This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

BlueScreenOfDeath

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I hope I am doing this correctly. The topic in which I am dealing with this is here:
http://forums.whatthetech.com/Blue_Screen_…762#entry630762
(for more info on what has been done so far)

I've ran all the programs you said in that "are you infected" thingy… though dds says that it doesn't support my OS (which is XP).

So here is Malwarebyte: … sorry, it is in Finnish. Well, nothing found anyhow. (Haitallisia kohteita ei löydetty = No malware found)

Malwarebytes' Anti-Malware 1.44
Tietokantaversio: 3807
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

28.2.2010 20:49:32
mbam-log-2010-02-28 (20-49-32).txt

Tarkistustyyppi: Pikatarkistus
Tarkistetut kohteet: 118598
Kulunut aika: 16 minute(s), 30 second(s)

Saastuneita muistiprosesseja: 0
Saastuneita muistimoduuleja: 0
Saastuneita rekisteriavaimia: 0
Saastuneita rekisteriarvoja: 0
Saastuneita rekisterikohteita: 0
Saastuneita hakemistoja: 0
Saastuneita tiedostoja: 0

Saastuneita muistiprosesseja:
(Haitallisia kohteita ei löydetty)

Saastuneita muistimoduuleja:
(Haitallisia kohteita ei löydetty)

Saastuneita rekisteriavaimia:
(Haitallisia kohteita ei löydetty)

Saastuneita rekisteriarvoja:
(Haitallisia kohteita ei löydetty)

Saastuneita rekisterikohteita:
(Haitallisia kohteita ei löydetty)

Saastuneita hakemistoja:
(Haitallisia kohteita ei löydetty)

Saastuneita tiedostoja:
(Haitallisia kohteita ei löydetty)



And here's GMER

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-28 21:43:12
Windows 5.1.2600 Service Pack 3
Running: cy6t22e9.exe; Driver: C:\DOCUME~1\KEVING~1\LOCALS~1\Temp\fgpyikod.sys


—- System - GMER 1.0.15 —-

SSDT spjm.sys ZwCreateKey [0xF74E40E0]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwCreateProcess [0xB5E83CD6]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwCreateProcessEx [0xB5E83CF0]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwCreateThread [0xB5E82E8C]
SSDT spjm.sys ZwEnumerateKey [0xF74FCDA4]
SSDT spjm.sys ZwEnumerateValueKey [0xF74FD132]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwLoadDriver [0xB5E831BC]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwMapViewOfSection [0xB5E82BCC]
SSDT spjm.sys ZwOpenKey [0xF74E40C0]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwOpenSection [0xB5E835EE]
SSDT spjm.sys ZwQueryKey [0xF74FD20A]
SSDT spjm.sys ZwQueryValueKey [0xF74FD08A]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwRenameKey [0xB5E8488C]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwSetSystemInformation [0xB5E8343E]
SSDT spjm.sys ZwSetValueKey [0xF74FD29C]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwSuspendProcess [0xB5E82A4C]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwSuspendThread [0xB5E82EC0]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwSystemDebugControl [0xB5E83042]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwTerminateProcess [0xB5E829A6]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwTerminateThread [0xB5E82B06]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwWriteVirtualMemory [0xB5E82F86]

INT 0x63 ? 89591BF8
INT 0x73 ? 8979BBF8
INT 0xB4 ? 89591BF8

Code fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation) IoCreateDevice

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!_abnormal_termination + 108 804E2774 8 Bytes CALL 688B182E
.text ntoskrnl.exe!_abnormal_termination + 169 804E27D5 3 Bytes [CD, 4F, F7]
.text ntoskrnl.exe!_abnormal_termination + 440 804E2AAC 12 Bytes CALL 687CEB66
.text ntoskrnl.exe!_abnormal_termination + 450 804E2ABC 8 Bytes CALL 68793176
PAGE ntoskrnl.exe!IoCreateDevice 8059FA51 5 Bytes JMP BAF41FFA fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
? spjm.sys Määritettyä tiedostoa ei löydy. !
PAGENPNP NDIS.SYS!NdisRegisterProtocol BAF1217F 5 Bytes JMP BAF41E0C fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENPNP NDIS.SYS!NdisOpenAdapter BAF12399 5 Bytes JMP BAF42394 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENPNP NDIS.SYS!NdisCloseAdapter BAF1C642 5 Bytes JMP BAF41F18 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENPNP NDIS.SYS!NdisDeregisterProtocol BAF1C821 5 Bytes JMP BAF421B0 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisReturnPackets BAF1F810 5 Bytes JMP BAF42C0C fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisRequest BAF1F97B 5 Bytes JMP BAF425AC fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisSend BAF22986 5 Bytes JMP BAF4358C fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisSendPackets BAF229A3 5 Bytes JMP BAF4365E fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisTransferData BAF229BE 5 Bytes JMP BAF42D0A fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDCO NDIS.SYS!NdisCoCreateVc BAF29186 5 Bytes JMP BAF41E76 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDCO NDIS.SYS!NdisCoDeleteVc BAF2A557 5 Bytes JMP BAF41EE4 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDCO NDIS.SYS!NdisCoSendPackets BAF2AAF1 5 Bytes JMP BAF43376 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
.text USBPORT.SYS!DllUnload B9B428AC 5 Bytes JMP 895911D8
.text a1oa948f.SYS A9FFC386 35 Bytes [00, 00, 00, 00, 00, 00, 20, …]
.text a1oa948f.SYS A9FFC3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, …]
.text a1oa948f.SYS A9FFC3C4 3 Bytes [00, 80, 02]
.text a1oa948f.SYS A9FFC3C9 1 Byte [30]
.text a1oa948f.SYS A9FFC3C9 11 Bytes [30, 00, 00, 00, 5E, 02, 00, …] {XOR [EAX], AL; ADD [EAX], AL; POP ESI; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text …

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\SearchIndexer.exe[336] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0E36000C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 0E36100C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0E36200C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[336] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 0E36300C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 0E36700C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 0E36500C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 0E36600C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 0E36800C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 0E36400C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 0E36A00C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 0E36900C
.text C:\WINDOWS\system32\winlogon.exe[552] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 010F000C
.text C:\WINDOWS\system32\winlogon.exe[552] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 010F100C
.text C:\WINDOWS\system32\winlogon.exe[552] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 010F200C
.text C:\WINDOWS\system32\winlogon.exe[552] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 010F300C
.text C:\WINDOWS\system32\winlogon.exe[552] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 010F700C
.text C:\WINDOWS\system32\winlogon.exe[552] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 010F500C
.text C:\WINDOWS\system32\winlogon.exe[552] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 010F600C
.text C:\WINDOWS\system32\winlogon.exe[552] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 010F800C
.text C:\WINDOWS\system32\winlogon.exe[552] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 010F400C
.text C:\WINDOWS\system32\winlogon.exe[552] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 010FA00C
.text C:\WINDOWS\system32\winlogon.exe[552] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 010F900C
.text C:\WINDOWS\system32\lsass.exe[608] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00DD000C
.text C:\WINDOWS\system32\lsass.exe[608] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 00DD100C
.text C:\WINDOWS\system32\lsass.exe[608] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00DD200C
.text C:\WINDOWS\system32\lsass.exe[608] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 00DD300C
.text C:\WINDOWS\system32\lsass.exe[608] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 00DD700C
.text C:\WINDOWS\system32\lsass.exe[608] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 00DD500C
.text C:\WINDOWS\system32\lsass.exe[608] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 00DD600C
.text C:\WINDOWS\system32\lsass.exe[608] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 00DD800C
.text C:\WINDOWS\system32\lsass.exe[608] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00DD400C
.text C:\WINDOWS\system32\lsass.exe[608] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 00DDA00C
.text C:\WINDOWS\system32\lsass.exe[608] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 00DD900C
.text C:\WINDOWS\System32\alg.exe[1740] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00B2000C
.text C:\WINDOWS\System32\alg.exe[1740] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 00B2100C
.text C:\WINDOWS\System32\alg.exe[1740] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B2200C
.text C:\WINDOWS\System32\alg.exe[1740] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 00B2300C
.text C:\WINDOWS\System32\alg.exe[1740] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00B2400C
.text C:\WINDOWS\System32\alg.exe[1740] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 00B2A00C
.text C:\WINDOWS\System32\alg.exe[1740] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 00B2700C
.text C:\WINDOWS\System32\alg.exe[1740] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 00B2500C
.text C:\WINDOWS\System32\alg.exe[1740] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 00B2600C
.text C:\WINDOWS\System32\alg.exe[1740] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 00B2800C
.text C:\WINDOWS\System32\alg.exe[1740] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 00B2900C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 003D000C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 003D100C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003D200C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 003D300C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D400C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 003D900C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 003D700C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003D500C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 003D600C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003D800C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 027B000C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 027B100C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 027B200C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 027B300C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 027B400C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 027BA00C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 027B700C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 027B500C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 027B600C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 027B800C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 027B900C
.text C:\WINDOWS\Explorer.EXE[2208] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0294000C
.text C:\WINDOWS\Explorer.EXE[2208] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 0294100C
.text C:\WINDOWS\Explorer.EXE[2208] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0294200C
.text C:\WINDOWS\Explorer.EXE[2208] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 0294300C
.text C:\WINDOWS\Explorer.EXE[2208] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 0294700C
.text C:\WINDOWS\Explorer.EXE[2208] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 0294500C
.text C:\WINDOWS\Explorer.EXE[2208] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 0294600C
.text C:\WINDOWS\Explorer.EXE[2208] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 0294800C
.text C:\WINDOWS\Explorer.EXE[2208] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 0294400C
.text C:\WINDOWS\Explorer.EXE[2208] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 0294A00C
.text C:\WINDOWS\Explorer.EXE[2208] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 0294900C
.text C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE[2364] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00BA000C
.text C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE[2364] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 00BA100C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 003D000C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 003D100C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003D200C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 003D300C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D400C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 003D900C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 003D700C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003D500C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 003D600C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003D800C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 011D000C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 011D100C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 011D200C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 011D300C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 011D400C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 011DA00C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 011D700C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 011D500C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 011D600C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 011D800C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 011D900C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 003D000C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 003D100C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003D200C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 003D300C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D400C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 003D500C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 003D800C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003D600C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 003D700C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003D900C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 03D7000C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 03D7100C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 03D7200C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 03D7300C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 03D7700C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 03D7500C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 03D7600C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 03D7800C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 03D7400C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 03D7A00C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 03D7900C

—- Kernel IAT/EAT - GMER 1.0.15 —-

IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 8979B2D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F750FDDC] spjm.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F750FE30] spjm.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74E5042] spjm.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74E513E] spjm.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74E50C0] spjm.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74E5800] spjm.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74E56D6] spjm.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 895912D8
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlInitUnicodeString] 8800001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!swprintf] 001CBA86
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeSetEvent] C61AEB00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 001C8986
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoGetConfigurationInformation] 86C61200
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 00001C8B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmFreeMappingAddress] 96868801
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 8800001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 001CB286
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmUnmapIoSpace] 88968B00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 8900001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IofCompleteRequest] 001CA496
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlCompareUnicodeString] C6168B00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IofCallDriver] 001CC186
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 428A0A00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] C286880C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoConnectInterrupt] 8B00001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoDetachDevice] 24A48DFA
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeWaitForSingleObject] 00000000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInitializeEvent] 4B8BDF8B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeCancelTimer] 8D3F0304
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] CB033043
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlInitAnsiString] 0673C13B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] C13B0003
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoQueueWorkItem] 8366FA72
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmMapIoSpace] 75000E7B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 0B7D80E3
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoReportDetectedDevice] 307B8D00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoReportResourceForDetection] 00AA840F
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] 83660000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!NlsMbCodePageTag] 6A000E7A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!PoRequestPowerIrp] C6647400
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 001CC386
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 4F8B0200
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!sprintf] 968D5140
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] 00001C98
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ObfDereferenceObject] 22F6E852
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 478B0000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 50016A40
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ZwClose] 1CB48E8D
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] E8510000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] 000022E4
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 6A18538B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 868D5200
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoCreateDevice] 00001CA0
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 22D2E850
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 4B8B0000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlQueryRegistryValues] 51016A18
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ZwOpenKey] 1CBC968D
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlFreeUnicodeString] E8520000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoStartTimer] 000022C0
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInitializeTimer] 8A05478A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoInitializeTimer] 001CC38E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInitializeDpc] 30C48300
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInitializeSpinLock] 1CC58688
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoInitializeIrp] 80E90000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ZwCreateKey] C6000000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 001CC386
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 438B0100
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ZwSetValueKey] 8E8D5018
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInsertQueueDpc] 00001C98
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 2292E851
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoStartPacket] 538B0000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 52016A18
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 1CB4868D
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoFreeMdl] E8500000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmUnlockPages] 00002280
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 8A05478A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 001CC38E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 18C48300
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 1CC58688
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeSynchronizeExecution] 43EB0000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoStartNextPacket] 320C538A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeBugCheckEx] 88F93BC0
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 001CC396
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeSetTimer] F6317300
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!_allmul] 74070647
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmProbeAndLockPages] 75C0841A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!_except_handler3] 05578A0B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!PoSetPowerState] 968801B0
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 00001CC5
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 57B60F66
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlDeleteRegistryValue] 533B6604
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!_aulldiv] 03087408
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!strstr] 72F93B3F
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!_strupr] 8A09EBDA
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeQuerySystemTime] 86880547
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 00001CC5
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeTickCount] 88084B8A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 001CC68E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoDeleteDevice] 40578B00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 8D52006A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAllocateWorkItem] 001CC886
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAllocateIrp] 11E85000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAllocateMdl] 8B000022
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 001CC08E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmLockPagableDataSection] C4968B00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 8900001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 001CCC8E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ExFreePoolWithTag] D0968900
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoFreeIrp] 8B00001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoFreeWorkItem] 016A4047
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!InitSafeBootMode] D4C68150
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlCompareMemory] 5600001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!PoCallDriver] 0021E7E8
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!memmove] 18C48300
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmHighestUserAddress] 5D5B5E5F
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KfAcquireSpinLock] 18C4830E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!READ_PORT_UCHAR] 1C959E88
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KeGetCurrentIrql] 9E880000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KfRaiseIrql] 00001CB1
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KfLowerIrql] 0E798366
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!HalGetInterruptVector] 74AAB000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!HalTranslateBusAddress] 8986C636
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KeStallExecutionProcessor] 1A00001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KfReleaseSpinLock] 1C8B86C6
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] C6020000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!READ_PORT_USHORT] 001C9686
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 86C60200
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!WRITE_PORT_UCHAR] 00001CB2
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[WMILIB.SYS!WmiSystemControl] 8800001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[WMILIB.SYS!WmiCompleteRequest] 001CB99E
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F74F4B90] spjm.sys

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 897971F8
Device \FileSystem\Fastfat \FatCdrom 89110500
Device \FileSystem\Udfs \UdfsCdRom 891D6500
Device \FileSystem\Udfs \UdfsCdRom BsUDF.SYS (UDF File System Driver (WindowsXP)/ahead software)
Device \FileSystem\Udfs \UdfsDisk 891D6500
Device \FileSystem\Udfs \UdfsDisk BsUDF.SYS (UDF File System Driver (WindowsXP)/ahead software)
Device \Driver\Tcpip \Device\Ip fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\usbohci \Device\USBPDO-0 895851F8
Device \Driver\usbohci \Device\USBPDO-1 895851F8
Device \Driver\usbehci \Device\USBPDO-2 894A91F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{C4C513B0-EED9-4AE5-B406-1C19213D4FE0} 892CB500
Device \Driver\PCI_PNP6612 \Device\00000047 spjm.sys
Device \Driver\PCI_PNP6612 \Device\00000047 spjm.sys
Device \Driver\Tcpip \Device\Tcp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\sptd \Device\1111024112 spjm.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 897991F8
Device \Driver\Cdrom \Device\CdRom0 89204500
Device \Driver\Cdrom \Device\CdRom1 89204500
Device \Driver\Cdrom \Device\CdRom2 89204500
Device \Driver\NetBT \Device\NetBt_Wins_Export 892CB500
Device \Driver\NetBT \Device\NetbiosSmb 892CB500
Device \Driver\Tcpip \Device\Udp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\Tcpip \Device\RawIp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\usbohci \Device\USBFDO-0 895851F8
Device \Driver\usbohci \Device\USBFDO-1 895851F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89309500
Device \Driver\Tcpip \Device\IPMULTICAST fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\usbehci \Device\USBFDO-2 894A91F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 89309500
Device \Driver\Ftdisk \Device\FtControl 897991F8
Device \Driver\nvidesm \Device\Scsi\nvidesm1Port0Path0Target0Lun0 897981F8
Device \Driver\a1oa948f \Device\Scsi\a1oa948f1 891F2500
Device \Driver\a1oa948f \Device\Scsi\a1oa948f1Port1Path0Target0Lun0 891F2500
Device \Driver\nvidesm \Device\Scsi\nvidesm1 897981F8
Device \Driver\nvidesm \Device\Scsi\nvidesm1Port0Path1Target1Lun0 897981F8
Device \Driver\nvidesm \Device\Scsi\nvidesm1Port0Path1Target0Lun0 897981F8
Device \FileSystem\Fastfat \Fat 89110500

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs 89333500
Device \FileSystem\Cdfs \Cdfs BsUDF.SYS (UDF File System Driver (WindowsXP)/ahead software)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xEE 0x4B 0x66 0x1C …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF3 0xD0 0x42 0xEB …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3F 0xCE 0xB3 0x3E …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xEE 0x4B 0x66 0x1C …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF3 0xD0 0x42 0xEB …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3F 0xCE 0xB3 0x3E …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{47A0EDF4-C995-E679-2068-E30EF0E60185}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{47A0EDF4-C995-E679-2068-E30EF0E60185}@oagfhdapkeojcikoaacemeihmdokcb 0x64 0x61 0x6A 0x64 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{47A0EDF4-C995-E679-2068-E30EF0E60185}@oakehnoakgldobmknkfilgjnonnhak 0x6B 0x61 0x6A 0x64 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{47A0EDF4-C995-E679-2068-E30EF0E60185}@naefbcnbbnpofjbhbcfbeafmeiin 0x6B 0x61 0x6A 0x64 …

—- EOF - GMER 1.0.15 —-



So.. um.. what now?

Thanks
Hi,

Please do the following:

Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.


NEXT




Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
Ok, so I disabled the drives and now I've got the OTL results as well:

OTL logfile created on: 8.2.2010 21:03:23 - Run 1
OTL by OldTimer - Version 3.1.35.0 Folder = C:\Documents and Settings\Kevin Gibbs\Työpöytä
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 0000040B | Country: Suomi | Language: FIN | Date Format: d.M.yyyy

1,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 69,00% Memory free
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 89,00% Paging File free
Paging file location(s): C:\pagefile.sys 1920 3840 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 114,48 Gb Total Space | 42,16 Gb Free Space | 36,83% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KEVIN-57FA3200B
Current User Name: Kevin Gibbs
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\Kevin Gibbs\Työpöytä\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsav32.exe (F-Secure Corporation)
PRC - C:\Program Files\Elisa Tietoturvapalvelu\FWES\program\fsdfwd.exe (F-Secure Corporation)
PRC - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fssm32.exe (F-Secure Corporation)
PRC - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32.exe (F-Secure Corporation)
PRC - C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe ()
PRC - C:\Program Files\Common Files\Iconix\IconixService.exe ()
PRC - C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Elisa Tietoturvapalvelu\Common\FSHDLL32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe ()
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Program Files\Elisa Tietoturvapalvelu\ORSP Client\fsorsp.exe (F-Secure Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Kevin Gibbs\Työpöytä\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Iconix\OEAddOn\OEldr_6.dll ()
MOD - \\?\c:\program files\elisa tietoturvapalvelu\hips\fshook32.dll ()
MOD - C:\WINDOWS\system32\rsaenh.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (FSDFWD) – C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe (F-Secure Corporation)
SRV - (IconixService) – C:\Program Files\Common Files\Iconix\IconixService.exe ()
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (FSMA) – C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (F-Secure Gatekeeper Handler Starter) – C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
SRV - (DTSRVC) – C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe ()
SRV - (FSORSPClient) – C:\Program Files\Elisa Tietoturvapalvelu\ORSP Client\fsorsp.exe (F-Secure Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 44
FF - prefs.js..extensions.enabledItems: {C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}:2.3.54
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7
FF - prefs.js..extensions.enabledItems: {6133DAA7-C343-9318-6DA3-48218CDE28E2}:3.87.4
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20091028


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.03.01 08:41:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.03.01 08:41:06 | 000,000,000 | —D | M]

[2009.10.14 10:53:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Gibbs\Application Data\Mozilla\Extensions
[2009.10.14 10:53:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Gibbs\Application Data\Mozilla\Extensions\[removed]
[2010.03.01 08:50:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Gibbs\Application Data\Mozilla\Firefox\Profiles\59cbfsek.default\extensions
[2009.11.06 19:56:27 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Kevin Gibbs\Application Data\Mozilla\Firefox\Profiles\59cbfsek.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010.01.16 19:18:07 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\Kevin Gibbs\Application Data\Mozilla\Firefox\Profiles\59cbfsek.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010.02.11 08:25:41 | 000,000,000 | —D | M] (Answers) – C:\Documents and Settings\Kevin Gibbs\Application Data\Mozilla\Firefox\Profiles\59cbfsek.default\extensions\{C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}
[2010.01.11 22:20:21 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Kevin Gibbs\Application Data\Mozilla\Firefox\Profiles\59cbfsek.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009.09.29 08:30:25 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Kevin Gibbs\Application Data\Mozilla\Firefox\Profiles\59cbfsek.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010.03.01 08:50:14 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009.11.18 21:26:03 | 000,000,000 | —D | M] (Iconix) – C:\Program Files\Mozilla Firefox\extensions\{6133DAA7-C343-9318-6DA3-48218CDE28E2}
[2009.11.08 18:36:38 | 000,195,928 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npIconixProxy35.dll
[2010.01.14 00:46:00 | 000,063,488 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2009.08.24 21:27:58 | 000,002,062 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bookplus-fi.xml
[2009.08.24 21:27:58 | 000,001,069 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\creativecommons-fi.xml
[2009.08.24 21:27:58 | 000,002,677 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\huuto-fi.xml
[2009.08.24 21:27:58 | 000,001,183 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-fi.xml
[2009.08.24 21:27:58 | 000,000,796 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-fi.xml

O1 HOSTS File: ([2004.09.15 14:00:00 | 000,000,665 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (IconixBHOClass Class) - {761233B6-F228-49E4-8F6B-668499D4E55A} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - HKLM..\Run: [F-Secure Manager] C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure TNB] C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\TNBUtil.exe (F-Secure Corporation)
O4 - HKLM..\Run: [IconixOEAddOn] C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe ()
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [MP10_EnsureFileVer] C:\WINDOWS\inf\unregmp2.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Email ID Preferences - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll ()
O9 - Extra 'Tools' menuitem : About Email ID - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Elisa Tietoturvapalvelu\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Elisa Tietoturvapalvelu\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Elisa Tietoturvapalvelu\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Elisa Tietoturvapalvelu\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1254169642218 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Nykyinen kotisivu) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Kevin Gibbs\Application Data\Mozilla\Firefox\Työpöydän taustakuva.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kevin Gibbs\Application Data\Mozilla\Firefox\Työpöydän taustakuva.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.09.28 20:30:10 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{42d2f942-ac74-11de-9bbb-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{42d2f942-ac74-11de-9bbb-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009.09.28 22:17:24 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (58550188179980288)

========== Files/Folders - Created Within 14 Days ==========

[2010.03.01 09:40:20 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Kevin Gibbs\Recent
[2010.03.01 08:41:06 | 000,000,000 | —D | C] – C:\Program Files\Winamp Detect
[2010.02.28 20:30:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Kevin Gibbs\Application Data\Malwarebytes
[2010.02.28 20:30:02 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.02.28 20:30:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010.02.28 20:29:59 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010.02.28 20:29:59 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010.02.28 20:29:10 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010.02.28 20:28:45 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010.02.28 19:01:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death
[2010.02.28 11:58:14 | 000,038,422 | —- | C] (Generic) – C:\WINDOWS\System32\drivers\StMp3Rec.sys
[2010.02.26 22:47:25 | 000,000,000 | R–D | C] – C:\Documents and Settings\Kevin Gibbs\Omat tiedostot\Omat videotiedostot
[2010.02.26 22:47:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DivX Shared
[2010.02.26 22:47:25 | 000,000,000 | —D | C] – C:\Program Files\DivX
[2010.02.26 21:24:10 | 000,000,000 | —D | C] – C:\Program Files\Speccy
[2010.02.25 21:48:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Kevin Gibbs\Application Data\vlc
[2010.02.13 19:03:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Kevin Gibbs\Työpöytä\ulkoinen kovo
[2010.02.13 10:51:19 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010.02.10 22:38:28 | 000,000,000 | —D | C] – C:\Program Files\Windows Live Safety Center
[2010.02.10 22:26:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Kevin Gibbs\Työpöytä\For Tatjaana
[2010.02.10 22:20:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Kevin Gibbs\Local Settings\Application Data\DOSBox
[2010.02.10 10:04:11 | 000,023,456 | —- | C] (Phoenix Technologies) – C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2010.02.10 10:04:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Kevin Gibbs\Local Settings\Application Data\eSupport.com
[2010.02.08 21:02:03 | 000,554,496 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Kevin Gibbs\Työpöytä\OTL.exe
[2010.02.01 21:25:05 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2010.01.28 23:47:25 | 000,000,000 | —D | C] – C:\Program Files\Lavalys
[2010.01.26 20:33:20 | 000,000,000 | —D | C] – C:\Program Files\StepMania
[2010.01.26 14:26:00 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2009.12.28 07:47:14 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2009.10.18 09:35:41 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009.09.28 22:31:50 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\F-Secure
[2009.09.28 20:33:03 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009.09.28 20:30:02 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft

========== Files - Modified Within 14 Days ==========

[2010.03.01 08:41:07 | 000,000,654 | —- | M] () – C:\Documents and Settings\All Users\Työpöytä\Winamp.lnk
[2010.02.28 20:30:05 | 000,000,714 | —- | M] () – C:\Documents and Settings\All Users\Työpöytä\Malwarebytes' Anti-Malware.lnk
[2010.02.28 20:28:48 | 000,000,611 | —- | M] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\NTREGOPT.lnk
[2010.02.28 20:28:48 | 000,000,592 | —- | M] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\ERUNT.lnk
[2010.02.28 11:58:15 | 000,000,822 | —- | M] () – C:\Documents and Settings\All Users\Työpöytä\MP3 Player Recovery Tool.lnk
[2010.02.27 21:37:15 | 000,000,731 | —- | M] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\Pikakuvake msnmsgr.lnk
[2010.02.26 23:26:19 | 000,000,637 | —- | M] () – C:\WINDOWS\win.ini
[2010.02.26 23:26:19 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010.02.26 23:26:19 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010.02.26 22:48:05 | 000,000,799 | —- | M] () – C:\Documents and Settings\All Users\Työpöytä\DivX Player.lnk
[2010.02.26 22:47:56 | 000,000,843 | —- | M] () – C:\Documents and Settings\All Users\Työpöytä\DivX Converter.lnk
[2010.02.26 22:47:25 | 000,001,555 | —- | M] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\DivX Movies.lnk
[2010.02.26 21:24:11 | 000,001,512 | —- | M] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\Speccy.lnk
[2010.02.26 21:24:00 | 000,001,580 | —- | M] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\Defraggler.lnk
[2010.02.25 17:44:40 | 000,000,719 | —- | M] () – C:\Documents and Settings\All Users\Työpöytä\VLC media player.lnk
[2010.02.24 20:46:51 | 000,019,456 | —- | M] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\Death note with dad.doc
[2010.02.17 19:50:54 | 002,772,576 | —- | M] () – C:\Documents and Settings\Kevin Gibbs\Omat tiedostot\FreeHi-Q 17-2-2010_19;47;02.mp3
[2010.02.13 17:30:30 | 000,000,302 | —- | M] () – C:\WINDOWS\tasks\Defraggler Volume C Task.job
[2010.02.13 10:51:37 | 000,000,375 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2010.02.12 23:13:26 | 000,000,692 | —- | M] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\WinRAR.lnk
[2010.02.11 22:08:59 | 003,358,672 | -H– | M] () – C:\Documents and Settings\Kevin Gibbs\Local Settings\Application Data\IconCache.db
[2010.02.10 10:04:11 | 000,023,456 | —- | M] (Phoenix Technologies) – C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2010.02.10 09:48:07 | 000,142,336 | —- | M] () – C:\Documents and Settings\Kevin Gibbs\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.02.08 21:02:07 | 000,554,496 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kevin Gibbs\Työpöytä\OTL.exe
[2010.02.08 20:59:13 | 000,013,686 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010.02.08 20:59:10 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010.02.08 20:59:08 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010.02.08 20:59:06 | 1341,706,240 | -HS- | M] () – C:\hiberfil.sys
[2010.02.08 20:58:30 | 005,242,880 | -H– | M] () – C:\Documents and Settings\Kevin Gibbs\NTUSER.DAT
[2010.02.08 20:58:27 | 000,000,188 | -HS- | M] () – C:\Documents and Settings\Kevin Gibbs\ntuser.ini
[2010.02.08 20:58:11 | 000,000,020 | —- | M] () – C:\Documents and Settings\Kevin Gibbs\defogger_reenable
[2010.02.08 20:57:44 | 000,050,477 | —- | M] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\Defogger.exe
[2010.02.08 20:13:21 | 000,000,532 | —- | M] () – C:\WINDOWS\tasks\Scheduled scanning task.job
[2010.01.30 09:39:07 | 000,033,920 | —- | M] () – C:\WINDOWS\System32\drivers\fsbts.sys
[2010.01.30 09:38:31 | 000,001,985 | —- | M] () – C:\Documents and Settings\All Users\Työpöytä\Elisa Tietoturvapalvelu.lnk
[2010.01.28 23:47:30 | 000,000,779 | —- | M] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\EVEREST Home Edition.lnk
[2010.01.27 18:59:15 | 000,111,104 | —- | M] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\ruokapaivakirja3pv.xls
[2010.01.26 20:33:40 | 000,000,778 | —- | M] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\Play StepMania 3.9.lnk
[2010.01.26 14:26:40 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Työpöytä\Adobe Reader 9.lnk

========== Files Created - No Company Name ==========

[2010.02.28 20:30:05 | 000,000,714 | —- | C] () – C:\Documents and Settings\All Users\Työpöytä\Malwarebytes' Anti-Malware.lnk
[2010.02.28 20:28:48 | 000,000,611 | —- | C] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\NTREGOPT.lnk
[2010.02.28 20:28:48 | 000,000,592 | —- | C] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\ERUNT.lnk
[2010.02.28 11:58:15 | 000,000,822 | —- | C] () – C:\Documents and Settings\All Users\Työpöytä\MP3 Player Recovery Tool.lnk
[2010.02.27 21:37:15 | 000,000,731 | —- | C] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\Pikakuvake msnmsgr.lnk
[2010.02.26 22:48:05 | 000,000,799 | —- | C] () – C:\Documents and Settings\All Users\Työpöytä\DivX Player.lnk
[2010.02.26 22:47:56 | 000,000,843 | —- | C] () – C:\Documents and Settings\All Users\Työpöytä\DivX Converter.lnk
[2010.02.26 22:47:25 | 000,001,555 | —- | C] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\DivX Movies.lnk
[2010.02.26 21:24:11 | 000,001,512 | —- | C] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\Speccy.lnk
[2010.02.25 17:44:40 | 000,000,719 | —- | C] () – C:\Documents and Settings\All Users\Työpöytä\VLC media player.lnk
[2010.02.23 09:29:33 | 000,019,456 | —- | C] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\Death note with dad.doc
[2010.02.17 20:04:50 | 002,772,576 | —- | C] () – C:\Documents and Settings\Kevin Gibbs\Omat tiedostot\FreeHi-Q 17-2-2010_19;47;02.mp3
[2010.02.17 19:13:45 | 1341,706,240 | -HS- | C] () – C:\hiberfil.sys
[2010.02.08 20:58:03 | 000,000,020 | —- | C] () – C:\Documents and Settings\Kevin Gibbs\defogger_reenable
[2010.02.08 20:57:43 | 000,050,477 | —- | C] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\Defogger.exe
[2010.01.30 09:38:31 | 000,001,985 | —- | C] () – C:\Documents and Settings\All Users\Työpöytä\Elisa Tietoturvapalvelu.lnk
[2010.01.28 23:47:30 | 000,000,779 | —- | C] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\EVEREST Home Edition.lnk
[2010.01.27 18:59:14 | 000,111,104 | —- | C] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\ruokapaivakirja3pv.xls
[2010.01.26 20:33:40 | 000,000,778 | —- | C] () – C:\Documents and Settings\Kevin Gibbs\Työpöytä\Play StepMania 3.9.lnk
[2010.01.26 14:26:40 | 000,001,729 | —- | C] () – C:\Documents and Settings\All Users\Työpöytä\Adobe Reader 9.lnk
[2009.11.12 10:49:49 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\Machnm32.sys
[2009.10.02 18:14:45 | 000,142,336 | —- | C] () – C:\Documents and Settings\Kevin Gibbs\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.09.29 09:57:23 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2009.09.29 09:34:51 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\WINKRNME.DLL
[2009.09.29 09:06:33 | 000,000,092 | —- | C] () – C:\WINDOWS\CMISETUP.INI
[2009.09.29 09:06:33 | 000,000,026 | —- | C] () – C:\WINDOWS\CMCDPLAY.INI
[2009.09.29 09:06:32 | 000,000,000 | —- | C] () – C:\WINDOWS\Wininit.ini
[2009.09.29 09:06:22 | 000,028,672 | —- | C] () – C:\WINDOWS\CMIRmDriver.dll
[2009.09.28 22:31:44 | 000,033,920 | —- | C] () – C:\WINDOWS\System32\drivers\fsbts.sys
[2009.09.28 22:00:23 | 000,000,134 | —- | C] () – C:\Documents and Settings\Kevin Gibbs\Local Settings\Application Data\fusioncache.dat
[2009.09.28 20:42:04 | 000,000,413 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008.05.26 21:23:08 | 000,015,486 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2008.05.26 21:23:06 | 000,022,466 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2008.05.26 21:23:04 | 000,015,260 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2003.02.19 00:26:28 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\cmirmdrv.dll
[1999.01.22 19:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1997.06.14 02:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll

========== LOP Check ==========

[2009.12.24 03:33:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009.09.28 22:31:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\f-secure
[2010.01.30 09:34:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fssg
[2009.11.18 21:26:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Iconix
[2009.12.27 20:29:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Gibbs\Application Data\ACAMPREF
[2010.02.28 22:15:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Gibbs\Application Data\BitTorrent
[2009.11.17 19:34:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Gibbs\Application Data\Broad Intelligence
[2009.12.24 20:04:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Gibbs\Application Data\DAEMON Tools Lite
[2009.11.12 10:54:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Gibbs\Application Data\DisplayTune
[2009.09.28 22:33:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Gibbs\Application Data\F-Secure
[2009.11.18 21:27:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Gibbs\Application Data\Iconix
[2009.11.08 13:16:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Gibbs\Application Data\LimeWire
[2009.09.29 17:45:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Gibbs\Application Data\uk.co.planetside
[2009.11.18 21:31:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Gibbs\Application Data\VSRevoGroup
[2009.09.28 21:44:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Gibbs\Application Data\Windows Desktop Search
[2009.09.29 09:17:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Gibbs\Application Data\Windows Search
[2010.02.13 17:30:30 | 000,000,302 | —- | M] () – C:\WINDOWS\Tasks\Defraggler Volume C Task.job
[2010.02.08 20:13:21 | 000,000,532 | —- | M] () – C:\WINDOWS\Tasks\Scheduled scanning task.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004.09.15 14:00:00 | 018,779,439 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009.09.28 21:07:42 | 023,885,539 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009.09.28 21:07:42 | 023,885,539 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 20:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004.09.15 14:00:00 | 018,779,439 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009.09.28 21:07:42 | 023,885,539 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009.09.28 21:07:42 | 023,885,539 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys
[2004.09.15 14:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2004.09.15 14:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=AEF44005EC0C17304B396D4FBAD1E567 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2008.04.14 18:11:34 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=CC101870D9108EFFB0DF2E408486F6B1 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 18:11:34 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=CC101870D9108EFFB0DF2E408486F6B1 – C:\WINDOWS\system32\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2004.09.15 14:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1FFF6E56C4E35EE694DCC8AF71097E42 – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 18:11:42 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=69D4744656BF74FBECA8A542CD46958C – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 18:11:42 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=69D4744656BF74FBECA8A542CD46958C – C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2008.04.14 18:11:45 | 000,183,808 | —- | M] (Microsoft Corporation) MD5=0828E43B78DCE1AA046D50B1BF93EEAB – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 18:11:45 | 000,183,808 | —- | M] (Microsoft Corporation) MD5=0828E43B78DCE1AA046D50B1BF93EEAB – C:\WINDOWS\system32\scecli.dll
[2004.09.15 14:00:00 | 000,182,784 | —- | M] (Microsoft Corporation) MD5=95D104AB056C21BEA3994E1B6F4288BA – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009.09.28 22:21:53 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009.09.28 22:21:53 | 000,638,976 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009.09.28 22:21:53 | 000,430,080 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< End of report >



