Hello Kahdah,
thank you for your helping me.
Here it is:
DDS (Ver_09-02-01.01) - NTFSx86
Run by Administrator at 15:33:00.04 on 03/02/2009
Internet Explorer: 6.0.2900.3311 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.3582.2990 [GMT 0:00]
AV: avast! antivirus 4.8.1296 [VPS 090202-1] *On-access scanning disabled* (Updated)
FW: ActiveArmor Firewall *disabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\WINDOWS\system32\nvsvc32.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Administrator\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
uRun: [Aim6]
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SkyTel] SkyTel.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [basicsmssmenu] "c:\program files\seagate\basics\basics status\MaxMenuMgrBasics.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [WinVNC] "c:\program files\ultravnc\WinVNC.exe" -servicehelper
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SSC Service Utility] c:\program files\ssc service utility\ssc_serv.exe /s
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
dRun: [ctfmon.exe] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\active~1.lnk - c:\program files\active shutdown\asd.exe
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\anapod~1.lnk - c:\program files\red chair software\anapod explorer\anamgr.exe
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\mirand~1.lnk - c:\program files\miranda im\miranda32.exe
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 2.2\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\epsons~1.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
TCP: {AC1F5BCF-9CD1-4470-B59A-466D6B613125} = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: textwareilluminatorbase - {CE5CD329-1650-414A-8DB0-4CBF72FAED87} - c:\windows\system32\textwareilluminatorbaseProtocol.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
AppInit_DLLs: mss.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\qrbjunla.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - component: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\qrbjunla.default\extensions\
[email protected]\components\coolirisstub.dll
FF - plugin: c:\program files\google\google updater\2.4.1441.4352\npCIDetect13.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPLV80Win32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPLV82Win32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmks.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-5-9 111184]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2008-12-4 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-12-4 55024]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-5-9 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-2-26 155160]
R2 MLPTDR_N;MLPTDR_N;c:\windows\system32\MLPTDR_N.SYS [2008-2-10 18848]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-5-17 24652]
R2 vnccom;vnccom;c:\windows\system32\drivers\vnccom.SYS [2008-12-20 6016]
R3 Mach3;Mach3 Pulseing Service;c:\windows\system32\drivers\Mach3.sys [2008-9-8 103040]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-12-4 7408]
S0 ati8bhxx;ati8bhxx;c:\windows\system32\drivers\ati8bhxx.sys --> c:\windows\system32\drivers\ati8bhxx.sys [?]
S1 24e4571f;24e4571f;c:\windows\system32\drivers\24e4571f.sys --> c:\windows\system32\drivers\24e4571f.sys [?]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2008-2-26 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2008-2-26 352920]
S3 HauppaugeTVServer;HauppaugeTVServer;c:\progra~1\wintv\HCWTVS~1.EXE [2008-2-27 815104]
=============== Created Last 30 ================
2009-01-31 09:26 <DIR> --d----- c:\program files\CCleaner
2009-01-30 23:37 <DIR> --d----- c:\documents and settings\administrator\DoctorWeb
2009-01-30 22:13 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-01-30 22:13 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-01-30 22:13 <DIR> --d----- c:\docume~1\admini~1\applic~1\SUPERAntiSpyware.com
2009-01-30 20:28 <DIR> --d----- c:\program files\Trend Micro
2009-01-29 13:39 135,168 a------- c:\windows\system32\EEBAPI.dll
2009-01-29 13:39 110,592 a------- c:\windows\system32\EEBDSCVR.dll
2009-01-29 13:39 69,632 a------- c:\windows\system32\EBAPI.dll
2009-01-29 13:39 65,536 a------- c:\windows\system32\EEBUtil.dll
2009-01-29 13:39 55,808 a------- c:\windows\system32\EEBSDKIF.dll
2009-01-29 13:36 155,648 a------- c:\windows\system32\EBAPI2.dll
2009-01-29 13:36 <DIR> --d----- c:\program files\common files\EPSON
2009-01-29 12:34 <DIR> --d----- c:\docume~1\admini~1\applic~1\Malwarebytes
2009-01-29 12:34 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-01-29 12:34 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-29 12:34 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-01-29 12:34 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-01-29 11:06 59 a------- c:\windows\system32\senekajbwnfghd.dat
2009-01-29 11:02 2 a------- C:\540284606
2009-01-29 11:01 447 a------- c:\windows\xccwinsys.ini
2009-01-29 11:01 <DIR> --d----- c:\windows\system32\inf
2009-01-29 11:01 6,454 a------- c:\windows\system32\senekajbgixjov.dat
2009-01-29 11:01 108,336 a------- c:\windows\system32\mswinsck.ocx
2009-01-28 20:05 73,728 a------- c:\windows\system32\EPRIPMNT.DLL
2009-01-28 20:05 61,440 a------- c:\windows\system32\MONINST.EXE
2009-01-28 20:05 19,744 a------- c:\windows\system32\drivers\EPSTNT01.SYS
2009-01-28 19:16 5,248 a------- c:\windows\system32\giveio.sys
2009-01-28 19:13 <DIR> --d----- c:\program files\SSC Service Utility
2009-01-26 23:09 <DIR> --d----- C:\EPSON
2009-01-26 23:01 80,166 a------- c:\windows\system32\EBPMON2.DLL
2009-01-26 23:01 64,000 a------- c:\windows\system32\ECBTEG.DLL
2009-01-26 23:01 34,304 a------- c:\windows\system32\EBPCHP.DLL
2009-01-26 22:53 <DIR> --d----- c:\windows\EPSON PhotoStarter Essential
2009-01-26 22:52 131,072 a----r-- c:\windows\system32\Epcmlib.dll
2009-01-26 22:52 <DIR> --d----- c:\program files\EPSON
2009-01-26 22:50 <DIR> --d----- c:\program files\EPSON Print CD
2009-01-26 22:50 <DIR> --d----- c:\program files\EPSON GrayBalancer
2009-01-18 11:15 <DIR> --d----- C:\HEX BLINK
2009-01-17 11:58 <DIR> --d----- c:\windows\system32\AGEIA
2009-01-17 11:58 206,755 a------- c:\windows\system32\nvapps.nvb
2009-01-17 11:58 <DIR> --d----- c:\windows\NV2003712.TMP
2009-01-17 11:57 <DIR> --d----- C:\NVIDIA
2009-01-17 11:46 <DIR> --d----- c:\program files\SystemRequirementsLab
2009-01-16 09:20 1,491,992 a------- c:\windows\system32\D3DCompiler_38.dll
2009-01-16 09:20 507,400 a------- c:\windows\system32\XAudio2_1.dll
2009-01-16 09:20 467,984 a------- c:\windows\system32\d3dx10_38.dll
2009-01-16 09:20 238,088 a------- c:\windows\system32\xactengine3_1.dll
2009-01-16 09:20 65,032 a------- c:\windows\system32\XAPOFX1_0.dll
2009-01-16 09:20 25,608 a------- c:\windows\system32\X3DAudio1_4.dll
2009-01-16 09:20 3,850,760 a------- c:\windows\system32\D3DX9_38.dll
2009-01-16 09:20 479,752 a------- c:\windows\system32\XAudio2_0.dll
2009-01-16 09:20 238,088 a------- c:\windows\system32\xactengine3_0.dll
2009-01-16 09:20 25,608 a------- c:\windows\system32\X3DAudio1_3.dll
2009-01-16 09:19 <DIR> --d----- c:\windows\Logs
2009-01-16 09:18 3,786,760 a------- c:\windows\system32\D3DX9_37.dll
2009-01-16 09:18 1,420,824 a------- c:\windows\system32\D3DCompiler_37.dll
2009-01-16 09:18 462,864 a------- c:\windows\system32\d3dx10_37.dll
2009-01-16 09:18 <DIR> --d----- c:\windows\system32\xlive
2009-01-16 09:18 <DIR> --d----- c:\program files\Microsoft Games for Windows - LIVE
2009-01-16 00:56 <DIR> --d----- c:\windows\system32\XPSViewer
2009-01-16 00:55 14,048 -------- c:\windows\system32\spmsg2.dll
2009-01-16 00:54 <DIR> --d----- c:\docume~1\admini~1\applic~1\DAEMON Tools Pro
2009-01-16 00:53 <DIR> --d----- c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite
2009-01-16 00:53 <DIR> --d----- c:\program files\DAEMON Tools Lite
2009-01-16 00:52 <DIR> --d----- c:\docume~1\admini~1\applic~1\DAEMON Tools Lite
2009-01-14 14:53 <DIR> --d-hr-- c:\docume~1\admini~1\applic~1\Microchip
2009-01-14 14:24 <DIR> --d----- c:\program files\Microchip
2009-01-14 14:15 <DIR> --d----- c:\program files\Mikroelektronika
2009-01-10 22:25 <DIR> --d----- c:\docume~1\admini~1\applic~1\Foxit
2009-01-10 17:52 <DIR> --d----- C:\PBP
2009-01-10 17:50 <DIR> --d----- c:\program files\PIC18 Simulator IDE
2009-01-10 17:48 <DIR> --d----- c:\program files\PIC Simulator IDE
2009-01-08 23:12 <DIR> --d----- C:\Pk2 Lessons
2009-01-08 18:51 21 a------- c:\windows\Picasa.ini
2009-01-08 15:24 49,664 a------- c:\windows\unvise32.exe
2009-01-08 15:24 <DIR> --d----- c:\program files\Active ShutDown
2009-01-05 22:33 3,751,995 a------- c:\windows\system32\GPhotos.scr
2009-01-05 16:14 <DIR> --d----- c:\program files\Foxit Software
==================== Find3M ====================
2009-02-02 22:50 2,516 a--sh--- c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys
2009-01-16 09:20 107,888 a------- c:\windows\system32\CmdLineExt.dll
2009-01-14 14:12 3,350 a--sh--- c:\windows\system32\KGyGaAvL.sys
2008-12-23 21:58 453,152 a------- c:\windows\system32\NVUNINST.EXE
2008-12-08 09:08 410,984 a------- c:\windows\system32\deploytk.dll
2008-09-20 16:29 8 ---shr-- c:\docume~1\alluse~1\applic~1\F5B9E44F42.sys
2008-03-06 21:15 32 a------- c:\docume~1\alluse~1\applic~1\ezsid.dat
2008-03-05 11:28 22,328 a------- c:\docume~1\admini~1\applic~1\PnkBstrK.sys
2008-03-05 11:21 103,736 a------- c:\docume~1\admini~1\applic~1\PnkBstrB.exe
2002-04-16 10:27 5 a--sh--- c:\windows\system32\CdI5T.drv
2008-09-17 22:10 88 ---shr-- c:\windows\system32\F5B9E44F42.sys
2008-02-12 09:29 54,898 ---shr-- c:\windows\system32\javaupd.exe
============= FINISH: 15:33:14.75 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-02-01.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 2/26/2008 11:58:12 AM
System Uptime: 2/3/2009 8:52:39 AM (7 hours ago)
Motherboard: ASUSTeK Computer INC. | | P5N-E SLI
Processor: Intel® Core2 Quad CPU Q6600 @ 2.40GHz | Socket 775 | 2399/266mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 98 GiB total, 68.79 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is FIXED (NTFS) - 368 GiB total, 285.274 GiB free.
G: is FIXED (NTFS) - 466 GiB total, 39.974 GiB free.
H: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
AC3Filter (remove only)
Active ShutDown
Ad-Aware
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color EU Recommended Settings
Adobe Color JA Extra Settings
Adobe Color NA Extra Settings
Adobe Color NA Recommended Settings
Adobe Default Language CS3
Adobe Device Central CS3
Adobe ExtendScript Toolkit 2
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Illustrator CS3
Adobe Linguistics CS3
Adobe PDF Library Files
Adobe Photoshop CS3
Adobe Reader 8.1.3
Adobe Setup
Adobe Shockwave Player 11
Adobe Stock Photos CS3
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
AeroFly Professional Deluxe
AIM 6
Alive YouTube Video Converter (version 1.2.3.9)
All Media Fixer 9.08
Anapod Explorer (remove only)
Aspell Czech Dictionary-0.50-2
Aspell English Dictionary-0.50-2
ASUSUpdate
µTorrent
Autopano Pro
AutoUpdate
avast! Antivirus
Cambridge Advanced Learner's Dictionary
CCleaner (remove only)
Chief Architect 9.5 Full Version
Corel Paint Shop Pro Photo XI
CorelDRAW Graphics Suite X4
CorelDRAW Graphics Suite X4 - Capture
CorelDRAW Graphics Suite X4 - Content
CorelDRAW Graphics Suite X4 - Draw
CorelDRAW Graphics Suite X4 - Filters
CorelDRAW Graphics Suite X4 - FontNav
CorelDRAW Graphics SUite X4 - ICA
CorelDRAW Graphics Suite X4 - IPM
CorelDRAW Graphics Suite X4 - Lang EN
CorelDRAW Graphics Suite X4 - PP
CorelDRAW Graphics Suite X4 - VBA
CorelDRAW® Graphics Suite X4
CorelDRAW® Graphics Suite X4 - Windows Shell Extension
DFX 8 for Windows Media Player
Direct Show Ogg Vorbis Filter (remove only)
DivX Codec
DivX Converter
DivX Player
DivX Web Player
Dr. DivX 2.0 OSS
Drive Manager
DVD X Player 4.0 Professional
Easy Duplicate Finder v. 1.5.1
EPSON GrayBalancer
EPSON PhotoQuicker3.4
EPSON PhotoStarter3.0
EPSON Print CD
EPSON Printer Software
EPSON PS Port Monitor
EPSON PS_Server
ERUNT 1.1j
Flash Saving Plugin
FLV Player 2.0, build 24
Foxit PDF Editor
Foxit Reader
GNU Aspell 0.50-3
Google Earth
Google Updater
GPL MPEG-1/2 DirectShow Decoder Filter
Grand Theft Auto IV
GTK+ Runtime 2.6.9 rev a (remove only)
Hauppauge WinTV
Hauppauge WinTV Scheduler
Hauppauge WinTV TV Services
Hauppauge WinTV2000
HD Tach version 3
HI-TECH C51-lite V9.60PL0
HI-TECH PICC lite V9.60PL0
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
InterVideo FilterSDK for Hauppauge
Java 6 Update 11
Java 6 Update 5
Java 6 Update 7
JMB36X Raid Configurer
K-Lite Codec Pack 3.5.0 Basic
KeeBook Creator 2.7.6.8
KONICA MINOLTA PagePro 1300W
LightScribe 1.8.15.1
Logitech SetPoint
Machinist ToolBox™ v9.x
Magic ISO Maker v5.4 (build 0255)
Magic ISO Maker v5.5 (build 0273)
Malwarebytes' Anti-Malware
Mayan Maze
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Visio Professional 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Web Publishing Wizard 1.52
mikroBasic (remove only)
Miranda IM 0.7.7
Mozilla Firefox (3.0.5)
Mozilla Thunderbird (2.0.0.19)
Mpeg Layer3 Codec FHG-Radium v1.263
MPLAB Tools v8.10
MSXML 4.0 SP2 (KB936181)
MSXML 6.0 Parser (KB933579)
nanoPEG-Editor 2.6.0 for WinTV
National Instruments Software
neroxml
NI Circuit Design Suite 10 Core
NI Circuit Design Suite 10 Pro
NI EULA Depot
NI LabVIEW Run-Time Engine 8.0.1
NI LabVIEW Run-Time Engine 8.2
NI LabWindows/CVI 8.0.1 Run-Time Engine
NI License Manager
NI Logos 4.7
NI Math Kernel Libraries
NI MDF Support
NI Service Locator
NI TDMS
NI Uninstaller
NI USI 1.3.0
NVIDIA Drivers
NVIDIA PhysX v8.10.13
oggcodecs 0.71.0946
OpenAL
OpenOffice.org 2.2
PC Probe II
PDF Settings
PIC Simulator IDE
PIC16F690 Lessons
PIC16F887 Lessons
PIC18 Simulator IDE
Picasa 3
PICBASIC PRO 2.50
PICkit 2 v2.50.02
PowerISO
Puzzle Quest
QuickTime Alternative 1.78
Realtek High Definition Audio Driver
Riva FLV Player
Rockstar Games Social Club
Sage Instant Accounts
Sage Instant Accounts V12.00
ScanToWeb
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
SJphone 1.65
Skype™ 3.8
Spybot - Search & Destroy
SSC Service Utility v4.30
SUPERAntiSpyware Professional
Survey
System Requirements Lab
TARGET 3001! V13 discover
Tomb Raider: Anniversary 1.0
Total Commander (Remove or Repair)
Ultimate Sudoku
UltraVNC v1.0.2
Update for Windows Media Player 10 (KB926251)
VideoLAN VLC media player 0.8.6h
Viewpoint Media Player
Visual Basic for Applications ® Core
Visual Basic for Applications ® Core - English
VoipDiscount
WebFldrs XP
Windows Communication Foundation
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Service Pack 3
WinRAR archiver
X-Lite 3.0
XML Paper Specification Shared Components Pack 1.0
XpertVision 5.9
Xvid 1.1.2 final uninstall
YPOPs! 0.9.6
==== Event Viewer Messages From Past Week ========
1/29/2009 12:07:21 PM, error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
1/29/2009 11:01:49 AM, error: Service Control Manager [7034] - The Windows Installer service terminated unexpectedly. It has done this 1 time(s).
1/29/2009 12:07:21 PM, error: Service Control Manager [7034] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s).
1/29/2009 12:12:09 PM, error: System Error [1003] - Error code 1000000a, parameter1 00000018, parameter2 00000002, parameter3 00000000, parameter4 804f459a.
==== End Of File ===========================
GMER 1.0.14.14536 -
http://www.gmer.netRootkit scan 2009-02-03 15:58:58
Windows 5.1.2600 Service Pack 3, v.3311
---- System - GMER 1.0.14 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xA5859576]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xA5859432]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xA5859910]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xA585900A]
SSDT spsq.sys ZwEnumerateKey [0xB9EC6CA2]
SSDT spsq.sys ZwEnumerateValueKey [0xB9EC7030]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xA585950C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xA5858F4A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xA5858FAE]
SSDT spsq.sys ZwQueryKey [0xB9EC7108]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xA585962C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xA58595EC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xA585976C]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xA6E07F20]
INT 0x62 ? 8B250BF8
INT 0x63 ? 8B2C6BF8
INT 0x73 ? 8B2C6BF8
INT 0x94 ? 8B022BF8
INT 0xB4 ? 8B253BF8
INT 0xB4 ? 8B253BF8
---- Kernel code sections - GMER 1.0.14 ----
? spsq.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload B7DE38AC 5 Bytes JMP 8B0221D8
.text aa5f53h4.SYS B7C9F386 35 Bytes [ 00, 00, 00, 00, 00, 00, 20, ... ]
.text aa5f53h4.SYS B7C9F3AA 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text aa5f53h4.SYS B7C9F3C4 3 Bytes [ 00, 70, 02 ]
.text aa5f53h4.SYS B7C9F3C9 1 Byte [ 2E ]
.text aa5f53h4.SYS B7C9F3CB 9 Bytes [ 00, 00, 5C, 02, 00, 00, 00, ... ]
.text ...
---- Kernel IAT/EAT - GMER 1.0.14 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B9EA9040] spsq.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B9EA913C] spsq.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B9EA90BE] spsq.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B9EA97FC] spsq.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B9EA96D2] spsq.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B9EB9048] spsq.sys
IAT \SystemRoot\System32\Drivers\aa5f53h4.SYS[HAL.dll!KfAcquireSpinLock] 4B8BDF8B
IAT \SystemRoot\System32\Drivers\aa5f53h4.SYS[HAL.dll!READ_PORT_UCHAR] 8D3F0304
IAT \SystemRoot\System32\Drivers\aa5f53h4.SYS[HAL.dll!KeGetCurrentIrql] CB033043
IAT \SystemRoot\System32\Drivers\aa5f53h4.SYS[HAL.dll!KfRaiseIrql] 0673C13B
IAT \SystemRoot\System32\Drivers\aa5f53h4.SYS[HAL.dll!KfLowerIrql] C13B0003
IAT \SystemRoot\System32\Drivers\aa5f53h4.SYS[HAL.dll!HalGetInterruptVector] 8366FA72
IAT \SystemRoot\System32\Drivers\aa5f53h4.SYS[HAL.dll!HalTranslateBusAddress] 75000E7B
IAT \SystemRoot\System32\Drivers\aa5f53h4.SYS[HAL.dll!KeStallExecutionProcessor] 0B7D80E3
IAT \SystemRoot\System32\Drivers\aa5f53h4.SYS[HAL.dll!KfReleaseSpinLock] 307B8D00
IAT \SystemRoot\System32\Drivers\aa5f53h4.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 00AA840F
IAT \SystemRoot\System32\Drivers\aa5f53h4.SYS[HAL.dll!READ_PORT_USHORT] 83660000
IAT \SystemRoot\System32\Drivers\aa5f53h4.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 6A000E7A
IAT \SystemRoot\System32\Drivers\aa5f53h4.SYS[HAL.dll!WRITE_PORT_UCHAR] C6647400
IAT \SystemRoot\System32\Drivers\aa5f53h4.SYS[WMILIB.SYS!WmiSystemControl] 4F8B0200
IAT \SystemRoot\System32\Drivers\aa5f53h4.SYS[WMILIB.SYS!WmiCompleteRequest] 968D5140
---- User IAT/EAT - GMER 1.0.14 ----
IAT C:\WINDOWS\system32\services.exe[728] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[728] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000
---- Devices - GMER 1.0.14 ----
Device \FileSystem\Ntfs \Ntfs 8B24E1F8
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
Device \FileSystem\Fastfat \FatCdrom 897A41F8
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbohci \Device\USBPDO-0 8B0211F8
Device \Driver\usbehci \Device\USBPDO-1 8B0111F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8B2C71F8
Device \Driver\dmio \Device\DmControl\DmConfig 8B2C71F8
Device \Driver\dmio \Device\DmControl\DmPnP 8B2C71F8
Device \Driver\dmio \Device\DmControl\DmInfo 8B2C71F8
Device \Driver\sptd \Device\3325962130 spsq.sys
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\PCI_PNP0880 \Device\00000057 spsq.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 8B2511F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8B2511F8
Device \Driver\Cdrom \Device\CdRom0 8AFF21F8
Device \Driver\Ftdisk \Device\HarddiskVolume3 8B2511F8
Device \Driver\Cdrom \Device\CdRom1 8AFF21F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8ABE8368
Device \Driver\usbstor \Device\00000083 8AC44500
Device \Driver\NetBT \Device\NetbiosSmb 8ABE8368
Device \Driver\usbstor \Device\00000085 8AC44500
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbohci \Device\USBFDO-0 8B0211F8
Device \Driver\usbehci \Device\USBFDO-1 8B0111F8
Device \Driver\nvata \Device\NvAta0 8B2C61F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8AC46500
Device \Driver\nvata \Device\NvAta1 8B2C61F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{AC1F5BCF-9CD1-4470-B59A-466D6B613125} 8ABE8368
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8AC46500
Device \Driver\nvata \Device\0000007c 8B2C61F8
Device \Driver\Ftdisk \Device\FtControl 8B2511F8
Device \Driver\aa5f53h4 \Device\Scsi\aa5f53h41 8AFCF1F8
Device \Driver\JRAID \Device\Scsi\JRAID1 8B24F1F8
Device \Driver\aa5f53h4 \Device\Scsi\aa5f53h41Port5Path0Target0Lun0 8AFCF1F8
Device \FileSystem\Fastfat \Fat 897A41F8
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
Device \FileSystem\Cdfs \Cdfs 8AC55370
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x9B 0x03 0xAA 0x46 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x35 0x95 0x5A 0x0D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x3E 0xD9 0x49 0xF5 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x9B 0x03 0xAA 0x46 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x35 0x95 0x5A 0x0D ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x3E 0xD9 0x49 0xF5 ...
---- EOF - GMER 1.0.14 ----
Edited by kaptain, 03 February 2009 - 12:35 PM.