I have a Win 7 machine that has recently contracted some virus/malware. Microsoft security essentials found several items but even after the removal of those items iexplore.exe starts on it's own and appears in the running process list. Occasionally you will see the IE window appear and be at some random page. Additionally when doing a google search and clicking on the search results you are re-directed elsewhere.
Here is the DDS log :
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by vasm at 16:19:59 on 2011-11-18
Microsoft Windows 7 Enterprise 6.1.7600.0.1252.61.1033.18.3037.1681 [GMT 11:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskmgr.exe
C:\Windows\system32\LogonUI.exe
C:\Windows\system32\rdpclip.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.au/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
TCP: DhcpNameServer = 192.168.1.5
TCP: Interfaces\{005B49CA-3BC8-42D9-8451-C3E37FA7A4B3} : DhcpNameServer = 192.168.1.5
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\759\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R1 MpKsl24f2bbd8;MpKsl24f2bbd8;c:\programdata\microsoft\microsoft antimalware\definition updates\{5de19336-a06f-401c-8a60-8f9cd1658992}\MpKsl24f2bbd8.sys [2011-11-18 28752]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2010-3-15 127488]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 65024]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-1-14 39272]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2011-4-18 43392]
.
=============== Created Last 30 ================
.
2011-11-18 05:11:55 28752 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{5de19336-a06f-401c-8a60-8f9cd1658992}\MpKsl24f2bbd8.sys
2011-11-18 05:11:53 56200 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{5de19336-a06f-401c-8a60-8f9cd1658992}\offreg.dll
2011-11-18 04:50:24 -------- d-----w- c:\windows\system32\SPReview
2011-11-18 04:38:02 -------- d-----w- c:\users\vasm.looknet\appdata\local\ElevatedDiagnostics
2011-11-18 03:16:18 6668624 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{5de19336-a06f-401c-8a60-8f9cd1658992}\mpengine.dll
2011-11-18 01:37:42 -------- d-s---w- C:\ComboFix
2011-11-15 05:05:37 -------- d-----w- c:\program files\ESET
2011-11-15 03:58:53 -------- d-----w- c:\users\vasm.looknet\appdata\local\temp
2011-11-15 03:55:15 -------- d-sh--w- C:\$RECYCLE.BIN
2011-11-15 02:54:44 6668624 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-11-15 01:59:11 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2011-11-14 23:27:13 -------- d-----w- c:\programdata\Malwarebytes
2011-11-14 23:27:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-13 23:16:45 2339840 ----a-w- c:\windows\system32\win32k.sys
2011-11-13 23:16:44 708608 ----a-w- c:\program files\common files\system\wab32.dll
2011-11-13 23:16:43 1285488 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-13 23:05:45 703824 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\nisbackup\gapaengine.dll
2011-11-13 23:05:44 703824 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{a7d926f4-163e-4714-be71-24489ce3ae6e}\gapaengine.dll
2011-11-13 23:04:38 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-11-13 22:57:45 -------- d-----w- c:\program files\Microsoft Security Client
2011-11-13 22:57:24 240008 ----a-w- c:\windows\system32\drivers\netio.sys
.
==================== Find3M ====================
.
2011-08-27 04:43:07 571904 ----a-w- c:\windows\system32\oleaut32.dll
2011-08-27 04:43:06 233472 ----a-w- c:\windows\system32\oleacc.dll
.
============= FINISH: 16:26:50.52 ===============
Here is the GMER log :
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-11-18 14:09:54
Windows 6.1.7600
Running: sm2nlkcm.exe; Driver: C:\Users\JIMMIL~1\AppData\Local\Temp\pxldypow.sys
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670@COD 9600
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670@DibServiceVersion 131072
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670@Name 0x41 0x70 0x70 0x6C ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670@PID 781
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670@Store Link Key 1
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670@VID 1452
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670@VIDType 2
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\CachedServices
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\CachedServices@00010000 0x36 0x01 0x54 0x09 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43@AuthenticationRequirements 5
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43@IoCapability 255
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43@RemoteAuthenticationRequirements 255
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43@SSP MITM Protected 0
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43@SSP Paired 0
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43@SSP Supported 0
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43\{00001124-0000-1000-8000-00805f9b34fb}
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43\{00001124-0000-1000-8000-00805f9b34fb}@Instance 1
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43\{00001124-0000-1000-8000-00805f9b34fb}\C00000000
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43\{00001124-0000-1000-8000-00805f9b34fb}\C00000000@CounterInstanceId 0
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43\{00001124-0000-1000-8000-00805f9b34fb}\C00000000@DeviceString
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43\{00001124-0000-1000-8000-00805f9b34fb}\C00000000@Enabled 1
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43\{00001124-0000-1000-8000-00805f9b34fb}\C00000000@PriLangServiceName 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Keys
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Keys\00190e060b43
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT\Keys\00190e060b43@c42c03ade670 0x99 0x32 0x88 0x7F ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\HidBth
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\HidBth\Devices
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\HidBth\Devices\00190e060b43c42c03ade670
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\HidBth\Devices\00190e060b43c42c03ade670@ConnectionAuthenticated 1
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\HidBth\Devices\00190e060b43c42c03ade670@VirtuallyCabled 1
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\0001
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\0001@BackupContext 0x02 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\0001@COD Type 1
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\0001@ExtPropDescSemaphore 1
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\0001@Scans Before Out of Range 8
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\0001@SCO Max Channels 2
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\0001@Store Link Key COD Masks 0x00 0x00 0x1F 0x43 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\0001@SymbolicLinkName \??\USB#VID_0A5C&PID_2153#00190E060B43#{0850302a-b344-4fda-9be9-90576b8d46f0}
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\0001@SymbolicName \??\USB#VID_0A5C&PID_2153#00190E060B43#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670@COD 9600
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670@DibServiceVersion 131072
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670@Name 0x41 0x70 0x70 0x6C ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670@PID 781
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670@Store Link Key 1
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670@VID 1452
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670@VIDType 2
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\CachedServices (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\CachedServices@00010000 0x36 0x01 0x54 0x09 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43@AuthenticationRequirements 5
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43@IoCapability 255
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43@RemoteAuthenticationRequirements 255
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43@SSP MITM Protected 0
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43@SSP Paired 0
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43@SSP Supported 0
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43\{00001124-0000-1000-8000-00805f9b34fb} (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43\{00001124-0000-1000-8000-00805f9b34fb}@Instance 1
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43\{00001124-0000-1000-8000-00805f9b34fb}\C00000000 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43\{00001124-0000-1000-8000-00805f9b34fb}\C00000000@CounterInstanceId 0
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43\{00001124-0000-1000-8000-00805f9b34fb}\C00000000@DeviceString
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43\{00001124-0000-1000-8000-00805f9b34fb}\C00000000@Enabled 1
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Devices\c42c03ade670\ServicesFor00190e060b43\{00001124-0000-1000-8000-00805f9b34fb}\C00000000@PriLangServiceName 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Keys (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Keys\00190e060b43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\BTHPORT\Keys\00190e060b43@c42c03ade670 0x99 0x32 0x88 0x7F ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\HidBth (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\HidBth\Devices (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\HidBth\Devices\00190e060b43c42c03ade670 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\HidBth\Devices\00190e060b43c42c03ade670@ConnectionAuthenticated 1
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\HidBth\Devices\00190e060b43c42c03ade670@VirtuallyCabled 1
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\0001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\0001@BackupContext 0x02 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\0001@COD Type 1
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\0001@ExtPropDescSemaphore 1
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\0001@Scans Before Out of Range 8
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\0001@SCO Max Channels 2
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\0001@Store Link Key COD Masks 0x00 0x00 0x1F 0x43 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\0001@SymbolicLinkName \??\USB#VID_0A5C&PID_2153#00190E060B43#{0850302a-b344-4fda-9be9-90576b8d46f0}
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\0001@SymbolicName \??\USB#VID_0A5C&PID_2153#00190E060B43#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
---- EOF - GMER 1.0.15 ----
Thanks
Vas
Attached File(s)
-
attach.txt (29.2K)
Number of downloads: 1

Help
This topic is locked

Back to top











