MBAM:
Malwarebytes' Anti-Malware 1.40
Database version: 2551
Windows 5.1.2600 Service Pack 3
23/08/2009 20:45:04
mbam-log-2009-08-23 (20-45-04).txt
Scan type: Quick Scan
Objects scanned: 88073
Time elapsed: 6 minute(s), 21 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 1
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.
Folders Infected:
C:\WINDOWS\system32\lowsec (Stolen.data) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\lowsec\local.ds (Stolen.data) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lowsec\user.ds (Stolen.data) -> Quarantined and deleted successfully.
RootRepeal:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/23 20:56
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: 00000048
Image Path: \Driver\00000048
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF4C2C000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8ABA000 Size: 8192 File Visible: No Signed: -
Status: -
Name: ejjjf.sys
Image Path: C:\WINDOWS\system32\drivers\ejjjf.sys
Address: 0xF4D15000 Size: 61440 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF0989000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden Services
-------------------
Service Name: kbiwkmxuwkbgko
Image Path: C:\WINDOWS\system32\drivers\kbiwkmobqjarlt.sys
==EOF==
OTL:
OTL logfile created on: 23/08/2009 20:58:40 - Run 2
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\Sony\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
510.42 Mb Total Physical Memory | 72.57 Mb Available Physical Memory | 14.22% Memory free
1.22 Gb Paging File | 0.63 Gb Available in Paging File | 51.57% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 27.95 Gb Total Space | 8.63 Gb Free Space | 30.88% Space Free | Partition Type: NTFS
Drive D: | 58.23 Gb Total Space | 7.02 Gb Free Space | 12.06% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: YOUR-844AEAC0A5
Current User Name: Sony
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2004/08/06 17:43:12 | 00,086,016 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
PRC - [2008/04/14 01:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2004/08/06 17:45:44 | 00,360,521 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
PRC - [2009/07/03 15:49:06 | 01,029,456 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2007/10/31 15:09:16 | 00,110,592 | ---- | M] (Apple, Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/08/23 15:17:59 | 00,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [1999/12/13 02:01:00 | 00,044,032 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\System32\CTSvcCDA.EXE
PRC - [2008/02/27 17:56:54 | 03,072,184 | ---- | M] (Kontiki Inc.) -- C:\Program Files\Kontiki\KService.exe
PRC - [2005/04/03 21:34:00 | 00,131,139 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe
PRC - [2004/09/29 13:14:36 | 00,069,632 | ---- | M] (HP) -- C:\WINDOWS\System32\HPZipm12.exe
PRC - [2004/08/06 17:42:36 | 00,139,264 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
PRC - [2004/09/30 11:54:20 | 00,150,016 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
PRC - [2009/08/23 15:18:12 | 00,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/08/23 15:18:12 | 00,595,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2004/10/25 10:35:30 | 00,278,528 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
PRC - [2000/06/26 08:44:20 | 00,053,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MsPMSPSv.exe
PRC - [2009/08/23 15:18:01 | 00,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2004/10/25 10:35:32 | 00,131,072 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
PRC - [2004/10/25 10:35:32 | 00,118,784 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
PRC - [2009/08/23 15:18:12 | 00,693,016 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2004/09/21 19:54:20 | 00,151,552 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
PRC - [2008/06/10 04:27:04 | 00,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
PRC - [2004/10/21 20:12:48 | 00,184,320 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
PRC - [2004/07/06 15:15:38 | 00,040,960 | R--- | M] (Utimaco Safeware AG) -- C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
PRC - [2002/03/14 17:46:58 | 00,045,056 | ---- | M] (Primax Electronics Ltd.) -- C:\WINDOWS\System32\ICO.EXE
PRC - [2004/02/20 15:12:34 | 00,032,768 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\ISB Utility\ISBMgr.exe
PRC - [2003/11/07 09:21:28 | 00,114,688 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\Apoint.exe
PRC - [2005/10/08 22:08:50 | 00,212,992 | ---- | M] (MB-Soft) -- C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
PRC - [2005/11/08 23:00:38 | 00,128,920 | ---- | M] (DT Soft Ltd.) -- C:\Program Files\DAEMON Tools\daemon.exe
PRC - [2008/01/15 04:22:56 | 00,267,048 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2008/02/27 17:56:54 | 01,032,376 | ---- | M] (Kontiki Inc.) -- C:\Program Files\Kontiki\KHost.exe
PRC - [2009/08/23 15:18:02 | 02,007,832 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2008/04/14 01:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
PRC - [2008/07/02 17:16:20 | 00,393,216 | ---- | M] (Sony Ericsson Mobile Communications AB) -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
PRC - [2003/07/30 02:52:00 | 00,217,195 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
PRC - [2003/02/26 03:08:42 | 00,045,056 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\Apntex.exe
PRC - [2004/10/29 10:32:06 | 03,547,136 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe
PRC - [2004/08/04 13:00:00 | 00,016,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\unsecapp.exe
PRC - [2004/07/28 16:39:30 | 00,962,661 | ---- | M] () -- C:\Program Files\SAGEM\SAGEM [email protected] 800-840\dslmon.exe
PRC - [1997/08/19 00:00:00 | 00,051,984 | ---- | M] () -- C:\Program Files\Microsoft Office\Office\OSA.EXE
PRC - [2009/02/06 11:10:02 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\wmiprvse.exe
PRC - [2005/10/05 13:32:26 | 00,434,176 | ---- | M] (OpenOffice.org) -- D:\Program Files\Open Office\program\soffice.exe
PRC - [2005/10/05 13:32:26 | 00,565,248 | ---- | M] (OpenOffice.org) -- D:\Program Files\Open Office\program\soffice.BIN
PRC - [2008/01/15 04:22:44 | 00,504,104 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/07/03 15:49:06 | 00,520,024 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2008/06/10 04:27:03 | 00,329,104 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
PRC - [2009/08/19 20:54:22 | 00,908,280 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/08/23 19:48:55 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sony\My Documents\Downloads\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - [2007/10/31 15:09:16 | 00,110,592 | ---- | M] (Apple, Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2009/08/23 15:18:01 | 00,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe -- (avg8emc [Auto | Running])
SRV - [2009/08/23 15:17:59 | 00,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running])
SRV - [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [1999/12/13 02:01:00 | 00,044,032 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\System32\CTSvcCDA.EXE -- (Creative Service for CDROM Access [Auto | Running])
SRV - [2004/08/06 17:43:12 | 00,086,016 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng [Auto | Running])
SRV - [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/04/14 01:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2005/11/14 02:06:04 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008/01/15 04:22:44 | 00,504,104 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2008/02/27 17:56:54 | 03,072,184 | ---- | M] (Kontiki Inc.) -- C:\Program Files\Kontiki\KService.exe -- (KService [Auto | Running])
SRV - [2009/07/03 15:49:06 | 01,029,456 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service [Auto | Running])
SRV - [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2005/04/03 21:34:00 | 00,131,139 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2004/09/29 13:14:36 | 00,069,632 | ---- | M] (HP) -- C:\WINDOWS\System32\HPZipm12.exe -- (Pml Driver HPZ12 [Auto | Running])
SRV - [2004/08/06 17:42:36 | 00,139,264 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc [Auto | Running])
SRV - [2004/08/06 17:45:44 | 00,360,521 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor [Auto | Running])
SRV - [2007/10/18 12:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Stopped])
SRV - [2004/08/23 14:02:58 | 00,139,264 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe -- (VAIO Entertainment Aggregation and Control Service [On_Demand | Stopped])
SRV - [2004/11/02 21:43:52 | 00,339,968 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Entertainment\VzTaskScheduler.exe -- (VAIO Entertainment Task Scheduler [On_Demand | Stopped])
SRV - [2004/10/25 10:35:34 | 00,073,728 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe -- (VAIO Entertainment TV Device Arbitration Service [On_Demand | Stopped])
SRV - [2004/09/30 11:54:20 | 00,150,016 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Event Service\VESMgr.exe -- (VAIO Event Service [Auto | Running])
SRV - [2004/10/01 14:46:34 | 01,826,816 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe -- (VAIOMediaPlatform-IntegratedServer-AppServer [On_Demand | Stopped])
SRV - [2004/06/16 03:42:34 | 00,057,344 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe -- (VAIOMediaPlatform-IntegratedServer-HTTP [On_Demand | Stopped])
SRV - [2004/06/22 11:58:14 | 00,733,184 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe -- (VAIOMediaPlatform-IntegratedServer-UPnP [On_Demand | Stopped])
SRV - [2004/06/16 03:41:06 | 00,188,416 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe -- (VAIOMediaPlatform-Mobile-Gateway [On_Demand | Stopped])
SRV - [2004/08/05 16:45:26 | 00,397,824 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe -- (VCI [Auto | Stopped])
SRV - [2004/10/25 10:35:30 | 00,278,528 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe -- (Vcsw [On_Demand | Running])
SRV - [2004/10/25 10:35:32 | 00,131,072 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe -- (VzCdbSvc [Auto | Running])
SRV - [2004/10/25 10:35:32 | 00,118,784 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe -- (VzFw [Auto | Running])
SRV - [2007/10/25 16:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])
SRV - [2000/06/26 08:44:20 | 00,053,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MsPMSPSv.exe -- (WMDM PMSP Service [Auto | Running])
SRV - [2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/ig"
FF - prefs.js..extensions.enabledItems: [email protected]:1.19
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.2
FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/08/19 22:21:12 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/08/23 15:17:59 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/19 20:54:38 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/19 20:54:38 | 00,000,000 | ---D | M]
[2008/09/02 18:33:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\mozilla\Extensions
[2008/09/02 18:33:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/23 16:01:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\mozilla\Firefox\Profiles\3aebxll4.default\extensions
[2007/03/19 22:45:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\mozilla\Firefox\Profiles\3aebxll4.default\extensions\{69087485-8EDE-4a6c-91BE-6B882EB268A5}
[2009/08/22 11:58:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\mozilla\Firefox\Profiles\3aebxll4.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2009/05/06 19:49:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\mozilla\Firefox\Profiles\3aebxll4.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2008/02/11 20:51:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\mozilla\Firefox\Profiles\3aebxll4.default\extensions\[email protected]
[2009/08/23 16:01:19 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/08/18 18:50:15 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/08/22 21:11:35 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2007/10/21 18:50:35 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/05/05 15:17:47 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/08/21 21:10:22 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/08/19 20:54:19 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/19 20:54:19 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2004/09/09 00:03:50 | 00,049,152 | ---- | M] (Macromedia, Inc.) -- C:\Program Files\mozilla firefox\plugins\np32dsw.dll
[2008/02/27 17:57:38 | 00,106,496 | ---- | M] (British Broadcasting Corporation) -- C:\Program Files\mozilla firefox\plugins\npBBCPlugin.dll
[2009/08/19 20:54:27 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2004/12/14 02:19:18 | 00,057,344 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2008/01/20 19:41:43 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2008/01/20 19:41:43 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2008/01/20 19:41:43 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2008/01/20 19:41:43 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2008/01/20 19:41:43 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2008/01/20 19:41:43 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2008/01/20 19:41:43 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2009/08/19 20:54:30 | 00,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2009/08/19 20:54:30 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/08/19 20:54:30 | 00,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2009/08/19 20:54:30 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/08/19 20:54:30 | 00,000,769 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2009/08/19 20:54:30 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/08/19 20:54:30 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/08/19 20:54:30 | 00,000,831 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [adiras] File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Anti-Blaxx Manager] C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe (MB-Soft)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DAEMON Tools] C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd.)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] C:\WINDOWS\System32\ICO.EXE (Primax Electronics Ltd.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PDService.exe] C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe (Utimaco Safeware AG)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [SpeedTouch USB Diagnostics] C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe (THOMSON Telecom Belgium)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [VAIO Update 2] C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe (Sony Corporation)
O4 - HKCU..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Sony Ericsson PC Suite] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB)
O4 - HKCU..\Run: [Vidalia] C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Audio Filter.lnk = C:\Program Files\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe (Sony Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DSLMON.lnk = C:\Program Files\SAGEM\SAGEM [email protected] 800-840\dslmon.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE ()
O4 - Startup: C:\Documents and Settings\Sony\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk = D:\Program Files\Open Office\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: sony-europe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sonystyle-europe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: vaio-link.com ([]* in Trusted sites)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} http://messenger.zon...kr.cab31267.cab (Checkers Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zon...nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\WINDOWS\System32\VESWinlogon.dll (Sony Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/11/15 14:34:08 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{eb93699c-3efd-11dd-bbad-000e35f02162}\Shell\AutoRun\command - "" = setupSNK.exe
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
========== Files/Folders - Created Within 14 Days ==========
[2009/08/23 20:30:35 | 53,528,5760 | -HS- | C] () -- C:\hiberfil.sys
[2009/08/23 20:10:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Sony\Application Data\Malwarebytes
[2009/08/23 20:10:21 | 00,000,700 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/23 20:10:19 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/23 20:10:17 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/08/23 20:10:17 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/08/23 20:10:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/08/23 20:07:43 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/08/23 20:07:17 | 00,000,615 | ---- | C] () -- C:\Documents and Settings\Sony\Desktop\NTREGOPT.lnk
[2009/08/23 20:07:17 | 00,000,596 | ---- | C] () -- C:\Documents and Settings\Sony\Desktop\ERUNT.lnk
[2009/08/23 20:07:16 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/08/23 19:19:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Sony\My Documents\prcocess exp
[2009/08/23 15:19:10 | 00,001,511 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/08/23 15:19:08 | 00,011,952 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/08/23 15:19:07 | 00,108,552 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/08/23 15:19:00 | 00,335,240 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/08/23 15:18:58 | 00,027,784 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/08/23 15:18:28 | 40,101,936 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/08/23 15:18:26 | 00,068,001 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/08/23 15:18:25 | 00,463,779 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/08/23 15:18:21 | 06,061,540 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/08/23 15:18:21 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg
[2009/08/23 14:41:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Sony\Application Data\AVG8
[2009/08/22 14:01:23 | 00,015,688 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/08/22 12:32:37 | 00,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/08/22 12:31:20 | 00,064,160 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2009/08/22 12:28:20 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
[2009/08/22 12:28:17 | 00,000,871 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/08/22 12:27:51 | 00,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2009/08/22 11:57:09 | 00,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2009/08/22 11:57:09 | 00,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2009/08/20 20:15:53 | 01,089,593 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/08/19 22:19:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2009/08/19 22:19:49 | 00,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2009/08/19 22:19:39 | 00,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2009/08/19 22:19:02 | 00,000,000 | ---D | C] -- C:\354a8477206311676f513bff1818
========== Files - Modified Within 14 Days ==========
[2009/08/23 20:48:30 | 00,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/08/23 20:48:25 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2009/08/23 20:48:02 | 00,017,548 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/08/23 20:47:47 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/08/23 20:47:42 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/08/23 20:47:40 | 53,528,5760 | -HS- | M] () -- C:\hiberfil.sys
[2009/08/23 20:28:20 | 00,000,700 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/23 20:07:17 | 00,000,615 | ---- | M] () -- C:\Documents and Settings\Sony\Desktop\NTREGOPT.lnk
[2009/08/23 20:07:17 | 00,000,596 | ---- | M] () -- C:\Documents and Settings\Sony\Desktop\ERUNT.lnk
[2009/08/23 19:19:58 | 00,000,954 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/08/23 15:19:10 | 00,001,511 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/08/23 15:19:08 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/08/23 15:19:07 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/08/23 15:19:00 | 00,335,240 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/08/23 15:18:58 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/08/23 15:18:56 | 40,101,936 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/08/23 15:18:28 | 00,068,001 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/08/23 15:18:26 | 00,463,779 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/08/23 15:18:25 | 06,061,540 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/08/22 12:32:37 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/08/22 12:28:17 | 00,000,871 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/08/22 11:57:09 | 00,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2009/08/22 10:35:51 | 00,044,384 | ---- | M] () -- C:\Documents and Settings\Sony\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/08/21 15:58:05 | 00,107,520 | ---- | M] () -- C:\Documents and Settings\Sony\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/20 20:08:22 | 00,185,816 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/19 22:25:41 | 00,489,078 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/08/19 22:25:41 | 00,432,924 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/08/19 22:25:41 | 00,067,714 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/08/17 18:32:54 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/08/17 01:37:34 | 00,055,656 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
========== LOP Check ==========
[2009/08/23 15:17:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/08/22 12:28:31 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
[2005/10/19 18:44:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ahead
[2008/07/15 22:38:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2004/11/15 15:14:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intel
[2009/08/23 20:58:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kontiki
[2004/11/15 17:41:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBSI
[2008/06/01 20:16:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sky
[2009/01/29 20:38:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2009/08/23 14:41:42 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Sony\Application Data
[2005/07/05 22:26:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\.BitTornado
[2005/10/19 18:45:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\Ahead
[2009/07/24 23:54:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\Azureus
[2008/10/11 05:27:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\i42 Software
[2006/10/18 17:56:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\Image Zone Express
[2005/10/19 20:00:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\InterVideo
[2005/04/27 16:40:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\Leadertech
[2008/10/11 05:11:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\leafChat
[2009/08/23 00:56:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\mIRC
[2008/04/01 20:40:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\My Games
[2009/08/23 20:48:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\OpenOffice.org2
[2009/01/04 11:59:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\Sports Interactive
[2008/11/14 20:04:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\SystemRequirementsLab
[2007/06/18 23:00:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\Teleca
[2007/02/25 20:37:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\TommyGun79
[2008/08/23 02:39:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Sony\Application Data\X-Chat 2
[2009/08/22 12:32:37 | 00,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/07/29 19:56:00 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 13:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/08/23 20:47:47 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2005/06/23 18:59:24 | 00,000,184 | ---- | M] () -- C:\setuplog.exe
< %systemroot%\system32\eventlog.dll >
[2008/04/14 01:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\eventlog.dll
< %systemroot%\system32\scecli.dll >
[2008/04/14 01:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\scecli.dll
< %systemroot%\netlogon.dll >
< %systemroot%\system32\cngaudit.dll >
< %systemroot%\system32\sceclt.dll >
< %systemroot%\ntelogon.dll >
< %systemroot%\system32\logevent.dll >
========== Alternate Data Streams ==========
@Alternate Data Stream - 65 bytes -> C:\Documents and Settings\All Users\Application Data\Sports Interactive:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EPPJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVV
VVV
< End of report >
GMER
GMER 1.0.15.15077 [kjci9020.exe] - http://www.gmer.net
Rootkit scan 2009-08-23 21:42:47
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
Code 82EF58D8 ZwEnumerateKey
Code 82D74878 ZwFlushInstructionCache
Code 82E8C316 ZwSaveKey
Code 82DA82CE ZwSaveKeyEx
Code 82E5F64E IofCallDriver
Code 82DE8EB6 IofCompleteRequest
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCallDriver 804EE130 5 Bytes JMP 82E5F653
.text ntkrnlpa.exe!IofCompleteRequest 804EE1C0 5 Bytes JMP 82DE8EBB
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805ABEC4 5 Bytes JMP 82D7487C
PAGE ntkrnlpa.exe!ZwEnumerateKey 8061AB70 5 Bytes JMP 82EF58DC
PAGE ntkrnlpa.exe!ZwSaveKey 8061BDE4 5 Bytes JMP 82E8C31A
PAGE ntkrnlpa.exe!ZwSaveKeyEx 8061BECA 5 Bytes JMP 82DA82D2
? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
? C:\WINDOWS\System32\Drivers\SPTD5325.SYS The process cannot access the file because it is being used by another process.
.text dtscsi.sys!A0DB34FC6FE35D429A28ADDE5467D4D7 F74434F0 16 Bytes CALL 4D1F7223
.text dtscsi.sys!A0DB34FC6FE35D429A28ADDE5467D4D7 + 11 F7443501 31 Bytes [20, 44, F7, 89, D2, CD, 86, ...]
? C:\WINDOWS\System32\Drivers\dtscsi.sys The process cannot access the file because it is being used by another process.
? system32\drivers\ejjjf.sys The system cannot find the path specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[1640] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00B8000A
.text C:\WINDOWS\Explorer.EXE[1640] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\WINDOWS\Explorer.EXE[1640] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\WINDOWS\Explorer.EXE[1640] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\WINDOWS\Explorer.EXE[1640] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[2068] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[2068] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[2068] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[2068] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe[2208] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe[2208] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe[2208] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe[2208] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Apoint\Apntex.exe[2232] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Apoint\Apntex.exe[2232] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Apoint\Apntex.exe[2232] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Apoint\Apntex.exe[2232] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[2704] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[2704] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[2704] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[2704] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\SAGEM\SAGEM [email protected] 800-840\dslmon.exe[3104] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\SAGEM\SAGEM [email protected] 800-840\dslmon.exe[3104] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\SAGEM\SAGEM [email protected] 800-840\dslmon.exe[3104] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\SAGEM\SAGEM [email protected] 800-840\dslmon.exe[3104] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[3308] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[3308] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[3308] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[3308] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony\VAIO Power Management\SPMgr.exe[3344] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony\VAIO Power Management\SPMgr.exe[3344] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony\VAIO Power Management\SPMgr.exe[3344] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony\VAIO Power Management\SPMgr.exe[3344] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe[3352] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe[3352] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe[3352] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe[3352] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\WINDOWS\system32\ICO.EXE[3364] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\WINDOWS\system32\ICO.EXE[3364] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\WINDOWS\system32\ICO.EXE[3364] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\WINDOWS\system32\ICO.EXE[3364] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[3372] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[3372] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[3372] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[3372] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Microsoft Office\Office\OSA.EXE[3396] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Microsoft Office\Office\OSA.EXE[3396] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Microsoft Office\Office\OSA.EXE[3396] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Microsoft Office\Office\OSA.EXE[3396] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Apoint\Apoint.exe[3460] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Apoint\Apoint.exe[3460] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Apoint\Apoint.exe[3460] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Apoint\Apoint.exe[3460] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe[3500] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe[3500] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe[3500] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe[3500] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\DAEMON Tools\daemon.exe[3512] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\DAEMON Tools\daemon.exe[3512] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\DAEMON Tools\daemon.exe[3512] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\DAEMON Tools\daemon.exe[3512] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Kontiki\KHost.exe[3552] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Kontiki\KHost.exe[3552] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Kontiki\KHost.exe[3552] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Kontiki\KHost.exe[3552] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3580] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3580] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3580] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3580] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Messenger\msmsgs.exe[3620] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Messenger\msmsgs.exe[3620] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Messenger\msmsgs.exe[3620] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Messenger\msmsgs.exe[3620] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\WINDOWS\system32\ctfmon.exe[3632] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\WINDOWS\system32\ctfmon.exe[3632] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\WINDOWS\system32\ctfmon.exe[3632] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\WINDOWS\system32\ctfmon.exe[3632] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text D:\Program Files\Open Office\program\soffice.BIN[4056] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text D:\Program Files\Open Office\program\soffice.BIN[4056] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text D:\Program Files\Open Office\program\soffice.BIN[4056] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text D:\Program Files\Open Office\program\soffice.BIN[4056] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Documents and Settings\Sony\My Documents\Downloads\kjci9020.exe[4320] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Documents and Settings\Sony\My Documents\Downloads\kjci9020.exe[4320] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Documents and Settings\Sony\My Documents\Downloads\kjci9020.exe[4320] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Documents and Settings\Sony\My Documents\Downloads\kjci9020.exe[4320] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[4936] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 66003B74 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[4936] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 66003B19 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[4936] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 66003A72 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[4936] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 66003AC5 C:\WINDOWS\system32\SonyAIwd.dll (Sony VAIO watchdog/QSound Labs, Inc.)
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F8393AD2] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F8393C0E] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F8393B96] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F839476C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F8394642] sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F83B6056] sptd.sys
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [10001D50] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [10001D50] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [10001D50] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [10001D50] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [10001D20] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AdjustWindowRectEx] [1002DE60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AdjustWindowRect] [1002DED0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [10001D20] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [10001D50] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongA] [1002DEF0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [10001D50] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [10001D20] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [10001D50] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!SetWindowLongA] [1002DEF0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [10001D20] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [10001D50] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[3692] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 831CCEB0
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\NetBT \Device\NetBT_Tcpip_{D4646AD9-0EE5-47E1-B0CA-5722D4D11E44} 82DEA3A0
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)
Device \Driver\Ftdisk \Device\HarddiskVolume1 831CD5D0
Device \Driver\Ftdisk \Device\HarddiskVolume2 831CD5D0
Device \Driver\Cdrom \Device\CdRom0 82F7F328
Device \FileSystem\Rdbss \Device\FsWrap 8239AEB0
Device \Driver\Ftdisk \Device\HarddiskVolume3 831CD5D0
Device \Driver\Cdrom \Device\CdRom1 82F7F328
Device \Driver\Cdrom \Device\CdRom2 82F7F328
Device \Driver\Cdrom \Device\CdRom3 82F7F328
Device \Driver\Cdrom \Device\CdRom4 82F7F328
Device \Driver\NetBT \Device\NetBT_Tcpip_{61C2CCB5-59E1-480A-9FEA-9658DD226873} 82DEA3A0
Device \Driver\NetBT \Device\NetBt_Wins_Export 82DEA3A0
Device \Driver\NetBT \Device\NetbiosSmb 82DEA3A0
Device \Driver\00000048 \Device\0000004e sptd.sys
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp Lbd.sys (Boot Driver/Lavasoft AB)
Device \Driver\Disk \Device\Harddisk0\DR0 831CC0E8
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp Lbd.sys (Boot Driver/Lavasoft AB)
Device \Driver\Disk \Device\Harddisk1\DR4 831CC0E8
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+5 831CC0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 823CAEB0
Device \FileSystem\MRxSmb \Device\LanmanRedirector 823CAEB0
Device \FileSystem\Npfs \Device\NamedPipe 8312FEB0
Device \Driver\Ftdisk \Device\FtControl 831CD5D0
Device \FileSystem\Msfs \Device\Mailslot 82B59360
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port1Path0Target2Lun0 82EBDEB0
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port1Path0Target0Lun0 82EBDEB0
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port1Path0Target3Lun0 82EBDEB0
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port1Path0Target1Lun0 82EBDEB0
Device \Driver\dtscsi \Device\Scsi\dtscsi1 82EBDEB0
Device \FileSystem\Cdfs \Cdfs 82EAA678
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\drivers\kbiwkmobqjarlt.sys (*** hidden *** ) [SYSTEM] kbiwkmxuwkbgko <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\[email protected] C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\[email protected] 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\[email protected] 0xF3 0xF1 0x25 0x34 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0[email protected] 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0[email protected] 0xE3 0xE6 0xB8 0x41 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0x69 0xEA 0x21 0xCA ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0xF6 0x1A 0x93 0x51 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0x31 0x00 0x40 0x6F ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0xCB 0x50 0xA8 0x9F ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\[email protected] C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\[email protected] 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\[email protected] 0xF3 0xF1 0x25 0x34 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0[email protected] 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0[email protected] 0xE3 0xE6 0xB8 0x41 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0x05 0x32 0x27 0x3C ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0xF6 0x1A 0x93 0x51 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0x31 0x00 0x40 0x6F ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0xCB 0x50 0xA8 0x9F ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\[email protected] C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\[email protected] 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\[email protected] 0xF3 0xF1 0x25 0x34 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0[email protected] 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0[email protected] 0xE3 0xE6 0xB8 0x41 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0x05 0x32 0x27 0x3C ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0xF6 0x1A 0x93 0x51 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0x31 0x00 0x40 0x6F ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0xCB 0x50 0xA8 0x9F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmxuwkbgko
Reg HKLM\SYSTEM\CurrentControlSet\Services\[email protected] 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\[email protected] 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\[email protected] file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\[email protected] \systemroot\system32\drivers\kbiwkmobqjarlt.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmxuwkbgko\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmxuwkbgko\[email protected] 10002
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmxuwkbgko\[email protected] 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmxuwkbgko\[email protected] 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmxuwkbgko\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmxuwkbgko\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmxuwkbgko\main\[email protected]* kbiwkmwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmxuwkbgko\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmxuwkbgko\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmxuwkbgko\[email protected] \systemroot\system32\drivers\kbiwkmobqjarlt.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmxuwkbgko\[email protected] \systemroot\system32\kbiwkmsewmycpa.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmxuwkbgko\[email protected] \systemroot\system32\kbiwkmswuphdja.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmxuwkbgko\[email protected] \systemroot\system32\kbiwkmxsnsxyte.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmxuwkbgko\[email protected] \systemroot\system32\kbiwkmtehtkbek.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\[email protected] C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\[email protected] 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\[email protected] 0xF3 0xF1 0x25 0x34 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0[email protected] 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0[email protected] 0xE3 0xE6 0xB8 0x41 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0x69 0xEA 0x21 0xCA ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0xF6 0x1A 0x93 0x51 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0x31 0x00 0x40 0x6F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0xCB 0x50 0xA8 0x9F ...
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmxuwkbgko (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\[email protected] 1
Reg HKLM\SYSTEM\ControlSet006\Services\[email protected] 1
Reg HKLM\SYSTEM\ControlSet006\Services\[email protected] file system
Reg HKLM\SYSTEM\ControlSet006\Services\[email protected] \systemroot\system32\drivers\kbiwkmobqjarlt.sys
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmxuwkbgko\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmxuwkbgko\[email protected] 10002
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmxuwkbgko\[email protected] 1
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmxuwkbgko\[email protected] 14400
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmxuwkbgko\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmxuwkbgko\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmxuwkbgko\main\[email protected]* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmxuwkbgko\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmxuwkbgko\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmxuwkbgko\[email protected]kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmobqjarlt.sys
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmxuwkbgko\[email protected] \systemroot\system32\kbiwkmsewmycpa.dll
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmxuwkbgko\[email protected] \systemroot\system32\kbiwkmswuphdja.dat
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmxuwkbgko\[email protected] \systemroot\system32\kbiwkmxsnsxyte.dll
Reg HKLM\SYSTEM\ControlSet006\Services\kbiwkmxuwkbgko\[email protected] \systemroot\system32\kbiwkmtehtkbek.dat
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\[email protected] C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\[email protected] 0
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\[email protected] 0xF3 0xF1 0x25 0x34 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0[email protected] 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0[email protected] 0xE3 0xE6 0xB8 0x41 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0x69 0xEA 0x21 0xCA ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0xF6 0x1A 0x93 0x51 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0x31 0x00 0x40 0x6F ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0xCB 0x50 0xA8 0x9F ...
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\kbiwkmsewmycpa.dll 45056 bytes executable
File C:\WINDOWS\system32\kbiwkmswuphdja.dat 31789 bytes
File C:\WINDOWS\system32\kbiwkmtehtkbek.dat 91 bytes
File C:\WINDOWS\system32\kbiwkmxsnsxyte.dll 19968 bytes executable
File C:\WINDOWS\system32\drivers\kbiwkmobqjarlt.sys 71168 bytes executable <-- ROOTKIT !!!
File C:\WINDOWS\Temp\kbiwkmlkvrchtixt.tmp 91 bytes
---- EOF - GMER 1.0.15 ----
Combifix:
ComboFix 09-08-22.06 - Sony 23/08/2009 22:20.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.93 [GMT 1:00]
Running from: c:\documents and settings\Sony\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\ALLUSE~1\STARTM~1\Programs\Windows Live Messenger .lnk
c:\recycler\S-1-5-21-2302734979-2663196984-2720711168-1003
c:\recycler\S-1-5-21-3335092285-3910610236-2503500597-1003
C:\setuplog.exe
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\Fonts\ZWAdobeF.TTF
c:\windows\system32\drivers\kbiwkmobqjarlt.sys
c:\windows\system32\kbiwkmsewmycpa.dll
c:\windows\system32\kbiwkmswuphdja.dat
c:\windows\system32\kbiwkmtehtkbek.dat
c:\windows\system32\kbiwkmxsnsxyte.dll
D:\install.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_kbiwkmxuwkbgko
-------\Legacy_kbiwkmxuwkbgko
((((((((((((((((((((((((( Files Created from 2009-07-23 to 2009-08-23 )))))))))))))))))))))))))))))))
.
2009-08-23 19:10 . 2009-08-23 19:10 -------- d-----w- c:\documents and settings\Sony\Application Data\Malwarebytes
2009-08-23 19:10 . 2009-08-03 12:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-23 19:10 . 2009-08-23 19:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-23 19:10 . 2009-08-23 19:10 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Malwarebytes
2009-08-23 19:10 . 2009-08-03 12:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-23 19:07 . 2009-08-23 19:07 -------- d-----w- c:\program files\ERUNT
2009-08-23 14:19 . 2009-08-23 14:19 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-23 14:19 . 2009-08-23 14:19 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-23 14:19 . 2009-08-23 14:19 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-23 14:18 . 2009-08-23 14:18 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-23 14:18 . 2009-08-23 14:18 -------- d-----w- c:\windows\system32\drivers\Avg
2009-08-23 13:41 . 2009-08-23 13:41 -------- d-----w- c:\documents and settings\Sony\Application Data\AVG8
2009-08-22 13:01 . 2009-07-03 14:49 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-08-22 11:31 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-08-22 11:28 . 2009-08-22 11:28 -------- dc-h--w- c:\docume~1\ALLUSE~1\APPLIC~1\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-22 11:27 . 2009-08-22 11:27 -------- d-----w- c:\program files\Lavasoft
2009-08-22 10:58 . 2008-02-17 16:16 90112 ----a-w- c:\documents and settings\Sony\Application Data\Mozilla\Firefox\Profiles\3aebxll4.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
2009-08-22 10:58 . 2007-12-28 10:15 172032 ----a-w- c:\documents and settings\Sony\Application Data\Mozilla\Firefox\Profiles\3aebxll4.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\puttygen.exe
2009-08-22 10:58 . 2007-10-08 00:57 307200 ----a-w- c:\documents and settings\Sony\Application Data\Mozilla\Firefox\Profiles\3aebxll4.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\psftp.exe
2009-08-19 21:19 . 2009-08-19 21:19 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-19 21:19 . 2009-08-19 21:19 -------- d-----w- c:\program files\MSBuild
2009-08-19 21:19 . 2009-08-19 21:19 -------- d-----w- c:\program files\Reference Assemblies
2009-08-19 21:19 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-19 21:19 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-19 21:19 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-19 21:19 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-19 21:19 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-19 21:19 . 2009-08-19 21:19 -------- d-----w- C:\354a8477206311676f513bff1818
2009-08-19 21:19 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-19 21:19 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-18 18:00 . 2009-08-18 18:00 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-17 00:37 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-28 17:48 . 2009-07-28 17:48 -------- d-----w- c:\program files\Recovery Toolbox for Outlook Express
2009-07-25 16:17 . 2009-07-25 16:17 39272 ---ha-w- c:\windows\system32\mlfcache.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-23 21:42 . 2007-06-17 10:05 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Kontiki
2009-08-23 21:37 . 2005-10-10 20:53 -------- d-----w- c:\documents and settings\Sony\Application Data\OpenOffice.org2
2009-08-23 14:17 . 2008-06-01 15:28 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\avg8
2009-08-22 23:56 . 2008-08-23 00:50 -------- d-----w- c:\documents and settings\Sony\Application Data\mIRC
2009-08-22 10:54 . 2006-04-07 15:32 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-08-22 10:54 . 2006-04-07 15:32 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-22 09:35 . 2005-06-11 22:20 44384 ----a-w- c:\documents and settings\Sony\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-17 00:37 . 2009-05-06 18:39 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-05 09:01 . 2008-09-03 21:37 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-24 22:54 . 2005-07-07 19:45 -------- d-----w- c:\documents and settings\Sony\Application Data\Azureus
2009-07-17 19:01 . 2008-09-03 21:38 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 22:43 . 2004-11-15 04:19 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2004-11-15 04:18 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-16 14:36 . 2008-09-03 21:37 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2008-09-03 21:37 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2008-09-03 21:37 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2008-09-03 21:38 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 08:19 . 2008-09-03 21:40 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2008-09-03 21:36 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2008-09-03 21:37 1291264 ----a-w- c:\windows\system32\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"kdx"="c:\program files\Kontiki\KHost.exe" [2008-02-27 1032376]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-02 393216]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VAIO Update 2"="c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe" [2004-09-21 151552]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2004-10-21 184320]
"PDService.exe"="c:\program files\Utimaco\SafeGuard PrivateDisk\pdservice.exe" [2004-07-06 40960]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-10-07 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-10-07 126976]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2003-11-07 114688]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Anti-Blaxx Manager"="c:\program files\Anti-Blaxx\Anti-Blaxx.exe" [2005-10-08 212992]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-11-08 128920]
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-10 385024]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-01-15 267048]
"kdx"="c:\program files\Kontiki\KHost.exe" [2008-02-27 1032376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-04-03 5406720]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-23 2007832]
"Mouse Suite 98 Daemon"="ICO.EXE" - c:\windows\system32\ico.exe [2002-03-14 45056]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Sony\Start Menu\Programs\Startup\
OpenOffice.org 2.0.lnk - d:\program files\Open Office\program\quickstart.exe [2005-9-23 61440]
c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-7-30 217195]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Audio Filter.lnk - c:\program files\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe [2005-4-21 3547136]
DSLMON.lnk - c:\program files\SAGEM\SAGEM [email protected] 800-840\dslmon.exe [2005-6-23 962661]
Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1997-8-19 111376]
Office Startup.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1997-8-19 51984]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-23 14:19 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2004-10-27 15:40 73728 ----a-w- c:\windows\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Java\\jre1.5.0_04\\bin\\javaw.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2009\\fm.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"d:\\Video\\mIRC 6.3 + keygen\\mIRC 6.3 + keygen\\mIRC - English.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"55395:TCP"= 55395:TCP:vuze
"55395:UDP"= 55395:UDP:vue1
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [22/08/2009 12:31 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [23/08/2009 15:19 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [23/08/2009 15:19 108552]
R1 PrivateDisk;PrivateDisk;c:\windows\system32\drivers\privatediskm.sys [06/07/2004 15:07 45627]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [23/08/2009 15:18 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [23/08/2009 15:17 297752]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [03/07/2009 15:49 1029456]
S1 eusk2par;EUTRON SmartKey Parallel Driver;c:\windows\system32\drivers\eusk2par.sys [07/01/2006 17:01 24786]
S3 s3017bus;Sony Ericsson Device 3017 driver (WDM);c:\windows\system32\drivers\s3017bus.sys [15/07/2008 22:37 83880]
S3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter;c:\windows\system32\drivers\s3017mdfl.sys [15/07/2008 22:37 15016]
S3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver;c:\windows\system32\drivers\s3017mdm.sys [15/07/2008 22:37 110632]
S3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s3017mgmt.sys [15/07/2008 22:37 104616]
S3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS);c:\windows\system32\drivers\s3017nd5.sys [15/07/2008 22:37 25512]
S3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface;c:\windows\system32\drivers\s3017obex.sys [15/07/2008 22:37 100648]
S3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM);c:\windows\system32\drivers\s3017unic.sys [15/07/2008 22:37 110120]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Vidalia - c:\program files\Vidalia Bundle\Vidalia\vidalia.exe
HKLM-Run-adiras - adiras.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
Trusted Zone: sony-europe.com
Trusted Zone: sonystyle-europe.com
Trusted Zone: vaio-link.com
FF - ProfilePath - c:\docume~1\Sony\APPLIC~1\Mozilla\Firefox\Profiles\3aebxll4.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\Sony\Application Data\Mozilla\Firefox\Profiles\3aebxll4.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npBBCPlugin.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-23 22:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(936)
c:\windows\system32\VESWinlogon.dll
- - - - - - - > 'explorer.exe'(4076)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\program files\Creative\Creative NOMAD Jukebox Zen Xtra\NOMAD Explorer\CTJBNS.DLL
c:\program files\Creative\Creative NOMAD Jukebox Zen Xtra\NOMAD Explorer\CTIntrfc.dll
c:\program files\Creative\Creative NOMAD Jukebox Zen Xtra\NOMAD Explorer\JBNSHK.dll
c:\program files\Creative\Creative NOMAD Jukebox Zen Xtra\NOMAD Explorer\JBNSRES.DLL
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Kontiki\KService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\windows\system32\MsPMSPSv.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\program files\Apoint\ApntEx.exe
d:\program files\Open Office\program\soffice.exe
d:\program files\Open Office\program\soffice.bin
c:\program files\iPod\bin\iPodService.exe
c:\program files\Java\jre1.6.0_07\bin\jucheck.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Completion time: 2009-08-23 22:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-23 21:49
Pre-Run: 9,151,201,280 bytes free
Post-Run: 9,048,051,712 bytes free
Current=5 Default=5 Failed=2 LastKnownGood=6 Sets=2,3,4,5,6
317 --- E O F --- 2009-08-21 12:34