This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

secure32.html

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

You're determined to make this hard work, aren't you! :unsure:
It seems that Kaspersky are upgrading their site again so that would explain why you aren't having any luck there. Forget that one, and go with this one instead:

Run the following online scan: Panda ActiveScan.
  • Please note that IE is required to run this scan.
  • You will need to fill in the "Country, region, email address" information before you can download and install the ActiveX components necessary to run the scan.
  • When you are asked to "Select a device to scan…", click on "My Computer".
When the scan has finished, click See Report > Save Report which by default will save the scan results as Activescan.txt in My Documents.

Copy and paste the result of the above scan into your next reply along with a fresh HJT log
Ok, I did the Panda Active Scan and a new HJT log below. Panda found a couple of items. Thanks.

PANDA ACTIVE SCAN
Incident Status Location

Spyware:spyware/betterinet Not disinfected c:\windows\inf\satmat.inf
Adware:adware/cws.008k Not disinfected c:\windows\iedb.dll
Adware:adware/instdollars Not disinfected Windows Registry
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@hitbox[2].txt
Potentially unwanted tool:Application/Altnet Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1B.tmp\mysearch.cab
Virus:Trj/Moli.AD


HIJACKTHIS LOG:
Logfile of HijackThis v1.99.1
Scan saved at 8:39:39 PM, on 1/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Scott's Programs\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Gateway\EzTune\DTSRVC.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Scott's Programs\Spyware Doctor\sdhelp.exe
C:\Program Files\SpywareDetector\SDService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\SpywareDetector\SDSystemTray.exe
C:\Scott's Programs\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\ATI Multimedia\main\ATISched.EXE
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\Program Files\The Jungle Media Center\The Jungle Media Center.exe
C:\WINDOWS\system32\ctfmon.exe
C:\SCOTT'~1\SPYWAR~1\swdoctor.exe
C:\Program Files\My Book\WD Backup\uBBMonitor.exe
C:\Program Files\WallpaperToy\Wallpapertoy.Exe
C:\Program Files\Portrait Displays\Pivot Software\floater.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Scott's Programs\iPod\Updater\iPod\bin\iPodService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Documents and Settings\Scott Collins\My Documents\1Temp\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Scott's Programs\Spybot - Search & Destroy\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\SCOTT'~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\SCOTT'~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [SystemTraySD] C:\Program Files\SpywareDetector\SDSystemTray.exe
O4 - HKLM\..\Run: [SDAutoLiveupdate] C:\Program Files\SpywareDetector\LiveUpdateSD.exe -AUTO
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Scott's Programs\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ATI Scheduler] C:\Program Files\ATI Multimedia\main\ATISched.EXE
O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [The Jim Rome Show] C:\Program Files\The Jungle Media Center\The Jungle Media Center.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Doctor] C:\SCOTT'~1\SPYWAR~1\swdoctor.exe /Q
O4 - Startup: Wallpaper Changer.lnk = C:\Program Files\WallpaperToy\Wallpapertoy.Exe
O4 - Global Startup: WD Backup Monitor.lnk = C:\Program Files\My Book\WD Backup\uBBMonitor.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\SCOTT'~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: (no name) - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\WINDOWS\System32\shdocvw.dll
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161827233919
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://phoenixcon.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A3380357-9A2A-41C3-A474-7F6B2B2737C4}: NameServer = 69.50.161.130
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: SDNotify - C:\Program Files\SpywareDetector\SDNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Scott's Programs\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Gateway\EzTune\DTSRVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Scott's Programs\iPod\Updater\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Scott's Programs\Spyware Doctor\sdhelp.exe
O23 - Service: SDService - Max Secure Software - C:\Program Files\SpywareDetector\SDService.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe

I would also like you to run GMER as per the earlier instructions and let me have the logs that are produced.

I don't see this one.
Here are the two GMER logs. I may have to put them into two messages because they are too many characters long.

GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2007-01-05 16:41:55
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.12 —-

SSDT 8A78F140 ZwConnectPort
SSDT sptd.sys ZwCreateKey
SSDT IPVNMon.sys ZwDeviceIoControlFile
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT sptd.sys ZwOpenKey
SSDT \??\C:\Scott's Programs\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT sptd.sys ZwSetValueKey
SSDT \??\C:\Scott's Programs\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess

—- Devices - GMER 1.0.12 —-

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 8A9C41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 8A9C41D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLOSE 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_WRITE 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_INFORMATION 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_EA 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_EA 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FLUSH_BUFFERS 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP 8A4DD3E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP 8A4DD3E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CREATE 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CLOSE 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_POWER 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_PNP 8A6E21D8
Device \Driver\NetBT \Device\NetBT_Tcpip_{5A5CC5A2-370B-47F4-99DB-FE71C6F34B74} IRP_MJ_CREATE 8A4983C0
Device \Driver\NetBT \Device\NetBT_Tcpip_{5A5CC5A2-370B-47F4-99DB-FE71C6F34B74} IRP_MJ_CLOSE 8A4983C0
Device \Driver\NetBT \Device\NetBT_Tcpip_{5A5CC5A2-370B-47F4-99DB-FE71C6F34B74} IRP_MJ_DEVICE_CONTROL 8A4983C0
Device \Driver\NetBT \Device\NetBT_Tcpip_{5A5CC5A2-370B-47F4-99DB-FE71C6F34B74} IRP_MJ_INTERNAL_DEVICE_CONTROL 8A4983C0
Device \Driver\NetBT \Device\NetBT_Tcpip_{5A5CC5A2-370B-47F4-99DB-FE71C6F34B74} IRP_MJ_CLEANUP 8A4983C0
Device \Driver\NetBT \Device\NetBT_Tcpip_{5A5CC5A2-370B-47F4-99DB-FE71C6F34B74} IRP_MJ_PNP 8A4983C0
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CREATE 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CLOSE 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_POWER 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_PNP 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CREATE 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CLOSE 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_DEVICE_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_POWER 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_SYSTEM_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_PNP 8A6E21D8
Device \Driver\00000063 \Device\00000054 IRP_MJ_POWER [F750ED74] sptd.sys
Device \Driver\00000063 \Device\00000054 IRP_MJ_SYSTEM_CONTROL [F75282A2] sptd.sys
Device \Driver\00000063 \Device\00000054 IRP_MJ_PNP [F7529228] sptd.sys
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CREATE 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CLOSE 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_DEVICE_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_POWER 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_SYSTEM_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_PNP 8A6E21D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_CREATE 8A6B31D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_CLOSE 8A6B31D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_DEVICE_CONTROL 8A6B31D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6B31D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_POWER 8A6B31D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_SYSTEM_CONTROL 8A6B31D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_PNP 8A6B31D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 8A9C61D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 8A9C61D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 8A8341D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 8A8341D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 8A8341D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 8A8341D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 8A8341D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 8A8341D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A8341D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 8A8341D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 8A8341D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 8A8341D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 8A8341D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 8A8341D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 8A8341D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 8A8341D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 8A8341D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 8A8341D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 8A8341D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A8341D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 8A8341D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 8A8341D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 8A8341D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 8A8341D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CREATE 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CLOSE 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_DEVICE_CONTROL 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_POWER 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SYSTEM_CONTROL 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_PNP 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP 8A9551D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 8A9551D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 8A9551D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 8A9551D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A9551D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 8A9551D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 8A9551D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 8A9551D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 8A9551D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 8A9551D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 8A9551D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A9551D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 8A9551D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 8A9551D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CREATE 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CLOSE 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_DEVICE_CONTROL 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_INTERNAL_DEVICE_CONTROL 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_POWER 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SYSTEM_CONTROL 8A9551D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_PNP 8A9551D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 8A8341D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 8A8341D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 8A8341D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 8A8341D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 8A8341D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 8A8341D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A8341D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 8A8341D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 8A8341D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 8A8341D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 8A8341D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 8A4983C0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 8A4983C0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 8A4983C0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 8A4983C0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 8A4983C0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 8A4983C0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 8A4983C0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 8A4983C0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 8A4983C0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 8A4983C0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 8A4983C0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 8A4983C0
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CREATE 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CLOSE 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_DEVICE_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_POWER 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_SYSTEM_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_PNP 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CREATE 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CLOSE 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_DEVICE_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_POWER 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_SYSTEM_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_PNP 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_CREATE 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_CLOSE 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_DEVICE_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_POWER 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_SYSTEM_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_PNP 8A6E21D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 8A802980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 8A802980
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_CREATE 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_CLOSE 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_DEVICE_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_POWER 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_SYSTEM_CONTROL 8A6E21D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_PNP 8A6E21D8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 8A802980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 8A802980
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 8A9C61D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_READ 8A9C61D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE 8A9C61D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS 8A9C61D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL 8A9C61D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL 8A9C61D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN 8A9C61D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP 8A9C61D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER 8A9C61D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL 8A9C61D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP 8A9C61D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_CREATE 8A6B31D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_CLOSE 8A6B31D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_DEVICE_CONTROL 8A6B31D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A6B31D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_POWER 8A6B31D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_SYSTEM_CONTROL 8A6B31D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_PNP 8A6B31D8
Device \Driver\arkhl6gm \Device\Scsi\arkhl6gm1 IRP_MJ_CREATE 8A5651D8
Device \Driver\arkhl6gm \Device\Scsi\arkhl6gm1 IRP_MJ_CLOSE 8A5651D8
Device \Driver\arkhl6gm \Device\Scsi\arkhl6gm1 IRP_MJ_DEVICE_CONTROL 8A5651D8
Device \Driver\arkhl6gm \Device\Scsi\arkhl6gm1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A5651D8
Device \Driver\arkhl6gm \Device\Scsi\arkhl6gm1 IRP_MJ_POWER 8A5651D8
Device \Driver\arkhl6gm \Device\Scsi\arkhl6gm1 IRP_MJ_SYSTEM_CONTROL 8A5651D8
Device \Driver\arkhl6gm \Device\Scsi\arkhl6gm1 IRP_MJ_PNP 8A5651D8
Device \Driver\arkhl6gm \Device\Scsi\arkhl6gm1Port2Path0Target0Lun0 IRP_MJ_CREATE 8A5651D8
Device \Driver\arkhl6gm \Device\Scsi\arkhl6gm1Port2Path0Target0Lun0 IRP_MJ_CLOSE 8A5651D8
Device \Driver\arkhl6gm \Device\Scsi\arkhl6gm1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 8A5651D8
Device \Driver\arkhl6gm \Device\Scsi\arkhl6gm1Port2Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A5651D8
Device \Driver\arkhl6gm \Device\Scsi\arkhl6gm1Port2Path0Target0Lun0 IRP_MJ_POWER 8A5651D8
Device \Driver\arkhl6gm \Device\Scsi\arkhl6gm1Port2Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 8A5651D8
Device \Driver\arkhl6gm \Device\Scsi\arkhl6gm1Port2Path0Target0Lun0 IRP_MJ_PNP 8A5651D8
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_READ 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP 8A4DD3E8
Device \FileSystem\Fastfat \Fat IRP_MJ_PNP 8A4DD3E8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 8A536980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE 8A536980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 8A536980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION 8A536980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION 8A536980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION 8A536980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL 8A536980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL 8A536980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL 8A536980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN 8A536980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL 8A536980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP 8A536980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP 8A536980

—- Files - GMER 1.0.12 —-

ADS C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
ADS C:\Documents and Settings\Scott Collins\Favorites\FAVORITES\Dell.com - e-mail, sccnyy23.url:favicon
ADS C:\Documents and Settings\Scott Collins\Favorites\FAVORITES\Yahoo! Personals.url:favicon
ADS C:\Documents and Settings\Scott Collins\Favorites\Fifth Generation iPod resets when playing some mono MP3 songs and podcasts.url:favicon
ADS C:\Documents and Settings\Scott Collins\Favorites\iPod-iTunes\All things iPod, iTunes and beyond iLounge.url:favicon
ADS C:\Documents and Settings\Scott Collins\Favorites\iPod-iTunes\Apple - Support - iPod - Battery Replacement.url:favicon
ADS C:\Documents and Settings\Scott Collins\Favorites\iPod-iTunes\Apple - Support - iTunes.url:favicon
ADS C:\Documents and Settings\Scott Collins\Favorites\iPod-iTunes\http–depot.info.apple.com-.url:favicon
ADS C:\Documents and Settings\Scott Collins\Favorites\iPod-iTunes\Tips and tricks to get the most out of your iPod's battery.url:favicon
ADS C:\Documents and Settings\Scott Collins\Favorites\iPod-iTunes\Updating iPod.url:favicon
ADS C:\Documents and Settings\Scott Collins\Favorites\ISA Home.url:favicon
ADS …

—- EOF - GMER 1.0.12 —-


I would also like you to run GMER as per the earlier instructions and let me have the logs that are produced.

I don't see this one.



GMER 1.0.12.12011 - http://www.gmer.net
Autostart scan 2007-01-05 16:43:13
Windows 5.1.2600 Service Pack 2


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
AtiExtEvent@DLLName = Ati2evxx.dll
igfxcui@DLLName = igfxsrvc.dll
SDNotify@DLLName = C:\Program Files\SpywareDetector\SDNotify.dll
WgaLogon@DLLName = WgaLogon.dll

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
Ati HotKey Poller@ = %SystemRoot%\system32\Ati2evxx.exe
ATI Smart /*ATI Smart*/@ = C:\WINDOWS\SYSTEM32\ati2sgag.exe
AVG Anti-Spyware Guard /*AVG Anti-Spyware Guard*/@ = C:\Scott's Programs\AVG Anti-Spyware 7.5\guard.exe
CAISafe /*CAISafe*/@ = C:\Program Files\Yahoo!\Antivirus\ISafe.exe
Creative Service for CDROM Access /*Creative Service for CDROM Access*/@ = C:\WINDOWS\System32\CTsvcCDA.exe
DTSRVC /*Portrait Displays Display Tune Service*/@ = C:\Program Files\Gateway\EzTune\DTSRVC.exe
Fax /*Fax*/@ = %systemroot%\system32\fxssvc.exe
LightScribeService /*LightScribeService Direct Disc Labeling Service*/@ = "C:\Program Files\Common Files\LightScribe\LSSrvc.exe"
ScsiPort@ = %SystemRoot%\system32\drivers\scsiport.sys
SDhelper /*PC Tools Spyware Doctor*/@ = C:\Scott's Programs\Spyware Doctor\sdhelp.exe
SDService /*SDService*/@ = C:\Program Files\SpywareDetector\SDService.exe
Spooler /*Print Spooler*/@ = %SystemRoot%\system32\spoolsv.exe
UStorage Server Service /*UStorage Server Service*/@ = C:\WINDOWS\system32\UStorSrv.exe /Service
VETMSGNT /*VET Message Service*/@ = C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
WMDM PMSP Service /*WMDM PMSP Service*/@ = C:\WINDOWS\System32\MsPMSPSv.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@PCMService"C:\Program Files\Dell\Media Experience\PCMService.exe" = "C:\Program Files\Dell\Media Experience\PCMService.exe"
@IntelMeMC:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe = C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
@IgfxTrayC:\WINDOWS\System32\igfxtray.exe = C:\WINDOWS\System32\igfxtray.exe
@HotKeysCmdsC:\WINDOWS\System32\hkcmd.exe = C:\WINDOWS\System32\hkcmd.exe
@DVDSentryC:\WINDOWS\System32\DSentry.exe = C:\WINDOWS\System32\DSentry.exe
@diagent"C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup = "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
@2wSysTrayC:\Program Files\2Wire\2PortalMon.exe = C:\Program Files\2Wire\2PortalMon.exe
@ATIPTAC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
@CaAvTray"C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" = "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
@CAVRID"C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" = "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
@YOPC:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart = C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
@itype"C:\Program Files\Microsoft IntelliType Pro\itype.exe" = "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
@PivotSoftware"C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe" = "C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe"
@iTunesHelper"C:\Program Files\iTunes\iTunesHelper.exe" = "C:\Program Files\iTunes\iTunesHelper.exe"
@WD Button ManagerWDBtnMgr.exe = WDBtnMgr.exe
@SystemTraySDC:\Program Files\SpywareDetector\SDSystemTray.exe = C:\Program Files\SpywareDetector\SDSystemTray.exe
@SDAutoLiveupdateC:\Program Files\SpywareDetector\LiveUpdateSD.exe -AUTO /*file not found*/ = C:\Program Files\SpywareDetector\LiveUpdateSD.exe -AUTO /*file not found*/
@!AVG Anti-Spyware"C:\Scott's Programs\AVG Anti-Spyware 7.5\avgas.exe" /minimized = "C:\Scott's Programs\AVG Anti-Spyware 7.5\avgas.exe" /minimized
@SunJavaUpdateSchedC:\Program Files\Java\jre1.5.0_09\bin\jusched.exe = C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
@NeroFilterCheckC:\WINDOWS\system32\NeroCheck.exe = C:\WINDOWS\system32\NeroCheck.exe
@QuickTime Task"C:\Program Files\QuickTime\qttask.exe" -atboottime = "C:\Program Files\QuickTime\qttask.exe" -atboottime

HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@H/PC Connection Agent"C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" = "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
@ATI SchedulerC:\Program Files\ATI Multimedia\main\ATISched.EXE = C:\Program Files\ATI Multimedia\main\ATISched.EXE
@ATI DeviceDetectC:\Program Files\ATI Multimedia\main\ATIDtct.EXE = C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
@The Jim Rome ShowC:\Program Files\The Jungle Media Center\The Jungle Media Center.exe = C:\Program Files\The Jungle Media Center\The Jungle Media Center.exe
@ctfmon.exeC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
@Spyware DoctorC:\SCOTT'~1\SPYWAR~1\swdoctor.exe /Q = C:\SCOTT'~1\SPYWAR~1\swdoctor.exe /Q

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad@WPDShServiceObj = C:\WINDOWS\system32\WPDShServiceObj.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks@{57B86673-276A-48B2-BAE7-C6DBB3020EB8} = C:\Scott's Programs\AVG Anti-Spyware 7.5\shellexecutehook.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Display Panning CPL Extension*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{30D02401-6A81-11d0-8274-00C04FD5AE38} /*IE Search Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{32683183-48a0-441b-a342-7c2a440a9478} /*Media Band*/(null) =
@{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} /*Shell DocObject Viewer*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FBF23B40-E3F0-101B-8488-00AA003E56F8} /*InternetShortcut*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3C374A40-BAE4-11CF-BF7D-00AA006946EE} /*Microsoft Url History Service*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FF393560-C2A7-11CF-BFF4-444553540000} /*History*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E00-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E01-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{CFBFAE00-17A6-11D0-99CB-00C04FD64497} /*Microsoft Url Search Hook*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} /*The Internet*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{871C5380-42A0-1069-A2EA-08002B30309D} /*Internet Name Space*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} /*Shell Extensions for RealOne Player*/(null) =
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\system32\extmgr.dll = C:\WINDOWS\system32\extmgr.dll
@{1CE2AA40-1317-11D3-9922-00104B0AD431} /*CA_AntiVirus*/C:\WINDOWS\avshlext.dll = C:\WINDOWS\avshlext.dll
@{FED7043D-346A-414D-ACD7-550D052499A7} /*dBpowerAMP Music Converter 1*/C:\Scott's Programs\dBpowerAMP\dBShell.dll = C:\Scott's Programs\dBpowerAMP\dBShell.dll
@{2C49B5D0-ACE7-4D17-9DF0-A254A6C5A0C5} /*dBpowerAMP Music Converter*/C:\Scott's Programs\dBpowerAMP\dMCShell.dll = C:\Scott's Programs\dBpowerAMP\dMCShell.dll
@{5464D816-CF16-4784-B9F3-75C0DB52B499} /*Yahoo! Mail*/C:\PROGRA~1\Yahoo!\Common\ymmapi.dll = C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
@{97FA8AA2-EE77-4FF2-9449-424D8924EF21} /*IntelliType Pro Zooming Control Panel Property Page*/"C:\Program Files\Microsoft IntelliType Pro\itcplzm.dll" = "C:\Program Files\Microsoft IntelliType Pro\itcplzm.dll"
@{111D8120-25EB-4E1C-A4DF-C9EE5FCA35CB} /*IntelliType Pro Scrolling Control Panel Property Page*/"C:\Program Files\Microsoft IntelliType Pro\itcplwhl.dll" = "C:\Program Files\Microsoft IntelliType Pro\itcplwhl.dll"
@{ED6E87C6-8A83-43aa-8208-8DBC8247F4D2} /*IntelliType Pro Key Settings Control Panel Property Page*/"C:\Program Files\Microsoft IntelliType Pro\itcplkey.dll" = "C:\Program Files\Microsoft IntelliType Pro\itcplkey.dll"
@{A2569D1F-4E06-43EC-9825-0088B471BE47} /*IntelliType Pro Wireless Control Panel Property Page*/"C:\Program Files\Microsoft IntelliType Pro\itcplwir.dll" = "C:\Program Files\Microsoft IntelliType Pro\itcplwir.dll"
@{654D0431-C930-43C4-B8DA-9AA01BA5B486} /*PDI GUI Engine COM Obj*/C:\Program Files\Gateway\EzTune\HtmlEngine.dll = C:\Program Files\Gateway\EzTune\HtmlEngine.dll
@{07C45BB1-4A8C-4642-A1F5-237E7215FF66} /*IE Microsoft BrowserBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{1C1EDB47-CE22-4bbb-B608-77B48F83C823} /*IE Fade Task*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{205D7A97-F16D-4691-86EF-F3075DCCA57D} /*IE Menu Desk Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3028902F-6374-48b2-8DC6-9725E775B926} /*IE AutoComplete*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{43886CD5-6529-41c4-A707-7B3C92C05E68} /*IE Navigation Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{44C76ECD-F7FA-411c-9929-1B77BA77F524} /*IE Menu Site*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{4B78D326-D922-44f9-AF2A-07805C2A3560} /*IE Menu Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6038EF75-ABFC-4e59-AB6F-12D397F6568D} /*IE Microsoft History AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE} /*IE Tracking Shell Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6CF48EF8-44CD-45d2-8832-A16EA016311B} /*IE IShellFolderBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{73CFD649-CD48-4fd8-A272-2070EA56526B} /*IE BandProxy*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8} /*IE MRU AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E} /*IE RSS Feeder Folder*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9D958C62-3954-4b44-8FAB-C4670C1DB4C2} /*IE Microsoft Shell Folder AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{B31C5FAE-961F-415b-BAF0-E697A5178B94} /*IE Microsoft Multiple AutoComplete List Container*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BC476F4C-D9D7-4100-8D4E-E043F6DEC409} /*Microsoft Browser Architecture*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A} /*IE Shell Rebar BandSite*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{E6EE9AAC-F76B-4947-8260-A9F136138E11} /*IE Shell Band Site Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F2CF5485-4E02-4f68-819C-B92DE9277049} /*&Links*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E} /*IE Registry Tree Options Utility*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} /*IE User Assist*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FDE7673D-2E19-4145-8376-BBD58C4BC7BA} /*IE Custom MRU AutoCompleted List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{35786D3C-B075-49b9-88DD-029876E11C01} /*Portable Devices*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} /*Portable Devices Menu*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} /*iTunes*/C:\Program Files\iTunes\iTunesMiniPlayer.dll = C:\Program Files\iTunes\iTunesMiniPlayer.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Web Folders*/C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{00020D75-0000-0000-C000-000000000046} /*Microsoft Office Outlook Desktop Icon Handler*/C:\PROGRA~1\MICROS~3\OFFICE11\MLSHEXT.DLL = C:\PROGRA~1\MICROS~3\OFFICE11\MLSHEXT.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Office Outlook Custom Icon Handler*/C:\PROGRA~1\MICROS~3\OFFICE11\OLKFSTUB.DLL = C:\PROGRA~1\MICROS~3\OFFICE11\OLKFSTUB.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Program Files\Microsoft Office\OFFICE11\msohev.dll = C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
@{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} /*PowerISO*/C:\Scott's Programs\PowerISO\PWRISOSH.DLL = C:\Scott's Programs\PowerISO\PWRISOSH.DLL
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Scott's Programs\WinRAR\rarext.dll = C:\Scott's Programs\WinRAR\rarext.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved@{BDEADF00-C265-11d0-BCED-00A0C90AB50F} /*Web Folders*/ = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Scott's Programs\AVG Anti-Spyware 7.5\context.dll
CA_AntiVirus@{1CE2AA40-1317-11D3-9922-00104B0AD431} = C:\WINDOWS\avshlext.dll
moveonboot_delete@{12B23346-6BD8-4812-BF8C-75E7C386ACB8} = C:\Scott's Programs\GiPo@MoveOnBoot\mboot.dll
PowerISO@{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} = C:\Scott's Programs\PowerISO\PWRISOSH.DLL
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Scott's Programs\WinRAR\rarext.dll
Yahoo! Mail@{5464D816-CF16-4784-B9F3-75C0DB52B499} = C:\PROGRA~1\Yahoo!\Common\ymmapi.dll

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Scott's Programs\AVG Anti-Spyware 7.5\context.dll
PowerISO@{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} = C:\Scott's Programs\PowerISO\PWRISOSH.DLL
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Scott's Programs\WinRAR\rarext.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
CA_AntiVirus@{1CE2AA40-1317-11D3-9922-00104B0AD431} = C:\WINDOWS\avshlext.dll
Library@{54F51408-DD44-4a12-82EF-519AD2A80DE9} = C:\Program Files\ATI Multimedia\mlibrary\MLShell.dll /*file not found*/
PowerISO@{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} = C:\Scott's Programs\PowerISO\PWRISOSH.DLL
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Scott's Programs\WinRAR\rarext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{02478D38-C3F9-4EFB-9B51-7695ECA05670}C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll = C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
@{53707962-6F74-2D53-2644-206D7942484F}C:\Scott's Programs\Spybot - Search & Destroy\Spybot - Search & Destroy\SDHelper.dll = C:\Scott's Programs\Spybot - Search & Destroy\Spybot - Search & Destroy\SDHelper.dll
@{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}C:\Program Files\Yahoo!\Common\yiesrvc.dll = C:\Program Files\Yahoo!\Common\yiesrvc.dll
@{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}C:\SCOTT'~1\SPYWAR~1\tools\iesdsg.dll = C:\SCOTT'~1\SPYWAR~1\tools\iesdsg.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll = C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
@{B56A7D7D-6927-48C8-A975-17DF180C71AC}C:\SCOTT'~1\SPYWAR~1\tools\iesdpb.dll = C:\SCOTT'~1\SPYWAR~1\tools\iesdpb.dll

HKCU\Control Panel\[removed] = C:\WINDOWS\System32\logon.scr

HKLM\Software\Microsoft\Internet Explorer\Plugins\Extension\.spop@Location = C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Start Pageabout:blank = about:blank
@Local PageC:\WINDOWS\SYSTEM32\blank.htm = C:\WINDOWS\SYSTEM32\blank.htm

HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://my.yahoo.com = http://my.yahoo.com
@Local Page\blank.htm = \blank.htm

HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
mctp@CLSID = C:\Program Files\Microsoft ActiveSync\aatp.dll
mhtml@CLSID = %SystemRoot%\System32\inetcomm.dll
mso-offdap@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
mso-offdap11@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\System32\wiascr.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
000000000001@PackedCatalogItem = C:\WINDOWS\system32\VetRedir.dll
000000000002@PackedCatalogItem = C:\WINDOWS\system32\VetRedir.dll
000000000003@PackedCatalogItem = C:\WINDOWS\system32\VetRedir.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009@PackedCatalogItem = C:\WINDOWS\system32\VetRedir.dll

C:\Documents and Settings\Scott Collins\Start Menu\Programs\Startup >>>
DESKTOP.INI = DESKTOP.INI
Wallpaper Changer.lnk = Wallpaper Changer.lnk

C:\Documents and Settings\All Users\Start Menu\Programs\Startup >>>
DESKTOP.INI = DESKTOP.INI
WD Backup Monitor.lnk = WD Backup Monitor.lnk

—- EOF - GMER 1.0.12 —-
These two files can go then:

c:\windows\inf\satmat.inf
c:\windows\iedb.dll


I think that that is about it. If you don't want to use the AVG A-S Resident Guard, do the following:
  • Go to Start > Run, enter services.msc and hit OK.
  • Locate and right click AVG Anti-Spyware Guard
  • Select Properties from the menu.
  • Under the General Tab, change the Service status: to Stopped and then the Startup type: to Disabled.
You don't need to have this service running if you aren't using the guard.
Once the trial period has expired, you will need to do this unless you upgrade as well.

I want you to run your PC as normal for a few days and when you are happy that everything is fine, do the following:

Update your anti-virus program,
Disable System Restore,
Boot into Safe Mode,
Scan your computer for viruses.
When you get the all clear, reboot into Normal Mode.
Re-enable System Restore,
Create a Restore Point.
This will give a clean Restore Point should you need it in the future.
A tutorial for System Restore is available here.

The reason for waiting is that if removing the malware has caused a problem, which it occasionally does, you can put your PC back to how it was before the fix. This will re-install the malware, but an infected PC is better than an expensive paperweight!

Some bedtime reading: This is a very good tutorial about keeping your computer safe and secure on the internet.
Noviciate I have deleted the two files: c:\windows\inf\satmat.inf c:\windows\iedb.dl I may end up getting the full version of AVG Anti-Spyware Guard, it looks like it catches a lot of things the others do not. If I end up not going with it, I will disable the guard at that point. I will also follow you advice and create a system restore point after I am convinced my computer is running fine in a few days. This will also give me time to go over the article you included about how to keep you computer safe. Once again, THANK YOU VERY MUCH!!!!!!!!! You did not have to take the time and assist me. You made my life much less stressful. THANK YOU!
Always a pleasure, never an imposition. :wavey: Since the issue appears to be resolved, this thread will now be locked. If you need this topic reopened, please contact a staff member with the address of this thread.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI