TechSpot

XP - Generic win32 process/ google.ca/webhp

By specialk2ca
Oct 21, 2010
  1. Hi,

    I've run XP for several years without any major hiccups and recently I started getting 2 distinct errors:

    1. Generic win32 process causes an unexpected error and is shut down. The internet would not work as a result
    2. I would get random popups in Firefox going to an ad then to google.ca/webhp

    Restarting solves the first problem temporarily. I've run Malware and AVG and nothing was found. Any help to resolve this would be greatly appreciated. I'll work on posting my logs in the meantime.
     
  2. specialk2ca

    specialk2ca TS Rookie Topic Starter

    Logs pasted
     

    Attached Files:

  3. Broni

    Broni Malware Annihilator Posts: 52,892   +344

  4. specialk2ca

    specialk2ca TS Rookie Topic Starter

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4052

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 6.0.2900.5512

    21/10/2010 9:29:26 PM
    mbam-log-2010-10-21 (21-29-26).txt

    Scan type: Quick scan
    Objects scanned: 127066
    Time elapsed: 10 minute(s), 57 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
     
  5. specialk2ca

    specialk2ca TS Rookie Topic Starter

    GMER 1.0.15.15477 - http://www.gmer.net
    Rootkit scan 2010-10-21 22:07:19
    Windows 5.1.2600 Service Pack 3
    Running: 9u291yhh.exe; Driver: C:\DOCUME~1\KENJEN~1\LOCALS~1\Temp\uxtdqpog.sys


    ---- System - GMER 1.0.15 ----

    SSDT sptd.sys ZwCreateKey [0xF7508AC8]
    SSDT sptd.sys ZwEnumerateKey [0xF7508C22]
    SSDT sptd.sys ZwEnumerateValueKey [0xF7508F9A]
    SSDT sptd.sys ZwOpenKey [0xF750898E]
    SSDT sptd.sys ZwQueryKey [0xF7509064]
    SSDT sptd.sys ZwQueryValueKey [0xF7508EFC]
    SSDT sptd.sys ZwSetValueKey [0xF75090EC]

    ---- Kernel code sections - GMER 1.0.15 ----

    ? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
    ? C:\WINDOWS\System32\Drivers\SPTD3805.SYS The process cannot access the file because it is being used by another process.
    .rsrc C:\WINDOWS\system32\drivers\agp440.sys entry point in ".rsrc" section [0xF74A5814]
    init C:\WINDOWS\system32\drivers\senfilt.sys entry point in "init" section [0xB8DE1F80]

    ---- User code sections - GMER 1.0.15 ----

    .text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtProtectVirtualMemory 7C90D6D0 5 Bytes JMP 007F000A
    .text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtWriteVirtualMemory 7C90DF90 5 Bytes JMP 0080000A
    .text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!KiUserExceptionDispatcher 7C90E45C 5 Bytes JMP 007E000C
    .text C:\WINDOWS\System32\svchost.exe[1092] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 0302000A
    .text C:\WINDOWS\System32\svchost.exe[1092] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00C7000A
    .text C:\WINDOWS\Explorer.EXE[1740] ntdll.dll!NtProtectVirtualMemory 7C90D6D0 5 Bytes JMP 00B1000A
    .text C:\WINDOWS\Explorer.EXE[1740] ntdll.dll!NtWriteVirtualMemory 7C90DF90 5 Bytes JMP 00B6000A
    .text C:\WINDOWS\Explorer.EXE[1740] ntdll.dll!KiUserExceptionDispatcher 7C90E45C 5 Bytes JMP 00B0000C

    ---- Kernel IAT/EAT - GMER 1.0.15 ----

    IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F751189E] sptd.sys
    IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7527D86] sptd.sys
    IAT ftdisk.sys[ntoskrnl.exe!IoGetAttachedDeviceReference] [F7511E24] sptd.sys
    IAT ftdisk.sys[ntoskrnl.exe!IoGetDeviceObjectPointer] [F7511D28] sptd.sys
    IAT ftdisk.sys[ntoskrnl.exe!IofCallDriver] [F7511EF4] sptd.sys
    IAT PartMgr.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F75271AE] sptd.sys
    IAT PartMgr.sys[ntoskrnl.exe!IoDetachDevice] [F7511A5A] sptd.sys
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortGetVirtualAddress] [F74F0068] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT atapi.sys[ntoskrnl.exe!IofCompleteRequest] [F752704A] sptd.sys
    IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F75118F2] sptd.sys
    IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F7504AD2] sptd.sys
    IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F7504C0E] sptd.sys
    IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F7504B96] sptd.sys
    IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F750576C] sptd.sys
    IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F7505642] sptd.sys
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortGetVirtualAddress] [F74F0068] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetSrb] [F74EFF9E] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetVirtualAddress] [F74F0068] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiDebugPrint] [F74EFF98] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortGetSrb] [F74EFF9E] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiDebugPrint] [F74EFF98] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetVirtualAddress] [F74F0068] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
     
  6. specialk2ca

    specialk2ca TS Rookie Topic Starter

    GMER 1.0.15.15477 - http://www.gmer.net
    Rootkit scan 2010-10-21 22:07:19
    Windows 5.1.2600 Service Pack 3
    Running: 9u291yhh.exe; Driver: C:\DOCUME~1\KENJEN~1\LOCALS~1\Temp\uxtdqpog.sys


    ---- System - GMER 1.0.15 ----

    SSDT sptd.sys ZwCreateKey [0xF7508AC8]
    SSDT sptd.sys ZwEnumerateKey [0xF7508C22]
    SSDT sptd.sys ZwEnumerateValueKey [0xF7508F9A]
    SSDT sptd.sys ZwOpenKey [0xF750898E]
    SSDT sptd.sys ZwQueryKey [0xF7509064]
    SSDT sptd.sys ZwQueryValueKey [0xF7508EFC]
    SSDT sptd.sys ZwSetValueKey [0xF75090EC]

    ---- Kernel code sections - GMER 1.0.15 ----

    ? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
    ? C:\WINDOWS\System32\Drivers\SPTD3805.SYS The process cannot access the file because it is being used by another process.
    .rsrc C:\WINDOWS\system32\drivers\agp440.sys entry point in ".rsrc" section [0xF74A5814]
    init C:\WINDOWS\system32\drivers\senfilt.sys entry point in "init" section [0xB8DE1F80]

    ---- User code sections - GMER 1.0.15 ----

    .text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtProtectVirtualMemory 7C90D6D0 5 Bytes JMP 007F000A
    .text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtWriteVirtualMemory 7C90DF90 5 Bytes JMP 0080000A
    .text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!KiUserExceptionDispatcher 7C90E45C 5 Bytes JMP 007E000C
    .text C:\WINDOWS\System32\svchost.exe[1092] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 0302000A
    .text C:\WINDOWS\System32\svchost.exe[1092] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00C7000A
    .text C:\WINDOWS\Explorer.EXE[1740] ntdll.dll!NtProtectVirtualMemory 7C90D6D0 5 Bytes JMP 00B1000A
    .text C:\WINDOWS\Explorer.EXE[1740] ntdll.dll!NtWriteVirtualMemory 7C90DF90 5 Bytes JMP 00B6000A
    .text C:\WINDOWS\Explorer.EXE[1740] ntdll.dll!KiUserExceptionDispatcher 7C90E45C 5 Bytes JMP 00B0000C

    ---- Kernel IAT/EAT - GMER 1.0.15 ----

    IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F751189E] sptd.sys
    IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7527D86] sptd.sys
    IAT ftdisk.sys[ntoskrnl.exe!IoGetAttachedDeviceReference] [F7511E24] sptd.sys
    IAT ftdisk.sys[ntoskrnl.exe!IoGetDeviceObjectPointer] [F7511D28] sptd.sys
    IAT ftdisk.sys[ntoskrnl.exe!IofCallDriver] [F7511EF4] sptd.sys
    IAT PartMgr.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F75271AE] sptd.sys
    IAT PartMgr.sys[ntoskrnl.exe!IoDetachDevice] [F7511A5A] sptd.sys
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortGetVirtualAddress] [F74F0068] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cpqarray.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT atapi.sys[ntoskrnl.exe!IofCompleteRequest] [F752704A] sptd.sys
    IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F75118F2] sptd.sys
    IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F7504AD2] sptd.sys
    IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F7504C0E] sptd.sys
    IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F7504B96] sptd.sys
    IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F750576C] sptd.sys
    IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F7505642] sptd.sys
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortGetVirtualAddress] [F74F0068] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aha154x.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetSrb] [F74EFF9E] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetVirtualAddress] [F74F0068] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiDebugPrint] [F74EFF98] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortGetSrb] [F74EFF9E] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiDebugPrint] [F74EFF98] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetVirtualAddress] [F74F0068] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
     
  7. specialk2ca

    specialk2ca TS Rookie Topic Starter

    [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetSrb] [F74EFF9E] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetVirtualAddress] [F74F0068] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiDebugPrint] [F74EFF98] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortGetSrb] [F74EFF9E] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiDebugPrint] [F74EFF98] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetVirtualAddress] [F74F0068] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2hib.sys[ntoskrnl.exe!IofCompleteRequest] [F752704A] sptd.sys
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT disk.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7527E4A] sptd.sys
    IAT \WINDOWS\system32\DRIVERS\CLASSPNP.SYS[ntoskrnl.exe!IoDetachDevice] [F75168C6] sptd.sys
    IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!IofCompleteRequest] [F752704A] sptd.sys
    IAT \SystemRoot\system32\DRIVERS\cdrom.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7527E4A] sptd.sys
    IAT \SystemRoot\system32\DRIVERS\rdbss.sys[ntoskrnl.exe!IofCallDriver] [F7511CC6] sptd.sys
    IAT \SystemRoot\system32\DRIVERS\mrxsmb.sys[ntoskrnl.exe!IofCallDriver] [F7511CC6] sptd.sys

    ---- Devices - GMER 1.0.15 ----

    Device \FileSystem\Ntfs \Ntfs 8A48F708
    Device \FileSystem\Fastfat \FatCdrom 89B3E970

    AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

    Device \Driver\Ftdisk \Device\HarddiskVolume1 8A4928C8
    Device \Driver\Ftdisk \Device\HarddiskVolume2 8A4928C8
    Device \Driver\Cdrom \Device\CdRom0 8A24F0E8
    Device \FileSystem\Rdbss \Device\FsWrap 89F8F1F8
    Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 8A333AEA
    Device \Driver\atapi \Device\Ide\IdePort0 [F7851B40] atapi.sys[unknown section] {MOV EAX, 0x8a447008; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7518e12; RET }
    Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 8A333AEA
    Device \Driver\atapi \Device\Ide\IdePort1 [F7851B40] atapi.sys[unknown section] {MOV EAX, 0x8a447008; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7518e12; RET }
    Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T0L0-e 8A333AEA
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F7851B40] atapi.sys[unknown section] {MOV EAX, 0x8a447008; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7518e12; RET }
    Device \Driver\Ftdisk \Device\HarddiskVolume3 8A4928C8

    AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

    Device \Driver\Disk \Device\Harddisk0\DR0 8A48F940
     
  8. specialk2ca

    specialk2ca TS Rookie Topic Starter

    [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78xx.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dac960nt.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql10wnt.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetSrb] [F74EFF9E] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortGetVirtualAddress] [F74F0068] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT amsint.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT i2omp.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiDebugPrint] [F74EFF98] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortGetSrb] [F74EFF9E] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ini910u.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ql1240.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT aic78u2.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT ABP480N5.SYS[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT asc3350p.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiDebugPrint] [F74EFF98] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cd20xrnt.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetLogicalUnit] [F74EFDE2] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT adpu160m.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetVirtualAddress] [F74F0068] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortValidateRange] [F74F00A4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortSetBusDataByOffset] [F74EBCF4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT dpti2o.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT perc2hib.sys[ntoskrnl.exe!IofCompleteRequest] [F752704A] sptd.sys
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortGetPhysicalAddress] [F74EFFE4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortGetBusData] [F74EC416] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortGetUncachedExtension] [F74EC508] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT hpn.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortMoveMemory] [F74EFF4C] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortStallExecution] [F74F00D4] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortLogError] [F74EFECC] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortNotification] [F74F00E6] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortFreeDeviceBase] [F74EBC28] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortConvertUlongToPhysicalAddress] [F74F00AE] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortGetDeviceBase] [F74EBAFA] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortCompleteRequest] [F74F046A] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT cbidf2k.sys[SCSIPORT.SYS!ScsiPortInitialize] [F74F6F74] \WINDOWS\System32\Drivers\SPTD3805.SYS
    IAT disk.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7527E4A] sptd.sys
    IAT \WINDOWS\system32\DRIVERS\CLASSPNP.SYS[ntoskrnl.exe!IoDetachDevice] [F75168C6] sptd.sys
    IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!IofCompleteRequest] [F752704A] sptd.sys
    IAT \SystemRoot\system32\DRIVERS\cdrom.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7527E4A] sptd.sys
    IAT \SystemRoot\system32\DRIVERS\rdbss.sys[ntoskrnl.exe!IofCallDriver] [F7511CC6] sptd.sys
    IAT \SystemRoot\system32\DRIVERS\mrxsmb.sys[ntoskrnl.exe!IofCallDriver] [F7511CC6] sptd.sys

