This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] can someone look at this log? what needs deleting

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

sorry–dont mean to be a pain but it seems that it is not letting me run otm.exe now it ran before i deleted it and redownloaded it but the same thing happens– i get a little vista circle for a couple of seconds and then it disappears and nothing happens
jv0802,

This should fix that.

Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.

Then go ahead an try re-downloading OTM.
thanks–that worked heres the OTM log: ========== PROCESSES ========== Process explorer.exe killed successfully. ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}\\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{C55BBCD6-41AD-48AD-9953-3609C48EACC7}\\ not found. ========== FILES ========== File/Folder c:\programdata\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} not found. File/Folder c:\programdata(2)\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} not found. c:\windows\DUMP6170.tmp moved successfully. LoadLibrary failed for c:\windows\system32\F31BF58A3D.dll c:\windows\system32\F31BF58A3D.dll NOT unregistered. c:\windows\system32\F31BF58A3D.dll moved successfully. ========== COMMANDS ========== File delete failed. C:\Users\jeff\AppData\Local\Temp\Temporary Internet Files\Content.IE5\985V8913\fc[2].htm scheduled to be deleted on reboot. File delete failed. C:\Users\jeff\AppData\Local\Temp\Temporary Internet Files\Content.IE5\985V8913\iframe[1].htm scheduled to be deleted on reboot. File delete failed. C:\Users\jeff\AppData\Local\Temp\Temporary Internet Files\Content.IE5\985V8913\launch[1].htm scheduled to be deleted on reboot. File delete failed. C:\Users\jeff\AppData\Local\Temp\Temporary Internet Files\Content.IE5\985V8913\st[2] scheduled to be deleted on reboot. File delete failed. C:\Users\jeff\AppData\Local\Temp\Temporary Internet Files\Content.IE5\3R83PD7T\blank[1].htm scheduled to be deleted on reboot. File delete failed. C:\Users\jeff\AppData\Local\Temp\Temporary Internet Files\Content.IE5\3R83PD7T\blank[4].htm scheduled to be deleted on reboot. File delete failed. C:\Users\jeff\AppData\Local\Temp\Temporary Internet Files\Content.IE5\3R83PD7T\can_someone_look_log_what_needs_deleting_t103498[1].htm scheduled to be deleted on reboot. File delete failed. C:\Users\jeff\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Users\jeff\AppData\Local\Temp\History\History.IE5\MSHist012009060220090603\index.dat scheduled to be deleted on reboot. File delete failed. C:\Users\jeff\AppData\Local\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Users\jeff\AppData\Local\Temp\Cookies\index.dat scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. Windows Temp folder emptied. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTM by OldTimer - Version 2.1.0.0 log created on 06022009_102030 Files moved on Reboot… C:\Users\jeff\AppData\Local\Temp\Temporary Internet Files\Content.IE5\985V8913\fc[2].htm moved successfully. C:\Users\jeff\AppData\Local\Temp\Temporary Internet Files\Content.IE5\985V8913\iframe[1].htm moved successfully. C:\Users\jeff\AppData\Local\Temp\Temporary Internet Files\Content.IE5\985V8913\launch[1].htm moved successfully. C:\Users\jeff\AppData\Local\Temp\Temporary Internet Files\Content.IE5\985V8913\st[2] moved successfully. C:\Users\jeff\AppData\Local\Temp\Temporary Internet Files\Content.IE5\3R83PD7T\blank[1].htm moved successfully. C:\Users\jeff\AppData\Local\Temp\Temporary Internet Files\Content.IE5\3R83PD7T\blank[4].htm moved successfully. C:\Users\jeff\AppData\Local\Temp\Temporary Internet Files\Content.IE5\3R83PD7T\can_someone_look_log_what_needs_deleting_t103498[1].htm moved successfully. Registry entries deleted on Reboot… and here is the systemlook log: SystemLook v1.0 by jpshortstuff (22.05.09) Log created at 10:29 on 02/06/2009 by jeff (Administrator - Elevation successful) ========== dir ========== c:\programdata - Parameters: "(none)" —Files— ntuser.pol -rahs- 258 bytes [16:23 24/10/2008] [16:23 24/10/2008] xnwfyhdk.mld –a— 5072 bytes [20:23 04/09/2007] [20:23 04/09/2007] ÝÃÄ›Ò3113›.sys —h– 13 bytes [22:40 04/03/2008] [22:40 04/03/2008] —Folders— Adobe d—– [04:02 30/05/2007] Adobe Systems d—– [20:57 29/03/2008] ALM d—– [04:07 24/01/2008] Apple d—– [16:43 01/09/2007] Apple Computer d—– [16:44 01/09/2007] Application Data d–hs- [22:42 22/08/2007] avg8 d—– [01:42 04/05/2008] AVS4YOU d—– [01:52 04/04/2008] Bluetooth d—– [00:30 12/01/2008] Broderbund LLC d—– [14:01 28/01/2008] Broderbund Software d—– [05:19 28/01/2008] Brother d—– [14:10 02/09/2007] CanonBJ d–h– [12:47 01/09/2007] CheckPoint d—– [02:48 23/08/2007] COMMON FILES d—– [13:17 05/06/2007] Corel d—– [13:59 05/06/2007] Desktop d—– [14:05 05/06/2007] Documents d–hs- [22:42 22/08/2007] Favorites d–hs- [22:42 22/08/2007] FLEXnet d—– [13:26 05/06/2007] Google d—– [22:36 10/02/2008] InstallShield d—– [02:13 07/10/2007] Intuit d—– [13:17 05/06/2007] Lavasoft d—– [12:40 25/05/2009] LF d—– [13:36 05/06/2007] Malwarebytes d—– [14:09 26/05/2009] McAfee d—– [15:00 31/01/2008] Memeo d—s- [03:04 15/06/2008] Microsoft d—s- [11:18 02/11/2006] Microsoft Help d—– [13:53 05/06/2007] Minnetonka Audio Software d—– [00:01 28/05/2008] Mozilla d—– [16:56 01/09/2007] Napster d—– [04:04 30/05/2007] NCH Swift Sound d—– [12:45 14/09/2007] NOS d—– [15:01 18/07/2008] NVIDIA d—– [02:08 27/08/2007] Office Genuine Advantage d—– [22:00 29/02/2008] Pinnacle d—– [23:36 28/08/2007] Protexis d—– [05:20 28/01/2008] PY_Software d—– [02:01 15/10/2007] QuickTime d—– [16:14 30/08/2007] Riverdeep Interactive Learning Limited d—– [05:22 28/01/2008] Roxio d—– [02:12 25/08/2007] SmartSound Software Inc d—– [17:29 01/09/2007] Sonic d—– [14:03 05/06/2007] SonicStage d—– [16:07 29/08/2007] Sony Corporation d—– [04:06 30/05/2007] SSScanAppDataDir d—– [12:42 01/09/2007] SSScanWizard d—– [12:42 01/09/2007] Start Menu d–hs- [22:42 22/08/2007] Symantec d—– [13:41 05/06/2007] TEMP d-a— [21:55 04/03/2008] Templates d–hs- [22:42 22/08/2007] TVU Networks d—– [19:38 14/08/2008] VAIO Media Platform d—– [14:18 05/06/2007] Yahoo! Companion d—– [11:40 25/05/2009] {174892B1-CBE7-44F5-86FF-AB555EFD73A3} d—– [14:38 05/06/2007] -=End Of File=-
jv0802,

Let's try this scan:


Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click Yes to all if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found:[external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    [external image: Posted Image]
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
I am running Dr webcure it. the express scan didnt find anything so i am running the long scan but while in the process of running the express scan with dr webcure it— AVG (which i did not know was running- must have started automatically after the last reboot–hope that didnt mess anything up) came up with this threat warning C:\windows\system32\drivers\gxvxcabomiopxlrdvrtsqghjelrodtghvfjbj.sys - Trojan horse Backdoor.generic11.QSM I dont know if that was caused by Dr webcureit or not so i have not done anything with it— it did not come up until shortly after i ran dr web cure it what should i tell AVG to do?
avg said that item can not be healed item with this value already exist in object not sure what that means also said that the process name is c:\users\jeff\appdata\local\temp\rarsfx0\tku2w.exe
jv0802,

C:\windows\system32\drivers\gxvxcabomiopxlrdvrtsqghjelrodtghvfjbj.sys could be a rootkit.

c:\users\jeff\appdata\local\temp\rarsfx0 should refer to your AVG installation folder.

After DR Web is done, post the results here and then go right ahead and do the following:

Please download gmer.zip from Gmer and save it to your desktop.

  • Right click on gmer.zip and select Extract All….
  • Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  • Click on the Browse button. Click on Desktop. Then click OK.
  • Click Next. It will start extracting.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Double click on gmer.exe to run it.
  • Select the Rootkit tab.
  • On the right hand side, check all the items to be scanned, but leave Show All box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click on the Scan button.
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard.
  • Open Notepad or a similar text editor.
  • Paste the clipboard contents into the text editor.
  • Save the Gmer scan log and post it in your next reply.

Note: Do not run any programs while Gmer is running.
i think it found something

here is the log

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-02 22:57:02
Windows 6.0.6000


—- System - GMER 1.0.15 —-

Code 8A685338 ZwEnumerateKey
Code 8A35C950 ZwFlushInstructionCache
Code 8A35DE75 IofCallDriver
Code 8A683176 IofCompleteRequest

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!IofCallDriver 82827F37 5 Bytes JMP 8A35DE7A
.text ntkrnlpa.exe!IofCompleteRequest 82827FA4 5 Bytes JMP 8A68317B
PAGE ntkrnlpa.exe!ZwEnumerateKey 82937F06 5 Bytes JMP 8A68533C
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 829E849F 5 Bytes JMP 8A35C954
? C:\Windows\System32\Drivers\sptd.sys The process cannot access the file because it is being used by another process.
.text USBPORT.SYS!DllUnload 8F032BBC 5 Bytes JMP 876341C8
? System32\Drivers\a93fh852.SYS The system cannot find the path specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\iexplore.exe[3016] USER32.dll!DialogBoxIndirectParamW 770B14EA 5 Bytes JMP 71581777 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3016] USER32.dll!MessageBoxExA 770C570D 5 Bytes JMP 715816BE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3016] USER32.dll!DialogBoxParamA 770C65BF 5 Bytes JMP 7158173C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3016] USER32.dll!MessageBoxIndirectW 770CF1B3 5 Bytes JMP 714116B6 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3016] USER32.dll!DialogBoxParamW 770D129F 5 Bytes JMP 713EF341 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3016] USER32.dll!DialogBoxIndirectParamA 770F29C9 5 Bytes JMP 715817B2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3016] USER32.dll!MessageBoxIndirectA 770FFACF 5 Bytes JMP 715816F8 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3016] USER32.dll!MessageBoxExW 770FFBC9 5 Bytes JMP 71581684 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

—- Kernel IAT/EAT - GMER 1.0.15 —-

IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [807285FE] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [80727AB4] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [80728728] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [80727B7C] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [80727BFA] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [8073AC5A] \SystemRoot\System32\Drivers\sptd.sys

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [7283FD78] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7280BBF1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [727FA31F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [727FCBFF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [727F8AB2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7280D168] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [727F7D98] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [727F7CFF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [727F6A54] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7288C1BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [728180FE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [727F90CD] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [7280223C] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [72802267] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [7280771C] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [7280753E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1944] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [72838585] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16683_none_9ea0f08a
c96e2537\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 84D611E8
Device \Driver\netbt \Device\NetBT_Tcpip_{DAC6341D-EB11-4868-B574-66DB51F49FDB} 8A276980

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

Device \Driver\volmgr \Device\VolMgrControl 84D5D1E8
Device \Driver\usbuhci \Device\USBPDO-0 873C21E8
Device \Driver\usbuhci \Device\USBPDO-1 873C21E8
Device \Driver\netbt \Device\NetBT_Tcpip_{7B40F1CE-74B3-4FA9-A7B8-5D06348E70C9} 8A276980
Device \Driver\usbehci \Device\USBPDO-2 874FB980
Device \Driver\usbuhci \Device\USBPDO-3 873C21E8
Device \Driver\usbuhci \Device\USBPDO-4 873C21E8
Device \Driver\usbuhci \Device\USBPDO-5 873C21E8
Device \Driver\usbehci \Device\USBPDO-6 874FB980
Device \Driver\volmgr \Device\HarddiskVolume1 84D5D1E8
Device \Driver\volmgr \Device\HarddiskVolume2 84D5D1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 84D601E8
Device \Driver\iaStor \Device\Ide\iaStor0 84D5F1E8
Device \Driver\atapi \Device\Ide\IdePort0 84D601E8
Device \Driver\atapi \Device\Ide\IdePort1 84D601E8
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 84D5F1E8
Device \Driver\netbt \Device\NetBT_Tcpip_{DE01F366-FB7E-4596-82D0-9E1A860C20C6} 8A276980
Device \Driver\netbt \Device\NetBt_Wins_Export 8A276980
Device \Driver\iScsiPrt \Device\RaidPort0 874F01E8
Device \Driver\PCI_NTPNP6912 \Device\0000005e sptd.sys
Device \Driver\usbuhci \Device\USBFDO-0 873C21E8
Device \Driver\usbuhci \Device\USBFDO-1 873C21E8
Device \Driver\usbehci \Device\USBFDO-2 874FB980
Device \Driver\usbuhci \Device\USBFDO-3 873C21E8
Device \Driver\usbuhci \Device\USBFDO-4 873C21E8
Device \Driver\usbuhci \Device\USBFDO-5 873C21E8
Device \Driver\usbehci \Device\USBFDO-6 874FB980
Device \Driver\a93fh852 \Device\Scsi\a93fh8521Port4Path0Target0Lun0 874E91E8
Device \Driver\a93fh852 \Device\Scsi\a93fh8521 874E91E8
—- Processes - GMER 1.0.15 —-

Library \\?\globalroot\systemroot\system32\gxvxcljwivpdlcjoejaiberbyjmgcorhtqjwd.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [956] 0x10000000
Library \\?\globalroot\systemroot\system32\gxvxcqsmhlcbnranuctivaljfcippbanaqbld.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\iexplore.exe [3016] 0x10000000
Library \\?\globalroot\systemroot\system32\gxvxcqsmhlcbnranuctivaljfcippbanaqbld.dll (*** hidden *** ) @ C:\program files\mozilla firefox\firefox.exe [4336] 0x10000000

—- Services - GMER 1.0.15 —-

Service system32\drivers\gxvxcabomiopxlrdvrtsqghjelrodtghvfjbj.sys (*** hidden *** ) [SYSTEM] gxvxcserv.sys <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxcabomiopxlrdvrtsqghjelrodtghvfjbj.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxcabomiopxlrdvrtsqghjelrodtghvfjbj.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxcljwivpdlcjoejaiberbyjmgcorhtqjwd.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules@gxvxcclk \\?\globalroot\systemroot\system32\gxvxcqsmhlcbnranuctivaljfcippbanaqbld.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 -110522744
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 -937616517
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x0B 0x9D 0x7D 0x9B …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x4C 0xC4 0xFE 0x18 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x9D 0x1C 0x81 0xEB …
Reg HKLM\SYSTEM\ControlSet009\Services\gxvxcserv.sys
Reg HKLM\SYSTEM\ControlSet009\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet009\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet009\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxcabomiopxlrdvrtsqghjelrodtghvfjbj.sys
Reg HKLM\SYSTEM\ControlSet009\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet009\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\ControlSet009\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxcabomiopxlrdvrtsqghjelrodtghvfjbj.sys
Reg HKLM\SYSTEM\ControlSet009\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxcljwivpdlcjoejaiberbyjmgcorhtqjwd.dll
Reg HKLM\SYSTEM\ControlSet009\Services\gxvxcserv.sys\modules@gxvxcclk \\?\globalroot\systemroot\system32\gxvxcqsmhlcbnranuctivaljfcippbanaqbld.dll
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x0B 0x9D 0x7D 0x9B …
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x4C 0xC4 0xFE 0x18 …
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x9D 0x1C 0x81 0xEB …
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF …
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 …
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0x7A 0x45 0x05 0xFD …
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 …
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 …
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 …
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x31 0x77 0xE1 0xBA …
Reg HKLM\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version
Reg HKLM\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version@Version 0xA8 0xB6 0x3D 0xF0 …
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x83 0x6C 0x56 0x8B …
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0x51 0xFA 0x6E 0x91 …
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 …
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0x2A 0xB7 0xCC 0xB5 …
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0x6C 0x43 0x2D 0x1E …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6DDF2296-D220-43C2-1C3A-B983307F2C81}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6DDF2296-D220-43C2-1C3A-B983307F2C81}@oacfkkahldhphjnpnmnmemobncejag 0x69 0x61 0x63 0x69 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6DDF2296-D220-43C2-1C3A-B983307F2C81}@nameaagljndhecijdbnnhojjmble 0x69 0x61 0x63 0x69 …

—- Files - GMER 1.0.15 —-

File C:\Windows\System32\gxvxccount 4 bytes
File C:\Windows\System32\gxvxcljwivpdlcjoejaiberbyjmgcorhtqjwd.dll 22529 bytes executable
File C:\Windows\System32\gxvxcqsmhlcbnranuctivaljfcippbanaqbld.dll 28673 bytes executable

—- EOF - GMER 1.0.15 —-
jv0802,

Yeppers. There is the cancer tumor. Now we need to rip it out and see how much it has metastasized.

AVENGER

  • Download The Avenger by Swandog46 from here.
  • Unzip/extract it to a folder on your desktop.
  • Double click on avenger.exe to run The Avenger.
  • Click OK.
  • Make sure that both the box next to Scan for rootkits and the box next to Automatically disable any rootkits found both have ticks in them.
  • Click the Execute button.
  • You will be asked No script has been entered. Do you want to execute a rootkit scan only?.
  • Click Yes.
  • You will now be asked First step completed — The Avenger has been successfully set up to run on next boot. Reboot now?.
  • Click Yes.
  • Your PC will now be rebooted.
  • Note: If The Avenger finds a hidden rootkit driver, then The Avenger will require two reboots to complete its operation.
  • If that is the case, it will force a BSOD on the first reboot. This is normal & expected behaviour.
  • After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at %systemdrive%\avenger.txt (typically C:\avenger.txt).
ok here is the log from avenger

Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows Vista

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

Hidden driver "gxvxcserv.sys" found!
ImagePath: \systemroot\system32\drivers\gxvxcabomiopxlrdvrtsqghjelrodtghvfjbj.sys
Driver disabled successfully.

Rootkit scan completed.


Completed script processing.

*******************

Finished! Terminate.
jv0802, Sometimes when you cut the serpents head off, there are other nasties revealed. Please run ComboFix per instructions in post #4.
k ii here is the combofix log

i can not find spysweeper anywhere–not in add/remove progams, or task manager or start menu–but it still said that it was running

ComboFix 09-06-01.03 - jeff 06/03/2009 11:52.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.3070.2065 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Spy Sweeper *enabled* (Updated) {68A41C74-A1E9-48F8-B2E5-D8232211AB6D}
SP: Spyware Doctor *disabled* (Updated) {1C3EDD79-273E-46ac-99F8-EFA9E7CBC301}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
c:\windows\system32\drivers\Sony_VGN-AR520E.mrk
c:\windows\system32\gxvxcljwivpdlcjoejaiberbyjmgcorhtqjwd.dll
c:\windows\system32\gxvxcqsmhlcbnranuctivaljfcippbanaqbld.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_gxvxcserv.sys


((((((((((((((((((((((((( Files Created from 2009-05-03 to 2009-06-03 )))))))))))))))))))))))))))))))
.

2009-06-02 16:32 . 2009-06-02 16:32 ——– d—–w- c:\users\jeff\DoctorWeb
2009-06-02 14:20 . 2009-06-02 14:20 ——– d—–w- C:\_OTM
2009-05-26 22:28 . 2009-05-26 22:28 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-26 22:24 . 2009-05-26 22:24 3371383 —-a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-26 22:10 . 2009-05-26 22:10 ——– d—–w- c:\users\jeff\AppData\Roaming\Malwarebytes
2009-05-26 14:09 . 2009-05-26 17:19 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-05-26 14:09 . 2009-05-26 17:20 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 14:09 . 2009-05-26 14:09 ——– d—–w- c:\programdata\Malwarebytes
2009-05-26 14:09 . 2009-05-26 22:25 ——– d—–w- c:\program files\kill
2009-05-26 13:29 . 2009-05-27 19:27 ——– d—–w- c:\program files\Trend Micro
2009-05-25 12:41 . 2009-06-01 20:16 ——– dc—-w- c:\windows\system32\DRVSTORE
2009-05-25 12:40 . 2009-06-01 20:16 ——– d—–w- c:\programdata\Lavasoft
2009-05-25 11:40 . 2009-05-25 12:09 ——– d—–w- c:\programdata\Yahoo! Companion
2009-05-25 11:39 . 2009-05-25 11:40 ——– d—–w- c:\program files\CCleaner
2009-05-23 00:09 . 2009-05-23 00:09 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-05-21 11:10 . 2009-05-21 11:10 738120 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-05-19 19:13 . 2009-05-19 19:13 1915520 —-a-w- c:\users\jeff\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-05-16 16:03 . 2009-05-16 16:03 416128 —-a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2009-05-15 21:00 . 2009-05-15 21:00 ——– d—–w- c:\program files\Common Files\xing shared
2009-05-15 00:27 . 2009-05-15 00:27 390664 —-a-w- c:\users\jeff\AppData\Roaming\Real\RealPlayer\Update\RealPlayer11.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-03 16:03 . 2007-08-22 22:57 214286 —-a-w- c:\users\jeff\AppData\Roaming\nvModes.dat
2009-06-03 16:02 . 2008-08-09 21:02 ——– d—–w- c:\users\jeff\AppData\Roaming\DNA
2009-06-03 16:02 . 2008-08-09 21:02 ——– d—–w- c:\program files\DNA
2009-06-03 15:40 . 2008-05-04 01:42 ——– d—–w- c:\programdata\avg8
2009-06-03 03:03 . 2007-09-01 16:55 ——– d—–w- c:\program files\DivX
2009-06-01 15:03 . 2007-05-30 04:04 ——– d—–w- c:\program files\Java
2009-05-29 11:18 . 2007-06-05 13:41 ——– d—–w- c:\programdata\Symantec
2009-05-29 11:18 . 2007-06-05 13:40 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-05-27 11:16 . 2007-09-11 14:22 1356 —-a-w- c:\users\jeff\AppData\Local\d3d9caps.dat
2009-05-25 11:40 . 2009-03-04 19:01 ——– d—–w- c:\program files\Yahoo!
2009-05-24 00:11 . 2008-01-05 02:19 ——– d—–w- c:\program files\LimeWire
2009-05-23 14:35 . 2007-06-05 13:26 ——– d—–w- c:\programdata\FLEXnet
2009-05-23 11:23 . 2007-08-22 22:46 338520 —-a-w- c:\users\jeff\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-22 17:18 . 2007-08-28 19:39 ——– d—–w- c:\users\jeff\AppData\Roaming\OpenOffice.org2
2009-05-22 16:27 . 2008-07-09 15:24 1 —-a-w- c:\users\jeff\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2009-05-15 21:00 . 2007-08-23 06:09 ——– d—–w- c:\program files\Common Files\Real
2009-05-06 17:21 . 2009-03-04 17:05 5 —-a-w- c:\windows\system32\SySAVI2WMV.dat
2009-04-22 19:38 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-04-22 19:38 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-04-22 16:37 . 2009-04-22 16:37 ——– d—–w- c:\program files\Sibelius Software
2009-04-22 13:43 . 2007-05-30 04:14 ——– d—–w- c:\program files\Microsoft SQL Server
2009-04-22 13:14 . 2009-04-21 19:23 ——– d—–w- c:\program files\StockPicker RT
2009-04-21 19:23 . 2009-04-21 19:23 200704 —-a-r- c:\users\jeff\AppData\Roaming\Microsoft\Installer\{CB4E1508-632E-4F3B-939C-920730231DF7}\_EA5052EEA198435A823FF7AC082E1D50.exe
2009-04-21 19:23 . 2009-04-21 19:23 200704 —-a-r- c:\users\jeff\AppData\Roaming\Microsoft\Installer\{CB4E1508-632E-4F3B-939C-920730231DF7}\_0D58037CB5A3428692D8780F31100D9F.exe
2009-04-21 19:23 . 2009-04-21 19:23 10134 —-a-r- c:\users\jeff\AppData\Roaming\Microsoft\Installer\{CB4E1508-632E-4F3B-939C-920730231DF7}\ARPPRODUCTICON.exe
2009-04-12 21:53 . 2008-08-09 20:33 ——– d—–w- c:\program files\Microsoft Silverlight
2009-03-24 13:12 . 2009-03-24 16:37 38200 —-a-w- c:\users\jeff\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-03-17 03:16 . 2009-04-22 13:30 14848 —-a-w- c:\windows\system32\apilogen.dll
2009-03-17 03:16 . 2009-04-22 13:30 25600 —-a-w- c:\windows\system32\amxread.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-04-23 342848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-09 835584]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-12 623992]
"VAIOSecurity"="c:\program files\Sony\VAIO Security Center\VSC.exe" [2007-03-14 2322432]
"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2007-02-08 411768]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-05-08 86016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-08 81920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-08 8429568]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-17 28672]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-04-02 321656]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-02-12 174872]
"AppMon Utility"="c:\program files\Sony\AppMonUtil\AppMonUtility.exe" [2007-04-12 415864]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-02-21 366400]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-03-06 236016]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-15 198160]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-26 148888]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-03-28 4390912]

c:\users\jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2008-10-16 3450608]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe [2008-1-24 295606]
Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2008-2-16 738968]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-04-24 00:19 98304 —-a-w- c:\windows\System32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{B2B2D27B-98F2-49F0-B07D-5A9B4373B84D}"= UDP:c:\program files\Sony\LocationFreePlayer\LFPC3\LFPC3.exe:LocationFree Player
"{646451B4-FE5B-418A-9EAF-07491CCD0409}"= TCP:c:\program files\Sony\LocationFreePlayer\LFPC3\LFPC3.exe:LocationFree Player
"{D1802DF7-6891-49D1-B8C8-6C49CCA9CD0B}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{3DC44E21-133D-4D43-9EE4-188960969E63}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{7AE6069F-9BCB-4897-A566-F0514E4F8940}"= Disabled:UDP:c:\program files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{58A6CF64-127E-425F-8801-8B518B653A1D}"= Disabled:TCP:c:\program files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{766EB3B3-6AA0-47E8-84F2-1AED63E682E8}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{565B7903-252E-45EB-BEFE-E93F953D39AF}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{747AE73B-1D89-4681-BEF6-254C034E2648}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{8A9F55DF-8740-48CA-BC1F-5C2CB751D354}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{CC9F93C8-491D-4D35-96C9-519E37618A50}"= UDP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{9C2C1816-5074-4570-B1DD-07BAC599585E}"= TCP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{E92C8746-0230-4460-B53D-8973A35CA6EC}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{688B854E-44F4-4023-801D-478890CC58E3}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{86D23BD2-A24D-4FEF-80EF-73EF0C06A477}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{46BB4DB5-BA89-4801-B69B-D4A8B65BB2BB}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{16BB9C54-AFA8-4956-8256-D197F5F87AF7}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{CFD61583-6D0F-4ECF-90BD-C0B5471C220C}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{C30C879A-2A97-4D1A-B4DA-F332D5E359E9}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{6F5506B4-0D8A-4746-A760-032CAFEF58E8}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{1565D5C6-F7F6-42E8-A7BE-4189D571611A}"= UDP:3703:Adobe Version Cue CS3 Server
"{C555D3C1-46C9-4805-8A60-A656921C2DF6}"= UDP:3704:Adobe Version Cue CS3 Server
"{E3BF3FF4-D219-4F77-A50A-5FCF17CF26EC}"= UDP:50900:Adobe Version Cue CS3 Server
"{9CF68788-735D-436C-9BEF-4358ECBD0AF8}"= UDP:50901:Adobe Version Cue CS3 Server
"{D609E531-7C0D-422A-8BFD-4BD68D51A9C2}"= UDP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{F72220DC-2EFC-4E46-9D3D-54741DC22CA1}"= TCP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{D8AFFEE4-C391-4082-8F6C-88F576C19389}"= UDP:3703:Adobe Version Cue CS3 Server
"{EDB44D35-8E26-4BF4-9D18-6DEA1DD6B502}"= UDP:3704:Adobe Version Cue CS3 Server
"{B60598B1-8221-4FF9-8095-CC8EC7DF2F5F}"= UDP:50900:Adobe Version Cue CS3 Server
"{FFCC6807-22D6-4726-8AF9-023A8F047BF3}"= UDP:50901:Adobe Version Cue CS3 Server
"{4AED6625-81FF-42BE-9642-0EC2DD81BEB5}"= UDP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{7E712E0F-F19B-4703-9122-326AF3E002A2}"= TCP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{58781EAA-2583-4CBA-929F-9C6B75FA6B8E}"= Disabled:UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{328719D2-742C-44DB-AA4B-ECA5C4861BB4}"= Disabled:TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{86A2DBB2-9710-46D4-87CF-B2202AE84D7C}"= UDP:c:\windows\System32\lxdccoms.exe:Lexmark Communications System
"{B9336D20-22F5-4FB8-8BAB-FA1B4DECE21A}"= TCP:c:\windows\System32\lxdccoms.exe:Lexmark Communications System
"{05B55E16-2730-4721-BC32-D5C6C6971529}"= UDP:c:\program files\Lexmark 1300 Series\lxdcamon.exe:Lexmark Device Monitor
"{8AFE7321-C84C-46D1-A4CC-C2609A090246}"= TCP:c:\program files\Lexmark 1300 Series\lxdcamon.exe:Lexmark Device Monitor
"{FBBCC76C-4C8F-45A0-B96E-05B73412310F}"= UDP:c:\program files\Lexmark 1300 Series\App4R.exe:Lexmark Imaging Studio
"{857A2126-90A1-47B0-9F71-06D4318934BD}"= TCP:c:\program files\Lexmark 1300 Series\App4R.exe:Lexmark Imaging Studio
"{4D6B2D22-8323-47AB-806D-CA5AC37B3B9B}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxdcpswx.exe:
"{B67B3776-E815-43F0-AEAD-CB7AC96E5A3B}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxdcpswx.exe:
"{E040BDFA-3F02-4C97-B49D-6FA0BD948336}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxdcjswx.exe:
"{41BF51B6-4AEC-427A-9A33-D5E1FB3526E1}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxdcjswx.exe:
"{F2074D86-2DFB-4974-BFB5-707B8A380A61}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxdctime.exe:
"{201C1480-CC0D-4E37-A002-568B2005D105}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxdctime.exe:
"{1FD43BDA-F75D-49BD-BB6E-2F20BD1F184A}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{7B2AFC58-865F-49D0-93D9-E978CFD3F91A}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{1546DC7A-BEF7-4C5B-8581-613B46233BB3}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{D153DA1B-D484-43B9-BCBC-A32567B59E81}"= UDP:58817:Pando P2P TCP Listening Port
"{6E109836-7070-4707-BB59-C7D9101660F3}"= TCP:58817:Pando P2P UDP Listening Port
"{BAA1FDBD-CE88-48E1-A669-5C521A091C26}"= UDP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{2E45C88E-646E-4642-A8D1-F242DCBE7E59}"= TCP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{EE89D57F-8C8C-449E-A2FA-E219F9A59DE0}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{3029BFE7-601C-406F-BACE-9E979BB2729F}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{2012A7A8-9187-487A-BD73-DBEA0690F7AE}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{1CF1866C-D540-4205-9B9A-128CC50EA982}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{9170339F-B3CA-4B0A-B604-C8561B8EB5C0}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"{D2A147FF-90B0-4290-9303-DE349A980A43}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent (TCP-In)
"{64404410-2090-4F21-898C-C7D765E8AB6B}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent (UDP-In)
"TCP Query User{5A1D7A1C-FBC8-47D1-BF60-760AD34A35FB}c:\\program files\\adobe\\adobe dreamweaver cs3\\dreamweaver.exe"= UDP:c:\program files\adobe\adobe dreamweaver cs3\dreamweaver.exe:Adobe Dreamweaver CS3
"UDP Query User{F511655C-C0D7-4621-8B73-3F8BFD71C117}c:\\program files\\adobe\\adobe dreamweaver cs3\\dreamweaver.exe"= TCP:c:\program files\adobe\adobe dreamweaver cs3\dreamweaver.exe:Adobe Dreamweaver CS3

