This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan i just can't remove!

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hiya, first off, i'm usually proficient enough to A) Avoid trojan infection in the first place and B ) Remove it when i do get infected.
But this sucker i'm infected with is just beyond me. Its obviously some sort of trojan which goes and installs things in the background. I've attempted to remove it several times now, but all i've managed to do is remove the software its installed (VIRUSBURSTER being the latest). I don't know what the name of the trojan is or how it works so i have no where to really start.
I've intentionally left a process called update.exe running as i'm sure thats the trojan, problem is it seems there are quite a few applications and other virus/trojans that use the same process name, so i don't know which sucker it is.
Anyway, i've done a Hijackthis log, maybe you can find something i've missed:

Logfile of HijackThis v1.99.1
Scan saved at 2:52:31 PM, on 16/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PCCTLCOM.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\{98B7A8CB-096C-1033-0623-05071505003d}\Update.exe
C:\Documents and Settings\scottrichmond\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = melbourne.cache.telstra.net:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O2 - BHO: (no name) - {59900857-4D71-782E-2CD8-06375AC562C8} - C:\WINDOWS\system32\gvbhhnk.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {F18F04B0-9CF1-4b93-B004-77A288BEE28B} - C:\WINDOWS\system32\afdfhjfc.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [bcgxzgn.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\bcgxzgn.dll,kzenukf
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1098175036125
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: wineil32 - C:\WINDOWS\SYSTEM32\wineil32.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

Hello DJDD and Welcome to TomCoyote,

Please do the following:

STEP 1.
======
Combofix
  • Download this file - combofix.exe
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

STEP 2.
======
GMER
Please create a new subfolder in the Program Files folder called GMER. If you have an older version of GMER installed, you must delete it.
  • Download GMER and extract it to the C:\program files\GMER folder.
  • Run the Gmer.exe program by double-clicking the executable file (gmer.exe) in Windows Explorer.
    You may be prompted to scan immediately if GMER detects rootkit activity.
  • If you are prompted to scan your system click "yes" to begin the scan.
  • If you are not prompted, Click the "Rootkit" tab, then click "Scan".
At the end of the scan, click "Copy" to copy the scan results to the clipboard. Then paste the results in a notepad file and also paste them back in a reply here.

Please reply with the log from ComboFix and GMER
Combofix.exe Log:
Unfortunately i exited out of the log as i was under the impression the log would be saved on the desktop (where i put the executable), if you could tell me where it stores the log (if at all) i can post it. :unsure:
If not, well it did do a disinfection, though i couldn't tell you exactly what it found.

MGER 1.0.11 Log:
GMER 1.0.11.11390 - http://www.gmer.net
Rootkit 2006-11-17 11:33:42
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.11 —-

SSDT sptd.sys ZwCreateKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT sptd.sys ZwOpenKey
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT sptd.sys ZwSetValueKey

INT 0x06 \??\C:\WINDOWS\system32\drivers\Haspnt.sys AE19116D
INT 0x0E \??\C:\WINDOWS\system32\drivers\Haspnt.sys AE190FC2

