lin0056
Topic Starter
Hi guys, I have some suspicious processes running which I believe may possibly be viruses.
iexplore.exe
Sachiel.sys.bat
Internet Explorer is never running yet the process for it is always there. Even when I end it, it comes back.
My computer runs normally but I'd just like to make sure these are safe and I have no viruses on my computer.
I also have a hidden folder in my Program Files folder called HaRepacker, which I can't delete.
My laptop is a school laptop connected to a network. -Acer TravelMate 6293
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 16:58:44.21 on Thu 19/11/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.1977.1190 [GMT 11:00]
AV: Sophos Anti-Virus *On-access scanning disabled* (Updated) {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\ifxspmgt.exe
C:\WINDOWS\system32\IFXTCS.exe
C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\IfxPsdSv.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\PLFSetI.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\Program Files\Infineon\Security Platform Software\PSDrt.exe
C:\Program Files\Infineon\Security Platform Software\SpTna.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\DOCUME~1\12linnz\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\12linnz\Desktop\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://intranet.cgs.vic.edu.au
uDefault_Page_URL = hxxp://intranet.cgs.vic.edu.au
mDefault_Page_URL = hxxp://intranet.cgs.vic.edu.au
uInternet Settings,ProxyOverride = local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Sophos Web Content Scanner: {39ea7695-b3f2-4c44-a4bc-297ada8fd235} - c:\program files\sophos\sophos anti-virus\SophosBHO.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [AzMixerSel] c:\program files\realtek\audio\installshield\AzMixerSel.exe
mRun: [ZPdtWzdVitaKey MC3000] "c:\program files\acer\acer bio protection\PdtWzd.exe" show
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [IFXSPMGT] c:\windows\system32\ifxspmgt.exe /NotifyLogon
mRun: [PLFSetI] c:\windows\PLFSetI.exe
mRun: [PLFSetL] c:\windows\PLFSetL.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [LManager] c:\progra~1\launch~1\LManager.exe
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: []
mRun: [Adobe_ID0ENQBO] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoup~1.lnk - c:\program files\sophos\autoupdate\ALMon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {10954C80-4F0F-11d3-B17C-00C0DFE39736} - c:\program files\acer\acer bio protection\PwdBank.exe
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
Notify: AWinNotifyVitaKey MC3000 - c:\program files\acer\acer bio protection\WinNotify.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\sophos\sophos~1\SOPHOS~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Notification Packages = scecli c:\program files\acer\acer bio protection\PwdFilter
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\12linnz\applic~1\mozilla\firefox\profiles\ehr3xlul.default\
FF - plugin: c:\documents and settings\12linnz\application data\mozilla\firefox\profiles\ehr3xlul.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npBFHUpdater.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 AlfaFF;AlfaFF File System mini-filter;c:\windows\system32\drivers\AlfaFF.sys [2008-10-22 43184]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [2007-7-24 38816]
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [2009-8-3 110848]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [2009-8-3 38528]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};c:\program files\cyberlink\powerdvd\000.fcl [2008-11-20 13560]
R2 FPSensor;LTT-Corp Fingerprint Reader Driver (FPSensor.sys);c:\windows\system32\drivers\FPSensor.sys [2008-10-22 20352]
R2 IGBASVC;iGroupTec Service;c:\program files\acer\acer bio protection\BASVC.exe [2008-10-22 3481600]
R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\sophos\sophos anti-virus\SAVAdminService.exe [2009-10-29 80936]
R2 SAVService;Sophos Anti-Virus;c:\program files\sophos\sophos anti-virus\SavService.exe [2009-8-3 98304]
R2 Sophos Agent;Sophos Agent;c:\program files\sophos\remote management system\ManagementAgentNT.exe [2009-8-3 266240]
R2 Sophos AutoUpdate Service;Sophos AutoUpdate Service;c:\program files\sophos\autoupdate\ALsvc.exe [2009-7-2 172032]
R2 Sophos Message Router;Sophos Message Router;c:\program files\sophos\remote management system\RouterNT.exe [2009-8-3 794624]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2007-7-24 41216]
R3 ITEIRDA;ITE Infrared Device Driver;c:\windows\system32\drivers\ITEirda.sys [2008-10-22 24576]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\common files\adobe\adobe version cue cs4\server\bin\VersionCueCS4.exe [2008-8-15 284016]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2009-11-16 25832]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\12linnz\locals~1\temp\kpn97.tmp –> c:\docume~1\12linnz\locals~1\temp\KPN97.tmp [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 tap0901;TAP-Win32 Adapter V9;c:\windows\system32\drivers\tap0901.sys [2009-7-23 28592]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2006-2-28 14336]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [2009-8-3 14976]
=============== Created Last 30 ================
2009-11-17 19:56 107,888 ac—— c:\windows\system32\CmdLineExt.dll
2009-11-17 16:37 -cd—– c:\docume~1\alluse~1\applic~1\BioWare
2009-11-17 11:50 -cd—– c:\windows\system32\winrm
2009-11-17 11:50 -cd-h— c:\windows\$968930Uinstall_KB968930$
2009-11-16 18:31 -cd—– c:\windows\1C4551A64743409391E41477CD655043.TMP
2009-11-16 17:57 -cd—– c:\program files\Dragon Age
2009-11-16 17:57 -cd—– c:\program files\common files\BioWare
2009-11-16 17:15 -cd—– c:\program files\Rockstar Games
2009-11-13 00:21 -cd—– C:\Log
2009-11-12 16:02 -cd—– c:\program files\SAW
2009-11-11 16:16 -cd—– c:\program files\Machinarium
2009-11-10 18:25 -cd—– c:\windows\D56B0E274A3E46C9B5C1D93D580C099C.TMP
2009-11-10 17:44 -cd—– c:\program files\2K Games
2009-11-10 17:44 -cd—– C:\BDS
2009-11-08 23:22 -cd—– c:\windows\system32\Adobe
2009-11-05 21:37 -cd—– c:\docume~1\12linnz\applic~1\runic games
2009-11-05 21:15 -cd—– c:\program files\Runic Games
2009-11-03 21:36 -cd—– c:\docume~1\12linnz\applic~1\MozillaControl
2009-11-03 21:35 -cd—– c:\program files\Mozilla ActiveX Control v1.7.12
2009-11-03 21:34 -cd—– c:\program files\VideoLAN
2009-11-03 21:30 -cd—– c:\program files\Graboid
2009-11-02 23:07 -cd—– c:\program files\iPod
2009-10-23 19:28 2,395,944 ac—— c:\windows\system32\pbsvc_heroes.exe
==================== Find3M ====================
2009-11-04 16:34 139,456 ac—— c:\windows\system32\drivers\PnkBstrK.sys
2009-11-04 16:34 190,160 ac—— c:\windows\system32\PnkBstrB.exe
2009-10-23 19:28 138,056 ac—— c:\docume~1\12linnz\applic~1\PnkBstrK.sys
2009-10-23 19:28 75,064 ac—— c:\windows\system32\PnkBstrA.exe
2009-10-19 16:39 77,028 ac–h— c:\windows\system32\mlfcache.dat
2009-10-11 04:17 411,368 ac—— c:\windows\system32\deploytk.dll
2009-10-09 16:23 1,107,456 -c—— c:\windows\system32\WsmSvc.dll
2009-10-09 16:23 178,176 -c—— c:\windows\system32\wevtfwd.dll
2009-10-09 16:22 368,640 -c—— c:\windows\system32\WsmRes.dll
2009-10-09 16:22 69,632 -c—— c:\windows\system32\winrs.exe
2009-10-09 16:22 42,496 -c—— c:\windows\system32\pwrshplugin.dll
2009-10-09 14:56 209,408 -c—— c:\windows\system32\WsmWmiPl.dll
2009-10-09 14:56 14,848 -c—— c:\windows\system32\wsmprovhost.exe
2009-10-09 14:56 22,528 -c—— c:\windows\system32\winrshost.exe
2009-10-09 14:56 25,088 -c—— c:\windows\system32\winrmprov.dll
2009-10-09 14:56 12,288 -c—— c:\windows\system32\wsmplpxy.dll
2009-10-09 14:56 2,048 -c—— c:\windows\system32\winrsmgr.dll
2009-10-09 14:56 233,984 -c—— c:\windows\system32\winrscmd.dll
2009-10-09 14:56 225,280 -c—— c:\windows\system32\wsmanhttpconfig.exe
2009-10-09 14:56 12,288 -c—— c:\windows\system32\winrssrv.dll
2009-10-09 14:56 139,776 -c—— c:\windows\system32\WsmAuto.dll
2009-10-08 14:57 611,328 ac—— c:\windows\system32\uiautomationcore.dll
2009-10-08 14:57 220,160 ac—— c:\windows\system32\oleacc.dll
2009-10-08 14:56 20,480 ac—— c:\windows\system32\oleaccrc.dll
2009-09-19 13:12 794,408 ac—— c:\windows\system32\pbsvc.exe
2009-09-18 17:39 444,952 ac—— c:\windows\system32\wrap_oal.dll
2009-09-18 17:39 109,080 ac—— c:\windows\system32\OpenAL32.dll
2009-09-11 23:30 25,268 -c–h— c:\docume~1\12linnz\applic~1\addons.dat
2009-09-04 18:44 515,416 ac—— c:\windows\system32\XAudio2_5.dll
2009-09-04 18:44 238,936 ac—— c:\windows\system32\xactengine3_5.dll
2009-09-04 18:44 69,464 ac—— c:\windows\system32\XAPOFX1_3.dll
2009-09-04 18:29 453,456 ac—— c:\windows\system32\d3dx10_42.dll
2009-09-04 18:29 235,344 ac—— c:\windows\system32\d3dx11_42.dll
2009-09-04 18:29 5,501,792 ac—— c:\windows\system32\d3dcsx_42.dll
2009-09-04 18:29 1,974,616 ac—— c:\windows\system32\D3DCompiler_42.dll
2009-09-04 18:29 1,892,184 ac—— c:\windows\system32\D3DX9_42.dll
2009-08-28 20:42 2,065,696 ac—— c:\windows\system32\usbaaplrc.dll
2003-06-09 07:56 23,552 -c-sh— c:\windows\help\Sachiel.sys.bat
2003-06-09 07:56 23,552 -c-sh— c:\windows\system32\helpdks.dll
2003-06-09 07:56 23,552 -c-sh— c:\windows\system32\winrun.sys.pif
============= FINISH: 16:59:15.06 ===============
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/11/19 17:00
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0x9F7AF000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBA604000 Size: 8192 File Visible: No Signed: -
Status: -
Name: PCI_PNP1570
Image Path: \Driver\PCI_PNP1570
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0x9E437000 Size: 49152 File Visible: No Signed: -
Status: -
Name: spis.sys
Image Path: spis.sys
Address: 0xB9EA6000 Size: 1052672 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
SSDT
——————-
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys" at address 0x9f9b0fa0
#: 063 Function Name: NtDeleteKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys" at address 0x9f9b10f6
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "spis.sys" at address 0xb9ec5ca4
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "spis.sys" at address 0xb9ec6032
#: 119 Function Name: NtOpenKey
Status: Hooked by "spis.sys" at address 0xb9ea70c0
#: 160 Function Name: NtQueryKey
Status: Hooked by "spis.sys" at address 0xb9ec610a
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "spis.sys" at address 0xb9ec5f8a
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys" at address 0x9f9b115c
==EOF==
EDIT: I'm going to be away until Thursday 26th November.