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

R0 AFS;AFS;c:\windows\System32\drivers\AFS.SYS [1/28/2008 1:19 AM 79052]
R2 lxdc_device;lxdc_device;c:\windows\system32\lxdccoms.exe -service –> c:\windows\system32\lxdccoms.exe -service [?]
R2 MSSQL$VAIO_VEDB;SQL Server (VAIO_VEDB);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [11/24/2008 10:31 PM 29263712]
R2 regi;regi;c:\windows\System32\drivers\regi.sys [4/17/2007 11:09 PM 11032]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\System32\drivers\R5U870FLx86.sys [5/29/2007 10:38 PM 73472]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\System32\drivers\R5U870FUx86.sys [5/29/2007 10:38 PM 43904]
R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\System32\drivers\SonyImgF.sys [5/29/2007 11:26 PM 31104]
R3 ti21sony;ti21sony;c:\windows\System32\drivers\ti21sony.sys [4/23/2007 2:29 PM 812544]
S2 lxdcCATSCustConnectService;lxdcCATSCustConnectService;c:\windows\System32\spool\drivers\w32x86\3\lxdcserv.exe [4/30/2007 4:04 PM 99248]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\drivers\ASPI32.SYS [1/6/2009 10:26 AM 84832]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [7/18/2008 11:01 AM 33176]
S3 ICScsiSV;Image Converter SCSI Service;c:\program files\Sony\Image Converter 3\ICScsiSV.exe [6/5/2007 9:36 AM 75952]
S3 IcVzMonLauncher;IcVzMonLauncher;c:\program files\Sony\Image Converter 3\IcVzMonLauncher.exe [6/5/2007 9:36 AM 67760]
S3 slim;Sony Lucid Integrated Mpeg encoder;c:\windows\System32\drivers\slim.sys [5/29/2007 10:51 PM 699520]
S4 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\Sony\VAIO Media Integrated Server\UCLS.exe [6/5/2007 10:17 AM 745472]
S4 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [6/5/2007 10:17 AM 397312]
S4 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [6/5/2007 10:17 AM 1089536]

— Other Services/Drivers In Memory —

*Deregistered* - sptd

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder

2009-06-03 c:\windows\Tasks\User_Feed_Synchronization-{2958714F-C4A5-4623-B88B-A8A30EFE3942}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-ISUSPM - c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
HKLM-Run-Corel Photo Downloader - c:\program files\Corel\Corel Snapfire\Corel PhotoDownloader.exe
HKLM-Run-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
SafeBoot-procexp90.Sys


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
FF - ProfilePath - c:\users\jeff\AppData\Roaming\Mozilla\Firefox\Profiles\hi30mrvu.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - component: c:\users\jeff\AppData\Roaming\Mozilla\Firefox\Profiles\hi30mrvu.default\extensions\{D249FD00-4DF9-11D9-9FDC-0080481ADA61}\components\mpint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-03 12:02
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3439640332-1277375291-2842798246-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6DDF2296-D220-43C2-1C3A-B983307F2C81}*]
"oacfkkahldhphjnpnmnmemobncejag"=hex:69,61,63,69,61,69,64,67,68,6f,65,66,6c,6a,
70,69,63,69,00,00
"nameaagljndhecijdbnnhojjmble"=hex:69,61,63,69,61,69,64,67,68,6f,65,66,6c,6a,
70,69,63,69,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{20aad932-494b-4675-8210-c04651858cc5}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:12020054
"Dhcpv6State"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{3e4c17bd-574c-482d-8cad-663222f909f4}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:0e0006bb
"Dhcpv6State"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{7b40f1ce-74b3-4fa9-a7b8-5d06348e70c9}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:0c0013a9
"Dhcpv6State"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{98732e4d-8fec-4f61-b9ed-4b6eec82549a}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:0e000000
"Dhcpv6State"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{9c642153-bfe0-4511-a0b6-e778ddd5ea9e}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:07001422
"Dhcpv6State"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{de01f366-fb7e-4596-82d0-9e1a860c20c6}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:100013e8
"Dhcpv6State"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{f50c0996-5b4a-4c6a-a322-6e991d4caa0e}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:06001422
"Dhcpv6State"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(2456)
c:\program files\Stardock\ObjectDock\DockShellHook.dll
c:\program files\ScanSoft\OmniPageSE2.0\ophookSE2.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\audiodg.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\windows\System32\lxdccoms.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\System32\stacsv.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\windows\System32\drivers\XAudio.exe
c:\program files\Sony\VAIO Event Service\VESMgrSub.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe
c:\program files\Sony\VAIO Update 3\VAIOUpdt.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\Sony\VAIO Power Management\SPMgr.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\ehome\mcupdate.exe
.
**************************************************************************
.
Completion time: 2009-06-03 12:11 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-03 16:11

Pre-Run: 28,659,859,456 bytes free
Post-Run: 29,455,233,024 bytes free

344 — E O F — 2009-05-27 17:01

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI