This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Various Processes(?) Want To Be Deleted

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

For the last few weeks I've had popups from Webroot Spy Sweeper saying that SVCHOST.EXE wants to delete tunnel, tcpip, tcpip6, net6t and BFE. In addtion, MSI EXEC wants to delete bwipt6 and WDFNet. Once in a while, WMIAPSRV wants to get rid of wmiApRpl.

Neither deleting these files or leaving them alone does anything useful because they keep coming back, asking to be deleted again.


Here's the Hijack This log:

Logfile of HijackThis v1.99.1
Scan saved at 8:40:07 PM, on 12/2/2007
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16546)

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell Photo AIO Printer 966\memcard.exe
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\NETGEAR\WG311T\wlancfg5.exe
C:\Program Files\Lunabar\Lunabar.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Webroot\Desktop Firewall\WDF.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Novatix\ExplorerPlus\NxExplo.exe
C:\Program Files\Novatix\ExplorerPlus\NXExplo.exe
C:\Users\ADMINI~1\AppData\Local\Temp\~~NXTEMP\HijackThis.exe
C:\Program Files\NoteTab Light\NoteTab.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [NvSvc] "RUNDLL32.EXE" C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 966\memcard.exe"
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [Webroot Desktop Firewall] "C:\Program Files\Webroot\Desktop Firewall\WDF.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\windows sidebar\sidebar.exe" /autoRun
O4 - HKCU\..\Run: [quickstart.exe] "C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe"
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: Lunabar.lnk = C:\Program Files\Lunabar\Lunabar.exe
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: NETGEAR WG311T Smart Wizard.lnk = C:\Program Files\NETGEAR\WG311T\wlancfg5.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {FFD85DC8-5261-4D11-B728-F7C59D911691} (iolo.ProductDetector) - http://www.iolo.com/app/ocx/UpgradeVerify.ocx
O20 - Winlogon Notify: WRNotifier - C:\Windows\SYSTEM32\WRLogonNTF.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: dlcq_device - - C:\Windows\system32\dlcqcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: iolo Product Update Service (ioloProductUpdate) - Unknown owner - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic 7\IoloSGCtrl.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
O23 - Service: Webroot Desktop Firewall network service (WDFNet) - Webroot Software, Inc. - C:\Program Files\Webroot\Desktop Firewall\wdfsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
Run this online scan from ESET
to check for additional infections from the malware.
You will need to use Internet explorer for this scan!
  • First, accept the Terms of Use
  • Click: Start
  • When asked, allow the ActiveX control to install
  • Click: Start
  • Make sure the options:
    Remove found threats, and Scan unwanted applications
    are both checked!
  • Click: Scan

When the scan finishes, use Notepad to open the ESET report.
It will be located here C:\Program Files\EsetOnlineScanner\log.txt
Using IE, the following steps were performed:

  • First, accept the Terms of Use
  • Click: Start
  • When asked, allow the ActiveX control to install
  • Click: Start

ESet responded with "Administrator rights required".
How do I enable Admin Rights at this point?
Here's the ESET report: # version=4 # OnlineScanner.ocx=1.0.0.56 # OnlineScannerDLLA.dll=1, 0, 0, 51 # OnlineScannerDLLW.dll=1, 0, 0, 51 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=2713 (20071210) # vers_arch_module=1.059 (20071108) # vers_adv_heur_module=1.064 (20070717) # EOSSerial=b98db1cc6b5be7408466aba6a26e8782 # end=finished # remove_checked=true # unwanted_checked=true # utc_time=2007-12-10 03:56:45 # local_time=2007-12-10 10:56:45 (-0500, Eastern Standard Time) # country="United States" # osver=6.0.6000 NT # scanned=350856 # found=0 # scan_time=2613
Download and install AVG Anti-Spyware (ewido). Then scan and post the report here.
Instructions and download link can be found here.

Also post a new hijackthis log when done. Reboot before scanning.
After running AVGAS, I realized that I hadn't rebooted before scanning. If this is significant, I'll redo it.

AVGAS report:

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 4:49:47 PM 12/11/2007

+ Scan result:



Nothing found.



::Report end

———–
An earlier AVGAS scan (Dec 8, 2007) found only six tracking cookies, which it deleted. (scan report is available if it's useful).
———–

HiJackThis report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:47:45 PM, on 12/11/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16546)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Windows\system32\dlcqcoms.exe
C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
C:\Program Files\iolo\System Mechanic 7\IoloSGCtrl.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\PSIService.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Webroot\Desktop Firewall\wdfsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell Photo AIO Printer 966\memcard.exe
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
C:\Program Files\Webroot\Desktop Firewall\WDF.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\NETGEAR\WG311T\wlancfg5.exe
C:\Program Files\Lunabar\Lunabar.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\iolo\System Mechanic 7\SMSystemAnalyzer.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WxEx\WxEx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Novatix\ExplorerPlus\NxExplo.exe
C:\Windows\system32\wbem\WmiApSrv.exe
C:\Program Files\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [NvSvc] "RUNDLL32.EXE" C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 966\memcard.exe"
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [Webroot Desktop Firewall] "C:\Program Files\Webroot\Desktop Firewall\WDF.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\windows sidebar\sidebar.exe" /autoRun
O4 - HKCU\..\Run: [quickstart.exe] "C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe"
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Lunabar.lnk = C:\Program Files\Lunabar\Lunabar.exe
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: NETGEAR WG311T Smart Wizard.lnk = C:\Program Files\NETGEAR\WG311T\wlancfg5.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O13 - Gopher Prefix:
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {FFD85DC8-5261-4D11-B728-F7C59D911691} (iolo.ProductDetector) - http://www.iolo.com/app/ocx/UpgradeVerify.ocx
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: dlcq_device - - C:\Windows\system32\dlcqcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: iolo Product Update Service (ioloProductUpdate) - Unknown owner - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic 7\IoloSGCtrl.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
O23 - Service: Webroot Desktop Firewall network service (WDFNet) - Webroot Software, Inc. - C:\Program Files\Webroot\Desktop Firewall\wdfsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 10291 bytes



———-
NOTE THIS:
A week or two ago, Webroot's Spy Sweeper notified me that an error had occurred. I sent the generated log file to Webroot, who replied with an email titled "Phone Home", asking me to run an exe they provided and to send them the report generated by that app. Running the app populated my desktop with 2-3 dozen files which then deleted themselves, but the desired report was not generated. I just found out today that "Phone Home" refers to a type of malware.

It has begun to dawn on me that something is amiss.
I suppose the problems described at the top of this thread (SVCHOST.EXE, and others, wanting to delete various files, might be caused by some peculiar file corruption, but that doesn't seem too likely. Is there anywhere else I might go for assistance do you think?
Lets try running combofix.exe
Download it from one of the links below:
Note:
It is important that it is saved directly to your desktop

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Double click combofix.exe & follow the prompts.
When finished, it will produce a log for you. Post that log in your next reply.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall
First, running ComboFix immediately pops up the REG.EXE error message seen in the atttached JPG:

And here's the ComboFix report:
==================
ComboFix 07-12-12.3 - Administrate 2007-12-12 11:16:21.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.321 [GMT -5:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Windows\system32\ps.exe

.
((((((((((((((((((((((((( Files Created from 2007-11-12 to 2007-12-12 )))))))))))))))))))))))))))))))
.

2007-12-11 19:37 . 2007-12-11 19:37 1,327,104 –a—— C:\Windows\System32\quartz.dll
2007-12-11 19:37 . 2007-12-11 19:37 223,232 –a—— C:\Windows\System32\WMASF.DLL
2007-12-11 19:37 . 2007-12-11 19:37 9,728 –a—— C:\Windows\System32\LAPRXY.DLL
2007-12-11 19:37 . 2007-12-11 19:37 2,048 –a—— C:\Windows\System32\asferror.dll
2007-12-11 19:35 . 2007-12-11 19:35 130,048 –a—— C:\Windows\System32\drivers\srv2.sys
2007-12-11 19:35 . 2007-12-11 19:35 101,888 –a—— C:\Windows\System32\drivers\mrxsmb.sys
2007-12-11 19:35 . 2007-12-11 19:35 84,992 –a—— C:\Windows\System32\drivers\srvnet.sys
2007-12-11 19:35 . 2007-12-11 19:35 58,368 –a—— C:\Windows\System32\drivers\mrxsmb20.sys
2007-12-11 19:33 . 2007-12-11 19:33 3,504,824 –a—— C:\Windows\System32\ntkrnlpa.exe
2007-12-11 19:33 . 2007-12-11 19:33 3,470,520 –a—— C:\Windows\System32\ntoskrnl.exe
2007-12-11 19:31 . 2007-12-11 19:31 2,048 –a—— C:\Windows\System32\tzres.dll
2007-12-11 16:02 . 2007-12-11 16:02 d——– C:\Users\All Users\Grisoft
2007-12-11 16:02 . 2007-12-11 16:02 d——– C:\ProgramData\Grisoft
2007-12-03 14:53 . 2007-12-03 14:53 d——– C:\Users\Administrate\AppData\Roaming\Uniblue
2007-12-03 14:50 . 1999-03-15 16:39 212,992 –a—— C:\Windows\ALCHUNIN.EXE
2007-12-03 14:50 . 2003-11-28 09:56 36,864 –a—— C:\Windows\Ultimate Screen Clock.scr
2007-11-29 20:01 . 2007-11-29 20:01 d——– C:\Program Files\DanAgonistes
2007-11-27 17:52 . 2007-11-27 17:54 d——– C:\Users\Administrate\{725d0b59-11fa-44de-a2df-a2d5f6180949}
2007-11-21 16:20 . 2007-11-21 16:23 d——– C:\Users\Administrate\AppData\Roaming\RaimaRadio
2007-11-21 16:20 . 2007-11-21 16:20 d——– C:\Program Files\RaimaRadio
2007-11-21 11:40 . 2007-12-07 17:06 273 –a—— C:\Windows\SysMech7.INI
2007-11-21 09:47 . 2007-11-20 11:13 370,536 –a—— C:\Windows\System32\Incinerator.dll
2007-11-21 09:47 . 2007-11-17 12:01 23,552 –a—— C:\Windows\System32\smrgdf.exe
2007-11-13 15:49 . 2007-11-13 15:49 224,768 –a—— C:\Windows\System32\drivers\usbport.sys
2007-11-13 15:49 . 2007-11-13 15:49 192,000 –a—— C:\Windows\System32\drivers\usbhub.sys
2007-11-13 15:49 . 2007-11-13 15:49 73,216 –a—— C:\Windows\System32\drivers\usbccgp.sys
2007-11-13 15:49 . 2007-11-13 15:49 38,400 –a—— C:\Windows\System32\drivers\usbehci.sys
2007-11-13 15:49 . 2007-11-13 15:49 19,456 –a—— C:\Windows\System32\drivers\usbohci.sys
2007-11-13 15:49 . 2007-11-13 15:49 8,704 –a—— C:\Windows\System32\hcrstco.dll
2007-11-13 15:49 . 2007-11-13 15:49 8,704 –a—— C:\Windows\System32\hccoin.dll
2007-11-13 15:49 . 2007-11-13 15:49 5,888 –a—— C:\Windows\System32\drivers\usbd.sys
2007-11-13 15:48 . 2007-11-13 15:48 1,244,672 –a—— C:\Windows\System32\mcmde.dll
2007-11-13 15:26 . 2007-11-13 15:27 d——– C:\Program Files\QuickTime

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-12 11:56 ——— d—–w C:\Users\Administrate\AppData\Roaming\OpenOffice.org2
2007-12-12 11:56 ——— d—–w C:\Program Files\Dl_cats
2007-12-12 00:36 56,320 —-a-w C:\Windows\System32\iesetup.dll
2007-12-12 00:36 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-12 00:36 26,624 —-a-w C:\Windows\System32\ieUnatt.exe
2007-12-05 12:18 ——— d—–w C:\Program Files\OpenOffice.org 2.3
2007-12-02 22:38 ——— d—–w C:\Program Files\Picasa2
2007-12-02 21:19 ——— d—–w C:\Users\Administrate\AppData\Roaming\PC Magazine Utilities
2007-12-02 21:18 ——— d—–w C:\Program Files\PC Magazine Utilities
2007-11-28 20:31 ——— d—–w C:\Users\Administrate\AppData\Roaming\ExplorerPlus
2007-11-21 14:48 ——— d—–w C:\ProgramData\iolo
2007-11-18 15:17 ——— d—–w C:\Users\Administrate\AppData\Roaming\iolo
2007-11-14 01:35 696 —-a-w C:\Users\Administrate\AppData\Roaming\wklnhst.dat
2007-11-13 20:51 704,000 —-a-w C:\Windows\System32\PhotoScreensaver.scr
2007-11-13 20:51 67,584 —-a-w C:\Windows\System32\wlanhlp.dll
2007-11-13 20:51 542,720 —-a-w C:\Windows\System32\sysmain.dll
2007-11-13 20:51 502,784 —-a-w C:\Windows\System32\wlansvc.dll
2007-11-13 20:51 47,104 —-a-w C:\Windows\System32\wlanapi.dll
2007-11-13 20:51 297,984 —-a-w C:\Windows\System32\wlansec.dll
2007-11-13 20:51 290,816 —-a-w C:\Windows\System32\wlanmsm.dll
2007-11-13 20:51 258,232 —-a-w C:\Windows\system32\drivers\acpi.sys
2007-11-13 20:51 24,064 —-a-w C:\Windows\System32\wtsapi32.dll
2007-11-13 20:51 2,923,520 —-a-w C:\Windows\explorer.exe
2007-11-13 20:51 2,027,008 —-a-w C:\Windows\System32\win32k.sys
2007-11-13 20:48 ——— d—–w C:\Program Files\Windows Mail
2007-11-08 23:05 ——— d—–w C:\Program Files\Webroot
2007-10-23 19:40 ——— d—–w C:\Program Files\Wheelhouse
2007-10-20 18:20 78,168 —-a-w C:\Windows\system32\drivers\pwipf6.sys
2007-10-20 18:20 177,496 —-a-w C:\Windows\System32\wdfproc.dll
2007-10-19 18:56 ——— d—–w C:\ProgramData\Webroot
2007-10-18 20:08 ——— d—–w C:\Program Files\Common Files\Intuit
2007-10-18 20:03 ——— d—–w C:\Program Files\Google
2007-10-18 17:20 164 —-a-w C:\install.dat
2007-10-17 21:01 ——— d—–w C:\Users\Administrate\AppData\Roaming\NoteTab Light
2007-10-17 20:57 ——— d—–w C:\Program Files\NoteTab Light
2007-10-10 11:32 8,147,968 —-a-w C:\Windows\System32\wmploc.DLL
2007-10-10 11:32 7,680 —-a-w C:\Windows\System32\spwmp.dll
2007-10-10 11:32 4,096 —-a-w C:\Windows\System32\dxmasf.dll
2007-10-10 11:32 356,864 —-a-w C:\Windows\System32\MediaMetadataHandler.dll
2007-10-10 11:30 84,480 —-a-w C:\Windows\System32\INETRES.dll
2007-10-10 11:30 788,992 —-a-w C:\Windows\System32\rpcrt4.dll
2007-10-10 11:30 737,792 —-a-w C:\Windows\System32\inetcomm.dll
2007-10-01 20:40 1,526,072 —-a-w C:\Windows\WRSetup.dll
2007-09-20 18:12 12,800 —-a-w C:\Windows\System32\elrawdsk.sys
2007-08-30 12:36 174 –sha-w C:\Program Files\desktop.ini
2007-03-06 21:06 963,072 —-a-w C:\Windows\inf\WG311T\WG311Tx.sys
2007-03-06 21:03 782,848 —-a-w C:\Windows\inf\WG311T\WG311T13.sys
2006-10-27 03:05 28,672 —-a-w C:\Windows\inf\WG311T\SetDrv.exe
2006-04-25 21:30 35,232 —-a-w C:\Windows\inf\WG311T\ME_INST.EXE
2006-04-25 21:30 26,112 —-a-w C:\Windows\inf\WG311T\install.exe
2007-09-04 19:44 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-09-04 19:44 32,768 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-09-04 19:44 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\windows sidebar\sidebar.exe" [2006-11-02 07:35]
"quickstart.exe"="C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe" []
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 07:36]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2007-12-03 14:46]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="RUNDLL32.exe" [2006-11-02 04:45 C:\Windows\System32\rundll32.exe]
"NvCplDaemon"="RUNDLL32.exe" [2006-11-02 04:45 C:\Windows\System32\rundll32.exe]
"NvMediaCenter"="RUNDLL32.exe" [2006-11-02 04:45 C:\Windows\System32\rundll32.exe]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 966\memcard.exe" [2006-12-12 03:22]
"DLCQCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-16 00:31]
"dlcqmon.exe"="C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe" [2006-12-12 03:22]
"FaxCenterServer"="C:\Program Files\Dell PC Fax\fm3032.exe" [2006-12-12 03:22]
"Webroot Desktop Firewall"="C:\Program Files\Webroot\Desktop Firewall\WDF.exe" [2007-10-20 13:20]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-05-24 17:00]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 13:42]
"iolo Startup"="C:\Program Files\iolo\Common\Lib\ioloLManager.exe" [2007-11-17 17:43]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-10-01 15:40]

C:\Users\Administrate\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Lunabar.lnk - C:\Program Files\Lunabar\Lunabar.exe [2007-05-26 11:12:21]
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 21:57:56]
WordWeb Pro.lnk - C:\Program Files\WordWeb\wweb32.exe [2007-06-11 15:04:05]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-04-04 14:06:20]
NETGEAR WG311T Smart Wizard.lnk - C:\Program Files\NETGEAR\WG311T\wlancfg5.exe [2007-04-10 18:09:06]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

R0 CLFS;Common Log (CLFS);C:\Windows\system32\CLFS.sys
R0 crcdisk;Crcdisk Filter Driver;C:\Windows\system32\drivers\crcdisk.sys
R0 Ecache;ReadyBoost Caching Driver;C:\Windows\system32\drivers\ecache.sys
R0 FileInfo;File Information FS MiniFilter;C:\Windows\system32\drivers\fileinfo.sys
R0 msisadrv;ISA/EISA Class Driver;C:\Windows\system32\drivers\msisadrv.sys
R0 nvstor;nvstor;C:\Windows\system32\drivers\nvstor.sys
R0 nvstor32;nvstor32;C:\Windows\system32\DRIVERS\nvstor32.sys
R0 spldr;Security Processor Loader Driver;C:\Windows\system32\drivers\spldr.sys
R0 SSFS0BB9;Spy Sweeper File System Filer Driver: 0BB9;C:\Windows\system32\Drivers\SSFS0BB9.SYS
R0 volmgr;Volume Manager Driver;C:\Windows\system32\drivers\volmgr.sys
R0 volmgrx;Dynamic Volume Manager;C:\Windows\system32\drivers\volmgrx.sys
R1 DfsC;Dfs Client Driver;C:\Windows\system32\Drivers\dfsc.sys
R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS
R1 ElRawDisk;ElRawDisk;\??\C:\Windows\system32\drivers\elrawdsk.sys
R1 nsiproxy;NSI proxy service;C:\Windows\system32\drivers\nsiproxy.sys
R1 pwipf6;Privacyware Filter Driver;C:\Windows\system32\DRIVERS\pwipf6.sys
R1 RDPENCDD;RDP Encoder Mirror Driver;C:\Windows\system32\drivers\rdpencdd.sys
R1 Smb;Message-oriented TCP/IP and TCP/IPv6 Protocol (SMB session);C:\Windows\system32\DRIVERS\smb.sys
R1 tdx;NetIO Legacy TDI Support Driver;C:\Windows\system32\DRIVERS\tdx.sys
R1 Wanarpv6;Remote Access IPv6 ARP Driver;C:\Windows\system32\DRIVERS\wanarp.sys
R2 AeLookupSvc;Application Experience;C:\Windows\system32\svchost.exe -k netsvcs
R2 AudioEndpointBuilder;Windows Audio Endpoint Builder;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
R2 BFE;Base Filtering Engine;C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
R2 dlcq_device;dlcq_device;C:\Windows\system32\dlcqcoms.exe -service
R2 DPS;Diagnostic Policy Service;C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
R2 EMDMgmt;ReadyBoost;C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
R2 FDResPub;Function Discovery Resource Publication;C:\Windows\system32\svchost.exe -k LocalService
R2 gpsvc;Group Policy Client;C:\Windows\system32\svchost.exe -k netsvcs
R2 IKEEXT;IKE and AuthIP IPsec Keying Modules;C:\Windows\system32\svchost.exe -k netsvcs
R2 ioloFileInfoList;iolo FileInfoList Service;C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
R2 ioloProductUpdate;iolo Product Update Service;C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
R2 ioloSystemService;iolo System Service;C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
R2 iphlpsvc;IP Helper;C:\Windows\System32\svchost.exe -k NetSvcs
R2 KtmRm;KtmRm for Distributed Transaction Coordinator;C:\Windows\System32\svchost.exe -k NetworkService
R2 lltdio;Link-Layer Topology Discovery Mapper I/O Driver;C:\Windows\system32\DRIVERS\lltdio.sys
R2 luafv;UAC File Virtualization;C:\Windows\system32\drivers\luafv.sys
R2 MMCSS;Multimedia Class Scheduler;C:\Windows\system32\svchost.exe -k netsvcs
R2 MpsSvc;Windows Firewall;C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
R2 netprofm;Network List Service;C:\Windows\System32\svchost.exe -k LocalService
R2 NlaSvc;Network Location Awareness;C:\Windows\System32\svchost.exe -k NetworkService
R2 nsi;Network Store Interface Service;C:\Windows\system32\svchost.exe -k LocalService
R2 PcaSvc;Program Compatibility Assistant Service;C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
R2 PEAUTH;PEAUTH;C:\Windows\system32\drivers\peauth.sys
R2 ProfSvc;User Profile Service;C:\Windows\system32\svchost.exe -k netsvcs
R2 slsvc;Software Licensing;C:\Windows\system32\SLsvc.exe
R2 SysMain;Superfetch;C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
R2 TabletInputService;Tablet PC Input Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
R2 tcpipreg;TCP/IP Registry Compatibility;C:\Windows\system32\drivers\tcpipreg.sys
R2 UxSms;Desktop Window Manager Session Manager;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
R2 WDFNet;Webroot Desktop Firewall network service;C:\Program Files\Webroot\Desktop Firewall\wdfsvc.exe
R2 WerSvc;Windows Error Reporting Service;C:\Windows\System32\svchost.exe -k WerSvcGroup
R2 Wlansvc;WLAN AutoConfig;C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
R2 WPDBusEnum;Portable Device Enumerator Service;C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys
R3 Appinfo;Application Information;C:\Windows\system32\svchost.exe -k netsvcs
R3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\WG311T13.sys
R3 bowser;Bowser;C:\Windows\system32\DRIVERS\bowser.sys
R3 DXGKrnl;LDDM Graphics Subsystem;C:\Windows\system32\drivers\dxgkrnl.sys
R3 EapHost;Extensible Authentication Protocol;C:\Windows\System32\svchost.exe -k netsvcs
R3 fdPHost;Function Discovery Provider Host;C:\Windows\system32\svchost.exe -k LocalService
R3 iScsiPrt;iScsiPort Driver;C:\Windows\system32\DRIVERS\msiscsi.sys
R3 KeyIso;CNG Key Isolation;C:\Windows\system32\lsass.exe
R3 monitor;Microsoft Monitor Class Function Driver Service;C:\Windows\system32\DRIVERS\monitor.sys
R3 mpsdrv;Windows Firewall Authorization Driver;C:\Windows\system32\drivers\mpsdrv.sys
R3 mrxsmb10;SMB 1.x MiniRedirector;C:\Windows\system32\DRIVERS\mrxsmb10.sys
R3 mrxsmb20;SMB 2.0 MiniRedirector;C:\Windows\system32\DRIVERS\mrxsmb20.sys
R3 NativeWifiP;NativeWiFi Filter;C:\Windows\system32\DRIVERS\nwifi.sys
R3 nvlddmkm;nvlddmkm;C:\Windows\system32\DRIVERS\nvlddmkm.sys
R3 srv2;srv2;C:\Windows\system32\DRIVERS\srv2.sys
R3 srvnet;srvnet;C:\Windows\system32\DRIVERS\srvnet.sys
R3 tunnel;Microsoft IPv6 Tunnel Miniport Adapter Driver;C:\Windows\system32\DRIVERS\tunnel.sys
R3 umbus;UMBus Enumerator Driver;C:\Windows\system32\DRIVERS\umbus.sys
R3 WdiSystemHost;Diagnostic System Host;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\Windows\system32\DRIVERS\A3AB.sys
S3 BrFiltLo;Brother USB Mass-Storage Lower Filter Driver;C:\Windows\system32\drivers\brfiltlo.sys
S3 BrFiltUp;Brother USB Mass-Storage Upper Filter Driver;C:\Windows\system32\drivers\brfiltup.sys
S3 BrUsbSer;Brother MFC USB Serial WDM Driver;C:\Windows\system32\drivers\brusbser.sys
S3 CertPropSvc;Certificate Propagation;C:\Windows\system32\svchost.exe -k netsvcs
S3 DFSR;DFS Replication;C:\Windows\system32\DFSR.exe
S3 dot3svc;Wired AutoConfig;C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
S3 E1G60;Intel® PRO/1000 NDIS 6 Adapter Driver;C:\Windows\system32\DRIVERS\E1G60I32.sys
S3 Filetrace;FileTrace;C:\Windows\system32\drivers\filetrace.sys
S3 hkmsvc;Health Key and Certificate Management;C:\Windows\System32\svchost.exe -k netsvcs
S3 IPBusEnum;PnP-X IP Bus Enumerator;C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
S3 lltdsvc;Link-Layer Topology Discovery Mapper;C:\Windows\System32\svchost.exe -k LocalService
S3 MSiSCSI;Microsoft iSCSI Initiator Service;C:\Windows\system32\svchost.exe -k netsvcs
S3 MsRPC;MsRPC;C:\Windows\system32\drivers\MsRPC.sys
S3 napagent;Network Access Protection Agent;C:\Windows\System32\svchost.exe -k NetworkService
S3 p2pimsvc;Peer Networking Identity Manager;C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
S3 p2psvc;Peer Networking Grouping;C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
S3 pla;Performance Logs & Alerts;C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
S3 PNRPAutoReg;PNRP Machine Name Publication Service;C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
S3 PNRPsvc;Peer Name Resolution Protocol;C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
S3 QWAVE;Quality Windows Audio Video Experience;C:\Windows\system32\svchost.exe -k LocalService
S3 QWAVEdrv;QWAVE driver;C:\Windows\system32\drivers\qwavedrv.sys
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys
S3 SCPolicySvc;Smart Card Removal Policy;C:\Windows\system32\svchost.exe -k netsvcs
S3 SDRSVC;Windows Backup;C:\Windows\system32\svchost.exe -k SDRSVC
S3 SessionEnv;Terminal Services Configuration;C:\Windows\System32\svchost.exe -k netsvcs
S3 sffp_mmc;SFF Storage Protocol Driver for MMC;C:\Windows\system32\drivers\sffp_mmc.sys
S3 SLUINotify;SL UI Notification Service;C:\Windows\system32\svchost.exe -k LocalService
S3 TBS;TPM Base Services;C:\Windows\System32\svchost.exe -k LocalService
S3 THREADORDER;Thread Ordering Server;C:\Windows\system32\svchost.exe -k LocalService
S3 TrustedInstaller;Windows Modules Installer;C:\Windows\servicing\TrustedInstaller.exe
S3 tssecsrv;Terminal Services Security Filter Driver;C:\Windows\system32\DRIVERS\tssecsrv.sys
S3 UI0Detect;Interactive Services Detection;C:\Windows\system32\UI0Detect.exe
S3 uliagpkx;Uli AGP Bus Filter;C:\Windows\system32\drivers\uliagpkx.sys
S3 vga;vga;C:\Windows\system32\DRIVERS\vgapnp.sys
S3 wcncsvc;Windows Connect Now - Config Registrar;C:\Windows\System32\svchost.exe -k LocalService
S3 WcsPlugInService;Windows Color System;C:\Windows\system32\svchost.exe -k wcssvc
S3 WdiServiceHost;Diagnostic Service Host;C:\Windows\System32\svchost.exe -k wdisvc
S3 Wecsvc;Windows Event Collector;C:\Windows\system32\svchost.exe -k NetworkService
S3 wercplsupport;Problem Reports and Solutions Control Panel Support;C:\Windows\System32\svchost.exe -k netsvcs
S3 WinHttpAutoProxySvc;WinHTTP Web Proxy Auto-Discovery Service;C:\Windows\system32\svchost.exe -k LocalService
S3 WinRM;Windows Remote Management (WS-Management);C:\Windows\System32\svchost.exe -k NetworkService
S3 WPCSvc;Parental Controls;C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
S4 adp94xx;adp94xx;C:\Windows\system32\drivers\adp94xx.sys
S4 adpahci;adpahci;C:\Windows\system32\drivers\adpahci.sys
S4 amdide;amdide;C:\Windows\system32\drivers\amdide.sys
S4 arc;arc;C:\Windows\system32\drivers\arc.sys
S4 arcsas;arcsas;C:\Windows\system32\drivers\arcsas.sys
S4 Brserid;Brother MFC Serial Port Interface Driver (WDM);C:\Windows\system32\drivers\brserid.sys
S4 BrSerWdm;Brother WDM Serial driver;C:\Windows\system32\drivers\brserwdm.sys
S4 BrUsbMdm;Brother MFC USB Fax Only Modem;C:\Windows\system32\drivers\brusbmdm.sys
S4 circlass;Consumer IR Devices;C:\Windows\system32\drivers\circlass.sys
S4 Crusoe;Transmeta Crusoe Processor Driver;C:\Windows\system32\drivers\crusoe.sys
S4 elxstor;elxstor;C:\Windows\system32\drivers\elxstor.sys
S4 HpCISSs;HpCISSs;C:\Windows\system32\drivers\hpcisss.sys
S4 iaStorV;Intel RAID Controller Vista;C:\Windows\system32\drivers\iastorv.sys
S4 iirsp;iirsp;C:\Windows\system32\drivers\iirsp.sys
S4 IPMIDRV;IPMIDRV;C:\Windows\system32\drivers\ipmidrv.sys
S4 iteraid;ITERAID_Service_Install;C:\Windows\system32\drivers\iteraid.sys
S4 LSI_FC;LSI_FC;C:\Windows\system32\drivers\lsi_fc.sys
S4 LSI_SAS;LSI_SAS;C:\Windows\system32\drivers\lsi_sas.sys
S4 LSI_SCSI;LSI_SCSI;C:\Windows\system32\drivers\lsi_scsi.sys
S4 Mcx2Svc;Windows Media Center Extender Service;C:\Windows\system32\svchost.exe -k LocalService
S4 megasas;megasas;C:\Windows\system32\drivers\megasas.sys
S4 mpio;Microsoft Multi-Path Bus Driver;C:\Windows\system32\drivers\mpio.sys
S4 msahci;msahci;C:\Windows\system32\drivers\msahci.sys
S4 msdsm;Microsoft Multi-Path Device Specific Module;C:\Windows\system32\drivers\msdsm.sys
S4 nfrd960;nfrd960;C:\Windows\system32\drivers\nfrd960.sys
S4 ntrigdigi;N-trig HID Tablet Driver;C:\Windows\system32\drivers\ntrigdigi.sys
S4 ql2300;QLogic Fibre Channel Miniport Driver;C:\Windows\system32\drivers\ql2300.sys
S4 ql40xx;QLogic iSCSI Miniport Driver;C:\Windows\system32\drivers\ql40xx.sys
S4 SiSRaid2;SiSRaid2;C:\Windows\system32\drivers\sisraid2.sys
S4 SiSRaid4;SiSRaid4;C:\Windows\system32\drivers\sisraid4.sys
S4 uliahci;uliahci;C:\Windows\system32\drivers\uliahci.sys
S4 ulsata2;ulsata2;C:\Windows\system32\drivers\ulsata2.sys
S4 usbcir;eHome Infrared Receiver (USBCIR);C:\Windows\system32\drivers\usbcir.sys
S4 ViaC7;VIA C7 Processor Driver;C:\Windows\system32\drivers\viac7.sys
S4 vsmraid;vsmraid;C:\Windows\system32\drivers\vsmraid.sys
S4 WacomPen;Wacom Serial Pen HID Driver;C:\Windows\system32\drivers\wacompen.sys
S4 Wd;Microsoft Watchdog Timer Driver;C:\Windows\system32\drivers\wd.sys

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService REG_MULTI_SZ nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE Mcx2Svc WebClient
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
NetworkServiceNetworkRestricted REG_MULTI_SZ PolicyAgent
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc ehstart
NetworkService REG_MULTI_SZ CryptSvc DHCP TermService KtmRm DNSCache NapAgent nlasvc WinRM WECSVC Tapisrv
WerSvcGroup REG_MULTI_SZ wersvc
swprv REG_MULTI_SZ swprv
LocalServiceNetworkRestricted REG_MULTI_SZ DHCP eventlog AudioSrv LmHosts wscsvc p2pimsvc PNRPSvc p2psvc WPCSvc PnrpAutoReg
regsvc REG_MULTI_SZ RemoteRegistry
wcssvc REG_MULTI_SZ WcsPlugInService
DcomLaunch REG_MULTI_SZ PlugPlay DcomLaunch
wdisvc REG_MULTI_SZ WdiServiceHost
sdrsvc REG_MULTI_SZ sdrsvc
secsvcs REG_MULTI_SZ WinDefend

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
AeLookupSvc
wercplsupport
Themes
CertPropSvc
SCPolicySvc
lanmanserver
gpsvc
IKEEXT
AudioSrv
FastUserSwitchingCompatibility
Nla
NWCWorkstation
SRService
Wmi
WmdmPmSp
TermService
wuauserv
BITS
ShellHWDetection
LogonHours
PCAudit
helpsvc
uploadmgr
iphlpsvc
seclogon
AppInfo
msiscsi
MMCSS
ProfSvc
EapHost
winmgmt
schedule
SessionEnv
browser
hkmsvc

*Newly Created Service* - CATCHME

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
.
Contents of the 'Scheduled Tasks' folder
"2007-12-10 15:00:03 C:\Windows\Tasks\wrSpySweeper_L66863BFF9B534C9090AA718ACDF24339.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe>/ScheduleSweep=wrSpySweeper_L66863BFF9B534C9090AA718ACDF24339
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
"2007-12-11 23:46:35 C:\Windows\Tasks\wrSpySweeper_L853E14CA99E6400DBC62BAAF28569A8A.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe>/ScheduleSweep=wrSpySweeper_L853E14CA99E6400DBC62BAAF28569A8A
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
- A:\
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-12 11:19:44
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-12 11:21:06
.
2007-12-12 00:55:11 — E O F —

ComboFix 07-12-12.3 - Administrate 2007-12-12 11:16:21.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.321 [GMT -5:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Windows\system32\ps.exe

.
((((((((((((((((((((((((( Files Created from 2007-11-12 to 2007-12-12 )))))))))))))))))))))))))))))))
.

2007-12-11 19:37 . 2007-12-11 19:37 1,327,104 –a—— C:\Windows\System32\quartz.dll
2007-12-11 19:37 . 2007-12-11 19:37 223,232 –a—— C:\Windows\System32\WMASF.DLL
2007-12-11 19:37 . 2007-12-11 19:37 9,728 –a—— C:\Windows\System32\LAPRXY.DLL
2007-12-11 19:37 . 2007-12-11 19:37 2,048 –a—— C:\Windows\System32\asferror.dll
2007-12-11 19:35 . 2007-12-11 19:35 130,048 –a—— C:\Windows\System32\drivers\srv2.sys
2007-12-11 19:35 . 2007-12-11 19:35 101,888 –a—— C:\Windows\System32\drivers\mrxsmb.sys
2007-12-11 19:35 . 2007-12-11 19:35 84,992 –a—— C:\Windows\System32\drivers\srvnet.sys
2007-12-11 19:35 . 2007-12-11 19:35 58,368 –a—— C:\Windows\System32\drivers\mrxsmb20.sys
2007-12-11 19:33 . 2007-12-11 19:33 3,504,824 –a—— C:\Windows\System32\ntkrnlpa.exe
2007-12-11 19:33 . 2007-12-11 19:33 3,470,520 –a—— C:\Windows\System32\ntoskrnl.exe
2007-12-11 19:31 . 2007-12-11 19:31 2,048 –a—— C:\Windows\System32\tzres.dll
2007-12-11 16:02 . 2007-12-11 16:02 d——– C:\Users\All Users\Grisoft
2007-12-11 16:02 . 2007-12-11 16:02 d——– C:\ProgramData\Grisoft
2007-12-03 14:53 . 2007-12-03 14:53 d——– C:\Users\Administrate\AppData\Roaming\Uniblue
2007-12-03 14:50 . 1999-03-15 16:39 212,992 –a—— C:\Windows\ALCHUNIN.EXE
2007-12-03 14:50 . 2003-11-28 09:56 36,864 –a—— C:\Windows\Ultimate Screen Clock.scr
2007-11-29 20:01 . 2007-11-29 20:01 d——– C:\Program Files\DanAgonistes
2007-11-27 17:52 . 2007-11-27 17:54 d——– C:\Users\Administrate\{725d0b59-11fa-44de-a2df-a2d5f6180949}
2007-11-21 16:20 . 2007-11-21 16:23 d——– C:\Users\Administrate\AppData\Roaming\RaimaRadio
2007-11-21 16:20 . 2007-11-21 16:20 d——– C:\Program Files\RaimaRadio
2007-11-21 11:40 . 2007-12-07 17:06 273 –a—— C:\Windows\SysMech7.INI
2007-11-21 09:47 . 2007-11-20 11:13 370,536 –a—— C:\Windows\System32\Incinerator.dll
2007-11-21 09:47 . 2007-11-17 12:01 23,552 –a—— C:\Windows\System32\smrgdf.exe
2007-11-13 15:49 . 2007-11-13 15:49 224,768 –a—— C:\Windows\System32\drivers\usbport.sys
2007-11-13 15:49 . 2007-11-13 15:49 192,000 –a—— C:\Windows\System32\drivers\usbhub.sys
2007-11-13 15:49 . 2007-11-13 15:49 73,216 –a—— C:\Windows\System32\drivers\usbccgp.sys
2007-11-13 15:49 . 2007-11-13 15:49 38,400 –a—— C:\Windows\System32\drivers\usbehci.sys
2007-11-13 15:49 . 2007-11-13 15:49 19,456 –a—— C:\Windows\System32\drivers\usbohci.sys
2007-11-13 15:49 . 2007-11-13 15:49 8,704 –a—— C:\Windows\System32\hcrstco.dll
2007-11-13 15:49 . 2007-11-13 15:49 8,704 –a—— C:\Windows\System32\hccoin.dll
2007-11-13 15:49 . 2007-11-13 15:49 5,888 –a—— C:\Windows\System32\drivers\usbd.sys
2007-11-13 15:48 . 2007-11-13 15:48 1,244,672 –a—— C:\Windows\System32\mcmde.dll
2007-11-13 15:26 . 2007-11-13 15:27 d——– C:\Program Files\QuickTime

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-12 11:56 ——— d—–w C:\Users\Administrate\AppData\Roaming\OpenOffice.org2
2007-12-12 11:56 ——— d—–w C:\Program Files\Dl_cats
2007-12-12 00:36 56,320 —-a-w C:\Windows\System32\iesetup.dll
2007-12-12 00:36 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-12 00:36 26,624 —-a-w C:\Windows\System32\ieUnatt.exe
2007-12-05 12:18 ——— d—–w C:\Program Files\OpenOffice.org 2.3
2007-12-02 22:38 ——— d—–w C:\Program Files\Picasa2
2007-12-02 21:19 ——— d—–w C:\Users\Administrate\AppData\Roaming\PC Magazine Utilities
2007-12-02 21:18 ——— d—–w C:\Program Files\PC Magazine Utilities
2007-11-28 20:31 ——— d—–w C:\Users\Administrate\AppData\Roaming\ExplorerPlus
2007-11-21 14:48 ——— d—–w C:\ProgramData\iolo
2007-11-18 15:17 ——— d—–w C:\Users\Administrate\AppData\Roaming\iolo
2007-11-14 01:35 696 —-a-w C:\Users\Administrate\AppData\Roaming\wklnhst.dat
2007-11-13 20:51 704,000 —-a-w C:\Windows\System32\PhotoScreensaver.scr
2007-11-13 20:51 67,584 —-a-w C:\Windows\System32\wlanhlp.dll
2007-11-13 20:51 542,720 —-a-w C:\Windows\System32\sysmain.dll
2007-11-13 20:51 502,784 —-a-w C:\Windows\System32\wlansvc.dll
2007-11-13 20:51 47,104 —-a-w C:\Windows\System32\wlanapi.dll
2007-11-13 20:51 297,984 —-a-w C:\Windows\System32\wlansec.dll
2007-11-13 20:51 290,816 —-a-w C:\Windows\System32\wlanmsm.dll
2007-11-13 20:51 258,232 —-a-w C:\Windows\system32\drivers\acpi.sys
2007-11-13 20:51 24,064 —-a-w C:\Windows\System32\wtsapi32.dll
2007-11-13 20:51 2,923,520 —-a-w C:\Windows\explorer.exe
2007-11-13 20:51 2,027,008 —-a-w C:\Windows\System32\win32k.sys
2007-11-13 20:48 ——— d—–w C:\Program Files\Windows Mail
2007-11-08 23:05 ——— d—–w C:\Program Files\Webroot
2007-10-23 19:40 ——— d—–w C:\Program Files\Wheelhouse
2007-10-20 18:20 78,168 —-a-w C:\Windows\system32\drivers\pwipf6.sys
2007-10-20 18:20 177,496 —-a-w C:\Windows\System32\wdfproc.dll
2007-10-19 18:56 ——— d—–w C:\ProgramData\Webroot
2007-10-18 20:08 ——— d—–w C:\Program Files\Common Files\Intuit
2007-10-18 20:03 ——— d—–w C:\Program Files\Google
2007-10-18 17:20 164 —-a-w C:\install.dat
2007-10-17 21:01 ——— d—–w C:\Users\Administrate\AppData\Roaming\NoteTab Light
2007-10-17 20:57 ——— d—–w C:\Program Files\NoteTab Light
2007-10-10 11:32 8,147,968 —-a-w C:\Windows\System32\wmploc.DLL
2007-10-10 11:32 7,680 —-a-w C:\Windows\System32\spwmp.dll
2007-10-10 11:32 4,096 —-a-w C:\Windows\System32\dxmasf.dll
2007-10-10 11:32 356,864 —-a-w C:\Windows\System32\MediaMetadataHandler.dll
2007-10-10 11:30 84,480 —-a-w C:\Windows\System32\INETRES.dll
2007-10-10 11:30 788,992 —-a-w C:\Windows\System32\rpcrt4.dll
2007-10-10 11:30 737,792 —-a-w C:\Windows\System32\inetcomm.dll
2007-10-01 20:40 1,526,072 —-a-w C:\Windows\WRSetup.dll
2007-09-20 18:12 12,800 —-a-w C:\Windows\System32\elrawdsk.sys
2007-08-30 12:36 174 –sha-w C:\Program Files\desktop.ini
2007-03-06 21:06 963,072 —-a-w C:\Windows\inf\WG311T\WG311Tx.sys
2007-03-06 21:03 782,848 —-a-w C:\Windows\inf\WG311T\WG311T13.sys
2006-10-27 03:05 28,672 —-a-w C:\Windows\inf\WG311T\SetDrv.exe
2006-04-25 21:30 35,232 —-a-w C:\Windows\inf\WG311T\ME_INST.EXE
2006-04-25 21:30 26,112 —-a-w C:\Windows\inf\WG311T\install.exe
2007-09-04 19:44 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-09-04 19:44 32,768 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-09-04 19:44 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\windows sidebar\sidebar.exe" [2006-11-02 07:35]
"quickstart.exe"="C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe" []
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 07:36]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2007-12-03 14:46]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="RUNDLL32.exe" [2006-11-02 04:45 C:\Windows\System32\rundll32.exe]
"NvCplDaemon"="RUNDLL32.exe" [2006-11-02 04:45 C:\Windows\System32\rundll32.exe]
"NvMediaCenter"="RUNDLL32.exe" [2006-11-02 04:45 C:\Windows\System32\rundll32.exe]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 966\memcard.exe" [2006-12-12 03:22]
"DLCQCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-16 00:31]
"dlcqmon.exe"="C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe" [2006-12-12 03:22]
"FaxCenterServer"="C:\Program Files\Dell PC Fax\fm3032.exe" [2006-12-12 03:22]
"Webroot Desktop Firewall"="C:\Program Files\Webroot\Desktop Firewall\WDF.exe" [2007-10-20 13:20]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-05-24 17:00]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 13:42]
"iolo Startup"="C:\Program Files\iolo\Common\Lib\ioloLManager.exe" [2007-11-17 17:43]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-10-01 15:40]

C:\Users\Administrate\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Lunabar.lnk - C:\Program Files\Lunabar\Lunabar.exe [2007-05-26 11:12:21]
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 21:57:56]
WordWeb Pro.lnk - C:\Program Files\WordWeb\wweb32.exe [2007-06-11 15:04:05]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-04-04 14:06:20]
NETGEAR WG311T Smart Wizard.lnk - C:\Program Files\NETGEAR\WG311T\wlancfg5.exe [2007-04-10 18:09:06]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

R0 CLFS;Common Log (CLFS);C:\Windows\system32\CLFS.sys
R0 crcdisk;Crcdisk Filter Driver;C:\Windows\system32\drivers\crcdisk.sys
R0 Ecache;ReadyBoost Caching Driver;C:\Windows\system32\drivers\ecache.sys
R0 FileInfo;File Information FS MiniFilter;C:\Windows\system32\drivers\fileinfo.sys
R0 msisadrv;ISA/EISA Class Driver;C:\Windows\system32\drivers\msisadrv.sys
R0 nvstor;nvstor;C:\Windows\system32\drivers\nvstor.sys
R0 nvstor32;nvstor32;C:\Windows\system32\DRIVERS\nvstor32.sys
R0 spldr;Security Processor Loader Driver;C:\Windows\system32\drivers\spldr.sys
R0 SSFS0BB9;Spy Sweeper File System Filer Driver: 0BB9;C:\Windows\system32\Drivers\SSFS0BB9.SYS
R0 volmgr;Volume Manager Driver;C:\Windows\system32\drivers\volmgr.sys
R0 volmgrx;Dynamic Volume Manager;C:\Windows\system32\drivers\volmgrx.sys
R1 DfsC;Dfs Client Driver;C:\Windows\system32\Drivers\dfsc.sys
R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS
R1 ElRawDisk;ElRawDisk;\??\C:\Windows\system32\drivers\elrawdsk.sys
R1 nsiproxy;NSI proxy service;C:\Windows\system32\drivers\nsiproxy.sys
R1 pwipf6;Privacyware Filter Driver;C:\Windows\system32\DRIVERS\pwipf6.sys
R1 RDPENCDD;RDP Encoder Mirror Driver;C:\Windows\system32\drivers\rdpencdd.sys
R1 Smb;Message-oriented TCP/IP and TCP/IPv6 Protocol (SMB session);C:\Windows\system32\DRIVERS\smb.sys
R1 tdx;NetIO Legacy TDI Support Driver;C:\Windows\system32\DRIVERS\tdx.sys
R1 Wanarpv6;Remote Access IPv6 ARP Driver;C:\Windows\system32\DRIVERS\wanarp.sys
R2 AeLookupSvc;Application Experience;C:\Windows\system32\svchost.exe -k netsvcs
R2 AudioEndpointBuilder;Windows Audio Endpoint Builder;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
R2 BFE;Base Filtering Engine;C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
R2 dlcq_device;dlcq_device;C:\Windows\system32\dlcqcoms.exe -service
R2 DPS;Diagnostic Policy Service;C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
R2 EMDMgmt;ReadyBoost;C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
R2 FDResPub;Function Discovery Resource Publication;C:\Windows\system32\svchost.exe -k LocalService
R2 gpsvc;Group Policy Client;C:\Windows\system32\svchost.exe -k netsvcs
R2 IKEEXT;IKE and AuthIP IPsec Keying Modules;C:\Windows\system32\svchost.exe -k netsvcs
R2 ioloFileInfoList;iolo FileInfoList Service;C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
R2 ioloProductUpdate;iolo Product Update Service;C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
R2 ioloSystemService;iolo System Service;C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
R2 iphlpsvc;IP Helper;C:\Windows\System32\svchost.exe -k NetSvcs
R2 KtmRm;KtmRm for Distributed Transaction Coordinator;C:\Windows\System32\svchost.exe -k NetworkService
R2 lltdio;Link-Layer Topology Discovery Mapper I/O Driver;C:\Windows\system32\DRIVERS\lltdio.sys
R2 luafv;UAC File Virtualization;C:\Windows\system32\drivers\luafv.sys
R2 MMCSS;Multimedia Class Scheduler;C:\Windows\system32\svchost.exe -k netsvcs
R2 MpsSvc;Windows Firewall;C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
R2 netprofm;Network List Service;C:\Windows\System32\svchost.exe -k LocalService
R2 NlaSvc;Network Location Awareness;C:\Windows\System32\svchost.exe -k NetworkService
R2 nsi;Network Store Interface Service;C:\Windows\system32\svchost.exe -k LocalService
R2 PcaSvc;Program Compatibility Assistant Service;C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
R2 PEAUTH;PEAUTH;C:\Windows\system32\drivers\peauth.sys
R2 ProfSvc;User Profile Service;C:\Windows\system32\svchost.exe -k netsvcs
R2 slsvc;Software Licensing;C:\Windows\system32\SLsvc.exe
R2 SysMain;Superfetch;C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
R2 TabletInputService;Tablet PC Input Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
R2 tcpipreg;TCP/IP Registry Compatibility;C:\Windows\system32\drivers\tcpipreg.sys
R2 UxSms;Desktop Window Manager Session Manager;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
R2 WDFNet;Webroot Desktop Firewall network service;C:\Program Files\Webroot\Desktop Firewall\wdfsvc.exe
R2 WerSvc;Windows Error Reporting Service;C:\Windows\System32\svchost.exe -k WerSvcGroup
R2 Wlansvc;WLAN AutoConfig;C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
R2 WPDBusEnum;Portable Device Enumerator Service;C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys
R3 Appinfo;Application Information;C:\Windows\system32\svchost.exe -k netsvcs
R3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\WG311T13.sys
R3 bowser;Bowser;C:\Windows\system32\DRIVERS\bowser.sys
R3 DXGKrnl;LDDM Graphics Subsystem;C:\Windows\system32\drivers\dxgkrnl.sys
R3 EapHost;Extensible Authentication Protocol;C:\Windows\System32\svchost.exe -k netsvcs
R3 fdPHost;Function Discovery Provider Host;C:\Windows\system32\svchost.exe -k LocalService
R3 iScsiPrt;iScsiPort Driver;C:\Windows\system32\DRIVERS\msiscsi.sys
R3 KeyIso;CNG Key Isolation;C:\Windows\system32\lsass.exe
R3 monitor;Microsoft Monitor Class Function Driver Service;C:\Windows\system32\DRIVERS\monitor.sys
R3 mpsdrv;Windows Firewall Authorization Driver;C:\Windows\system32\drivers\mpsdrv.sys
R3 mrxsmb10;SMB 1.x MiniRedirector;C:\Windows\system32\DRIVERS\mrxsmb10.sys
R3 mrxsmb20;SMB 2.0 MiniRedirector;C:\Windows\system32\DRIVERS\mrxsmb20.sys
R3 NativeWifiP;NativeWiFi Filter;C:\Windows\system32\DRIVERS\nwifi.sys
R3 nvlddmkm;nvlddmkm;C:\Windows\system32\DRIVERS\nvlddmkm.sys
R3 srv2;srv2;C:\Windows\system32\DRIVERS\srv2.sys
R3 srvnet;srvnet;C:\Windows\system32\DRIVERS\srvnet.sys
R3 tunnel;Microsoft IPv6 Tunnel Miniport Adapter Driver;C:\Windows\system32\DRIVERS\tunnel.sys
R3 umbus;UMBus Enumerator Driver;C:\Windows\system32\DRIVERS\umbus.sys
R3 WdiSystemHost;Diagnostic System Host;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\Windows\system32\DRIVERS\A3AB.sys
S3 BrFiltLo;Brother USB Mass-Storage Lower Filter Driver;C:\Windows\system32\drivers\brfiltlo.sys
S3 BrFiltUp;Brother USB Mass-Storage Upper Filter Driver;C:\Windows\system32\drivers\brfiltup.sys
S3 BrUsbSer;Brother MFC USB Serial WDM Driver;C:\Windows\system32\drivers\brusbser.sys
S3 CertPropSvc;Certificate Propagation;C:\Windows\system32\svchost.exe -k netsvcs
S3 DFSR;DFS Replication;C:\Windows\system32\DFSR.exe
S3 dot3svc;Wired AutoConfig;C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
S3 E1G60;Intel® PRO/1000 NDIS 6 Adapter Driver;C:\Windows\system32\DRIVERS\E1G60I32.sys
S3 Filetrace;FileTrace;C:\Windows\system32\drivers\filetrace.sys
S3 hkmsvc;Health Key and Certificate Management;C:\Windows\System32\svchost.exe -k netsvcs
S3 IPBusEnum;PnP-X IP Bus Enumerator;C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
S3 lltdsvc;Link-Layer Topology Discovery Mapper;C:\Windows\System32\svchost.exe -k LocalService
S3 MSiSCSI;Microsoft iSCSI Initiator Service;C:\Windows\system32\svchost.exe -k netsvcs
S3 MsRPC;MsRPC;C:\Windows\system32\drivers\MsRPC.sys
S3 napagent;Network Access Protection Agent;C:\Windows\System32\svchost.exe -k NetworkService
S3 p2pimsvc;Peer Networking Identity Manager;C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
S3 p2psvc;Peer Networking Grouping;C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
S3 pla;Performance Logs & Alerts;C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
S3 PNRPAutoReg;PNRP Machine Name Publication Service;C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
S3 PNRPsvc;Peer Name Resolution Protocol;C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
S3 QWAVE;Quality Windows Audio Video Experience;C:\Windows\system32\svchost.exe -k LocalService
S3 QWAVEdrv;QWAVE driver;C:\Windows\system32\drivers\qwavedrv.sys
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys
S3 SCPolicySvc;Smart Card Removal Policy;C:\Windows\system32\svchost.exe -k netsvcs
S3 SDRSVC;Windows Backup;C:\Windows\system32\svchost.exe -k SDRSVC
S3 SessionEnv;Terminal Services Configuration;C:\Windows\System32\svchost.exe -k netsvcs
S3 sffp_mmc;SFF Storage Protocol Driver for MMC;C:\Windows\system32\drivers\sffp_mmc.sys
S3 SLUINotify;SL UI Notification Service;C:\Windows\system32\svchost.exe -k LocalService
S3 TBS;TPM Base Services;C:\Windows\System32\svchost.exe -k LocalService
S3 THREADORDER;Thread Ordering Server;C:\Windows\system32\svchost.exe -k LocalService
S3 TrustedInstaller;Windows Modules Installer;C:\Windows\servicing\TrustedInstaller.exe
S3 tssecsrv;Terminal Services Security Filter Driver;C:\Windows\system32\DRIVERS\tssecsrv.sys
S3 UI0Detect;Interactive Services Detection;C:\Windows\system32\UI0Detect.exe
S3 uliagpkx;Uli AGP Bus Filter;C:\Windows\system32\drivers\uliagpkx.sys
S3 vga;vga;C:\Windows\system32\DRIVERS\vgapnp.sys
S3 wcncsvc;Windows Connect Now - Config Registrar;C:\Windows\System32\svchost.exe -k LocalService
S3 WcsPlugInService;Windows Color System;C:\Windows\system32\svchost.exe -k wcssvc
S3 WdiServiceHost;Diagnostic Service Host;C:\Windows\System32\svchost.exe -k wdisvc
S3 Wecsvc;Windows Event Collector;C:\Windows\system32\svchost.exe -k NetworkService
S3 wercplsupport;Problem Reports and Solutions Control Panel Support;C:\Windows\System32\svchost.exe -k netsvcs
S3 WinHttpAutoProxySvc;WinHTTP Web Proxy Auto-Discovery Service;C:\Windows\system32\svchost.exe -k LocalService
S3 WinRM;Windows Remote Management (WS-Management);C:\Windows\System32\svchost.exe -k NetworkService
S3 WPCSvc;Parental Controls;C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
S4 adp94xx;adp94xx;C:\Windows\system32\drivers\adp94xx.sys
S4 adpahci;adpahci;C:\Windows\system32\drivers\adpahci.sys
S4 amdide;amdide;C:\Windows\system32\drivers\amdide.sys
S4 arc;arc;C:\Windows\system32\drivers\arc.sys
S4 arcsas;arcsas;C:\Windows\system32\drivers\arcsas.sys
S4 Brserid;Brother MFC Serial Port Interface Driver (WDM);C:\Windows\system32\drivers\brserid.sys
S4 BrSerWdm;Brother WDM Serial driver;C:\Windows\system32\drivers\brserwdm.sys
S4 BrUsbMdm;Brother MFC USB Fax Only Modem;C:\Windows\system32\drivers\brusbmdm.sys
S4 circlass;Consumer IR Devices;C:\Windows\system32\drivers\circlass.sys
S4 Crusoe;Transmeta Crusoe Processor Driver;C:\Windows\system32\drivers\crusoe.sys
S4 elxstor;elxstor;C:\Windows\system32\drivers\elxstor.sys
S4 HpCISSs;HpCISSs;C:\Windows\system32\drivers\hpcisss.sys
S4 iaStorV;Intel RAID Controller Vista;C:\Windows\system32\drivers\iastorv.sys
S4 iirsp;iirsp;C:\Windows\system32\drivers\iirsp.sys
S4 IPMIDRV;IPMIDRV;C:\Windows\system32\drivers\ipmidrv.sys
S4 iteraid;ITERAID_Service_Install;C:\Windows\system32\drivers\iteraid.sys
S4 LSI_FC;LSI_FC;C:\Windows\system32\drivers\lsi_fc.sys
S4 LSI_SAS;LSI_SAS;C:\Windows\system32\drivers\lsi_sas.sys
S4 LSI_SCSI;LSI_SCSI;C:\Windows\system32\drivers\lsi_scsi.sys
S4 Mcx2Svc;Windows Media Center Extender Service;C:\Windows\system32\svchost.exe -k LocalService
S4 megasas;megasas;C:\Windows\system32\drivers\megasas.sys
S4 mpio;Microsoft Multi-Path Bus Driver;C:\Windows\system32\drivers\mpio.sys
S4 msahci;msahci;C:\Windows\system32\drivers\msahci.sys
S4 msdsm;Microsoft Multi-Path Device Specific Module;C:\Windows\system32\drivers\msdsm.sys
S4 nfrd960;nfrd960;C:\Windows\system32\drivers\nfrd960.sys
S4 ntrigdigi;N-trig HID Tablet Driver;C:\Windows\system32\drivers\ntrigdigi.sys
S4 ql2300;QLogic Fibre Channel Miniport Driver;C:\Windows\system32\drivers\ql2300.sys
S4 ql40xx;QLogic iSCSI Miniport Driver;C:\Windows\system32\drivers\ql40xx.sys
S4 SiSRaid2;SiSRaid2;C:\Windows\system32\drivers\sisraid2.sys
S4 SiSRaid4;SiSRaid4;C:\Windows\system32\drivers\sisraid4.sys
S4 uliahci;uliahci;C:\Windows\system32\drivers\uliahci.sys
S4 ulsata2;ulsata2;C:\Windows\system32\drivers\ulsata2.sys
S4 usbcir;eHome Infrared Receiver (USBCIR);C:\Windows\system32\drivers\usbcir.sys
S4 ViaC7;VIA C7 Processor Driver;C:\Windows\system32\drivers\viac7.sys
S4 vsmraid;vsmraid;C:\Windows\system32\drivers\vsmraid.sys
S4 WacomPen;Wacom Serial Pen HID Driver;C:\Windows\system32\drivers\wacompen.sys
S4 Wd;Microsoft Watchdog Timer Driver;C:\Windows\system32\drivers\wd.sys

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService REG_MULTI_SZ nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE Mcx2Svc WebClient
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
NetworkServiceNetworkRestricted REG_MULTI_SZ PolicyAgent
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc ehstart
NetworkService REG_MULTI_SZ CryptSvc DHCP TermService KtmRm DNSCache NapAgent nlasvc WinRM WECSVC Tapisrv
WerSvcGroup REG_MULTI_SZ wersvc
swprv REG_MULTI_SZ swprv
LocalServiceNetworkRestricted REG_MULTI_SZ DHCP eventlog AudioSrv LmHosts wscsvc p2pimsvc PNRPSvc p2psvc WPCSvc PnrpAutoReg
regsvc REG_MULTI_SZ RemoteRegistry
wcssvc REG_MULTI_SZ WcsPlugInService
DcomLaunch REG_MULTI_SZ PlugPlay DcomLaunch
wdisvc REG_MULTI_SZ WdiServiceHost
sdrsvc REG_MULTI_SZ sdrsvc
secsvcs REG_MULTI_SZ WinDefend

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
AeLookupSvc
wercplsupport
Themes
CertPropSvc
SCPolicySvc
lanmanserver
gpsvc
IKEEXT
AudioSrv
FastUserSwitchingCompatibility
Nla
NWCWorkstation
SRService
Wmi
WmdmPmSp
TermService
wuauserv
BITS
ShellHWDetection
LogonHours
PCAudit
helpsvc
uploadmgr
iphlpsvc
seclogon
AppInfo
msiscsi
MMCSS
ProfSvc
EapHost
winmgmt
schedule
SessionEnv
browser
hkmsvc

*Newly Created Service* - CATCHME

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
.
Contents of the 'Scheduled Tasks' folder
"2007-12-10 15:00:03 C:\Windows\Tasks\wrSpySweeper_L66863BFF9B534C9090AA718ACDF24339.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe>/ScheduleSweep=wrSpySweeper_L66863BFF9B534C9090AA718ACDF24339
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
"2007-12-11 23:46:35 C:\Windows\Tasks\wrSpySweeper_L853E14CA99E6400DBC62BAAF28569A8A.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe>/ScheduleSweep=wrSpySweeper_L853E14CA99E6400DBC62BAAF28569A8A
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
- A:\
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-12 11:19:44
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-12 11:21:06
.
2007-12-12 00:55:11 — E O F —
I've uninstalled Webroot's Spy Sweeper and Firewall, and installed ZoneAlarm Security Suite. The cited problems no longer occur, but other strange ones do (like shutdown takes 10-15 minutes). I suppose it's due to Vista or a combination of Vista and one or more applications. I think my best hope now is the announced but not yet released Vista SP. Thanks for your attempt to help.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI