GMER 1.0.15.15077 [59gpoe0e.exe] -
http://www.gmer.net
Rootkit scan 2009-08-27 19:10:23
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT 8A912830 ZwAlertResumeThread
SSDT 8A914830 ZwAlertThread
SSDT 8AA24E98 ZwAllocateVirtualMemory
SSDT 8A888408 ZwConnectPort
SSDT spuq.sys ZwCreateKey [0xB9EA80E0]
SSDT 8A4D7830 ZwCreateMutant
SSDT 8A8EFC70 ZwCreateThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xB5A84350]
SSDT spuq.sys ZwEnumerateKey [0xB9EC6CA2]
SSDT spuq.sys ZwEnumerateValueKey [0xB9EC7030]
SSDT 8A6A1260 ZwFreeVirtualMemory
SSDT 8A8CC830 ZwImpersonateAnonymousToken
SSDT 8A8CD830 ZwImpersonateThread
SSDT 8AA2A5B8 ZwMapViewOfSection
SSDT 8A8AD830 ZwOpenEvent
SSDT spuq.sys ZwOpenKey [0xB9EA80C0]
SSDT 8A896620 ZwOpenProcessToken
SSDT 8A9561E8 ZwOpenThreadToken
SSDT spuq.sys ZwQueryKey [0xB9EC7108]
SSDT 8A8F8270 ZwQueryValueKey
SSDT 8A906688 ZwResumeThread
SSDT 8AA78368 ZwSetContextThread
SSDT 8AA41128 ZwSetInformationProcess
SSDT 8A91C318 ZwSetInformationThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xB5A84580]
SSDT 8A99D830 ZwSuspendProcess
SSDT 8A8E5830 ZwSuspendThread
SSDT 8A86C2E0 ZwTerminateProcess
SSDT 8A8E6830 ZwTerminateThread
SSDT 8A4E5340 ZwUnmapViewOfSection
SSDT 8A666DB8 ZwWriteVirtualMemory
INT 0x63 ? 8AA0FBF8
INT 0x73 ? 8AC9BBF8
INT 0x73 ? 8AC9BBF8
INT 0x73 ? 8AA0FBF8
INT 0x73 ? 8AC9BBF8
INT 0x83 ? 8AC9BBF8
INT 0x83 ? 8AC9BBF8
INT 0x83 ? 8AA0FBF8
INT 0x83 ? 8AC9BBF8
INT 0x94 ? 8AA0FBF8
INT 0xB4 ? 8AA0FBF8
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2DC8 80504664 4 Bytes CALL 82DADBCA
? spuq.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload B95E78AC 5 Bytes JMP 8AA0F1D8
.text a4l33ywk.SYS B94E5384 1 Byte [20]
.text a4l33ywk.SYS B94E5384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...]
.text a4l33ywk.SYS B94E53AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...]