—- Devices - GMER 1.0.11 —-

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 8A6CE1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 8A6CE1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLOSE 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_WRITE 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_INFORMATION 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_EA 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_EA 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FLUSH_BUFFERS 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP 89FCD1D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP 89FCD1D8
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_CREATE 8A0311D8
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_CLOSE 8A0311D8
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 8A0311D8
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A0311D8
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_POWER 8A0311D8
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 8A0311D8
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_PNP 8A0311D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 8A66A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 8A66A1D8
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_CREATE 8A0251D8
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_CLOSE 8A0251D8
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 8A0251D8
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A0251D8
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_POWER 8A0251D8
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 8A0251D8
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_PNP 8A0251D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 8A6D11D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 89F881D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 89F881D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 89F881D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 89F881D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 89F881D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 89F881D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89F881D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 89F881D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 89F881D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 89F881D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 89F881D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_READ 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_WRITE 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_FLUSH_BUFFERS 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DEVICE_CONTROL 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SHUTDOWN 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CLEANUP 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_POWER 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SYSTEM_CONTROL 8A6D11D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_PNP 8A6D11D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 89F881D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 89F881D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 89F881D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 89F881D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 89F881D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 89F881D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89F881D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 89F881D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 89F881D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 89F881D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 89F881D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CLOSE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_POWER 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SYSTEM_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_PNP 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CREATE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CLOSE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_POWER 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SYSTEM_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_PNP 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CREATE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CLOSE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_POWER 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SYSTEM_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_PNP 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CREATE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CLOSE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_POWER 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SYSTEM_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_PNP 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort4 IRP_MJ_CREATE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort4 IRP_MJ_CLOSE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort4 IRP_MJ_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort4 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort4 IRP_MJ_POWER 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort4 IRP_MJ_SYSTEM_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort4 IRP_MJ_PNP 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort5 IRP_MJ_CREATE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort5 IRP_MJ_CLOSE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort5 IRP_MJ_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort5 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort5 IRP_MJ_POWER 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort5 IRP_MJ_SYSTEM_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdePort5 IRP_MJ_PNP 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1f IRP_MJ_CREATE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1f IRP_MJ_CLOSE 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1f IRP_MJ_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1f IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1f IRP_MJ_POWER 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1f IRP_MJ_SYSTEM_CONTROL 8A6D01D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1f IRP_MJ_PNP 8A6D01D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 89F881D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 89F881D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 89F881D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 89F881D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 89F881D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 89F881D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 89F881D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 89F881D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 89F881D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 89F881D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 89F881D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 895FC1D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 895FC1D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 895FC1D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 895FC1D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 895FC1D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 895FC1D8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 895FC1D8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 895FC1D8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 895FC1D8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 895FC1D8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 895FC1D8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 895FC1D8
Device \Driver\00000029 \Device\0000004e IRP_MJ_POWER [BA6ECDB6] sptd.sys
Device \Driver\00000029 \Device\0000004e IRP_MJ_SYSTEM_CONTROL [BA70273C] sptd.sys
Device \Driver\00000029 \Device\0000004e IRP_MJ_PNP [BA6FB77E] sptd.sys
Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_CREATE 8A0311D8
Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_CLOSE 8A0311D8
Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_DEVICE_CONTROL 8A0311D8
Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A0311D8
Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_POWER 8A0311D8
Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_SYSTEM_CONTROL 8A0311D8
Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_PNP 8A0311D8
Device \Driver\usbehci \Device\USBFDO-1 IRP_MJ_CREATE 8A0251D8
Device \Driver\usbehci \Device\USBFDO-1 IRP_MJ_CLOSE 8A0251D8
Device \Driver\usbehci \Device\USBFDO-1 IRP_MJ_DEVICE_CONTROL 8A0251D8
Device \Driver\usbehci \Device\USBFDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A0251D8
Device \Driver\usbehci \Device\USBFDO-1 IRP_MJ_POWER 8A0251D8
Device \Driver\usbehci \Device\USBFDO-1 IRP_MJ_SYSTEM_CONTROL 8A0251D8
Device \Driver\usbehci \Device\USBFDO-1 IRP_MJ_PNP 8A0251D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 895E21D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 895E21D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 895E21D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 895E21D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 895E21D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 895E21D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 895E21D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 895E21D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 895E21D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 895E21D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 895E21D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 895E21D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 895E21D8
Device \FileSystem\MRxSmb \
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 895E21D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 895E21D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 895E21D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 895E21D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 895E21D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 895E21D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 895E21D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 895E21D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 895E21D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 895E21D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 895E21D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 895E21D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 895E21D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 895E21D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 895E21D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 895E21D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 8A6D11D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_READ 8A6D11D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE 8A6D11D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS 8A6D11D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL 8A6D11D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6D11D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN 8A6D11D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP 8A6D11D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER 8A6D11D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL 8A6D11D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP 8A6D11D8 Device \Driver\NetBT \Device\NetBT_Tcpip_{BDB46B34-4ABB-4251-8AFF-D552698FBB13} IRP_MJ_CREATE 895FC1D8 Device \Driver\NetBT \Device\NetBT_Tcpip_{BDB46B34-4ABB-4251-8AFF-D552698FBB13} IRP_MJ_CLOSE 895FC1D8 Device \Driver\NetBT \Device\NetBT_Tcpip_{BDB46B34-4ABB-4251-8AFF-D552698FBB13} IRP_MJ_DEVICE_CONTROL 895FC1D8 Device \Driver\NetBT \Device\NetBT_Tcpip_{BDB46B34-4ABB-4251-8AFF-D552698FBB13} IRP_MJ_INTERNAL_DEVICE_CONTROL 895FC1D8 Device \Driver\NetBT \Device\NetBT_Tcpip_{BDB46B34-4ABB-4251-8AFF-D552698FBB13} IRP_MJ_CLEANUP 895FC1D8 Device \Driver\NetBT \Device\NetBT_Tcpip_{BDB46B34-4ABB-4251-8AFF-D552698FBB13} IRP_MJ_PNP 895FC1D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path0Target10Lun0 IRP_MJ_CREATE 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path0Target10Lun0 IRP_MJ_CLOSE 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path0Target10Lun0 IRP_MJ_DEVICE_CONTROL 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path0Target10Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path0Target10Lun0 IRP_MJ_POWER 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path0Target10Lun0 IRP_MJ_SYSTEM_CONTROL 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path0Target10Lun0 IRP_MJ_PNP 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51 IRP_MJ_CREATE 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51 IRP_MJ_CLOSE 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51 IRP_MJ_DEVICE_CONTROL 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51 IRP_MJ_POWER 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51 IRP_MJ_SYSTEM_CONTROL 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51 IRP_MJ_PNP 8A6691D8 Device \Driver\a81ipayq \Device\Scsi\a81ipayq1 IRP_MJ_CREATE 89F451D8 Device \Driver\a81ipayq \Device\Scsi\a81ipayq1 IRP_MJ_CLOSE 89F451D8 Device \Driver\a81ipayq \Device\Scsi\a81ipayq1 IRP_MJ_DEVICE_CONTROL 89F451D8 Device \Driver\a81ipayq \Device\Scsi\a81ipayq1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89F451D8 Device \Driver\a81ipayq \Device\Scsi\a81ipayq1 IRP_MJ_POWER 89F451D8 Device \Driver\a81ipayq \Device\Scsi\a81ipayq1 IRP_MJ_SYSTEM_CONTROL 89F451D8 Device \Driver\a81ipayq \Device\Scsi\a81ipayq1 IRP_MJ_PNP 89F451D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path2Target10Lun0 IRP_MJ_CREATE 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path2Target10Lun0 IRP_MJ_CLOSE 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path2Target10Lun0 IRP_MJ_DEVICE_CONTROL 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path2Target10Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path2Target10Lun0 IRP_MJ_POWER 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path2Target10Lun0 IRP_MJ_SYSTEM_CONTROL 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path2Target10Lun0 IRP_MJ_PNP 8A6691D8 Device \Driver\a81ipayq \Device\Scsi\a81ipayq1Port7Path0Target0Lun0 IRP_MJ_CREATE 89F451D8 Device \Driver\a81ipayq \Device\Scsi\a81ipayq1Port7Path0Target0Lun0 IRP_MJ_CLOSE 89F451D8 Device \Driver\a81ipayq \Device\Scsi\a81ipayq1Port7Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 89F451D8 Device \Driver\a81ipayq \Device\Scsi\a81ipayq1Port7Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89F451D8 Device \Driver\a81ipayq \Device\Scsi\a81ipayq1Port7Path0Target0Lun0 IRP_MJ_POWER 89F451D8 Device \Driver\a81ipayq \Device\Scsi\a81ipayq1Port7Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 89F451D8 Device \Driver\a81ipayq \Device\Scsi\a81ipayq1Port7Path0Target0Lun0 IRP_MJ_PNP 89F451D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path0Target11Lun0 IRP_MJ_CREATE 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path0Target11Lun0 IRP_MJ_CLOSE 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path0Target11Lun0 IRP_MJ_DEVICE_CONTROL 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path0Target11Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path0Target11Lun0 IRP_MJ_POWER 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path0Target11Lun0 IRP_MJ_SYSTEM_CONTROL 8A6691D8 Device \Driver\si3114r5 \Device\Scsi\si3114r51Port6Path0Target11Lun0 IRP_MJ_PNP 8A6691D8 Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_READ 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP 89FCD1D8 Device \FileSystem\Fastfat \Fat IRP_MJ_PNP 89FCD1D8 Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 89EAD470 Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE 89EAD470 Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 89EAD470 Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION 89EAD470 Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION 89EAD470 Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION 89EAD470 Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL 89EAD470 Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL 89EAD470 Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL 89EAD470 Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN 89EAD470 Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL 89EAD470 Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP 89EAD470 Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP 89EAD470 —- Registry - GMER 1.0.11 —- Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{498DEF9F-ED0F-DC8F-6293-D2E0CA7D6F0A}\InProcServer32@jafekibakaglmbnioofi 0x6B 0x61 0x6C 0x6A … Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{498DEF9F-ED0F-DC8F-6293-D2E0CA7D6F0A}\InProcServer32@iafeahdppgnanoligo 0x6A 0x61 0x6C 0x6A … Reg \Registry\USER\S-1-5-21-2025429265-484061587-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{498DEF9F-ED0F-DC8F-6293-D2E0CA7D6F0A}@iahegdblapgnmkemfo 0x6B 0x61 0x6C 0x6A … Reg \Registry\USER\S-1-5-21-2025429265-484061587-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{498DEF9F-ED0F-DC8F-6293-D2E0CA7D6F0A}@hajeabpnjhkbfele 0x6A 0x61 0x6C 0x6A … Reg \Registry\USER\S-1-5-21-2025429265-484061587-839522115-1003\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY@?? 0xA3 0x20 0xF6 0xF8 … Reg \Registry\USER\S-1-5-21-2025429265-484061587-839522115-1003\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY@?? 0xFB 0xB6 0x5C 0x55 … —- Files - GMER 1.0.11 —- ADS C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF ADS … ADS … ADS … —- EOF - GMER 1.0.11 —-
Scroll down to the next reply view the original combofix.exe!
Conbofix.exe Log:
scottrichmond - 06-11-17 13:53:59.28 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\scottrichmond\Desktop"

((((((((((((((((((((((((((((((( Files Created from 2006-10-17 to 2006-11-17 ))))))))))))))))))))))))))))))))))


2006-11-16 15:13 121,856 ——— C:\WINDOWS\system32\xmllite.dll
2006-11-16 14:35 53,248 –a—— C:\WINDOWS\system32\Process.exe
2006-11-16 14:35 40,960 –a—— C:\WINDOWS\system32\swsc.exe
2006-11-16 14:35 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2006-11-16 14:35 2,172 –a—— C:\WINDOWS\system32\tmp.reg
2006-11-16 14:35 135,168 –a—— C:\WINDOWS\system32\swreg.exe
2006-11-16 14:05 93,696 –a—— C:\WINDOWS\system32\bcgxzgn.dll
2006-11-16 14:05 72,192 –a—— C:\WINDOWS\system32\gvbhhnk.dll
2006-11-08 20:50 2,560 –a—— C:\WINDOWS\_MSRSTRT.EXE
2006-11-07 20:23 68,888 –a—— C:\WINDOWS\system32\xinput1_3.dll
2006-11-07 20:23 62,744 –a—— C:\WINDOWS\system32\xinput1_2.dll
2006-11-07 20:23 237,848 –a—— C:\WINDOWS\system32\xactengine2_4.dll
2006-11-07 20:23 236,824 –a—— C:\WINDOWS\system32\xactengine2_3.dll
2006-11-07 20:23 2,414,360 –a—— C:\WINDOWS\system32\d3dx9_31.dll
2006-11-07 20:23 2,297,552 –a—— C:\WINDOWS\system32\d3dx9_26.dll
2006-11-07 20:23 15,128 –a—— C:\WINDOWS\system32\x3daudio1_1.dll
2006-11-02 18:38 51,200 –a—— C:\WINDOWS\system32\drvruw.dll
2006-11-02 18:38 40,973 –ahs—- C:\WINDOWS\system32\qommjge.dll.vir
2006-11-02 16:00 426,091 —hs—- C:\WINDOWS\system32\gjjlm.bak2
2006-11-01 16:00 60,436 –a—— C:\WINDOWS\system32\afdfhjfc.dll
2006-11-01 16:00 423,609 —hs—- C:\WINDOWS\system32\gjjlm.bak1
2006-11-01 16:00 110,612 –a—— C:\WINDOWS\system32\aptfxuhg.exe
2006-11-01 15:59 692,276 –ahs—- C:\WINDOWS\system32\mljjg.dll.vir
2006-11-01 15:53 51,200 –a—— C:\WINDOWS\system32\drvruv.dll
2006-11-01 15:53 40,973 —hs—- C:\WINDOWS\system32\yayyaby.dll
2006-11-01 15:53 15,872 –a—— C:\WINDOWS\system32\wineil32.dll
2006-10-27 15:09 6,049,280 ——— C:\WINDOWS\system32\ieframe.dll
2006-10-27 15:09 50,688 ——— C:\WINDOWS\system32\msfeedsbs.dll
2006-10-27 15:09 458,752 ——— C:\WINDOWS\system32\msfeeds.dll
2006-10-27 15:09 180,736 ——— C:\WINDOWS\system32\ieui.dll
2006-10-27 02:44 13,312 –a—— C:\WINDOWS\system32\ieudinit.exe
2006-10-27 00:08 40,960 –a—— C:\WINDOWS\system32\frapsvid.dll
2006-10-26 21:49 1,038,848 –a—— C:\WINDOWS\system32\dbghelp-xfw.dll
2006-10-26 19:09 15,440 –a—— C:\WINDOWS\system32\drivers\hamachi.sys
2006-10-24 20:22 89,673 C:\WINDOWSThumbplug TGA Uninstaller.exe
2006-10-24 15:13 102,400 –a—— C:\WINDOWS\system32\tsccvid.dll
2006-10-23 15:27 73,728 –a—— C:\WINDOWS\system32\drivers\SENTINEL.SYS
2006-10-23 15:27 685,056 –a—— C:\WINDOWS\system32\drivers\hardlock.sys
2006-10-23 15:27 6,656 –a—— C:\WINDOWS\system32\haspvdd.dll
2006-10-23 15:27 49,664 –a—— C:\WINDOWS\system32\SNTI386.DLL
2006-10-23 15:27 47,616 –a—— C:\WINDOWS\system32\drivers\Haspnt.sys
2006-10-23 15:27 383 –a—— C:\WINDOWS\system32\haspdos.sys
2006-10-23 15:27 305,152 –a—— C:\WINDOWS\IsUninst.exe
2006-10-23 15:27 20,032 -ra—— C:\WINDOWS\system32\drivers\SNTNLUSB.SYS
2006-10-23 15:27 18,432 –a—— C:\WINDOWS\system32\RNBOVDD.DLL
2006-10-22 12:22 888,832 –a—— C:\WINDOWS\system32\nvmobls.dll
2006-10-22 12:22 86,016 –a—— C:\WINDOWS\system32\nvmctray.dll
2006-10-22 12:22 81,920 –a—— C:\WINDOWS\system32\nvwddi.dll
2006-10-22 12:22 794,624 –a—— C:\WINDOWS\system32\nvcplui.exe
2006-10-22 12:22 7,700,480 –a—— C:\WINDOWS\system32\nvcpl.dll
2006-10-22 12:22 581,632 –a—— C:\WINDOWS\system32\nvhwvid.dll
2006-10-22 12:22 5,644,288 –a—— C:\WINDOWS\system32\nvoglnt.dll
2006-10-22 12:22 5,619,712 –a—— C:\WINDOWS\system32\nvdisps.dll
2006-10-22 12:22 5,255,168 –a—— C:\WINDOWS\system32\nvdispsr.dll
2006-10-22 12:22 466,944 –a—— C:\WINDOWS\system32\nvshell.dll
2006-10-22 12:22 458,752 –a—— C:\WINDOWS\system32\nvmccssr.dll
2006-10-22 12:22 45,056 –a—— C:\WINDOWS\system32\nvmccsrs.dll
2006-10-22 12:22 442,368 –a—— C:\WINDOWS\system32\nvappbar.exe
2006-10-22 12:22 425,984 –a—— C:\WINDOWS\system32\keystone.exe
2006-10-22 12:22 35,840 –a—— C:\WINDOWS\system32\nvcodins.dll
2006-10-22 12:22 35,840 –a—— C:\WINDOWS\system32\nvcod.dll
2006-10-22 12:22 311,296 –a—— C:\WINDOWS\system32\nvexpbar.dll
2006-10-22 12:22 3,203,072 –a—— C:\WINDOWS\system32\nvgamesr.dll
2006-10-22 12:22 3,047,424 –a—— C:\WINDOWS\system32\nvgames.dll
2006-10-22 12:22 286,720 –a—— C:\WINDOWS\system32\nvnt4cpl.dll
2006-10-22 12:22 229,376 –a—— C:\WINDOWS\system32\nvmccs.dll
2006-10-22 12:22 212,992 –a—— C:\WINDOWS\system32\nvapi.dll
2006-10-22 12:22 2,973,696 –a—— C:\WINDOWS\system32\nvvitvsr.dll
2006-10-22 12:22 2,924,544 –a—— C:\WINDOWS\system32\nvvitvs.dll
2006-10-22 12:22 2,859,008 –a—— C:\WINDOWS\system32\nvmoblsr.dll
2006-10-22 12:22 188,416 –a—— C:\WINDOWS\system32\nvmccss.dll
2006-10-22 12:22 159,810 –a—— C:\WINDOWS\system32\nvsvc32.exe
2006-10-22 12:22 147,456 –a—— C:\WINDOWS\system32\nvcolor.exe
2006-10-22 12:22 1,732,608 –a—— C:\WINDOWS\system32\nvwssr.dll
2006-10-22 12:22 1,662,976 –a—— C:\WINDOWS\system32\nvwdmcpl.dll
2006-10-22 12:22 1,622,016 –a—— C:\WINDOWS\system32\nwiz.exe
2006-10-22 12:22 1,470,464 –a—— C:\WINDOWS\system32\nview.dll
2006-10-22 12:22 1,339,392 –a—— C:\WINDOWS\system32\nvdspsch.exe
2006-10-22 12:22 1,236,992 –a—— C:\WINDOWS\system32\nvwss.dll
2006-10-22 12:22 1,019,904 –a—— C:\WINDOWS\system32\nvwimg.dll
2006-10-22 12:22 1,011,712 –a—— C:\WINDOWS\system32\nvcpluir.dll
2006-10-21 20:31 4,682 –a—— C:\WINDOWS\system32\npptNT2.sys
2006-10-20 14:07 8,704 –a—— C:\WINDOWS\system32\CNMVS7L.DLL
2006-10-20 14:07 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2006-10-20 14:07 140,288 –a—— C:\WINDOWS\system32\CNMLM7L.DLL
2006-10-20 14:06 69,632 –a—— C:\WINDOWS\system32\CNCI500.DLL
2006-10-20 14:06 49,152 –a—— C:\WINDOWS\system32\cncisco.dll
2006-10-20 14:06 221,184 –a—— C:\WINDOWS\system32\CNCC500.DLL
2006-10-20 14:06 139,264 –a—— C:\WINDOWS\system32\CNCL500.DLL
2006-10-20 14:04 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2006-10-20 12:55 6,016 –a—— C:\WINDOWS\system32\drivers\vnccom.SYS
2006-10-20 12:55 5,760 –a—— C:\WINDOWS\system32\vnchelp.dll
2006-10-20 12:55 4,736 –a—— C:\WINDOWS\system32\drivers\vncdrv.sys
2006-10-20 12:55 12,800 –a—— C:\WINDOWS\system32\vncdrv.dll
2006-10-20 11:22 36,528 ——— C:\WINDOWS\system32\drivers\PxHelp20.sys
2006-10-20 11:22 2,560 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2006-10-20 11:22 2,432 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2006-10-20 11:22 129,784 ——— C:\WINDOWS\system32\pxafs.dll
2006-10-20 11:22 115,880 ——— C:\WINDOWS\system32\pxinsi64.exe
2006-10-20 11:14 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2006-10-20 11:14 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2006-10-20 11:14 24,064 ——— C:\WINDOWS\system32\msxml3a.dll
2006-10-20 01:07 24,816 –a—— C:\WINDOWS\system32\mdimon.dll
2006-10-20 00:15 98,304 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2006-10-19 23:00 611,064 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2006-10-19 20:27 761,856 –a—— C:\WINDOWS\system32\xvidcore.dll
2006-10-19 20:27 180,224 –a—— C:\WINDOWS\system32\xvidvfw.dll
2006-10-19 20:20 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2006-10-19 19:40 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2006-10-19 01:36 26,496 –a—— C:\WINDOWS\system32\drivers\USBSTOR.SYS
2006-10-18 23:32 13,312 –a—— C:\WINDOWS\system32\BASSMOD.dll
2006-10-17 13:05 206,336 ——— C:\WINDOWS\system32\WinFXDocObj.exe
2006-10-17 12:58 61,952 ——— C:\WINDOWS\system32\icardie.dll
2006-10-17 12:58 12,288 ——— C:\WINDOWS\system32\msfeedssync.exe
2006-10-17 12:57 266,752 ——— C:\WINDOWS\system32\iertutil.dll
2006-10-17 12:27 380,928 ——— C:\WINDOWS\system32\ieapfltr.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-17 13:51 ——– d——– C:\Program Files\Mozilla Firefox
2006-11-17 11:17 ——– d——– C:\Program Files\Common Files
2006-11-17 03:06 ——– d——– C:\Program Files\Internet Explorer
2006-11-17 03:05 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Azureus
2006-11-16 15:18 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\OfficeUpdate12
2006-11-14 19:09 ——– d——– C:\Program Files\Steam
2006-11-13 15:49 ——– d——– C:\Program Files\GetRight
2006-11-13 10:32 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Hamachi
2006-11-12 17:45 ——– d——– C:\Program Files\Trillian Pro
2006-11-12 01:55 ——– d——– C:\Program Files\NetMeeting
2006-11-12 01:15 ——– d——– C:\Program Files\Far Cry
2006-11-12 00:02 ——– d——– C:\Program Files\GFI
2006-11-11 22:58 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-11-11 22:58 ——– d——– C:\Program Files\Atari
2006-11-11 22:20 ——– d——– C:\Program Files\NovaLogic
2006-11-11 21:37 ——– d——– C:\Program Files\FEAR