    ---- Devices - GMER 1.0.15 ----

    Device \FileSystem\Ntfs \Ntfs 8A48F708
    Device \FileSystem\Fastfat \FatCdrom 89B3E970

    AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

    Device \Driver\Ftdisk \Device\HarddiskVolume1 8A4928C8
    Device \Driver\Ftdisk \Device\HarddiskVolume2 8A4928C8
    Device \Driver\Cdrom \Device\CdRom0 8A24F0E8
    Device \FileSystem\Rdbss \Device\FsWrap 89F8F1F8
    Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 8A333AEA
    Device \Driver\atapi \Device\Ide\IdePort0 [F7851B40] atapi.sys[unknown section] {MOV EAX, 0x8a447008; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7518e12; RET }
    Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 8A333AEA
    Device \Driver\atapi \Device\Ide\IdePort1 [F7851B40] atapi.sys[unknown section] {MOV EAX, 0x8a447008; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7518e12; RET }
    Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T0L0-e 8A333AEA
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F7851B40] atapi.sys[unknown section] {MOV EAX, 0x8a447008; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7518e12; RET }
    Device \Driver\Ftdisk \Device\HarddiskVolume3 8A4928C8

    AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

    Device \Driver\Disk \Device\Harddisk0\DR0 8A48F940
     
  9. specialk2ca

    specialk2ca TS Rookie Topic Starter

    AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89DFB2B0
    Device \FileSystem\MRxSmb \Device\LanmanRedirector 89DFB2B0
    Device \FileSystem\Npfs \Device\NamedPipe 89E3B0E8
    Device \Driver\Ftdisk \Device\FtControl 8A4928C8
    Device \FileSystem\Msfs \Device\Mailslot 89F70EB0
    Device \FileSystem\Fastfat \Fat 89B3E970

    AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
    AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
    Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
    Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
    Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
    Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
    Device \FileSystem\Cdfs \Cdfs 8A23E0E8
    Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
    Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskMaxtor_6Y080L0__________________________YAR41BW0#3259383234474332202020202020202020202020#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
    ---- Processes - GMER 1.0.15 ----

    Library C:\Program (*** hidden *** ) @ C:\WINDOWS\Explorer.EXE [1740] 0x10000000

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s0 1394729538
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 145048597
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 -1059318691
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x23 0x54 0x75 0xAD ...
    Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
    Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x23 0x54 0x75 0xAD ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x23 0x54 0x75 0xAD ...

    ---- Disk sectors - GMER 1.0.15 ----

    Disk \Device\Harddisk0\DR0 sectors 156249813 (+185): rootkit-like behavior;

    ---- Files - GMER 1.0.15 ----

    File C:\WINDOWS\system32\drivers\agp440.sys suspicious modification; TDL3 <-- ROOTKIT !!!

    ---- EOF - GMER 1.0.15 ----
     
  10. specialk2ca

    specialk2ca TS Rookie Topic Starter

    DDS (Ver_09-09-29.01) - NTFSx86
    Run by Ken Jennings at 22:10:47.50 on 21/10/2010
    Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_22
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1534.903 [GMT -5:00]

    AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    svchost.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\PROGRA~1\AVG\AVG9\avgtray.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\AVG\AVG9\avgemc.exe
    C:\Program Files\AVG\AVG9\avgam.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\Documents and Settings\Ken Jennings\Desktop\dds.com

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.ca/
    uDefault_Page_URL = hxxp://www.dell.com
    uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
    mStart Page = hxxp://www.dell.com
    uInternet Connection Wizard,ShellNext = iexplore
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - No File
    {8bb8ff12-eddb-416f-baff-d12fb3c38b0c}
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    {90d3af5f-7644-4d03-b715-3cee804598d1}
    BHO: {B56A7D7D-6927-48C8-A975-17DF180C71AC} - No File
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
    TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
    TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
    EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
    uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [PCMService] "c:\program files\dell\media experience\PCMService.exe"
    mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
    mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
    mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe
    mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
    mRun: [igfxpers] c:\windows\system32\igfxpers.exe
    mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
    mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper_3004.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
    StartupFolder: c:\docume~1\kenjen~1\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\interv~1.lnk - c:\program files\intervideo\common\bin\WinCinemaMgr.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
    IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
    IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partypoker\PartyPoker.exe
    IE: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
    IE: {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - {A1EDC4A1-940F-48E0-8DFD-E38F1D501021}
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
    Notify: avgrsstarter - avgrsstx.dll
    Notify: igfxcui - igfxdev.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: {9C28EAFB-FF50-4F42-8D39-A006129CC907} - No File
    SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
    LSA: Authentication Packages = msv1_0 c:\windows\system32\pmnKaxYo

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\kenjen~1\applic~1\mozilla\firefox\profiles\ca53cpon.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
    FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
    FF - plugin: c:\documents and settings\ken jennings\application data\mozilla\firefox\profiles\ca53cpon.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\nphssb.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

    ============= SERVICES / DRIVERS ===============

    R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2008-6-22 52872]
    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-22 216400]
    R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-6-22 29584]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-6-22 243024]
    R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-10-11 921952]
    R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-10-11 308136]
    S0 CFRMD;CFRMD;c:\windows\system32\drivers\cfrmd.sys --> c:\windows\system32\drivers\CFRMD.sys [?]
    S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2004-8-4 14336]

    =============== Created Last 30 ================

    2010-10-17 13:31 <DIR> --d----- c:\docume~1\kenjen~1\applic~1\ComodoGroup
    2010-10-17 13:23 <DIR> --d----- c:\documents and settings\ken jennings\Application DataComodoGroup
    2010-10-17 13:20 <DIR> --d----- c:\program files\COMODO
    2010-10-13 18:49 472,808 a------- c:\windows\system32\deployJava1.dll
    2010-10-11 10:04 12,536 a------- c:\windows\system32\avgrsstx.dll

    ==================== Find3M ====================

    2010-10-11 10:04 243,024 a------- c:\windows\system32\drivers\avgtdix.sys
    2010-10-11 10:04 216,400 a------- c:\windows\system32\drivers\avgldx86.sys
    2010-10-11 10:04 52,872 a------- c:\windows\system32\drivers\avgrkx86.sys
    2010-10-11 09:27 43,752 a------- c:\docume~1\kenjen~1\applic~1\wklnhst.dat
    2010-07-27 18:44 197,920 a------- c:\windows\system32\dnssdX.dll
    2010-07-27 18:44 107,808 a------- c:\windows\system32\dns-sd.exe
    2010-07-27 18:44 91,424 a------- c:\windows\system32\dnssd.dll
    2010-07-27 18:44 75,040 a------- c:\windows\system32\jdns_sd.dll
    2008-10-13 11:56 60,408 a------- c:\docume~1\kenjen~1\applic~1\GDIPFONTCACHEV1.DAT
    2007-04-09 19:54 8 a------- c:\docume~1\kenjen~1\applic~1\usb.dat.bin
    2005-07-29 16:24 472 a--shr-- c:\windows\s2vuieplbm5pbmdz\mZpRKHD5vAcDvAxW.vbs

    ============= FINISH: 22:11:28.89 ===============
     
  11. specialk2ca

    specialk2ca TS Rookie Topic Starter

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-09-29.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume2
    Install Date: 18/02/2005 4:57:58 PM
    System Uptime: 21/10/2010 9:15:28 PM (1 hours ago)

    Motherboard: Dell Computer Corp. | | 0K8979
    Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz | Microprocessor | 2793/533mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 71 GiB total, 22.876 GiB free.
    D: is CDROM (CDFS)

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP1997: 24/07/2010 2:57:42 AM - System Checkpoint
    RP1998: 25/07/2010 3:31:46 AM - System Checkpoint
    RP1999: 26/07/2010 4:19:28 AM - System Checkpoint
    RP2000: 27/07/2010 5:19:28 AM - System Checkpoint
    RP2001: 28/07/2010 6:19:28 AM - System Checkpoint
    RP2002: 29/07/2010 7:26:58 AM - System Checkpoint
    RP2003: 29/07/2010 6:13:34 PM - Installed iTunes
    RP2004: 30/07/2010 6:39:00 PM - System Checkpoint
    RP2005: 31/07/2010 6:40:04 PM - System Checkpoint
    RP2006: 01/08/2010 7:52:39 PM - System Checkpoint
    RP2007: 02/08/2010 8:39:00 PM - System Checkpoint
    RP2008: 03/08/2010 10:19:26 PM - System Checkpoint
    RP2009: 04/08/2010 10:26:35 PM - System Checkpoint
    RP2010: 05/08/2010 11:26:35 PM - System Checkpoint
    RP2011: 07/08/2010 12:07:34 AM - System Checkpoint
    RP2012: 08/08/2010 1:24:53 AM - System Checkpoint
    RP2013: 09/08/2010 2:07:34 AM - System Checkpoint
    RP2014: 10/08/2010 3:07:34 AM - System Checkpoint
    RP2015: 11/08/2010 4:07:33 AM - System Checkpoint
    RP2016: 12/08/2010 4:34:34 AM - System Checkpoint
    RP2017: 13/08/2010 4:38:25 AM - System Checkpoint
    RP2018: 14/08/2010 5:05:50 AM - System Checkpoint
    RP2019: 15/08/2010 6:05:49 AM - System Checkpoint
    RP2020: 16/08/2010 7:05:49 AM - System Checkpoint
    RP2021: 17/08/2010 8:08:16 AM - System Checkpoint
    RP2022: 18/08/2010 9:05:50 AM - System Checkpoint
    RP2023: 19/08/2010 1:34:07 PM - System Checkpoint
    RP2024: 20/08/2010 8:07:00 PM - System Checkpoint
    RP2025: 21/08/2010 8:21:12 PM - System Checkpoint
    RP2026: 22/08/2010 8:22:18 PM - System Checkpoint
    RP2027: 23/08/2010 8:37:29 PM - System Checkpoint
    RP2028: 24/08/2010 9:59:35 PM - System Checkpoint
    RP2029: 25/08/2010 10:19:33 PM - System Checkpoint
    RP2030: 26/08/2010 10:36:23 PM - System Checkpoint
    RP2031: 27/08/2010 11:12:53 PM - System Checkpoint
    RP2032: 29/08/2010 12:12:53 AM - System Checkpoint
    RP2033: 30/08/2010 1:12:53 AM - System Checkpoint
    RP2034: 31/08/2010 2:12:53 AM - System Checkpoint
    RP2035: 01/09/2010 3:12:53 AM - System Checkpoint
    RP2036: 01/09/2010 10:42:29 PM - Installed iTunes
    RP2037: 02/09/2010 11:06:28 PM - System Checkpoint
    RP2038: 03/09/2010 11:37:09 PM - System Checkpoint
    RP2039: 05/09/2010 12:37:10 AM - System Checkpoint
    RP2040: 05/09/2010 3:30:59 PM - Unsigned driver install
    RP2041: 06/09/2010 3:38:15 PM - System Checkpoint
    RP2042: 07/09/2010 4:37:09 PM - System Checkpoint
    RP2043: 08/09/2010 5:37:09 PM - System Checkpoint
    RP2044: 09/09/2010 7:05:39 PM - System Checkpoint
    RP2045: 10/09/2010 7:37:10 PM - System Checkpoint
    RP2046: 11/09/2010 8:22:50 PM - System Checkpoint
    RP2047: 12/09/2010 7:15:02 PM - Unsigned driver install
    RP2048: 13/09/2010 8:45:54 PM - System Checkpoint
    RP2049: 14/09/2010 9:21:45 PM - System Checkpoint
    RP2050: 15/09/2010 9:54:55 PM - System Checkpoint
    RP2051: 16/09/2010 10:24:20 PM - System Checkpoint
    RP2052: 17/09/2010 11:22:50 PM - System Checkpoint
    RP2053: 19/09/2010 9:10:27 AM - System Checkpoint
    RP2054: 20/09/2010 9:36:10 AM - System Checkpoint
    RP2055: 21/09/2010 10:36:10 AM - System Checkpoint
    RP2056: 22/09/2010 11:36:10 AM - System Checkpoint
    RP2057: 23/09/2010 12:36:10 PM - System Checkpoint
    RP2058: 24/09/2010 1:36:10 PM - System Checkpoint
    RP2059: 25/09/2010 1:50:00 PM - System Checkpoint
    RP2060: 26/09/2010 1:55:34 PM - System Checkpoint
    RP2061: 27/09/2010 2:36:11 PM - System Checkpoint
    RP2062: 28/09/2010 3:36:11 PM - System Checkpoint
    RP2063: 29/09/2010 6:22:56 PM - System Checkpoint
    RP2064: 30/09/2010 6:37:13 PM - System Checkpoint
    RP2065: 01/10/2010 7:03:52 PM - System Checkpoint
    RP2066: 02/10/2010 9:12:43 PM - System Checkpoint
    RP2067: 03/10/2010 10:03:52 PM - System Checkpoint
    RP2068: 04/10/2010 10:04:57 PM - System Checkpoint
    RP2069: 05/10/2010 10:39:21 PM - System Checkpoint
    RP2070: 06/10/2010 11:17:19 PM - System Checkpoint
    RP2071: 07/10/2010 11:41:48 PM - System Checkpoint
    RP2072: 09/10/2010 12:31:10 AM - System Checkpoint
    RP2073: 10/10/2010 12:44:30 AM - System Checkpoint
    RP2074: 11/10/2010 9:59:36 AM - Avg8 Update
    RP2075: 11/10/2010 10:04:56 AM - Avg Update
    RP2076: 12/10/2010 10:06:48 AM - System Checkpoint
    RP2077: 13/10/2010 6:13:10 PM - System Checkpoint
    RP2078: 13/10/2010 6:34:38 PM - Removed J2SE Runtime Environment 5.0 Update 10
    RP2079: 13/10/2010 6:35:35 PM - Removed J2SE Runtime Environment 5.0 Update 11
    RP2080: 13/10/2010 6:36:27 PM - Removed J2SE Runtime Environment 5.0 Update 4
    RP2081: 13/10/2010 6:37:20 PM - Removed J2SE Runtime Environment 5.0 Update 6
    RP2082: 13/10/2010 6:38:17 PM - Removed J2SE Runtime Environment 5.0 Update 8
    RP2083: 13/10/2010 6:39:09 PM - Removed J2SE Runtime Environment 5.0 Update 9
    RP2084: 13/10/2010 6:40:09 PM - Removed Java 2 Runtime Environment, SE v1.4.2_03
    RP2085: 13/10/2010 6:41:15 PM - Removed Java(TM) SE Runtime Environment 6 Update 1
    RP2086: 13/10/2010 6:47:29 PM - Removed Java(TM) 6 Update 11
    RP2087: 13/10/2010 6:48:10 PM - Installed Java(TM) 6 Update 22
    RP2088: 14/10/2010 8:09:16 PM - System Checkpoint
    RP2089: 15/10/2010 8:36:21 PM - System Checkpoint
    RP2090: 16/10/2010 9:06:07 PM - System Checkpoint
    RP2091: 17/10/2010 1:20:07 PM - [ErrorText_1715]
    RP2092: 18/10/2010 1:34:16 PM - System Checkpoint
    RP2093: 19/10/2010 1:36:31 PM - System Checkpoint
    RP2094: 20/10/2010 1:43:33 PM - System Checkpoint
    RP2095: 21/10/2010 2:22:01 PM - System Checkpoint
    RP2096: 21/10/2010 9:33:14 PM - Removed Adobe Reader 7.0
    RP2097: 21/10/2010 9:33:40 PM - Installed Adobe Reader 9.4.0.

    ==== Installed Programs ======================

    2007 Microsoft Office Suite Service Pack 1 (SP1)
    AC3Filter (remove only)
    Adobe AIR
    Adobe Download Manager
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Photoshop 7.0
    Adobe Reader 9.4.0
    AOL (Choose which version to remove)
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    ArcSoft Camera Suite 1.3
    AVG 9.0
    Azureus
    BitTorrent 3.4.2
    Blaze Media Pro
    Bonjour
    Camera Support Core Library
    Camera Window
    Canon Camera Support Core Library
    Canon Camera Window for ZoomBrowser EX
    Canon MovieEdit Task for ZoomBrowser EX
    Canon PhotoRecord
    Canon RAW Image Task for ZoomBrowser EX
    Canon RemoteCapture Task for ZoomBrowser EX
    Canon Utilities PhotoStitch 3.1
    Canon Utilities ZoomBrowser EX
    Choice Guard
    COMODO System - Cleaner
    CoreVorbis Audio Decoder (remove only)
    Creative DVD Audio Plugin for Audigy Series
    Cribbage
    Dell Driver Reset Tool
    Dell Media Experience
    Dell Picture Studio v3.0
    DellSupport
    Digital Line Detect
    FLAC Installer 1.1.2a (remove only)
    Full Tilt Poker
    Heroes of Might and Magic® IV
    Intel(R) Extreme Graphics 2 Driver
    Intel(R) PRO Network Adapters and Drivers
    Intel(R) PROSet for Wired Connections
    InterVideo WinDVD 6
    Invision 2.0 Build 3515
    iPod for Windows 2006-03-23
    iTunes
    Jasc Paint Shop Pro Studio, Dell Editon
    Java Auto Updater
    Java(TM) 6 Update 2
    Java(TM) 6 Update 22
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    JMPIN
    Kodak EasyShare software
    Lexmark Z600 Series
    LiveUpdate 2.6 (Symantec Corporation)
    Macromedia Dreamweaver 8
    Macromedia Extension Manager
    Macromedia Shockwave Player
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0 Service Pack 1
    Microsoft Application Error Reporting
    Microsoft Encarta Encyclopedia Standard 2004
    Microsoft Money 2004
    Microsoft Money 2004 System Pack
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Home and Student 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Picture It! Photo Premium 9
    Microsoft Plus! Digital Media Edition Installer
    Microsoft Plus! Photo Story 2 LE
    Microsoft Software Update for Web Folders (English) 12
    Microsoft Streets and Trips 2004
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Works
    Microsoft Works 2004 Setup Launcher
    Microsoft Works Suite Add-in for Microsoft Word
    mIRC
    mkw Audio Compression Toolkit
    mkw Runtime Libraries
    Modem Helper
    MovieEdit Task
    Mozilla Firefox (3.5.14)
    MSN Gaming Zone
    MSVCRT
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    Musicmatch for Windows Media Player
    Musicmatch® Jukebox
    Myst for Windows 95
    Nero 6 Ultra Edition
    netbrdg
    NetWaiting
    Network Play System (Patching)
    Noah's Ark Deluxe 1.1
    Notifier
    Paragon Poker Pal™ Professional Edition
    PCDADDIN
    PCDHELP
    PhotoStitch
    PokerStars
    QuickTime
    RAW Image Task 1.1
    RealPlayer
    RemoteCapture Task 1.0.3
    Replay 7.0
    Security Update for 2007 Microsoft Office System (KB951550)
    Security Update for 2007 Microsoft Office System (KB951944)
    Security Update for 2007 Microsoft Office System (KB958439)
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft Office Excel 2007 (KB958437)
    Security Update for Microsoft Office OneNote 2007 (KB950130)
    Security Update for Microsoft Office PowerPoint 2007 (KB951338)
    Security Update for Microsoft Office system 2007 (KB954326)
    Security Update for Microsoft Office system 2007 (KB956828)
    Security Update for Microsoft Office Word 2007 (KB956358)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960714)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB971633)
    Shockwave
    Sid Meier's Civilization 4
    SimCity 2000® Special Edition
    Sonic DLA
    Sonic RecordNow!
    Sonic Update Manager
    Sony ACID XPress 5.0a
    SoundMAX
    Spybot - Search & Destroy
    Staples Easy Button
    The Rise of Atlantis (remove only)
    tooltips
    Update for Office 2007 (KB946691)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    VPRINTOL
    WAV to MP3 Encoder
    WebFldrs XP
    WebMessenger WMP Client
    Windows Genuine Advantage Notifications (KB905474)
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Live Upload Tool
    Windows Media Format 11 runtime
    Windows Media Player 10
    Windows Media Player 11
    Windows XP Service Pack 3
    WinRAR archiver
    WIRELESS
    XviD MPEG-4 Video Codec
    Zuma Deluxe 1.0

    ==== Event Viewer Messages From Past Week ========

    21/10/2010 9:42:05 PM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
    21/10/2010 9:18:29 PM, error: Service Control Manager [7022] - The Automatic Updates service hung on starting.
    19/10/2010 7:12:36 AM, error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\D.
    17/10/2010 2:40:21 PM, error: ipnathlp [31008] - The DNS proxy agent was unable to read the local list of name-resolution servers from the registry. The data is the error code.
    17/10/2010 12:20:24 PM, error: ipnathlp [30013] - The DHCP allocator has disabled itself on IP address 192.168.100.100, since the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, please change the scope to include the IP address, or change the IP address to fall within the scope.
    17/10/2010 1:11:15 PM, error: Service Control Manager [7000] - The PC Tools Spyware Doctor service failed to start due to the following error: The system cannot find the file specified.
    17/10/2010 1:11:13 PM, error: NetBT [4311] - Initialization failed because the driver device could not be created.
    17/10/2010 1:11:13 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
    17/10/2010 1:11:13 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.
    16/10/2010 7:49:02 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
    15/10/2010 7:07:29 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the avg9wd service.

    ==== End Of File ===========================
     
  12. Broni

    Broni Malware Annihilator Posts: 52,892   +344

    Any particular reason, why you didn't follow our instructions to update MBAM before running it?
    Please, update it and post fresh log.

    Then....

    Download TDSSKiller and save it to your desktop.
    • Extract (unzip) its contents to your desktop.
    • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
     
  13. specialk2ca

    specialk2ca TS Rookie Topic Starter

    I actually tried to update MBAM but it didn't find anything when I ran it last time. I updated and reran:

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4920

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 6.0.2900.5512

    22/10/2010 6:00:54 PM
    mbam-log-2010-10-22 (18-00-54).txt

    Scan type: Quick scan
    Objects scanned: 146446
    Time elapsed: 16 minute(s), 47 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
     
  14. specialk2ca

    specialk2ca TS Rookie Topic Starter

    2010/10/22 17:33:57.0609 TDSS rootkit removing tool 2.4.4.0 Oct 4 2010 09:06:59
    2010/10/22 17:33:57.0609 ================================================================================
    2010/10/22 17:33:57.0609 SystemInfo:
    2010/10/22 17:33:57.0609
    2010/10/22 17:33:57.0609 OS Version: 5.1.2600 ServicePack: 3.0
    2010/10/22 17:33:57.0609 Product type: Workstation
    2010/10/22 17:33:57.0609 ComputerName: KEENAN
    2010/10/22 17:33:57.0609 UserName: Ken Jennings
    2010/10/22 17:33:57.0609 Windows directory: C:\WINDOWS
    2010/10/22 17:33:57.0609 System windows directory: C:\WINDOWS
    2010/10/22 17:33:57.0609 Processor architecture: Intel x86
    2010/10/22 17:33:57.0609 Number of processors: 1
    2010/10/22 17:33:57.0609 Page size: 0x1000
    2010/10/22 17:33:57.0609 Boot type: Normal boot
    2010/10/22 17:33:57.0609 ================================================================================
    2010/10/22 17:33:57.0890 Initialize success
    2010/10/22 17:34:00.0062 ================================================================================
    2010/10/22 17:34:00.0062 Scan started
    2010/10/22 17:34:00.0062 Mode: Manual;
    2010/10/22 17:34:00.0062 ================================================================================
    2010/10/22 17:34:02.0484 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
    2010/10/22 17:34:02.0656 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
    2010/10/22 17:34:02.0828 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
    2010/10/22 17:34:02.0906 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
    2010/10/22 17:34:03.0062 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
    2010/10/22 17:34:03.0171 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
    2010/10/22 17:34:03.0328 agp440 (a538a3e1ad1e6c443774610ec3d5aca1) C:\WINDOWS\system32\DRIVERS\agp440.sys
    2010/10/22 17:34:03.0328 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\agp440.sys. Real md5: a538a3e1ad1e6c443774610ec3d5aca1, Fake md5: 08fd04aa961bdc77fb983f328334e3d7
    2010/10/22 17:34:03.0343 agp440 - detected Rootkit.Win32.TDSS.tdl3 (0)
    2010/10/22 17:34:03.0500 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
    2010/10/22 17:34:03.0687 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
    2010/10/22 17:34:03.0890 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
    2010/10/22 17:34:04.0109 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
    2010/10/22 17:34:04.0312 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
    2010/10/22 17:34:04.0406 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
    2010/10/22 17:34:04.0531 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
    2010/10/22 17:34:04.0734 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
    2010/10/22 17:34:04.0906 APLMp50 (a9a22d7bad607cf7f698e32fb2983d2d) C:\WINDOWS\system32\Drivers\APLMp50.sys
    2010/10/22 17:34:05.0078 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
    2010/10/22 17:34:05.0250 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
    2010/10/22 17:34:05.0437 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
    2010/10/22 17:34:05.0562 ASPI32 (5b01af89d16d562825c4db4530f20cbb) C:\WINDOWS\system32\drivers\ASPI32.sys
    2010/10/22 17:34:05.0687 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
    2010/10/22 17:34:05.0875 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
    2010/10/22 17:34:06.0156 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
    2010/10/22 17:34:06.0328 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
    2010/10/22 17:34:06.0515 AvgLdx86 (b8c187439d27aba430dd69fdcf1fa657) C:\WINDOWS\System32\Drivers\avgldx86.sys
    2010/10/22 17:34:06.0656 AvgMfx86 (53b3f979930a786a614d29cafe99f645) C:\WINDOWS\System32\Drivers\avgmfx86.sys
    2010/10/22 17:34:06.0828 AvgRkx86 (5bbcd8646074a3af4ee9b321d12c2b64) C:\WINDOWS\system32\Drivers\avgrkx86.sys
    2010/10/22 17:34:06.0984 AvgTdiX (22e3b793c3e61720f03d3a22351af410) C:\WINDOWS\System32\Drivers\avgtdix.sys
    2010/10/22 17:34:07.0125 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
    2010/10/22 17:34:07.0390 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
    2010/10/22 17:34:07.0718 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
    2010/10/22 17:34:08.0156 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
    2010/10/22 17:34:08.0546 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
    2010/10/22 17:34:08.0984 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
    2010/10/22 17:34:09.0125 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
    2010/10/22 17:34:09.0406 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
    2010/10/22 17:34:09.0609 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
    2010/10/22 17:34:09.0812 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
    2010/10/22 17:34:10.0015 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
    2010/10/22 17:34:10.0156 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
    2010/10/22 17:34:10.0359 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
    2010/10/22 17:34:10.0531 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
    2010/10/22 17:34:10.0687 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
    2010/10/22 17:34:10.0796 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
    2010/10/22 17:34:10.0937 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
    2010/10/22 17:34:11.0109 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
    2010/10/22 17:34:11.0281 drvmcdb (b15f9e526ba511a48b1b1b8537815740) C:\WINDOWS\system32\drivers\drvmcdb.sys
    2010/10/22 17:34:11.0484 drvnddm (fa4670cae95ae2bb857c68e535661145) C:\WINDOWS\system32\drivers\drvnddm.sys
    2010/10/22 17:34:11.0671 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
    2010/10/22 17:34:11.0828 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
    2010/10/22 17:34:12.0000 dtscsi (6461e57bb51a848aae26f52427b7cf9e) C:\WINDOWS\System32\Drivers\dtscsi.sys
    2010/10/22 17:34:12.0218 E100B (7d91dc6342248369f94d6eba0cf42e99) C:\WINDOWS\system32\DRIVERS\e100b325.sys
    2010/10/22 17:34:12.0562 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
    2010/10/22 17:34:12.0765 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
    2010/10/22 17:34:13.0140 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
    2010/10/22 17:34:13.0593 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
    2010/10/22 17:34:13.0781 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
    2010/10/22 17:34:13.0937 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
    2010/10/22 17:34:14.0078 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
    2010/10/22 17:34:14.0250 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
    2010/10/22 17:34:14.0421 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
    2010/10/22 17:34:14.0593 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
    2010/10/22 17:34:14.0796 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
    2010/10/22 17:34:15.0000 HSFHWBS2 (77e4ff0b73bc0aeaaf39bf0c8104231f) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys
    2010/10/22 17:34:15.0171 HSF_DP (60e1604729a15ef4a3b05f298427b3b1) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
    2010/10/22 17:34:15.0359 HTTP (f6aacf5bce2893e0c1754afeb672e5c9) C:\WINDOWS\system32\Drivers\HTTP.sys
    2010/10/22 17:34:15.0718 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
    2010/10/22 17:34:15.0921 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
    2010/10/22 17:34:16.0109 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
    2010/10/22 17:34:16.0359 ialm (9a883c3c4d91292c0d09de7c728e781c) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
    2010/10/22 17:34:16.0593 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
    2010/10/22 17:34:16.0781 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
    2010/10/22 17:34:17.0015 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
    2010/10/22 17:34:17.0171 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
    2010/10/22 17:34:17.0421 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
    2010/10/22 17:34:17.0609 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
    2010/10/22 17:34:17.0843 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
    2010/10/22 17:34:18.0093 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
    2010/10/22 17:34:18.0312 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
    2010/10/22 17:34:18.0562 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
    2010/10/22 17:34:18.0765 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
    2010/10/22 17:34:18.0984 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
    2010/10/22 17:34:19.0171 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
    2010/10/22 17:34:19.0812 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
    2010/10/22 17:34:20.0343 KSecDD (1705745d900dabf2d89f90ebaddc7517) C:\WINDOWS\system32\drivers\KSecDD.sys
    2010/10/22 17:34:20.0734 mdmxsdk (eeaea6514ba7c9d273b5e87c4e1aab30) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
    2010/10/22 17:34:20.0875 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
    2010/10/22 17:34:20.0984 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
    2010/10/22 17:34:21.0140 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
    2010/10/22 17:34:21.0250 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
    2010/10/22 17:34:21.0437 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
    2010/10/22 17:34:21.0625 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
    2010/10/22 17:34:21.0812 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
    2010/10/22 17:34:22.0031 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
    2010/10/22 17:34:22.0218 MRxSmb (60ae98742484e7ab80c3c1450e708148) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
    2010/10/22 17:34:22.0406 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
    2010/10/22 17:34:22.0578 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
    2010/10/22 17:34:22.0734 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
    2010/10/22 17:34:22.0890 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
    2010/10/22 17:34:23.0031 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
    2010/10/22 17:34:23.0218 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
    2010/10/22 17:34:23.0375 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
    2010/10/22 17:34:23.0531 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
    2010/10/22 17:34:23.0890 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
    2010/10/22 17:34:23.0984 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
    2010/10/22 17:34:24.0046 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
    2010/10/22 17:34:24.0093 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
    2010/10/22 17:34:24.0140 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
    2010/10/22 17:34:24.0234 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
    2010/10/22 17:34:24.0296 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
    2010/10/22 17:34:24.0937 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
    2010/10/22 17:34:25.0312 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
    2010/10/22 17:34:25.0515 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
    2010/10/22 17:34:25.0687 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
    2010/10/22 17:34:25.0796 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
    2010/10/22 17:34:25.0921 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
    2010/10/22 17:34:26.0078 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
    2010/10/22 17:34:26.0265 Pcatip (6d3c5deef9a7ec5cd2a40e0113192d27) C:\WINDOWS\system32\DRIVERS\Pcatip.sys
    2010/10/22 17:34:26.0421 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
    2010/10/22 17:34:26.0640 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
    2010/10/22 17:34:26.0781 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
    2010/10/22 17:34:26.0921 Pcouffin (5b68c60b01dac03d895ec1ca0a0365da) C:\WINDOWS\system32\Drivers\Pcouffin.sys
    2010/10/22 17:34:27.0390 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
    2010/10/22 17:34:27.0484 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
    2010/10/22 17:34:27.0562 pfc (ed2e7f396b4098608c95bc3806bdf6fc) C:\WINDOWS\system32\drivers\pfc.sys
    2010/10/22 17:34:27.0703 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
    2010/10/22 17:34:27.0859 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
    2010/10/22 17:34:28.0031 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
    2010/10/22 17:34:28.0234 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
    2010/10/22 17:34:28.0375 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
    2010/10/22 17:34:28.0531 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
    2010/10/22 17:34:28.0687 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
    2010/10/22 17:34:28.0843 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
    2010/10/22 17:34:29.0000 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
    2010/10/22 17:34:29.0156 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
    2010/10/22 17:34:29.0328 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
    2010/10/22 17:34:29.0500 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
    2010/10/22 17:34:29.0671 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
    2010/10/22 17:34:29.0890 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
    2010/10/22 17:34:30.0140 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
    2010/10/22 17:34:30.0359 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
    2010/10/22 17:34:30.0562 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
    2010/10/22 17:34:30.0765 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
    2010/10/22 17:34:31.0468 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
    2010/10/22 17:34:31.0687 senfilt (b9c7617c1e8ab6fdff75d3c8dafcb4c8) C:\WINDOWS\system32\drivers\senfilt.sys
    2010/10/22 17:34:31.0875 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
    2010/10/22 17:34:32.0031 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
    2010/10/22 17:34:32.0218 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
    2010/10/22 17:34:32.0484 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
    2010/10/22 17:34:32.0890 smwdm (c6d9959e493682f872a639b6ec1b4a08) C:\WINDOWS\system32\drivers\smwdm.sys
    2010/10/22 17:34:33.0109 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
    2010/10/22 17:34:33.0359 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
    2010/10/22 17:34:33.0531 sptd (de294e505d4f2e2f123efea5aceda43b) C:\WINDOWS\system32\Drivers\sptd.sys
    2010/10/22 17:34:33.0531 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: de294e505d4f2e2f123efea5aceda43b
    2010/10/22 17:34:33.0546 sptd - detected Locked file (1)
    2010/10/22 17:34:34.0359 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
    2010/10/22 17:34:34.0703 Srv (3bb03f2ba89d2be417206c373d2af17c) C:\WINDOWS\system32\DRIVERS\srv.sys
    2010/10/22 17:34:35.0078 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys
    2010/10/22 17:34:35.0250 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys
    2010/10/22 17:34:35.0437 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
    2010/10/22 17:34:35.0609 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
    2010/10/22 17:34:35.0781 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
    2010/10/22 17:34:35.0890 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
    2010/10/22 17:34:35.0937 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
    2010/10/22 17:34:36.0000 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
    2010/10/22 17:34:36.0093 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
    2010/10/22 17:34:36.0250 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
    2010/10/22 17:34:36.0500 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
    2010/10/22 17:34:36.0687 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
    2010/10/22 17:34:36.0859 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
    2010/10/22 17:34:37.0000 tfsnboio (1d265cd2fb1673a0873bf8cec19ddc7f) C:\WINDOWS\system32\dla\tfsnboio.sys
    2010/10/22 17:34:37.0156 tfsncofs (62e4901295e0467cac78e5b4b131ae5c) C:\WINDOWS\system32\dla\tfsncofs.sys
    2010/10/22 17:34:37.0296 tfsndrct (a2f380f9252ab3464c859adf91eead9c) C:\WINDOWS\system32\dla\tfsndrct.sys
    2010/10/22 17:34:37.0375 tfsndres (eee79bbefe9c6a2a3ce6c8753cfea950) C:\WINDOWS\system32\dla\tfsndres.sys
    2010/10/22 17:34:37.0453 tfsnifs (9d644eb11fec9487450c4cfcd63a5df4) C:\WINDOWS\system32\dla\tfsnifs.sys
    2010/10/22 17:34:37.0609 tfsnopio (e656af05c67edb7c0e9230a5df71ed1b) C:\WINDOWS\system32\dla\tfsnopio.sys
    2010/10/22 17:34:37.0750 tfsnpool (64fccb9cce703ca507dffc3cebf6b2cb) C:\WINDOWS\system32\dla\tfsnpool.sys
    2010/10/22 17:34:37.0890 tfsnudf (48bc9d8ab4e4b9bff70fb18e55cec3d6) C:\WINDOWS\system32\dla\tfsnudf.sys
    2010/10/22 17:34:38.0281 tfsnudfa (79f60822224256b49bfc855da8d651d5) C:\WINDOWS\system32\dla\tfsnudfa.sys
    2010/10/22 17:34:38.0484 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
    2010/10/22 17:34:38.0718 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
    2010/10/22 17:34:39.0125 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
    2010/10/22 17:34:39.0562 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
    2010/10/22 17:34:40.0062 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
    2010/10/22 17:34:40.0515 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
    2010/10/22 17:34:40.0937 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
    2010/10/22 17:34:41.0375 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
    2010/10/22 17:34:41.0843 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
    2010/10/22 17:34:42.0281 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
    2010/10/22 17:34:42.0734 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
    2010/10/22 17:34:43.0250 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
    2010/10/22 17:34:43.0875 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
    2010/10/22 17:34:44.0468 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
    2010/10/22 17:34:45.0109 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
    2010/10/22 17:34:46.0578 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
    2010/10/22 17:34:47.0828 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
    2010/10/22 17:34:48.0484 winachsf (f59ed5a43b988a18ef582bb07b2327a7) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
    2010/10/22 17:34:49.0328 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
    2010/10/22 17:34:50.0031 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
    2010/10/22 17:34:50.0312 ================================================================================
    2010/10/22 17:34:50.0312 Scan finished
    2010/10/22 17:34:50.0312 ================================================================================
    2010/10/22 17:34:50.0328 Detected object count: 2
    2010/10/22 17:36:13.0062 agp440 (a538a3e1ad1e6c443774610ec3d5aca1) C:\WINDOWS\system32\DRIVERS\agp440.sys
    2010/10/22 17:36:13.0062 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\agp440.sys. Real md5: a538a3e1ad1e6c443774610ec3d5aca1, Fake md5: 08fd04aa961bdc77fb983f328334e3d7
    2010/10/22 17:36:15.0890 Backup copy not found, trying to cure infected file..
    2010/10/22 17:36:15.0890 Cure success, using it..
    2010/10/22 17:36:15.0921 C:\WINDOWS\system32\DRIVERS\agp440.sys - will be cured after reboot
    2010/10/22 17:36:15.0921 Rootkit.Win32.TDSS.tdl3(agp440) - User select action: Cure
    2010/10/22 17:36:15.0937 Locked file(sptd) - User select action: Skip
    2010/10/22 17:36:19.0312 Deinitialize success
     
  15. Broni

    Broni Malware Annihilator Posts: 52,892   +344

    Good :)
    That took care of a rootkit.

    Download MBRCheck to your desktop

    Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
    It will show a black screen with some data on it.
    Enter N to exit.
    A report called MBRcheckxxxx.txt will be on your desktop
    Open this report and post its content in your next reply.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...