.text a4l33ywk.SYS B94E53C4 3 Bytes [00, 00, 00]
.text a4l33ywk.SYS B94E53C9 1 Byte [00]
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[700] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[700] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9521 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[700] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DCB69 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[700] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED3AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[700] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E2543F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[700] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E3C10 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[700] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E3B42 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[700] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E3BAD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[700] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E3A13 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[700] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E3A75 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[700] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E3C73 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[700] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E3AD7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[700] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2ED408 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[700] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E3E3F78 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2556] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2556] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED3AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2556] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E3C10 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2556] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E3B42 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2556] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E3BAD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2556] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E3A13 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2556] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E3A75 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2556] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E3C73 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2556] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E3AD7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B9EA9040] spuq.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B9EA913C] spuq.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B9EA90BE] spuq.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B9EA97FC] spuq.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B9EA96D2] spuq.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B9EB9048] spuq.sys
IAT \SystemRoot\System32\Drivers\a4l33ywk.SYS[HAL.dll!KfAcquireSpinLock] 00000034
IAT \SystemRoot\System32\Drivers\a4l33ywk.SYS[HAL.dll!READ_PORT_UCHAR] 0000008E
IAT \SystemRoot\System32\Drivers\a4l33ywk.SYS[HAL.dll!KeGetCurrentIrql] 00000043
IAT \SystemRoot\System32\Drivers\a4l33ywk.SYS[HAL.dll!KfRaiseIrql] 00000044
IAT \SystemRoot\System32\Drivers\a4l33ywk.SYS[HAL.dll!KfLowerIrql] 000000C4
IAT \SystemRoot\System32\Drivers\a4l33ywk.SYS[HAL.dll!HalGetInterruptVector] 000000DE
IAT \SystemRoot\System32\Drivers\a4l33ywk.SYS[HAL.dll!HalTranslateBusAddress] 000000E9
IAT \SystemRoot\System32\Drivers\a4l33ywk.SYS[HAL.dll!KeStallExecutionProcessor] 000000CB
IAT \SystemRoot\System32\Drivers\a4l33ywk.SYS[HAL.dll!KfReleaseSpinLock] 00000054
IAT \SystemRoot\System32\Drivers\a4l33ywk.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 0000007B
IAT \SystemRoot\System32\Drivers\a4l33ywk.SYS[HAL.dll!READ_PORT_USHORT] 00000094
IAT \SystemRoot\System32\Drivers\a4l33ywk.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 00000032
IAT \SystemRoot\System32\Drivers\a4l33ywk.SYS[HAL.dll!WRITE_PORT_UCHAR] 000000A6
IAT \SystemRoot\System32\Drivers\a4l33ywk.SYS[WMILIB.SYS!WmiSystemControl] 00000023
IAT \SystemRoot\System32\Drivers\a4l33ywk.SYS[WMILIB.SYS!WmiCompleteRequest] 0000003D
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Internet Explorer\iexplore.exe[700] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8AC9A1F8
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
Device \FileSystem\Fastfat \FatCdrom 8A67B500
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\usbuhci \Device\USBPDO-0 8AA701F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8AC271F8
Device \Driver\dmio \Device\DmControl\DmConfig 8AC271F8
Device \Driver\dmio \Device\DmControl\DmPnP 8AC271F8
Device \Driver\dmio \Device\DmControl\DmInfo 8AC271F8
Device \Driver\usbuhci \Device\USBPDO-1 8AA701F8
Device \Driver\usbehci \Device\USBPDO-2 8AA661F8
Device \Driver\usbuhci \Device\USBPDO-3 8AA701F8
Device \Driver\usbuhci \Device\USBPDO-4 8AA701F8
Device \Driver\sptd \Device\1164620576 spuq.sys
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\usbuhci \Device\USBPDO-5 8AA701F8
Device \Driver\usbehci \Device\USBPDO-6 8AA661F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 8AC9C1F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8AC9C1F8
Device \Driver\Cdrom \Device\CdRom0 8A9E51F8
Device \Driver\Ftdisk \Device\HarddiskVolume3 8AC9C1F8
Device \Driver\Cdrom \Device\CdRom1 8A9E51F8
Device \Driver\atapi \Device\Ide\IdePort0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort2 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-24 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort3 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-e sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-6 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-19 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\Cdrom \Device\CdRom2 8A9E51F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8A901410
Device \Driver\NetBT \Device\NetbiosSmb 8A901410
Device \Driver\usbstor \Device\00000085 8A4DA500
Device \Driver\usbstor \Device\00000085 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\NetBT \Device\NetBT_Tcpip_{11A9B682-FC84-479C-B083-7A3093F803E1} 8A901410
Device \Driver\usbstor \Device\00000086 8A4DA500
Device \Driver\usbstor \Device\00000086 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\PCI_PNP6826 \Device\0000004f spuq.sys
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\usbuhci \Device\USBFDO-0 8AA701F8
Device \Driver\usbuhci \Device\USBFDO-1 8AA701F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A8C9500
Device \Driver\usbehci \Device\USBFDO-2 8AA661F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A8C9500
Device \Driver\usbuhci \Device\USBFDO-3 8AA701F8
Device \Driver\usbuhci \Device\USBFDO-4 8AA701F8
Device \Driver\Ftdisk \Device\FtControl 8AC9C1F8
Device \Driver\usbuhci \Device\USBFDO-5 8AA701F8
Device \Driver\usbehci \Device\USBFDO-6 8AA661F8
Device \Driver\a4l33ywk \Device\Scsi\a4l33ywk1 8A98B1F8
Device \Driver\a4l33ywk \Device\Scsi\a4l33ywk1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\a4l33ywk \Device\Scsi\a4l33ywk1Port4Path0Target0Lun0 8A98B1F8
Device \Driver\a4l33ywk \Device\Scsi\a4l33ywk1Port4Path0Target0Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\a4l33ywk \Device\Scsi\a4l33ywk1Port4Path0Target1Lun0 8A98B1F8
Device \Driver\a4l33ywk \Device\Scsi\a4l33ywk1Port4Path0Target1Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \FileSystem\Fastfat \Fat 8A67B500
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs 8A8D4500
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04@ujdew 0x6E 0xED 0x1E 0x5E ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04\00000001@ujdew 0x4B 0x01 0xED 0x32 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04\00000001\jdgg40@ujdew 0xD3 0x1B 0x51 0x2B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04\00000001\jdgg41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04\00000001\jdgg41@ujdew 0x47 0xF3 0xF4 0xC8 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x29 0xBF 0xC3 0xD0 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x78 0x73 0x3F 0x1E ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7B 0x64 0xC6 0xCF ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x99 0x0E 0xFD 0x1D ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04@ujdew 0x6E 0xED 0x1E 0x5E ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04\00000001@ujdew 0x4B 0x01 0xED 0x32 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04\00000001\jdgg40@ujdew 0xD3 0x1B 0x51 0x2B ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04\00000001\jdgg41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0d79c293c1ed61418462e24595c90d04\00000001\jdgg41@ujdew 0x47 0xF3 0xF4 0xC8 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x29 0xBF 0xC3 0xD0 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x78 0x73 0x3F 0x1E ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7B 0x64 0xC6 0xCF ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x99 0x0E 0xFD 0x1D ...
---- EOF - GMER 1.0.15 ----
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-07-30.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 01/01/2009 4:20:07 AM
System Uptime: 27/08/2009 3:01:56 AM (13 hours ago)
Motherboard: ASUSTeK Computer INC. | | P5B
Processor: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz | Socket 775 | 2401/266mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 112 GiB total, 89.749 GiB free.
D: is FIXED (NTFS) - 298 GiB total, 183.644 GiB free.
E: is FIXED (NTFS) - 466 GiB total, 57.55 GiB free.
F: is Removable
H: is CDROM (CDFS)
I: is CDROM ()
J: is CDROM ()
==== Disabled Device Manager Items =============
Class GUID: {4D36E97B-E325-11CE-BFC1-08002BE10318}
Description: IDE Controller
Device ID: PCI\VEN_197B&DEV_2363&SUBSYS_81E41043&REV_02\4&18CD42CE&0&00E4
Manufacturer:
Name: IDE Controller
PNP Device ID: PCI\VEN_197B&DEV_2363&SUBSYS_81E41043&REV_02\4&18CD42CE&0&00E4
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description:
Device ID: ACPI\ATK0110\1010110
Manufacturer:
Name:
PNP Device ID: ACPI\ATK0110\1010110
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: SM Bus Controller
Device ID: PCI\VEN_8086&DEV_283E&SUBSYS_81EC1043&REV_02\3&11583659&0&FB
Manufacturer:
Name: SM Bus Controller
PNP Device ID: PCI\VEN_8086&DEV_283E&SUBSYS_81EC1043&REV_02\3&11583659&0&FB
Service:
==== System Restore Points ===================
RP137: 16/08/2009 5:08:19 AM - System Checkpoint
RP138: 17/08/2009 5:08:35 AM - System Checkpoint
RP139: 18/08/2009 6:05:51 AM - System Checkpoint
RP140: 19/08/2009 6:22:34 AM - System Checkpoint
RP141: 20/08/2009 7:22:33 AM - System Checkpoint
RP142: 20/08/2009 8:05:01 PM - Unsigned driver install
RP143: 21/08/2009 8:56:17 PM - System Checkpoint
RP144: 22/08/2009 3:00:19 AM - Software Distribution Service 3.0
RP145: 22/08/2009 10:32:59 AM - Printer Driver Microsoft XPS Document Writer Installed
RP146: 23/08/2009 1:48:12 AM - Unsigned driver install
RP147: 23/08/2009 7:16:09 PM - Removed Age of Empires III - The WarChiefs
RP148: 23/08/2009 7:19:25 PM - Removed Age of Empires III
RP149: 23/08/2009 7:26:14 PM - Removed Age of Empires III - The Asian Dynasties
RP150: 23/08/2009 7:34:14 PM - Removed Star Wars(R) Knights of the Old Republic(R) II: The Sith
RP151: 23/08/2009 7:43:47 PM - Removed Microsoft Games for Windows - LIVE
RP152: 23/08/2009 7:44:04 PM - Removed Microsoft Games for Windows - LIVE Redistributable
RP153: 23/08/2009 7:46:13 PM - Removed Marvel(TM) - Ultimate Alliance
RP154: 24/08/2009 7:51:06 PM - Restore Operation
RP155: 25/08/2009 6:17:12 PM - Installed Java(TM) 6 Update 15
RP156: 25/08/2009 6:43:09 PM - Installed QuickTime
RP157: 25/08/2009 6:48:33 PM - Installed iTunes
RP158: 25/08/2009 7:05:24 PM - Software Distribution Service 3.0
RP159: 25/08/2009 7:24:42 PM - Installed Windows XP WgaNotify.
RP160: 25/08/2009 7:27:56 PM - Software Distribution Service 3.0
RP161: 26/08/2009 8:15:45 PM - System Checkpoint
==== Installed Programs ======================
"Nero SoundTrax Help
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.1
Advertising Center
Aion
AirPort
ANNO 1404
Anno 1404 Bonus
Apple Mobile Device Support
Apple Software Update
Bejeweled 2 Deluxe
Blitzkrieg 2
Bonjour
Choice Guard
COWON Media Center - jetAudio Basic
CPUID CPU-Z 1.52.1
Diablo II
DolbyFiles
Europa Universalis III - Complete
Fallout 3
Hearts of Iron III
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
ImagXpress
iTunes
Java(TM) 6 Update 15
LiveUpdate 3.2 (Symantec Corporation)
Locomotion
Malwarebytes' Anti-Malware
Menu Templates - Starter Kit
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft WSE 3.0 Runtime
Miracle C
Movie Templates - Starter Kit
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 6.0 Parser (KB925673)
NCsoft Launcher
Nero 9
Nero Burning ROM Help
Nero BurnRights
Nero ControlCenter
Nero CoverDesigner
Nero CoverDesigner Help
Nero Disc Copy Gadget
Nero Disc Copy Gadget Help
Nero DiscSpeed
Nero DriveSpeed
Nero Express Help
Nero InfoTool
Nero Installer
Nero PhotoSnap
Nero PhotoSnap Help
Nero Recode
Nero Recode Help
Nero Rescue Agent
Nero RescueAgent Help
Nero ShowTime
Nero StartSmart
Nero StartSmart Help
Nero Vision
Nero WaveEditor
Nero WaveEditor Help
NeroBurningROM
NeroExpress
neroxml
NVIDIA Drivers
PlayGATE Setup
QuickTime
RCT3 Soaked
RealPlayer
REALTEK GbE & FE Ethernet PCI-E NIC Driver
RollerCoaster Tycoon® 3
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Segoe UI
SoundMAX
SoundTrax
Spybot - Search & Destroy
SpywareBlaster 4.2
SSH Secure Shell
Steam
Symantec AntiVirus
TeamSpeak 2 RC2
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB973874)
Update for Windows XP (KB943729)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973815)
Ventrilo Client
Warcraft III: All Products
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Media Format 11 runtime
Windows Media Player 11
Windows PowerShell(TM) 1.0
Windows Presentation Foundation
Windows XP Service Pack 3
WinRAR archiver
World of Warcraft
XML Paper Specification Shared Components Pack 1.0
==== Event Viewer Messages From Past Week ========
27/08/2009 12:41:29 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
26/08/2009 2:43:26 AM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
26/08/2009 2:43:14 AM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
26/08/2009 2:42:58 AM, error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
25/08/2009 6:46:41 PM, error: Service Control Manager [7034] - The getPlus(R) Helper service terminated unexpectedly. It has done this 1 time(s).
25/08/2009 5:41:36 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
23/08/2009 8:31:53 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
22/08/2009 3:12:06 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 3.5 Service Pack 1 and .NET Framework 3.5 Family Update for .NET versions 2.0 through 3.5 (KB951847) x86.
22/08/2009 3:11:45 AM, error: Service Control Manager [7034] - The Windows Installer service terminated unexpectedly. It has done this 1 time(s).
22/08/2009 3:07:29 AM, error: atapi [9] - The device, \Device\Ide\IdePort3, did not respond within the timeout period.
22/08/2009 3:07:17 AM, error: atapi [11] - The driver detected a controller error on \Device\Ide\IdePort3.
==== End Of File ===========================
DDS (Ver_09-07-30.01) - NTFSx86
Run by Stefan at 16:19:39.64 on 27/08/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3007.2192 [GMT -4:00]
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\AirPort\APAgent.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Stefan\Desktop\dds.scr
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [AirPort Base Station Agent] "c:\program files\airport\APAgent.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSCONFIG.EXE /auto
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1230803270651
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2007-5-29 192104]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2007-5-29 169576]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\common files\nero\nero backitup 4\NBService.exe [2008-11-25 935208]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2007-10-7 1822648]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-8-21 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090825.004\naveng.sys [2009-8-25 84912]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090825.004\navex15.sys [2009-8-25 1323568]
S0 ati8tlxx;ati8tlxx;c:\windows\system32\drivers\ati8tlxx.sys --> c:\windows\system32\drivers\ati8tlxx.sys [?]
S3 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [2009-8-24 12672]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 RkPavproc1;RkPavproc1;c:\windows\system32\drivers\RkPavproc1.sys [2009-6-22 16952]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2007-10-7 116664]
=============== Created Last 30 ================
2009-08-27 02:38 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Blizzard Entertainment
2009-08-25 19:23 <DIR> --dsh--- c:\documents and settings\stefan\PrivacIE
2009-08-25 19:20 <DIR> --dsh--- c:\documents and settings\stefan\IETldCache
2009-08-25 19:17 100,352 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-08-25 19:17 <DIR> --d----- c:\windows\ie8updates
2009-08-25 19:16 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll
2009-08-25 19:16 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll
2009-08-25 19:14 <DIR> -cd-h--- c:\windows\ie8
2009-08-25 19:10 215,465 a------- c:\windows\system32\nvapps.nvb
2009-08-25 19:09 <DIR> --d----- c:\docume~1\stefan\applic~1\Windows Search
2009-08-25 19:08 <DIR> --d----- c:\windows\system32\GroupPolicy
2009-08-25 19:08 <DIR> --d----- c:\program files\Windows Desktop Search
2009-08-25 19:07 192,000 -c------ c:\windows\system32\dllcache\offfilt.dll
2009-08-25 19:07 98,304 -c------ c:\windows\system32\dllcache\nlhtml.dll
2009-08-25 19:07 29,696 -c------ c:\windows\system32\dllcache\mimefilt.dll
2009-08-25 19:07 <DIR> --d----- c:\program files\Windows Media Connect 2
2009-08-25 19:05 <DIR> --d----- c:\windows\system32\LogFiles
2009-08-25 18:49 <DIR> --d----- c:\program files\iPod
2009-08-25 18:49 <DIR> --d----- c:\program files\iTunes
2009-08-25 18:49 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-25 18:46 2,060,288 a------- c:\windows\system32\usbaaplrc.dll
2009-08-25 17:59 <DIR> --d----- c:\windows\pss
2009-08-24 19:49 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-08-24 01:30 12,672 a------- c:\windows\system32\drivers\cpuz132_x32.sys
2009-08-24 01:30 <DIR> --d----- c:\program files\CPUID
2009-08-23 20:26 229,376 a------- c:\windows\PEV.exe
2009-08-23 20:26 161,792 a------- c:\windows\SWREG.exe
2009-08-23 20:26 98,816 a------- c:\windows\sed.exe
2009-08-22 10:35 1,089,593 -c------ c:\windows\system32\dllcache\ntprint.cat
2009-08-13 02:27 128,512 -c------ c:\windows\system32\dllcache\dhtmled.ocx
2009-08-13 02:27 1,315,328 -c------ c:\windows\system32\dllcache\msoe.dll
2009-08-11 01:27 <DIR> --d----- c:\program files\Paradox Interactive
2009-08-10 16:48 <DIR> --d----- c:\program files\Atari
2009-08-03 23:24 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Age of Empires 3
2009-07-28 22:28 21,840 a------- c:\windows\system32\SIntfNT.dll
2009-07-28 22:28 17,212 a------- c:\windows\system32\SIntf32.dll
2009-07-28 22:28 12,067 a------- c:\windows\system32\SIntf16.dll
2009-07-28 22:14 35,213 a------- c:\windows\DIIUnin.dat
2009-07-28 22:14 94,208 a------- c:\windows\DIIUnin.exe
2009-07-28 22:14 2,829 a------- c:\windows\DIIUnin.pif
==================== Find3M ====================
2009-08-05 05:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-03 13:36 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 13:36 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-07-28 08:55 143,360 a------- c:\windows\system32\drivers\Rtenicxp.sys
2009-07-25 05:23 411,368 a------- c:\windows\system32\deploytk.dll
2009-07-24 16:00 281,760 a------- c:\windows\system32\drivers\atksgt.sys
2009-07-24 16:00 25,888 a------- c:\windows\system32\drivers\lirsgt.sys
2009-07-17 15:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 23:43 286,208 a------- c:\windows\system32\wmpdxm.dll
2009-07-08 04:05 73,728 a------- c:\windows\system32\RtNicProp32.dll
2009-07-03 13:09 915,456 -------- c:\windows\system32\wininet.dll
2009-07-01 00:48 76,869 a------- c:\windows\War3Unin.dat
2009-07-01 00:45 139,264 a------- c:\windows\War3Unin.exe
2009-07-01 00:45 2,829 a------- c:\windows\War3Unin.pif
2009-06-25 04:25 730,112 a------- c:\windows\system32\lsasrv.dll
2009-06-25 04:25 301,568 a------- c:\windows\system32\kerberos.dll
2009-06-25 04:25 147,456 a------- c:\windows\system32\schannel.dll
2009-06-25 04:25 136,192 a------- c:\windows\system32\msv1_0.dll
2009-06-25 04:25 56,832 a------- c:\windows\system32\secur32.dll
2009-06-25 04:25 54,272 a------- c:\windows\system32\wdigest.dll
2009-06-16 10:36 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 10:36 81,920 a------- c:\windows\system32\fontsub.dll
2009-06-12 08:31 80,896 a------- c:\windows\system32\tlntsess.exe
2009-06-12 08:31 76,288 a------- c:\windows\system32\telnet.exe
2009-06-10 10:13 84,992 a------- c:\windows\system32\avifil32.dll
2009-06-10 09:19 2,066,432 a------- c:\windows\system32\mstscax.dll
2009-06-10 02:14 132,096 a------- c:\windows\system32\wkssvc.dll
2009-06-03 15:09 1,291,264 a------- c:\windows\system32\quartz.dll
2006-06-23 02:48 32,768 a----r-- c:\windows\inf\UpdateUSB.exe
============= FINISH: 16:20:11.82 ===============