JoshLyman Posted July 24, 2009 Report Share Posted July 24, 2009 hey been having a problem with FB and BT himself said i should post some logs in here to see if i was infected ...MBAM said was clean since problem started.Rooter.exe (v1.0.2) by Eric_71.SeDebugPrivilege granted successfully ....Windows Vista . (6.0.6001) Service Pack 1[32_bits] - x86 Family 6 Model 15 Stepping 13, GenuineIntel.[wscsvc] (Security Center) RUNNING (state:4)[MpsSvc] RUNNING (state:4)Windows Firewall -> EnabledWindows Defender -> EnabledUser Account Control (UAC) -> Disabled !.Internet Explorer 7.0.6001.18000Mozilla Firefox 3.5.1 (en-GB).C:\ [Fixed-NTFS] .. ( Total:138 Go - Free:50 Go )D:\ [Fixed-NTFS] .. ( Total:149 Go - Free:148 Go )E:\ [Fixed-NTFS] .. ( Total:9 Go - Free:6 Go )F:\ [CD_Rom].Scan : 00:24.35Path : C:\Users\Big Si\Downloads\Rooter.exeUser : Big Si ( Administrator -> YES ).----------------------\\ Processes.Locked [system Process] (0)Locked System (4)______ \SystemRoot\System32\smss.exe (464)______ C:\Windows\system32\csrss.exe (532)______ C:\Windows\system32\wininit.exe (576)______ C:\Windows\system32\csrss.exe (588)______ C:\Windows\system32\winlogon.exe (648)______ C:\Windows\system32\services.exe (668)______ C:\Windows\system32\lsass.exe (680)______ C:\Windows\system32\lsm.exe (692)______ C:\Windows\system32\svchost.exe (912)______ C:\Windows\system32\svchost.exe (980)______ ?? (1028)______ C:\Windows\system32\svchost.exe (1148)______ C:\Windows\System32\svchost.exe (1168)______ C:\Windows\System32\svchost.exe (1228)______ C:\Windows\System32\svchost.exe (1276)______ C:\Windows\system32\svchost.exe (1320)Locked audiodg.exe (1432)______ C:\Windows\system32\svchost.exe (1532)______ C:\Windows\system32\SLsvc.exe (1596)______ C:\Windows\system32\svchost.exe (1652)______ C:\Windows\System32\spoolsv.exe (2040)______ C:\Windows\system32\svchost.exe (260)______ C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (1240)______ C:\Windows\system32\svchost.exe (1868)______ C:\PROGRA~1\AVG\AVG8\avgrsx.exe (920)______ C:\Program Files\Spyware Doctor\pctsAuxs.exe (2224)______ C:\Program Files\Spyware Doctor\pctsSvc.exe (2256)______ C:\Windows\system32\svchost.exe (2308)______ C:\Windows\System32\svchost.exe (2340)______ C:\Windows\system32\SearchIndexer.exe (2392)______ C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (2640)______ C:\Windows\system32\taskeng.exe (3700)______ C:\Windows\system32\Dwm.exe (3820)______ C:\Windows\Explorer.EXE (3860)______ C:\Windows\RtHDVCpl.exe (3144)______ C:\Program Files\Common Files\Real\Update_OB\realsched.exe (3196)______ C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (3204)______ C:\Program Files\AVG\AVG8\avgtray.exe (3228)______ C:\Windows\System32\hkcmd.exe (848)______ C:\Windows\System32\igfxpers.exe (2416)______ C:\Windows\system32\igfxsrvc.exe (1612)______ ?? (3636)______ C:\Program Files\Java\jre6\bin\jusched.exe (948)______ C:\Program Files\Spyware Doctor\pctsTray.exe (1312)______ C:\Users\Big Si\AppData\Local\Google\Update\GoogleUpdate.exe (4012)______ C:\Program Files\Windows Media Player\wmpnscfg.exe (3724)______ C:\Windows\system32\wbem\unsecapp.exe (1156)______ C:\Windows\system32\wbem\wmiprvse.exe (1604)______ C:\Program Files\Windows Media Player\wmpnetwk.exe (2676)______ C:\Windows\System32\mobsync.exe (4072)______ C:\Program Files\Mozilla Firefox\firefox.exe (2632)______ C:\Windows\system32\wuauclt.exe (2604)______ C:\Windows\system32\cmd.exe (3628)______ C:\Windows\system32\svchost.exe (2488)______ C:\Windows\system32\SearchProtocolHost.exe (2512)______ C:\Windows\system32\SearchFilterHost.exe (2932)______ C:\Users\Big Si\Downloads\Rooter.exe (1184).----------------------\\ Device\Harddisk0\.\Device\Harddisk0 [sectors : 63 x 512 Bytes].\Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:49319424)\Device\Harddisk0\Partition2 (Start_Offset:50331648 | Length:10737418240)\Device\Harddisk0\Partition3 --[ MBR ]-- (Start_Offset:10787749888 | Length:149210267648).----------------------\\ Scheduled Tasks.C:\Windows\Tasks\desktop.iniC:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-505280420-2691023175-4179455115-1000.jobC:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-505280420-2691023175-4179455115-1000Core.jobC:\Windows\Tasks\Norton Security Scan for Big Si.jobC:\Windows\Tasks\SA.DATC:\Windows\Tasks\SCHEDLGU.TXTC:\Windows\Tasks\User_Feed_Synchronization-{E2CE5761-1AA0-474D-B0F4-3BA691DE2C0E}.job.----------------------\\ Registry..----------------------\\ Files & Folders.----------------------\\ Scan completed at 00:25.11.C:\Rooter$\Rooter_1.txt - (25/07/2009 | 00:25.11)ROOTREPEAL © AD, 2007-2009==================================================Scan Start Time: 2009/07/25 00:34Program Version: Version 1.3.2.0Windows Version: Windows Vista SP1==================================================SSDT-------------------#: 000 Function Name: NtAcceptConnectPortStatus: Not hooked#: 001 Function Name: NtAccessCheckStatus: Not hooked#: 002 Function Name: NtAccessCheckAndAuditAlarmStatus: Not hooked#: 003 Function Name: NtAccessCheckByTypeStatus: Not hooked#: 004 Function Name: NtAccessCheckByTypeAndAuditAlarmStatus: Not hooked#: 005 Function Name: NtAccessCheckByTypeResultListStatus: Not hooked#: 006 Function Name: NtAccessCheckByTypeResultListAndAuditAlarmStatus: Not hooked#: 007 Function Name: NtAccessCheckByTypeResultListAndAuditAlarmByHandleStatus: Not hooked#: 008 Function Name: NtAddAtomStatus: Not hooked#: 009 Function Name: NtAddBootEntryStatus: Not hooked#: 010 Function Name: NtAddDriverEntryStatus: Not hooked#: 011 Function Name: NtAdjustGroupsTokenStatus: Not hooked#: 012 Function Name: NtAdjustPrivilegesTokenStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd82472#: 013 Function Name: NtAlertResumeThreadStatus: Not hooked#: 014 Function Name: NtAlertThreadStatus: Not hooked#: 015 Function Name: NtAllocateLocallyUniqueIdStatus: Not hooked#: 016 Function Name: NtAllocateUserPhysicalPagesStatus: Not hooked#: 017 Function Name: NtAllocateUuidsStatus: Not hooked#: 018 Function Name: NtAllocateVirtualMemoryStatus: Not hooked#: 019 Function Name: NtAlpcAcceptConnectPortStatus: Not hooked#: 020 Function Name: NtAlpcCancelMessageStatus: Not hooked#: 021 Function Name: NtAlpcConnectPortStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd83340#: 022 Function Name: NtAlpcCreatePortStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd828a6#: 023 Function Name: NtAlpcCreatePortSectionStatus: Not hooked#: 024 Function Name: NtAlpcCreateResourceReserveStatus: Not hooked#: 025 Function Name: NtAlpcCreateSectionViewStatus: Not hooked#: 026 Function Name: NtAlpcCreateSecurityContextStatus: Not hooked#: 027 Function Name: NtAlpcDeletePortSectionStatus: Not hooked#: 028 Function Name: NtAlpcDeleteResourceReserveStatus: Not hooked#: 029 Function Name: NtAlpcDeleteSectionViewStatus: Not hooked#: 030 Function Name: NtAlpcDeleteSecurityContextStatus: Not hooked#: 031 Function Name: NtAlpcDisconnectPortStatus: Not hooked#: 032 Function Name: NtAlpcImpersonateClientOfPortStatus: Not hooked#: 033 Function Name: NtAlpcOpenSenderProcessStatus: Not hooked#: 034 Function Name: NtAlpcOpenSenderThreadStatus: Not hooked#: 035 Function Name: NtAlpcQueryInformationStatus: Not hooked#: 036 Function Name: NtAlpcQueryInformationMessageStatus: Not hooked#: 037 Function Name: NtAlpcRevokeSecurityContextStatus: Not hooked#: 038 Function Name: NtAlpcSendWaitReceivePortStatus: Not hooked#: 039 Function Name: NtAlpcSetInformationStatus: Not hooked#: 040 Function Name: NtApphelpCacheControlStatus: Not hooked#: 041 Function Name: NtAreMappedFilesTheSameStatus: Not hooked#: 042 Function Name: NtAssignProcessToJobObjectStatus: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0x8c642cd6#: 043 Function Name: NtCallbackReturnStatus: Not hooked#: 044 Function Name: NtRequestDeviceWakeupStatus: Not hooked#: 045 Function Name: NtCancelIoFileStatus: Not hooked#: 046 Function Name: NtCancelTimerStatus: Not hooked#: 047 Function Name: NtClearEventStatus: Not hooked#: 048 Function Name: NtCloseStatus: Not hooked#: 049 Function Name: NtCloseObjectAuditAlarmStatus: Not hooked#: 050 Function Name: NtCompactKeysStatus: Not hooked#: 051 Function Name: NtCompareTokensStatus: Not hooked#: 052 Function Name: NtCompleteConnectPortStatus: Not hooked#: 053 Function Name: NtCompressKeyStatus: Not hooked#: 054 Function Name: NtConnectPortStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd817ea#: 055 Function Name: NtContinueStatus: Not hooked#: 056 Function Name: NtCreateDebugObjectStatus: Not hooked#: 057 Function Name: NtCreateDirectoryObjectStatus: Not hooked#: 058 Function Name: NtCreateEventStatus: Not hooked#: 059 Function Name: NtCreateEventPairStatus: Not hooked#: 060 Function Name: NtCreateFileStatus: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0x8c64338c#: 061 Function Name: NtCreateIoCompletionStatus: Not hooked#: 062 Function Name: NtCreateJobObjectStatus: Not hooked#: 063 Function Name: NtCreateJobSetStatus: Not hooked#: 064 Function Name: NtCreateKeyStatus: Not hooked#: 065 Function Name: NtCreateKeyTransactedStatus: Not hooked#: 066 Function Name: NtCreateMailslotFileStatus: Not hooked#: 067 Function Name: NtCreateMutantStatus: Not hooked#: 068 Function Name: NtCreateNamedPipeFileStatus: Not hooked#: 069 Function Name: NtCreatePrivateNamespaceStatus: Not hooked#: 070 Function Name: NtCreatePagingFileStatus: Not hooked#: 071 Function Name: NtCreatePortStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd81544#: 072 Function Name: NtCreateProcessStatus: Not hooked#: 073 Function Name: NtCreateProcessExStatus: Not hooked#: 074 Function Name: NtCreateProfileStatus: Not hooked#: 075 Function Name: NtCreateSectionStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd81e84#: 076 Function Name: NtCreateSemaphoreStatus: Not hooked#: 077 Function Name: NtCreateSymbolicLinkObjectStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd82658#: 078 Function Name: NtCreateThreadStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd81112#: 079 Function Name: NtCreateTimerStatus: Not hooked#: 080 Function Name: NtCreateTokenStatus: Not hooked#: 081 Function Name: NtCreateTransactionStatus: Not hooked#: 082 Function Name: NtOpenTransactionStatus: Not hooked#: 083 Function Name: NtQueryInformationTransactionStatus: Not hooked#: 084 Function Name: NtQueryInformationTransactionManagerStatus: Not hooked#: 085 Function Name: NtPrePrepareEnlistmentStatus: Not hooked#: 086 Function Name: NtPrepareEnlistmentStatus: Not hooked#: 087 Function Name: NtCommitEnlistmentStatus: Not hooked#: 088 Function Name: NtReadOnlyEnlistmentStatus: Not hooked#: 089 Function Name: NtRollbackCompleteStatus: Not hooked#: 090 Function Name: NtRollbackEnlistmentStatus: Not hooked#: 091 Function Name: NtCommitTransactionStatus: Not hooked#: 092 Function Name: NtRollbackTransactionStatus: Not hooked#: 093 Function Name: NtPrePrepareCompleteStatus: Not hooked#: 094 Function Name: NtPrepareCompleteStatus: Not hooked#: 095 Function Name: NtCommitCompleteStatus: Not hooked#: 096 Function Name: NtSinglePhaseRejectStatus: Not hooked#: 097 Function Name: NtSetInformationTransactionStatus: Not hooked#: 098 Function Name: NtSetInformationTransactionManagerStatus: Not hooked#: 099 Function Name: NtSetInformationResourceManagerStatus: Not hooked#: 100 Function Name: NtCreateTransactionManagerStatus: Not hooked#: 101 Function Name: NtOpenTransactionManagerStatus: Not hooked#: 102 Function Name: NtRenameTransactionManagerStatus: Not hooked#: 103 Function Name: NtRollforwardTransactionManagerStatus: Not hooked#: 104 Function Name: NtRecoverEnlistmentStatus: Not hooked#: 105 Function Name: NtRecoverResourceManagerStatus: Not hooked#: 106 Function Name: NtRecoverTransactionManagerStatus: Not hooked#: 107 Function Name: NtCreateResourceManagerStatus: Not hooked#: 108 Function Name: NtOpenResourceManagerStatus: Not hooked#: 109 Function Name: NtGetNotificationResourceManagerStatus: Not hooked#: 110 Function Name: NtQueryInformationResourceManagerStatus: Not hooked#: 111 Function Name: NtCreateEnlistmentStatus: Not hooked#: 112 Function Name: NtOpenEnlistmentStatus: Not hooked#: 113 Function Name: NtSetInformationEnlistmentStatus: Not hooked#: 114 Function Name: NtQueryInformationEnlistmentStatus: Not hooked#: 115 Function Name: NtCreateWaitablePortStatus: Not hooked#: 116 Function Name: NtDebugActiveProcessStatus: Not hooked#: 117 Function Name: NtDebugContinueStatus: Not hooked#: 118 Function Name: NtDelayExecutionStatus: Not hooked#: 119 Function Name: NtDeleteAtomStatus: Not hooked#: 120 Function Name: NtDeleteBootEntryStatus: Not hooked#: 121 Function Name: NtDeleteDriverEntryStatus: Not hooked#: 122 Function Name: NtDeleteFileStatus: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0x8c643504#: 123 Function Name: NtDeleteKeyStatus: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0x8c646cb8#: 124 Function Name: NtDeletePrivateNamespaceStatus: Not hooked#: 125 Function Name: NtDeleteObjectAuditAlarmStatus: Not hooked#: 126 Function Name: NtDeleteValueKeyStatus: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0x8c646cf6#: 127 Function Name: NtDeviceIoControlFileStatus: Not hooked#: 128 Function Name: NtDisplayStringStatus: Not hooked#: 129 Function Name: NtDuplicateObjectStatus: Not hooked#: 130 Function Name: NtDuplicateTokenStatus: Not hooked#: 131 Function Name: NtEnumerateBootEntriesStatus: Not hooked#: 132 Function Name: NtEnumerateDriverEntriesStatus: Not hooked#: 133 Function Name: NtEnumerateKeyStatus: Not hooked#: 134 Function Name: NtEnumerateSystemEnvironmentValuesExStatus: Not hooked#: 135 Function Name: NtEnumerateTransactionObjectStatus: Not hooked#: 136 Function Name: NtEnumerateValueKeyStatus: Not hooked#: 137 Function Name: NtExtendSectionStatus: Not hooked#: 138 Function Name: NtFilterTokenStatus: Not hooked#: 139 Function Name: NtFindAtomStatus: Not hooked#: 140 Function Name: NtFlushBuffersFileStatus: Not hooked#: 141 Function Name: NtFlushInstructionCacheStatus: Not hooked#: 142 Function Name: NtFlushKeyStatus: Not hooked#: 143 Function Name: NtFlushProcessWriteBuffersStatus: Not hooked#: 144 Function Name: NtFlushVirtualMemoryStatus: Not hooked#: 145 Function Name: NtFlushWriteBufferStatus: Not hooked#: 146 Function Name: NtFreeUserPhysicalPagesStatus: Not hooked#: 147 Function Name: NtFreeVirtualMemoryStatus: Not hooked#: 148 Function Name: NtFreezeRegistryStatus: Not hooked#: 149 Function Name: NtFreezeTransactionsStatus: Not hooked#: 150 Function Name: NtFsControlFileStatus: Not hooked#: 151 Function Name: NtGetContextThreadStatus: Not hooked#: 152 Function Name: NtGetDevicePowerStateStatus: Not hooked#: 153 Function Name: NtGetNlsSectionPtrStatus: Not hooked#: 154 Function Name: NtGetPlugPlayEventStatus: Not hooked#: 155 Function Name: NtGetWriteWatchStatus: Not hooked#: 156 Function Name: NtImpersonateAnonymousTokenStatus: Not hooked#: 157 Function Name: NtImpersonateClientOfPortStatus: Not hooked#: 158 Function Name: NtImpersonateThreadStatus: Not hooked#: 159 Function Name: NtInitializeNlsFilesStatus: Not hooked#: 160 Function Name: NtInitializeRegistryStatus: Not hooked#: 161 Function Name: NtInitiatePowerActionStatus: Not hooked#: 162 Function Name: NtIsProcessInJobStatus: Not hooked#: 163 Function Name: NtIsSystemResumeAutomaticStatus: Not hooked#: 164 Function Name: NtListenPortStatus: Not hooked#: 165 Function Name: NtLoadDriverStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd82fc2#: 166 Function Name: NtLoadKeyStatus: Not hooked#: 167 Function Name: NtLoadKey2Status: Not hooked#: 168 Function Name: NtLoadKeyExStatus: Not hooked#: 169 Function Name: NtLockFileStatus: Not hooked#: 170 Function Name: NtLockProductActivationKeysStatus: Not hooked#: 171 Function Name: NtLockRegistryKeyStatus: Not hooked#: 172 Function Name: NtLockVirtualMemoryStatus: Not hooked#: 173 Function Name: NtMakePermanentObjectStatus: Not hooked#: 174 Function Name: NtMakeTemporaryObjectStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd81a6e#: 175 Function Name: NtMapUserPhysicalPagesStatus: Not hooked#: 176 Function Name: NtMapUserPhysicalPagesScatterStatus: Not hooked#: 177 Function Name: NtMapViewOfSectionStatus: Not hooked#: 178 Function Name: NtModifyBootEntryStatus: Not hooked#: 179 Function Name: NtModifyDriverEntryStatus: Not hooked#: 180 Function Name: NtNotifyChangeDirectoryFileStatus: Not hooked#: 181 Function Name: NtNotifyChangeKeyStatus: Not hooked#: 182 Function Name: NtNotifyChangeMultipleKeysStatus: Not hooked#: 183 Function Name: NtOpenDirectoryObjectStatus: Not hooked#: 184 Function Name: NtOpenEventStatus: Not hooked#: 185 Function Name: NtOpenEventPairStatus: Not hooked#: 186 Function Name: NtOpenFileStatus: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0x8c643450#: 187 Function Name: NtOpenIoCompletionStatus: Not hooked#: 188 Function Name: NtOpenJobObjectStatus: Not hooked#: 189 Function Name: NtOpenKeyStatus: Not hooked#: 190 Function Name: NtOpenKeyTransactedStatus: Not hooked#: 191 Function Name: NtOpenMutantStatus: Not hooked#: 192 Function Name: NtOpenPrivateNamespaceStatus: Not hooked#: 193 Function Name: NtOpenObjectAuditAlarmStatus: Not hooked#: 194 Function Name: NtOpenProcessStatus: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0x8c642e0e#: 195 Function Name: NtOpenProcessTokenStatus: Not hooked#: 196 Function Name: NtOpenProcessTokenExStatus: Not hooked#: 197 Function Name: NtOpenSectionStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd81cfe#: 198 Function Name: NtOpenSemaphoreStatus: Not hooked#: 199 Function Name: NtOpenSessionStatus: Not hooked#: 200 Function Name: NtOpenSymbolicLinkObjectStatus: Not hooked#: 201 Function Name: NtOpenThreadStatus: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0x8c642fbc#: 202 Function Name: NtOpenThreadTokenStatus: Not hooked#: 203 Function Name: NtOpenThreadTokenExStatus: Not hooked#: 204 Function Name: NtOpenTimerStatus: Not hooked#: 205 Function Name: NtPlugPlayControlStatus: Not hooked#: 206 Function Name: NtPowerInformationStatus: Not hooked#: 207 Function Name: NtPrivilegeCheckStatus: Not hooked#: 208 Function Name: NtPrivilegeObjectAuditAlarmStatus: Not hooked#: 209 Function Name: NtPrivilegedServiceAuditAlarmStatus: Not hooked#: 210 Function Name: NtProtectVirtualMemoryStatus: Not hooked#: 211 Function Name: NtPulseEventStatus: Not hooked#: 212 Function Name: NtQueryAttributesFileStatus: Not hooked#: 213 Function Name: NtQueryBootEntryOrderStatus: Not hooked#: 214 Function Name: NtQueryBootOptionsStatus: Not hooked#: 215 Function Name: NtQueryDebugFilterStateStatus: Not hooked#: 216 Function Name: NtQueryDefaultLocaleStatus: Not hooked#: 217 Function Name: NtQueryDefaultUILanguageStatus: Not hooked#: 218 Function Name: NtQueryDirectoryFileStatus: Not hooked#: 219 Function Name: NtQueryDirectoryObjectStatus: Not hooked#: 220 Function Name: NtQueryDriverEntryOrderStatus: Not hooked#: 221 Function Name: NtQueryEaFileStatus: Not hooked#: 222 Function Name: NtQueryEventStatus: Not hooked#: 223 Function Name: NtQueryFullAttributesFileStatus: Not hooked#: 224 Function Name: NtQueryInformationAtomStatus: Not hooked#: 225 Function Name: NtQueryInformationFileStatus: Not hooked#: 226 Function Name: NtQueryInformationJobObjectStatus: Not hooked#: 227 Function Name: NtQueryInformationPortStatus: Not hooked#: 228 Function Name: NtQueryInformationProcessStatus: Not hooked#: 229 Function Name: NtQueryInformationThreadStatus: Not hooked#: 230 Function Name: NtQueryInformationTokenStatus: Not hooked#: 231 Function Name: NtQueryInstallUILanguageStatus: Not hooked#: 232 Function Name: NtQueryIntervalProfileStatus: Not hooked#: 233 Function Name: NtQueryIoCompletionStatus: Not hooked#: 234 Function Name: NtQueryKeyStatus: Not hooked#: 235 Function Name: NtQueryMultipleValueKeyStatus: Not hooked#: 236 Function Name: NtQueryMutantStatus: Not hooked#: 237 Function Name: NtQueryObjectStatus: Not hooked#: 238 Function Name: NtQueryOpenSubKeysStatus: Not hooked#: 239 Function Name: NtQueryOpenSubKeysExStatus: Not hooked#: 240 Function Name: NtQueryPerformanceCounterStatus: Not hooked#: 241 Function Name: NtQueryQuotaInformationFileStatus: Not hooked#: 242 Function Name: NtQuerySectionStatus: Not hooked#: 243 Function Name: NtQuerySecurityObjectStatus: Not hooked#: 244 Function Name: NtQuerySemaphoreStatus: Not hooked#: 245 Function Name: NtQuerySymbolicLinkObjectStatus: Not hooked#: 246 Function Name: NtQuerySystemEnvironmentValueStatus: Not hooked#: 247 Function Name: NtQuerySystemEnvironmentValueExStatus: Not hooked#: 248 Function Name: NtQuerySystemInformationStatus: Not hooked#: 249 Function Name: NtQuerySystemTimeStatus: Not hooked#: 250 Function Name: NtQueryTimerStatus: Not hooked#: 251 Function Name: NtQueryTimerResolutionStatus: Not hooked#: 252 Function Name: NtQueryValueKeyStatus: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0x8c646dfa#: 253 Function Name: NtQueryVirtualMemoryStatus: Not hooked#: 254 Function Name: NtQueryVolumeInformationFileStatus: Not hooked#: 255 Function Name: NtQueueApcThreadStatus: Not hooked#: 256 Function Name: NtRaiseExceptionStatus: Not hooked#: 257 Function Name: NtRaiseHardErrorStatus: Not hooked#: 258 Function Name: NtReadFileStatus: Not hooked#: 259 Function Name: NtReadFileScatterStatus: Not hooked#: 260 Function Name: NtReadRequestDataStatus: Not hooked#: 261 Function Name: NtReadVirtualMemoryStatus: Not hooked#: 262 Function Name: NtRegisterThreadTerminatePortStatus: Not hooked#: 263 Function Name: NtReleaseMutantStatus: Not hooked#: 264 Function Name: NtReleaseSemaphoreStatus: Not hooked#: 265 Function Name: NtRemoveIoCompletionStatus: Not hooked#: 266 Function Name: NtRemoveProcessDebugStatus: Not hooked#: 267 Function Name: NtRenameKeyStatus: Not hooked#: 268 Function Name: NtReplaceKeyStatus: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0x8c646d7e#: 269 Function Name: NtReplacePartitionUnitStatus: Not hooked#: 270 Function Name: NtReplyPortStatus: Not hooked#: 271 Function Name: NtReplyWaitReceivePortStatus: Not hooked#: 272 Function Name: NtReplyWaitReceivePortExStatus: Not hooked#: 273 Function Name: NtReplyWaitReplyPortStatus: Not hooked#: 274 Function Name: NtRequestDeviceWakeupStatus: Not hooked#: 275 Function Name: NtRequestPortStatus: Not hooked#: 276 Function Name: NtRequestWaitReplyPortStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd81662#: 277 Function Name: NtRequestWakeupLatencyStatus: Not hooked#: 278 Function Name: NtResetEventStatus: Not hooked#: 279 Function Name: NtResetWriteWatchStatus: Not hooked#: 280 Function Name: NtRestoreKeyStatus: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0x8c646dbc#: 281 Function Name: NtResumeProcessStatus: Not hooked#: 282 Function Name: NtResumeThreadStatus: Not hooked#: 283 Function Name: NtSaveKeyStatus: Not hooked#: 284 Function Name: NtSaveKeyExStatus: Not hooked#: 285 Function Name: NtSaveMergedKeysStatus: Not hooked#: 286 Function Name: NtSecureConnectPortStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd82d5e#: 287 Function Name: NtSetBootEntryOrderStatus: Not hooked#: 288 Function Name: NtSetBootOptionsStatus: Not hooked#: 289 Function Name: NtSetContextThreadStatus: Not hooked#: 290 Function Name: NtSetDebugFilterStateStatus: Not hooked#: 291 Function Name: NtSetDefaultHardErrorPortStatus: Not hooked#: 292 Function Name: NtSetDefaultLocaleStatus: Not hooked#: 293 Function Name: NtSetDefaultUILanguageStatus: Not hooked#: 294 Function Name: NtSetDriverEntryOrderStatus: Not hooked#: 295 Function Name: NtSetEaFileStatus: Not hooked#: 296 Function Name: NtSetEventStatus: Not hooked#: 297 Function Name: NtSetEventBoostPriorityStatus: Not hooked#: 298 Function Name: NtSetHighEventPairStatus: Not hooked#: 299 Function Name: NtSetHighWaitLowEventPairStatus: Not hooked#: 300 Function Name: NtSetInformationDebugObjectStatus: Not hooked#: 301 Function Name: NtSetInformationFileStatus: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0x8c643572#: 302 Function Name: NtSetInformationJobObjectStatus: Not hooked#: 303 Function Name: NtSetInformationKeyStatus: Not hooked#: 304 Function Name: NtSetInformationObjectStatus: Not hooked#: 305 Function Name: NtSetInformationProcessStatus: Not hooked#: 306 Function Name: NtSetInformationThreadStatus: Not hooked#: 307 Function Name: NtSetInformationTokenStatus: Not hooked#: 308 Function Name: NtSetIntervalProfileStatus: Not hooked#: 309 Function Name: NtSetIoCompletionStatus: Not hooked#: 310 Function Name: NtSetLdtEntriesStatus: Not hooked#: 311 Function Name: NtSetLowEventPairStatus: Not hooked#: 312 Function Name: NtSetLowWaitHighEventPairStatus: Not hooked#: 313 Function Name: NtSetQuotaInformationFileStatus: Not hooked#: 314 Function Name: NtSetSecurityObjectStatus: Not hooked#: 315 Function Name: NtSetSystemEnvironmentValueStatus: Not hooked#: 316 Function Name: NtSetSystemEnvironmentValueExStatus: Not hooked#: 317 Function Name: NtSetSystemInformationStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd83170#: 318 Function Name: NtSetSystemPowerStateStatus: Not hooked#: 319 Function Name: NtSetSystemTimeStatus: Not hooked#: 320 Function Name: NtSetThreadExecutionStateStatus: Not hooked#: 321 Function Name: NtSetTimerStatus: Not hooked#: 322 Function Name: NtSetTimerResolutionStatus: Not hooked#: 323 Function Name: NtSetUuidSeedStatus: Not hooked#: 324 Function Name: NtSetValueKeyStatus: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0x8c646c4c#: 325 Function Name: NtSetVolumeInformationFileStatus: Not hooked#: 326 Function Name: NtShutdownSystemStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd81a08#: 327 Function Name: NtSignalAndWaitForSingleObjectStatus: Not hooked#: 328 Function Name: NtStartProfileStatus: Not hooked#: 329 Function Name: NtStopProfileStatus: Not hooked#: 330 Function Name: NtSuspendProcessStatus: Not hooked#: 331 Function Name: NtSuspendThreadStatus: Not hooked#: 332 Function Name: NtSystemDebugControlStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd81bf2#: 333 Function Name: NtTerminateJobObjectStatus: Not hooked#: 334 Function Name: NtTerminateProcessStatus: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0x8c642b5a#: 335 Function Name: NtTerminateThreadStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd812dc#: 336 Function Name: NtTestAlertStatus: Not hooked#: 337 Function Name: NtThawRegistryStatus: Not hooked#: 338 Function Name: NtThawTransactionsStatus: Not hooked#: 339 Function Name: NtTraceEventStatus: Not hooked#: 340 Function Name: NtTraceControlStatus: Not hooked#: 341 Function Name: NtTranslateFilePathStatus: Not hooked#: 342 Function Name: NtUnloadDriverStatus: Not hooked#: 343 Function Name: NtUnloadKeyStatus: Not hooked#: 344 Function Name: NtUnloadKey2Status: Not hooked#: 345 Function Name: NtUnloadKeyExStatus: Not hooked#: 346 Function Name: NtUnlockFileStatus: Not hooked#: 347 Function Name: NtUnlockVirtualMemoryStatus: Not hooked#: 348 Function Name: NtUnmapViewOfSectionStatus: Not hooked#: 349 Function Name: NtVdmControlStatus: Not hooked#: 350 Function Name: NtWaitForDebugEventStatus: Not hooked#: 351 Function Name: NtWaitForMultipleObjectsStatus: Not hooked#: 352 Function Name: NtWaitForSingleObjectStatus: Not hooked#: 353 Function Name: NtWaitHighEventPairStatus: Not hooked#: 354 Function Name: NtWaitLowEventPairStatus: Not hooked#: 355 Function Name: NtWriteFileStatus: Not hooked#: 356 Function Name: NtWriteFileGatherStatus: Not hooked#: 357 Function Name: NtWriteRequestDataStatus: Not hooked#: 358 Function Name: NtWriteVirtualMemoryStatus: Not hooked#: 359 Function Name: NtYieldExecutionStatus: Not hooked#: 360 Function Name: NtCreateKeyedEventStatus: Not hooked#: 361 Function Name: NtOpenKeyedEventStatus: Not hooked#: 362 Function Name: NtReleaseKeyedEventStatus: Not hooked#: 363 Function Name: NtWaitForKeyedEventStatus: Not hooked#: 364 Function Name: NtQueryPortInformationProcessStatus: Not hooked#: 365 Function Name: NtGetCurrentProcessorNumberStatus: Not hooked#: 366 Function Name: NtWaitForMultipleObjects32Status: Not hooked#: 367 Function Name: NtGetNextProcessStatus: Not hooked#: 368 Function Name: NtGetNextThreadStatus: Not hooked#: 369 Function Name: NtCancelIoFileExStatus: Not hooked#: 370 Function Name: NtCancelSynchronousIoFileStatus: Not hooked#: 371 Function Name: NtRemoveIoCompletionExStatus: Not hooked#: 372 Function Name: NtRegisterProtocolAddressInformationStatus: Not hooked#: 373 Function Name: NtPropagationCompleteStatus: Not hooked#: 374 Function Name: NtPropagationFailedStatus: Not hooked#: 375 Function Name: NtCreateWorkerFactoryStatus: Not hooked#: 376 Function Name: NtReleaseWorkerFactoryWorkerStatus: Not hooked#: 377 Function Name: NtWaitForWorkViaWorkerFactoryStatus: Not hooked#: 378 Function Name: NtSetInformationWorkerFactoryStatus: Not hooked#: 379 Function Name: NtQueryInformationWorkerFactoryStatus: Not hooked#: 380 Function Name: NtWorkerFactoryWorkerReadyStatus: Not hooked#: 381 Function Name: NtShutdownWorkerFactoryStatus: Not hooked#: 382 Function Name: NtCreateThreadExStatus: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8bd829b2#: 383 Function Name: NtCreateUserProcessStatus: Not hooked#: 384 Function Name: NtQueryLicenseValueStatus: Not hooked#: 385 Function Name: NtMapCMFModuleStatus: Not hooked#: 386 Function Name: NtIsUILanguageComittedStatus: Not hooked#: 387 Function Name: NtFlushInstallUILanguageStatus: Not hooked#: 388 Function Name: NtGetMUIRegistryInfoStatus: Not hooked#: 389 Function Name: NtAcquireCMFViewOwnershipStatus: Not hooked#: 390 Function Name: NtReleaseCMFViewOwnershipStatus: Not hookedROOTREPEAL © AD, 2007-2009==================================================Scan Start Time: 2009/07/25 00:34Program Version: Version 1.3.2.0Windows Version: Windows Vista SP1==================================================Drivers-------------------Name: acpi.sysImage Path: C:\Windows\system32\drivers\acpi.sysAddress: 0x80694000 Size: 286720 File Visible: - Signed: -Status: -Name: ACPI_HALImage Path: \Driver\ACPI_HALAddress: 0x82812000 Size: 3903488 File Visible: - Signed: -Status: -Name: afd.sysImage Path: C:\Windows\system32\drivers\afd.sysAddress: 0x8C318000 Size: 294912 File Visible: - Signed: -Status: -Name: atapi.sysImage Path: C:\Windows\system32\drivers\atapi.sysAddress: 0x807A6000 Size: 32768 File Visible: - Signed: -Status: -Name: ataport.SYSImage Path: C:\Windows\system32\drivers\ataport.SYSAddress: 0x807AE000 Size: 122880 File Visible: - Signed: -Status: -Name: ATMFD.DLLImage Path: C:\Windows\System32\ATMFD.DLLAddress: 0x81900000 Size: 311296 File Visible: - Signed: -Status: -Name: avgldx86.sysImage Path: C:\Windows\System32\Drivers\avgldx86.sysAddress: 0x8C6E5000 Size: 329088 File Visible: - Signed: -Status: -Name: avgmfx86.sysImage Path: C:\Windows\System32\Drivers\avgmfx86.sysAddress: 0x8C6DF000 Size: 21120 File Visible: - Signed: -Status: -Name: Beep.SYSImage Path: C:\Windows\System32\Drivers\Beep.SYSAddress: 0x8BFF7000 Size: 28672 File Visible: - Signed: -Status: -Name: BOOTVID.dllImage Path: C:\Windows\system32\BOOTVID.dllAddress: 0x80481000 Size: 32768 File Visible: - Signed: -Status: -Name: bowser.sysImage Path: C:\Windows\system32\DRIVERS\bowser.sysAddress: 0xA899C000 Size: 102400 File Visible: - Signed: -Status: -Name: cdd.dllImage Path: C:\Windows\System32\cdd.dllAddress: 0x818F0000 Size: 57344 File Visible: - Signed: -Status: -Name: cdfs.sysImage Path: C:\Windows\system32\DRIVERS\cdfs.sysAddress: 0x8C736000 Size: 90112 File Visible: - Signed: -Status: -Name: cdrom.sysImage Path: C:\Windows\system32\DRIVERS\cdrom.sysAddress: 0x8353B000 Size: 98304 File Visible: - Signed: -Status: -Name: CI.dllImage Path: C:\Windows\system32\CI.dllAddress: 0x804CA000 Size: 917504 File Visible: - Signed: -Status: -Name: CLASSPNP.SYSImage Path: C:\Windows\system32\drivers\CLASSPNP.SYSAddress: 0x8379E000 Size: 135168 File Visible: - Signed: -Status: -Name: CLFS.SYSImage Path: C:\Windows\system32\CLFS.SYSAddress: 0x80489000 Size: 266240 File Visible: - Signed: -Status: -Name: cmdguard.sysImage Path: C:\Windows\System32\DRIVERS\cmdguard.sysAddress: 0x8BD7E000 Size: 126976 File Visible: - Signed: -Status: -Name: cmdhlp.sysImage Path: C:\Windows\System32\DRIVERS\cmdhlp.sysAddress: 0x8C2FA000 Size: 40960 File Visible: - Signed: -Status: -Name: crashdmp.sysImage Path: C:\Windows\System32\Drivers\crashdmp.sysAddress: 0x8C74C000 Size: 53248 File Visible: - Signed: -Status: -Name: crcdisk.sysImage Path: C:\Windows\system32\drivers\crcdisk.sysAddress: 0x837BF000 Size: 36864 File Visible: - Signed: -Status: -Name: csc.sysImage Path: C:\Windows\system32\drivers\csc.sysAddress: 0x8C66E000 Size: 368640 File Visible: - Signed: -Status: -Name: dfsc.sysImage Path: C:\Windows\System32\Drivers\dfsc.sysAddress: 0x8C6C8000 Size: 94208 File Visible: - Signed: -Status: -Name: disk.sysImage Path: C:\Windows\system32\drivers\disk.sysAddress: 0x8378D000 Size: 69632 File Visible: - Signed: -Status: -Name: drmk.sysImage Path: C:\Windows\system32\drivers\drmk.sysAddress: 0x8BD59000 Size: 151552 File Visible: - Signed: -Status: -Name: dump_atapi.sysImage Path: C:\Windows\System32\Drivers\dump_atapi.sysAddress: 0x8C764000 Size: 32768 File Visible: No Signed: -Status: -Name: dump_dumpata.sysImage Path: C:\Windows\System32\Drivers\dump_dumpata.sysAddress: 0x8C759000 Size: 45056 File Visible: No Signed: -Status: -Name: Dxapi.sysImage Path: C:\Windows\System32\drivers\Dxapi.sysAddress: 0x8C76C000 Size: 40960 File Visible: - Signed: -Status: -Name: dxgkrnl.sysImage Path: C:\Windows\System32\drivers\dxgkrnl.sysAddress: 0x8BACA000 Size: 651264 File Visible: - Signed: -Status: -Name: e1e6032.sysImage Path: C:\Windows\system32\DRIVERS\e1e6032.sysAddress: 0x8BB76000 Size: 241664 File Visible: - Signed: -Status: -Name: ecache.sysImage Path: C:\Windows\System32\drivers\ecache.sysAddress: 0x83766000 Size: 159744 File Visible: - Signed: -Status: -Name: fastfat.SYSImage Path: C:\Windows\System32\Drivers\fastfat.SYSAddress: 0xA972C000 Size: 163840 File Visible: - Signed: -Status: -Name: fdc.sysImage Path: C:\Windows\system32\DRIVERS\fdc.sysAddress: 0x83530000 Size: 45056 File Visible: - Signed: -Status: -Name: fileinfo.sysImage Path: C:\Windows\system32\drivers\fileinfo.sysAddress: 0x805AA000 Size: 65536 File Visible: - Signed: -Status: -Name: fltmgr.sysImage Path: C:\Windows\system32\drivers\fltmgr.sysAddress: 0x807CC000 Size: 204800 File Visible: - Signed: -Status: -Name: Fs_Rec.SYSImage Path: C:\Windows\System32\Drivers\Fs_Rec.SYSAddress: 0x8BFE7000 Size: 36864 File Visible: - Signed: -Status: -Name: fwpkclnt.sysImage Path: C:\Windows\System32\drivers\fwpkclnt.sysAddress: 0x834F4000 Size: 110592 File Visible: - Signed: -Status: -Name: hal.dllImage Path: C:\Windows\system32\hal.dllAddress: 0x82BCB000 Size: 208896 File Visible: - Signed: -Status: -Name: HDAudBus.sysImage Path: C:\Windows\system32\DRIVERS\HDAudBus.sysAddress: 0x8351E000 Size: 73728 File Visible: - Signed: -Status: -Name: HIDCLASS.SYSImage Path: C:\Windows\system32\DRIVERS\HIDCLASS.SYSAddress: 0x8C2A7000 Size: 65536 File Visible: - Signed: -Status: -Name: HIDPARSE.SYSImage Path: C:\Windows\system32\DRIVERS\HIDPARSE.SYSAddress: 0x8BD9D000 Size: 28672 File Visible: - Signed: -Status: -Name: hidusb.sysImage Path: C:\Windows\system32\DRIVERS\hidusb.sysAddress: 0x8C29E000 Size: 36864 File Visible: - Signed: -Status: -Name: HTTP.sysImage Path: C:\Windows\system32\drivers\HTTP.sysAddress: 0xA8914000 Size: 438272 File Visible: - Signed: -Status: -Name: igdkmd32.sysImage Path: C:\Windows\system32\DRIVERS\igdkmd32.sysAddress: 0x8B40F000 Size: 7057408 File Visible: - Signed: -Status: -Name: ikfilesec.sysImage Path: C:\Windows\system32\drivers\ikfilesec.sysAddress: 0x805BA000 Size: 57344 File Visible: - Signed: -Status: -Name: inspect.sysImage Path: C:\Windows\system32\DRIVERS\inspect.sysAddress: 0x8C376000 Size: 77824 File Visible: - Signed: -Status: -Name: intelide.sysImage Path: C:\Windows\system32\DRIVERS\intelide.sysAddress: 0x8077A000 Size: 28672 File Visible: - Signed: -Status: -Name: intelppm.sysImage Path: C:\Windows\system32\DRIVERS\intelppm.sysAddress: 0x8350F000 Size: 61440 File Visible: - Signed: -Status: -Name: kbdclass.sysImage Path: C:\Windows\system32\DRIVERS\kbdclass.sysAddress: 0x8BCBB000 Size: 45056 File Visible: - Signed: -Status: -Name: kbdhid.sysImage Path: C:\Windows\system32\DRIVERS\kbdhid.sysAddress: 0x8C2B7000 Size: 36864 File Visible: - Signed: -Status: -Name: kdcom.dllImage Path: C:\Windows\system32\kdcom.dllAddress: 0x80408000 Size: 32768 File Visible: - Signed: -Status: -Name: ks.sysImage Path: C:\Windows\system32\DRIVERS\ks.sysAddress: 0x8BCD3000 Size: 172032 File Visible: - Signed: -Status: -Name: ksecdd.sysImage Path: C:\Windows\System32\Drivers\ksecdd.sysAddress: 0x82E0F000 Size: 462848 File Visible: - Signed: -Status: -Name: lltdio.sysImage Path: C:\Windows\system32\DRIVERS\lltdio.sysAddress: 0xA88BD000 Size: 65536 File Visible: - Signed: -Status: -Name: luafv.sysImage Path: C:\Windows\system32\drivers\luafv.sysAddress: 0x8C785000 Size: 110592 File Visible: - Signed: -Status: -Name: mcupdate_GenuineIntel.dllImage Path: C:\Windows\system32\mcupdate_GenuineIntel.dllAddress: 0x80410000 Size: 393216 File Visible: - Signed: -Status: -Name: monitor.sysImage Path: C:\Windows\system32\DRIVERS\monitor.sysAddress: 0x8C776000 Size: 61440 File Visible: - Signed: -Status: -Name: mouclass.sysImage Path: C:\Windows\system32\DRIVERS\mouclass.sysAddress: 0x8BCC6000 Size: 45056 File Visible: - Signed: -Status: -Name: mouhid.sysImage Path: C:\Windows\system32\DRIVERS\mouhid.sysAddress: 0x8C2C0000 Size: 32768 File Visible: - Signed: -Status: -Name: mountmgr.sysImage Path: C:\Windows\System32\drivers\mountmgr.sysAddress: 0x80796000 Size: 65536 File Visible: - Signed: -Status: -Name: mpsdrv.sysImage Path: C:\Windows\System32\drivers\mpsdrv.sysAddress: 0xA89B5000 Size: 86016 File Visible: - Signed: -Status: -Name: mrxdav.sysImage Path: C:\Windows\system32\drivers\mrxdav.sysAddress: 0xA89CA000 Size: 131072 File Visible: - Signed: -Status: -Name: mrxsmb.sysImage Path: C:\Windows\system32\DRIVERS\mrxsmb.sysAddress: 0x8C7A8000 Size: 126976 File Visible: - Signed: -Status: -Name: mrxsmb10.sysImage Path: C:\Windows\system32\DRIVERS\mrxsmb10.sysAddress: 0x8C7C7000 Size: 233472 File Visible: - Signed: -Status: -Name: mrxsmb20.sysImage Path: C:\Windows\system32\DRIVERS\mrxsmb20.sysAddress: 0x8C3D1000 Size: 98304 File Visible: - Signed: -Status: -Name: Msfs.SYSImage Path: C:\Windows\System32\Drivers\Msfs.SYSAddress: 0x8BDD9000 Size: 45056 File Visible: - Signed: -Status: -Name: msisadrv.sysImage Path: C:\Windows\system32\drivers\msisadrv.sysAddress: 0x806E3000 Size: 32768 File Visible: - Signed: -Status: -Name: msiscsi.sysImage Path: C:\Windows\system32\DRIVERS\msiscsi.sysAddress: 0x83553000 Size: 188416 File Visible: - Signed: -Status: -Name: msrpc.sysImage Path: C:\Windows\system32\drivers\msrpc.sysAddress: 0x82F8B000 Size: 176128 File Visible: - Signed: -Status: -Name: mssmbios.sysImage Path: C:\Windows\system32\DRIVERS\mssmbios.sysAddress: 0x8BCFD000 Size: 40960 File Visible: - Signed: -Status: -Name: mup.sysImage Path: C:\Windows\System32\Drivers\mup.sysAddress: 0x83757000 Size: 61440 File Visible: - Signed: -Status: -Name: ndis.sysImage Path: C:\Windows\system32\drivers\ndis.sysAddress: 0x82E80000 Size: 1093632 File Visible: - Signed: -Status: -Name: ndistapi.sysImage Path: C:\Windows\system32\DRIVERS\ndistapi.sysAddress: 0x835E4000 Size: 45056 File Visible: - Signed: -Status: -Name: ndisuio.sysImage Path: C:\Windows\system32\DRIVERS\ndisuio.sysAddress: 0xA88F7000 Size: 40960 File Visible: - Signed: -Status: -Name: ndiswan.sysImage Path: C:\Windows\system32\DRIVERS\ndiswan.sysAddress: 0x805C8000 Size: 143360 File Visible: - Signed: -Status: -Name: NDProxy.SYSImage Path: C:\Windows\System32\Drivers\NDProxy.SYSAddress: 0x8BD48000 Size: 69632 File Visible: - Signed: -Status: -Name: netbios.sysImage Path: C:\Windows\system32\DRIVERS\netbios.sysAddress: 0x8C389000 Size: 57344 File Visible: - Signed: -Status: -Name: netbt.sysImage Path: C:\Windows\System32\DRIVERS\netbt.sysAddress: 0x8C2C8000 Size: 204800 File Visible: - Signed: -Status: -Name: NETIO.SYSImage Path: C:\Windows\system32\drivers\NETIO.SYSAddress: 0x82FB6000 Size: 237568 File Visible: - Signed: -Status: -Name: netr73.sysImage Path: C:\Windows\system32\DRIVERS\netr73.sysAddress: 0x8C223000 Size: 495616 File Visible: - Signed: -Status: -Name: Npfs.SYSImage Path: C:\Windows\System32\Drivers\Npfs.SYSAddress: 0x8BDE4000 Size: 57344 File Visible: - Signed: -Status: -Name: nsiproxy.sysImage Path: C:\Windows\system32\drivers\nsiproxy.sysAddress: 0x8C664000 Size: 40960 File Visible: - Signed: -Status: -Name: Ntfs.sysImage Path: C:\Windows\System32\Drivers\Ntfs.sysAddress: 0x83607000 Size: 1110016 File Visible: - Signed: -Status: -Name: ntkrnlpa.exeImage Path: C:\Windows\system32\ntkrnlpa.exeAddress: 0x82812000 Size: 3903488 File Visible: - Signed: -Status: -Name: Null.SYSImage Path: C:\Windows\System32\Drivers\Null.SYSAddress: 0x8BFF0000 Size: 28672 File Visible: - Signed: -Status: -Name: nwifi.sysImage Path: C:\Windows\system32\DRIVERS\nwifi.sysAddress: 0xA88CD000 Size: 172032 File Visible: - Signed: -Status: -Name: pacer.sysImage Path: C:\Windows\system32\DRIVERS\pacer.sysAddress: 0x8C360000 Size: 90112 File Visible: - Signed: -Status: -Name: partmgr.sysImage Path: C:\Windows\System32\drivers\partmgr.sysAddress: 0x80712000 Size: 61440 File Visible: - Signed: -Status: -Name: pci.sysImage Path: C:\Windows\system32\drivers\pci.sysAddress: 0x806EB000 Size: 159744 File Visible: - Signed: -Status: -Name: pciide.sysImage Path: C:\Windows\system32\drivers\pciide.sysAddress: 0x8078F000 Size: 28672 File Visible: - Signed: -Status: -Name: PCIIDEX.SYSImage Path: C:\Windows\system32\DRIVERS\PCIIDEX.SYSAddress: 0x80781000 Size: 57344 File Visible: - Signed: -Status: -Name: peauth.sysImage Path: C:\Windows\system32\drivers\peauth.sysAddress: 0xA964E000 Size: 909312 File Visible: - Signed: -Status: -Name: PnpManagerImage Path: \Driver\PnpManagerAddress: 0x82812000 Size: 3903488 File Visible: - Signed: -Status: -Name: portcls.sysImage Path: C:\Windows\system32\drivers\portcls.sysAddress: 0x8BFBA000 Size: 184320 File Visible: - Signed: -Status: -Name: PSHED.dllImage Path: C:\Windows\system32\PSHED.dllAddress: 0x80470000 Size: 69632 File Visible: - Signed: -Status: -Name: PxHelp20.sysImage Path: C:\Windows\System32\Drivers\PxHelp20.sysAddress: 0x80600000 Size: 35648 File Visible: - Signed: -Status: -Name: RapportKELL.sysImage Path: C:\Program Files\Trusteer\Rapport\bin\RapportKELL.sysAddress: 0x8C657000 Size: 51456 File Visible: - Signed: -Status: -Name: RapportPG.sysImage Path: C:\Program Files\Trusteer\Rapport\bin\RapportPG.sysAddress: 0x8C642000 Size: 83840 File Visible: - Signed: -Status: -Name: rasacd.sysImage Path: C:\Windows\System32\DRIVERS\rasacd.sysAddress: 0x8BDF2000 Size: 36864 File Visible: - Signed: -Status: -Name: rasl2tp.sysImage Path: C:\Windows\system32\DRIVERS\rasl2tp.sysAddress: 0x835CD000 Size: 94208 File Visible: - Signed: -Status: -Name: raspppoe.sysImage Path: C:\Windows\system32\DRIVERS\raspppoe.sysAddress: 0x835EF000 Size: 61440 File Visible: - Signed: -Status: -Name: raspptp.sysImage Path: C:\Windows\system32\DRIVERS\raspptp.sysAddress: 0x805EB000 Size: 81920 File Visible: - Signed: -Status: -Name: rassstp.sysImage Path: C:\Windows\system32\DRIVERS\rassstp.sysAddress: 0x8BC0D000 Size: 86016 File Visible: - Signed: -Status: -Name: RAWImage Path: \FileSystem\RAWAddress: 0x82812000 Size: 3903488 File Visible: - Signed: -Status: -Name: rdbss.sysImage Path: C:\Windows\system32\DRIVERS\rdbss.sysAddress: 0x8C606000 Size: 245760 File Visible: - Signed: -Status: -Name: RDPCDD.sysImage Path: C:\Windows\System32\DRIVERS\RDPCDD.sysAddress: 0x8BE00000 Size: 32768 File Visible: - Signed: -Status: -Name: rdpdr.sysImage Path: C:\Windows\system32\DRIVERS\rdpdr.sysAddress: 0x8BC22000 Size: 561152 File Visible: - Signed: -Status: -Name: rdpencdd.sysImage Path: C:\Windows\system32\drivers\rdpencdd.sysAddress: 0x8BDD1000 Size: 32768 File Visible: - Signed: -Status: -Name: rootrepeal.sysImage Path: C:\Windows\system32\drivers\rootrepeal.sysAddress: 0xA9776000 Size: 49152 File Visible: No Signed: -Status: -Name: rspndr.sysImage Path: C:\Windows\system32\DRIVERS\rspndr.sysAddress: 0xA8901000 Size: 77824 File Visible: - Signed: -Status: -Name: RTKVHDA.sysImage Path: C:\Windows\system32\drivers\RTKVHDA.sysAddress: 0x8BE0A000 Size: 1767872 File Visible: - Signed: -Status: -Name: SASDIFSV.SYSImage Path: C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYSAddress: 0x8C3CB000 Size: 24576 File Visible: - Signed: -Status: -Name: SASKUTIL.sysImage Path: C:\Program Files\SUPERAntiSpyware\SASKUTIL.sysAddress: 0x8C3AA000 Size: 135168 File Visible: - Signed: -Status: -Name: secdrv.SYSImage Path: C:\Windows\System32\Drivers\secdrv.SYSAddress: 0xA9754000 Size: 40960 File Visible: - Signed: -Status: -Name: smb.sysImage Path: C:\Windows\system32\DRIVERS\smb.sysAddress: 0x8C304000 Size: 81920 File Visible: - Signed: -Status: -Name: spldr.sysImage Path: C:\Windows\System32\Drivers\spldr.sysAddress: 0x8374F000 Size: 32768 File Visible: - Signed: -Status: -Name: spsys.sysImage Path: C:\Windows\system32\drivers\spsys.sysAddress: 0xA880E000 Size: 716800 File Visible: - Signed: -Status: -Name: srv.sysImage Path: C:\Windows\System32\DRIVERS\srv.sysAddress: 0xA9602000 Size: 311296 File Visible: - Signed: -Status: -Name: srv2.sysImage Path: C:\Windows\System32\DRIVERS\srv2.sysAddress: 0x837C8000 Size: 159744 File Visible: - Signed: -Status: -Name: srvnet.sysImage Path: C:\Windows\System32\DRIVERS\srvnet.sysAddress: 0xA897F000 Size: 118784 File Visible: - Signed: -Status: -Name: storport.sysImage Path: C:\Windows\system32\DRIVERS\storport.sysAddress: 0x83581000 Size: 266240 File Visible: - Signed: -Status: -Name: swenum.sysImage Path: C:\Windows\system32\DRIVERS\swenum.sysAddress: 0x8BCD1000 Size: 4992 File Visible: - Signed: -Status: -Name: tcpip.sysImage Path: C:\Windows\System32\drivers\tcpip.sysAddress: 0x8340D000 Size: 946176 File Visible: - Signed: -Status: -Name: tcpipreg.sysImage Path: C:\Windows\System32\drivers\tcpipreg.sysAddress: 0xA975E000 Size: 49152 File Visible: - Signed: -Status: -Name: TDI.SYSImage Path: C:\Windows\system32\DRIVERS\TDI.SYSAddress: 0x835C2000 Size: 45056 File Visible: - Signed: -Status: -Name: tdx.sysImage Path: C:\Windows\system32\DRIVERS\tdx.sysAddress: 0x8C20D000 Size: 90112 File Visible: - Signed: -Status: -Name: termdd.sysImage Path: C:\Windows\system32\DRIVERS\termdd.sysAddress: 0x8BCAB000 Size: 65536 File Visible: - Signed: -Status: -Name: TSDDD.dllImage Path: C:\Windows\System32\TSDDD.dllAddress: 0x818D0000 Size: 36864 File Visible: - Signed: -Status: -Name: tunmp.sysImage Path: C:\Windows\system32\DRIVERS\tunmp.sysAddress: 0x837F3000 Size: 36864 File Visible: - Signed: -Status: -Name: umbus.sysImage Path: C:\Windows\system32\DRIVERS\umbus.sysAddress: 0x8BD07000 Size: 53248 File Visible: - Signed: -Status: -Name: USBD.SYSImage Path: C:\Windows\system32\DRIVERS\USBD.SYSAddress: 0x8C29C000 Size: 8192 File Visible: - Signed: -Status: -Name: usbehci.sysImage Path: C:\Windows\system32\DRIVERS\usbehci.sysAddress: 0x8B400000 Size: 61440 File Visible: - Signed: -Status: -Name: usbhub.sysImage Path: C:\Windows\system32\DRIVERS\usbhub.sysAddress: 0x8BD14000 Size: 212992 File Visible: - Signed: -Status: -Name: USBPORT.SYSImage Path: C:\Windows\system32\DRIVERS\USBPORT.SYSAddress: 0x8BBBC000 Size: 253952 File Visible: - Signed: -Status: -Name: usbuhci.sysImage Path: C:\Windows\system32\DRIVERS\usbuhci.sysAddress: 0x8BBB1000 Size: 45056 File Visible: - Signed: -Status: -Name: vga.sysImage Path: C:\Windows\System32\drivers\vga.sysAddress: 0x8BDA4000 Size: 49152 File Visible: - Signed: -Status: -Name: VIDEOPRT.SYSImage Path: C:\Windows\System32\drivers\VIDEOPRT.SYSAddress: 0x8BDB0000 Size: 135168 File Visible: - Signed: -Status: -Name: volmgr.sysImage Path: C:\Windows\system32\drivers\volmgr.sysAddress: 0x80721000 Size: 61440 File Visible: - Signed: -Status: -Name: volmgrx.sysImage Path: C:\Windows\System32\drivers\volmgrx.sysAddress: 0x80730000 Size: 303104 File Visible: - Signed: -Status: -Name: volsnap.sysImage Path: C:\Windows\system32\drivers\volsnap.sysAddress: 0x83716000 Size: 233472 File Visible: - Signed: -Status: -Name: wanarp.sysImage Path: C:\Windows\system32\DRIVERS\wanarp.sysAddress: 0x8C397000 Size: 77824 File Visible: - Signed: -Status: -Name: watchdog.sysImage Path: C:\Windows\System32\drivers\watchdog.sysAddress: 0x8BB69000 Size: 53248 File Visible: - Signed: -Status: -Name: Wdf01000.sysImage Path: C:\Windows\system32\drivers\Wdf01000.sysAddress: 0x8060B000 Size: 507904 File Visible: - Signed: -Status: -Name: WDFLDR.SYSImage Path: C:\Windows\system32\drivers\WDFLDR.SYSAddress: 0x80687000 Size: 53248 File Visible: - Signed: -Status: -Name: Win32kImage Path: \Driver\Win32kAddress: 0x816B0000 Size: 2105344 File Visible: - Signed: -Status: -Name: win32k.sysImage Path: C:\Windows\System32\win32k.sysAddress: 0x816B0000 Size: 2105344 File Visible: - Signed: -Status: -Name: WMILIB.SYSImage Path: C:\Windows\system32\drivers\WMILIB.SYSAddress: 0x806DA000 Size: 36864 File Visible: - Signed: -Status: -Name: WMIxWDMImage Path: \Driver\WMIxWDMAddress: 0x82812000 Size: 3903488 File Visible: - Signed: -Status: -OOTREPEAL © AD, 2007-2009==================================================Scan Start Time: 2009/07/25 00:35Program Version: Version 1.3.2.0Windows Version: Windows Vista SP1==================================================Hidden Services-------------------ROOTREPEAL © AD, 2007-2009==================================================Scan Start Time: 2009/07/25 00:35Program Version: Version 1.3.2.0Windows Version: Windows Vista SP1==================================================Processes-------------------Path: SystemPID: 4 Status: Locked to the Windows API!Path: C:\Windows\System32\svchost.exePID: 260 Status: -Path: C:\Windows\System32\smss.exePID: 464 Status: -Path: C:\Windows\System32\csrss.exePID: 532 Status: -Path: C:\Windows\System32\wininit.exePID: 576 Status: -Path: C:\Windows\System32\csrss.exePID: 588 Status: -Path: C:\Windows\System32\winlogon.exePID: 648 Status: -Path: C:\Windows\System32\services.exePID: 668 Status: -Path: C:\Windows\System32\lsass.exePID: 680 Status: -Path: C:\Windows\System32\lsm.exePID: 692 Status: -Path: C:\Windows\System32\hkcmd.exePID: 848 Status: -Path: C:\Windows\System32\svchost.exePID: 912 Status: -Path: C:\Program Files\AVG\AVG8\avgrsx.exePID: 920 Status: -Path: C:\Program Files\Java\jre6\bin\jusched.exePID: 948 Status: -Path: C:\Windows\System32\svchost.exePID: 980 Status: -Path: C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exePID: 1028 Status: -Path: C:\Windows\System32\svchost.exePID: 1148 Status: -Path: C:\Windows\System32\wbem\unsecapp.exePID: 1156 Status: -Path: C:\Windows\System32\svchost.exePID: 1168 Status: -Path: C:\Windows\System32\svchost.exePID: 1228 Status: -Path: C:\PROGRA~1\AVG\AVG8\avgwdsvc.exePID: 1240 Status: -Path: C:\Windows\System32\svchost.exePID: 1276 Status: -Path: C:\Program Files\Spyware Doctor\pctsTray.exePID: 1312 Status: -Path: C:\Windows\System32\svchost.exePID: 1320 Status: -Path: C:\Windows\System32\audiodg.exePID: 1432 Status: Locked to the Windows API!Path: C:\Windows\System32\svchost.exePID: 1532 Status: -Path: C:\Windows\System32\SLsvc.exePID: 1596 Status: -Path: C:\Windows\System32\wbem\WmiPrvSE.exePID: 1604 Status: -Path: C:\Windows\System32\igfxsrvc.exePID: 1612 Status: -Path: C:\Windows\System32\svchost.exePID: 1652 Status: -Path: C:\Windows\System32\svchost.exePID: 1868 Status: -Path: C:\Windows\System32\spoolsv.exePID: 2040 Status: -Path: C:\Program Files\Spyware Doctor\pctsAuxs.exePID: 2224 Status: -Path: C:\Program Files\Spyware Doctor\pctsSvc.exePID: 2256 Status: -Path: C:\Windows\System32\svchost.exePID: 2308 Status: -Path: C:\Windows\System32\svchost.exePID: 2340 Status: -Path: C:\Windows\System32\SearchIndexer.exePID: 2392 Status: -Path: C:\Windows\System32\igfxpers.exePID: 2416 Status: -Path: C:\Windows\System32\svchost.exePID: 2488 Status: -Path: C:\Windows\System32\wuauclt.exePID: 2604 Status: -Path: C:\Program Files\Spybot - Search & Destroy\SDWinSec.exePID: 2640 Status: -Path: C:\Program Files\Windows Media Player\wmpnetwk.exePID: 2676 Status: -Path: C:\Program Files\Mozilla Firefox\firefox.exePID: 2936 Status: -Path: C:\Windows\RtHDVCpl.exePID: 3144 Status: -Path: C:\Program Files\Common Files\Real\Update_OB\realsched.exePID: 3196 Status: -Path: C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exePID: 3204 Status: -Path: C:\Program Files\AVG\AVG8\avgtray.exePID: 3228 Status: -Path: C:\Program Files\COMODO\COMODO Internet Security\cfp.exePID: 3636 Status: -Path: C:\Windows\System32\taskeng.exePID: 3700 Status: -Path: C:\Program Files\Windows Media Player\wmpnscfg.exePID: 3724 Status: -Path: C:\Windows\System32\dwm.exePID: 3820 Status: -Path: C:\Windows\explorer.exePID: 3860 Status: -Path: C:\Users\Big Si\AppData\Local\Google\Update\GoogleUpdate.exePID: 4012 Status: -Path: C:\Users\Big Si\Desktop\RootRepeal.exePID: 4024 Status: -Path: C:\Windows\System32\mobsync.exePID: 4072 Status: -Path: C:\Windows\System32\SearchProtocolHost.exePID: 4636 Status: -Path: C:\Windows\System32\SearchFilterHost.exePID: 4664 Status: -OTL logOTL logfile created on: 25/07/2009 12:36:20 AM - Run 1OTL by OldTimer - Version 3.0.10.3 Folder = C:\Users\Big Si\DownloadsWindows Vista Business Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstationInternet Explorer (Version = 7.0.6001.18000)Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy1012.45 Mb Total Physical Memory | 273.96 Mb Available Physical Memory | 27.06% Memory free2.24 Gb Paging File | 0.94 Gb Available in Paging File | 42.17% Paging File freePaging file location(s): ?:\pagefile.sys [binary data]%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program FilesDrive C: | 138.96 Gb Total Space | 50.62 Gb Free Space | 36.43% Space Free | Partition Type: NTFSDrive D: | 149.01 Gb Total Space | 148.91 Gb Free Space | 99.93% Space Free | Partition Type: NTFSDrive E: | 10.00 Gb Total Space | 6.56 Gb Free Space | 65.62% Space Free | Partition Type: NTFSDrive F: | 659.16 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFSG: Drive not present or media not loadedH: Drive not present or media not loadedI: Drive not present or media not loadedComputer Name: PCSBSSDT5Current User Name: Big SiLogged in as Administrator.Current Boot Mode: NormalScan Mode: Current userCompany Name Whitelist: OffSkip Microsoft Files: OffFile Age = 30 DaysOutput = Minimal========== Processes (SafeList) ==========PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe ()PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)PRC - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)PRC - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)PRC - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)PRC - C:\Windows\System32\hkcmd.exe (Intel Corporation)PRC - C:\Windows\System32\igfxpers.exe (Intel Corporation)PRC - C:\Windows\System32\igfxsrvc.exe (Intel Corporation)PRC - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe ()PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)PRC - C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)PRC - C:\Users\Big Si\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)PRC - C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation)PRC - C:\Windows\System32\wbem\wmiprvse.exe (Microsoft Corporation)PRC - C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)PRC - C:\Windows\System32\mobsync.exe (Microsoft Corporation)PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)PRC - C:\Users\Big Si\Downloads\OTL.exe (OldTimer Tools)========== Win32 Services (SafeList) ==========SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)SRV - (cmdAgent [Auto | Running]) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe ()SRV - (Eventlog [Auto | Running]) -- C:\Windows\System32\wevtsvc.dll (Microsoft Corporation)SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)SRV - (GoogleDesktopManager [On_Demand | Stopped]) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)SRV - (idsvc [unknown | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)SRV - (KService [Auto | Stopped]) -- C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)SRV - (Microsoft Office Groove Audit Service [On_Demand | Stopped]) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)SRV - (RoxMediaDB9 [On_Demand | Stopped]) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)SRV - (RoxWatch9 [Auto | Stopped]) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)SRV - (SBSDWSCService [Auto | Running]) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)SRV - (sdAuxService [Auto | Running]) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)SRV - (sdCoreService [Auto | Running]) -- C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)SRV - (stllssvr [On_Demand | Stopped]) -- C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)SRV - (usnjsvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)SRV - (WinDefend [Auto | Running]) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)SRV - (WLSetupSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)SRV - (WMPNetworkSvc [Auto | Running]) -- C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)========== Driver Services (SafeList) ==========DRV - (adp94xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)DRV - (adpahci [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)DRV - (adpu160m [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)DRV - (adpu320 [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)DRV - (aic78xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)DRV - (aliide [Disabled | Stopped]) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)DRV - (arc [Disabled | Stopped]) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)DRV - (arcsas [Disabled | Stopped]) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)DRV - (AvgLdx86 [system | Running]) -- C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)DRV - (AvgMfx86 [system | Running]) -- C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)DRV - (BrFiltLo [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)DRV - (BrFiltUp [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)DRV - (Brserid [Disabled | Stopped]) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)DRV - (BrSerWdm [Disabled | Stopped]) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)DRV - (BrUsbMdm [Disabled | Stopped]) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)DRV - (BrUsbSer [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)DRV - (cmdGuard [system | Running]) -- C:\Windows\System32\DRIVERS\cmdguard.sys (COMODO)DRV - (cmdHlp [system | Running]) -- C:\Windows\System32\DRIVERS\cmdhlp.sys (COMODO)DRV - (cmdide [Disabled | Stopped]) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)DRV - (e1express [On_Demand | Running]) -- C:\Windows\System32\DRIVERS\e1e6032.sys (Intel Corporation)DRV - (E1G60 [On_Demand | Stopped]) -- C:\Windows\System32\DRIVERS\E1G60I32.sys (Intel Corporation)DRV - (elxstor [Disabled | Stopped]) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)DRV - (HpCISSs [Disabled | Stopped]) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)DRV - (iaStor [Disabled | Stopped]) -- C:\Windows\system32\drivers\iastor.sys (Intel Corporation)DRV - (iaStorV [Disabled | Stopped]) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)DRV - (igfx [On_Demand | Running]) -- C:\Windows\System32\DRIVERS\igdkmd32.sys (Intel Corporation)DRV - (iirsp [Disabled | Stopped]) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)DRV - (IKFileSec [boot | Running]) -- C:\Windows\system32\drivers\ikfilesec.sys (PCTools Research Pty Ltd.)DRV - (IKSysFlt [On_Demand | Stopped]) -- C:\Windows\System32\drivers\iksysflt.sys (PCTools Research Pty Ltd.)DRV - (IKSysSec [On_Demand | Stopped]) -- C:\Windows\System32\drivers\iksyssec.sys (PCTools Research Pty Ltd.)DRV - (Inspect [system | Running]) -- C:\Windows\System32\DRIVERS\inspect.sys (COMODO)DRV - (IntcAzAudAddService [On_Demand | Running]) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)DRV - (iteatapi [Disabled | Stopped]) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)DRV - (iteraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)DRV - (LSI_FC [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)DRV - (LSI_SAS [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)DRV - (LSI_SCSI [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)DRV - (megasas [Disabled | Stopped]) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)DRV - (Mraid35x [Disabled | Stopped]) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)DRV - (netr73 [On_Demand | Running]) -- C:\Windows\System32\DRIVERS\netr73.sys (Ralink Technology, Corp.)DRV - (nfrd960 [Disabled | Stopped]) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)DRV - (ntrigdigi [Disabled | Stopped]) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)DRV - (nvraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)DRV - (nvstor [Disabled | Stopped]) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)DRV - (PxHelp20 [boot | Running]) -- C:\Windows\System32\Drivers\PxHelp20.sys (Sonic Solutions)DRV - (ql2300 [Disabled | Stopped]) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)DRV - (ql40xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)DRV - (R300 [On_Demand | Stopped]) -- C:\Windows\System32\DRIVERS\atikmdag.sys (ATI Technologies Inc.)DRV - (RapportKELL [system | Running]) -- C:\Program Files\Trusteer\Rapport\bin\RapportKELL.sys (Trusteer Ltd.)DRV - (RapportPG [system | Running]) -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)DRV - (SASDIFSV [system | Running]) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)DRV - (SASENUM [On_Demand | Stopped]) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)DRV - (SASKUTIL [system | Running]) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)DRV - (secdrv [Auto | Running]) -- C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)DRV - (SiSRaid2 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)DRV - (SiSRaid4 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)DRV - (Symc8xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)DRV - (Sym_hi [Disabled | Stopped]) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)DRV - (Sym_u3 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)DRV - (uliahci [Disabled | Stopped]) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)DRV - (UlSata [Disabled | Stopped]) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)DRV - (ulsata2 [Disabled | Stopped]) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)DRV - (usbbus [On_Demand | Stopped]) -- C:\Windows\System32\DRIVERS\lgusbbus.sys (LG Electronics Inc.)DRV - (UsbDiag [On_Demand | Stopped]) -- C:\Windows\System32\DRIVERS\lgusbdiag.sys (LG Electronics Inc.)DRV - (USBModem [On_Demand | Stopped]) -- C:\Windows\System32\DRIVERS\lgusbmodem.sys (LG Electronics Inc.)DRV - (viaide [Disabled | Stopped]) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)DRV - (vsdatant [On_Demand | Stopped]) -- C:\Windows\System32\drivers\vsdatant.sys (Check Point Software Technologies LTD)DRV - (vsmraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)========== Standard Registry (SafeList) ==================== Internet Explorer ==========IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-onsIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRiskIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htmIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.kent.ac.uk/student/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0========== FireFox ==========FF - prefs.js..browser.search.useDBForOrder: trueFF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.1FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/06/17 08:21:41 | 00,000,000 | ---D | M]FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/07/24 03:30:07 | 00,000,000 | ---D | M]FF - HKLM\software\mozilla\Mozilla Firefox 3.5.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/07/19 11:14:09 | 00,000,000 | ---D | M]FF - HKLM\software\mozilla\Mozilla Firefox 3.5.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/07/24 00:24:05 | 00,000,000 | ---D | M]FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.6\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2009/03/01 14:48:39 | 00,000,000 | ---D | M]FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.6\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2009/07/24 00:24:05 | 00,000,000 | ---D | M][2008/11/04 01:00:28 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Extensions[2008/11/04 01:00:28 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}[2009/07/24 08:01:49 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Firefox\Profiles\4p5b4vyi.default\extensions[2009/07/08 07:45:33 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Firefox\Profiles\4p5b4vyi.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}[2009/06/30 22:50:26 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Firefox\Profiles\4p5b4vyi.default\extensions\{1ABADB6E-DC4B-11DA-9F70-791A9CD9513E}[2008/07/30 02:58:15 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Firefox\Profiles\4p5b4vyi.default\extensions\{4AB21F99-91C5-4a9d-813E-425841874FB1}[2008/07/30 02:54:38 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Firefox\Profiles\4p5b4vyi.default\extensions\{526fd696-27a0-11dc-8314-0800200c9a66}[2008/11/04 01:10:33 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Firefox\Profiles\4p5b4vyi.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}[2008/05/14 23:49:04 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Firefox\Profiles\4p5b4vyi.default\extensions\{c36177c0-224a-11da-8cd6-0800200c9a66}[2009/07/02 08:01:18 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Firefox\Profiles\4p5b4vyi.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}[2009/06/30 22:51:58 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Firefox\Profiles\4p5b4vyi.default\extensions\[email protected][2009/06/03 15:49:45 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Firefox\Profiles\4p5b4vyi.default\extensions\firefox@facebook(27).com[2009/07/02 08:01:19 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Firefox\Profiles\4p5b4vyi.default\extensions\[email protected][2009/07/08 07:45:18 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Firefox\Profiles\4p5b4vyi.default\extensions\[email protected][2009/07/08 07:45:18 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Firefox\Profiles\4p5b4vyi.default\extensions\[email protected][2009/03/11 19:34:35 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Firefox\Profiles\4p5b4vyi.default\extensions\[email protected][2009/06/30 23:04:43 | 00,000,000 | ---D | M] -- C:\Users\Big Si\AppData\Roaming\mozilla\Firefox\Profiles\4p5b4vyi.default\extensions\[email protected][2009/06/25 22:14:08 | 00,007,976 | ---- | M] () -- C:\Users\Big Si\AppData\Roaming\Mozilla\FireFox\Profiles\4p5b4vyi.default\searchplugins\oneriot-social-web-search.xml[2009/07/24 08:01:50 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions[2009/07/19 11:14:09 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}[2008/12/16 20:28:19 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}[2009/03/28 00:52:25 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}[2009/07/19 11:13:51 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll[2009/07/19 11:13:51 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll[2007/04/10 18:21:08 | 00,163,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\np-mswmp.dll[2008/02/27 17:57:38 | 00,106,496 | ---- | M] (British Broadcasting Corporation) -- C:\Program Files\mozilla firefox\plugins\npBBCPlugin.dll[2009/03/09 06:19:09 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll[2007/09/28 18:53:46 | 00,717,312 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll[2007/09/28 18:54:22 | 00,098,304 | ---- | M] (DivX, Inc) -- C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll[2009/07/19 11:13:56 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll[2006/10/26 21:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL[2007/05/10 22:52:34 | 00,095,864 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll[2008/01/14 15:43:30 | 00,144,720 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nppl3260.dll[2009/03/01 14:48:37 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll[2009/03/01 14:48:37 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll[2009/03/01 14:48:37 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll[2009/03/01 14:48:37 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll[2009/03/01 14:48:37 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll[2009/03/01 14:48:37 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll[2009/03/01 14:48:37 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll[2008/01/14 15:44:04 | 00,024,576 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprjplug.dll[2008/01/14 15:42:59 | 00,081,920 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprpjplug.dll[2009/06/24 13:14:16 | 00,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml[2009/06/24 13:14:16 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml[2009/06/24 13:14:16 | 00,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml[2009/06/24 13:14:16 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml[2009/06/24 13:14:16 | 00,000,769 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml[2009/06/24 13:14:16 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml[2009/06/24 13:14:16 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml[2009/06/24 13:14:16 | 00,000,831 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xmlO1 HOSTS File: (318388 bytes) - C:\Windows\System32\drivers\etc\HostsO1 - Hosts: 127.0.0.1 localhostO1 - Hosts: ::1 localhostO1 - Hosts: 127.0.0.1 www.007guard.comO1 - Hosts: 127.0.0.1 007guard.comO1 - Hosts: 127.0.0.1 008i.comO1 - Hosts: 127.0.0.1 www.008k.comO1 - Hosts: 127.0.0.1 008k.comO1 - Hosts: 127.0.0.1 www.00hq.comO1 - Hosts: 127.0.0.1 00hq.comO1 - Hosts: 127.0.0.1 010402.comO1 - Hosts: 127.0.0.1 www.032439.comO1 - Hosts: 127.0.0.1 032439.comO1 - Hosts: 127.0.0.1 www.100888290cs.comO1 - Hosts: 127.0.0.1 100888290cs.comO1 - Hosts: 127.0.0.1 www.100sexlinks.comO1 - Hosts: 127.0.0.1 100sexlinks.comO1 - Hosts: 127.0.0.1 www.10sek.comO1 - Hosts: 127.0.0.1 10sek.comO1 - Hosts: 127.0.0.1 www.123topsearch.comO1 - Hosts: 127.0.0.1 123topsearch.comO1 - Hosts: 127.0.0.1 www.132.comO1 - Hosts: 127.0.0.1 132.comO1 - Hosts: 127.0.0.1 www.136136.netO1 - Hosts: 127.0.0.1 136136.netO1 - Hosts: 127.0.0.1 www.163ns.comO1 - Hosts: 10922 more lines...O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll (Google Inc.)O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)O3 - HKLM\..\Toolbar: (Veoh Browser Plug-in) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll (Veoh Networks Inc)O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.O4 - HKLM..\Run: [] File not foundO4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe ()O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe (Intel Corporation)O4 - HKLM..\Run: [igfxTray] C:\Windows\System32\igfxtray.exe (Intel Corporation)O4 - HKLM..\Run: [iSTray] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)O4 - HKLM..\Run: [iSUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)O4 - HKLM..\Run: [pdfFactory Pro Dispatcher v3] C:\Windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe (FinePrint Software, LLC)O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe (Intel Corporation)O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)O4 - HKCU..\Run: [] File not foundO4 - HKCU..\Run: [Google Update] C:\Users\Big Si\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)O4 - HKCU..\Run: [MsnMsgr] C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe (Microsoft Corporation)O4 - HKCU..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskmgr = 0O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)O13 - gopher Prefix: missingO15 - HKLM\..Trusted Domains: 56 domain(s) and sub-domain(s) not assigned to a zone.O15 - HKCU\..Trusted Domains: kent.ac.uk ([webct] https in Trusted sites)O15 - HKCU\..Trusted Domains: 65 domain(s) and sub-domain(s) not assigned to a zone.O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab (MessengerStatsClient Class)O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0)O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab (Shockwave Flash Object)O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)O18 - Protocol\Filter: - application/x-internet-signup - C:\Program Files\Tiscali\Tiscali Internet\dlls\tiscalifilter.dll ()O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)O31 - SafeBoot: AlternateShell - cmd.exeO32 - HKLM CDRom: AutoRun - 1O32 - AutoRun File - [2006/09/18 22:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]O32 - AutoRun File - [2004/05/06 04:02:21 | 00,000,145 | R--- | M] () - F:\autorun.inf -- [ CDFS ]O33 - MountPoints2\{2df57193-99f6-11dc-b156-806e6f6e6963}\Shell - "" = AutoRunO33 - MountPoints2\{2df57193-99f6-11dc-b156-806e6f6e6963}\Shell\AutoRun\command - "" = F:\Setup\rsrc\Autorun.exe -- [2000/01/17 17:28:36 | 00,028,672 | R--- | M] (Dipl.-Ing. Stefan Krueger <[email protected]>)O33 - MountPoints2\{2df57193-99f6-11dc-b156-806e6f6e6963}\Shell\dinstall\command - "" = F:\Directx\dxsetup.exe -- [2004/07/09 12:08:36 | 00,472,576 | R--- | M] (Microsoft Corporation)O34 - HKLM BootExecute: (autocheck) - File not foundO34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)O34 - HKLM BootExecute: (*) - File not foundO34 - HKLM BootExecute: (lsdelete) - File not found========== Files/Folders - Created Within 30 Days ==========[2009/07/25 00:31:41 | 00,000,014 | ---- | C] () -- C:\Users\Big Si\Desktop\settings.dat[2009/07/25 00:25:11 | 00,000,000 | ---D | C] -- C:\Rooter$[2009/07/24 21:46:07 | 00,001,709 | ---- | C] () -- C:\Users\Public\Desktop\Vampire - The Masquerade Bloodlines.lnk[2009/07/24 21:45:59 | 00,000,292 | ---- | C] () -- C:\Windows\vtmb.ini[2009/07/24 03:19:58 | 00,097,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\infocardapi.dll[2009/07/24 03:19:57 | 00,105,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll[2009/07/24 03:19:56 | 00,622,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardagt.exe[2009/07/24 03:19:56 | 00,043,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll[2009/07/24 03:19:56 | 00,037,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\infocardcpl.cpl[2009/07/24 03:19:56 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardres.dll[2009/07/24 03:19:51 | 00,781,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationNative_v0300.dll[2009/07/24 03:19:47 | 00,326,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe[2009/07/24 03:03:50 | 00,096,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dfshim.dll[2009/07/24 03:03:44 | 00,282,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscoree.dll[2009/07/24 03:03:42 | 00,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netfxperf.dll[2009/07/24 03:03:12 | 00,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscorier.dll[2009/07/24 03:02:59 | 00,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscories.dll[2009/07/22 21:09:01 | 00,004,487 | ---- | C] () -- C:\Users\Big Si\Desktop\cobb.jpg[2009/07/16 19:23:32 | 00,294,912 | ---- | C] () -- C:\Users\Big Si\Documents\Database1.accdb[2009/07/15 00:35:50 | 00,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\t2embed.dll[2009/07/15 00:35:49 | 00,289,792 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll[2009/07/15 00:35:49 | 00,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll[2009/07/15 00:35:46 | 00,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dciman32.dll[2009/07/14 00:21:56 | 00,015,707 | ---- | C] () -- C:\Users\Big Si\Documents\I have vast experience in delivering an excellent standard of customer service.docx[2009/07/12 22:38:38 | 00,033,280 | ---- | C] () -- C:\Users\Big Si\Documents\surgery casework.doc[2009/07/12 21:39:46 | 00,469,504 | ---- | C] ( ) -- C:\Users\Big Si\Desktop\RootRepeal.exe[2009/07/08 01:43:16 | 00,010,614 | ---- | C] () -- C:\Users\Big Si\Documents\right here we go.docx[2009/07/01 04:13:55 | 00,000,858 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-505280420-2691023175-4179455115-1000Core.job[2009/06/30 22:57:40 | 00,001,475 | ---- | C] () -- C:\Users\Big Si\Desktop\Launch Cooliris.lnk[2009/06/30 22:57:37 | 00,000,000 | ---D | C] -- C:\Users\Big Si\AppData\Local\Cooliris[2009/06/28 21:29:06 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Office Outlook Connector[2009/03/08 22:03:33 | 00,748,160 | ---- | C] () -- C:\Windows\System32\Co2c40en.dll[2009/03/08 22:03:33 | 00,054,272 | ---- | C] () -- C:\Windows\System32\P2irdao.dll[2009/03/08 22:03:33 | 00,050,176 | ---- | C] () -- C:\Windows\System32\P2ctdao.dll[2009/03/08 22:03:33 | 00,018,944 | ---- | C] ( ) -- C:\Windows\System32\Implode.dll[2009/02/23 23:32:36 | 00,155,384 | ---- | C] () -- C:\Windows\System32\guard32.dll[2008/04/25 06:11:04 | 00,007,680 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll[2008/04/25 06:11:04 | 00,000,547 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest[2008/04/22 19:47:19 | 00,000,025 | ---- | C] () -- C:\Windows\cdplayer.ini[2008/02/11 19:55:18 | 00,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1437.dll[2008/01/02 17:57:36 | 00,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1409.dll[2008/01/02 17:47:22 | 01,953,696 | ---- | C] () -- C:\Windows\System32\igklg400.dll[2008/01/02 17:47:22 | 01,533,360 | ---- | C] () -- C:\Windows\System32\igklg450.dll[2007/11/24 03:57:17 | 01,238,832 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll[2007/11/24 03:57:17 | 00,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1322.dll[2007/11/24 03:57:17 | 00,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll[2007/10/18 10:12:20 | 00,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1350.dll[2007/10/04 19:33:10 | 00,000,416 | ---- | C] () -- C:\Windows\System32\dtu100.dll.manifest[2007/10/04 19:33:10 | 00,000,416 | ---- | C] () -- C:\Windows\System32\dpl100.dll.manifest[2007/09/28 18:56:22 | 03,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll[2007/09/28 18:53:06 | 00,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll[2006/11/07 20:25:58 | 00,000,000 | ---- | C] () -- C:\Windows\System32\px.ini[2006/11/02 11:25:44 | 00,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll[2006/11/02 11:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\win.ini[2006/11/02 11:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini[2006/11/02 08:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini[2006/09/17 00:36:50 | 00,520,192 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Roxio.dll[2006/09/17 00:36:50 | 00,204,800 | ---- | C] () -- C:\Windows\System32\CddbFileTaggerRoxio.dll[2005/09/23 13:52:14 | 00,207,872 | ---- | C] () -- C:\Windows\System32\OneWay.dll[2002/06/02 16:05:40 | 00,038,912 | ---- | C] () -- C:\Windows\System32\1Way.dll========== Files - Modified Within 30 Days ==========[2009/07/25 00:33:16 | 00,000,014 | ---- | M] () -- C:\Users\Big Si\Desktop\settings.dat[2009/07/25 00:30:30 | 00,469,504 | ---- | M] ( ) -- C:\Users\Big Si\Desktop\RootRepeal.exe[2009/07/25 00:07:09 | 00,000,394 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{E2CE5761-1AA0-474D-B0F4-3BA691DE2C0E}.job[2009/07/24 23:52:59 | 00,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0[2009/07/24 23:52:59 | 00,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0[2009/07/24 23:52:59 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT[2009/07/24 23:52:50 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat[2009/07/24 23:52:48 | 10,623,91808 | -HS- | M] () -- C:\hiberfil.sys[2009/07/24 23:44:29 | 00,000,858 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-505280420-2691023175-4179455115-1000.job[2009/07/24 21:46:07 | 00,001,709 | ---- | M] () -- C:\Users\Public\Desktop\Vampire - The Masquerade Bloodlines.lnk[2009/07/24 21:45:59 | 00,000,292 | ---- | M] () -- C:\Windows\vtmb.ini[2009/07/24 13:54:14 | 02,667,969 | -H-- | M] () -- C:\Users\Big Si\AppData\Local\IconCache.db[2009/07/24 07:55:21 | 00,118,712 | ---- | M] () -- C:\Users\Big Si\AppData\Local\GDIPFONTCACHEV1.DAT[2009/07/24 03:55:05 | 00,424,488 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT[2009/07/24 03:34:31 | 00,000,219 | ---- | M] () -- C:\Windows\win.ini[2009/07/23 22:23:30 | 39,197,810 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm[2009/07/23 22:23:30 | 00,040,937 | ---- | M] () -- C:\Windows\System32\drivers\Avg\microavi.avg[2009/07/23 19:28:29 | 00,001,672 | ---- | M] () -- C:\Users\Big Si\Desktop\CCleaner.lnk[2009/07/22 21:30:11 | 00,000,547 | ---- | M] () -- C:\Users\Big Si\Documents\My Sharing Folders.lnk[2009/07/22 21:09:59 | 00,004,487 | ---- | M] () -- C:\Users\Big Si\Desktop\cobb.jpg[2009/07/22 18:00:01 | 00,000,410 | ---- | M] () -- C:\Windows\tasks\Norton Security Scan for Big Si.job[2009/07/19 23:08:28 | 00,318,388 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts[2009/07/19 08:49:53 | 00,335,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys[2009/07/17 01:16:49 | 00,002,090 | ---- | M] () -- C:\Users\Big Si\Desktop\Google Chrome.lnk[2009/07/16 19:26:03 | 00,294,912 | ---- | M] () -- C:\Users\Big Si\Documents\Database1.accdb[2009/07/16 00:36:20 | 00,033,280 | ---- | M] () -- C:\Users\Big Si\Documents\surgery casework.doc[2009/07/14 00:22:53 | 00,015,707 | ---- | M] () -- C:\Users\Big Si\Documents\I have vast experience in delivering an excellent standard of customer service.docx[2009/07/13 13:36:34 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys[2009/07/13 13:36:12 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys[2009/07/08 01:43:25 | 00,010,614 | ---- | M] () -- C:\Users\Big Si\Documents\right here we go.docx[2009/07/07 16:10:56 | 24,539,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mrt.exe[2009/07/06 19:44:39 | 00,317,482 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20090719-230827.backup[2009/07/01 04:13:55 | 00,000,858 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-505280420-2691023175-4179455115-1000Core.job[2009/06/30 22:57:40 | 00,001,475 | ---- | M] () -- C:\Users\Big Si\Desktop\Launch Cooliris.lnk[2009/06/30 22:46:32 | 00,001,726 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk[2009/06/30 08:19:23 | 00,463,779 | ---- | M] () -- C:\Windows\System32\drivers\Avg\miniavi.avg========== Alternate Data Streams ==========@Alternate Data Stream - 64 bytes -> C:\Users\Big Si\Desktop\Mark Thomas - MTCP - s01e03 - Mark Stands As An MP.avi:TOC.WMV@Alternate Data Stream - 64 bytes -> C:\Users\Big Si\Desktop\ftp-bccathouse.avi:TOC.WMV@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:DFC5A2B2@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:C31F31E6@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:1CA73D29< End of report >right , i think that everything i was asked?so any issues? Link to post Share on other sites
Rorschach112 Posted July 25, 2009 Report Share Posted July 25, 2009 hiRun OTLUnder the Custom Scans/Fixes box at the bottom, paste in the following:OTLPRC - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)PRC - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)PRC - C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)O33 - MountPoints2\{2df57193-99f6-11dc-b156-806e6f6e6963}\Shell - "" = AutoRunO33 - MountPoints2\{2df57193-99f6-11dc-b156-806e6f6e6963}\Shell\AutoRun\command - "" = F:\Setup\rsrc\Autorun.exe -- [2000/01/17 17:28:36 | 00,028,672 | R--- | M] (Dipl.-Ing. Stefan Krueger <[email protected]>)O33 - MountPoints2\{2df57193-99f6-11dc-b156-806e6f6e6963}\Shell\dinstall\command - "" = F:\Directx\dxsetup.exe -- [2004/07/09 12:08:36 | 00,472,576 | R--- | M] (Microsoft Corporation):Services:Reg:Files:Commands[purity][emptytemp][Reboot]Then click the Run Fix button at the topLet the program run unhindered, reboot the PC when it is doneDownload Security Check from here or here.Save it to your Desktop.Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.A Notepad document should open automatically called checkup.txt; please post the contents of that document. Link to post Share on other sites
JoshLyman Posted July 26, 2009 Author Report Share Posted July 26, 2009 hiRun OTLUnder the Custom Scans/Fixes box at the bottom, paste in the following:OTLPRC - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)PRC - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)PRC - C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)O33 - MountPoints2\{2df57193-99f6-11dc-b156-806e6f6e6963}\Shell - "" = AutoRunO33 - MountPoints2\{2df57193-99f6-11dc-b156-806e6f6e6963}\Shell\AutoRun\command - "" = F:\Setup\rsrc\Autorun.exe -- [2000/01/17 17:28:36 | 00,028,672 | R--- | M] (Dipl.-Ing. Stefan Krueger <[email protected]>)O33 - MountPoints2\{2df57193-99f6-11dc-b156-806e6f6e6963}\Shell\dinstall\command - "" = F:\Directx\dxsetup.exe -- [2004/07/09 12:08:36 | 00,472,576 | R--- | M] (Microsoft Corporation):Services:Reg:Files:Commands[purity][emptytemp][Reboot]Then click the Run Fix button at the topLet the program run unhindered, reboot the PC when it is doneDownload Security Check from here or here.Save it to your Desktop.Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.A Notepad document should open automatically called checkup.txt; please post the contents of that document.after the fix it wont let me run security check as it is not a valid win32 programsame thing when i tried to re-install my comodo firewall Link to post Share on other sites
Rorschach112 Posted July 27, 2009 Report Share Posted July 27, 2009 I think your problem is down to too many security programs runningI would remove Comodo, Spyware Doctor, and SpybotSee how it runs after that Link to post Share on other sites
JoshLyman Posted July 27, 2009 Author Report Share Posted July 27, 2009 disabled everything, just tried to run it againstill wont work along with various install programs i downloaded like avg 8.5also avg 8 wont display its console (test centre and whatnot) Link to post Share on other sites
Rorschach112 Posted July 28, 2009 Report Share Posted July 28, 2009 did you disable or uninstall them ?your issue isn't malware related thats for sure Link to post Share on other sites
Rorschach112 Posted August 5, 2009 Report Share Posted August 5, 2009 Inactive topic...If you still need help on this problem, contact me or one of the Moderators to re-open this up.Topic closed. Link to post Share on other sites
Recommended Posts