OTL Extras logfile created on: 8.2.2010 21:03:23 - Run 1
OTL by OldTimer - Version 3.1.35.0 Folder = C:\Documents and Settings\Kevin Gibbs\Työpöytä
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 0000040B | Country: Suomi | Language: FIN | Date Format: d.M.yyyy

1,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 69,00% Memory free
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 89,00% Paging File free
Paging file location(s): C:\pagefile.sys 1920 3840 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 114,48 Gb Total Space | 42,16 Gb Free Space | 36,83% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KEVIN-57FA3200B
Current User Name: Kevin Gibbs
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"6881:TCP" = 6881:TCP:*:Enabled:Bittorrent download
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam – (Valve Corporation)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – File not found
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – File not found
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001040B-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Professional
"{0217E1D1-BCEF-4A61-AF6D-F7740F65A066}" = Pivot Software
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0DEA342C-15CB-4F52-97B6-06A9C4B9C06F}" = SDK
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1883A84D-94AA-432C-9519-FA31B6B118B9}" = forteManager
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1B2DBF55-05D4-4072-87D8-689141E262BD}" = Creative ZEN
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Liven lataustyökalu
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 17
"{350C940b-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{4538A1AF-6894-4F10-ABDA-6CB9E6ACF8B6}" = Microsoft .NET Framework 1.1 Finnish Language Pack
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{85EB1E72-4FAA-40E4-A511-DF3A9A0A4CA8}" = Windows Live Messenger
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{998152E5-B605-4BBB-9853-E749AEE02B21}" = Windows Liven kirjautumisavustaja
"{9C87F6BB-75E4-4F35-8353-F5E295264E98}" = Windows Live Call
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4D7B764-4140-11D4-88EB-0050DA3579C0}" = Nero - Burning Rom
"{A5E9A73E-8FC0-387D-9CCE-8BAA6B042872}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FIN
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AA2BCB44-B44F-445A-A80C-E6C50218940C}" = Windows Liven asennustyökalu
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCEB53A5-A252-4CF3-8602-429AB06BF0AE}" = Terragen
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E2903F16-9A5A-4292-9D97-8328088086B6}" = forteManager
"{E2E7A0E8-77C4-495F-8FA3-63DAEDAA2DB3}" = F-Secure PSC Prerequisites
"{E369A040-E812-37B3-A5B9-311E5579FAC3}" = Microsoft .NET Framework 3.5 Language Pack SP1 - fin
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{FC97690A-90AD-3A67-BE73-50886A93CFF5}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FIN
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"All ATI Software" = ATI-ohjelmiston poisto-ohjelma
"AudibleManager" = AudibleManager
"BitTorrent" = BitTorrent
"CCleaner" = CCleaner
"C-Media Audio" = C-Media 3D Audio
"C-Media Audio Driver" = C-Media WDM Audio Driver
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2009-09-09
"Defraggler" = Defraggler
"Direct MIDI to MP3 Converter_is1" = Direct MIDI to MP3 Converter version 6.1.1.34
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DriverAgent.exe" = DriverAgent by eSupport.com
"ERUNT_is1" = ERUNT 1.1j
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"Fallout" = Fallout
"Fallout Tactics" = Fallout Tactics
"Fallout Tactics_is1" = Fallout Tactics
"FREE Hi-Q Recorder_is1" = FREE Hi-Q Recorder 1.9
"F-Secure Product 277" = Elisa Tietoturvapalvelu
"Harmony Assistant" = Harmony Assistant
"Iconix eMail ID" = Iconix® eMail ID
"InCD!UninstallKey" = InCD (Ahead Software)
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaShow" = Medi@Show
"Melody Assistant" = Melody Assistant
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - fin" = Microsoft .NET Framework 3.5 SP1:n kielitukipaketti - FI
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.8)" = Mozilla Firefox (3.5.8)
"MP3 Player Recovery Tool_is1" = MP3 Player Recovery Tool
"Revo Uninstaller" = Revo Uninstaller 1.85
"Speccy" = Speccy
"Steam App 12900" = Audiosurf
"StepMania" = StepMania (remove only)
"SysInfo" = Creative System Information
"Task Killer" = Task Killer (remove only)
"Winamp" = Winamp
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Liven asennustyökalu
"WinRAR archiver" = WinRAR archiver
"VLC media player" = VLC media player 1.0.5
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"XULPlayer" = XULPlayer 0.6.0
"ZENcast Organizer" = ZENcast Organizer

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11.2.2010 6:56:33 | Computer Name = KEVIN-57FA3200B | Source = Windows Search Service | ID = 3013
Description = Hajautuskartan merkintää
ei voi päivittää. Konteksti: Sovellus , luettelo SystemIndex Lisätietoja: Järjestelmään
kytketty laite ei toimi. (0x8007001f)

Error - 19.2.2010 4:38:58 | Computer Name = KEVIN-57FA3200B | Source = Windows Search Service | ID = 3013
Description = Hajautuskartan merkintää
ei voi päivittää. Konteksti: Sovellus , luettelo SystemIndex Lisätietoja: Järjestelmään
kytketty laite ei toimi. (0x8007001f)

Error - 26.2.2010 3:15:47 | Computer Name = KEVIN-57FA3200B | Source = Windows Search Service | ID = 3013
Description = Hajautuskartan merkintää
ei voi päivittää. Konteksti: Sovellus , luettelo SystemIndex Lisätietoja: Järjestelmään
kytketty laite ei toimi. (0x8007001f)

Error - 26.2.2010 3:16:07 | Computer Name = KEVIN-57FA3200B | Source = Windows Search Service | ID = 3013
Description = Hajautuskartan merkintää
ei voi päivittää. Konteksti: Sovellus , luettelo SystemIndex Lisätietoja: Järjestelmään
kytketty laite ei toimi. (0x8007001f)

Error - 26.2.2010 17:23:01 | Computer Name = KEVIN-57FA3200B | Source = F-Secure Management Agent | ID = 103
Description = 1 2010-02-26 23:23:01+03:00 kevin-57fa3200b KEVIN-57FA3200B\Kevin
Gibbs F-Secure Management Agent The incremental policy file (policy.ipf) was corrupted
and a backup copy of it was successfully taken into use. Some local settings or
statistics may have been lost.

Error - 27.2.2010 16:48:01 | Computer Name = KEVIN-57FA3200B | Source = Windows Search Service | ID = 3013
Description = Hajautuskartan merkintää
ei voi päivittää. Konteksti: Sovellus , luettelo SystemIndex Lisätietoja: Järjestelmään
kytketty laite ei toimi. (0x8007001f)

Error - 28.2.2010 6:00:21 | Computer Name = KEVIN-57FA3200B | Source = Application Error | ID = 1000
Description = Virhesovellus redbutton.exe, versio 2.0.0.5, moduuli kernel32.dll,
versio 5.1.2600.5781, osoite 0x00012afb.

Error - 28.2.2010 15:44:58 | Computer Name = KEVIN-57FA3200B | Source = Application Error | ID = 1000
Description = Virhesovellus find.exe, versio 5.1.2600.0, moduuli unknown, versio
0.0.0.0, osoite 0x7ffa0000.

Error - 28.2.2010 15:45:04 | Computer Name = KEVIN-57FA3200B | Source = Application Error | ID = 1000
Description = Virhesovellus find.exe, versio 5.1.2600.0, moduuli unknown, versio
0.0.0.0, osoite 0x7ffa0000.

Error - 28.2.2010 15:45:06 | Computer Name = KEVIN-57FA3200B | Source = Application Error | ID = 1000
Description = Virhesovellus find.exe, versio 5.1.2600.0, moduuli unknown, versio
0.0.0.0, osoite 0x7ffa0000.

[ System Events ]
Error - 28.2.2010 14:25:44 | Computer Name = KEVIN-57FA3200B | Source = BROWSER | ID = 8009
Description = Selaaja ei voinut ylentää itseään pääselaajaksi. Tällä hetkellä itsensä
pääselaajaksi tunnistava kone on ROBIN-PC.

Error - 28.2.2010 14:27:37 | Computer Name = KEVIN-57FA3200B | Source = NetBT | ID = 4321
Description = Nimeä MSHOME :1d ei voi rekisteröidä liittymään, jonka IP-osoite
on 10.0.0.3. Laite, jonka IP-osoite on 10.0.0.4, ei salli nimen käyttöönottoa.

Error - 28.2.2010 14:32:47 | Computer Name = KEVIN-57FA3200B | Source = NetBT | ID = 4321
Description = Nimeä MSHOME :1d ei voi rekisteröidä liittymään, jonka IP-osoite
on 10.0.0.3. Laite, jonka IP-osoite on 10.0.0.4, ei salli nimen käyttöönottoa.

Error - 28.2.2010 14:37:57 | Computer Name = KEVIN-57FA3200B | Source = NetBT | ID = 4321
Description = Nimeä MSHOME :1d ei voi rekisteröidä liittymään, jonka IP-osoite
on 10.0.0.3. Laite, jonka IP-osoite on 10.0.0.4, ei salli nimen käyttöönottoa.

Error - 28.2.2010 14:39:50 | Computer Name = KEVIN-57FA3200B | Source = NetBT | ID = 4321
Description = Nimeä MSHOME :1d ei voi rekisteröidä liittymään, jonka IP-osoite
on 10.0.0.3. Laite, jonka IP-osoite on 10.0.0.4, ei salli nimen käyttöönottoa.

Error - 28.2.2010 14:45:00 | Computer Name = KEVIN-57FA3200B | Source = NetBT | ID = 4321
Description = Nimeä MSHOME :1d ei voi rekisteröidä liittymään, jonka IP-osoite
on 10.0.0.3. Laite, jonka IP-osoite on 10.0.0.4, ei salli nimen käyttöönottoa.

Error - 28.2.2010 14:50:10 | Computer Name = KEVIN-57FA3200B | Source = NetBT | ID = 4321
Description = Nimeä MSHOME :1d ei voi rekisteröidä liittymään, jonka IP-osoite
on 10.0.0.3. Laite, jonka IP-osoite on 10.0.0.4, ei salli nimen käyttöönottoa.

Error - 28.2.2010 14:52:05 | Computer Name = KEVIN-57FA3200B | Source = NetBT | ID = 4321
Description = Nimeä MSHOME :1d ei voi rekisteröidä liittymään, jonka IP-osoite
on 10.0.0.3. Laite, jonka IP-osoite on 10.0.0.4, ei salli nimen käyttöönottoa.

Error - 8.2.2010 14:13:12 | Computer Name = KEVIN-57FA3200B | Source = NetBT | ID = 4321
Description = Nimeä MSHOME :1d ei voi rekisteröidä liittymään, jonka IP-osoite
on 10.0.0.3. Laite, jonka IP-osoite on 10.0.0.4, ei salli nimen käyttöönottoa.

Error - 8.2.2010 14:15:03 | Computer Name = KEVIN-57FA3200B | Source = NetBT | ID = 4321
Description = Nimeä MSHOME :1d ei voi rekisteröidä liittymään, jonka IP-osoite
on 10.0.0.3. Laite, jonka IP-osoite on 10.0.0.4, ei salli nimen käyttöönottoa.


< End of report >


Umm.. how are you to understand this when it comes in finnish?

Thanks, though :D So, what's next?
You know, there is one thing I don't like about this: lots of my personal information might be apparent here without me realizing it, such as what's my name and what files I have on my computer… so, I don't really feel very comfortable with this.
Hi,

you can edit your threads and attach the logs if you wish, having a name is not something anyone can do anything with, there is nothing publicly listed that can lead directly to you.

how are you to understand this when it comes in finnish?

the format is the same regardless of language and Google is my friend :D


There are no obvious signs of malware, but let's do a scan in case anything is hiding:
make sure fsecure is disabled, while the scan runs.

Please do the following:

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan.
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
The scan is done and there was not a single thing in the report. I don't mean that there was nothing wrong, I mean there was NOTHING in the report. But it also showed before pushing "view report" that nothing was infected.
Okay, it will sometimes show an empty log if there were no infections identified. I don't see any indication of malware in your log and the Kaspersky scan appears to confirm that. What symptoms are you still experiencing? Please try and explain in as much detail as possible
OK

reenable your sptd drivers and clean up OTL

go back to the other topic

this is not malware related


see if they can continue from here


To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.
Your Emulation drivers are now re-enabled.


NEXT



Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
I'm not certain, obviously there is some conflicts there or perhaps failing sectors of your harddrive. Hopefully our expert techs will be able to resolve the matter for you good luck.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI