04:12 14,848 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-11 01:22 0 ----a-w C:\Users\Spicka\AppData\Roaming\wklnhst.dat
2008-02-14 21:50 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-02-14 21:50 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-02-14 21:50 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 03:33 1233920]
"avast! service GUI component"="C:\Program Files\Alwil Software\Avast4\ashDisp.exe" [2008-03-29 14:37 79224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 17:16 65536]
"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 07:59 118784]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2008-01-09 15:23 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-01-09 15:23 8530464]
"RivaTunerStartupDaemon"="C:\Program Files\RivaTuner v2.06\RivaTuner.exe" [2007-10-30 14:05 2650112]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 19:27 9117696]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Gaming Software.lnk - C:\Windows\Installer\{C5961323-A2E5-4FAB-B92D-DBF6C282F0F5}\NewShortcut1_C5961323A2E54FABB92DDBF6C282F0F5.exe [2007-12-27 20:25:16 40960]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^RivaTuner.exe]
backup=C:\Windows\pss\RivaTuner.exe.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Spicka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
backup=C:\Windows\pss\MagicDisc.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Spicka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office Groove.lnk]
path=C:\Users\Spicka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office Groove.lnk
backup=C:\Windows\pss\Microsoft Office Groove.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD_Display]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\b44b5fc7]
C:\Users\Spicka\AppData\Local\Temp\iebemyiq.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cmds]
C:\Users\Spicka\AppData\Local\Temp\mllkh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dog about manager team]
--a------ 2008-01-06 15:13 114704 C:\ProgramData\META THIRD 4.l9q7bk
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
--a------ 2008-01-19 03:33 125952 C:\Windows\ehome\ehTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 01:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
--a------ 2007-04-18 11:01 65536 c:\hp\support\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jumpsafe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
--a------ 2006-12-08 17:16 65536 C:\HP\KBD\KbdStub.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MS Juan]
C:\Users\Spicka\AppData\Local\Temp\mlhuacox.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 12:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSServer]
C:\Users\Spicka\AppData\Local\Temp\gebay.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2008-01-09 15:23 8530464 C:\Windows\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2008-01-09 15:23 81920 C:\Windows\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
--a------ 2008-01-09 15:23 86016 C:\Windows\system32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeerGuardian]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2008-03-14 19:50 233472 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RivaTunerStartupDaemon]
--a------ 2007-10-30 14:05 2650112 C:\Program Files\RivaTuner v2.06\RivaTuner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
--a------ 2007-10-25 05:52 4702208 C:\Windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateReg]
--a------ 2007-09-25 02:11 54672 C:\Windows\system32\jureg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VMware hqtray]
--a------ 2007-10-08 09:26 55856 C:\Program Files\VMware\VMware Workstation\hqtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmware-tray]
--a------ 2007-10-08 09:27 72240 C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-01-19 03:38 1008184 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2008-01-19 03:33 202240 C:\Program Files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
ComboFix 08-05-21.3 - Spicka 2008-05-25 22:00:17.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.631 [GMT -4:00]
Running from: C:\Users\Spicka\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-04-26 to 2008-05-26 )))))))))))))))))))))))))))))))
.
2008-05-25 00:16 . 2008-05-25 00:16 <DIR> d-------- C:\Users\Spicka\Roaming
2008-05-25 00:16 . 2008-05-25 00:16 <DIR> d-------- C:\Users\Spicka\AppData\Roaming\MySpace
2008-05-25 00:15 . 2008-05-25 00:15 <DIR> d-------- C:\Program Files\MySpace
2008-05-23 22:25 . 2008-05-23 22:27 <DIR> d-------- C:\Program Files\rFactorLexus
2008-05-22 18:59 . 2008-05-22 19:12 <DIR> d-------- C:\Program Files\rFactor
2008-05-21 19:37 . 2008-05-21 19:37 <DIR> d--h----- C:\Windows\PIF
2008-05-19 16:30 . 2008-05-19 16:30 <DIR> dr------- C:\Users\Public\Videos
2008-05-19 16:30 . 2008-05-22 20:15 <DIR> dr------- C:\Users\Public\Pictures
2008-05-18 12:14 . 2008-05-18 12:14 <DIR> dr------- C:\Users\Public\Documents
2008-05-17 21:38 . 2008-05-17 21:38 <DIR> dr------- C:\Users\Public\Music
2008-05-10 21:33 . 2008-05-10 21:33 <DIR> d-------- C:\Users\Spicka\AppData\Roaming\dvdcss
2008-05-10 18:49 . 2008-05-25 04:03 <DIR> d-------- C:\Program Files\DVDFab 5
2008-05-09 23:59 . 2008-05-09 23:59 <DIR> d-------- C:\Users\All Users\Codemasters
2008-05-09 23:59 . 2008-05-09 23:59 <DIR> d-------- C:\ProgramData\Codemasters
2008-05-09 23:57 . 2008-03-05 15:56 3,786,760 --a------ C:\Windows\System32\D3DX9_37.dll
2008-05-09 23:57 . 2008-03-05 15:56 1,420,824 --a------ C:\Windows\System32\D3DCompiler_37.dll
2008-05-09 23:57 . 2008-03-05 16:03 479,752 --a------ C:\Windows\System32\XAudio2_0.dll
2008-05-09 23:57 . 2008-02-05 23:07 462,864 --a------ C:\Windows\System32\d3dx10_37.dll
2008-05-09 23:57 . 2008-03-05 16:03 238,088 --a------ C:\Windows\System32\xactengine3_0.dll
2008-05-09 23:57 . 2008-03-05 16:00 25,608 --a------ C:\Windows\System32\X3DAudio1_3.dll
2008-05-09 19:19 . 2008-05-09 19:19 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-05-08 16:24 . 2008-05-08 16:25 <DIR> d-------- C:\Program Files\Clock Tray Skins
2008-05-07 21:28 . 2008-03-12 19:38 445,504 -ra------ C:\Windows\System32\vp6vfw.dll
2008-05-04 17:12 . 2008-05-04 17:13 <DIR> d-------- C:\Users\Spicka\AppData\Roaming\Off Road
2008-05-04 17:03 . 2008-05-04 17:03 <DIR> d-------- C:\Program Files\Xplosiv
2008-05-04 00:06 . 2008-05-04 00:06 <DIR> d-------- C:\Users\Spicka\AppData\Roaming\Ubisoft
2008-05-03 22:17 . 2008-05-03 22:17 <DIR> d-------- C:\Users\Spicka\AppData\Roaming\THQ
2008-05-03 22:13 . 2008-05-03 22:13 <DIR> d-------- C:\Users\All Users\InstallShield
2008-05-03 22:13 . 2008-05-03 22:13 <DIR> d-------- C:\ProgramData\InstallShield
2008-05-03 22:02 . 2006-05-16 10:58 73,728 --a------ C:\Windows\System32\ISUSPM.cpl
2008-05-03 11:57 . 2008-05-07 21:28 <DIR> d-------- C:\Program Files\EA GAMES
2008-05-01 20:04 . 2008-05-01 20:04 <DIR> d-------- C:\Program Files\Rockstar Games
2008-04-30 19:12 . 2008-04-30 19:12 319 --a------ C:\Windows\game.ini
2008-04-30 18:46 . 2008-04-30 18:46 <DIR> d-------- C:\Program Files\Activision
2008-04-30 17:32 . 2008-05-03 22:02 <DIR> d-------- C:\Program Files\THQ
2008-04-29 16:46 . 2008-04-29 16:46 <DIR> dr-h----- C:\Users\Spicka\AppData\Roaming\SecuROM
2008-04-29 16:46 . 2008-04-29 16:46 107,888 --a------ C:\Windows\System32\CmdLineExt.dll
2008-04-28 19:52 . 2008-05-03 00:46 <DIR> d-------- C:\Users\Spicka\AppData\Roaming\X-NetStat
2008-04-28 19:52 . 2008-04-28 19:52 <DIR> d-------- C:\Program Files\X-NetStat Professional
2008-04-28 17:00 . 2008-04-28 17:00 <DIR> d-------- C:\Program Files\AceLogix
2008-04-27 17:13 . 2008-05-19 15:14 <DIR> d-------- C:\Users\Spicka\AppData\Roaming\VMware
2008-04-27 17:08 . 2008-04-27 17:08 <DIR> d-------- C:\Program Files\VMware
2008-04-27 17:08 . 2008-04-27 17:08 <DIR> d-------- C:\Program Files\Common Files\VMware
2008-04-26 00:15 . 2008-04-26 00:15 <DIR> d-------- C:\Windows\System32\URTTEMP
2008-04-26 00:12 . 2008-04-26 00:12 <DIR> d-------- C:\Users\All Users\Media Center Programs
2008-04-26 00:12 . 2008-04-26 00:12 <DIR> d-------- C:\ProgramData\Media Center Programs
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-26 02:00 --------- d-----w C:\Users\Spicka\AppData\Roaming\uTorrent
2008-05-26 01:43 --------- d-----w C:\Users\Spicka\AppData\Roaming\Vso
2008-05-25 03:50 --------- d-----w C:\Program Files\Trillian
2008-05-24 15:57 --------- d---a-w C:\ProgramData\TEMP
2008-05-21 22:23 --------- d-----w C:\Users\Spicka\AppData\Roaming\Audacity
2008-05-19 18:00 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-05-19 17:56 --------- d-----w C:\ProgramData\Autodesk
2008-05-17 23:25 --------- d-----w C:\ProgramData\VMware
2008-05-17 02:49 --------- d-----w C:\Program Files\GPU-Z
2008-05-14 22:24 --------- d-----w C:\Program Files\Windows Mail
2008-05-10 03:57 444,952 ----a-w C:\Windows\System32\wrap_oal.dll
2008-05-10 03:57 109,080 ----a-w C:\Windows\System32\OpenAL32.dll
2008-05-10 03:49 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-10 03:49 --------- d-----w C:\Program Files\Codemasters
2008-05-08 15:00 --------- d-----w C:\Program Files\GTR2
2008-05-07 14:53 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-07 14:12 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-05-04 04:04 --------- d-----w C:\ProgramData\Ubisoft
2008-05-04 03:50 --------- d-----w C:\Program Files\Ubisoft
2008-05-02 00:17 --------- d-----w C:\Program Files\Microsoft Games
2008-04-29 00:29 --------- d-----w C:\ProgramData\Test Drive Unlimited
2008-04-27 03:53 --------- d-----w C:\Program Files\Grand Theft Auto San Andreas
2008-04-26 03:57 --------- d-----w C:\ProgramData\WindowsSearch
2008-04-26 03:46 --------- d-----w C:\Program Files\Electronic Arts
2008-04-23 00:41 --------- d-----w C:\Program Files\PowerISO
2008-04-22 19:37 --------- d-----w C:\Program Files\uTorrent
2008-04-21 20:02 --------- d-----w C:\Program Files\Atari
2008-04-21 00:21 --------- d-----w C:\Program Files\Easy Video Downloader
2008-04-15 22:48 --------- d-----w C:\Program Files\Fraps
2008-04-12 20:07 --------- d-----w C:\Program Files\VirtualDJ
2008-04-12 01:13 --------- d-----w C:\Program Files\DFX
2008-04-12 00:24 --------- d-----w C:\Users\Spicka\AppData\Roaming\Thinking Minds Budiling Bytes
2008-04-12 00:24 --------- d-----w C:\Program Files\CubeDesktop
2008-04-11 22:53 --------- d-----w C:\ProgramData\NVIDIA Corporation
2008-04-11 22:46 --------- d-----w C:\Program Files\Fast Explorer
2008-04-11 22:18 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-11 21:55 319,456 ----a-w C:\Windows\DIFxAPI.dll
2008-04-11 21:55 --------- d-----w C:\Program Files\Realtek
2008-04-11 02:04 --------- d-----w C:\ProgramData\Stardock
2008-04-11 01:38 --------- d-----w C:\Program Files\Foxit Software
2008-04-11 01:01 2,516 --sha-w C:\Windows\System32\KGyGaAvL.sys
2008-04-10 19:55 --------- d-----w C:\ProgramData\DFX
2008-04-10 19:54 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-10 18:19 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-04-10 06:22 --------- d-----w C:\Program Files\RocketDock
2008-04-10 03:18 --------- d-----w C:\Program Files\HyCam2
2008-04-10 01:03 --------- d-----w C:\Program Files\UltraISO
2008-04-10 01:02 --------- d-----w C:\Program Files\Common Files\EZB Systems
2008-04-07 03:07 --------- d-----w C:\ProgramData\vsosdk
2008-04-05 19:12 --------- d-----w C:\Program Files\Audacity 1.3 Beta (Unicode)
2008-04-05 00:45 47,360 ----a-w C:\Users\Spicka\AppData\Roaming\pcouffin.sys
2008-04-05 00:45 --------- d-----w C:\Program Files\VSO
2008-04-04 04:52 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-04 04:51 --------- d-----w C:\ProgramData\Messenger Plus!
2008-04-04 02:58 --------- d-----w C:\Program Files\RivaTuner v2.06
2008-03-31 23:15 --------- d-----w C:\Program Files\Rainbow Six Vegas
2008-03-30 23:00 --------- d-----w C:\Program Files\MagicISO
2008-03-29 21:03 --------- d-----w C:\ProgramData\Nero
2008-03-29 18:32 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
2008-03-29 16:19 716,272 ----a-w C:\Windows\system32\drivers\sptd.sys
2008-03-29 15:42 --------- d-----w C:\Program Files\Java
2008-03-29 15:41 --------- d-----w C:\Program Files\Common Files\Java
2008-03-29 15:29 --------- d-----w C:\ProgramData\SlySoft
2008-03-28 23:28 --------- d-----w C:\Program Files\Trojan Remover
2008-03-28 23:27 --------- d-----w C:\Users\Spicka\AppData\Roaming\Simply Super Software
2008-03-28 23:27 --------- d-----w C:\ProgramData\Simply Super Software
2008-03-28 20:59 --------- d-----w C:\Users\Spicka\AppData\Roaming\InstallShield
2008-03-27 23:03 --------- d-----w C:\ProgramData\FLEXnet
2008-03-27 22:14 --------- d-----w C:\Program Files\Image-Line
2008-03-27 22:12 --------- d-----w C:\Program Files\Steinberg
2008-03-26 23:41 --------- d-----w C:\ProgramData\Corel
2008-03-20 00:34 174 --sha-w C:\Program Files\desktop.ini
2008-03-20 00:11 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-03-20 00:11 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-03-04 22:30 98,304 ----a-w C:\Windows\system32CmdLineExt.dll
2008-02-29 07:14 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 07:11 988,216 ----a-w C:\Windows\System32\winload.exe
2008-02-29 07:11 927,288 ----a-w C:\Windows\System32\winresume.exe
2008-02-29 06:53 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll
2008-02-29 06:53 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:53 378,368 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 04:21 2,032,128 ----a-w C:\Windows\System32\win32k.sys
2008-02-29 04:12 318,464 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 04:12 14,848 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-11 01:22 0 ----a-w C:\Users\Spicka\AppData\Roaming\wklnhst.dat
2008-02-14 21:50 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-02-14 21:50 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-02-14 21:50 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 03:33 1233920]
"avast! service GUI component"="C:\Program Files\Alwil Software\Avast4\ashDisp.exe" [2008-03-29 14:37 79224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 17:16 65536]
"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 07:59 118784]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2008-01-09 15:23 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-01-09 15:23 8530464]
"RivaTunerStartupDaemon"="C:\Program Files\RivaTuner v2.06\RivaTuner.exe" [2007-10-30 14:05 2650112]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 19:27 9117696]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Gaming Software.lnk - C:\Windows\Installer\{C5961323-A2E5-4FAB-B92D-DBF6C282F0F5}\NewShortcut1_C5961323A2E54FABB92DDBF6C282F0F5.exe [2007-12-27 20:25:16 40960]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^RivaTuner.exe]
backup=C:\Windows\pss\RivaTuner.exe.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Spicka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
backup=C:\Windows\pss\MagicDisc.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Spicka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office Groove.lnk]
path=C:\Users\Spicka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office Groove.lnk
backup=C:\Windows\pss\Microsoft Office Groove.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD_Display]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\b44b5fc7]
C:\Users\Spicka\AppData\Local\Temp\iebemyiq.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cmds]
C:\Users\Spicka\AppData\Local\Temp\mllkh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dog about manager team]
--a------ 2008-01-06 15:13 114704 C:\ProgramData\META THIRD 4.l9q7bk
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
--a------ 2008-01-19 03:33 125952 C:\Windows\ehome\ehTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 01:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
--a------ 2007-04-18 11:01 65536 c:\hp\support\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jumpsafe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
--a------ 2006-12-08 17:16 65536 C:\HP\KBD\KbdStub.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MS Juan]
C:\Users\Spicka\AppData\Local\Temp\mlhuacox.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 12:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSServer]
C:\Users\Spicka\AppData\Local\Temp\gebay.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2008-01-09 15:23 8530464 C:\Windows\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2008-01-09 15:23 81920 C:\Windows\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
--a------ 2008-01-09 15:23 86016 C:\Windows\system32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeerGuardian]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2008-03-14 19:50 233472 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RivaTunerStartupDaemon]
--a------ 2007-10-30 14:05 2650112 C:\Program Files\RivaTuner v2.06\RivaTuner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
--a------ 2007-10-25 05:52 4702208 C:\Windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateReg]
--a------ 2007-09-25 02:11 54672 C:\Windows\system32\jureg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VMware hqtray]
--a------ 2007-10-08 09:26 55856 C:\Program Files\VMware\VMware Workstation\hqtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmware-tray]
--a------ 2007-10-08 09:27 72240 C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-01-19 03:38 1008184 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2008-01-19 03:33 202240 C:\Program Files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001