This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Critical: System compromised Rootkit, Trojan backdoor Hidde

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am on a dual boot system dual boot Windows XP Pro SP3 and Vista 64bit Ultimate but this relates for now on Windows XP Pro. I noticed unusual activity on my hard drive when not in use. It will start accessing the hard drive for long periods of time. I launched MS procexp.exe and notice a large number of processes occurring Improcserv32 and svchost processes. I did a netstart with various switches -anfotr and notice a large number of connections to various tcp and udp ports from ip addresses I did not recognize. On whois some are in foreign countries. I believe that my system is compromised by a rootkit or backdoor trojan or hidden services as my Avira, malwarebytes, Superantispyware, sypbot, spywareblaster, & winpatrol show that my system is clean. I added Online Armor firewall thinking that would help but to know avail. So I suspect some rogue software is hidden below their scans. Can any one help me or point me to the right direction. I do a lot of financial transactions. I use firefox and use cc cleaner after each internet connection. Thanks
Hi,

please do the following:

Please download exeHelper to your desktop.
  • Double-click on exeHelper.com to run the fix.
  • A black window should pop up, press any key to close once the fix is completed.
  • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
exeHelper by Raktor Build 20091220 Run at 20:27:32 on 12/28/09 Now searching… Checking for numerical processes… Checking for sysguard processes… Checking for bad processes… Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished– exeHelper by Raktor Build 20091220 Run at 20:51:34 on 12/28/09 Now searching… Checking for numerical processes… Checking for sysguard processes… Checking for bad processes… Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished– DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 14:38:07.75 on Sat 12/12/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2116 [GMT -8:00] AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} FW: Online Armor Firewall *enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Tall Emu\Online Armor\OAcat.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe svchost.exe C:\Program Files\a-squared Free\a2service.exe C:\Program Files\Common Files\Apricorn\Schedule2\schedul2.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Program Files\Bonjour\mDNSResponder.exe svchost.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\Pa-software\Disc Image Demo\dimsvc.exe C:\Program Files\DigitalPersona\Bin\DpHost.exe C:\Program Files\Gizmo\gservice.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Microsoft LifeCam\MSCamS32.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Apricorn\SMART-ER\SMART-ER Service.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe C:\WINDOWS\Explorer.EXE C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Tall Emu\Online Armor\oaui.exe C:\Program Files\Tall Emu\Online Armor\OAhlp.exe C:\Program Files\Tall Emu\Online Armor\oasrv.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\BillP Studios\WinPatrol\WinPatrolEx.exe C:\Program Files\Wisdom-soft ScreenHunter 5 Free\ScreenHunter.exe C:\Documents and Settings\JUNE\Desktop\iexplore.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe C:\Documents and Settings\June\Desktop\VIRUS SCAN PROCEDURES &PROGRAMS\dds.scr ============== Pseudo HJT Report =============== uLocal Page = hxxp://www.msn.com uSearch Page = hxxp://google.com uDefault_Page_URL = hxxp://www.msn.com uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll {5ca3d70e-1895-11cf-8e15-001234567890} BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File BHO: Encarta Web Companion Helper Object: {955be0b8-bc85-4caf-856e-8e0d8b610560} - c:\program files\common files\microsoft shared\encarta web companion\2007\ENCWCBAR.DLL BHO: {A057A204-BACC-4D26-9990-79A187E2698E} - No File BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\4.1.805.4472\swg.dll BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll BHO: 1 (0x1) - No File BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll TB: Encarta Web Companion: {147d6308-0614-4112-89b1-31402f9b82c4} - c:\program files\common files\microsoft shared\encarta web companion\2007\ENCWCBAR.DLL TB: Hotmail Spam Filter: {58a83e4f-477a-4a3f-bf9b-b65bc2bd5598} - c:\program files\sunbelt software\ihatespam\siClientUIHotmail.dll TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File TB: {EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide mRun: [nwiz] nwiz.exe /install mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [@OnlineArmor GUI] "c:\program files\tall emu\online armor\oaui.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t IE: &Clean Traces - c:\program files\dap\privacy package\dapcleanerie.htm IE: &Download with &DAP - c:\program files\dap\dapextie.htm IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM IE: Download &all with DAP - c:\program files\dap\dapextie2.htm IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi1933~1\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL IE: {B6F776D7-C231-11D4-8158-005004ADEFCA} - {B3FD2434-2839-4750-A849-FF8FC0C54E5F} - c:\program files\software river solutions\visual whois 2004\srstools.dll IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/su/ocx/15026/CTSUEng.cab DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} - hxxp://download.microsoft.com/download/7/0/7/707a44ad-52ad-49af-b7ef-e21b6b0656e4/VirtualEarth3D.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} - hxxp://download.microsoft.com/download/7/1/D/71D9F11F-0C02-4707-9D60-D56EA8951020/pmupd806.exe DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} - hxxps://actsvr.comcastonline.com/techtools/dl/Comcast%20Activation%20Controls.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1166092553967 DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://support.f-secure.com/ols/fscax.cab DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/su/ocx/15028/CTPID.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} - c:\program files\microsoft activesync\aatp.dll Handler: msell2 - {9367D24B-8506-471A-915A-CFBB4BCEB631} - c:\program files\common files\microsoft shared\reference titles\MSELL2.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll WinCE Filter: image/bmp - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\progra~1\mi3aa1~1\CENetFlt.dll WinCE Filter: image/gif - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\progra~1\mi3aa1~1\CENetFlt.dll WinCE Filter: image/jpeg - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\progra~1\mi3aa1~1\CENetFlt.dll WinCE Filter: image/xbm - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\progra~1\mi3aa1~1\CENetFlt.dll WinCE Filter: text/asp - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\progra~1\mi3aa1~1\CENetFlt.dll WinCE Filter: text/html - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\progra~1\mi3aa1~1\CENetFlt.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL Notify: DPWLN - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL SEH: OA Shell Helper: {4f07da45-8170-4859-9b5f-037ef2970034} - c:\progra~1\tallem~1\online~1\oaevent.dll LSA: Authentication Packages = msv1_0 relog_ap LSA: Notification Packages = scecli DPPWDFLT Hosts: 127.0.0.1 www.spywareinfo.com ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\June\applic~1\mozilla\firefox\profiles\c5k4s1z3.default\ FF - prefs.js: browser.startup.homepage - msn.com FF - component: c:\documents and settings\June\application data\mozilla\firefox\profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll FF - component: c:\documents and settings\june\application data\mozilla\firefox\profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll FF - component: c:\program files\dap\dapfirefox\components\DAPFireFox.dll FF - plugin: c:\documents and settings\june \application data\mozilla\firefox\profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll FF - plugin: c:\program files\google\google earth plugin\npgeplugin.dll FF - plugin: c:\program files\google\google updater\2.4.1368.5602\npCIDetect13.dll FF - plugin: c:\program files\google\update\1.2.141.5\npGoogleOneClick7.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ —- FIREFOX POLICIES —- c:\program files\mozilla firefox 3.55\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); ============= SERVICES / DRIVERS =============== R0 AVG Anti-Rootkit;AVG Anti-Rootkit;c:\windows\system32\drivers\avgarkt.sys [2007-1-31 5632] R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2009-3-12 40368] R1 AvgArCln;Avg Anti-Rootkit Clean Driver;c:\windows\system32\drivers\AvgArCln.sys [2007-9-20 3968] R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-5-28 11608] R1 DiscImage;Disc image driver;c:\windows\system32\drivers\discimage.sys [2007-5-26 24704] R1 GizmoDrv;Gizmo Device Driver;c:\windows\system32\drivers\gizmodrv.sys [2009-4-30 23624] R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2009-5-28 196688] R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2009-5-28 31824] R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [2009-5-28 29776] R1 pfmfs_27B;pfmfs_27B;c:\windows\system32\drivers\pfmfs_27B.sys [2009-4-30 179896] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2008-8-19 9968] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-8-19 74480] R2 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2009-5-28 1858144] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-5-28 108289] R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-5-28 185089] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-5-28 56816] R2 DIMSVC;Disc Image Demo mount service;c:\program files\pa-software\disc image demo\dimsvc.exe [2007-5-26 36864] R2 Gizmo Central;Gizmo Central;c:\program files\gizmo\gservice.exe [2009-4-30 31856] R2 OAcat;Online Armor Helper Service;c:\program files\tall emu\online armor\oacat.exe [2009-5-28 361160] R2 SMART-ERService;SMART-ER Service;c:\program files\apricorn\smart-er\SMART-ER Service.exe [2007-6-4 69632] R2 SvcOnlineArmor;Online Armor;c:\program files\tall emu\online armor\oasrv.exe [2009-5-28 3049160] R2 VirtualDrive;VirtualDrive;c:\program files\all image\vdd-x86.sys [2009-4-30 10752] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [2008-4-19 30560] R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-8-19 7408] S1 AntiLog32;AntiLog32;\??\c:\program files\antilogger\antilog32.sys –> c:\program files\antilogger\AntiLog32.sys [?] S2 AnonMgmtSvc;Anonymizer Management Service;"c:\program files\anonymizer\anonymizer software\common\anonmgmtsvc.exe" –> c:\program files\anonymizer\anonymizer software\common\AnonMgmtSvc.exe [?] S3 ALSysIO;ALSysIO;\??\c:\docume~1\june\locals~1\temp\alsysio.sys –> c:\docume~1\june\locals~1\temp\ALSysIO.sys [?] S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2008-6-27 99352] S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2008-6-27 99352] S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2008-6-27 555032] S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2008-6-27 555032] S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2008-6-27 100888] S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2008-6-27 100888] S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2008-6-27 566296] S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2008-6-27 566296] S3 dpK0Bx01;Fingerprint Reader Filter Driver;c:\windows\system32\drivers\dpK0Bx01.sys [2007-1-5 35584] S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2009-3-24 8704] S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2009-3-24 3072] S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\lavalys\everest home edition\kerneld.wnt [2005-8-17 7168] S3 IntelDH;IntelDH Driver;c:\windows\system32\drivers\inteldh.sys –> c:\windows\system32\drivers\IntelDH.sys [?] S3 SWUSBFLT;Microsoft SideWinder VIA Filter Driver;c:\windows\system32\drivers\SWUSBFLT.SYS [2006-12-22 3968] S3 UsbdpFP;Fingerprint Reader Class Driver;c:\windows\system32\drivers\usbdpfp.sys [2007-1-5 47360] S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [2006-12-12 2385896] S3 xusb20;Xbox 360 Wireless Receiver for Windows Driver Service;c:\windows\system32\drivers\xusb20.sys [2006-10-13 50048] S3 yeddef;YEDDEF driver;c:\windows\system32\drivers\yeddef.sys –> c:\windows\system32\drivers\yeddef.sys [?] S3 ZD1211U(Hawking Technologies);Hawking Technologies HWU54D Hi-Gain Wireless-G USB Adapter(Hawking Technologies);c:\windows\system32\drivers\ZD1211U.sys [2006-12-6 233472] S4 gupdate1c901a09a323bba;Google Update Service (gupdate1c901a09a323bba);c:\program files\google\update\GoogleUpdate.exe [2008-8-18 133104] S4 NSLHNZKPEI;NSLHNZKPEI;c:\docume~1\june\locals~1\temp\nslhnzkpei.exe –> c:\docume~1\june\locals~1\temp\NSLHNZKPEI.exe [?] S4 TABKB;TABKB;c:\docume~1\june\locals~1\temp\tabkb.exe –> c:\docume~1\june\locals~1\temp\TABKB.exe [?] =============== Created Last 30 ================ 2009-12-12 08:31:59 15 —-a-w- c:\documents and settings\june\settings.dat 2009-12-12 00:42:32 0 d—–w- c:\program files\MSXML 4.0 2009-12-12 00:37:06 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll 2009-12-11 21:56:57 0 d—–w- c:\program files\Mozilla Firefox 3.55 ==================== Find3M ==================== 2009-12-11 20:08:51 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2009-12-04 00:14:06 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-12-04 00:13:56 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-11-03 04:42:06 195456 ——w- c:\windows\system32\MpSigStub.exe 2009-10-29 07:46:59 832512 —-a-w- c:\windows\system32\wininet.dll 2009-10-29 07:46:52 78336 —-a-w- c:\windows\system32\ieencode.dll 2009-10-29 07:46:50 17408 —-a-w- c:\windows\system32\corpol.dll 2009-10-21 05:38:36 75776 —-a-w- c:\windows\system32\strmfilt.dll 2009-10-21 05:38:36 25088 —-a-w- c:\windows\system32\httpapi.dll 2009-10-20 16:20:16 265728 —-a-w- c:\windows\system32\drivers\http.sys 2009-10-13 10:30:16 270336 —-a-w- c:\windows\system32\oakley.dll 2009-10-12 13:38:19 149504 —-a-w- c:\windows\system32\rastls.dll 2009-10-12 13:38:18 79872 —-a-w- c:\windows\system32\raschap.dll 2009-10-08 22:57:02 611328 —-a-w- c:\windows\system32\uiautomationcore.dll 2009-10-08 22:57:00 220160 —-a-w- c:\windows\system32\oleacc.dll 2009-10-08 22:56:56 20480 —-a-w- c:\windows\system32\oleaccrc.dll 2008-09-20 18:42:46 88 –sha-r- c:\windows\system32\892202FEA3.sys 2008-06-13 04:32:03 23 –sha-w- c:\windows\system32\aafcebeaff4_g.dll 2008-09-20 18:43:54 4856 –sha-w- c:\windows\system32\KGyGaAvL.sys 2008-06-11 13:49:32 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008061120080612\index.dat ============= FINISH: 14:40:01.53 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-12-01.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume4 Install Date: 12/14/2006 2:05:00 AM System Uptime: 12/11/2009 4:54:01 PM (22 hours ago) Motherboard: Dell Inc. | | 0WG855 Processor: Intel® Core™2 CPU 6600 @ 2.40GHz | Microprocessor | 2394/1066mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 229 GiB total, 8.015 GiB free. D: is CDROM () E: is Removable F: is FIXED (NTFS) - 385 GiB total, 294.72 GiB free. G: is FIXED (NTFS) - 547 GiB total, 117.799 GiB free. H: is FIXED (NTFS) - 501 GiB total, 70.662 GiB free. I: is Removable J: is Removable K: is CDROM () L: is Removable M: is Removable N: is FIXED (NTFS) - 430 GiB total, 168.489 GiB free. ==== Disabled Device Manager Items ============= Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318} Description: Intel® software driver for Intel® Viiv™ technology Device ID: ROOT\SYSTEM\0004 Manufacturer: Intel Corporation Name: Intel® software driver for Intel® Viiv™ technology PNP Device ID: ROOT\SYSTEM\0004 Service: IntelDH ==== System Restore Points =================== RP1: 4/28/2009 4:18:56 PM - System Checkpoint RP2: 4/30/2009 4:44:02 PM - Software Distribution Service 3.0 RP3: 4/30/2009 5:38:38 PM - Software Distribution Service 3.0 RP4: 4/30/2009 7:14:43 PM - SPTD setup V1.58 RP5: 4/30/2009 11:17:56 PM - Installed PC Inspector File Recovery RP6: 5/2/2009 8:55:06 PM - Installed DirectX RP7: 5/3/2009 1:36:18 AM - Installed DirectX 9.0 RP8: 5/3/2009 3:12:09 AM - Installed Trainz RP9: 5/3/2009 3:45:40 AM - Installed TRS2004 RP10: 5/3/2009 3:52:21 AM - Installed Trainz Paint Shed RP11: 5/3/2009 4:00:38 AM - Installed TRS2006 RP12: 5/3/2009 4:03:56 AM - Installed TRS2006 RP13: 5/3/2009 2:11:22 PM - Installed Silent Hunter Wolves of the Pacific RP14: 5/3/2009 4:02:53 PM - Installed DirectX RP15: 5/3/2009 4:04:31 PM - Installed GameShadow RP16: 5/3/2009 4:05:42 PM - Removed GameShadow RP17: 5/3/2009 4:05:52 PM - Installed GameShadow RP18: 5/3/2009 4:13:27 PM - Installed Medieval II Total War RP19: 5/8/2009 3:57:05 AM - Avg8 Update RP20: 5/8/2009 4:10:21 AM - Avg8 Update RP21: 5/8/2009 4:22:54 AM - Software Distribution Service 3.0 RP22: 5/8/2009 4:23:54 AM - Revo Uninstaller's restore point - Medal of Honor Allied Assault RP23: 5/8/2009 4:24:29 AM - Removed Medal of Honor Allied Assault RP24: 5/8/2009 4:28:37 AM - Revo Uninstaller's restore point - Medal of Honor Allied Assault™ Breakthrough RP25: 5/8/2009 4:28:46 AM - Removed Medal of Honor Allied Assault™ Breakthrough RP26: 5/8/2009 4:30:10 AM - Revo Uninstaller's restore point - Medal of Honor Allied Assault™ Spearhead RP27: 5/8/2009 4:30:20 AM - Removed Medal of Honor Allied Assault™ Spearhead RP28: 5/8/2009 4:31:34 AM - Revo Uninstaller's restore point - Battlefield 2™ RP29: 5/8/2009 4:31:46 AM - Removed Battlefield 2™ RP30: 5/8/2009 4:34:41 AM - Revo Uninstaller's restore point - Battlefield 2: Special Forces RP31: 5/8/2009 4:34:48 AM - Removed Battlefield 2: Special Forces RP32: 5/8/2009 4:50:35 AM - Installed Medal of Honor Allied Assault RP33: 5/8/2009 5:10:38 AM - Removed Medal of Honor Allied Assault UK & US 1.11 Patch RP34: 5/8/2009 5:19:53 AM - Installed Medal of Honor Allied Assault™ Spearhead RP35: 5/8/2009 5:21:05 AM - Installed Medal of Honor Allied Assault™ Spearhead RP36: 5/8/2009 5:29:36 AM - Installed Medal of Honor Allied Assault™ Breakthrough RP37: 5/8/2009 1:45:55 PM - Installed AGEIA PhysX v7.07.09 RP38: 5/8/2009 1:54:27 PM - Installed Medal of Honor Airborne RP39: 5/8/2009 1:58:21 PM - Installed Battlefield 2™ RP40: 5/8/2009 2:04:22 PM - Installed Battlefield 2™ RP41: 5/8/2009 2:14:03 PM - Installed Battlefield 2 Patch RP42: 5/8/2009 2:19:18 PM - Installed Battlefield 2: Special Forces RP43: 5/8/2009 2:24:21 PM - Installed Battlefield 2 Patch v1.41 RP44: 5/8/2009 11:58:17 PM - Installed Battlefield 2™ RP45: 5/9/2009 12:10:25 AM - Installed Battlefield 2 Patch v1.41 RP46: 5/9/2009 12:21:07 AM - Installed Battlefield 2: Euro Force Booster Pack RP47: 5/9/2009 12:22:18 AM - Installed Battlefield 2: Armored Fury Booster Pack RP48: 5/9/2009 12:26:27 AM - Installed Battlefield 2 Patch v1.41 RP49: 5/9/2009 12:59:47 AM - Installed DirectX 9.0 RP50: 5/9/2009 1:38:02 AM - Installed Medal of Honor Pacific Assault™ RP51: 5/9/2009 1:41:41 AM - Installed Blazing Angels Squadrons of WWII RP52: 5/9/2009 1:46:37 AM - Installed DirectX RP53: 5/9/2009 7:54:19 PM - Installed Disc Image Demo RP54: 5/11/2009 11:10:53 PM - Software Distribution Service 3.0 RP55: 5/12/2009 12:54:47 PM - Avg8 Update RP56: 5/15/2009 5:50:34 PM - Software Distribution Service 3.0 RP57: 5/15/2009 9:28:43 PM - Software Distribution Service 3.0 RP58: 5/17/2009 8:37:02 PM - Software Distribution Service 3.0 RP59: 5/19/2009 10:57:09 AM - Avg8 Update RP60: 5/19/2009 11:00:40 AM - Avg8 Update RP61: 5/19/2009 3:40:09 PM - Software Distribution Service 3.0 RP62: 5/19/2009 5:55:41 PM - Installed WD Diagnostics RP63: 5/20/2009 11:37:11 AM - Software Distribution Service 3.0 RP64: 5/20/2009 12:32:57 PM - Configured Turbo Lister 2 RP65: 5/28/2009 10:57:23 PM - Avira AntiVir Personal - 5/28/2009 22:57 RP66: 5/28/2009 11:09:38 PM - Software Distribution Service 3.0 RP67: 5/30/2009 12:20:48 AM - Software Distribution Service 3.0 RP68: 5/31/2009 6:02:52 PM - Configured AVG Free 8.5 RP69: 5/31/2009 7:30:42 PM - Configured AVG Free 8.5 RP70: 5/31/2009 7:41:42 PM - Configured AVG Free 8.5 RP71: 5/31/2009 7:45:06 PM - Revo Uninstaller's restore point - avast! Antivirus RP72: 5/31/2009 7:50:41 PM - Revo Uninstaller's restore point - AVG Free 8.5 RP73: 5/31/2009 7:51:12 PM - Removed AVG 8.5 RP74: 5/31/2009 7:51:48 PM - Installed AVG 8.5 RP75: 6/1/2009 6:18:36 PM - Revo Uninstaller's restore point - Turbo Lister 2 RP76: 6/1/2009 6:18:55 PM - Configured Turbo Lister 2 RP77: 6/1/2009 6:35:50 PM - Configured Turbo Lister 2 RP78: 6/1/2009 6:37:35 PM - Configured Turbo Lister 2 RP79: 6/14/2009 10:51:02 AM - UPDATING VIRUS MICROSOFT RP80: 6/14/2009 11:11:39 AM - Software Distribution Service 3.0 RP81: 6/14/2009 4:47:25 PM - Revo Uninstaller's restore point - Turbo Lister 2 RP82: 6/14/2009 4:47:37 PM - Configured Turbo Lister 2 RP83: 6/14/2009 5:08:30 PM - Installed Turbo Lister 2 RP84: 6/14/2009 7:29:00 PM - CCleaner june12 2009 RP85: 6/16/2009 8:05:04 PM - Software Distribution Service 3.0 RP86: 6/17/2009 12:42:02 AM - Installed Java™ 6 Update 14 RP87: 6/17/2009 12:49:59 AM - Revo Uninstaller's restore point - Ad-Aware RP88: 6/17/2009 12:52:12 AM - Revo Uninstaller's restore point - Ad-Aware RP89: 6/17/2009 1:32:28 AM - Revo Uninstaller's restore point - Ad-Aware RP90: 6/17/2009 1:32:54 AM - Removed Ad-Aware RP91: 6/17/2009 1:39:43 AM - Revo Uninstaller's restore point - Ad-Aware RP92: 6/17/2009 1:41:52 AM - Revo Uninstaller's restore point - Ad-Aware RP93: 6/18/2009 1:30:49 PM - Software Distribution Service 3.0 RP94: 6/23/2009 1:46:44 AM - Software Distribution Service 3.0 RP95: 6/25/2009 7:40:39 PM - SoundCapture Installation RP96: 6/25/2009 7:43:59 PM - SoundCapture Installation RP97: 6/26/2009 12:15:28 AM - Software Distribution Service 3.0 RP98: 7/15/2009 5:58:55 PM - Software Distribution Service 3.0 RP99: 7/26/2009 7:17:43 PM - Software Distribution Service 3.0 RP100: 7/28/2009 8:56:28 PM - Software Distribution Service 3.0 RP101: 8/3/2009 7:49:23 PM - Software Distribution Service 3.0 RP102: 8/4/2009 7:54:38 PM - Software Distribution Service 3.0 RP103: 9/7/2009 1:10:21 PM - Software Distribution Service 3.0 RP104: 9/7/2009 1:26:11 PM - Software Distribution Service 3.0 RP105: 9/7/2009 1:43:27 PM - Revo Uninstaller's restore point - Citrix ICA Web Client RP106: 9/7/2009 1:45:14 PM - Revo Uninstaller's restore point - Citrix ICA Web Client RP107: 10/17/2009 7:51:33 PM - Software Distribution Service 3.0 RP108: 10/17/2009 9:17:44 PM - Software Distribution Service 3.0 RP109: 10/17/2009 10:16:55 PM - Software Distribution Service 3.0 RP110: 10/17/2009 10:54:50 PM - Software Distribution Service 3.0 RP111: 10/17/2009 11:10:32 PM - Software Distribution Service 3.0 RP112: 11/1/2009 4:19:03 AM - Restore Operation RP113: 11/1/2009 3:04:00 PM - Software Distribution Service 3.0 RP114: 11/1/2009 3:38:54 PM - Software Distribution Service 3.0 RP115: 11/1/2009 4:19:29 PM - RESTORE POINT AFTER ERROR ON REGISTRY LOG BOOTUP RP116: 11/1/2009 4:41:16 PM - Software Distribution Service 3.0 RP117: 12/11/2009 4:41:57 PM - Software Distribution Service 3.0 RP118: 12/11/2009 5:31:01 PM - Software Distribution Service 3.0 RP119: 12/11/2009 5:32:20 PM - Software Distribution Service 3.0 RP120: 12/11/2009 5:38:40 PM - Software Distribution Service 3.0 RP121: 12/11/2009 5:39:47 PM - Software Distribution Service 3.0 ==== Installed Programs ====================== a-squared Free 4.5 A4Desk v6.26 AAC Decoder Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Photoshop 6.0 Adobe Reader 8.1.2 Adobe Reader 8.1.2 Security Update 1 (KB403742) Adobe Shockwave Player 11 Adobe SVG Viewer 3.0 AFPL Ghostscript Fonts Age of Empires III - The WarChiefs AGEIA PhysX v7.07.09 All Image 1.3.1 AntiLogger Any Video-Audio Converter 3.3.1 Apricorn EZ Gig II AutoUpdate AVG Anti-Rootkit Free Avira AntiVir Personal - Free Antivirus Battlefield 2™ Battlefield 2: Special Forces Battlestations: Midway BiA Earned in Blood SDK Blazing Angels Squadrons of WWII Bonjour Britannica Ready Reference Brothers In Arms Brothers In Arms EiB BSR Screen Recorder 4 Business Contact Manager for Outlook 2007 SP2 Call of Duty® 2 Call of Duty® 2 Mod Tools Call of Duty® 2 Patch 1.01 Call of Duty® 2 Patch 1.2 Call of Duty® 2 Patch 1.3 Canon IJ Network Scan Utility Canon IJ Network Tool Canon MP Navigator EX 1.1 Canon MX850 series Canon MX850 series User Registration Canon Utilities Easy-PhotoPrint EX Canon Utilities My Printer Canon Utilities Solution Menu CaptureWizPro 3.B0 CCleaner Company of Heroes Complete Do-It-Yourself Guide Compton's Interactive Bible NIV Cookie Pal Corel Snapfire Plus Creative Audio Console Creative WaveStudio 7 Crimson Editor (remove only) Critical Update for Windows Media Player 11 (KB959772) Data Lifeguard Tools Dell CinePlayer Dell Driver Reset Tool Dell System Restore Digital Content Portal DigitalPersona Password Manager 2.0.0 Disc Image Demo DiscAPI (Studio 10) DivX Codec DivX Converter DivX Player DivX Plus DirectShow Filters DivX Version Checker DivX Web Player Download Accelerator Plus (DAP) e-Sword EA Download Manager Early Church Fathers 2008 EASEUS Partition Manager 3.0 Home Edition Empire: Total War Encarta Language Learning French Encarta Language Learning Spanish ERUNT 1.1j EVEREST Home Edition v2.20 Far Cry ffdshow [rev 1782] [2008-01-15] Form Fill (Windows Live Toolbar) FoxyTunes for Firefox Free YouTube Download 1.3 FSX Flight Weather Report GameShadow Garmin Communicator Plugin Garmin WebUpdater Gizmo Central Google Earth Plugin Google Photos Screensaver Google Update Helper Google Updater H.264 Decoder Hawking HWU54D Hi-Gain Wireless-G USB Adapter Highlight Viewer (Windows Live Toolbar) HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) iCall iHatePopups iHateSpam Intel® Matrix Storage Manager Intel® Network Connections [removed] ISA 2 basic IsoBuster 2.5 J2SE Runtime Environment 5.0 Update 11 J2SE Runtime Environment 5.0 Update 6 Java™ 6 Update 14 Java™ 6 Update 2 Java™ 6 Update 3 Java™ 6 Update 7 Java™ SE Runtime Environment 6 Update 1 JBidwatcher 2 L&H PC/MM ASR1600 for Windows V3 French L&H PCMM ASR1600 for Windows V3 Basic L&H PCMM ASR1600 for Windows V3 Engine L&H PCMM ASR1600 for Windows V3 Mexican Spanish Learn2 Player (Uninstall Only) Learning Essentials for Microsoft Office Madden NFL 2005 Malwarebytes' Anti-Malware Medal of Honor Allied Assault Medal of Honor Allied Assault™ Breakthrough Medal of Honor Allied Assault™ Spearhead Medieval II Total War Medieval Total War Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft ActiveSync 3.5 Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Baseline Security Analyzer 2.1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Digital Image Library 9 - Blocker Microsoft Digital Image Suite 2006 Microsoft Digital Image Suite 2006 Editor Microsoft Digital Image Suite 2006 Library Microsoft Easy Assist Microsoft Easy Assist v2 Microsoft Expression Web Microsoft Expression Web MUI (English) Microsoft Expression Web Service Pack 1 (SP1) Microsoft Flight Simulator X Microsoft Flight Simulator X Photo Scenery Display Update Microsoft Internationalized Domain Names Mitigation APIs Microsoft J# Browser Controls v1.1 Microsoft Kernel-Mode Driver Framework Feature Pack 1.1 Microsoft LifeCam Microsoft Location Finder Microsoft Math Microsoft MSDN 2005 Express Edition - ENU Microsoft National Language Support Downlevel APIs Microsoft Network Monitor 3.3 Microsoft Network Monitor: Microsoft Parsers 3.3 Microsoft Office 2003 Web Components Microsoft Office 2007 Primary Interop Assemblies Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Accounting 2007 Microsoft Office Accounting ADP Payroll Addin Microsoft Office Accounting Equifax Addin Microsoft Office Accounting Fixed Asset Manager Microsoft Office Accounting PayPal Addin Microsoft Office Excel MUI (English) 2007 Microsoft Office FrontPage 2003 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2) Microsoft Office Small Business Connectivity Components Microsoft Office Ultimate 2007 Microsoft Office Visio 2007 Service Pack 2 (SP2) Microsoft Office Visio MUI (English) 2007 Microsoft Office Visio Professional 2007 Microsoft Office Word MUI (English) 2007 Microsoft Office XP Professional with FrontPage Microsoft Outlook Personal Folders Backup Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft Student 2007 for Learning Essentials Microsoft Student with Encarta Premium 2007 Microsoft Train Simulator Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual Web Developer 2005 Express Edition - ENU Microsoft Visual Web Developer 2005 Express Edition - ENU Service Pack 1 (KB926751) Microsoft Works Microsoft XML Parser MKV Splitter Mobipocket Reader 6.2 Mozilla Firefox (2.0.0.20) Mozilla Firefox (3.0.9) Mozilla Firefox (3.5.5) MSN Money Investment Toolbox MSN Money Toolbar Add-in MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK MSXML4 Parser Nero PhotoShow Express 4 Nikon Message Center NVIDIA Drivers NVIDIA nTune NVIDIA System Monitor NVIDIA System Update Octoshape add-in for Adobe Flash Player OneCare Advisor (Windows Live Toolbar) Online Armor 3.5 Painter 4.0.3 Panorama Maker PANZERS - Phase2 Paragon Drive Copy 9.0 Personal Demo PC Inspector File Recovery PC Study Bible 3.1 PCFriendly PDFtypewriter Printer Driver Pinnacle Instant DVD Recorder Pinnacle MediaServer Pismo File Mount Audit Package Player Pocket PC Connection Wizard Popup Blocker (Windows Live Toolbar) PowerDVD PowerFile 5.4 Driver PowerFile C200 PowerISO Pradis Do Not Remove Pradis: Greek Grammar Beyond the Basics Praetorians Presto! PageManager 7.15.20 proDAD Heroglyph 2.5 Qualxserve Service Agreement QuickTime Railroad Tycoon 3 RAPID (Studio 10) RealPlayer Basic Recover My Files RegSupreme Replay Media Catcher 3.01 Revo Uninstaller 1.83 Rhapsody Player Engine Rome - Total War Rome - Total War - Alexander Rome - Total War - Gold Edition Roxio Express Labeler Roxio MyDVD Plus Roxio RecordNow Audio Roxio RecordNow Copy Roxio RecordNow Data ScanSoft OmniPage SE 4 SearchAssist Security Update for 2007 Microsoft Office System (KB951550) Security Update for 2007 Microsoft Office System (KB951944) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB973704) Security Update for CAPICOM (KB931906) Security Update for Microsoft Office Excel 2007 (KB973593) Security Update for Microsoft Office Outlook 2007 (KB972363) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office Publisher 2007 (KB969693) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975467) Shockwave Shopping Cart 3 Silent Hunter III Silent Hunter Wolves of the Pacific Skype™ 3.8 SMART-ER Smart Menus (Windows Live Toolbar) SmartSound Quicktracks Plugin Sonic Activation Module SoundCapture SpeedFan (remove only) Spelling Dictionaries Support For Adobe Reader 8 Spybot - Search & Destroy Spybot - Search & Destroy 1.4 SpywareBlaster 4.2 SpywareGuard v2.2 Startup Mechanic 2.2 Steam Studio 10 Studio 10 Bonus DVD SUPERAntiSpyware Free Edition System Requirements Lab Tabbed Browsing (Windows Live Toolbar) TBS WMP Plug-in Teknia Language Tools (Greek) The History Channel: Civil War Trainz Trainz Paint Shed TRS2004 TRS2006 Turbo Lister 2 Tweak UI Typing Tutor 7 Uninstall 1.0.0.0 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office InfoPath 2007 (KB976416) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Visio 2007 Help (KB963666) Update for Microsoft Office Word 2007 (KB974561) Update for Microsoft Office Word 2007 Help (KB963665) Update for Microsoft Windows (KB971513) Update for Outlook 2007 Junk Email Filter (kb976884) Update for Windows XP (KB943729) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) URL Assistant VC80CRTRedist - 8.0.50727.762 Viewpoint Media Player Virtual Earth 3D (Beta) Visual WhoIs 2004 Waterloo - Napoleon's Last Battle WD Diagnostics WebFldrs XP Windows Backup Utility Windows Defender Windows Desktop Search 3.0 Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Internet Explorer 7 Windows Live Messenger Windows Live Outlook Toolbar (Windows Live Toolbar) Windows Live Sign-in Assistant Windows Live Toolbar Windows Live Toolbar Extension (Windows Live Toolbar) Windows Live Toolbar Feed Detector (Windows Live Toolbar) Windows Media Format 11 runtime Windows Media Player 10 Windows Media Player 11 Windows PowerShell™ 1.0 Windows PowerShell™ 1.0 MUI pack Windows Vista Upgrade Advisor Windows XP Service Pack 3 WinPatrol 2009 Wisdom-soft ScreenHunter 5.1 Free WOT for Internet Explorer X-Lite 3.0 Yahoo! Install Manager Yahoo! Messenger ==== End Of File =========================== I got an error message on GMER but ran RootRepeal instead. ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/12/12 01:05 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: dump_iaStor.sys Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys Address: 0xB69AE000 Size: 749568 File Visible: No Signed: - Status: - Name: giveio.sys Image Path: giveio.sys Address: 0xBA670000 Size: 1664 File Visible: No Signed: - Status: - Name: PCI_PNP9818 Image Path: \Driver\PCI_PNP9818 Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xB6539000 Size: 49152 File Visible: No Signed: - Status: - Name: speedfan.sys Image Path: speedfan.sys Address: 0xBA5B0000 Size: 5248 File Visible: No Signed: - Status: - Name: sprt.sys Image Path: sprt.sys Address: 0xB9EA6000 Size: 1052672 File Visible: No Signed: - Status: - Name: sptd Image Path: \Driver\sptd Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Hidden/Locked Files ——————- Path: C:\hiberfil.sys Status: Locked to the Windows API! SSDT ——————- #: 017 Function Name: NtAllocateVirtualMemory Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2e320 #: 019 Function Name: NtAssignProcessToJobObject Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2e940 #: 031 Function Name: NtConnectPort Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2ce30 #: 037 Function Name: NtCreateFile Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3b420 #: 041 Function Name: NtCreateKey Status: Hooked by "" at address 0xba6f2746 #: 046 Function Name: NtCreatePort Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2cae0 #: 047 Function Name: NtCreateProcess Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c29db0 #: 048 Function Name: NtCreateProcessEx Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2a180 #: 050 Function Name: NtCreateSection Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c298d0 #: 053 Function Name: NtCreateThread Status: Hooked by "" at address 0xba6f273c #: 057 Function Name: NtDebugActiveProcess Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2bdc0 #: 062 Function Name: NtDeleteFile Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3beb0 #: 063 Function Name: NtDeleteKey Status: Hooked by "" at address 0xba6f274b #: 065 Function Name: NtDeleteValueKey Status: Hooked by "" at address 0xba6f2755 #: 068 Function Name: NtDuplicateObject Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2c800 #: 071 Function Name: NtEnumerateKey Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3b3c0 #: 073 Function Name: NtEnumerateValueKey Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3b3f0 #: 097 Function Name: NtLoadDriver Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2ddf0 #: 098 Function Name: NtLoadKey Status: Hooked by "" at address 0xba6f275a #: 116 Function Name: NtOpenFile Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3bac0 #: 119 Function Name: NtOpenKey Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c39f30 #: 122 Function Name: NtOpenProcess Status: Hooked by "" at address 0xba6f2728 #: 125 Function Name: NtOpenSection Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c29b40 #: 128 Function Name: NtOpenThread Status: Hooked by "" at address 0xba6f272d #: 137 Function Name: NtProtectVirtualMemory Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2e5d0 #: 160 Function Name: NtQueryKey Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3b360 #: 177 Function Name: NtQueryValueKey Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3b390 #: 180 Function Name: NtQueueApcThread Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2eac0 #: 193 Function Name: NtReplaceKey Status: Hooked by "" at address 0xba6f2764 #: 200 Function Name: NtRequestWaitReplyPort Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2d9a0 #: 204 Function Name: NtRestoreKey Status: Hooked by "" at address 0xba6f275f #: 206 Function Name: NtResumeThread Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2c4b0 #: 207 Function Name: NtSaveKey Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3b340 #: 210 Function Name: NtSecureConnectPort Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2d1f0 #: 213 Function Name: NtSetContextThread Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2bbe0 #: 224 Function Name: NtSetInformationFile Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c3c170 #: 240 Function Name: NtSetSystemInformation Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2bf40 #: 247 Function Name: NtSetValueKey Status: Hooked by "" at address 0xba6f2750 #: 249 Function Name: NtShutdownSystem Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2dcf0 #: 253 Function Name: NtSuspendProcess Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2c660 #: 254 Function Name: NtSuspendThread Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2c2e0 #: 255 Function Name: NtSystemDebugControl Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2c120 #: 257 Function Name: NtTerminateProcess Status: Hooked by "C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys" at address 0xb6c8b0b0 #: 258 Function Name: NtTerminateThread Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2b9c0 #: 262 Function Name: NtUnloadDriver Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2e010 #: 277 Function Name: NtWriteVirtualMemory Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c2e780 Stealth Objects ——————- Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP] Process: System Address: 0x8b1131f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP] Process: System Address: 0x897281f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CREATE] Process: System Address: 0x897f31f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CLOSE] Process: System Address: 0x897f31f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_READ] Process: System Address: 0x897f31f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_WRITE] Process: System Address: 0x897f31f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x897f31f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_POWER] Process: System Address: 0x897f31f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x897f31f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_PNP] Process: System Address: 0x897f31f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE] Process: System Address: 0x8b1851f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE] Process: System Address: 0x8b1851f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_READ] Process: System Address: 0x8b1851f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE] Process: System Address: 0x8b1851f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x8b1851f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8b1851f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8b1851f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN] Process: System Address: 0x8b1851f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_POWER] Process: System Address: 0x8b1851f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8b1851f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_PNP] Process: System Address: 0x8b1851f8 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE] Process: System Address: 0x8a6721f8 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE] Process: System Address: 0x8a6721f8 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8a6721f8 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8a6721f8 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER] Process: System Address: 0x8a6721f8 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8a6721f8 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP] Process: System Address: 0x8a6721f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE] Process: System Address: 0x8a6211f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE] Process: System Address: 0x8a6211f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ] Process: System Address: 0x8a6211f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE] Process: System Address: 0x8a6211f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x8a6211f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8a6211f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8a6211f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN] Process: System Address: 0x8a6211f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER] Process: System Address: 0x8a6211f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8a6211f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP] Process: System Address: 0x8a6211f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE] Process: System Address: 0x8b1151f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ] Process: System Address: 0x8b1151f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE] Process: System Address: 0x8b1151f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x8b1151f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8b1151f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8b1151f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN] Process: System Address: 0x8b1151f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP] Process: System Address: 0x8b1151f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER] Process: System Address: 0x8b1151f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8b1151f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP] Process: System Address: 0x8b1151f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE] Process: System Address: 0x8997a1f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE] Process: System Address: 0x8997a1f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8997a1f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8997a1f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP] Process: System Address: 0x8997a1f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP] Process: System Address: 0x8997a1f8 Size: 121 Object: Hidden Code [Driver: ao063amy؅జ灐敲, IRP_MJ_CREATE] Process: System Address: 0x8a6121f8 Size: 121 Object: Hidden Code [Driver: ao063amy؅జ灐敲, IRP_MJ_CLOSE] Process: System Address: 0x8a6121f8 Size: 121 Object: Hidden Code [Driver: ao063amy؅జ灐敲, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8a6121f8 Size: 121 Object: Hidden Code [Driver: ao063amy؅జ灐敲, IRP_MJ_POWER] Process: System Address: 0x8a6121f8 Size: 121 Object: Hidden Code [Driver: ao063amy؅జ灐敲, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8a6121f8 Size: 121 Object: Hidden Code [Driver: ao063amy؅జ灐敲, IRP_MJ_PNP] Process: System Address: 0x8a6121f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE] Process: System Address: 0x8a65e1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE] Process: System Address: 0x8a65e1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8a65e1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8a65e1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER] Process: System Address: 0x8a65e1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8a65e1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP] Process: System Address: 0x8a65e1f8 Size: 121 Object: Hidden Code [Driver: sbp2port, IRP_MJ_CREATE] Process: System Address: 0x8b1831f8 Size: 121 Object: Hidden Code [Driver: sbp2port, IRP_MJ_CLOSE] Process: System Address: 0x8b1831f8 Size: 121 Object: Hidden Code [Driver: sbp2port, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8b1831f8 Size: 121 Object: Hidden Code [Driver: sbp2port, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8b1831f8 Size: 121 Object: Hidden Code [Driver: sbp2port, IRP_MJ_POWER] Process: System Address: 0x8b1831f8 Size: 121 Object: Hidden Code [Driver: sbp2port, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8b1831f8 Size: 121 Object: Hidden Code [Driver: sbp2port, IRP_MJ_PNP] Process: System Address: 0x8b1831f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP] Process: System Address: 0x898061f8 Size: 121 Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_CREATE] Process: System Address: 0x897261f8 Size: 121 Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_CLOSE] Process: System Address: 0x897261f8 Size: 121 Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_READ] Process: System Address: 0x897261f8 Size: 121 Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x897261f8 Size: 121 Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_SET_INFORMATION] Process: System Address: 0x897261f8 Size: 121 Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x897261f8 Size: 121 Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x897261f8 Size: 121 Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x897261f8 Size: 121 Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x897261f8 Size: 121 Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_SHUTDOWN] Process: System Address: 0x897261f8 Size: 121 Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x897261f8 Size: 121 Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_CLEANUP] Process: System Address: 0x897261f8 Size: 121 Object: Hidden Code [Driver: CdfsЅఐ卆浩ޫ, IRP_MJ_PNP] Process: System Address: 0x897261f8 Size: 121 Shadow SSDT ——————- #: 013 Function Name: NtGdiBitBlt Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c28130 #: 233 Function Name: NtGdiOpenDCW Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c28450 #: 307 Function Name: NtUserAttachThreadInput Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c25a30 #: 310 Function Name: NtUserBlockInput Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c27230 #: 383 Function Name: NtUserGetAsyncKeyState Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c26450 #: 389 Function Name: NtUserGetClipboardData Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c274e0 #: 401 Function Name: NtUserGetDC Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c27e10 #: 414 Function Name: NtUserGetKeyboardState Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c26320 #: 416 Function Name: NtUserGetKeyState Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c261f0 #: 439 Function Name: NtUserGetWindowDC Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c27fa0 #: 460 Function Name: NtUserMessageCall Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c26580 #: 465 Function Name: NtUserMoveWindow Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c27800 #: 475 Function Name: NtUserPostMessage Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c26950 #: 476 Function Name: NtUserPostThreadMessage Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c26cb0 #: 491 Function Name: NtUserRegisterRawInputDevices Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c258d0 #: 502 Function Name: NtUserSendInput Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c27000 #: 509 Function Name: NtUserSetClipboardViewer Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c273a0 #: 529 Function Name: NtUserSetParent Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c27630 #: 546 Function Name: NtUserSetWindowPos Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c27af0 #: 548 Function Name: NtUserSetWindowsHookAW Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c25420 #: 549 Function Name: NtUserSetWindowsHookEx Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c25040 #: 552 Function Name: NtUserSetWinEventHook Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c25680 #: 555 Function Name: NtUserShowWindow Status: Hooked by "C:\WINDOWS\system32\drivers\OADriver.sys" at address 0xb6c27a20 ==EOF== Thanks for your help!
Hi,

please do the following:

You have CD Emulation drivers which interfere with our tools, we will disable them till your machine is clean.

Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.


NEXT

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
ComboFix 09-12-28.03 - GEORGE 12/29/2009 0:16.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2560 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\VIRUS SCAN PROCEDURES
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
ADS - WINDOWS: deleted 72 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-303087950-19637512-4056949597-1000
c:\documents and settings\GEORGE\Application Data\inst.exe
c:\documents and settings\GEORGE\My Documents\022809reg.reg
c:\documents and settings\GEORGE\My Documents\7-14-08.reg
c:\documents and settings\GEORGE\My Documents\backup.reg
c:\documents and settings\GEORGE\My Documents\BACKUP120107.reg
c:\documents and settings\GEORGE\My Documents\dec292008reg.reg
c:\documents and settings\GEORGE\My Documents\december15.reg
c:\documents and settings\GEORGE\My Documents\feb1408.reg
c:\documents and settings\GEORGE\My Documents\reg021109.reg
c:\recycler\S-1-5-21-1446432944-476004442-2805334122-1006
c:\windows\Downloaded Program Files\Temp
c:\windows\EventSystem.log
c:\windows\system\oeminfo.ini
c:\windows\system32\drivers\1028_DELL_XPS_Dell DXP061 .MRK
c:\windows\system32\drivers\DELL_XPS_Dell DXP061 .MRK
c:\windows\system32\vobis32.dll

.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-29 )))))))))))))))))))))))))))))))
.

2009-12-23 11:16 . 2009-12-23 11:16 ——– d—–w- c:\program files\Softwin
2009-12-21 10:52 . 2009-12-21 10:52 ——– d—–w- c:\program files\Sophos
2009-12-18 11:19 . 2009-12-29 04:57 52224 —-a-w- c:\documents and settings\GEORGE\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-18 10:52 . 2009-12-17 22:14 150888 —-a-w- C:\Tcpvcon.exe
2009-12-17 20:11 . 2008-04-14 01:11 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2009-12-12 08:31 . 2009-12-12 09:02 15 —-a-w- c:\documents and settings\GEORGE\settings.dat
2009-12-12 00:42 . 2009-12-12 00:42 ——– d—–w- c:\program files\MSXML 4.0
2009-12-12 00:37 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2009-12-11 22:00 . 2009-08-25 09:30 13312 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
2009-12-11 22:00 . 2009-10-20 21:33 545280 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\PicLensHelper.exe
2009-12-11 22:00 . 2009-10-20 21:33 4716544 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
2009-12-11 22:00 . 2009-10-20 21:33 344064 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\LaunchCooliris.exe
2009-12-11 22:00 . 2009-10-20 21:33 153600 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
2009-12-11 22:00 . 2009-10-20 21:33 103424 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\pixomatic.dll
2009-12-11 21:56 . 2009-12-29 05:06 ——– d—–w- c:\program files\Mozilla Firefox 3.55

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 07:58 . 2008-07-21 03:46 ——– d—–w- c:\program files\Mozilla Firefox3.0
2009-12-29 05:05 . 2007-09-18 10:38 ——– d—–w- c:\program files\Mozilla Firefox2.0
2009-12-29 05:01 . 2007-12-02 21:43 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-29 05:01 . 2008-02-06 16:14 ——– d—–w- c:\program files\SpywareBlaster
2009-12-29 05:00 . 2006-12-13 07:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-29 04:57 . 2009-03-17 20:59 117760 —-a-w- c:\documents and settings\GEORGE\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-20 01:55 . 2006-12-13 07:16 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-19 10:22 . 2006-11-29 21:40 ——– d—–w- c:\program files\Java
2009-12-19 10:00 . 2006-11-29 21:47 ——– d—–w- c:\program files\Real
2009-12-19 09:52 . 2006-11-29 21:44 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-19 08:57 . 2006-11-29 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-12-19 08:33 . 2006-11-29 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\QuickTime
2009-12-19 08:31 . 2008-02-15 21:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-19 08:12 . 2007-09-21 23:12 ——– d—–w- c:\program files\Microsoft Location Finder
2009-12-19 07:46 . 2006-11-29 21:47 ——– d—–w- c:\program files\Common Files\Real
2009-12-19 07:44 . 2008-03-04 22:06 ——– d—–w- c:\program files\CounterPath
2009-12-19 07:21 . 2006-12-07 10:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Windows Live Toolbar
2009-12-19 07:18 . 2007-10-06 17:03 ——– d—–w- c:\program files\MSN Money Toolbar Add-in
2009-12-19 07:17 . 2006-11-29 21:52 ——– d—–w- c:\program files\Yahoo!
2009-12-19 06:31 . 2008-03-27 03:06 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-19 02:42 . 2009-01-27 03:22 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-18 11:17 . 2009-05-29 06:12 ——– d—–w- c:\program files\a-squared Free
2009-12-17 22:10 . 2008-06-20 21:56 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-12-17 20:12 . 2009-12-17 20:12 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-12-17 20:12 . 2009-12-17 20:12 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-12-15 05:01 . 2009-04-28 03:50 95744 —-a-w- c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll
2009-12-12 01:31 . 2007-02-02 04:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-12 00:48 . 2006-11-29 21:53 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-12-12 00:24 . 2009-05-29 06:17 ——– d—–w- c:\documents and settings\GEORGE\Application Data\OnlineArmor
2009-12-11 22:05 . 2006-12-13 04:58 ——– d—–w- c:\documents and settings\GEORGE\Application Data\Skype
2009-12-11 20:33 . 2009-02-17 11:30 4844296 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-11 20:08 . 2009-05-29 06:07 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-04 00:14 . 2009-01-27 03:22 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-04 00:13 . 2009-01-27 03:22 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-21 15:51 . 2006-02-28 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-03 04:42 . 2009-11-01 22:10 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-11-02 00:06 . 2008-10-12 08:39 ——– d—–w- c:\program files\SpywareGuard
2009-11-01 22:40 . 2009-11-01 22:40 ——– d—–w- c:\program files\Microsoft Network Monitor 3
2009-11-01 22:08 . 2008-01-14 19:59 ——– d—–w- c:\program files\Microsoft Silverlight
2009-11-01 22:07 . 2006-11-29 21:52 ——– d—–w- c:\program files\Microsoft Works
2009-11-01 11:19 . 2009-10-18 06:10 ——– d—–w- c:\program files\Microsoft Network Monitor 3(2)
2009-10-29 07:46 . 2006-02-28 12:00 832512 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2006-02-28 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2006-02-28 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-10-21 05:38 . 2006-02-28 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-02-28 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2006-02-28 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2006-02-28 12:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2006-02-28 12:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2006-02-28 12:00 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-08 22:57 . 2008-07-30 03:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2009-10-08 22:57 . 2006-02-28 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 22:56 . 2006-02-28 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2008-09-20 18:42 . 2008-03-08 08:25 88 –sha-r- c:\windows\system32\892202FEA3.sys
2008-06-13 04:32 . 2008-06-13 04:32 23 –sha-w- c:\windows\system32\aafcebeaff4_g.dll
2008-09-20 18:43 . 2008-03-08 08:25 4856 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}]
@="{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}"
[HKEY_CLASSES_ROOT\CLSID\{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}]
2009-03-06 03:17 143160 —-a-w- c:\windows\system32\pfmshx_27B.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-17 2002160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"nwiz"="nwiz.exe" [2009-03-28 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 13684736]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 86016]
"@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2009-04-16 2044104]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-10-19 293888]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2009-04-16 335048]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-07 20:23 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-10-09 21:33 1949480 —-a-w- c:\program files\Apricorn\EZ Gig II\TimounterMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apricorn Scheduler Service]
2007-10-09 21:24 148712 —-a-w- c:\program files\Common Files\Apricorn\Schedule2\schedhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2008-03-18 09:06 1848648 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2008-12-12 09:31 722256 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2008-12-17 18:36 50520 —-a-w- c:\documents and settings\GEORGE\Application Data\mjusbsp\cdloader2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 —-a-w- c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZGigMonitor.exe]
2007-10-09 21:20 1169264 —-a-w- c:\program files\Apricorn\EZ Gig II\EZGigMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GizmoDriveDelegate]
2009-05-01 04:06 390752 —-a-w- c:\progra~1\Gizmo\gdrive.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 18:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJNetworkScanUtility]
2007-05-21 08:37 124512 —-a-w- c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 22:50 221184 —-a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
2007-05-17 21:45 279912 —-a-w- c:\program files\Microsoft LifeCam\LifeExp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2007-06-13 17:39 73728 —-a-w- c:\program files\ScanSoft\OmniPageSE4\OpWareSE4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
2004-03-11 08:26 406016 —-a-w- c:\windows\system32\PSDrvCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2009-03-15 10:15 180224 —-a-w- c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\siService.exe]
2003-12-23 18:31 204800 —-a-w- c:\program files\Sunbelt Software\iHateSpam\siService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 16:03 210472 —-a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-04-27 18:56 1410296 —-a-w- c:\program files\GAMES\Steam\steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-05-21 18:34 148888 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX6000]
2007-04-10 21:46 996712 —-a-w- c:\windows\vVX6000.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SQLWriter"=2 (0x2)
"SQLBrowser"=2 (0x2)
"MSSQL$MSSMLBIZ"=3 (0x3)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AdobeUpdater"=c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Plugin Install"=c:\program files\QuickTime\Plugins\DeleteMe1.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Sunbelt Software\\iHateSpam\\siMailProxyServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Google\\Google Updater\\GoogleUpdater.exe"=
"c:\\Program Files\\PowerFile C200\\PowerFile.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\GAMES\\Steam\\SteamApps\\common\\empire total war\\Empire.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Logging]
"LogSuccessfulConnections"= 0 (0x0)
"LogDroppedPackets"= 0 (0x0)
"LogFileSize"= 0 (0x0)
"LogFilePath"=

R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [3/12/2009 2:23 PM 40368]
R1 DiscImage;Disc image driver;c:\windows\system32\drivers\discimage.sys [5/26/2007 7:04 PM 24704]
R1 GizmoDrv;Gizmo Device Driver;c:\windows\system32\drivers\gizmodrv.sys [4/30/2009 8:07 PM 23624]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [5/28/2009 10:17 PM 196688]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [5/28/2009 10:17 PM 31824]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [5/28/2009 10:17 PM 29776]
R1 pfmfs_27B;pfmfs_27B;c:\windows\system32\drivers\pfmfs_27B.sys [4/30/2009 8:05 PM 179896]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [8/19/2008 11:34 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/19/2008 11:34 PM 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [5/28/2009 10:12 PM 1858144]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/28/2009 10:07 PM 108289]
R2 DIMSVC;Disc Image Demo mount service;c:\program files\Pa-software\Disc Image Demo\dimsvc.exe [5/26/2007 7:03 PM 36864]
R2 Gizmo Central;Gizmo Central;c:\program files\Gizmo\gservice.exe [4/30/2009 8:06 PM 31856]
R2 SMART-ERService;SMART-ER Service;c:\program files\Apricorn\SMART-ER\SMART-ER Service.exe [6/4/2007 10:20 AM 69632]
R2 VirtualDrive;VirtualDrive;c:\program files\All Image\vdd-x86.sys [4/30/2009 7:41 PM 10752]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [4/19/2008 1:46 PM 30560]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/19/2008 11:34 PM 7408]
S1 AntiLog32;AntiLog32;\??\c:\program files\AntiLogger\AntiLog32.sys –> c:\program files\AntiLogger\AntiLog32.sys [?]
S2 AnonMgmtSvc;Anonymizer Management Service;"c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe" –> c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe [?]
S2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [5/28/2009 10:17 PM 361160]
S2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [5/28/2009 10:17 PM 3049160]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\GEORGE\LOCALS~1\Temp\ALSysIO.sys –> c:\docume~1\GEORGE\LOCALS~1\Temp\ALSysIO.sys [?]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 DarkSpy;DarkSpy;\??\c:\windows\system32\DarkSpyKernel.sys –> c:\windows\system32\DarkSpyKernel.sys [?]
S3 dpK0Bx01;Fingerprint Reader Filter Driver;c:\windows\system32\drivers\dpK0Bx01.sys [1/5/2007 3:45 PM 35584]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [3/24/2009 12:15 PM 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [3/24/2009 12:15 PM 3072]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [8/17/2005 11:00 PM 7168]
S3 IntelDH;IntelDH Driver;c:\windows\system32\Drivers\IntelDH.sys –> c:\windows\system32\Drivers\IntelDH.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\16.tmp –> c:\windows\system32\16.tmp [?]
S3 PORTMON;PORTMON;\??\c:\documents and settings\GEORGE\Desktop\DOWNLOADS\Portmon\PORTMSYS.SYS –> c:\documents and settings\GEORGE\Desktop\DOWNLOADS\Portmon\PORTMSYS.SYS [?]
S3 SWUSBFLT;Microsoft SideWinder VIA Filter Driver;c:\windows\system32\drivers\SWUSBFLT.SYS [12/22/2006 10:46 PM 3968]
S3 UsbdpFP;Fingerprint Reader Class Driver;c:\windows\system32\drivers\usbdpfp.sys [1/5/2007 3:45 PM 47360]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [12/12/2006 6:43 PM 2385896]
S3 xusb20;Xbox 360 Wireless Receiver for Windows Driver Service;c:\windows\system32\drivers\xusb20.sys [10/13/2006 5:19 PM 50048]
S3 yeddef;YEDDEF driver;c:\windows\system32\Drivers\yeddef.sys –> c:\windows\system32\Drivers\yeddef.sys [?]
S3 ZD1211U(Hawking Technologies);Hawking Technologies HWU54D Hi-Gain Wireless-G USB Adapter(Hawking Technologies);c:\windows\system32\drivers\ZD1211U.sys [12/6/2006 4:17 AM 233472]
S4 gupdate1c901a09a323bba;Google Update Service (gupdate1c901a09a323bba);c:\program files\Google\Update\GoogleUpdate.exe [8/18/2008 6:09 PM 133104]
S4 NSLHNZKPEI;NSLHNZKPEI;c:\docume~1\GEORGE\LOCALS~1\Temp\NSLHNZKPEI.exe –> c:\docume~1\GEORGE\LOCALS~1\Temp\NSLHNZKPEI.exe [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4/30/2009 6:14 PM 721904]
S4 TABKB;TABKB;c:\docume~1\GEORGE\LOCALS~1\Temp\TABKB.exe –> c:\docume~1\GEORGE\LOCALS~1\Temp\TABKB.exe [?]

— Other Services/Drivers In Memory —

*Deregistered* - PROCEXP111
.
——- Supplementary Scan ——-
.
uLocal Page = hxxp://www.msn.com
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
Handler: msell2 - {9367D24B-8506-471A-915A-CFBB4BCEB631} - c:\program files\Common Files\Microsoft Shared\Reference Titles\MSELL2.dll
DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} - hxxps://actsvr.comcastonline.com/techtools/dl/Comcast%20Activation%20Controls.cab
FF - ProfilePath - c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\
FF - prefs.js: browser.startup.homepage - msn.com
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
FF - component: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - plugin: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npdeploytk.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npnul32.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - (no file)
Notify-DPWLN - (no file)
MSConfigStartUp-Anonymizer - c:\program files\Anonymizer\Anonymizer Software\Anonymizer.exe
AddRemove-AntiLogger - c:\documents and settings\All Users\Application Data\{DBBDCE5C-C9B7-4F00-BA4F-3D64168B6576}\AntiLogger_Setup.exe
AddRemove-BrothersInArms - e:\brothersinarms\System\Setup.exe
AddRemove-BrothersInArmsEiB - e:\ubisoft\Gearbox Software\BrothersInArmsEiB\System\Setup.exe
AddRemove-BrothersInArmsEIBSDK - e:\ubisoft\Gearbox Software\BrothersInArmsEiB\EIBSDKUninstall.exe
AddRemove-CompleteDoItYourselfGuide - d:\data\diyguide.exe
AddRemove-FoxyTunesForFirefox - c:\program files\Mozilla Firefox\firefox.exe
AddRemove-Microsoft MSDN 2005 Express Edition - ENU - e:\program files\Microsoft Visual Studio 8\Microsoft MSDN 2005 Express Edition - ENU\install.exe
AddRemove-Microsoft Visual Web Developer 2005 Express Edition - ENU - e:\program files\Microsoft Visual Studio 8\Microsoft Visual Web Developer 2005 Express Edition - ENU\setup.exe
AddRemove-Mozilla Firefox (2.0.0.20) - c:\program files\Mozilla Firefox\uninstall\helper.exe
AddRemove-Nero PhotoShow Express 4 - e:\nero photoshow 4\data\Xtras\Uninstall.exe
AddRemove-{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 - c:\program files\Spybot - Search & Destroy\unins001.exe
AddRemove-{C5089197-5B15-44AD-B0FC-2E94EE9ECB63} - c:\documents and settings\GEORGE\Local Settings\Application Data\{044CCC32-19C8-40C9-92DE-7D50DCAC47BA}\wsc.exe



**************************************************************************
scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\16.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3060164775-2224625509-1354611237-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1076)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(1136)
c:\windows\system32\relog_ap.dll
c:\windows\DPPWDFLT.dll
.
Completion time: 2009-12-29 00:23:48
ComboFix-quarantined-files.txt 2009-12-29 08:23

Pre-Run: 15,852,703,744 bytes free
Post-Run: 15,987,843,072 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - B55EF24745AE95E2F263C0B3DC025394

I ran defogger. I ran the combo-fix.exe program. During the process, Combo stated not to start any program, I needed to download recovery console.
which I suppose it installed. It stated not to click on the program but after it started running a screen popped up saying swxcalx.cfxxe is corrupt and windows
needs to run chkdsk now click OK which I didn't do….was wondering if this was legit or not. Finished posted below

ComboFix 09-12-28.03 - GEORGE 12/29/2009 0:16.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2560 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\VIRUS SCAN PROCEDURES
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
ADS - WINDOWS: deleted 72 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-303087950-19637512-4056949597-1000
c:\documents and settings\GEORGE\Application Data\inst.exe
c:\documents and settings\GEORGE\My Documents\022809reg.reg
c:\documents and settings\GEORGE\My Documents\7-14-08.reg
c:\documents and settings\GEORGE\My Documents\backup.reg
c:\documents and settings\GEORGE\My Documents\BACKUP120107.reg
c:\documents and settings\GEORGE\My Documents\dec292008reg.reg
c:\documents and settings\GEORGE\My Documents\december15.reg
c:\documents and settings\GEORGE\My Documents\feb1408.reg
c:\documents and settings\GEORGE\My Documents\reg021109.reg
c:\recycler\S-1-5-21-1446432944-476004442-2805334122-1006
c:\windows\Downloaded Program Files\Temp
c:\windows\EventSystem.log
c:\windows\system\oeminfo.ini
c:\windows\system32\drivers\1028_DELL_XPS_Dell DXP061 .MRK
c:\windows\system32\drivers\DELL_XPS_Dell DXP061 .MRK
c:\windows\system32\vobis32.dll

.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-29 )))))))))))))))))))))))))))))))
.

2009-12-23 11:16 . 2009-12-23 11:16 ——– d—–w- c:\program files\Softwin
2009-12-21 10:52 . 2009-12-21 10:52 ——– d—–w- c:\program files\Sophos
2009-12-18 11:19 . 2009-12-29 04:57 52224 —-a-w- c:\documents and settings\GEORGE\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-18 10:52 . 2009-12-17 22:14 150888 —-a-w- C:\Tcpvcon.exe
2009-12-17 20:11 . 2008-04-14 01:11 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2009-12-12 08:31 . 2009-12-12 09:02 15 —-a-w- c:\documents and settings\GEORGE\settings.dat
2009-12-12 00:42 . 2009-12-12 00:42 ——– d—–w- c:\program files\MSXML 4.0
2009-12-12 00:37 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2009-12-11 22:00 . 2009-08-25 09:30 13312 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
2009-12-11 22:00 . 2009-10-20 21:33 545280 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\PicLensHelper.exe
2009-12-11 22:00 . 2009-10-20 21:33 4716544 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
2009-12-11 22:00 . 2009-10-20 21:33 344064 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\LaunchCooliris.exe
2009-12-11 22:00 . 2009-10-20 21:33 153600 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
2009-12-11 22:00 . 2009-10-20 21:33 103424 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\pixomatic.dll
2009-12-11 21:56 . 2009-12-29 05:06 ——– d—–w- c:\program files\Mozilla Firefox 3.55

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 07:58 . 2008-07-21 03:46 ——– d—–w- c:\program files\Mozilla Firefox3.0
2009-12-29 05:05 . 2007-09-18 10:38 ——– d—–w- c:\program files\Mozilla Firefox2.0
2009-12-29 05:01 . 2007-12-02 21:43 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-29 05:01 . 2008-02-06 16:14 ——– d—–w- c:\program files\SpywareBlaster
2009-12-29 05:00 . 2006-12-13 07:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-29 04:57 . 2009-03-17 20:59 117760 —-a-w- c:\documents and settings\GEORGE\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-20 01:55 . 2006-12-13 07:16 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-19 10:22 . 2006-11-29 21:40 ——– d—–w- c:\program files\Java
2009-12-19 10:00 . 2006-11-29 21:47 ——– d—–w- c:\program files\Real
2009-12-19 09:52 . 2006-11-29 21:44 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-19 08:57 . 2006-11-29 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-12-19 08:33 . 2006-11-29 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\QuickTime
2009-12-19 08:31 . 2008-02-15 21:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-19 08:12 . 2007-09-21 23:12 ——– d—–w- c:\program files\Microsoft Location Finder
2009-12-19 07:46 . 2006-11-29 21:47 ——– d—–w- c:\program files\Common Files\Real
2009-12-19 07:44 . 2008-03-04 22:06 ——– d—–w- c:\program files\CounterPath
2009-12-19 07:21 . 2006-12-07 10:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Windows Live Toolbar
2009-12-19 07:18 . 2007-10-06 17:03 ——– d—–w- c:\program files\MSN Money Toolbar Add-in
2009-12-19 07:17 . 2006-11-29 21:52 ——– d—–w- c:\program files\Yahoo!
2009-12-19 06:31 . 2008-03-27 03:06 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-19 02:42 . 2009-01-27 03:22 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-18 11:17 . 2009-05-29 06:12 ——– d—–w- c:\program files\a-squared Free
2009-12-17 22:10 . 2008-06-20 21:56 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-12-17 20:12 . 2009-12-17 20:12 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-12-17 20:12 . 2009-12-17 20:12 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-12-15 05:01 . 2009-04-28 03:50 95744 —-a-w- c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll
2009-12-12 01:31 . 2007-02-02 04:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-12 00:48 . 2006-11-29 21:53 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-12-12 00:24 . 2009-05-29 06:17 ——– d—–w- c:\documents and settings\GEORGE\Application Data\OnlineArmor
2009-12-11 22:05 . 2006-12-13 04:58 ——– d—–w- c:\documents and settings\GEORGE\Application Data\Skype
2009-12-11 20:33 . 2009-02-17 11:30 4844296 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-11 20:08 . 2009-05-29 06:07 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-04 00:14 . 2009-01-27 03:22 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-04 00:13 . 2009-01-27 03:22 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-21 15:51 . 2006-02-28 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-03 04:42 . 2009-11-01 22:10 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-11-02 00:06 . 2008-10-12 08:39 ——– d—–w- c:\program files\SpywareGuard
2009-11-01 22:40 . 2009-11-01 22:40 ——– d—–w- c:\program files\Microsoft Network Monitor 3
2009-11-01 22:08 . 2008-01-14 19:59 ——– d—–w- c:\program files\Microsoft Silverlight
2009-11-01 22:07 . 2006-11-29 21:52 ——– d—–w- c:\program files\Microsoft Works
2009-11-01 11:19 . 2009-10-18 06:10 ——– d—–w- c:\program files\Microsoft Network Monitor 3(2)
2009-10-29 07:46 . 2006-02-28 12:00 832512 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2006-02-28 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2006-02-28 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-10-21 05:38 . 2006-02-28 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-02-28 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2006-02-28 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2006-02-28 12:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2006-02-28 12:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2006-02-28 12:00 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-08 22:57 . 2008-07-30 03:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2009-10-08 22:57 . 2006-02-28 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 22:56 . 2006-02-28 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2008-09-20 18:42 . 2008-03-08 08:25 88 –sha-r- c:\windows\system32\892202FEA3.sys
2008-06-13 04:32 . 2008-06-13 04:32 23 –sha-w- c:\windows\system32\aafcebeaff4_g.dll
2008-09-20 18:43 . 2008-03-08 08:25 4856 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}]
@="{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}"
[HKEY_CLASSES_ROOT\CLSID\{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}]
2009-03-06 03:17 143160 —-a-w- c:\windows\system32\pfmshx_27B.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-17 2002160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"nwiz"="nwiz.exe" [2009-03-28 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 13684736]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 86016]
"@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2009-04-16 2044104]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-10-19 293888]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2009-04-16 335048]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-07 20:23 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-10-09 21:33 1949480 —-a-w- c:\program files\Apricorn\EZ Gig II\TimounterMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apricorn Scheduler Service]
2007-10-09 21:24 148712 —-a-w- c:\program files\Common Files\Apricorn\Schedule2\schedhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2008-03-18 09:06 1848648 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2008-12-12 09:31 722256 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2008-12-17 18:36 50520 —-a-w- c:\documents and settings\GEORGE\Application Data\mjusbsp\cdloader2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 —-a-w- c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZGigMonitor.exe]
2007-10-09 21:20 1169264 —-a-w- c:\program files\Apricorn\EZ Gig II\EZGigMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GizmoDriveDelegate]
2009-05-01 04:06 390752 —-a-w- c:\progra~1\Gizmo\gdrive.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 18:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJNetworkScanUtility]
2007-05-21 08:37 124512 —-a-w- c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 22:50 221184 —-a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
2007-05-17 21:45 279912 —-a-w- c:\program files\Microsoft LifeCam\LifeExp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2007-06-13 17:39 73728 —-a-w- c:\program files\ScanSoft\OmniPageSE4\OpWareSE4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
2004-03-11 08:26 406016 —-a-w- c:\windows\system32\PSDrvCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2009-03-15 10:15 180224 —-a-w- c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\siService.exe]
2003-12-23 18:31 204800 —-a-w- c:\program files\Sunbelt Software\iHateSpam\siService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 16:03 210472 —-a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-04-27 18:56 1410296 —-a-w- c:\program files\GAMES\Steam\steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-05-21 18:34 148888 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX6000]
2007-04-10 21:46 996712 —-a-w- c:\windows\vVX6000.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SQLWriter"=2 (0x2)
"SQLBrowser"=2 (0x2)
"MSSQL$MSSMLBIZ"=3 (0x3)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AdobeUpdater"=c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Plugin Install"=c:\program files\QuickTime\Plugins\DeleteMe1.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Sunbelt Software\\iHateSpam\\siMailProxyServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Google\\Google Updater\\GoogleUpdater.exe"=
"c:\\Program Files\\PowerFile C200\\PowerFile.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\GAMES\\Steam\\SteamApps\\common\\empire total war\\Empire.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Logging]
"LogSuccessfulConnections"= 0 (0x0)
"LogDroppedPackets"= 0 (0x0)
"LogFileSize"= 0 (0x0)
"LogFilePath"=

R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [3/12/2009 2:23 PM 40368]
R1 DiscImage;Disc image driver;c:\windows\system32\drivers\discimage.sys [5/26/2007 7:04 PM 24704]
R1 GizmoDrv;Gizmo Device Driver;c:\windows\system32\drivers\gizmodrv.sys [4/30/2009 8:07 PM 23624]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [5/28/2009 10:17 PM 196688]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [5/28/2009 10:17 PM 31824]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [5/28/2009 10:17 PM 29776]
R1 pfmfs_27B;pfmfs_27B;c:\windows\system32\drivers\pfmfs_27B.sys [4/30/2009 8:05 PM 179896]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [8/19/2008 11:34 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/19/2008 11:34 PM 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [5/28/2009 10:12 PM 1858144]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/28/2009 10:07 PM 108289]
R2 DIMSVC;Disc Image Demo mount service;c:\program files\Pa-software\Disc Image Demo\dimsvc.exe [5/26/2007 7:03 PM 36864]
R2 Gizmo Central;Gizmo Central;c:\program files\Gizmo\gservice.exe [4/30/2009 8:06 PM 31856]
R2 SMART-ERService;SMART-ER Service;c:\program files\Apricorn\SMART-ER\SMART-ER Service.exe [6/4/2007 10:20 AM 69632]
R2 VirtualDrive;VirtualDrive;c:\program files\All Image\vdd-x86.sys [4/30/2009 7:41 PM 10752]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [4/19/2008 1:46 PM 30560]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/19/2008 11:34 PM 7408]
S1 AntiLog32;AntiLog32;\??\c:\program files\AntiLogger\AntiLog32.sys –> c:\program files\AntiLogger\AntiLog32.sys [?]
S2 AnonMgmtSvc;Anonymizer Management Service;"c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe" –> c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe [?]
S2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [5/28/2009 10:17 PM 361160]
S2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [5/28/2009 10:17 PM 3049160]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\GEORGE\LOCALS~1\Temp\ALSysIO.sys –> c:\docume~1\GEORGE\LOCALS~1\Temp\ALSysIO.sys [?]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 DarkSpy;DarkSpy;\??\c:\windows\system32\DarkSpyKernel.sys –> c:\windows\system32\DarkSpyKernel.sys [?]
S3 dpK0Bx01;Fingerprint Reader Filter Driver;c:\windows\system32\drivers\dpK0Bx01.sys [1/5/2007 3:45 PM 35584]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [3/24/2009 12:15 PM 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [3/24/2009 12:15 PM 3072]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [8/17/2005 11:00 PM 7168]
S3 IntelDH;IntelDH Driver;c:\windows\system32\Drivers\IntelDH.sys –> c:\windows\system32\Drivers\IntelDH.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\16.tmp –> c:\windows\system32\16.tmp [?]
S3 PORTMON;PORTMON;\??\c:\documents and settings\GEORGE\Desktop\DOWNLOADS\Portmon\PORTMSYS.SYS –> c:\documents and settings\GEORGE\Desktop\DOWNLOADS\Portmon\PORTMSYS.SYS [?]
S3 SWUSBFLT;Microsoft SideWinder VIA Filter Driver;c:\windows\system32\drivers\SWUSBFLT.SYS [12/22/2006 10:46 PM 3968]
S3 UsbdpFP;Fingerprint Reader Class Driver;c:\windows\system32\drivers\usbdpfp.sys [1/5/2007 3:45 PM 47360]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [12/12/2006 6:43 PM 2385896]
S3 xusb20;Xbox 360 Wireless Receiver for Windows Driver Service;c:\windows\system32\drivers\xusb20.sys [10/13/2006 5:19 PM 50048]
S3 yeddef;YEDDEF driver;c:\windows\system32\Drivers\yeddef.sys –> c:\windows\system32\Drivers\yeddef.sys [?]
S3 ZD1211U(Hawking Technologies);Hawking Technologies HWU54D Hi-Gain Wireless-G USB Adapter(Hawking Technologies);c:\windows\system32\drivers\ZD1211U.sys [12/6/2006 4:17 AM 233472]
S4 gupdate1c901a09a323bba;Google Update Service (gupdate1c901a09a323bba);c:\program files\Google\Update\GoogleUpdate.exe [8/18/2008 6:09 PM 133104]
S4 NSLHNZKPEI;NSLHNZKPEI;c:\docume~1\GEORGE\LOCALS~1\Temp\NSLHNZKPEI.exe –> c:\docume~1\GEORGE\LOCALS~1\Temp\NSLHNZKPEI.exe [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4/30/2009 6:14 PM 721904]
S4 TABKB;TABKB;c:\docume~1\GEORGE\LOCALS~1\Temp\TABKB.exe –> c:\docume~1\GEORGE\LOCALS~1\Temp\TABKB.exe [?]

— Other Services/Drivers In Memory —

*Deregistered* - PROCEXP111
.
——- Supplementary Scan ——-
.
uLocal Page = hxxp://www.msn.com
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
Handler: msell2 - {9367D24B-8506-471A-915A-CFBB4BCEB631} - c:\program files\Common Files\Microsoft Shared\Reference Titles\MSELL2.dll
DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} - hxxps://actsvr.comcastonline.com/techtools/dl/Comcast%20Activation%20Controls.cab
FF - ProfilePath - c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\
FF - prefs.js: browser.startup.homepage - msn.com
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
FF - component: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - plugin: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npdeploytk.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npnul32.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - (no file)
Notify-DPWLN - (no file)
MSConfigStartUp-Anonymizer - c:\program files\Anonymizer\Anonymizer Software\Anonymizer.exe
AddRemove-AntiLogger - c:\documents and settings\All Users\Application Data\{DBBDCE5C-C9B7-4F00-BA4F-3D64168B6576}\AntiLogger_Setup.exe
AddRemove-BrothersInArms - e:\brothersinarms\System\Setup.exe
AddRemove-BrothersInArmsEiB - e:\ubisoft\Gearbox Software\BrothersInArmsEiB\System\Setup.exe
AddRemove-BrothersInArmsEIBSDK - e:\ubisoft\Gearbox Software\BrothersInArmsEiB\EIBSDKUninstall.exe
AddRemove-CompleteDoItYourselfGuide - d:\data\diyguide.exe
AddRemove-FoxyTunesForFirefox - c:\program files\Mozilla Firefox\firefox.exe
AddRemove-Microsoft MSDN 2005 Express Edition - ENU - e:\program files\Microsoft Visual Studio 8\Microsoft MSDN 2005 Express Edition - ENU\install.exe
AddRemove-Microsoft Visual Web Developer 2005 Express Edition - ENU - e:\program files\Microsoft Visual Studio 8\Microsoft Visual Web Developer 2005 Express Edition - ENU\setup.exe
AddRemove-Mozilla Firefox (2.0.0.20) - c:\program files\Mozilla Firefox\uninstall\helper.exe
AddRemove-Nero PhotoShow Express 4 - e:\nero photoshow 4\data\Xtras\Uninstall.exe
AddRemove-{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 - c:\program files\Spybot - Search & Destroy\unins001.exe
AddRemove-{C5089197-5B15-44AD-B0FC-2E94EE9ECB63} - c:\documents and settings\GEORGE\Local Settings\Application Data\{044CCC32-19C8-40C9-92DE-7D50DCAC47BA}\wsc.exe



**************************************************************************
scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\16.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3060164775-2224625509-1354611237-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1076)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(1136)
c:\windows\system32\relog_ap.dll
c:\windows\DPPWDFLT.dll
.
Completion time: 2009-12-29 00:23:48
ComboFix-quarantined-files.txt 2009-12-29 08:23

Pre-Run: 15,852,703,744 bytes free
Post-Run: 15,987,843,072 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - B55EF24745AE95E2F263C0B3DC025394

Thanks I disable all software other then going into taskmanager to kill process trees which it wouldn;'t le tme do anyway
ComboFix 09-12-28.03 - GEORGE 12/29/2009 0:16.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2560 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\VIRUS SCAN PROCEDURES
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
ADS - WINDOWS: deleted 72 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-303087950-19637512-4056949597-1000
c:\documents and settings\GEORGE\Application Data\inst.exe
c:\documents and settings\GEORGE\My Documents\022809reg.reg
c:\documents and settings\GEORGE\My Documents\7-14-08.reg
c:\documents and settings\GEORGE\My Documents\backup.reg
c:\documents and settings\GEORGE\My Documents\BACKUP120107.reg
c:\documents and settings\GEORGE\My Documents\dec292008reg.reg
c:\documents and settings\GEORGE\My Documents\december15.reg
c:\documents and settings\GEORGE\My Documents\feb1408.reg
c:\documents and settings\GEORGE\My Documents\reg021109.reg
c:\recycler\S-1-5-21-1446432944-476004442-2805334122-1006
c:\windows\Downloaded Program Files\Temp
c:\windows\EventSystem.log
c:\windows\system\oeminfo.ini
c:\windows\system32\drivers\1028_DELL_XPS_Dell DXP061 .MRK
c:\windows\system32\drivers\DELL_XPS_Dell DXP061 .MRK
c:\windows\system32\vobis32.dll

.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-29 )))))))))))))))))))))))))))))))
.

2009-12-23 11:16 . 2009-12-23 11:16 ——– d—–w- c:\program files\Softwin
2009-12-21 10:52 . 2009-12-21 10:52 ——– d—–w- c:\program files\Sophos
2009-12-18 11:19 . 2009-12-29 04:57 52224 —-a-w- c:\documents and settings\GEORGE\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-18 10:52 . 2009-12-17 22:14 150888 —-a-w- C:\Tcpvcon.exe
2009-12-17 20:11 . 2008-04-14 01:11 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2009-12-12 08:31 . 2009-12-12 09:02 15 —-a-w- c:\documents and settings\GEORGE\settings.dat
2009-12-12 00:42 . 2009-12-12 00:42 ——– d—–w- c:\program files\MSXML 4.0
2009-12-12 00:37 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2009-12-11 22:00 . 2009-08-25 09:30 13312 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
2009-12-11 22:00 . 2009-10-20 21:33 545280 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\PicLensHelper.exe
2009-12-11 22:00 . 2009-10-20 21:33 4716544 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
2009-12-11 22:00 . 2009-10-20 21:33 344064 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\LaunchCooliris.exe
2009-12-11 22:00 . 2009-10-20 21:33 153600 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
2009-12-11 22:00 . 2009-10-20 21:33 103424 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\pixomatic.dll
2009-12-11 21:56 . 2009-12-29 05:06 ——– d—–w- c:\program files\Mozilla Firefox 3.55

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 07:58 . 2008-07-21 03:46 ——– d—–w- c:\program files\Mozilla Firefox3.0
2009-12-29 05:05 . 2007-09-18 10:38 ——– d—–w- c:\program files\Mozilla Firefox2.0
2009-12-29 05:01 . 2007-12-02 21:43 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-29 05:01 . 2008-02-06 16:14 ——– d—–w- c:\program files\SpywareBlaster
2009-12-29 05:00 . 2006-12-13 07:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-29 04:57 . 2009-03-17 20:59 117760 —-a-w- c:\documents and settings\GEORGE\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-20 01:55 . 2006-12-13 07:16 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-19 10:22 . 2006-11-29 21:40 ——– d—–w- c:\program files\Java
2009-12-19 10:00 . 2006-11-29 21:47 ——– d—–w- c:\program files\Real
2009-12-19 09:52 . 2006-11-29 21:44 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-19 08:57 . 2006-11-29 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-12-19 08:33 . 2006-11-29 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\QuickTime
2009-12-19 08:31 . 2008-02-15 21:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-19 08:12 . 2007-09-21 23:12 ——– d—–w- c:\program files\Microsoft Location Finder
2009-12-19 07:46 . 2006-11-29 21:47 ——– d—–w- c:\program files\Common Files\Real
2009-12-19 07:44 . 2008-03-04 22:06 ——– d—–w- c:\program files\CounterPath
2009-12-19 07:21 . 2006-12-07 10:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Windows Live Toolbar
2009-12-19 07:18 . 2007-10-06 17:03 ——– d—–w- c:\program files\MSN Money Toolbar Add-in
2009-12-19 07:17 . 2006-11-29 21:52 ——– d—–w- c:\program files\Yahoo!
2009-12-19 06:31 . 2008-03-27 03:06 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-19 02:42 . 2009-01-27 03:22 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-18 11:17 . 2009-05-29 06:12 ——– d—–w- c:\program files\a-squared Free
2009-12-17 22:10 . 2008-06-20 21:56 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-12-17 20:12 . 2009-12-17 20:12 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-12-17 20:12 . 2009-12-17 20:12 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-12-15 05:01 . 2009-04-28 03:50 95744 —-a-w- c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll
2009-12-12 01:31 . 2007-02-02 04:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-12 00:48 . 2006-11-29 21:53 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-12-12 00:24 . 2009-05-29 06:17 ——– d—–w- c:\documents and settings\GEORGE\Application Data\OnlineArmor
2009-12-11 22:05 . 2006-12-13 04:58 ——– d—–w- c:\documents and settings\GEORGE\Application Data\Skype
2009-12-11 20:33 . 2009-02-17 11:30 4844296 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-11 20:08 . 2009-05-29 06:07 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-04 00:14 . 2009-01-27 03:22 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-04 00:13 . 2009-01-27 03:22 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-21 15:51 . 2006-02-28 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-03 04:42 . 2009-11-01 22:10 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-11-02 00:06 . 2008-10-12 08:39 ——– d—–w- c:\program files\SpywareGuard
2009-11-01 22:40 . 2009-11-01 22:40 ——– d—–w- c:\program files\Microsoft Network Monitor 3
2009-11-01 22:08 . 2008-01-14 19:59 ——– d—–w- c:\program files\Microsoft Silverlight
2009-11-01 22:07 . 2006-11-29 21:52 ——– d—–w- c:\program files\Microsoft Works
2009-11-01 11:19 . 2009-10-18 06:10 ——– d—–w- c:\program files\Microsoft Network Monitor 3(2)
2009-10-29 07:46 . 2006-02-28 12:00 832512 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2006-02-28 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2006-02-28 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-10-21 05:38 . 2006-02-28 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-02-28 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2006-02-28 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2006-02-28 12:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2006-02-28 12:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2006-02-28 12:00 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-08 22:57 . 2008-07-30 03:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2009-10-08 22:57 . 2006-02-28 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 22:56 . 2006-02-28 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2008-09-20 18:42 . 2008-03-08 08:25 88 –sha-r- c:\windows\system32\892202FEA3.sys
2008-06-13 04:32 . 2008-06-13 04:32 23 –sha-w- c:\windows\system32\aafcebeaff4_g.dll
2008-09-20 18:43 . 2008-03-08 08:25 4856 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}]
@="{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}"
[HKEY_CLASSES_ROOT\CLSID\{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}]
2009-03-06 03:17 143160 —-a-w- c:\windows\system32\pfmshx_27B.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-17 2002160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"nwiz"="nwiz.exe" [2009-03-28 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 13684736]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 86016]
"@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2009-04-16 2044104]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-10-19 293888]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2009-04-16 335048]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-07 20:23 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-10-09 21:33 1949480 —-a-w- c:\program files\Apricorn\EZ Gig II\TimounterMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apricorn Scheduler Service]
2007-10-09 21:24 148712 —-a-w- c:\program files\Common Files\Apricorn\Schedule2\schedhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2008-03-18 09:06 1848648 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2008-12-12 09:31 722256 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2008-12-17 18:36 50520 —-a-w- c:\documents and settings\GEORGE\Application Data\mjusbsp\cdloader2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 —-a-w- c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZGigMonitor.exe]
2007-10-09 21:20 1169264 —-a-w- c:\program files\Apricorn\EZ Gig II\EZGigMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GizmoDriveDelegate]
2009-05-01 04:06 390752 —-a-w- c:\progra~1\Gizmo\gdrive.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 18:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJNetworkScanUtility]
2007-05-21 08:37 124512 —-a-w- c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 22:50 221184 —-a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
2007-05-17 21:45 279912 —-a-w- c:\program files\Microsoft LifeCam\LifeExp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2007-06-13 17:39 73728 —-a-w- c:\program files\ScanSoft\OmniPageSE4\OpWareSE4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
2004-03-11 08:26 406016 —-a-w- c:\windows\system32\PSDrvCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2009-03-15 10:15 180224 —-a-w- c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\siService.exe]
2003-12-23 18:31 204800 —-a-w- c:\program files\Sunbelt Software\iHateSpam\siService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 16:03 210472 —-a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-04-27 18:56 1410296 —-a-w- c:\program files\GAMES\Steam\steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-05-21 18:34 148888 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX6000]
2007-04-10 21:46 996712 —-a-w- c:\windows\vVX6000.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SQLWriter"=2 (0x2)
"SQLBrowser"=2 (0x2)
"MSSQL$MSSMLBIZ"=3 (0x3)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AdobeUpdater"=c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Plugin Install"=c:\program files\QuickTime\Plugins\DeleteMe1.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Sunbelt Software\\iHateSpam\\siMailProxyServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Google\\Google Updater\\GoogleUpdater.exe"=
"c:\\Program Files\\PowerFile C200\\PowerFile.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\GAMES\\Steam\\SteamApps\\common\\empire total war\\Empire.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Logging]
"LogSuccessfulConnections"= 0 (0x0)
"LogDroppedPackets"= 0 (0x0)
"LogFileSize"= 0 (0x0)
"LogFilePath"=

R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [3/12/2009 2:23 PM 40368]
R1 DiscImage;Disc image driver;c:\windows\system32\drivers\discimage.sys [5/26/2007 7:04 PM 24704]
R1 GizmoDrv;Gizmo Device Driver;c:\windows\system32\drivers\gizmodrv.sys [4/30/2009 8:07 PM 23624]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [5/28/2009 10:17 PM 196688]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [5/28/2009 10:17 PM 31824]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [5/28/2009 10:17 PM 29776]
R1 pfmfs_27B;pfmfs_27B;c:\windows\system32\drivers\pfmfs_27B.sys [4/30/2009 8:05 PM 179896]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [8/19/2008 11:34 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/19/2008 11:34 PM 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [5/28/2009 10:12 PM 1858144]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/28/2009 10:07 PM 108289]
R2 DIMSVC;Disc Image Demo mount service;c:\program files\Pa-software\Disc Image Demo\dimsvc.exe [5/26/2007 7:03 PM 36864]
R2 Gizmo Central;Gizmo Central;c:\program files\Gizmo\gservice.exe [4/30/2009 8:06 PM 31856]
R2 SMART-ERService;SMART-ER Service;c:\program files\Apricorn\SMART-ER\SMART-ER Service.exe [6/4/2007 10:20 AM 69632]
R2 VirtualDrive;VirtualDrive;c:\program files\All Image\vdd-x86.sys [4/30/2009 7:41 PM 10752]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [4/19/2008 1:46 PM 30560]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/19/2008 11:34 PM 7408]
S1 AntiLog32;AntiLog32;\??\c:\program files\AntiLogger\AntiLog32.sys –> c:\program files\AntiLogger\AntiLog32.sys [?]
S2 AnonMgmtSvc;Anonymizer Management Service;"c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe" –> c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe [?]
S2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [5/28/2009 10:17 PM 361160]
S2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [5/28/2009 10:17 PM 3049160]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\GEORGE\LOCALS~1\Temp\ALSysIO.sys –> c:\docume~1\GEORGE\LOCALS~1\Temp\ALSysIO.sys [?]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 DarkSpy;DarkSpy;\??\c:\windows\system32\DarkSpyKernel.sys –> c:\windows\system32\DarkSpyKernel.sys [?]
S3 dpK0Bx01;Fingerprint Reader Filter Driver;c:\windows\system32\drivers\dpK0Bx01.sys [1/5/2007 3:45 PM 35584]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [3/24/2009 12:15 PM 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [3/24/2009 12:15 PM 3072]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [8/17/2005 11:00 PM 7168]
S3 IntelDH;IntelDH Driver;c:\windows\system32\Drivers\IntelDH.sys –> c:\windows\system32\Drivers\IntelDH.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\16.tmp –> c:\windows\system32\16.tmp [?]
S3 PORTMON;PORTMON;\??\c:\documents and settings\GEORGE\Desktop\DOWNLOADS\Portmon\PORTMSYS.SYS –> c:\documents and settings\GEORGE\Desktop\DOWNLOADS\Portmon\PORTMSYS.SYS [?]
S3 SWUSBFLT;Microsoft SideWinder VIA Filter Driver;c:\windows\system32\drivers\SWUSBFLT.SYS [12/22/2006 10:46 PM 3968]
S3 UsbdpFP;Fingerprint Reader Class Driver;c:\windows\system32\drivers\usbdpfp.sys [1/5/2007 3:45 PM 47360]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [12/12/2006 6:43 PM 2385896]
S3 xusb20;Xbox 360 Wireless Receiver for Windows Driver Service;c:\windows\system32\drivers\xusb20.sys [10/13/2006 5:19 PM 50048]
S3 yeddef;YEDDEF driver;c:\windows\system32\Drivers\yeddef.sys –> c:\windows\system32\Drivers\yeddef.sys [?]
S3 ZD1211U(Hawking Technologies);Hawking Technologies HWU54D Hi-Gain Wireless-G USB Adapter(Hawking Technologies);c:\windows\system32\drivers\ZD1211U.sys [12/6/2006 4:17 AM 233472]
S4 gupdate1c901a09a323bba;Google Update Service (gupdate1c901a09a323bba);c:\program files\Google\Update\GoogleUpdate.exe [8/18/2008 6:09 PM 133104]
S4 NSLHNZKPEI;NSLHNZKPEI;c:\docume~1\GEORGE\LOCALS~1\Temp\NSLHNZKPEI.exe –> c:\docume~1\GEORGE\LOCALS~1\Temp\NSLHNZKPEI.exe [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4/30/2009 6:14 PM 721904]
S4 TABKB;TABKB;c:\docume~1\GEORGE\LOCALS~1\Temp\TABKB.exe –> c:\docume~1\GEORGE\LOCALS~1\Temp\TABKB.exe [?]

— Other Services/Drivers In Memory —

*Deregistered* - PROCEXP111
.
——- Supplementary Scan ——-
.
uLocal Page = hxxp://www.msn.com
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
Handler: msell2 - {9367D24B-8506-471A-915A-CFBB4BCEB631} - c:\program files\Common Files\Microsoft Shared\Reference Titles\MSELL2.dll
DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} - hxxps://actsvr.comcastonline.com/techtools/dl/Comcast%20Activation%20Controls.cab
FF - ProfilePath - c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\
FF - prefs.js: browser.startup.homepage - msn.com
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
FF - component: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - plugin: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npdeploytk.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npnul32.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - (no file)
Notify-DPWLN - (no file)
MSConfigStartUp-Anonymizer - c:\program files\Anonymizer\Anonymizer Software\Anonymizer.exe
AddRemove-AntiLogger - c:\documents and settings\All Users\Application Data\{DBBDCE5C-C9B7-4F00-BA4F-3D64168B6576}\AntiLogger_Setup.exe
AddRemove-BrothersInArms - e:\brothersinarms\System\Setup.exe
AddRemove-BrothersInArmsEiB - e:\ubisoft\Gearbox Software\BrothersInArmsEiB\System\Setup.exe
AddRemove-BrothersInArmsEIBSDK - e:\ubisoft\Gearbox Software\BrothersInArmsEiB\EIBSDKUninstall.exe
AddRemove-CompleteDoItYourselfGuide - d:\data\diyguide.exe
AddRemove-FoxyTunesForFirefox - c:\program files\Mozilla Firefox\firefox.exe
AddRemove-Microsoft MSDN 2005 Express Edition - ENU - e:\program files\Microsoft Visual Studio 8\Microsoft MSDN 2005 Express Edition - ENU\install.exe
AddRemove-Microsoft Visual Web Developer 2005 Express Edition - ENU - e:\program files\Microsoft Visual Studio 8\Microsoft Visual Web Developer 2005 Express Edition - ENU\setup.exe
AddRemove-Mozilla Firefox (2.0.0.20) - c:\program files\Mozilla Firefox\uninstall\helper.exe
AddRemove-Nero PhotoShow Express 4 - e:\nero photoshow 4\data\Xtras\Uninstall.exe
AddRemove-{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 - c:\program files\Spybot - Search & Destroy\unins001.exe
AddRemove-{C5089197-5B15-44AD-B0FC-2E94EE9ECB63} - c:\documents and settings\GEORGE\Local Settings\Application Data\{044CCC32-19C8-40C9-92DE-7D50DCAC47BA}\wsc.exe



**************************************************************************
scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\16.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3060164775-2224625509-1354611237-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1076)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(1136)
c:\windows\system32\relog_ap.dll
c:\windows\DPPWDFLT.dll
.
Completion time: 2009-12-29 00:23:48
ComboFix-quarantined-files.txt 2009-12-29 08:23

Pre-Run: 15,852,703,744 bytes free
Post-Run: 15,987,843,072 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - B55EF24745AE95E2F263C0B3DC025394

I ran defogger. I ran the combo-fix.exe program. During the process, Combo stated not to start any program, I needed to download recovery console.
which I suppose it installed. It stated not to click on the program but after it started running a screen popped up saying swxcalx.cfxxe is corrupt and windows
needs to run chkdsk now click OK which I didn't do….was wondering if this was legit or not. Finished posted below

ComboFix 09-12-28.03 - GEORGE 12/29/2009 0:16.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2560 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\VIRUS SCAN PROCEDURES
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
ADS - WINDOWS: deleted 72 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-303087950-19637512-4056949597-1000
c:\documents and settings\GEORGE\Application Data\inst.exe
c:\documents and settings\GEORGE\My Documents\022809reg.reg
c:\documents and settings\GEORGE\My Documents\7-14-08.reg
c:\documents and settings\GEORGE\My Documents\backup.reg
c:\documents and settings\GEORGE\My Documents\BACKUP120107.reg
c:\documents and settings\GEORGE\My Documents\dec292008reg.reg
c:\documents and settings\GEORGE\My Documents\december15.reg
c:\documents and settings\GEORGE\My Documents\feb1408.reg
c:\documents and settings\GEORGE\My Documents\reg021109.reg
c:\recycler\S-1-5-21-1446432944-476004442-2805334122-1006
c:\windows\Downloaded Program Files\Temp
c:\windows\EventSystem.log
c:\windows\system\oeminfo.ini
c:\windows\system32\drivers\1028_DELL_XPS_Dell DXP061 .MRK
c:\windows\system32\drivers\DELL_XPS_Dell DXP061 .MRK
c:\windows\system32\vobis32.dll

.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-29 )))))))))))))))))))))))))))))))
.

2009-12-23 11:16 . 2009-12-23 11:16 ——– d—–w- c:\program files\Softwin
2009-12-21 10:52 . 2009-12-21 10:52 ——– d—–w- c:\program files\Sophos
2009-12-18 11:19 . 2009-12-29 04:57 52224 —-a-w- c:\documents and settings\GEORGE\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-18 10:52 . 2009-12-17 22:14 150888 —-a-w- C:\Tcpvcon.exe
2009-12-17 20:11 . 2008-04-14 01:11 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2009-12-12 08:31 . 2009-12-12 09:02 15 —-a-w- c:\documents and settings\GEORGE\settings.dat
2009-12-12 00:42 . 2009-12-12 00:42 ——– d—–w- c:\program files\MSXML 4.0
2009-12-12 00:37 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2009-12-11 22:00 . 2009-08-25 09:30 13312 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
2009-12-11 22:00 . 2009-10-20 21:33 545280 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\PicLensHelper.exe
2009-12-11 22:00 . 2009-10-20 21:33 4716544 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
2009-12-11 22:00 . 2009-10-20 21:33 344064 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\LaunchCooliris.exe
2009-12-11 22:00 . 2009-10-20 21:33 153600 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
2009-12-11 22:00 . 2009-10-20 21:33 103424 —-a-w- c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\libs\pixomatic.dll
2009-12-11 21:56 . 2009-12-29 05:06 ——– d—–w- c:\program files\Mozilla Firefox 3.55

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 07:58 . 2008-07-21 03:46 ——– d—–w- c:\program files\Mozilla Firefox3.0
2009-12-29 05:05 . 2007-09-18 10:38 ——– d—–w- c:\program files\Mozilla Firefox2.0
2009-12-29 05:01 . 2007-12-02 21:43 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-29 05:01 . 2008-02-06 16:14 ——– d—–w- c:\program files\SpywareBlaster
2009-12-29 05:00 . 2006-12-13 07:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-29 04:57 . 2009-03-17 20:59 117760 —-a-w- c:\documents and settings\GEORGE\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-20 01:55 . 2006-12-13 07:16 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-19 10:22 . 2006-11-29 21:40 ——– d—–w- c:\program files\Java
2009-12-19 10:00 . 2006-11-29 21:47 ——– d—–w- c:\program files\Real
2009-12-19 09:52 . 2006-11-29 21:44 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-19 08:57 . 2006-11-29 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-12-19 08:33 . 2006-11-29 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\QuickTime
2009-12-19 08:31 . 2008-02-15 21:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-19 08:12 . 2007-09-21 23:12 ——– d—–w- c:\program files\Microsoft Location Finder
2009-12-19 07:46 . 2006-11-29 21:47 ——– d—–w- c:\program files\Common Files\Real
2009-12-19 07:44 . 2008-03-04 22:06 ——– d—–w- c:\program files\CounterPath
2009-12-19 07:21 . 2006-12-07 10:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Windows Live Toolbar
2009-12-19 07:18 . 2007-10-06 17:03 ——– d—–w- c:\program files\MSN Money Toolbar Add-in
2009-12-19 07:17 . 2006-11-29 21:52 ——– d—–w- c:\program files\Yahoo!
2009-12-19 06:31 . 2008-03-27 03:06 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-19 02:42 . 2009-01-27 03:22 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-18 11:17 . 2009-05-29 06:12 ——– d—–w- c:\program files\a-squared Free
2009-12-17 22:10 . 2008-06-20 21:56 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-12-17 20:12 . 2009-12-17 20:12 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-12-17 20:12 . 2009-12-17 20:12 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-12-15 05:01 . 2009-04-28 03:50 95744 —-a-w- c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll
2009-12-12 01:31 . 2007-02-02 04:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-12 00:48 . 2006-11-29 21:53 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-12-12 00:24 . 2009-05-29 06:17 ——– d—–w- c:\documents and settings\GEORGE\Application Data\OnlineArmor
2009-12-11 22:05 . 2006-12-13 04:58 ——– d—–w- c:\documents and settings\GEORGE\Application Data\Skype
2009-12-11 20:33 . 2009-02-17 11:30 4844296 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-11 20:08 . 2009-05-29 06:07 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-04 00:14 . 2009-01-27 03:22 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-04 00:13 . 2009-01-27 03:22 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-21 15:51 . 2006-02-28 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-03 04:42 . 2009-11-01 22:10 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-11-02 00:06 . 2008-10-12 08:39 ——– d—–w- c:\program files\SpywareGuard
2009-11-01 22:40 . 2009-11-01 22:40 ——– d—–w- c:\program files\Microsoft Network Monitor 3
2009-11-01 22:08 . 2008-01-14 19:59 ——– d—–w- c:\program files\Microsoft Silverlight
2009-11-01 22:07 . 2006-11-29 21:52 ——– d—–w- c:\program files\Microsoft Works
2009-11-01 11:19 . 2009-10-18 06:10 ——– d—–w- c:\program files\Microsoft Network Monitor 3(2)
2009-10-29 07:46 . 2006-02-28 12:00 832512 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2006-02-28 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2006-02-28 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-10-21 05:38 . 2006-02-28 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-02-28 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2006-02-28 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2006-02-28 12:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2006-02-28 12:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2006-02-28 12:00 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-08 22:57 . 2008-07-30 03:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2009-10-08 22:57 . 2006-02-28 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 22:56 . 2006-02-28 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2008-09-20 18:42 . 2008-03-08 08:25 88 –sha-r- c:\windows\system32\892202FEA3.sys
2008-06-13 04:32 . 2008-06-13 04:32 23 –sha-w- c:\windows\system32\aafcebeaff4_g.dll
2008-09-20 18:43 . 2008-03-08 08:25 4856 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}]
@="{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}"
[HKEY_CLASSES_ROOT\CLSID\{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}]
2009-03-06 03:17 143160 —-a-w- c:\windows\system32\pfmshx_27B.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-17 2002160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"nwiz"="nwiz.exe" [2009-03-28 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 13684736]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 86016]
"@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2009-04-16 2044104]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-10-19 293888]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2009-04-16 335048]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-07 20:23 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-10-09 21:33 1949480 —-a-w- c:\program files\Apricorn\EZ Gig II\TimounterMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apricorn Scheduler Service]
2007-10-09 21:24 148712 —-a-w- c:\program files\Common Files\Apricorn\Schedule2\schedhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2008-03-18 09:06 1848648 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2008-12-12 09:31 722256 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2008-12-17 18:36 50520 —-a-w- c:\documents and settings\GEORGE\Application Data\mjusbsp\cdloader2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 —-a-w- c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZGigMonitor.exe]
2007-10-09 21:20 1169264 —-a-w- c:\program files\Apricorn\EZ Gig II\EZGigMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GizmoDriveDelegate]
2009-05-01 04:06 390752 —-a-w- c:\progra~1\Gizmo\gdrive.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 18:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJNetworkScanUtility]
2007-05-21 08:37 124512 —-a-w- c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 22:50 221184 —-a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
2007-05-17 21:45 279912 —-a-w- c:\program files\Microsoft LifeCam\LifeExp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2007-06-13 17:39 73728 —-a-w- c:\program files\ScanSoft\OmniPageSE4\OpWareSE4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
2004-03-11 08:26 406016 —-a-w- c:\windows\system32\PSDrvCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2009-03-15 10:15 180224 —-a-w- c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\siService.exe]
2003-12-23 18:31 204800 —-a-w- c:\program files\Sunbelt Software\iHateSpam\siService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 16:03 210472 —-a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-04-27 18:56 1410296 —-a-w- c:\program files\GAMES\Steam\steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-05-21 18:34 148888 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX6000]
2007-04-10 21:46 996712 —-a-w- c:\windows\vVX6000.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SQLWriter"=2 (0x2)
"SQLBrowser"=2 (0x2)
"MSSQL$MSSMLBIZ"=3 (0x3)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AdobeUpdater"=c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Plugin Install"=c:\program files\QuickTime\Plugins\DeleteMe1.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Sunbelt Software\\iHateSpam\\siMailProxyServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Google\\Google Updater\\GoogleUpdater.exe"=
"c:\\Program Files\\PowerFile C200\\PowerFile.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\GAMES\\Steam\\SteamApps\\common\\empire total war\\Empire.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Logging]
"LogSuccessfulConnections"= 0 (0x0)
"LogDroppedPackets"= 0 (0x0)
"LogFileSize"= 0 (0x0)
"LogFilePath"=

R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [3/12/2009 2:23 PM 40368]
R1 DiscImage;Disc image driver;c:\windows\system32\drivers\discimage.sys [5/26/2007 7:04 PM 24704]
R1 GizmoDrv;Gizmo Device Driver;c:\windows\system32\drivers\gizmodrv.sys [4/30/2009 8:07 PM 23624]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [5/28/2009 10:17 PM 196688]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [5/28/2009 10:17 PM 31824]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [5/28/2009 10:17 PM 29776]
R1 pfmfs_27B;pfmfs_27B;c:\windows\system32\drivers\pfmfs_27B.sys [4/30/2009 8:05 PM 179896]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [8/19/2008 11:34 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/19/2008 11:34 PM 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [5/28/2009 10:12 PM 1858144]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/28/2009 10:07 PM 108289]
R2 DIMSVC;Disc Image Demo mount service;c:\program files\Pa-software\Disc Image Demo\dimsvc.exe [5/26/2007 7:03 PM 36864]
R2 Gizmo Central;Gizmo Central;c:\program files\Gizmo\gservice.exe [4/30/2009 8:06 PM 31856]
R2 SMART-ERService;SMART-ER Service;c:\program files\Apricorn\SMART-ER\SMART-ER Service.exe [6/4/2007 10:20 AM 69632]
R2 VirtualDrive;VirtualDrive;c:\program files\All Image\vdd-x86.sys [4/30/2009 7:41 PM 10752]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [4/19/2008 1:46 PM 30560]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/19/2008 11:34 PM 7408]
S1 AntiLog32;AntiLog32;\??\c:\program files\AntiLogger\AntiLog32.sys –> c:\program files\AntiLogger\AntiLog32.sys [?]
S2 AnonMgmtSvc;Anonymizer Management Service;"c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe" –> c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe [?]
S2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [5/28/2009 10:17 PM 361160]
S2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [5/28/2009 10:17 PM 3049160]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\GEORGE\LOCALS~1\Temp\ALSysIO.sys –> c:\docume~1\GEORGE\LOCALS~1\Temp\ALSysIO.sys [?]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 DarkSpy;DarkSpy;\??\c:\windows\system32\DarkSpyKernel.sys –> c:\windows\system32\DarkSpyKernel.sys [?]
S3 dpK0Bx01;Fingerprint Reader Filter Driver;c:\windows\system32\drivers\dpK0Bx01.sys [1/5/2007 3:45 PM 35584]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [3/24/2009 12:15 PM 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [3/24/2009 12:15 PM 3072]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [8/17/2005 11:00 PM 7168]
S3 IntelDH;IntelDH Driver;c:\windows\system32\Drivers\IntelDH.sys –> c:\windows\system32\Drivers\IntelDH.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\16.tmp –> c:\windows\system32\16.tmp [?]
S3 PORTMON;PORTMON;\??\c:\documents and settings\GEORGE\Desktop\DOWNLOADS\Portmon\PORTMSYS.SYS –> c:\documents and settings\GEORGE\Desktop\DOWNLOADS\Portmon\PORTMSYS.SYS [?]
S3 SWUSBFLT;Microsoft SideWinder VIA Filter Driver;c:\windows\system32\drivers\SWUSBFLT.SYS [12/22/2006 10:46 PM 3968]
S3 UsbdpFP;Fingerprint Reader Class Driver;c:\windows\system32\drivers\usbdpfp.sys [1/5/2007 3:45 PM 47360]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [12/12/2006 6:43 PM 2385896]
S3 xusb20;Xbox 360 Wireless Receiver for Windows Driver Service;c:\windows\system32\drivers\xusb20.sys [10/13/2006 5:19 PM 50048]
S3 yeddef;YEDDEF driver;c:\windows\system32\Drivers\yeddef.sys –> c:\windows\system32\Drivers\yeddef.sys [?]
S3 ZD1211U(Hawking Technologies);Hawking Technologies HWU54D Hi-Gain Wireless-G USB Adapter(Hawking Technologies);c:\windows\system32\drivers\ZD1211U.sys [12/6/2006 4:17 AM 233472]
S4 gupdate1c901a09a323bba;Google Update Service (gupdate1c901a09a323bba);c:\program files\Google\Update\GoogleUpdate.exe [8/18/2008 6:09 PM 133104]
S4 NSLHNZKPEI;NSLHNZKPEI;c:\docume~1\GEORGE\LOCALS~1\Temp\NSLHNZKPEI.exe –> c:\docume~1\GEORGE\LOCALS~1\Temp\NSLHNZKPEI.exe [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4/30/2009 6:14 PM 721904]
S4 TABKB;TABKB;c:\docume~1\GEORGE\LOCALS~1\Temp\TABKB.exe –> c:\docume~1\GEORGE\LOCALS~1\Temp\TABKB.exe [?]

— Other Services/Drivers In Memory —

*Deregistered* - PROCEXP111
.
——- Supplementary Scan ——-
.
uLocal Page = hxxp://www.msn.com
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
Handler: msell2 - {9367D24B-8506-471A-915A-CFBB4BCEB631} - c:\program files\Common Files\Microsoft Shared\Reference Titles\MSELL2.dll
DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} - hxxps://actsvr.comcastonline.com/techtools/dl/Comcast%20Activation%20Controls.cab
FF - ProfilePath - c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\
FF - prefs.js: browser.startup.homepage - msn.com
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\cooliris.dll
FF - component: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\components\nsTwitterFoxSign.dll
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - plugin: c:\documents and settings\GEORGE\Application Data\Mozilla\Firefox\Profiles\c5k4s1z3.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npdeploytk.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox3.0\plugins\npnul32.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - (no file)
Notify-DPWLN - (no file)
MSConfigStartUp-Anonymizer - c:\program files\Anonymizer\Anonymizer Software\Anonymizer.exe
AddRemove-AntiLogger - c:\documents and settings\All Users\Application Data\{DBBDCE5C-C9B7-4F00-BA4F-3D64168B6576}\AntiLogger_Setup.exe
AddRemove-BrothersInArms - e:\brothersinarms\System\Setup.exe
AddRemove-BrothersInArmsEiB - e:\ubisoft\Gearbox Software\BrothersInArmsEiB\System\Setup.exe
AddRemove-BrothersInArmsEIBSDK - e:\ubisoft\Gearbox Software\BrothersInArmsEiB\EIBSDKUninstall.exe
AddRemove-CompleteDoItYourselfGuide - d:\data\diyguide.exe
AddRemove-FoxyTunesForFirefox - c:\program files\Mozilla Firefox\firefox.exe
AddRemove-Microsoft MSDN 2005 Express Edition - ENU - e:\program files\Microsoft Visual Studio 8\Microsoft MSDN 2005 Express Edition - ENU\install.exe
AddRemove-Microsoft Visual Web Developer 2005 Express Edition - ENU - e:\program files\Microsoft Visual Studio 8\Microsoft Visual Web Developer 2005 Express Edition - ENU\setup.exe
AddRemove-Mozilla Firefox (2.0.0.20) - c:\program files\Mozilla Firefox\uninstall\helper.exe
AddRemove-Nero PhotoShow Express 4 - e:\nero photoshow 4\data\Xtras\Uninstall.exe
AddRemove-{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 - c:\program files\Spybot - Search & Destroy\unins001.exe
AddRemove-{C5089197-5B15-44AD-B0FC-2E94EE9ECB63} - c:\documents and settings\GEORGE\Local Settings\Application Data\{044CCC32-19C8-40C9-92DE-7D50DCAC47BA}\wsc.exe



**************************************************************************
scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\16.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3060164775-2224625509-1354611237-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1076)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(1136)
c:\windows\system32\relog_ap.dll
c:\windows\DPPWDFLT.dll
.
Completion time: 2009-12-29 00:23:48
ComboFix-quarantined-files.txt 2009-12-29 08:23

Pre-Run: 15,852,703,744 bytes free
Post-Run: 15,987,843,072 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - B55EF24745AE95E2F263C0B3DC025394

Thanks I disable all software other then going into taskmanager to kill process trees which it wouldn't le tme do anyway . Also S3 show Dark Spy DarkSpyKernel.sys, I was on a dark read site which boast that they can tunnel or pentrate any system against any anti spy,mal, trojan etc detection sofware. I may have been playing in their sanbox to see if my computer could be penetrated. fYI
Hi,

Please do the following:


  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:



    c:\windows\system32\aafcebeaff4_g.dll

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


NEXT

Go to Start > Run > type

sc delete TABKB

press enter, then Go to Start > Run > type

sc delete NSLHNZKPEI

press enter



NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.




NEXT


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
I uploaded the file to virus scan and it was clean I executed your next statement TABKB Malwarebytes' Anti-Malware 1.42 Database version: 3450 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 12/29/2009 10:09:52 AM mbam-log-2009-12-29 (10-09-52).txt Scan type: Quick Scan Objects scanned: 135921 Time elapsed: 6 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) I ran Kaspersky an it took 7 hours and everything was clean on Drive C. The report came up empty when I stopped it. I stopped the scan as I have 3 other drives that are TB each and would have probably takne me a week to finish the scan since Drive C was the main Drive with problems. I couldn't specify Drive C only. So hmm I was wondering if it could be something like Conflicker where it hides from most scanning software. Can someone put software on my computer and access the computer remotely without the scanning software detecting it or put software that can change security policies or permissions? I notice when I start firefox, I get a lot of schost.exe files and when I click on processes I notice different number of SID with ? markes on them that give full control. I also have a group called interactive and another everyman with full access. When I start to probe by using whois TCP Viewer will flash red on about ten or so connections and then they will all disappear.
I would say your computer is clean of malware, ComboFix took care of it. Please post a fresh DDS and Attach.txt Did you also delete NSLHNZKPEI as well?
Why is it when, and this is getting way over my head, that when I log into the internet, I have a09-17-148-58.deploy.AKAMAITECHNOLOGIES.COM Cambridge, MA 02142 logged on and connected to me on ports 3116, 3130, 3133, 3134, 3138, 3139? When I look at the TCP/IP under process and highlight them under Security I have Mandatory: Everyone, Local, Interactive and SID s-5-5-0-77779 as groups even though that SID is not in my registry . When I snoop further, all those lines in TCPview flash red and disappear from TCP viewer and my normal connections to comcast are left? Am I being to paranoid? Why are they connected to me? I attach the txt files which the window said I should do instead of pasting it the reply where the whole world can view my programs :blush: Thanks for all your help! :)
Forgot to add: Did you also delete NSLHNZKPEI as well? YES I also attach Avira log file from a 12/12 scan that quarantine, I think, some problems :o
Hi,

The connection issue I can't answer at all, I'm afraid that isn't my area of expertise.

The log isn't showing any more malware on your system.

I suggest we clean up our tools here. Then post a new topic in out Browsers, Internet and email forum and let the expert techs check the connections.

Please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]



NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI