I am on a dual boot system dual boot Windows XP Pro SP3 and Vista 64bit Ultimate but this relates for now on Windows XP Pro. I noticed unusual activity on my hard drive when not in use. It will start accessing the hard drive for long periods of time. I launched MS procexp.exe and notice a large number of processes occurring Improcserv32 and svchost processes. I did a netstart with various switches -anfotr and notice a large number of connections to various tcp and udp ports from ip addresses I did not recognize. On whois some are in foreign countries.
I believe that my system is compromised by a rootkit or backdoor trojan or hidden services as my Avira, malwarebytes, Superantispyware, sypbot, spywareblaster, & winpatrol show that my system is clean. I added Online Armor firewall thinking that would help but to know avail. So I suspect some rogue software is hidden below their scans.
Can any one help me or point me to the right direction. I do a lot of financial transactions. I use firefox and use cc cleaner after each internet connection.
Thanks
Hi,
please do the following:
Please download
exeHelper to your desktop.
Double-click on exeHelper.com to run the fix. A black window should pop up, press any key to close once the fix is completed. Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
NEXT
Please download
DDS from either of these links
LINK 1
LINK 2
and save it to your
desktop.
Disable any script blocking protection Double click dds.pif to run the tool. When done, two DDS.txt's will open. Save both reports to your desktop. —————————————————
Please include the contents of the following in your next reply:
DDS.txt
Attach.txt .
NEXT
[external image: Posted Image]
Download
GMER Rootkit Scanner from
here or
here .
Extract the contents of the zipped file to desktop. Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent . If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO .
[external image: Posted Image]
Click the image to enlarge it
In the right panel, you will see several boxes that have been checked. Uncheck the following … Sections IAT/EAT Drives/Partition other than Systemdrive (typically C:\) Show All (don't miss this one) Then click the Scan button & wait for it to finish. Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and post it in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
exeHelper by Raktor
Build 20091220
Run at 20:27:32 on 12/28/09
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Checking for bad files…
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–
exeHelper by Raktor
Build 20091220
Run at 20:51:34 on 12/28/09
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Checking for bad files…
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–
DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 14:38:07.75 on Sat 12/12/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2116 [GMT -8:00]
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Online Armor Firewall *enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Tall Emu\Online Armor\OAcat.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Common Files\Apricorn\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
svchost.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Pa-software\Disc Image Demo\dimsvc.exe
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\Program Files\Gizmo\gservice.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Apricorn\SMART-ER\SMART-ER Service.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Tall Emu\Online Armor\oaui.exe
C:\Program Files\Tall Emu\Online Armor\OAhlp.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrolEx.exe
C:\Program Files\Wisdom-soft ScreenHunter 5 Free\ScreenHunter.exe
C:\Documents and Settings\JUNE\Desktop\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Documents and Settings\June\Desktop\VIRUS SCAN PROCEDURES &PROGRAMS\dds.scr
============== Pseudo HJT Report ===============
uLocal Page = hxxp://www.msn.com
uSearch Page = hxxp://google.com
uDefault_Page_URL = hxxp://www.msn.com
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
{5ca3d70e-1895-11cf-8e15-001234567890}
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO: Encarta Web Companion Helper Object: {955be0b8-bc85-4caf-856e-8e0d8b610560} - c:\program files\common files\microsoft shared\encarta web companion\2007\ENCWCBAR.DLL
BHO: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\4.1.805.4472\swg.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: 1 (0x1) - No File
BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: Encarta Web Companion: {147d6308-0614-4112-89b1-31402f9b82c4} - c:\program files\common files\microsoft shared\encarta web companion\2007\ENCWCBAR.DLL
TB: Hotmail Spam Filter: {58a83e4f-477a-4a3f-bf9b-b65bc2bd5598} - c:\program files\sunbelt software\ihatespam\siClientUIHotmail.dll
TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide
mRun: [nwiz] nwiz.exe /install
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [@OnlineArmor GUI] "c:\program files\tall emu\online armor\oaui.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
IE: &Clean Traces - c:\program files\dap\privacy package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\dap\dapextie.htm
IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: Download &all with DAP - c:\program files\dap\dapextie2.htm
IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi1933~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
IE: {B6F776D7-C231-11D4-8158-005004ADEFCA} - {B3FD2434-2839-4750-A849-FF8FC0C54E5F} - c:\program files\software river solutions\visual whois 2004\srstools.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/su/ocx/15026/CTSUEng.cab
DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} - hxxp://download.microsoft.com/download/7/0/7/707a44ad-52ad-49af-b7ef-e21b6b0656e4/VirtualEarth3D.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} - hxxp://download.microsoft.com/download/7/1/D/71D9F11F-0C02-4707-9D60-D56EA8951020/pmupd806.exe
DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} - hxxps://actsvr.comcastonline.com/techtools/dl/Comcast%20Activation%20Controls.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1166092553967
DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://support.f-secure.com/ols/fscax.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/su/ocx/15028/CTPID.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} - c:\program files\microsoft activesync\aatp.dll
Handler: msell2 - {9367D24B-8506-471A-915A-CFBB4BCEB631} - c:\program files\common files\microsoft shared\reference titles\MSELL2.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll
WinCE Filter: image/bmp - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\progra~1\mi3aa1~1\CENetFlt.dll
WinCE Filter: image/gif - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\progra~1\mi3aa1~1\CENetFlt.dll
WinCE Filter: image/jpeg - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\progra~1\mi3aa1~1\CENetFlt.dll
WinCE Filter: image/xbm - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\progra~1\mi3aa1~1\CENetFlt.dll
WinCE Filter: text/asp - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\progra~1\mi3aa1~1\CENetFlt.dll
WinCE Filter: text/html - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\progra~1\mi3aa1~1\CENetFlt.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: DPWLN -
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SEH: OA Shell Helper: {4f07da45-8170-4859-9b5f-037ef2970034} - c:\progra~1\tallem~1\online~1\oaevent.dll
LSA: Authentication Packages = msv1_0 relog_ap
LSA: Notification Packages = scecli DPPWDFLT
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\June\applic~1\mozilla\firefox\profiles\c5k4s1z3.default\
FF - prefs.js: browser.startup.homepage - msn.com
FF - component: c:\documents and settings\June\application data\mozilla\firefox\profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
FF - component: c:\documents and settings\june\application data\mozilla\firefox\profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
FF - component: c:\program files\dap\dapfirefox\components\DAPFireFox.dll
FF - plugin: c:\documents and settings\june
\application data\mozilla\firefox\profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\google\google earth plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox 3.55\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R0 AVG Anti-Rootkit;AVG Anti-Rootkit;c:\windows\system32\drivers\avgarkt.sys [2007-1-31 5632]
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2009-3-12 40368]
R1 AvgArCln;Avg Anti-Rootkit Clean Driver;c:\windows\system32\drivers\AvgArCln.sys [2007-9-20 3968]
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-5-28 11608]
R1 DiscImage;Disc image driver;c:\windows\system32\drivers\discimage.sys [2007-5-26 24704]
R1 GizmoDrv;Gizmo Device Driver;c:\windows\system32\drivers\gizmodrv.sys [2009-4-30 23624]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2009-5-28 196688]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2009-5-28 31824]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [2009-5-28 29776]
R1 pfmfs_27B;pfmfs_27B;c:\windows\system32\drivers\pfmfs_27B.sys [2009-4-30 179896]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2008-8-19 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-8-19 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2009-5-28 1858144]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-5-28 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-5-28 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-5-28 56816]
R2 DIMSVC;Disc Image Demo mount service;c:\program files\pa-software\disc image demo\dimsvc.exe [2007-5-26 36864]
R2 Gizmo Central;Gizmo Central;c:\program files\gizmo\gservice.exe [2009-4-30 31856]
R2 OAcat;Online Armor Helper Service;c:\program files\tall emu\online armor\oacat.exe [2009-5-28 361160]
R2 SMART-ERService;SMART-ER Service;c:\program files\apricorn\smart-er\SMART-ER Service.exe [2007-6-4 69632]
R2 SvcOnlineArmor;Online Armor;c:\program files\tall emu\online armor\oasrv.exe [2009-5-28 3049160]
R2 VirtualDrive;VirtualDrive;c:\program files\all image\vdd-x86.sys [2009-4-30 10752]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [2008-4-19 30560]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-8-19 7408]
S1 AntiLog32;AntiLog32;\??\c:\program files\antilogger\antilog32.sys –> c:\program files\antilogger\AntiLog32.sys [?]
S2 AnonMgmtSvc;Anonymizer Management Service;"c:\program files\anonymizer\anonymizer software\common\anonmgmtsvc.exe" –> c:\program files\anonymizer\anonymizer software\common\AnonMgmtSvc.exe [?]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\june\locals~1\temp\alsysio.sys –> c:\docume~1\june\locals~1\temp\ALSysIO.sys [?]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2008-6-27 99352]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2008-6-27 99352]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2008-6-27 555032]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2008-6-27 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2008-6-27 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2008-6-27 100888]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2008-6-27 566296]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2008-6-27 566296]
S3 dpK0Bx01;Fingerprint Reader Filter Driver;c:\windows\system32\drivers\dpK0Bx01.sys [2007-1-5 35584]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2009-3-24 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2009-3-24 3072]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\lavalys\everest home edition\kerneld.wnt [2005-8-17 7168]
S3 IntelDH;IntelDH Driver;c:\windows\system32\drivers\inteldh.sys –> c:\windows\system32\drivers\IntelDH.sys [?]
S3 SWUSBFLT;Microsoft SideWinder VIA Filter Driver;c:\windows\system32\drivers\SWUSBFLT.SYS [2006-12-22 3968]
S3 UsbdpFP;Fingerprint Reader Class Driver;c:\windows\system32\drivers\usbdpfp.sys [2007-1-5 47360]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [2006-12-12 2385896]
S3 xusb20;Xbox 360 Wireless Receiver for Windows Driver Service;c:\windows\system32\drivers\xusb20.sys [2006-10-13 50048]
S3 yeddef;YEDDEF driver;c:\windows\system32\drivers\yeddef.sys –> c:\windows\system32\drivers\yeddef.sys [?]
S3 ZD1211U(Hawking Technologies);Hawking Technologies HWU54D Hi-Gain Wireless-G USB Adapter(Hawking Technologies);c:\windows\system32\drivers\ZD1211U.sys [2006-12-6 233472]
S4 gupdate1c901a09a323bba;Google Update Service (gupdate1c901a09a323bba);c:\program files\google\update\GoogleUpdate.exe [2008-8-18 133104]
S4 NSLHNZKPEI;NSLHNZKPEI;c:\docume~1\june\locals~1\temp\nslhnzkpei.exe –> c:\docume~1\june\locals~1\temp\NSLHNZKPEI.exe [?]
S4 TABKB;TABKB;c:\docume~1\june\locals~1\temp\tabkb.exe –> c:\docume~1\june\locals~1\temp\TABKB.exe [?]
=============== Created Last 30 ================
2009-12-12 08:31:59 15 —-a-w- c:\documents and settings\june\settings.dat
2009-12-12 00:42:32 0 d—–w- c:\program files\MSXML 4.0
2009-12-12 00:37:06 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2009-12-11 21:56:57 0 d—–w- c:\program files\Mozilla Firefox 3.55
==================== Find3M ====================
2009-12-11 20:08:51 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-04 00:14:06 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-04 00:13:56 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-03 04:42:06 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-10-29 07:46:59 832512 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46:52 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46:50 17408 —-a-w- c:\windows\system32\corpol.dll
2009-10-21 05:38:36 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20:16 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30:16 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38:19 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38:18 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-08 22:57:02 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2009-10-08 22:57:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 22:56:56 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2008-09-20 18:42:46 88 –sha-r- c:\windows\system32\892202FEA3.sys
2008-06-13 04:32:03 23 –sha-w- c:\windows\system32\aafcebeaff4_g.dll
2008-09-20 18:43:54 4856 –sha-w- c:\windows\system32\KGyGaAvL.sys
2008-06-11 13:49:32 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008061120080612\index.dat
============= FINISH: 14:40:01.53 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-12-01.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume4
Install Date: 12/14/2006 2:05:00 AM
System Uptime: 12/11/2009 4:54:01 PM (22 hours ago)
Motherboard: Dell Inc. | | 0WG855
Processor: Intel® Core™2 CPU 6600 @ 2.40GHz | Microprocessor | 2394/1066mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 229 GiB total, 8.015 GiB free.
D: is CDROM ()
E: is Removable
F: is FIXED (NTFS) - 385 GiB total, 294.72 GiB free.
G: is FIXED (NTFS) - 547 GiB total, 117.799 GiB free.
H: is FIXED (NTFS) - 501 GiB total, 70.662 GiB free.
I: is Removable
J: is Removable
K: is CDROM ()
L: is Removable
M: is Removable
N: is FIXED (NTFS) - 430 GiB total, 168.489 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: Intel® software driver for Intel® Viiv™ technology
Device ID: ROOT\SYSTEM\0004
Manufacturer: Intel Corporation
Name: Intel® software driver for Intel® Viiv™ technology
PNP Device ID: ROOT\SYSTEM\0004
Service: IntelDH
==== System Restore Points ===================
RP1: 4/28/2009 4:18:56 PM - System Checkpoint
RP2: 4/30/2009 4:44:02 PM - Software Distribution Service 3.0
RP3: 4/30/2009 5:38:38 PM - Software Distribution Service 3.0
RP4: 4/30/2009 7:14:43 PM - SPTD setup V1.58
RP5: 4/30/2009 11:17:56 PM - Installed PC Inspector File Recovery
RP6: 5/2/2009 8:55:06 PM - Installed DirectX
RP7: 5/3/2009 1:36:18 AM - Installed DirectX 9.0
RP8: 5/3/2009 3:12:09 AM - Installed Trainz
RP9: 5/3/2009 3:45:40 AM - Installed TRS2004
RP10: 5/3/2009 3:52:21 AM - Installed Trainz Paint Shed
RP11: 5/3/2009 4:00:38 AM - Installed TRS2006
RP12: 5/3/2009 4:03:56 AM - Installed TRS2006
RP13: 5/3/2009 2:11:22 PM - Installed Silent Hunter Wolves of the Pacific
RP14: 5/3/2009 4:02:53 PM - Installed DirectX
RP15: 5/3/2009 4:04:31 PM - Installed GameShadow
RP16: 5/3/2009 4:05:42 PM - Removed GameShadow
RP17: 5/3/2009 4:05:52 PM - Installed GameShadow
RP18: 5/3/2009 4:13:27 PM - Installed Medieval II Total War
RP19: 5/8/2009 3:57:05 AM - Avg8 Update
RP20: 5/8/2009 4:10:21 AM - Avg8 Update
RP21: 5/8/2009 4:22:54 AM - Software Distribution Service 3.0
RP22: 5/8/2009 4:23:54 AM - Revo Uninstaller's restore point - Medal of Honor Allied Assault
RP23: 5/8/2009 4:24:29 AM - Removed Medal of Honor Allied Assault
RP24: 5/8/2009 4:28:37 AM - Revo Uninstaller's restore point - Medal of Honor Allied Assault™ Breakthrough
RP25: 5/8/2009 4:28:46 AM - Removed Medal of Honor Allied Assault™ Breakthrough
RP26: 5/8/2009 4:30:10 AM - Revo Uninstaller's restore point - Medal of Honor Allied Assault™ Spearhead
RP27: 5/8/2009 4:30:20 AM - Removed Medal of Honor Allied Assault™ Spearhead
RP28: 5/8/2009 4:31:34 AM - Revo Uninstaller's restore point - Battlefield 2™
RP29: 5/8/2009 4:31:46 AM - Removed Battlefield 2™
RP30: 5/8/2009 4:34:41 AM - Revo Uninstaller's restore point - Battlefield 2: Special Forces
RP31: 5/8/2009 4:34:48 AM - Removed Battlefield 2: Special Forces
RP32: 5/8/2009 4:50:35 AM - Installed Medal of Honor Allied Assault
RP33: 5/8/2009 5:10:38 AM - Removed Medal of Honor Allied Assault UK & US 1.11 Patch
RP34: 5/8/2009 5:19:53 AM - Installed Medal of Honor Allied Assault™ Spearhead
RP35: 5/8/2009 5:21:05 AM - Installed Medal of Honor Allied Assault™ Spearhead
RP36: 5/8/2009 5:29:36 AM - Installed Medal of Honor Allied Assault™ Breakthrough
RP37: 5/8/2009 1:45:55 PM - Installed AGEIA PhysX v7.07.09
RP38: 5/8/2009 1:54:27 PM - Installed Medal of Honor Airborne
RP39: 5/8/2009 1:58:21 PM - Installed Battlefield 2™
RP40: 5/8/2009 2:04:22 PM - Installed Battlefield 2™
RP41: 5/8/2009 2:14:03 PM - Installed Battlefield 2 Patch
RP42: 5/8/2009 2:19:18 PM - Installed Battlefield 2: Special Forces
RP43: 5/8/2009 2:24:21 PM - Installed Battlefield 2 Patch v1.41
RP44: 5/8/2009 11:58:17 PM - Installed Battlefield 2™
RP45: 5/9/2009 12:10:25 AM - Installed Battlefield 2 Patch v1.41
RP46: 5/9/2009 12:21:07 AM - Installed Battlefield 2: Euro Force Booster Pack
RP47: 5/9/2009 12:22:18 AM - Installed Battlefield 2: Armored Fury Booster Pack
RP48: 5/9/2009 12:26:27 AM - Installed Battlefield 2 Patch v1.41
RP49: 5/9/2009 12:59:47 AM - Installed DirectX 9.0
RP50: 5/9/2009 1:38:02 AM - Installed Medal of Honor Pacific Assault™
RP51: 5/9/2009 1:41:41 AM - Installed Blazing Angels Squadrons of WWII
RP52: 5/9/2009 1:46:37 AM - Installed DirectX
RP53: 5/9/2009 7:54:19 PM - Installed Disc Image Demo
RP54: 5/11/2009 11:10:53 PM - Software Distribution Service 3.0
RP55: 5/12/2009 12:54:47 PM - Avg8 Update
RP56: 5/15/2009 5:50:34 PM - Software Distribution Service 3.0
RP57: 5/15/2009 9:28:43 PM - Software Distribution Service 3.0
RP58: 5/17/2009 8:37:02 PM - Software Distribution Service 3.0
RP59: 5/19/2009 10:57:09 AM - Avg8 Update
RP60: 5/19/2009 11:00:40 AM - Avg8 Update
RP61: 5/19/2009 3:40:09 PM - Software Distribution Service 3.0
RP62: 5/19/2009 5:55:41 PM - Installed WD Diagnostics
RP63: 5/20/2009 11:37:11 AM - Software Distribution Service 3.0
RP64: 5/20/2009 12:32:57 PM - Configured Turbo Lister 2
RP65: 5/28/2009 10:57:23 PM - Avira AntiVir Personal - 5/28/2009 22:57
RP66: 5/28/2009 11:09:38 PM - Software Distribution Service 3.0
RP67: 5/30/2009 12:20:48 AM - Software Distribution Service 3.0
RP68: 5/31/2009 6:02:52 PM - Configured AVG Free 8.5
RP69: 5/31/2009 7:30:42 PM - Configured AVG Free 8.5
RP70: 5/31/2009 7:41:42 PM - Configured AVG Free 8.5
RP71: 5/31/2009 7:45:06 PM - Revo Uninstaller's restore point - avast! Antivirus
RP72: 5/31/2009 7:50:41 PM - Revo Uninstaller's restore point - AVG Free 8.5
RP73: 5/31/2009 7:51:12 PM - Removed AVG 8.5
RP74: 5/31/2009 7:51:48 PM - Installed AVG 8.5
RP75: 6/1/2009 6:18:36 PM - Revo Uninstaller's restore point - Turbo Lister 2
RP76: 6/1/2009 6:18:55 PM - Configured Turbo Lister 2
RP77: 6/1/2009 6:35:50 PM - Configured Turbo Lister 2
RP78: 6/1/2009 6:37:35 PM - Configured Turbo Lister 2
RP79: 6/14/2009 10:51:02 AM - UPDATING VIRUS MICROSOFT
RP80: 6/14/2009 11:11:39 AM - Software Distribution Service 3.0
RP81: 6/14/2009 4:47:25 PM - Revo Uninstaller's restore point - Turbo Lister 2
RP82: 6/14/2009 4:47:37 PM - Configured Turbo Lister 2
RP83: 6/14/2009 5:08:30 PM - Installed Turbo Lister 2
RP84: 6/14/2009 7:29:00 PM - CCleaner june12 2009
RP85: 6/16/2009 8:05:04 PM - Software Distribution Service 3.0
RP86: 6/17/2009 12:42:02 AM - Installed Java™ 6 Update 14
RP87: 6/17/2009 12:49:59 AM - Revo Uninstaller's restore point - Ad-Aware
RP88: 6/17/2009 12:52:12 AM - Revo Uninstaller's restore point - Ad-Aware
RP89: 6/17/2009 1:32:28 AM - Revo Uninstaller's restore point - Ad-Aware
RP90: 6/17/2009 1:32:54 AM - Removed Ad-Aware
RP91: 6/17/2009 1:39:43 AM - Revo Uninstaller's restore point - Ad-Aware
RP92: 6/17/2009 1:41:52 AM - Revo Uninstaller's restore point - Ad-Aware
RP93: 6/18/2009 1:30:49 PM - Software Distribution Service 3.0
RP94: 6/23/2009 1:46:44 AM - Software Distribution Service 3.0
RP95: 6/25/2009 7:40:39 PM - SoundCapture Installation
RP96: 6/25/2009 7:43:59 PM - SoundCapture Installation
RP97: 6/26/2009 12:15:28 AM - Software Distribution Service 3.0
RP98: 7/15/2009 5:58:55 PM - Software Distribution Service 3.0
RP99: 7/26/2009 7:17:43 PM - Software Distribution Service 3.0
RP100: 7/28/2009 8:56:28 PM - Software Distribution Service 3.0
RP101: 8/3/2009 7:49:23 PM - Software Distribution Service 3.0
RP102: 8/4/2009 7:54:38 PM - Software Distribution Service 3.0
RP103: 9/7/2009 1:10:21 PM - Software Distribution Service 3.0
RP104: 9/7/2009 1:26:11 PM - Software Distribution Service 3.0
RP105: 9/7/2009 1:43:27 PM - Revo Uninstaller's restore point - Citrix ICA Web Client
RP106: 9/7/2009 1:45:14 PM - Revo Uninstaller's restore point - Citrix ICA Web Client
RP107: 10/17/2009 7:51:33 PM - Software Distribution Service 3.0
RP108: 10/17/2009 9:17:44 PM - Software Distribution Service 3.0
RP109: 10/17/2009 10:16:55 PM - Software Distribution Service 3.0
RP110: 10/17/2009 10:54:50 PM - Software Distribution Service 3.0
RP111: 10/17/2009 11:10:32 PM - Software Distribution Service 3.0
RP112: 11/1/2009 4:19:03 AM - Restore Operation
RP113: 11/1/2009 3:04:00 PM - Software Distribution Service 3.0
RP114: 11/1/2009 3:38:54 PM - Software Distribution Service 3.0
RP115: 11/1/2009 4:19:29 PM - RESTORE POINT AFTER ERROR ON REGISTRY LOG BOOTUP
RP116: 11/1/2009 4:41:16 PM - Software Distribution Service 3.0
RP117: 12/11/2009 4:41:57 PM - Software Distribution Service 3.0
RP118: 12/11/2009 5:31:01 PM - Software Distribution Service 3.0
RP119: 12/11/2009 5:32:20 PM - Software Distribution Service 3.0
RP120: 12/11/2009 5:38:40 PM - Software Distribution Service 3.0
RP121: 12/11/2009 5:39:47 PM - Software Distribution Service 3.0
==== Installed Programs ======================
a-squared Free 4.5
A4Desk v6.26
AAC Decoder
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop 6.0
Adobe Reader 8.1.2
Adobe Reader 8.1.2 Security Update 1 (KB403742)
Adobe Shockwave Player 11
Adobe SVG Viewer 3.0
AFPL Ghostscript Fonts
Age of Empires III - The WarChiefs
AGEIA PhysX v7.07.09
All Image 1.3.1
AntiLogger
Any Video-Audio Converter 3.3.1
Apricorn EZ Gig II
AutoUpdate
AVG Anti-Rootkit Free
Avira AntiVir Personal - Free Antivirus
Battlefield 2™
Battlefield 2: Special Forces
Battlestations: Midway
BiA Earned in Blood SDK
Blazing Angels Squadrons of WWII
Bonjour
Britannica Ready Reference
Brothers In Arms
Brothers In Arms EiB
BSR Screen Recorder 4
Business Contact Manager for Outlook 2007 SP2
Call of Duty® 2
Call of Duty® 2 Mod Tools
Call of Duty® 2 Patch 1.01
Call of Duty® 2 Patch 1.2
Call of Duty® 2 Patch 1.3
Canon IJ Network Scan Utility
Canon IJ Network Tool
Canon MP Navigator EX 1.1
Canon MX850 series
Canon MX850 series User Registration
Canon Utilities Easy-PhotoPrint EX
Canon Utilities My Printer
Canon Utilities Solution Menu
CaptureWizPro 3.B0
CCleaner
Company of Heroes
Complete Do-It-Yourself Guide
Compton's Interactive Bible NIV
Cookie Pal
Corel Snapfire Plus
Creative Audio Console
Creative WaveStudio 7
Crimson Editor (remove only)
Critical Update for Windows Media Player 11 (KB959772)
Data Lifeguard Tools
Dell CinePlayer
Dell Driver Reset Tool
Dell System Restore
Digital Content Portal
DigitalPersona Password Manager 2.0.0
Disc Image Demo
DiscAPI (Studio 10)
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
Download Accelerator Plus (DAP)
e-Sword
EA Download Manager
Early Church Fathers 2008
EASEUS Partition Manager 3.0 Home Edition
Empire: Total War
Encarta Language Learning French
Encarta Language Learning Spanish
ERUNT 1.1j
EVEREST Home Edition v2.20
Far Cry
ffdshow [rev 1782] [2008-01-15]
Form Fill (Windows Live Toolbar)
FoxyTunes for Firefox
Free YouTube Download 1.3
FSX Flight Weather Report
GameShadow
Garmin Communicator Plugin
Garmin WebUpdater
Gizmo Central
Google Earth Plugin
Google Photos Screensaver
Google Update Helper
Google Updater
H.264 Decoder
Hawking HWU54D Hi-Gain Wireless-G USB Adapter
Highlight Viewer (Windows Live Toolbar)
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
iCall
iHatePopups
iHateSpam
Intel® Matrix Storage Manager
Intel® Network Connections [removed]
ISA 2 basic
IsoBuster 2.5
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 6
Java™ 6 Update 14
Java™ 6 Update 2
Java™ 6 Update 3
Java™ 6 Update 7
Java™ SE Runtime Environment 6 Update 1
JBidwatcher 2
L&H PC/MM ASR1600 for Windows V3 French
L&H PCMM ASR1600 for Windows V3 Basic
L&H PCMM ASR1600 for Windows V3 Engine
L&H PCMM ASR1600 for Windows V3 Mexican Spanish
Learn2 Player (Uninstall Only)
Learning Essentials for Microsoft Office
Madden NFL 2005
Malwarebytes' Anti-Malware
Medal of Honor Allied Assault
Medal of Honor Allied Assault™ Breakthrough
Medal of Honor Allied Assault™ Spearhead
Medieval II Total War
Medieval Total War
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft ActiveSync 3.5
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Baseline Security Analyzer 2.1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Digital Image Library 9 - Blocker
Microsoft Digital Image Suite 2006
Microsoft Digital Image Suite 2006 Editor
Microsoft Digital Image Suite 2006 Library
Microsoft Easy Assist
Microsoft Easy Assist v2
Microsoft Expression Web
Microsoft Expression Web MUI (English)
Microsoft Expression Web Service Pack 1 (SP1)
Microsoft Flight Simulator X
Microsoft Flight Simulator X Photo Scenery Display Update
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft J# Browser Controls v1.1
Microsoft Kernel-Mode Driver Framework Feature Pack 1.1
Microsoft LifeCam
Microsoft Location Finder
Microsoft Math
Microsoft MSDN 2005 Express Edition - ENU
Microsoft National Language Support Downlevel APIs
Microsoft Network Monitor 3.3
Microsoft Network Monitor: Microsoft Parsers 3.3
Microsoft Office 2003 Web Components
Microsoft Office 2007 Primary Interop Assemblies
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Accounting 2007
Microsoft Office Accounting ADP Payroll Addin
Microsoft Office Accounting Equifax Addin
Microsoft Office Accounting Fixed Asset Manager
Microsoft Office Accounting PayPal Addin
Microsoft Office Excel MUI (English) 2007
Microsoft Office FrontPage 2003
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
Microsoft Office Small Business Connectivity Components
Microsoft Office Ultimate 2007
Microsoft Office Visio 2007 Service Pack 2 (SP2)
Microsoft Office Visio MUI (English) 2007
Microsoft Office Visio Professional 2007
Microsoft Office Word MUI (English) 2007
Microsoft Office XP Professional with FrontPage
Microsoft Outlook Personal Folders Backup
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft Student 2007 for Learning Essentials
Microsoft Student with Encarta Premium 2007
Microsoft Train Simulator
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual Web Developer 2005 Express Edition - ENU
Microsoft Visual Web Developer 2005 Express Edition - ENU Service Pack 1 (KB926751)
Microsoft Works
Microsoft XML Parser
MKV Splitter
Mobipocket Reader 6.2
Mozilla Firefox (2.0.0.20)
Mozilla Firefox (3.0.9)
Mozilla Firefox (3.5.5)
MSN Money Investment Toolbox
MSN Money Toolbar Add-in
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
MSXML4 Parser
Nero PhotoShow Express 4
Nikon Message Center
NVIDIA Drivers
NVIDIA nTune
NVIDIA System Monitor
NVIDIA System Update
Octoshape add-in for Adobe Flash Player
OneCare Advisor (Windows Live Toolbar)
Online Armor 3.5
Painter 4.0.3
Panorama Maker
PANZERS - Phase2
Paragon Drive Copy 9.0 Personal Demo
PC Inspector File Recovery
PC Study Bible 3.1
PCFriendly
PDFtypewriter Printer Driver
Pinnacle Instant DVD Recorder
Pinnacle MediaServer
Pismo File Mount Audit Package
Player
Pocket PC Connection Wizard
Popup Blocker (Windows Live Toolbar)
PowerDVD
PowerFile 5.4 Driver
PowerFile C200
PowerISO
Pradis Do Not Remove
Pradis: Greek Grammar Beyond the Basics
Praetorians
Presto! PageManager 7.15.20
proDAD Heroglyph 2.5
Qualxserve Service Agreement
QuickTime
Railroad Tycoon 3
RAPID (Studio 10)
RealPlayer Basic
Recover My Files
RegSupreme
Replay Media Catcher 3.01
Revo Uninstaller 1.83
Rhapsody Player Engine
Rome - Total War
Rome - Total War - Alexander
Rome - Total War - Gold Edition
Roxio Express Labeler
Roxio MyDVD Plus
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
ScanSoft OmniPage SE 4
SearchAssist
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB969693)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975467)
Shockwave
Shopping Cart 3
Silent Hunter III
Silent Hunter Wolves of the Pacific
Skype™ 3.8
SMART-ER
Smart Menus (Windows Live Toolbar)
SmartSound Quicktracks Plugin
Sonic Activation Module
SoundCapture
SpeedFan (remove only)
Spelling Dictionaries Support For Adobe Reader 8
Spybot - Search & Destroy
Spybot - Search & Destroy 1.4
SpywareBlaster 4.2
SpywareGuard v2.2
Startup Mechanic 2.2
Steam
Studio 10
Studio 10 Bonus DVD
SUPERAntiSpyware Free Edition
System Requirements Lab
Tabbed Browsing (Windows Live Toolbar)
TBS WMP Plug-in
Teknia Language Tools (Greek)
The History Channel: Civil War
Trainz
Trainz Paint Shed
TRS2004
TRS2006
Turbo Lister 2
Tweak UI
Typing Tutor 7
Uninstall 1.0.0.0
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Visio 2007 Help (KB963666)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Microsoft Windows (KB971513)
Update for Outlook 2007 Junk Email Filter (kb976884)
Update for Windows XP (KB943729)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
URL Assistant
VC80CRTRedist - 8.0.50727.762
Viewpoint Media Player
Virtual Earth 3D (Beta)
Visual WhoIs 2004
Waterloo - Napoleon's Last Battle
WD Diagnostics
WebFldrs XP
Windows Backup Utility
Windows Defender
Windows Desktop Search 3.0
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Internet Explorer 7
Windows Live Messenger
Windows Live Outlook Toolbar (Windows Live Toolbar)
Windows Live Sign-in Assistant
Windows Live Toolbar
Windows Live Toolbar Extension (Windows Live Toolbar)
Windows Live Toolbar Feed Detector (Windows Live Toolbar)
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows PowerShell™ 1.0
Windows PowerShell™ 1.0 MUI pack
Windows Vista Upgrade Advisor
Windows XP Service Pack 3
WinPatrol 2009
Wisdom-soft ScreenHunter 5.1 Free
WOT for Internet Explorer
X-Lite 3.0
Yahoo! Install Manager
Yahoo! Messenger
==== End Of File ===========================
I got an error message on GMER but ran RootRepeal instead.
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/12/12 01:05
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
——————-
Name: dump_iaStor.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys
Address: 0xB69AE000 Size: 749568 File Visible: No Signed: -
Status: -
Name: giveio.sys
Image Path: giveio.sys
Address: 0xBA670000 Size: 1664 File Visible: No Signed: -
Status: -
Name: PCI_PNP9818
Image Path: \Driver\PCI_PNP9818
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB6539000 Size: 49152 File Visible: No Signed: -
Status: -
Name: speedfan.sys
Image Path: speedfan.sys
Address: 0xBA5B0000 Size: 5248 File Visible: No Signed: -
Status: -
Name: sprt.sys
Image Path: sprt.sys
Address: 0xB9EA6000 Size: 1052672 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Hidden/Locked Files
——————-
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
SSDT
——————-
#: 017 Function Name: NtAllocateVirtualMemory
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2e320
#: 019 Function Name: NtAssignProcessToJobObject
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2e940
#: 031 Function Name: NtConnectPort
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2ce30
#: 037 Function Name: NtCreateFile
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3b420
#: 041 Function Name: NtCreateKey
Status: Hooked by "" at address 0xba6f2746
#: 046 Function Name: NtCreatePort
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2cae0
#: 047 Function Name: NtCreateProcess
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c29db0
#: 048 Function Name: NtCreateProcessEx
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2a180
#: 050 Function Name: NtCreateSection
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c298d0
#: 053 Function Name: NtCreateThread
Status: Hooked by "" at address 0xba6f273c
#: 057 Function Name: NtDebugActiveProcess
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2bdc0
#: 062 Function Name: NtDeleteFile
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3beb0
#: 063 Function Name: NtDeleteKey
Status: Hooked by "" at address 0xba6f274b
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "" at address 0xba6f2755
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2c800
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3b3c0
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3b3f0
#: 097 Function Name: NtLoadDriver
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2ddf0
#: 098 Function Name: NtLoadKey
Status: Hooked by "" at address 0xba6f275a
#: 116 Function Name: NtOpenFile
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3bac0
#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c39f30
#: 122 Function Name: NtOpenProcess
Status: Hooked by "" at address 0xba6f2728
#: 125 Function Name: NtOpenSection
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c29b40
#: 128 Function Name: NtOpenThread
Status: Hooked by "" at address 0xba6f272d
#: 137 Function Name: NtProtectVirtualMemory
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2e5d0
#: 160 Function Name: NtQueryKey
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3b360
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3b390
#: 180 Function Name: NtQueueApcThread
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2eac0
#: 193 Function Name: NtReplaceKey
Status: Hooked by "" at address 0xba6f2764
#: 200 Function Name: NtRequestWaitReplyPort
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2d9a0
#: 204 Function Name: NtRestoreKey
Status: Hooked by "" at address 0xba6f275f
#: 206 Function Name: NtResumeThread
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2c4b0
#: 207 Function Name: NtSaveKey
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3b340
#: 210 Function Name: NtSecureConnectPort
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2d1f0
#: 213 Function Name: NtSetContextThread
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2bbe0
#: 224 Function Name: NtSetInformationFile
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3c170
#: 240 Function Name: NtSetSystemInformation
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2bf40
#: 247 Function Name: NtSetValueKey
Status: Hooked by "" at address 0xba6f2750
#: 249 Function Name: NtShutdownSystem
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2dcf0
#: 253 Function Name: NtSuspendProcess
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2c660
#: 254 Function Name: NtSuspendThread
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2c2e0
#: 255 Function Name: NtSystemDebugControl
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2c120
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys" at address 0xb6c8b0b0
#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2b9c0
#: 262 Function Name: NtUnloadDriver
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2e010
#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2e780
Stealth Objects
——————-
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x8b1131f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP]
Process: System Address: 0x897281f8 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CREATE]
Process: System Address: 0x897f31f8 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CLOSE]
Process: System Address: 0x897f31f8 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_READ]
Process: System Address: 0x897f31f8 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_WRITE]
Process: System Address: 0x897f31f8 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x897f31f8 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_POWER]
Process: System Address: 0x897f31f8 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x897f31f8 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_PNP]
Process: System Address: 0x897f31f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x8b1851f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x8b1851f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x8b1851f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x8b1851f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8b1851f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8b1851f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8b1851f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8b1851f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x8b1851f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8b1851f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x8b1851f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x8a6721f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x8a6721f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a6721f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a6721f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x8a6721f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a6721f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x8a6721f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x8a6211f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x8a6211f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x8a6211f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x8a6211f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a6211f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a6211f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a6211f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a6211f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x8a6211f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a6211f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x8a6211f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x8b1151f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x8b1151f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x8b1151f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8b1151f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8b1151f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8b1151f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8b1151f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x8b1151f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x8b1151f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8b1151f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x8b1151f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x8997a1f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x8997a1f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8997a1f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8997a1f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x8997a1f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x8997a1f8 Size: 121
Object: Hidden Code [Driver: ao063amyజ灐敲, IRP_MJ_CREATE]
Process: System Address: 0x8a6121f8 Size: 121
Object: Hidden Code [Driver: ao063amyజ灐敲, IRP_MJ_CLOSE]
Process: System Address: 0x8a6121f8 Size: 121
Object: Hidden Code [Driver: ao063amyజ灐敲, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a6121f8 Size: 121
Object: Hidden Code [Driver: ao063amyజ灐敲, IRP_MJ_POWER]
Process: System Address: 0x8a6121f8 Size: 121
Object: Hidden Code [Driver: ao063amyజ灐敲, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a6121f8 Size: 121
Object: Hidden Code [Driver: ao063amyజ灐敲, IRP_MJ_PNP]
Process: System Address: 0x8a6121f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x8a65e1f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x8a65e1f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a65e1f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a65e1f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x8a65e1f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a65e1f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x8a65e1f8 Size: 121
Object: Hidden Code [Driver: sbp2port, IRP_MJ_CREATE]
Process: System Address: 0x8b1831f8 Size: 121
Object: Hidden Code [Driver: sbp2port, IRP_MJ_CLOSE]
Process: System Address: 0x8b1831f8 Size: 121
Object: Hidden Code [Driver: sbp2port, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8b1831f8 Size: 121
Object: Hidden Code [Driver: sbp2port, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8b1831f8 Size: 121
Object: Hidden Code [Driver: sbp2port, IRP_MJ_POWER]
Process: System Address: 0x8b1831f8 Size: 121
Object: Hidden Code [Driver: sbp2port, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8b1831f8 Size: 121
Object: Hidden Code [Driver: sbp2port, IRP_MJ_PNP]
Process: System Address: 0x8b1831f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x898061f8 Size: 121
Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_CREATE]
Process: System Address: 0x897261f8 Size: 121
Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_CLOSE]
Process: System Address: 0x897261f8 Size: 121
Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_READ]
Process: System Address: 0x897261f8 Size: 121
Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x897261f8 Size: 121
Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x897261f8 Size: 121
Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x897261f8 Size: 121
Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x897261f8 Size: 121
Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x897261f8 Size: 121
Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x897261f8 Size: 121
Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_SHUTDOWN]
Process: System Address: 0x897261f8 Size: 121
Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x897261f8 Size: 121
Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_CLEANUP]
Process: System Address: 0x897261f8 Size: 121
Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_PNP]
Process: System Address: 0x897261f8 Size: 121
Shadow SSDT
——————-
#: 013 Function Name: NtGdiBitBlt
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c28130
#: 233 Function Name: NtGdiOpenDCW
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c28450
#: 307 Function Name: NtUserAttachThreadInput
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c25a30
#: 310 Function Name: NtUserBlockInput
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c27230
#: 383 Function Name: NtUserGetAsyncKeyState
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c26450
#: 389 Function Name: NtUserGetClipboardData
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c274e0
#: 401 Function Name: NtUserGetDC
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c27e10
#: 414 Function Name: NtUserGetKeyboardState
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c26320
#: 416 Function Name: NtUserGetKeyState
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c261f0
#: 439 Function Name: NtUserGetWindowDC
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c27fa0
#: 460 Function Name: NtUserMessageCall
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c26580
#: 465 Function Name: NtUserMoveWindow
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c27800
#: 475 Function Name: NtUserPostMessage
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c26950
#: 476 Function Name: NtUserPostThreadMessage
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c26cb0
#: 491 Function Name: NtUserRegisterRawInputDevices
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c258d0
#: 502 Function Name: NtUserSendInput
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c27000
#: 509 Function Name: NtUserSetClipboardViewer
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c273a0
#: 529 Function Name: NtUserSetParent
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c27630
#: 546 Function Name: NtUserSetWindowPos
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c27af0
#: 548 Function Name: NtUserSetWindowsHookAW
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c25420
#: 549 Function Name: NtUserSetWindowsHookEx
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c25040
#: 552 Function Name: NtUserSetWinEventHook
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c25680
#: 555 Function Name: NtUserShowWindow
Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c27a20
==EOF==
Thanks for your help!
Hi,
please do the following:
You have CD Emulation drivers which interfere with our tools, we will disable them till your machine is clean.
Please download
DeFogger to your
desktop .
Double click
DeFogger to run the tool.
The application window will appear Click the Disable button to disable your CD Emulation drivers Click Yes to continue A 'Finished!' message will appear Click OK DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log
defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.
NEXT
Download
ComboFix from one of the following locations:
Link 1
Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your
Desktop
*
IMPORTANT -
Disable your AntiVirus and AntiSpyware applications , usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
here
Double click on ComboFix.exe & follow the prompts.
As part of it's process,
ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's
strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes , to continue scanning for malware.
When finished, it shall produce a log for you.
Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
ComboFix 09-12-28.03 - GEORGE 12/29/2009 0:16.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2560 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\VIRUS SCAN PROCEDURES
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
ADS - WINDOWS: deleted 72 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-303087950-19637512-4056949597-1000
c:\documents and settings\GEORGE\Application Data\inst.exe
c:\documents and settings\GEORGE\My Documents\022809reg.reg
c:\documents and settings\GEORGE\My Documents\7-14-08.reg
c:\documents and settings\GEORGE\My Documents\backup.reg
c:\documents and settings\GEORGE\My Documents\BACKUP120107.reg
c:\documents and settings\GEORGE\My Documents\dec292008reg.reg
c:\documents and settings\GEORGE\My Documents\december15.reg
c:\documents and settings\GEORGE\My Documents\feb1408.reg
c:\documents and settings\GEORGE\My Documents\reg021109.reg
c:\recycler\S-1-5-21-1446432944-476004442-2805334122-1006
c:\windows\Downloaded Program Files\Temp
c:\windows\EventSystem.log
c:\windows\system\oeminfo.ini
c:\windows\system32\drivers\1028_DELL_XPS_Dell DXP061 .MRK
c:\windows\system32\drivers\DELL_XPS_Dell DXP061 .MRK
c:\windows\system32\vobis32.dll
.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-29 )))))))))))))))))))))))))))))))
.
2009-12-23 11:16 . 2009-12-23 11:16 ——– d—–w- c:\program files\Softwin
2009-12-21 10:52 . 2009-12-21 10:52 ——– d—–w- c:\program files\Sophos
2009-12-18 11:19 . 2009-12-29 04:57 52224 —-a-w- c:\documents and settings\GEORGE\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-18 10:52 . 2009-12-17 22:14 150888 —-a-w- C:\Tcpvcon.exe
2009-12-17 20:11 . 2008-04-14 01:11 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2009-12-12 08:31 . 2009-12-12 09:02 15 —-a-w- c:\documents and settings\GEORGE\settings.dat
2009-12-12 00:42 . 2009-12-12 00:42 ——– d—–w- c:\program files\MSXML 4.0
2009-12-12 00:37 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2009-12-11 22:00 . 2009-08-25 09:30 13312 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
2009-12-11 22:00 . 2009-10-20 21:33 545280 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\PicLensHelper.exe
2009-12-11 22:00 . 2009-10-20 21:33 4716544 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
2009-12-11 22:00 . 2009-10-20 21:33 344064 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\LaunchCooliris.exe
2009-12-11 22:00 . 2009-10-20 21:33 153600 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
2009-12-11 22:00 . 2009-10-20 21:33 103424 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\pixomatic.dll
2009-12-11 21:56 . 2009-12-29 05:06 ——– d—–w- c:\program files\Mozilla Firefox 3.55
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 07:58 . 2008-07-21 03:46 ——– d—–w- c:\program files\Mozilla Firefox3.0
2009-12-29 05:05 . 2007-09-18 10:38 ——– d—–w- c:\program files\Mozilla Firefox2.0
2009-12-29 05:01 . 2007-12-02 21:43 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-29 05:01 . 2008-02-06 16:14 ——– d—–w- c:\program files\SpywareBlaster
2009-12-29 05:00 . 2006-12-13 07:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-29 04:57 . 2009-03-17 20:59 117760 —-a-w- c:\documents and settings\GEORGE\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-20 01:55 . 2006-12-13 07:16 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-19 10:22 . 2006-11-29 21:40 ——– d—–w- c:\program files\Java
2009-12-19 10:00 . 2006-11-29 21:47 ——– d—–w- c:\program files\Real
2009-12-19 09:52 . 2006-11-29 21:44 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-19 08:57 . 2006-11-29 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-12-19 08:33 . 2006-11-29 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\QuickTime
2009-12-19 08:31 . 2008-02-15 21:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-19 08:12 . 2007-09-21 23:12 ——– d—–w- c:\program files\Microsoft Location Finder
2009-12-19 07:46 . 2006-11-29 21:47 ——– d—–w- c:\program files\Common Files\Real
2009-12-19 07:44 . 2008-03-04 22:06 ——– d—–w- c:\program files\CounterPath
2009-12-19 07:21 . 2006-12-07 10:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Windows Live Toolbar
2009-12-19 07:18 . 2007-10-06 17:03 ——– d—–w- c:\program files\MSN Money Toolbar Add-in
2009-12-19 07:17 . 2006-11-29 21:52 ——– d—–w- c:\program files\Yahoo!
2009-12-19 06:31 . 2008-03-27 03:06 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-19 02:42 . 2009-01-27 03:22 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-18 11:17 . 2009-05-29 06:12 ——– d—–w- c:\program files\a-squared Free
2009-12-17 22:10 . 2008-06-20 21:56 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-12-17 20:12 . 2009-12-17 20:12 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-12-17 20:12 . 2009-12-17 20:12 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-12-15 05:01 . 2009-04-28 03:50 95744 —-a-w- c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll
2009-12-12 01:31 . 2007-02-02 04:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-12 00:48 . 2006-11-29 21:53 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-12-12 00:24 . 2009-05-29 06:17 ——– d—–w- c:\documents and settings\GEORGE\Application Data\OnlineArmor
2009-12-11 22:05 . 2006-12-13 04:58 ——– d—–w- c:\documents and settings\GEORGE\Application Data\Skype
2009-12-11 20:33 . 2009-02-17 11:30 4844296 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-11 20:08 . 2009-05-29 06:07 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-04 00:14 . 2009-01-27 03:22 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-04 00:13 . 2009-01-27 03:22 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-21 15:51 . 2006-02-28 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-03 04:42 . 2009-11-01 22:10 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-11-02 00:06 . 2008-10-12 08:39 ——– d—–w- c:\program files\SpywareGuard
2009-11-01 22:40 . 2009-11-01 22:40 ——– d—–w- c:\program files\Microsoft Network Monitor 3
2009-11-01 22:08 . 2008-01-14 19:59 ——– d—–w- c:\program files\Microsoft Silverlight
2009-11-01 22:07 . 2006-11-29 21:52 ——– d—–w- c:\program files\Microsoft Works
2009-11-01 11:19 . 2009-10-18 06:10 ——– d—–w- c:\program files\Microsoft Network Monitor 3(2)
2009-10-29 07:46 . 2006-02-28 12:00 832512 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2006-02-28 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2006-02-28 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-10-21 05:38 . 2006-02-28 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-02-28 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2006-02-28 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2006-02-28 12:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2006-02-28 12:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2006-02-28 12:00 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-08 22:57 . 2008-07-30 03:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2009-10-08 22:57 . 2006-02-28 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 22:56 . 2006-02-28 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2008-09-20 18:42 . 2008-03-08 08:25 88 –sha-r- c:\windows\system32\892202FEA3.sys
2008-06-13 04:32 . 2008-06-13 04:32 23 –sha-w- c:\windows\system32\aafcebeaff4_g.dll
2008-09-20 18:43 . 2008-03-08 08:25 4856 –sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}]
@="{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}"
[HKEY_CLASSES_ROOT\CLSID\{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}]
2009-03-06 03:17 143160 —-a-w- c:\windows\system32\pfmshx_27B.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-17 2002160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"nwiz"="nwiz.exe" [2009-03-28 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 13684736]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 86016]
"@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2009-04-16 2044104]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-10-19 293888]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2009-04-16 335048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-07 20:23 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-10-09 21:33 1949480 —-a-w- c:\program files\Apricorn\EZ Gig II\TimounterMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apricorn Scheduler Service]
2007-10-09 21:24 148712 —-a-w- c:\program files\Common Files\Apricorn\Schedule2\schedhlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2008-03-18 09:06 1848648 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2008-12-12 09:31 722256 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2008-12-17 18:36 50520 —-a-w- c:\documents and settings\GEORGE\Application Data\mjusbsp\cdloader2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 —-a-w- c:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZGigMonitor.exe]
2007-10-09 21:20 1169264 —-a-w- c:\program files\Apricorn\EZ Gig II\EZGigMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GizmoDriveDelegate]
2009-05-01 04:06 390752 —-a-w- c:\progra~1\Gizmo\gdrive.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 18:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJNetworkScanUtility]
2007-05-21 08:37 124512 —-a-w- c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 22:50 221184 —-a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
2007-05-17 21:45 279912 —-a-w- c:\program files\Microsoft LifeCam\LifeExp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2007-06-13 17:39 73728 —-a-w- c:\program files\ScanSoft\OmniPageSE4\OpWareSE4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
2004-03-11 08:26 406016 —-a-w- c:\windows\system32\PSDrvCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2009-03-15 10:15 180224 —-a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\siService.exe]
2003-12-23 18:31 204800 —-a-w- c:\program files\Sunbelt Software\iHateSpam\siService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 16:03 210472 —-a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-04-27 18:56 1410296 —-a-w- c:\program files\GAMES\Steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-05-21 18:34 148888 —-a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX6000]
2007-04-10 21:46 996712 —-a-w- c:\windows\vVX6000.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SQLWriter"=2 (0x2)
"SQLBrowser"=2 (0x2)
"MSSQL$MSSMLBIZ"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AdobeUpdater"=c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Plugin Install"=c:\program files\QuickTime\Plugins\DeleteMe1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Sunbelt Software\\iHateSpam\\siMailProxyServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Google\\Google Updater\\GoogleUpdater.exe"=
"c:\\Program Files\\PowerFile C200\\PowerFile.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\GAMES\\Steam\\SteamApps\\common\\empire total war\\Empire.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Logging]
"LogSuccessfulConnections"= 0 (0x0)
"LogDroppedPackets"= 0 (0x0)
"LogFileSize"= 0 (0x0)
"LogFilePath"=
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [3/12/2009 2:23 PM 40368]
R1 DiscImage;Disc image driver;c:\windows\system32\drivers\discimage.sys [5/26/2007 7:04 PM 24704]
R1 GizmoDrv;Gizmo Device Driver;c:\windows\system32\drivers\gizmodrv.sys [4/30/2009 8:07 PM 23624]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [5/28/2009 10:17 PM 196688]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [5/28/2009 10:17 PM 31824]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [5/28/2009 10:17 PM 29776]
R1 pfmfs_27B;pfmfs_27B;c:\windows\system32\drivers\pfmfs_27B.sys [4/30/2009 8:05 PM 179896]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [8/19/2008 11:34 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/19/2008 11:34 PM 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [5/28/2009 10:12 PM 1858144]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/28/2009 10:07 PM 108289]
R2 DIMSVC;Disc Image Demo mount service;c:\program files\Pa-software\Disc Image Demo\dimsvc.exe [5/26/2007 7:03 PM 36864]
R2 Gizmo Central;Gizmo Central;c:\program files\Gizmo\gservice.exe [4/30/2009 8:06 PM 31856]
R2 SMART-ERService;SMART-ER Service;c:\program files\Apricorn\SMART-ER\SMART-ER Service.exe [6/4/2007 10:20 AM 69632]
R2 VirtualDrive;VirtualDrive;c:\program files\All Image\vdd-x86.sys [4/30/2009 7:41 PM 10752]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [4/19/2008 1:46 PM 30560]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/19/2008 11:34 PM 7408]
S1 AntiLog32;AntiLog32;\??\c:\program files\AntiLogger\AntiLog32.sys –> c:\program files\AntiLogger\AntiLog32.sys [?]
S2 AnonMgmtSvc;Anonymizer Management Service;"c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe" –> c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe [?]
S2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [5/28/2009 10:17 PM 361160]
S2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [5/28/2009 10:17 PM 3049160]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\GEORGE\LOCALS~1\Temp\ALSysIO.sys –> c:\docume~1\GEORGE\LOCALS~1\Temp\ALSysIO.sys [?]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 DarkSpy;DarkSpy;\??\c:\windows\system32\DarkSpyKernel.sys –> c:\windows\system32\DarkSpyKernel.sys [?]
S3 dpK0Bx01;Fingerprint Reader Filter Driver;c:\windows\system32\drivers\dpK0Bx01.sys [1/5/2007 3:45 PM 35584]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [3/24/2009 12:15 PM 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [3/24/2009 12:15 PM 3072]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [8/17/2005 11:00 PM 7168]
S3 IntelDH;IntelDH Driver;c:\windows\system32\Drivers\IntelDH.sys –> c:\windows\system32\Drivers\IntelDH.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\16.tmp –> c:\windows\system32\16.tmp [?]
S3 PORTMON;PORTMON;\??\c:\documents and settings\GEORGE\Desktop\DOWNLOADS\Portmon\PORTMSYS.SYS –> c:\documents and settings\GEORGE\Desktop\DOWNLOADS\Portmon\PORTMSYS.SYS [?]
S3 SWUSBFLT;Microsoft SideWinder VIA Filter Driver;c:\windows\system32\drivers\SWUSBFLT.SYS [12/22/2006 10:46 PM 3968]
S3 UsbdpFP;Fingerprint Reader Class Driver;c:\windows\system32\drivers\usbdpfp.sys [1/5/2007 3:45 PM 47360]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [12/12/2006 6:43 PM 2385896]
S3 xusb20;Xbox 360 Wireless Receiver for Windows Driver Service;c:\windows\system32\drivers\xusb20.sys [10/13/2006 5:19 PM 50048]
S3 yeddef;YEDDEF driver;c:\windows\system32\Drivers\yeddef.sys –> c:\windows\system32\Drivers\yeddef.sys [?]
S3 ZD1211U(Hawking Technologies);Hawking Technologies HWU54D Hi-Gain Wireless-G USB Adapter(Hawking Technologies);c:\windows\system32\drivers\ZD1211U.sys [12/6/2006 4:17 AM 233472]
S4 gupdate1c901a09a323bba;Google Update Service (gupdate1c901a09a323bba);c:\program files\Google\Update\GoogleUpdate.exe [8/18/2008 6:09 PM 133104]
S4 NSLHNZKPEI;NSLHNZKPEI;c:\docume~1\GEORGE\LOCALS~1\Temp\NSLHNZKPEI.exe –> c:\docume~1\GEORGE\LOCALS~1\Temp\NSLHNZKPEI.exe [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4/30/2009 6:14 PM 721904]
S4 TABKB;TABKB;c:\docume~1\GEORGE\LOCALS~1\Temp\TABKB.exe –> c:\docume~1\GEORGE\LOCALS~1\Temp\TABKB.exe [?]
— Other Services/Drivers In Memory —
*Deregistered* - PROCEXP111
.
——- Supplementary Scan ——-
.
uLocal Page = hxxp://www.msn.com
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
Handler: msell2 - {9367D24B-8506-471A-915A-CFBB4BCEB631} - c:\program files\Common Files\Microsoft Shared\Reference Titles\MSELL2.dll
DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} - hxxps://actsvr.comcastonline.com/techtools/dl/Comcast%20Activation%20Controls.cab
FF - ProfilePath - c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\
FF - prefs.js: browser.startup.homepage - msn.com
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
FF - component: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - plugin: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npdeploytk.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npnul32.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - (no file)
Notify-DPWLN - (no file)
MSConfigStartUp-Anonymizer - c:\program files\Anonymizer\Anonymizer Software\Anonymizer.exe
AddRemove-AntiLogger - c:\documents and settings\All Users\Application Data\{DBBDCE5C-C9B7-4F00-BA4F-3D64168B6576}\AntiLogger_Setup.exe
AddRemove-BrothersInArms - e:\brothersinarms\System\Setup.exe
AddRemove-BrothersInArmsEiB - e:\ubisoft\Gearbox Software\BrothersInArmsEiB\System\Setup.exe
AddRemove-BrothersInArmsEIBSDK - e:\ubisoft\Gearbox Software\BrothersInArmsEiB\EIBSDKUninstall.exe
AddRemove-CompleteDoItYourselfGuide - d:\data\diyguide.exe
AddRemove-FoxyTunesForFirefox - c:\program files\Mozilla Firefox\firefox.exe
AddRemove-Microsoft MSDN 2005 Express Edition - ENU - e:\program files\Microsoft Visual Studio 8\Microsoft MSDN 2005 Express Edition - ENU\install.exe
AddRemove-Microsoft Visual Web Developer 2005 Express Edition - ENU - e:\program files\Microsoft Visual Studio 8\Microsoft Visual Web Developer 2005 Express Edition - ENU\setup.exe
AddRemove-Mozilla Firefox (2.0.0.20) - c:\program files\Mozilla Firefox\uninstall\helper.exe
AddRemove-Nero PhotoShow Express 4 - e:\nero photoshow 4\data\Xtras\Uninstall.exe
AddRemove-{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 - c:\program files\Spybot - Search & Destroy\unins001.exe
AddRemove-{C5089197-5B15-44AD-B0FC-2E94EE9ECB63} - c:\documents and settings\GEORGE\Local Settings\Application Data\{044CCC32-19C8-40C9-92DE-7D50DCAC47BA}\wsc.exe
**************************************************************************
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\16.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-3060164775-2224625509-1354611237-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1076)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'lsass.exe'(1136)
c:\windows\system32\relog_ap.dll
c:\windows\DPPWDFLT.dll
.
Completion time: 2009-12-29 00:23:48
ComboFix-quarantined-files.txt 2009-12-29 08:23
Pre-Run: 15,852,703,744 bytes free
Post-Run: 15,987,843,072 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - B55EF24745AE95E2F263C0B3DC025394
I ran defogger. I ran the combo-fix.exe program. During the process, Combo stated not to start any program, I needed to download recovery console.
which I suppose it installed. It stated not to click on the program but after it started running a screen popped up saying swxcalx.cfxxe is corrupt and windows
needs to run chkdsk now click OK which I didn't do….was wondering if this was legit or not. Finished posted below
ComboFix 09-12-28.03 - GEORGE 12/29/2009 0:16.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2560 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\VIRUS SCAN PROCEDURES
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
ADS - WINDOWS: deleted 72 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-303087950-19637512-4056949597-1000
c:\documents and settings\GEORGE\Application Data\inst.exe
c:\documents and settings\GEORGE\My Documents\022809reg.reg
c:\documents and settings\GEORGE\My Documents\7-14-08.reg
c:\documents and settings\GEORGE\My Documents\backup.reg
c:\documents and settings\GEORGE\My Documents\BACKUP120107.reg
c:\documents and settings\GEORGE\My Documents\dec292008reg.reg
c:\documents and settings\GEORGE\My Documents\december15.reg
c:\documents and settings\GEORGE\My Documents\feb1408.reg
c:\documents and settings\GEORGE\My Documents\reg021109.reg
c:\recycler\S-1-5-21-1446432944-476004442-2805334122-1006
c:\windows\Downloaded Program Files\Temp
c:\windows\EventSystem.log
c:\windows\system\oeminfo.ini
c:\windows\system32\drivers\1028_DELL_XPS_Dell DXP061 .MRK
c:\windows\system32\drivers\DELL_XPS_Dell DXP061 .MRK
c:\windows\system32\vobis32.dll
.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-29 )))))))))))))))))))))))))))))))
.
2009-12-23 11:16 . 2009-12-23 11:16 ——– d—–w- c:\program files\Softwin
2009-12-21 10:52 . 2009-12-21 10:52 ——– d—–w- c:\program files\Sophos
2009-12-18 11:19 . 2009-12-29 04:57 52224 —-a-w- c:\documents and settings\GEORGE\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-18 10:52 . 2009-12-17 22:14 150888 —-a-w- C:\Tcpvcon.exe
2009-12-17 20:11 . 2008-04-14 01:11 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2009-12-12 08:31 . 2009-12-12 09:02 15 —-a-w- c:\documents and settings\GEORGE\settings.dat
2009-12-12 00:42 . 2009-12-12 00:42 ——– d—–w- c:\program files\MSXML 4.0
2009-12-12 00:37 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2009-12-11 22:00 . 2009-08-25 09:30 13312 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
2009-12-11 22:00 . 2009-10-20 21:33 545280 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\PicLensHelper.exe
2009-12-11 22:00 . 2009-10-20 21:33 4716544 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
2009-12-11 22:00 . 2009-10-20 21:33 344064 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\LaunchCooliris.exe
2009-12-11 22:00 . 2009-10-20 21:33 153600 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
2009-12-11 22:00 . 2009-10-20 21:33 103424 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\pixomatic.dll
2009-12-11 21:56 . 2009-12-29 05:06 ——– d—–w- c:\program files\Mozilla Firefox 3.55
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 07:58 . 2008-07-21 03:46 ——– d—–w- c:\program files\Mozilla Firefox3.0
2009-12-29 05:05 . 2007-09-18 10:38 ——– d—–w- c:\program files\Mozilla Firefox2.0
2009-12-29 05:01 . 2007-12-02 21:43 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-29 05:01 . 2008-02-06 16:14 ——– d—–w- c:\program files\SpywareBlaster
2009-12-29 05:00 . 2006-12-13 07:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-29 04:57 . 2009-03-17 20:59 117760 —-a-w- c:\documents and settings\GEORGE\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-20 01:55 . 2006-12-13 07:16 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-19 10:22 . 2006-11-29 21:40 ——– d—–w- c:\program files\Java
2009-12-19 10:00 . 2006-11-29 21:47 ——– d—–w- c:\program files\Real
2009-12-19 09:52 . 2006-11-29 21:44 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-19 08:57 . 2006-11-29 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-12-19 08:33 . 2006-11-29 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\QuickTime
2009-12-19 08:31 . 2008-02-15 21:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-19 08:12 . 2007-09-21 23:12 ——– d—–w- c:\program files\Microsoft Location Finder
2009-12-19 07:46 . 2006-11-29 21:47 ——– d—–w- c:\program files\Common Files\Real
2009-12-19 07:44 . 2008-03-04 22:06 ——– d—–w- c:\program files\CounterPath
2009-12-19 07:21 . 2006-12-07 10:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Windows Live Toolbar
2009-12-19 07:18 . 2007-10-06 17:03 ——– d—–w- c:\program files\MSN Money Toolbar Add-in
2009-12-19 07:17 . 2006-11-29 21:52 ——– d—–w- c:\program files\Yahoo!
2009-12-19 06:31 . 2008-03-27 03:06 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-19 02:42 . 2009-01-27 03:22 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-18 11:17 . 2009-05-29 06:12 ——– d—–w- c:\program files\a-squared Free
2009-12-17 22:10 . 2008-06-20 21:56 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-12-17 20:12 . 2009-12-17 20:12 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-12-17 20:12 . 2009-12-17 20:12 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-12-15 05:01 . 2009-04-28 03:50 95744 —-a-w- c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll
2009-12-12 01:31 . 2007-02-02 04:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-12 00:48 . 2006-11-29 21:53 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-12-12 00:24 . 2009-05-29 06:17 ——– d—–w- c:\documents and settings\GEORGE\Application Data\OnlineArmor
2009-12-11 22:05 . 2006-12-13 04:58 ——– d—–w- c:\documents and settings\GEORGE\Application Data\Skype
2009-12-11 20:33 . 2009-02-17 11:30 4844296 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-11 20:08 . 2009-05-29 06:07 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-04 00:14 . 2009-01-27 03:22 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-04 00:13 . 2009-01-27 03:22 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-21 15:51 . 2006-02-28 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-03 04:42 . 2009-11-01 22:10 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-11-02 00:06 . 2008-10-12 08:39 ——– d—–w- c:\program files\SpywareGuard
2009-11-01 22:40 . 2009-11-01 22:40 ——– d—–w- c:\program files\Microsoft Network Monitor 3
2009-11-01 22:08 . 2008-01-14 19:59 ——– d—–w- c:\program files\Microsoft Silverlight
2009-11-01 22:07 . 2006-11-29 21:52 ——– d—–w- c:\program files\Microsoft Works
2009-11-01 11:19 . 2009-10-18 06:10 ——– d—–w- c:\program files\Microsoft Network Monitor 3(2)
2009-10-29 07:46 . 2006-02-28 12:00 832512 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2006-02-28 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2006-02-28 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-10-21 05:38 . 2006-02-28 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-02-28 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2006-02-28 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2006-02-28 12:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2006-02-28 12:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2006-02-28 12:00 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-08 22:57 . 2008-07-30 03:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2009-10-08 22:57 . 2006-02-28 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 22:56 . 2006-02-28 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2008-09-20 18:42 . 2008-03-08 08:25 88 –sha-r- c:\windows\system32\892202FEA3.sys
2008-06-13 04:32 . 2008-06-13 04:32 23 –sha-w- c:\windows\system32\aafcebeaff4_g.dll
2008-09-20 18:43 . 2008-03-08 08:25 4856 –sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}]
@="{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}"
[HKEY_CLASSES_ROOT\CLSID\{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}]
2009-03-06 03:17 143160 —-a-w- c:\windows\system32\pfmshx_27B.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-17 2002160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"nwiz"="nwiz.exe" [2009-03-28 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 13684736]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 86016]
"@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2009-04-16 2044104]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-10-19 293888]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2009-04-16 335048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-07 20:23 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-10-09 21:33 1949480 —-a-w- c:\program files\Apricorn\EZ Gig II\TimounterMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apricorn Scheduler Service]
2007-10-09 21:24 148712 —-a-w- c:\program files\Common Files\Apricorn\Schedule2\schedhlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2008-03-18 09:06 1848648 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2008-12-12 09:31 722256 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2008-12-17 18:36 50520 —-a-w- c:\documents and settings\GEORGE\Application Data\mjusbsp\cdloader2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 —-a-w- c:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZGigMonitor.exe]
2007-10-09 21:20 1169264 —-a-w- c:\program files\Apricorn\EZ Gig II\EZGigMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GizmoDriveDelegate]
2009-05-01 04:06 390752 —-a-w- c:\progra~1\Gizmo\gdrive.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 18:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJNetworkScanUtility]
2007-05-21 08:37 124512 —-a-w- c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 22:50 221184 —-a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
2007-05-17 21:45 279912 —-a-w- c:\program files\Microsoft LifeCam\LifeExp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2007-06-13 17:39 73728 —-a-w- c:\program files\ScanSoft\OmniPageSE4\OpWareSE4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
2004-03-11 08:26 406016 —-a-w- c:\windows\system32\PSDrvCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2009-03-15 10:15 180224 —-a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\siService.exe]
2003-12-23 18:31 204800 —-a-w- c:\program files\Sunbelt Software\iHateSpam\siService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 16:03 210472 —-a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-04-27 18:56 1410296 —-a-w- c:\program files\GAMES\Steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-05-21 18:34 148888 —-a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX6000]
2007-04-10 21:46 996712 —-a-w- c:\windows\vVX6000.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SQLWriter"=2 (0x2)
"SQLBrowser"=2 (0x2)
"MSSQL$MSSMLBIZ"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AdobeUpdater"=c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Plugin Install"=c:\program files\QuickTime\Plugins\DeleteMe1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Sunbelt Software\\iHateSpam\\siMailProxyServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Google\\Google Updater\\GoogleUpdater.exe"=
"c:\\Program Files\\PowerFile C200\\PowerFile.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\GAMES\\Steam\\SteamApps\\common\\empire total war\\Empire.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Logging]
"LogSuccessfulConnections"= 0 (0x0)
"LogDroppedPackets"= 0 (0x0)
"LogFileSize"= 0 (0x0)
"LogFilePath"=
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [3/12/2009 2:23 PM 40368]
R1 DiscImage;Disc image driver;c:\windows\system32\drivers\discimage.sys [5/26/2007 7:04 PM 24704]
R1 GizmoDrv;Gizmo Device Driver;c:\windows\system32\drivers\gizmodrv.sys [4/30/2009 8:07 PM 23624]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [5/28/2009 10:17 PM 196688]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [5/28/2009 10:17 PM 31824]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [5/28/2009 10:17 PM 29776]
R1 pfmfs_27B;pfmfs_27B;c:\windows\system32\drivers\pfmfs_27B.sys [4/30/2009 8:05 PM 179896]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [8/19/2008 11:34 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/19/2008 11:34 PM 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [5/28/2009 10:12 PM 1858144]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/28/2009 10:07 PM 108289]
R2 DIMSVC;Disc Image Demo mount service;c:\program files\Pa-software\Disc Image Demo\dimsvc.exe [5/26/2007 7:03 PM 36864]
R2 Gizmo Central;Gizmo Central;c:\program files\Gizmo\gservice.exe [4/30/2009 8:06 PM 31856]
R2 SMART-ERService;SMART-ER Service;c:\program files\Apricorn\SMART-ER\SMART-ER Service.exe [6/4/2007 10:20 AM 69632]
R2 VirtualDrive;VirtualDrive;c:\program files\All Image\vdd-x86.sys [4/30/2009 7:41 PM 10752]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [4/19/2008 1:46 PM 30560]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/19/2008 11:34 PM 7408]
S1 AntiLog32;AntiLog32;\??\c:\program files\AntiLogger\AntiLog32.sys –> c:\program files\AntiLogger\AntiLog32.sys [?]
S2 AnonMgmtSvc;Anonymizer Management Service;"c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe" –> c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe [?]
S2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [5/28/2009 10:17 PM 361160]
S2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [5/28/2009 10:17 PM 3049160]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\GEORGE\LOCALS~1\Temp\ALSysIO.sys –> c:\docume~1\GEORGE\LOCALS~1\Temp\ALSysIO.sys [?]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 DarkSpy;DarkSpy;\??\c:\windows\system32\DarkSpyKernel.sys –> c:\windows\system32\DarkSpyKernel.sys [?]
S3 dpK0Bx01;Fingerprint Reader Filter Driver;c:\windows\system32\drivers\dpK0Bx01.sys [1/5/2007 3:45 PM 35584]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [3/24/2009 12:15 PM 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [3/24/2009 12:15 PM 3072]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [8/17/2005 11:00 PM 7168]
S3 IntelDH;IntelDH Driver;c:\windows\system32\Drivers\IntelDH.sys –> c:\windows\system32\Drivers\IntelDH.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\16.tmp –> c:\windows\system32\16.tmp [?]
S3 PORTMON;PORTMON;\??\c:\documents and settings\GEORGE\Desktop\DOWNLOADS\Portmon\PORTMSYS.SYS –> c:\documents and settings\GEORGE\Desktop\DOWNLOADS\Portmon\PORTMSYS.SYS [?]
S3 SWUSBFLT;Microsoft SideWinder VIA Filter Driver;c:\windows\system32\drivers\SWUSBFLT.SYS [12/22/2006 10:46 PM 3968]
S3 UsbdpFP;Fingerprint Reader Class Driver;c:\windows\system32\drivers\usbdpfp.sys [1/5/2007 3:45 PM 47360]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [12/12/2006 6:43 PM 2385896]
S3 xusb20;Xbox 360 Wireless Receiver for Windows Driver Service;c:\windows\system32\drivers\xusb20.sys [10/13/2006 5:19 PM 50048]
S3 yeddef;YEDDEF driver;c:\windows\system32\Drivers\yeddef.sys –> c:\windows\system32\Drivers\yeddef.sys [?]
S3 ZD1211U(Hawking Technologies);Hawking Technologies HWU54D Hi-Gain Wireless-G USB Adapter(Hawking Technologies);c:\windows\system32\drivers\ZD1211U.sys [12/6/2006 4:17 AM 233472]
S4 gupdate1c901a09a323bba;Google Update Service (gupdate1c901a09a323bba);c:\program files\Google\Update\GoogleUpdate.exe [8/18/2008 6:09 PM 133104]
S4 NSLHNZKPEI;NSLHNZKPEI;c:\docume~1\GEORGE\LOCALS~1\Temp\NSLHNZKPEI.exe –> c:\docume~1\GEORGE\LOCALS~1\Temp\NSLHNZKPEI.exe [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4/30/2009 6:14 PM 721904]
S4 TABKB;TABKB;c:\docume~1\GEORGE\LOCALS~1\Temp\TABKB.exe –> c:\docume~1\GEORGE\LOCALS~1\Temp\TABKB.exe [?]
— Other Services/Drivers In Memory —
*Deregistered* - PROCEXP111
.
——- Supplementary Scan ——-
.
uLocal Page = hxxp://www.msn.com
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
Handler: msell2 - {9367D24B-8506-471A-915A-CFBB4BCEB631} - c:\program files\Common Files\Microsoft Shared\Reference Titles\MSELL2.dll
DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} - hxxps://actsvr.comcastonline.com/techtools/dl/Comcast%20Activation%20Controls.cab
FF - ProfilePath - c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\
FF - prefs.js: browser.startup.homepage - msn.com
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
FF - component: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - plugin: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npdeploytk.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npnul32.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - (no file)
Notify-DPWLN - (no file)
MSConfigStartUp-Anonymizer - c:\program files\Anonymizer\Anonymizer Software\Anonymizer.exe
AddRemove-AntiLogger - c:\documents and settings\All Users\Application Data\{DBBDCE5C-C9B7-4F00-BA4F-3D64168B6576}\AntiLogger_Setup.exe
AddRemove-BrothersInArms - e:\brothersinarms\System\Setup.exe
AddRemove-BrothersInArmsEiB - e:\ubisoft\Gearbox Software\BrothersInArmsEiB\System\Setup.exe
AddRemove-BrothersInArmsEIBSDK - e:\ubisoft\Gearbox Software\BrothersInArmsEiB\EIBSDKUninstall.exe
AddRemove-CompleteDoItYourselfGuide - d:\data\diyguide.exe
AddRemove-FoxyTunesForFirefox - c:\program files\Mozilla Firefox\firefox.exe
AddRemove-Microsoft MSDN 2005 Express Edition - ENU - e:\program files\Microsoft Visual Studio 8\Microsoft MSDN 2005 Express Edition - ENU\install.exe
AddRemove-Microsoft Visual Web Developer 2005 Express Edition - ENU - e:\program files\Microsoft Visual Studio 8\Microsoft Visual Web Developer 2005 Express Edition - ENU\setup.exe
AddRemove-Mozilla Firefox (2.0.0.20) - c:\program files\Mozilla Firefox\uninstall\helper.exe
AddRemove-Nero PhotoShow Express 4 - e:\nero photoshow 4\data\Xtras\Uninstall.exe
AddRemove-{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 - c:\program files\Spybot - Search & Destroy\unins001.exe
AddRemove-{C5089197-5B15-44AD-B0FC-2E94EE9ECB63} - c:\documents and settings\GEORGE\Local Settings\Application Data\{044CCC32-19C8-40C9-92DE-7D50DCAC47BA}\wsc.exe
**************************************************************************
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\16.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-3060164775-2224625509-1354611237-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1076)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'lsass.exe'(1136)
c:\windows\system32\relog_ap.dll
c:\windows\DPPWDFLT.dll
.
Completion time: 2009-12-29 00:23:48
ComboFix-quarantined-files.txt 2009-12-29 08:23
Pre-Run: 15,852,703,744 bytes free
Post-Run: 15,987,843,072 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - B55EF24745AE95E2F263C0B3DC025394
Thanks I disable all software other then going into taskmanager to kill process trees which it wouldn;'t le tme do anyway
ComboFix 09-12-28.03 - GEORGE 12/29/2009 0:16.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2560 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\VIRUS SCAN PROCEDURES
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
ADS - WINDOWS: deleted 72 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-303087950-19637512-4056949597-1000
c:\documents and settings\GEORGE\Application Data\inst.exe
c:\documents and settings\GEORGE\My Documents\022809reg.reg
c:\documents and settings\GEORGE\My Documents\7-14-08.reg
c:\documents and settings\GEORGE\My Documents\backup.reg
c:\documents and settings\GEORGE\My Documents\BACKUP120107.reg
c:\documents and settings\GEORGE\My Documents\dec292008reg.reg
c:\documents and settings\GEORGE\My Documents\december15.reg
c:\documents and settings\GEORGE\My Documents\feb1408.reg
c:\documents and settings\GEORGE\My Documents\reg021109.reg
c:\recycler\S-1-5-21-1446432944-476004442-2805334122-1006
c:\windows\Downloaded Program Files\Temp
c:\windows\EventSystem.log
c:\windows\system\oeminfo.ini
c:\windows\system32\drivers\1028_DELL_XPS_Dell DXP061 .MRK
c:\windows\system32\drivers\DELL_XPS_Dell DXP061 .MRK
c:\windows\system32\vobis32.dll
.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-29 )))))))))))))))))))))))))))))))
.
2009-12-23 11:16 . 2009-12-23 11:16 ——– d—–w- c:\program files\Softwin
2009-12-21 10:52 . 2009-12-21 10:52 ——– d—–w- c:\program files\Sophos
2009-12-18 11:19 . 2009-12-29 04:57 52224 —-a-w- c:\documents and settings\GEORGE\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-18 10:52 . 2009-12-17 22:14 150888 —-a-w- C:\Tcpvcon.exe
2009-12-17 20:11 . 2008-04-14 01:11 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2009-12-12 08:31 . 2009-12-12 09:02 15 —-a-w- c:\documents and settings\GEORGE\settings.dat
2009-12-12 00:42 . 2009-12-12 00:42 ——– d—–w- c:\program files\MSXML 4.0
2009-12-12 00:37 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2009-12-11 22:00 . 2009-08-25 09:30 13312 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
2009-12-11 22:00 . 2009-10-20 21:33 545280 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\PicLensHelper.exe
2009-12-11 22:00 . 2009-10-20 21:33 4716544 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
2009-12-11 22:00 . 2009-10-20 21:33 344064 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\LaunchCooliris.exe
2009-12-11 22:00 . 2009-10-20 21:33 153600 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
2009-12-11 22:00 . 2009-10-20 21:33 103424 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\pixomatic.dll
2009-12-11 21:56 . 2009-12-29 05:06 ——– d—–w- c:\program files\Mozilla Firefox 3.55
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 07:58 . 2008-07-21 03:46 ——– d—–w- c:\program files\Mozilla Firefox3.0
2009-12-29 05:05 . 2007-09-18 10:38 ——– d—–w- c:\program files\Mozilla Firefox2.0
2009-12-29 05:01 . 2007-12-02 21:43 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-29 05:01 . 2008-02-06 16:14 ——– d—–w- c:\program files\SpywareBlaster
2009-12-29 05:00 . 2006-12-13 07:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-29 04:57 . 2009-03-17 20:59 117760 —-a-w- c:\documents and settings\GEORGE\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-20 01:55 . 2006-12-13 07:16 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-19 10:22 . 2006-11-29 21:40 ——– d—–w- c:\program files\Java
2009-12-19 10:00 . 2006-11-29 21:47 ——– d—–w- c:\program files\Real
2009-12-19 09:52 . 2006-11-29 21:44 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-19 08:57 . 2006-11-29 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-12-19 08:33 . 2006-11-29 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\QuickTime
2009-12-19 08:31 . 2008-02-15 21:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-19 08:12 . 2007-09-21 23:12 ——– d—–w- c:\program files\Microsoft Location Finder
2009-12-19 07:46 . 2006-11-29 21:47 ——– d—–w- c:\program files\Common Files\Real
2009-12-19 07:44 . 2008-03-04 22:06 ——– d—–w- c:\program files\CounterPath
2009-12-19 07:21 . 2006-12-07 10:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Windows Live Toolbar
2009-12-19 07:18 . 2007-10-06 17:03 ——– d—–w- c:\program files\MSN Money Toolbar Add-in
2009-12-19 07:17 . 2006-11-29 21:52 ——– d—–w- c:\program files\Yahoo!
2009-12-19 06:31 . 2008-03-27 03:06 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-19 02:42 . 2009-01-27 03:22 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-18 11:17 . 2009-05-29 06:12 ——– d—–w- c:\program files\a-squared Free
2009-12-17 22:10 . 2008-06-20 21:56 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-12-17 20:12 . 2009-12-17 20:12 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-12-17 20:12 . 2009-12-17 20:12 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-12-15 05:01 . 2009-04-28 03:50 95744 —-a-w- c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll
2009-12-12 01:31 . 2007-02-02 04:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-12 00:48 . 2006-11-29 21:53 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-12-12 00:24 . 2009-05-29 06:17 ——– d—–w- c:\documents and settings\GEORGE\Application Data\OnlineArmor
2009-12-11 22:05 . 2006-12-13 04:58 ——– d—–w- c:\documents and settings\GEORGE\Application Data\Skype
2009-12-11 20:33 . 2009-02-17 11:30 4844296 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-11 20:08 . 2009-05-29 06:07 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-04 00:14 . 2009-01-27 03:22 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-04 00:13 . 2009-01-27 03:22 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-21 15:51 . 2006-02-28 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-03 04:42 . 2009-11-01 22:10 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-11-02 00:06 . 2008-10-12 08:39 ——– d—–w- c:\program files\SpywareGuard
2009-11-01 22:40 . 2009-11-01 22:40 ——– d—–w- c:\program files\Microsoft Network Monitor 3
2009-11-01 22:08 . 2008-01-14 19:59 ——– d—–w- c:\program files\Microsoft Silverlight
2009-11-01 22:07 . 2006-11-29 21:52 ——– d—–w- c:\program files\Microsoft Works
2009-11-01 11:19 . 2009-10-18 06:10 ——– d—–w- c:\program files\Microsoft Network Monitor 3(2)
2009-10-29 07:46 . 2006-02-28 12:00 832512 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2006-02-28 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2006-02-28 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-10-21 05:38 . 2006-02-28 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-02-28 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2006-02-28 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2006-02-28 12:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2006-02-28 12:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2006-02-28 12:00 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-08 22:57 . 2008-07-30 03:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2009-10-08 22:57 . 2006-02-28 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 22:56 . 2006-02-28 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2008-09-20 18:42 . 2008-03-08 08:25 88 –sha-r- c:\windows\system32\892202FEA3.sys
2008-06-13 04:32 . 2008-06-13 04:32 23 –sha-w- c:\windows\system32\aafcebeaff4_g.dll
2008-09-20 18:43 . 2008-03-08 08:25 4856 –sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}]
@="{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}"
[HKEY_CLASSES_ROOT\CLSID\{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}]
2009-03-06 03:17 143160 —-a-w- c:\windows\system32\pfmshx_27B.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-17 2002160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"nwiz"="nwiz.exe" [2009-03-28 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 13684736]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 86016]
"@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2009-04-16 2044104]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-10-19 293888]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2009-04-16 335048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-07 20:23 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-10-09 21:33 1949480 —-a-w- c:\program files\Apricorn\EZ Gig II\TimounterMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apricorn Scheduler Service]
2007-10-09 21:24 148712 —-a-w- c:\program files\Common Files\Apricorn\Schedule2\schedhlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2008-03-18 09:06 1848648 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2008-12-12 09:31 722256 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2008-12-17 18:36 50520 —-a-w- c:\documents and settings\GEORGE\Application Data\mjusbsp\cdloader2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 —-a-w- c:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZGigMonitor.exe]
2007-10-09 21:20 1169264 —-a-w- c:\program files\Apricorn\EZ Gig II\EZGigMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GizmoDriveDelegate]
2009-05-01 04:06 390752 —-a-w- c:\progra~1\Gizmo\gdrive.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 18:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJNetworkScanUtility]
2007-05-21 08:37 124512 —-a-w- c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 22:50 221184 —-a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
2007-05-17 21:45 279912 —-a-w- c:\program files\Microsoft LifeCam\LifeExp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2007-06-13 17:39 73728 —-a-w- c:\program files\ScanSoft\OmniPageSE4\OpWareSE4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
2004-03-11 08:26 406016 —-a-w- c:\windows\system32\PSDrvCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2009-03-15 10:15 180224 —-a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\siService.exe]
2003-12-23 18:31 204800 —-a-w- c:\program files\Sunbelt Software\iHateSpam\siService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 16:03 210472 —-a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-04-27 18:56 1410296 —-a-w- c:\program files\GAMES\Steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-05-21 18:34 148888 —-a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX6000]
2007-04-10 21:46 996712 —-a-w- c:\windows\vVX6000.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SQLWriter"=2 (0x2)
"SQLBrowser"=2 (0x2)
"MSSQL$MSSMLBIZ"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AdobeUpdater"=c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Plugin Install"=c:\program files\QuickTime\Plugins\DeleteMe1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Sunbelt Software\\iHateSpam\\siMailProxyServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Google\\Google Updater\\GoogleUpdater.exe"=
"c:\\Program Files\\PowerFile C200\\PowerFile.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\GAMES\\Steam\\SteamApps\\common\\empire total war\\Empire.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Logging]
"LogSuccessfulConnections"= 0 (0x0)
"LogDroppedPackets"= 0 (0x0)
"LogFileSize"= 0 (0x0)
"LogFilePath"=
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [3/12/2009 2:23 PM 40368]
R1 DiscImage;Disc image driver;c:\windows\system32\drivers\discimage.sys [5/26/2007 7:04 PM 24704]
R1 GizmoDrv;Gizmo Device Driver;c:\windows\system32\drivers\gizmodrv.sys [4/30/2009 8:07 PM 23624]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [5/28/2009 10:17 PM 196688]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [5/28/2009 10:17 PM 31824]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [5/28/2009 10:17 PM 29776]
R1 pfmfs_27B;pfmfs_27B;c:\windows\system32\drivers\pfmfs_27B.sys [4/30/2009 8:05 PM 179896]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [8/19/2008 11:34 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/19/2008 11:34 PM 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [5/28/2009 10:12 PM 1858144]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/28/2009 10:07 PM 108289]
R2 DIMSVC;Disc Image Demo mount service;c:\program files\Pa-software\Disc Image Demo\dimsvc.exe [5/26/2007 7:03 PM 36864]
R2 Gizmo Central;Gizmo Central;c:\program files\Gizmo\gservice.exe [4/30/2009 8:06 PM 31856]
R2 SMART-ERService;SMART-ER Service;c:\program files\Apricorn\SMART-ER\SMART-ER Service.exe [6/4/2007 10:20 AM 69632]
R2 VirtualDrive;VirtualDrive;c:\program files\All Image\vdd-x86.sys [4/30/2009 7:41 PM 10752]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [4/19/2008 1:46 PM 30560]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/19/2008 11:34 PM 7408]
S1 AntiLog32;AntiLog32;\??\c:\program files\AntiLogger\AntiLog32.sys –> c:\program files\AntiLogger\AntiLog32.sys [?]
S2 AnonMgmtSvc;Anonymizer Management Service;"c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe" –> c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe [?]
S2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [5/28/2009 10:17 PM 361160]
S2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [5/28/2009 10:17 PM 3049160]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\GEORGE\LOCALS~1\Temp\ALSysIO.sys –> c:\docume~1\GEORGE\LOCALS~1\Temp\ALSysIO.sys [?]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 DarkSpy;DarkSpy;\??\c:\windows\system32\DarkSpyKernel.sys –> c:\windows\system32\DarkSpyKernel.sys [?]
S3 dpK0Bx01;Fingerprint Reader Filter Driver;c:\windows\system32\drivers\dpK0Bx01.sys [1/5/2007 3:45 PM 35584]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [3/24/2009 12:15 PM 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [3/24/2009 12:15 PM 3072]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [8/17/2005 11:00 PM 7168]
S3 IntelDH;IntelDH Driver;c:\windows\system32\Drivers\IntelDH.sys –> c:\windows\system32\Drivers\IntelDH.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\16.tmp –> c:\windows\system32\16.tmp [?]
S3 PORTMON;PORTMON;\??\c:\documents and settings\GEORGE\Desktop\DOWNLOADS\Portmon\PORTMSYS.SYS –> c:\documents and settings\GEORGE\Desktop\DOWNLOADS\Portmon\PORTMSYS.SYS [?]
S3 SWUSBFLT;Microsoft SideWinder VIA Filter Driver;c:\windows\system32\drivers\SWUSBFLT.SYS [12/22/2006 10:46 PM 3968]
S3 UsbdpFP;Fingerprint Reader Class Driver;c:\windows\system32\drivers\usbdpfp.sys [1/5/2007 3:45 PM 47360]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [12/12/2006 6:43 PM 2385896]
S3 xusb20;Xbox 360 Wireless Receiver for Windows Driver Service;c:\windows\system32\drivers\xusb20.sys [10/13/2006 5:19 PM 50048]
S3 yeddef;YEDDEF driver;c:\windows\system32\Drivers\yeddef.sys –> c:\windows\system32\Drivers\yeddef.sys [?]
S3 ZD1211U(Hawking Technologies);Hawking Technologies HWU54D Hi-Gain Wireless-G USB Adapter(Hawking Technologies);c:\windows\system32\drivers\ZD1211U.sys [12/6/2006 4:17 AM 233472]
S4 gupdate1c901a09a323bba;Google Update Service (gupdate1c901a09a323bba);c:\program files\Google\Update\GoogleUpdate.exe [8/18/2008 6:09 PM 133104]
S4 NSLHNZKPEI;NSLHNZKPEI;c:\docume~1\GEORGE\LOCALS~1\Temp\NSLHNZKPEI.exe –> c:\docume~1\GEORGE\LOCALS~1\Temp\NSLHNZKPEI.exe [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4/30/2009 6:14 PM 721904]
S4 TABKB;TABKB;c:\docume~1\GEORGE\LOCALS~1\Temp\TABKB.exe –> c:\docume~1\GEORGE\LOCALS~1\Temp\TABKB.exe [?]
— Other Services/Drivers In Memory —
*Deregistered* - PROCEXP111
.
——- Supplementary Scan ——-
.
uLocal Page = hxxp://www.msn.com
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
Handler: msell2 - {9367D24B-8506-471A-915A-CFBB4BCEB631} - c:\program files\Common Files\Microsoft Shared\Reference Titles\MSELL2.dll
DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} - hxxps://actsvr.comcastonline.com/techtools/dl/Comcast%20Activation%20Controls.cab
FF - ProfilePath - c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\
FF - prefs.js: browser.startup.homepage - msn.com
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
FF - component: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - plugin: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npdeploytk.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npnul32.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - (no file)
Notify-DPWLN - (no file)
MSConfigStartUp-Anonymizer - c:\program files\Anonymizer\Anonymizer Software\Anonymizer.exe
AddRemove-AntiLogger - c:\documents and settings\All Users\Application Data\{DBBDCE5C-C9B7-4F00-BA4F-3D64168B6576}\AntiLogger_Setup.exe
AddRemove-BrothersInArms - e:\brothersinarms\System\Setup.exe
AddRemove-BrothersInArmsEiB - e:\ubisoft\Gearbox Software\BrothersInArmsEiB\System\Setup.exe
AddRemove-BrothersInArmsEIBSDK - e:\ubisoft\Gearbox Software\BrothersInArmsEiB\EIBSDKUninstall.exe
AddRemove-CompleteDoItYourselfGuide - d:\data\diyguide.exe
AddRemove-FoxyTunesForFirefox - c:\program files\Mozilla Firefox\firefox.exe
AddRemove-Microsoft MSDN 2005 Express Edition - ENU - e:\program files\Microsoft Visual Studio 8\Microsoft MSDN 2005 Express Edition - ENU\install.exe
AddRemove-Microsoft Visual Web Developer 2005 Express Edition - ENU - e:\program files\Microsoft Visual Studio 8\Microsoft Visual Web Developer 2005 Express Edition - ENU\setup.exe
AddRemove-Mozilla Firefox (2.0.0.20) - c:\program files\Mozilla Firefox\uninstall\helper.exe
AddRemove-Nero PhotoShow Express 4 - e:\nero photoshow 4\data\Xtras\Uninstall.exe
AddRemove-{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 - c:\program files\Spybot - Search & Destroy\unins001.exe
AddRemove-{C5089197-5B15-44AD-B0FC-2E94EE9ECB63} - c:\documents and settings\GEORGE\Local Settings\Application Data\{044CCC32-19C8-40C9-92DE-7D50DCAC47BA}\wsc.exe
**************************************************************************
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\16.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-3060164775-2224625509-1354611237-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1076)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'lsass.exe'(1136)
c:\windows\system32\relog_ap.dll
c:\windows\DPPWDFLT.dll
.
Completion time: 2009-12-29 00:23:48
ComboFix-quarantined-files.txt 2009-12-29 08:23
Pre-Run: 15,852,703,744 bytes free
Post-Run: 15,987,843,072 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - B55EF24745AE95E2F263C0B3DC025394
I ran defogger. I ran the combo-fix.exe program. During the process, Combo stated not to start any program, I needed to download recovery console.
which I suppose it installed. It stated not to click on the program but after it started running a screen popped up saying swxcalx.cfxxe is corrupt and windows
needs to run chkdsk now click OK which I didn't do….was wondering if this was legit or not. Finished posted below
ComboFix 09-12-28.03 - GEORGE 12/29/2009 0:16.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2560 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\VIRUS SCAN PROCEDURES
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
ADS - WINDOWS: deleted 72 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-303087950-19637512-4056949597-1000
c:\documents and settings\GEORGE\Application Data\inst.exe
c:\documents and settings\GEORGE\My Documents\022809reg.reg
c:\documents and settings\GEORGE\My Documents\7-14-08.reg
c:\documents and settings\GEORGE\My Documents\backup.reg
c:\documents and settings\GEORGE\My Documents\BACKUP120107.reg
c:\documents and settings\GEORGE\My Documents\dec292008reg.reg
c:\documents and settings\GEORGE\My Documents\december15.reg
c:\documents and settings\GEORGE\My Documents\feb1408.reg
c:\documents and settings\GEORGE\My Documents\reg021109.reg
c:\recycler\S-1-5-21-1446432944-476004442-2805334122-1006
c:\windows\Downloaded Program Files\Temp
c:\windows\EventSystem.log
c:\windows\system\oeminfo.ini
c:\windows\system32\drivers\1028_DELL_XPS_Dell DXP061 .MRK
c:\windows\system32\drivers\DELL_XPS_Dell DXP061 .MRK
c:\windows\system32\vobis32.dll
.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-29 )))))))))))))))))))))))))))))))
.
2009-12-23 11:16 . 2009-12-23 11:16 ——– d—–w- c:\program files\Softwin
2009-12-21 10:52 . 2009-12-21 10:52 ——– d—–w- c:\program files\Sophos
2009-12-18 11:19 . 2009-12-29 04:57 52224 —-a-w- c:\documents and settings\GEORGE\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-18 10:52 . 2009-12-17 22:14 150888 —-a-w- C:\Tcpvcon.exe
2009-12-17 20:11 . 2008-04-14 01:11 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2009-12-12 08:31 . 2009-12-12 09:02 15 —-a-w- c:\documents and settings\GEORGE\settings.dat
2009-12-12 00:42 . 2009-12-12 00:42 ——– d—–w- c:\program files\MSXML 4.0
2009-12-12 00:37 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2009-12-11 22:00 . 2009-08-25 09:30 13312 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
2009-12-11 22:00 . 2009-10-20 21:33 545280 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\PicLensHelper.exe
2009-12-11 22:00 . 2009-10-20 21:33 4716544 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
2009-12-11 22:00 . 2009-10-20 21:33 344064 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\LaunchCooliris.exe
2009-12-11 22:00 . 2009-10-20 21:33 153600 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
2009-12-11 22:00 . 2009-10-20 21:33 103424 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\pixomatic.dll
2009-12-11 21:56 . 2009-12-29 05:06 ——– d—–w- c:\program files\Mozilla Firefox 3.55
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 07:58 . 2008-07-21 03:46 ——– d—–w- c:\program files\Mozilla Firefox3.0
2009-12-29 05:05 . 2007-09-18 10:38 ——– d—–w- c:\program files\Mozilla Firefox2.0
2009-12-29 05:01 . 2007-12-02 21:43 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-29 05:01 . 2008-02-06 16:14 ——– d—–w- c:\program files\SpywareBlaster
2009-12-29 05:00 . 2006-12-13 07:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-29 04:57 . 2009-03-17 20:59 117760 —-a-w- c:\documents and settings\GEORGE\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-20 01:55 . 2006-12-13 07:16 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-19 10:22 . 2006-11-29 21:40 ——– d—–w- c:\program files\Java
2009-12-19 10:00 . 2006-11-29 21:47 ——– d—–w- c:\program files\Real
2009-12-19 09:52 . 2006-11-29 21:44 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-19 08:57 . 2006-11-29 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-12-19 08:33 . 2006-11-29 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\QuickTime
2009-12-19 08:31 . 2008-02-15 21:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-19 08:12 . 2007-09-21 23:12 ——– d—–w- c:\program files\Microsoft Location Finder
2009-12-19 07:46 . 2006-11-29 21:47 ——– d—–w- c:\program files\Common Files\Real
2009-12-19 07:44 . 2008-03-04 22:06 ——– d—–w- c:\program files\CounterPath
2009-12-19 07:21 . 2006-12-07 10:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Windows Live Toolbar
2009-12-19 07:18 . 2007-10-06 17:03 ——– d—–w- c:\program files\MSN Money Toolbar Add-in
2009-12-19 07:17 . 2006-11-29 21:52 ——– d—–w- c:\program files\Yahoo!
2009-12-19 06:31 . 2008-03-27 03:06 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-19 02:42 . 2009-01-27 03:22 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-18 11:17 . 2009-05-29 06:12 ——– d—–w- c:\program files\a-squared Free
2009-12-17 22:10 . 2008-06-20 21:56 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-12-17 20:12 . 2009-12-17 20:12 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-12-17 20:12 . 2009-12-17 20:12 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-12-15 05:01 . 2009-04-28 03:50 95744 —-a-w- c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll
2009-12-12 01:31 . 2007-02-02 04:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-12 00:48 . 2006-11-29 21:53 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-12-12 00:24 . 2009-05-29 06:17 ——– d—–w- c:\documents and settings\GEORGE\Application Data\OnlineArmor
2009-12-11 22:05 . 2006-12-13 04:58 ——– d—–w- c:\documents and settings\GEORGE\Application Data\Skype
2009-12-11 20:33 . 2009-02-17 11:30 4844296 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-11 20:08 . 2009-05-29 06:07 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-04 00:14 . 2009-01-27 03:22 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-04 00:13 . 2009-01-27 03:22 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-21 15:51 . 2006-02-28 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-03 04:42 . 2009-11-01 22:10 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-11-02 00:06 . 2008-10-12 08:39 ——– d—–w- c:\program files\SpywareGuard
2009-11-01 22:40 . 2009-11-01 22:40 ——– d—–w- c:\program files\Microsoft Network Monitor 3
2009-11-01 22:08 . 2008-01-14 19:59 ——– d—–w- c:\program files\Microsoft Silverlight
2009-11-01 22:07 . 2006-11-29 21:52 ——– d—–w- c:\program files\Microsoft Works
2009-11-01 11:19 . 2009-10-18 06:10 ——– d—–w- c:\program files\Microsoft Network Monitor 3(2)
2009-10-29 07:46 . 2006-02-28 12:00 832512 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2006-02-28 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2006-02-28 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-10-21 05:38 . 2006-02-28 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-02-28 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2006-02-28 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2006-02-28 12:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2006-02-28 12:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2006-02-28 12:00 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-08 22:57 . 2008-07-30 03:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2009-10-08 22:57 . 2006-02-28 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 22:56 . 2006-02-28 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2008-09-20 18:42 . 2008-03-08 08:25 88 –sha-r- c:\windows\system32\892202FEA3.sys
2008-06-13 04:32 . 2008-06-13 04:32 23 –sha-w- c:\windows\system32\aafcebeaff4_g.dll
2008-09-20 18:43 . 2008-03-08 08:25 4856 –sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}]
@="{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}"
[HKEY_CLASSES_ROOT\CLSID\{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}]
2009-03-06 03:17 143160 —-a-w- c:\windows\system32\pfmshx_27B.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-17 2002160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"nwiz"="nwiz.exe" [2009-03-28 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 13684736]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 86016]
"@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2009-04-16 2044104]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-10-19 293888]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2009-04-16 335048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-07 20:23 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-10-09 21:33 1949480 —-a-w- c:\program files\Apricorn\EZ Gig II\TimounterMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apricorn Scheduler Service]
2007-10-09 21:24 148712 —-a-w- c:\program files\Common Files\Apricorn\Schedule2\schedhlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2008-03-18 09:06 1848648 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2008-12-12 09:31 722256 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2008-12-17 18:36 50520 —-a-w- c:\documents and settings\GEORGE\Application Data\mjusbsp\cdloader2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 —-a-w- c:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZGigMonitor.exe]
2007-10-09 21:20 1169264 —-a-w- c:\program files\Apricorn\EZ Gig II\EZGigMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GizmoDriveDelegate]
2009-05-01 04:06 390752 —-a-w- c:\progra~1\Gizmo\gdrive.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 18:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJNetworkScanUtility]
2007-05-21 08:37 124512 —-a-w- c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 22:50 221184 —-a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
2007-05-17 21:45 279912 —-a-w- c:\program files\Microsoft LifeCam\LifeExp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2007-06-13 17:39 73728 —-a-w- c:\program files\ScanSoft\OmniPageSE4\OpWareSE4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
2004-03-11 08:26 406016 —-a-w- c:\windows\system32\PSDrvCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2009-03-15 10:15 180224 —-a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\siService.exe]
2003-12-23 18:31 204800 —-a-w- c:\program files\Sunbelt Software\iHateSpam\siService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 16:03 210472 —-a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-04-27 18:56 1410296 —-a-w- c:\program files\GAMES\Steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-05-21 18:34 148888 —-a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX6000]
2007-04-10 21:46 996712 —-a-w- c:\windows\vVX6000.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SQLWriter"=2 (0x2)
"SQLBrowser"=2 (0x2)
"MSSQL$MSSMLBIZ"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AdobeUpdater"=c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Plugin Install"=c:\program files\QuickTime\Plugins\DeleteMe1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Sunbelt Software\\iHateSpam\\siMailProxyServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Google\\Google Updater\\GoogleUpdater.exe"=
"c:\\Program Files\\PowerFile C200\\PowerFile.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\GAMES\\Steam\\SteamApps\\common\\empire total war\\Empire.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Logging]
"LogSuccessfulConnections"= 0 (0x0)
"LogDroppedPackets"= 0 (0x0)
"LogFileSize"= 0 (0x0)
"LogFilePath"=
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [3/12/2009 2:23 PM 40368]
R1 DiscImage;Disc image driver;c:\windows\system32\drivers\discimage.sys [5/26/2007 7:04 PM 24704]
R1 GizmoDrv;Gizmo Device Driver;c:\windows\system32\drivers\gizmodrv.sys [4/30/2009 8:07 PM 23624]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [5/28/2009 10:17 PM 196688]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [5/28/2009 10:17 PM 31824]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [5/28/2009 10:17 PM 29776]
R1 pfmfs_27B;pfmfs_27B;c:\windows\system32\drivers\pfmfs_27B.sys [4/30/2009 8:05 PM 179896]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [8/19/2008 11:34 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/19/2008 11:34 PM 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [5/28/2009 10:12 PM 1858144]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/28/2009 10:07 PM 108289]
R2 DIMSVC;Disc Image Demo mount service;c:\program files\Pa-software\Disc Image Demo\dimsvc.exe [5/26/2007 7:03 PM 36864]
R2 Gizmo Central;Gizmo Central;c:\program files\Gizmo\gservice.exe [4/30/2009 8:06 PM 31856]
R2 SMART-ERService;SMART-ER Service;c:\program files\Apricorn\SMART-ER\SMART-ER Service.exe [6/4/2007 10:20 AM 69632]
R2 VirtualDrive;VirtualDrive;c:\program files\All Image\vdd-x86.sys [4/30/2009 7:41 PM 10752]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [4/19/2008 1:46 PM 30560]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/19/2008 11:34 PM 7408]
S1 AntiLog32;AntiLog32;\??\c:\program files\AntiLogger\AntiLog32.sys –> c:\program files\AntiLogger\AntiLog32.sys [?]
S2 AnonMgmtSvc;Anonymizer Management Service;"c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe" –> c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe [?]
S2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [5/28/2009 10:17 PM 361160]
S2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [5/28/2009 10:17 PM 3049160]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\GEORGE\LOCALS~1\Temp\ALSysIO.sys –> c:\docume~1\GEORGE\LOCALS~1\Temp\ALSysIO.sys [?]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 DarkSpy;DarkSpy;\??\c:\windows\system32\DarkSpyKernel.sys –> c:\windows\system32\DarkSpyKernel.sys [?]
S3 dpK0Bx01;Fingerprint Reader Filter Driver;c:\windows\system32\drivers\dpK0Bx01.sys [1/5/2007 3:45 PM 35584]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [3/24/2009 12:15 PM 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [3/24/2009 12:15 PM 3072]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [8/17/2005 11:00 PM 7168]
S3 IntelDH;IntelDH Driver;c:\windows\system32\Drivers\IntelDH.sys –> c:\windows\system32\Drivers\IntelDH.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\16.tmp –> c:\windows\system32\16.tmp [?]
S3 PORTMON;PORTMON;\??\c:\documents and settings\GEORGE\Desktop\DOWNLOADS\Portmon\PORTMSYS.SYS –> c:\documents and settings\GEORGE\Desktop\DOWNLOADS\Portmon\PORTMSYS.SYS [?]
S3 SWUSBFLT;Microsoft SideWinder VIA Filter Driver;c:\windows\system32\drivers\SWUSBFLT.SYS [12/22/2006 10:46 PM 3968]
S3 UsbdpFP;Fingerprint Reader Class Driver;c:\windows\system32\drivers\usbdpfp.sys [1/5/2007 3:45 PM 47360]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [12/12/2006 6:43 PM 2385896]
S3 xusb20;Xbox 360 Wireless Receiver for Windows Driver Service;c:\windows\system32\drivers\xusb20.sys [10/13/2006 5:19 PM 50048]
S3 yeddef;YEDDEF driver;c:\windows\system32\Drivers\yeddef.sys –> c:\windows\system32\Drivers\yeddef.sys [?]
S3 ZD1211U(Hawking Technologies);Hawking Technologies HWU54D Hi-Gain Wireless-G USB Adapter(Hawking Technologies);c:\windows\system32\drivers\ZD1211U.sys [12/6/2006 4:17 AM 233472]
S4 gupdate1c901a09a323bba;Google Update Service (gupdate1c901a09a323bba);c:\program files\Google\Update\GoogleUpdate.exe [8/18/2008 6:09 PM 133104]
S4 NSLHNZKPEI;NSLHNZKPEI;c:\docume~1\GEORGE\LOCALS~1\Temp\NSLHNZKPEI.exe –> c:\docume~1\GEORGE\LOCALS~1\Temp\NSLHNZKPEI.exe [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4/30/2009 6:14 PM 721904]
S4 TABKB;TABKB;c:\docume~1\GEORGE\LOCALS~1\Temp\TABKB.exe –> c:\docume~1\GEORGE\LOCALS~1\Temp\TABKB.exe [?]
— Other Services/Drivers In Memory —
*Deregistered* - PROCEXP111
.
——- Supplementary Scan ——-
.
uLocal Page = hxxp://www.msn.com
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
Handler: msell2 - {9367D24B-8506-471A-915A-CFBB4BCEB631} - c:\program files\Common Files\Microsoft Shared\Reference Titles\MSELL2.dll
DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} - hxxps://actsvr.comcastonline.com/techtools/dl/Comcast%20Activation%20Controls.cab
FF - ProfilePath - c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\
FF - prefs.js: browser.startup.homepage - msn.com
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
FF - component: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - plugin: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npdeploytk.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npnul32.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - (no file)
Notify-DPWLN - (no file)
MSConfigStartUp-Anonymizer - c:\program files\Anonymizer\Anonymizer Software\Anonymizer.exe
AddRemove-AntiLogger - c:\documents and settings\All Users\Application Data\{DBBDCE5C-C9B7-4F00-BA4F-3D64168B6576}\AntiLogger_Setup.exe
AddRemove-BrothersInArms - e:\brothersinarms\System\Setup.exe
AddRemove-BrothersInArmsEiB - e:\ubisoft\Gearbox Software\BrothersInArmsEiB\System\Setup.exe
AddRemove-BrothersInArmsEIBSDK - e:\ubisoft\Gearbox Software\BrothersInArmsEiB\EIBSDKUninstall.exe
AddRemove-CompleteDoItYourselfGuide - d:\data\diyguide.exe
AddRemove-FoxyTunesForFirefox - c:\program files\Mozilla Firefox\firefox.exe
AddRemove-Microsoft MSDN 2005 Express Edition - ENU - e:\program files\Microsoft Visual Studio 8\Microsoft MSDN 2005 Express Edition - ENU\install.exe
AddRemove-Microsoft Visual Web Developer 2005 Express Edition - ENU - e:\program files\Microsoft Visual Studio 8\Microsoft Visual Web Developer 2005 Express Edition - ENU\setup.exe
AddRemove-Mozilla Firefox (2.0.0.20) - c:\program files\Mozilla Firefox\uninstall\helper.exe
AddRemove-Nero PhotoShow Express 4 - e:\nero photoshow 4\data\Xtras\Uninstall.exe
AddRemove-{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 - c:\program files\Spybot - Search & Destroy\unins001.exe
AddRemove-{C5089197-5B15-44AD-B0FC-2E94EE9ECB63} - c:\documents and settings\GEORGE\Local Settings\Application Data\{044CCC32-19C8-40C9-92DE-7D50DCAC47BA}\wsc.exe
**************************************************************************
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\16.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-3060164775-2224625509-1354611237-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1076)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'lsass.exe'(1136)
c:\windows\system32\relog_ap.dll
c:\windows\DPPWDFLT.dll
.
Completion time: 2009-12-29 00:23:48
ComboFix-quarantined-files.txt 2009-12-29 08:23
Pre-Run: 15,852,703,744 bytes free
Post-Run: 15,987,843,072 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - B55EF24745AE95E2F263C0B3DC025394
Thanks I disable all software other then going into taskmanager to kill process trees which it wouldn't le tme do anyway . Also S3 show Dark Spy DarkSpyKernel.sys, I was on a dark read site which boast that they can tunnel or pentrate any system against any anti spy,mal, trojan etc detection sofware. I may have been playing in their sanbox to see if my computer could be penetrated. fYI
Hi,
Please do the following:
NEXT
Go to Start > Run > type
sc delete TABKB
press enter, then Go to Start > Run > type
sc delete NSLHNZKPEI
press enter
NEXT
Please open your MalwareBytes AntiMalware Program Click the Update Tab and search for updates If an update is found, it will download and install the latest version. Once the program has loaded, select "Perform Quick Scan" , then click Scan. The scan may take some time to finish, so please be patient. When the scan is complete, click OK , then Show Results to view the results. Make sure that everything is checked, and click Remove Selected . <– very important When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note) The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM. Copy&Paste the entire report in your next reply.
Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
NEXT
Run an on-line scan with Kaspersky
Using Internet Explorer or Firefox, visit
Kaspersky On-line Scanner
1. Click
Accept , when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
Close any open programs Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click
Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan. Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it. Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined. Click View scan report at the bottom.
[external image: Posted Image]
Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
In your next reply please include
I uploaded the file to virus scan and it was clean
I executed your next statement TABKB
Malwarebytes' Anti-Malware 1.42
Database version: 3450
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
12/29/2009 10:09:52 AM
mbam-log-2009-12-29 (10-09-52).txt
Scan type: Quick Scan
Objects scanned: 135921
Time elapsed: 6 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
I ran Kaspersky an it took 7 hours and everything was clean on Drive C. The report came up empty when I stopped it.
I stopped the scan as I have 3 other drives that are TB each and would have probably takne me a week to finish the scan since Drive C was the main Drive with problems. I couldn't specify Drive C only.
So hmm I was wondering if it could be something like Conflicker where it hides from most scanning software. Can someone put software on my computer and access the computer remotely without the scanning software detecting it or put software that can change security policies or permissions?
I notice when I start firefox, I get a lot of schost.exe files and when I click on processes I notice different number of SID with ? markes on them that give full control. I also have a group called interactive and another everyman with full access. When I start to probe by using whois TCP Viewer will flash red on about ten or so connections and then they will all disappear.
I would say your computer is clean of malware, ComboFix took care of it.
Please post a fresh DDS and Attach.txt
Did you also delete NSLHNZKPEI as well?
Why is it when, and this is getting way over my head, that when I log into the internet, I have a09-17-148-58.deploy.AKAMAITECHNOLOGIES.COM Cambridge, MA 02142 logged on and connected to me on ports 3116, 3130, 3133, 3134, 3138, 3139? When I look at the TCP/IP under process and highlight them under Security I have Mandatory: Everyone, Local, Interactive and SID s-5-5-0-77779 as groups even though that SID is not in my registry . When I snoop further, all those lines in TCPview flash red and disappear from TCP viewer and my normal connections to comcast are left? Am I being to paranoid? Why are they connected to me?
I attach the txt files which the window said I should do instead of pasting it the reply where the whole world can view my programs
Thanks for all your help!
Forgot to add:
Did you also delete NSLHNZKPEI as well? YES
I also attach Avira log file from a 12/12 scan that quarantine, I think, some problems
Hi,
The connection issue I can't answer at all, I'm afraid that isn't my area of expertise.
The log isn't showing any more malware on your system.
I suggest we clean up our tools here. Then post a new topic in out Browsers, Internet and email forum and let the expert techs check the connections.
Please do the following:
Follow these steps to uninstall Combofix
Click START then RUN Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U , it needs to be there.
[external image: Posted Image]
NEXT
Now to remove the rest of the tools that we have used in fixing your machine: Make sure you have an Internet Connection. Download OTC to your desktop and run it A list of tool components used in the Cleanup of malware will be downloaded. If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so. Click Yes to begin the Cleanup process and remove these components, including this application. You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.
NEXT
Below I have included a number of recommendations for how to protect your computer against malware infections.
It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
Strong passwords: How to create and use them
Then consider a password keeper, to keep all your passwords safe.
Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.
Make Internet Explorer more secure
Click Start > Run Type Inetcpl.cpl & click OK Click on the Security tab Click Reset all zones to default level Make sure the Internet Zone is selected & Click Custom level In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable". Next Click OK , then Apply button and then OK to exit the Internet Properties page. ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
WOT , Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:Green to go Yellow for caution Red to stop WOT has an addon available for both Firefox, IE and chrome.
Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
Think Prevention.
PC Safety and Security–What Do I Need?.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.