2006-11-10 12:28 163644 –a—— C:\WINDOWS\system32\drivers\secdrv.sys
2006-11-09 22:24 ——– d——– C:\Program Files\Electronic Arts
2006-11-09 21:57 ——– d——– C:\Program Files\WinRAR
2006-11-08 20:51 ——– d——– C:\Program Files\FlashGet
2006-11-08 20:50 2560 –a—— C:\WINDOWS\_MSRSTRT.EXE
2006-11-05 16:34 218624 –a—— C:\WINDOWS\system32\uxtheme.dll
2006-11-04 21:06 ——– d——– C:\Program Files\BPFTP Server
2006-11-03 13:01 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Real
2006-11-03 13:00 ——– d——– C:\Program Files\Real
2006-11-03 13:00 ——– d——– C:\Program Files\Common Files\xing shared
2006-11-03 13:00 ——– d——– C:\Program Files\Common Files\Real
2006-11-02 17:09 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\SearchToolbarCorp
2006-11-01 16:00 ——– d——– C:\Program Files\VSAdd-in
2006-10-31 16:44 ——– d——– C:\Program Files\QuickTime Alternative
2006-10-31 16:44 ——– d——– C:\Program Files\Media Player Classic
2006-10-31 16:44 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Media Player Classic
2006-10-31 16:32 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Filter Forge
2006-10-29 22:49 ——– d——– C:\Program Files\Doom 3
2006-10-29 19:19 ——– d——– C:\Program Files\Filter Forge
2006-10-28 14:07 ——– d—s—- C:\Documents and Settings\scottrichmond\Application Data\Microsoft
2006-10-27 15:09 413696 –a—— C:\WINDOWS\system32\vbscript.dll
2006-10-27 15:09 231424 –a—— C:\WINDOWS\system32\webcheck.dll
2006-10-27 15:09 156160 –a—— C:\WINDOWS\system32\msls31.dll
2006-10-27 04:26 ——– d——– C:\Program Files\THQ
2006-10-27 02:44 71680 –a—— C:\WINDOWS\system32\admparse.dll
2006-10-27 02:44 55296 –a—— C:\WINDOWS\system32\iesetup.dll
2006-10-27 02:44 54784 –a—— C:\WINDOWS\system32\ie4uinit.exe
2006-10-27 02:44 43008 –a—— C:\WINDOWS\system32\iernonce.dll
2006-10-27 02:44 382976 –a—— C:\WINDOWS\system32\iedkcs32.dll
2006-10-27 02:44 229376 –a—— C:\WINDOWS\system32\ieaksie.dll
2006-10-27 02:44 152064 –a—— C:\WINDOWS\system32\ieakeng.dll
2006-10-27 02:44 123904 –a—— C:\WINDOWS\system32\advpack.dll
2006-10-27 02:42 161792 –a—— C:\WINDOWS\system32\ieakui.dll
2006-10-26 19:10 ——– d——– C:\Program Files\Hamachi
2006-10-24 21:04 ——– d——– C:\Program Files\NVIDIA Corporation
2006-10-24 20:22 89673 –a—— C:\WINDOWS\Thumbplug TGA Uninstaller.exe
2006-10-24 20:22 ——– d——– C:\Program Files\Thumbplug TGA
2006-10-23 15:26 ——– d——– C:\Program Files\Alias
2006-10-23 15:25 ——– d——– C:\Program Files\Common Files\Alias Shared
2006-10-23 15:24 ——– d——– C:\Program Files\Common Files\Autodesk Shared
2006-10-22 23:27 ——– d——– C:\Program Files\Microsoft Office
2006-10-22 23:27 ——– d——– C:\Program Files\Common Files\Microsoft Shared
2006-10-22 12:42 ——– d——– C:\Program Files\TPG Usage Meter
2006-10-22 12:22 4527488 –a—— C:\WINDOWS\system32\nv4_disp.dll
2006-10-22 12:22 3994624 –a—— C:\WINDOWS\system32\drivers\nv4_mini.sys
2006-10-20 17:15 ——– d——– C:\Program Files\Winamp
2006-10-20 17:12 ——– d——– C:\Program Files\EQ2MAP Updater
2006-10-20 15:44 ——– d——– C:\Program Files\ID3-TagIT 3
2006-10-20 14:19 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Canon
2006-10-20 14:07 ——– d——– C:\Program Files\Canon
2006-10-20 13:52 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Adobe
2006-10-20 13:39 ——– d——– C:\Program Files\BulletProof FTP Client v2.5
2006-10-20 13:38 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\BPFTP
2006-10-20 12:55 ——– d——– C:\Program Files\UltraVNC
2006-10-20 11:46 ——– d——– C:\Program Files\Common Files\InstallShield
2006-10-20 11:17 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\CyberLink
2006-10-20 11:14 ——– d——– C:\Program Files\CyberLink
2006-10-20 11:08 ——– d——– C:\Program Files\Common Files\Adobe
2006-10-20 11:08 ——– d——– C:\Program Files\Adobe
2006-10-20 11:06 ——– d——– C:\Program Files\Common Files\Adobe Systems Shared
2006-10-20 10:39 ——– d——– C:\Program Files\DAEMON Tools
2006-10-20 01:07 ——– d——– C:\Program Files\Microsoft.NET
2006-10-20 01:06 ——– d——– C:\Program Files\Microsoft ActiveSync
2006-10-20 01:06 ——– d——– C:\Program Files\Common Files\DESIGNER
2006-10-20 00:15 ——– dr-h—– C:\Documents and Settings\scottrichmond\Application Data\SecuROM
2006-10-19 23:36 ——– d——– C:\Program Files\7-Zip
2006-10-19 23:08 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Macromedia
2006-10-19 21:29 ——– d——– C:\Program Files\Sony
2006-10-19 21:22 ——– d——– C:\Program Files\Trend Micro
2006-10-19 20:27 ——– d——– C:\Program Files\XviD
2006-10-19 20:21 ——– d——– C:\Program Files\Diskeeper Corporation
2006-10-19 20:21 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Leadertech
2006-10-19 19:59 ——– d——– C:\Program Files\Java
2006-10-19 19:59 ——– d——– C:\Program Files\Common Files\Java
2006-10-19 19:58 ——– d——– C:\Program Files\Windows Media Player
2006-10-19 19:58 ——– d——– C:\Program Files\Outlook Express
2006-10-19 19:58 ——– d——– C:\Program Files\Common Files\System
2006-10-19 19:56 ——– d——– C:\Program Files\Messenger
2006-10-19 19:52 ——– d——– C:\Program Files\Azureus
2006-10-19 19:52 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Mozilla
2006-10-19 19:14 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\InstallShield
2006-10-18 23:18 ——– d——– C:\Program Files\IDM Computer Solutions
2006-10-18 23:18 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\IDMComp
2006-10-18 21:29 ——– d——– C:\Program Files\MSN Messenger
2006-10-18 20:32 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Sun
2006-10-18 20:03 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\ID3-TagIT 3
2006-10-18 19:35 ——– d——– C:\Program Files\Macromedia
2006-10-18 19:33 ——– d——– C:\Program Files\Common Files\Macromedia
2006-10-17 13:06 78336 –a—— C:\WINDOWS\system32\ieencode.dll
2006-10-17 13:05 40960 –a—— C:\WINDOWS\system32\licmgr10.dll
2006-10-17 13:05 105984 –a—— C:\WINDOWS\system32\url.dll
2006-10-17 13:04 101376 –a—— C:\WINDOWS\system32\occache.dll
2006-10-17 12:57 36352 –a—— C:\WINDOWS\system32\imgutil.dll
2006-10-17 12:56 45568 –a—— C:\WINDOWS\system32\mshta.exe
2006-10-17 12:28 48128 –a—— C:\WINDOWS\system32\mshtmler.dll
2006-10-13 23:35 65536 –a—— C:\WINDOWS\system32\nwwks.dll
2006-10-13 23:35 64000 –a—— C:\WINDOWS\system32\nwapi32.dll
2006-10-13 23:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll
2006-10-13 21:23 163584 –a—— C:\WINDOWS\system32\drivers\nwrdr.sys
2006-09-30 09:18 524288 –a—— C:\WINDOWS\opuc.dll
2006-09-15 17:39 208896 –a—— C:\WINDOWS\system32\nvusmb.exe
2006-09-15 17:39 208896 –a—— C:\WINDOWS\system32\nvunrm.exe
2006-09-15 17:39 208896 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2006-09-13 16:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll
2006-08-26 02:45 617472 –a—— C:\WINDOWS\system32\comctl32.dll
2006-08-21 23:21 16896 –a—— C:\WINDOWS\system32\fltlib.dll
2006-08-21 20:14 23040 –a—— C:\WINDOWS\system32\fltmc.exe
2006-08-17 23:28 721920 –a—— C:\WINDOWS\system32\lsasrv.dll
2006-08-17 23:28 132096 –a—— C:\WINDOWS\system32\wkssvc.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SoundMan"="SOUNDMAN.EXE"
"pccguide.exe"="\"C:\\Program Files\\Trend Micro\\Internet Security 2006\\pccguide.exe\""
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RunDLL32.exe NvMCTray.dll,NvTaskbarInit"
"bcgxzgn.dll"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\bcgxzgn.dll,kzenukf"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{2B1B63E0-D818-4FB0-A504-DB8546149ABB}"=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"DisableTaskMgr"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^scottrichmond^Start Menu^Programs^Startup^Adobe Gamma.lnk]
"path"="C:\\Documents and Settings\\scottrichmond\\Start Menu\\Programs\\Startup\\Adobe Gamma.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "
"item"="Adobe Gamma"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDrive]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="drvruv"
"hkey"="HKLM"
"command"="rundll32.exe C:\\WINDOWS\\system32\\drvruv.dll,startup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DiskeeperSystray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DkIcon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Diskeeper Corporation\\Diskeeper\\DkIcon.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Language"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\Language\\Language.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msnmsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RichVideo"=dword:00000002
"ose"=dword:00000003
"Diskeeper"=dword:00000002

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wineil32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

Completion time: 06-11-17 13:54:18.48
C:\ComboFix.txt … 06-11-17 13:54
C:\ComboFix2.txt … 06-11-17 11:21
Ah it does save to logs. Heres the one from earlyer, which actually went about fixing some things. Sorry for the confusion.

Original Combofix.exe Log:
scottrichmond - 06-11-17 11:17:10.09 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\scottrichmond\Desktop"

((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Documents and Settings\scottrichmond\Desktop\DXTweaker\DXCTPlugin.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\components
C:\Program Files\Common Files\{38B7A8CB-096C-1033-0623-05071505003d}
C:\Program Files\Common Files\{98B7A8CB-096C-1033-0623-05071505003d}


((((((((((((((((((((((((((((((( Files Created from 2006-10-17 to 2006-11-17 ))))))))))))))))))))))))))))))))))


2006-11-16 15:13 121,856 ——— C:\WINDOWS\system32\xmllite.dll
2006-11-16 14:35 53,248 –a—— C:\WINDOWS\system32\Process.exe
2006-11-16 14:35 40,960 –a—— C:\WINDOWS\system32\swsc.exe
2006-11-16 14:35 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2006-11-16 14:35 2,172 –a—— C:\WINDOWS\system32\tmp.reg
2006-11-16 14:35 135,168 –a—— C:\WINDOWS\system32\swreg.exe
2006-11-16 14:05 93,696 –a—— C:\WINDOWS\system32\bcgxzgn.dll
2006-11-16 14:05 72,192 –a—— C:\WINDOWS\system32\gvbhhnk.dll
2006-11-08 20:50 2,560 –a—— C:\WINDOWS\_MSRSTRT.EXE
2006-11-07 20:23 68,888 –a—— C:\WINDOWS\system32\xinput1_3.dll
2006-11-07 20:23 62,744 –a—— C:\WINDOWS\system32\xinput1_2.dll
2006-11-07 20:23 237,848 –a—— C:\WINDOWS\system32\xactengine2_4.dll
2006-11-07 20:23 236,824 –a—— C:\WINDOWS\system32\xactengine2_3.dll
2006-11-07 20:23 2,414,360 –a—— C:\WINDOWS\system32\d3dx9_31.dll
2006-11-07 20:23 2,297,552 –a—— C:\WINDOWS\system32\d3dx9_26.dll
2006-11-07 20:23 15,128 –a—— C:\WINDOWS\system32\x3daudio1_1.dll
2006-11-02 18:38 51,200 –a—— C:\WINDOWS\system32\drvruw.dll
2006-11-02 18:38 40,973 –ahs—- C:\WINDOWS\system32\qommjge.dll.vir
2006-11-02 16:00 426,091 —hs—- C:\WINDOWS\system32\gjjlm.bak2
2006-11-01 16:00 60,436 –a—— C:\WINDOWS\system32\afdfhjfc.dll
2006-11-01 16:00 423,609 —hs—- C:\WINDOWS\system32\gjjlm.bak1
2006-11-01 16:00 110,612 –a—— C:\WINDOWS\system32\aptfxuhg.exe
2006-11-01 15:59 692,276 –ahs—- C:\WINDOWS\system32\mljjg.dll.vir
2006-11-01 15:53 51,200 –a—— C:\WINDOWS\system32\drvruv.dll
2006-11-01 15:53 40,973 —hs—- C:\WINDOWS\system32\yayyaby.dll
2006-11-01 15:53 15,872 –a—— C:\WINDOWS\system32\wineil32.dll
2006-10-27 15:09 6,049,280 ——— C:\WINDOWS\system32\ieframe.dll
2006-10-27 15:09 50,688 ——— C:\WINDOWS\system32\msfeedsbs.dll
2006-10-27 15:09 458,752 ——— C:\WINDOWS\system32\msfeeds.dll
2006-10-27 15:09 180,736 ——— C:\WINDOWS\system32\ieui.dll
2006-10-27 02:44 13,312 –a—— C:\WINDOWS\system32\ieudinit.exe
2006-10-27 00:08 40,960 –a—— C:\WINDOWS\system32\frapsvid.dll
2006-10-26 21:49 1,038,848 –a—— C:\WINDOWS\system32\dbghelp-xfw.dll
2006-10-26 19:09 15,440 –a—— C:\WINDOWS\system32\drivers\hamachi.sys
2006-10-24 20:22 89,673 C:\WINDOWSThumbplug TGA Uninstaller.exe
2006-10-24 15:13 102,400 –a—— C:\WINDOWS\system32\tsccvid.dll
2006-10-23 15:27 73,728 –a—— C:\WINDOWS\system32\drivers\SENTINEL.SYS
2006-10-23 15:27 685,056 –a—— C:\WINDOWS\system32\drivers\hardlock.sys
2006-10-23 15:27 6,656 –a—— C:\WINDOWS\system32\haspvdd.dll
2006-10-23 15:27 49,664 –a—— C:\WINDOWS\system32\SNTI386.DLL
2006-10-23 15:27 47,616 –a—— C:\WINDOWS\system32\drivers\Haspnt.sys
2006-10-23 15:27 383 –a—— C:\WINDOWS\system32\haspdos.sys
2006-10-23 15:27 305,152 –a—— C:\WINDOWS\IsUninst.exe
2006-10-23 15:27 20,032 -ra—— C:\WINDOWS\system32\drivers\SNTNLUSB.SYS
2006-10-23 15:27 18,432 –a—— C:\WINDOWS\system32\RNBOVDD.DLL
2006-10-22 12:22 888,832 –a—— C:\WINDOWS\system32\nvmobls.dll
2006-10-22 12:22 86,016 –a—— C:\WINDOWS\system32\nvmctray.dll
2006-10-22 12:22 81,920 –a—— C:\WINDOWS\system32\nvwddi.dll
2006-10-22 12:22 794,624 –a—— C:\WINDOWS\system32\nvcplui.exe
2006-10-22 12:22 7,700,480 –a—— C:\WINDOWS\system32\nvcpl.dll
2006-10-22 12:22 581,632 –a—— C:\WINDOWS\system32\nvhwvid.dll
2006-10-22 12:22 5,644,288 –a—— C:\WINDOWS\system32\nvoglnt.dll
2006-10-22 12:22 5,619,712 –a—— C:\WINDOWS\system32\nvdisps.dll
2006-10-22 12:22 5,255,168 –a—— C:\WINDOWS\system32\nvdispsr.dll
2006-10-22 12:22 466,944 –a—— C:\WINDOWS\system32\nvshell.dll
2006-10-22 12:22 458,752 –a—— C:\WINDOWS\system32\nvmccssr.dll
2006-10-22 12:22 45,056 –a—— C:\WINDOWS\system32\nvmccsrs.dll
2006-10-22 12:22 442,368 –a—— C:\WINDOWS\system32\nvappbar.exe
2006-10-22 12:22 425,984 –a—— C:\WINDOWS\system32\keystone.exe
2006-10-22 12:22 35,840 –a—— C:\WINDOWS\system32\nvcodins.dll
2006-10-22 12:22 35,840 –a—— C:\WINDOWS\system32\nvcod.dll
2006-10-22 12:22 311,296 –a—— C:\WINDOWS\system32\nvexpbar.dll
2006-10-22 12:22 3,203,072 –a—— C:\WINDOWS\system32\nvgamesr.dll
2006-10-22 12:22 3,047,424 –a—— C:\WINDOWS\system32\nvgames.dll
2006-10-22 12:22 286,720 –a—— C:\WINDOWS\system32\nvnt4cpl.dll
2006-10-22 12:22 229,376 –a—— C:\WINDOWS\system32\nvmccs.dll
2006-10-22 12:22 212,992 –a—— C:\WINDOWS\system32\nvapi.dll
2006-10-22 12:22 2,973,696 –a—— C:\WINDOWS\system32\nvvitvsr.dll
2006-10-22 12:22 2,924,544 –a—— C:\WINDOWS\system32\nvvitvs.dll
2006-10-22 12:22 2,859,008 –a—— C:\WINDOWS\system32\nvmoblsr.dll
2006-10-22 12:22 188,416 –a—— C:\WINDOWS\system32\nvmccss.dll
2006-10-22 12:22 159,810 –a—— C:\WINDOWS\system32\nvsvc32.exe
2006-10-22 12:22 147,456 –a—— C:\WINDOWS\system32\nvcolor.exe
2006-10-22 12:22 1,732,608 –a—— C:\WINDOWS\system32\nvwssr.dll
2006-10-22 12:22 1,662,976 –a—— C:\WINDOWS\system32\nvwdmcpl.dll
2006-10-22 12:22 1,622,016 –a—— C:\WINDOWS\system32\nwiz.exe
2006-10-22 12:22 1,470,464 –a—— C:\WINDOWS\system32\nview.dll
2006-10-22 12:22 1,339,392 –a—— C:\WINDOWS\system32\nvdspsch.exe
2006-10-22 12:22 1,236,992 –a—— C:\WINDOWS\system32\nvwss.dll
2006-10-22 12:22 1,019,904 –a—— C:\WINDOWS\system32\nvwimg.dll
2006-10-22 12:22 1,011,712 –a—— C:\WINDOWS\system32\nvcpluir.dll
2006-10-21 20:31 4,682 –a—— C:\WINDOWS\system32\npptNT2.sys
2006-10-20 14:07 8,704 –a—— C:\WINDOWS\system32\CNMVS7L.DLL
2006-10-20 14:07 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2006-10-20 14:07 140,288 –a—— C:\WINDOWS\system32\CNMLM7L.DLL
2006-10-20 14:06 69,632 –a—— C:\WINDOWS\system32\CNCI500.DLL
2006-10-20 14:06 49,152 –a—— C:\WINDOWS\system32\cncisco.dll
2006-10-20 14:06 221,184 –a—— C:\WINDOWS\system32\CNCC500.DLL
2006-10-20 14:06 139,264 –a—— C:\WINDOWS\system32\CNCL500.DLL
2006-10-20 14:04 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2006-10-20 12:55 6,016 –a—— C:\WINDOWS\system32\drivers\vnccom.SYS
2006-10-20 12:55 5,760 –a—— C:\WINDOWS\system32\vnchelp.dll
2006-10-20 12:55 4,736 –a—— C:\WINDOWS\system32\drivers\vncdrv.sys
2006-10-20 12:55 12,800 –a—— C:\WINDOWS\system32\vncdrv.dll
2006-10-20 11:22 36,528 ——— C:\WINDOWS\system32\drivers\PxHelp20.sys
2006-10-20 11:22 2,560 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2006-10-20 11:22 2,432 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2006-10-20 11:22 129,784 ——— C:\WINDOWS\system32\pxafs.dll
2006-10-20 11:22 115,880 ——— C:\WINDOWS\system32\pxinsi64.exe
2006-10-20 11:14 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2006-10-20 11:14 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2006-10-20 11:14 24,064 ——— C:\WINDOWS\system32\msxml3a.dll
2006-10-20 01:07 24,816 –a—— C:\WINDOWS\system32\mdimon.dll
2006-10-20 00:15 98,304 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2006-10-19 23:00 611,064 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2006-10-19 20:27 761,856 –a—— C:\WINDOWS\system32\xvidcore.dll
2006-10-19 20:27 180,224 –a—— C:\WINDOWS\system32\xvidvfw.dll
2006-10-19 20:20 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2006-10-19 19:40 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2006-10-19 01:36 26,496 –a—— C:\WINDOWS\system32\drivers\USBSTOR.SYS
2006-10-18 23:32 13,312 –a—— C:\WINDOWS\system32\BASSMOD.dll
2006-10-17 13:05 206,336 ——— C:\WINDOWS\system32\WinFXDocObj.exe
2006-10-17 12:58 61,952 ——— C:\WINDOWS\system32\icardie.dll
2006-10-17 12:58 12,288 ——— C:\WINDOWS\system32\msfeedssync.exe
2006-10-17 12:57 266,752 ——— C:\WINDOWS\system32\iertutil.dll
2006-10-17 12:27 380,928 ——— C:\WINDOWS\system32\ieapfltr.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-17 11:17 ——– d——– C:\Program Files\Common Files
2006-11-17 11:11 ——– d——– C:\Program Files\Mozilla Firefox
2006-11-17 03:06 ——– d——– C:\Program Files\Internet Explorer
2006-11-17 03:05 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Azureus
2006-11-16 15:18 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\OfficeUpdate12
2006-11-14 19:09 ——– d——– C:\Program Files\Steam
2006-11-13 15:49 ——– d——– C:\Program Files\GetRight
2006-11-13 10:32 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Hamachi
2006-11-12 17:45 ——– d——– C:\Program Files\Trillian Pro
2006-11-12 01:55 ——– d——– C:\Program Files\NetMeeting
2006-11-12 01:15 ——– d——– C:\Program Files\Far Cry
2006-11-12 00:02 ——– d——– C:\Program Files\GFI
2006-11-11 22:58 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-11-11 22:58 ——– d——– C:\Program Files\Atari
2006-11-11 22:20 ——– d——– C:\Program Files\NovaLogic
2006-11-11 21:37 ——– d——– C:\Program Files\FEAR
2006-11-10 12:28 163644 –a—— C:\WINDOWS\system32\drivers\secdrv.sys
2006-11-09 22:24 ——– d——– C:\Program Files\Electronic Arts
2006-11-09 21:57 ——– d——– C:\Program Files\WinRAR
2006-11-08 20:51 ——– d——– C:\Program Files\FlashGet
2006-11-08 20:50 2560 –a—— C:\WINDOWS\_MSRSTRT.EXE
2006-11-05 16:34 218624 –a—— C:\WINDOWS\system32\uxtheme.dll
2006-11-04 21:06 ——– d——– C:\Program Files\BPFTP Server
2006-11-03 13:01 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Real
2006-11-03 13:00 ——– d——– C:\Program Files\Real
2006-11-03 13:00 ——– d——– C:\Program Files\Common Files\xing shared
2006-11-03 13:00 ——– d——– C:\Program Files\Common Files\Real
2006-11-02 17:09 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\SearchToolbarCorp
2006-11-01 16:00 ——– d——– C:\Program Files\VSAdd-in
2006-10-31 16:44 ——– d——– C:\Program Files\QuickTime Alternative
2006-10-31 16:44 ——– d——– C:\Program Files\Media Player Classic
2006-10-31 16:44 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Media Player Classic
2006-10-31 16:32 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Filter Forge
2006-10-29 22:49 ——– d——– C:\Program Files\Doom 3
2006-10-29 19:19 ——– d——– C:\Program Files\Filter Forge
2006-10-28 14:07 ——– d—s—- C:\Documents and Settings\scottrichmond\Application Data\Microsoft
2006-10-27 15:09 413696 –a—— C:\WINDOWS\system32\vbscript.dll
2006-10-27 15:09 231424 –a—— C:\WINDOWS\system32\webcheck.dll
2006-10-27 15:09 156160 –a—— C:\WINDOWS\system32\msls31.dll
2006-10-27 04:26 ——– d——– C:\Program Files\THQ
2006-10-27 02:44 71680 –a—— C:\WINDOWS\system32\admparse.dll
2006-10-27 02:44 55296 –a—— C:\WINDOWS\system32\iesetup.dll
2006-10-27 02:44 54784 –a—— C:\WINDOWS\system32\ie4uinit.exe
2006-10-27 02:44 43008 –a—— C:\WINDOWS\system32\iernonce.dll
2006-10-27 02:44 382976 –a—— C:\WINDOWS\system32\iedkcs32.dll
2006-10-27 02:44 229376 –a—— C:\WINDOWS\system32\ieaksie.dll
2006-10-27 02:44 152064 –a—— C:\WINDOWS\system32\ieakeng.dll
2006-10-27 02:44 123904 –a—— C:\WINDOWS\system32\advpack.dll
2006-10-27 02:42 161792 –a—— C:\WINDOWS\system32\ieakui.dll
2006-10-26 19:10 ——– d——– C:\Program Files\Hamachi
2006-10-24 21:04 ——– d——– C:\Program Files\NVIDIA Corporation
2006-10-24 20:22 89673 –a—— C:\WINDOWS\Thumbplug TGA Uninstaller.exe
2006-10-24 20:22 ——– d——– C:\Program Files\Thumbplug TGA
2006-10-23 15:26 ——– d——– C:\Program Files\Alias
2006-10-23 15:25 ——– d——– C:\Program Files\Common Files\Alias Shared
2006-10-23 15:24 ——– d——– C:\Program Files\Common Files\Autodesk Shared
2006-10-22 23:27 ——– d——– C:\Program Files\Microsoft Office
2006-10-22 23:27 ——– d——– C:\Program Files\Common Files\Microsoft Shared
2006-10-22 12:42 ——– d——– C:\Program Files\TPG Usage Meter
2006-10-22 12:22 4527488 –a—— C:\WINDOWS\system32\nv4_disp.dll
2006-10-22 12:22 3994624 –a—— C:\WINDOWS\system32\drivers\nv4_mini.sys
2006-10-20 17:15 ——– d——– C:\Program Files\Winamp
2006-10-20 17:12 ——– d——– C:\Program Files\EQ2MAP Updater
2006-10-20 15:44 ——– d——– C:\Program Files\ID3-TagIT 3
2006-10-20 14:19 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Canon
2006-10-20 14:07 ——– d——– C:\Program Files\Canon
2006-10-20 13:52 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Adobe
2006-10-20 13:39 ——– d——– C:\Program Files\BulletProof FTP Client v2.5
2006-10-20 13:38 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\BPFTP
2006-10-20 12:55 ——– d——– C:\Program Files\UltraVNC
2006-10-20 11:46 ——– d——– C:\Program Files\Common Files\InstallShield
2006-10-20 11:17 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\CyberLink
2006-10-20 11:14 ——– d——– C:\Program Files\CyberLink
2006-10-20 11:08 ——– d——– C:\Program Files\Common Files\Adobe
2006-10-20 11:08 ——– d——– C:\Program Files\Adobe
2006-10-20 11:06 ——– d——– C:\Program Files\Common Files\Adobe Systems Shared
2006-10-20 10:39 ——– d——– C:\Program Files\DAEMON Tools
2006-10-20 01:07 ——– d——– C:\Program Files\Microsoft.NET
2006-10-20 01:06 ——– d——– C:\Program Files\Microsoft ActiveSync
2006-10-20 01:06 ——– d——– C:\Program Files\Common Files\DESIGNER
2006-10-20 00:15 ——– dr-h—– C:\Documents and Settings\scottrichmond\Application Data\SecuROM
2006-10-19 23:36 ——– d——– C:\Program Files\7-Zip
2006-10-19 23:08 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Macromedia
2006-10-19 21:29 ——– d——– C:\Program Files\Sony
2006-10-19 21:22 ——– d——– C:\Program Files\Trend Micro
2006-10-19 20:27 ——– d——– C:\Program Files\XviD
2006-10-19 20:21 ——– d——– C:\Program Files\Diskeeper Corporation
2006-10-19 20:21 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Leadertech
2006-10-19 19:59 ——– d——– C:\Program Files\Java
2006-10-19 19:59 ——– d——– C:\Program Files\Common Files\Java
2006-10-19 19:58 ——– d——– C:\Program Files\Windows Media Player
2006-10-19 19:58 ——– d——– C:\Program Files\Outlook Express
2006-10-19 19:58 ——– d——– C:\Program Files\Common Files\System
2006-10-19 19:56 ——– d——– C:\Program Files\Messenger
2006-10-19 19:52 ——– d——– C:\Program Files\Azureus
2006-10-19 19:52 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Mozilla
2006-10-19 19:14 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\InstallShield
2006-10-18 23:18 ——– d——– C:\Program Files\IDM Computer Solutions
2006-10-18 23:18 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\IDMComp
2006-10-18 21:29 ——– d——– C:\Program Files\MSN Messenger
2006-10-18 20:32 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Sun
2006-10-18 20:03 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\ID3-TagIT 3
2006-10-18 19:35 ——– d——– C:\Program Files\Macromedia
2006-10-18 19:33 ——– d——– C:\Program Files\Common Files\Macromedia
2006-10-17 13:06 78336 –a—— C:\WINDOWS\system32\ieencode.dll
2006-10-17 13:05 40960 –a—— C:\WINDOWS\system32\licmgr10.dll
2006-10-17 13:05 105984 –a—— C:\WINDOWS\system32\url.dll
2006-10-17 13:04 101376 –a—— C:\WINDOWS\system32\occache.dll
2006-10-17 12:57 36352 –a—— C:\WINDOWS\system32\imgutil.dll
2006-10-17 12:56 45568 –a—— C:\WINDOWS\system32\mshta.exe
2006-10-17 12:28 48128 –a—— C:\WINDOWS\system32\mshtmler.dll
2006-10-13 23:35 65536 –a—— C:\WINDOWS\system32\nwwks.dll
2006-10-13 23:35 64000 –a—— C:\WINDOWS\system32\nwapi32.dll
2006-10-13 23:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll
2006-10-13 21:23 163584 –a—— C:\WINDOWS\system32\drivers\nwrdr.sys
2006-09-30 09:18 524288 –a—— C:\WINDOWS\opuc.dll
2006-09-15 17:39 208896 –a—— C:\WINDOWS\system32\nvusmb.exe
2006-09-15 17:39 208896 –a—— C:\WINDOWS\system32\nvunrm.exe
2006-09-15 17:39 208896 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2006-09-13 16:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll
2006-08-26 02:45 617472 –a—— C:\WINDOWS\system32\comctl32.dll
2006-08-21 23:21 16896 –a—— C:\WINDOWS\system32\fltlib.dll
2006-08-21 20:14 23040 –a—— C:\WINDOWS\system32\fltmc.exe
2006-08-17 23:28 721920 –a—— C:\WINDOWS\system32\lsasrv.dll
2006-08-17 23:28 132096 –a—— C:\WINDOWS\system32\wkssvc.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SoundMan"="SOUNDMAN.EXE"
"pccguide.exe"="\"C:\\Program Files\\Trend Micro\\Internet Security 2006\\pccguide.exe\""
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RunDLL32.exe NvMCTray.dll,NvTaskbarInit"
"bcgxzgn.dll"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\bcgxzgn.dll,kzenukf"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{2B1B63E0-D818-4FB0-A504-DB8546149ABB}"=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"DisableTaskMgr"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^scottrichmond^Start Menu^Programs^Startup^Adobe Gamma.lnk]
"path"="C:\\Documents and Settings\\scottrichmond\\Start Menu\\Programs\\Startup\\Adobe Gamma.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "
"item"="Adobe Gamma"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDrive]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="drvruv"
"hkey"="HKLM"
"command"="rundll32.exe C:\\WINDOWS\\system32\\drvruv.dll,startup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DiskeeperSystray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DkIcon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Diskeeper Corporation\\Diskeeper\\DkIcon.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Language"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\Language\\Language.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msnmsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RichVideo"=dword:00000002
"ose"=dword:00000003
"Diskeeper"=dword:00000002

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wineil32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

Completion time: 06-11-17 11:21:45.65
C:\ComboFix.txt … 06-11-17 11:21
Sorry about the delay.

Hijackthis Log (19/11/2006)

Logfile of HijackThis v1.99.1
Scan saved at 7:49:20 PM, on 19/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PCCTLCOM.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TMPFW.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Documents and Settings\scottrichmond\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = melbourne.cache.telstra.net:3128
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O2 - BHO: (no name) - {59900857-4D71-782E-2CD8-06375AC562C8} - C:\WINDOWS\system32\gvbhhnk.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {F18F04B0-9CF1-4b93-B004-77A288BEE28B} - C:\WINDOWS\system32\afdfhjfc.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [bcgxzgn.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\bcgxzgn.dll,kzenukf
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1098175036125
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: wineil32 - C:\WINDOWS\SYSTEM32\wineil32.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Hi DJDD,

Let's work with eliminating the Vundo infection first.

STEP 1.
======
Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Wow, ouch. Vundofix starts scanning but when it hits mscore_lib.dll (may not be exact name) it automatically kills the explorer.exe process and its self (all i get is my background) and then 10 seconds later i get a BSOD saying 'Unknown hard error'. :huh:
Hi DJDD.

Sorry about the BSOD. Have you run VundoFix in the past? Reason I ask is that the C:\WINDOWS\system32\qommjge.dll.vir with the .vir extension tacked on looks like what you would get after running VundoFix.

Anyway we will use a different approach now.


STEP 1.
======
Delete Files with Killbox

Download Pocket Killbox from http://www.downloads.subratam.org/KillBox.zip and unzip it; save it to your Desktop. DO NOT RUN IT YET.
==========
Double-click on KillBox.exe to launch the program. It is the red circle with a large white X in it
- Highlight the files in bold RED below and press the Ctrl key and the C key at the same time to copy them to the clipboard
C:\WINDOWS\system32\drvruw.dll
C:\WINDOWS\system32\qommjge.dll.vir
C:\WINDOWS\system32\gjjlm.bak2
C:\WINDOWS\system32\afdfhjfc.dll
C:\WINDOWS\system32\gjjlm.bak1
C:\WINDOWS\system32\aptfxuhg.exe
C:\WINDOWS\system32\mljjg.dll.vir
C:\WINDOWS\system32\drvruv.dll
C:\WINDOWS\system32\yayyaby.dll
C:\WINDOWS\system32\wineil32.dll


In Killbox click on the File menu and then the Paste from Clipboard item
in the Full Path of File to Delete field drop down the arrow and make sure that all of the files are listed
(Please note that the tool checks your computer for the presence of the files pasted into the box so if files are not present, it is possible that you might not see all files you pasted into the box.)
  • Click the option to Delete on Reboot
  • Click End Explorer Shell while Killing File
  • Click All Files right of the flashing green "Single files"
  • Click Yes when it asks "Files will be Removed on Reboot, Do you want to reboot now?"
(Note: If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just reboot manually)

If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X …and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until the last one at which time you click yes to allow the reboot.

Please run ComboFix again and post another hijackthis log.
Indeed i may have run VundoFix before in my attempt to kill this problem my self before i came here to seek help.
All files deleted with Killbox (I checked again after reboot).
Ran Combofix again, didn't say it found anything.
Incedently, something called VS-Addin keeps being detected by Cillin every time i open an explorer window or internet explorer (Which now crashes every time i run it). This issue has nothing to do with what you just told me to do, it has been happening for quite a few days now. Thought i'd just mention it.

Log file from Hijackthis:

Logfile of HijackThis v1.99.1
Scan saved at 9:53:16 PM, on 21/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PCCTLCOM.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TMPROXY.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\TMPFW.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRAM FILES\TRILLIAN PRO\TRILLIAN.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
C:\Documents and Settings\scottrichmond\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = melbourne.cache.telstra.net:3128
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O2 - BHO: (no name) - {59900857-4D71-782E-2CD8-06375AC562C8} - C:\WINDOWS\system32\gvbhhnk.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {F18F04B0-9CF1-4b93-B004-77A288BEE28B} - C:\WINDOWS\system32\afdfhjfc.dll (file missing)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [bcgxzgn.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\bcgxzgn.dll,kzenukf
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1098175036125
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: wineil32 - wineil32.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
I see a couple of files we still need to get.

STEP 1.
======
Delete Files with Killbox

Skip the download since you already have it.
Download Pocket Killbox from http://www.downloads.subratam.org/KillBox.zip and unzip it; save it to your Desktop. DO NOT RUN IT YET.
==========
Double-click on KillBox.exe to launch the program. It is the red circle with a large white X in it
- Highlight the files in bold RED below and press the Ctrl key and the C key at the same time to copy them to the clipboard
C:\WINDOWS\system32\bcgxzgn.dll
C:\WINDOWS\system32\gvbhhnk.dll


In Killbox click on the File menu and then the Paste from Clipboard item
in the Full Path of File to Delete field drop down the arrow and make sure that all of the files are listed
(Please note that the tool checks your computer for the presence of the files pasted into the box so if files are not present, it is possible that you might not see all files you pasted into the box.)
  • Click the option to Delete on Reboot
  • Click End Explorer Shell while Killing File
  • Click All Files right of the flashing green "Single files"
  • Click Yes when it asks "Files will be Removed on Reboot, Do you want to reboot now?"
(Note: If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just reboot manually)

If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X …and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until the last one at which time you click yes to allow the reboot.

Please set your system to show all files; please see here if you're unsure how to do this.

Scan with HijackThis. Place a check against each of the following:
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O2 - BHO: (no name) - {59900857-4D71-782E-2CD8-06375AC562C8} - C:\WINDOWS\system32\gvbhhnk.dll
O2 - BHO: (no name) - {F18F04B0-9CF1-4b93-B004-77A288BEE28B} - C:\WINDOWS\system32\afdfhjfc.dll (file missing)
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O20 - Winlogon Notify: wineil32 - wineil32.dll (file missing)

Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

Reboot into Safe Mode: please see here if you are not sure how to do this.

Using Windows Explorer, locate the following files/folders, and delete them:
C:\Program Files\VSAdd-in\<=folder
Exit Explorer, and reboot as normal afterwards.

Post (reply) with a fresh HijackThis log and please post(reply) a fresh ComboFix log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI