Thanks!
Here's ESET
C:\AppsNoInstall\xmplay34\Skins\EyePhone.xmpskin probably a variant of Win32/Agent trojan cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\Documents and Settings\B4BD\Application Data\AD ON Multimedia\eBay Shortcuts\eBayShortcuts.exe.vir a variant of Win32/Adware.ADON application cleaned by deleting - quarantined
C:\WINDOWS\system32\ActiveScan\pskavs.dll probably a variant of Win32/Agent trojan cleaned by deleting - quarantined
Here's SysProt (just the hidden items)
SysProt AntiRootkit v1.0.1.0
by swatkat
********************************************************************************
**********
********************************************************************************
**********
No Hidden Processes found
********************************************************************************
**********
********************************************************************************
**********
Kernel Modules:
Module Name: spfw.sys
Service Name: ---
Module Base: B9EA7000
Module End: B9FA7000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\aenbh6wo.SYS
Service Name: ---
Module Base: B80AA000
Module End: B80E1000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: AB22B000
Module End: AB243000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: ---
Module Base: BA5DC000
Module End: BA5DE000
Hidden: Yes
********************************************************************************
**********
********************************************************************************
**********
SSDT:
Function Name: ZwAssignProcessToJobObject
Address: AB4DDC50
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwClose
Address: AB4C2C70
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwConnectPort
Address: AB4E1370
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwCreateFile
Address: AB4BEFE0
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwCreateKey
Address: AB4CA280
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwCreateProcess
Address: AB4D64A0
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwCreateProcessEx
Address: AB4D6DA0
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwCreateSection
Address: AB4BDD90
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwCreateSymbolicLinkObject
Address: AB4CA030
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwCreateThread
Address: AB4D4F60
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwDebugActiveProcess
Address: AB4E4E00
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwDeleteFile
Address: AB4C8D10
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwDeleteKey
Address: AB4CBAF0
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwDeleteValueKey
Address: AB4D2590
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwEnumerateKey
Address: B9EC6CA2
Driver Base: B9EA7000
Driver End: B9FA7000
Driver Name: spfw.sys
Function Name: ZwEnumerateValueKey
Address: B9EC7030
Driver Base: B9EA7000
Driver End: B9FA7000
Driver Name: spfw.sys
Function Name: ZwLoadDriver
Address: AB4D3DA0
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwMakeTemporaryObject
Address: AB4C98A0
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwOpenFile
Address: AB4C1C90
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwOpenKey
Address: AB4CB1B0
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwOpenProcess
Address: AB4D8E90
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwOpenSection
Address: AB4BE600
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwOpenThread
Address: AB4D8250
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwProtectVirtualMemory
Address: AB4DEF90
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwQueryDirectoryFile
Address: AB4C3A90
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwQueryKey
Address: AB4CD940
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwQueryValueKey
Address: AB4CE190
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwQueueApcThread
Address: AB4DD0C0
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwRenameKey
Address: AB4D1780
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwReplaceKey
Address: AB4CF6F0
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwRequestPort
Address: AB4E3610
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwRequestWaitReplyPort
Address: AB4E3930
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwRestoreKey
Address: AB4D0F10
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwSaveKey
Address: AB4CFE70
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwSaveKeyEx
Address: AB4D06C0
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwSecureConnectPort
Address: AB4E1F50
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwSetContextThread
Address: AB4DC630
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwSetInformationDebugObject
Address: AB4E53F0
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwSetInformationFile
Address: AB4C4DE0
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwSetSystemInformation
Address: AB4D33B0
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwSetValueKey
Address: AB4CEA10
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwSuspendProcess
Address: AB4DB380
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwSuspendThread
Address: AB4DBCB0
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwSystemDebugControl
Address: AB4E4640
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwTerminateProcess
Address: AB4D9980
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwTerminateThread
Address: AB4DA810
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwUnloadDriver
Address: AB4D4720
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
Function Name: ZwWriteVirtualMemory
Address: AB4DE4A0
Driver Base: AB4BD000
Driver End: AB56A000
Driver Name: \SystemRoot\system32\DRIVERS\SandBox.sys
********************************************************************************
**********
********************************************************************************
**********
No Kernel Hooks found
********************************************************************************
**********
********************************************************************************
**********
IRP Hooks:
Hooked Module: C:\WINDOWS\system32\drivers\atapi.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 8B0841F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\atapi.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 8B0841F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\atapi.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 8B0841F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\atapi.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 8B0841F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\atapi.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 8B0841F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\atapi.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 8B0841F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_CREATE
Jump To: 8A3F4500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_CLOSE
Jump To: 8A3F4500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_READ
Jump To: 8A3F4500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_WRITE
Jump To: 8A3F4500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 8A3F4500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 8A3F4500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_POWER
Jump To: 8A3F4500
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 8A3F4500
Hooking Module: _unknown_
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CREATE
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CREATE_NAMED_PIPE
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CLOSE
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_READ
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_WRITE
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_INFORMATION
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_INFORMATION
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_EA
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_EA
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_VOLUME_INFORMATION
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_VOLUME_INFORMATION
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_DIRECTORY_CONTROL
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_FILE_SYSTEM_CONTROL
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_LOCK_CONTROL
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CLEANUP
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_CREATE_MAILSLOT
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_SECURITY
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_SECURITY
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_POWER
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_DEVICE_CHANGE
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_QUERY_QUOTA
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: \Driver\sptd
Hooked IRP: IRP_MJ_SET_QUOTA
Jump To: B9EA8000
Hooking Module: spfw.sys
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 8B0F51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 8B0F51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_READ
Jump To: 8B0F51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_WRITE
Jump To: 8B0F51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: 8B0F51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 8B0F51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 8B0F51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: 8B0F51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 8B0F51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\dmio.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 8B0F51F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 8AE1E1F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 8AE1E1F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 8AE1E1F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 8AE1E1F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 8AE1E1F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 8AE1E1F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 8B0851F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_READ
Jump To: 8B0851F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_WRITE
Jump To: 8B0851F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: 8B0851F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 8B0851F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 8B0851F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: 8B0851F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_CLEANUP
Jump To: 8B0851F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 8B0851F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\ftdisk.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 8B0851F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 8ABE4258
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 8ABE4258
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 8ABE4258
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 8ABE4258
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\netbt.sys
Hooked IRP: IRP_MJ_CLEANUP
Jump To: 8ABE4258
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 8AD711F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 8AD711F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_READ
Jump To: 8AD711F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_WRITE
Jump To: 8AD711F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: 8AD711F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 8AD711F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 8AD711F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: 8AD711F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 8AD711F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 8AD711F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: B807A740
Hooking Module: C:\WINDOWS\system32\drivers\afwcore.sys
Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: B807AC64
Hooking Module: C:\WINDOWS\system32\drivers\afwcore.sys
Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: B807AAA6
Hooking Module: C:\WINDOWS\system32\drivers\afwcore.sys
Hooked Module: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_CLEANUP
Jump To: B807A84C
Hooking Module: C:\WINDOWS\system32\drivers\afwcore.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_CREATE
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_CREATE_NAMED_PIPE
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_CLOSE
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_READ
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_WRITE
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_QUERY_INFORMATION
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_SET_INFORMATION
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_QUERY_EA
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_SET_EA
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_FLUSH_BUFFERS
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_QUERY_VOLUME_INFORMATION
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_SET_VOLUME_INFORMATION
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_DIRECTORY_CONTROL
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_FILE_SYSTEM_CONTROL
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_SHUTDOWN
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_LOCK_CONTROL
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_CLEANUP
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_CREATE_MAILSLOT
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_QUERY_SECURITY
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_SET_SECURITY
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_POWER
Jump To: B9EAFE1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: B9EC4514
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_DEVICE_CHANGE
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_QUERY_QUOTA
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: \Driver\PCI_PNP0670
Hooked IRP: IRP_MJ_SET_QUOTA
Jump To: B9EEBB1C
Hooking Module: spfw.sys
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 8AD841F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 8AD841F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 8AD841F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 8AD841F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 8AD841F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 8AD841F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\sbp2port.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: 8B0F31F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\sbp2port.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: 8B0F31F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\sbp2port.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 8B0F31F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\sbp2port.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 8B0F31F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\sbp2port.sys
Hooked IRP: IRP_MJ_POWER
Jump To: 8B0F31F8
Hooking Module: _unknown_
Hooked Module: C:\WINDOWS\system32\drivers\sbp2port.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 8B0F31F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\aenbh6wo.SYS
Hooked IRP: IRP_MJ_CREATE
Jump To: 8AD661F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\aenbh6wo.SYS
Hooked IRP: IRP_MJ_CLOSE
Jump To: 8AD661F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\aenbh6wo.SYS
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: 8AD661F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\aenbh6wo.SYS
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: 8AD661F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\aenbh6wo.SYS
Hooked IRP: IRP_MJ_POWER
Jump To: 8AD661F8
Hooking Module: _unknown_
Hooked Module: \SystemRoot\System32\Drivers\aenbh6wo.SYS
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: 8AD661F8
Hooking Module: _unknown_
********************************************************************************
**********
********************************************************************************
**********
Ports:
Local Address: BNMC01:1028
Remote Address: BNMV01:MICROSOFT-DS
Type: TCP
Process: System
State: ESTABLISHED
Local Address: BNMC01:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: BNMC01:5152
Remote Address: LOCALHOST:1044
Type: TCP
Process: C:\Program Files\Java\jre6\bin\jqs.exe
State: CLOSE_WAIT
Local Address: BNMC01:5152
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Java\jre6\bin\jqs.exe
State: LISTENING
Local Address: BNMC01:1025
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\alg.exe
State: LISTENING
Local Address: BNMC01:3390
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: BNMC01:3389
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: BNMC01:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: BNMC01:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: BNMC01:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: BNMC01:138
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: BNMC01:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: BNMC01:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: BNMC01:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: BNMC01:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: BNMC01:4500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: BNMC01:500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: BNMC01:MICROSOFT-DS
Remote Address: NA
Type: UDP
Process: System
State: NA
********************************************************************************
**********
********************************************************************************
**********
No hidden files/folders found
Here's GMer (I had to run it in Safemode to get it to complete)
GMER 1.0.15.15220 -
http://www.gmer.netRootkit scan 2009-11-11 16:13:34
Windows 5.1.2600 Service Pack 2
Running: ftw126s4.exe; Driver: C:\Temp\TempSys\ffldqpob.sys
---- System - GMER 1.0.15 ----
SSDT spgt.sys ZwCreateKey [0xF74D70E0]
SSDT spgt.sys ZwEnumerateKey [0xF74F5CA2]
SSDT spgt.sys ZwEnumerateValueKey [0xF74F6030]
SSDT spgt.sys ZwOpenKey [0xF74D70C0]
SSDT spgt.sys ZwQueryKey [0xF74F6108]
SSDT spgt.sys ZwQueryValueKey [0xF74F5F88]
SSDT spgt.sys ZwSetValueKey [0xF74F619A]
INT 0x62 ? 8AEFFBF8
INT 0x63 ? 8AD98BF8
INT 0x83 ? 8AD98BF8
INT 0x94 ? 8AD98BF8
INT 0xB4 ? 8AEFFBF8
INT 0xB4 ? 8AEFFBF8
INT 0xB4 ? 8AD98BF8
INT 0xB4 ? 8AEFFBF8
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8AEFE1F8
Device \Driver\USBSTOR \Device\0000008e 8AD321F8
Device \Driver\sptd \Device\3114432250 spgt.sys
Device \Driver\usbuhci \Device\USBPDO-0 8ACC01F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8AF721F8
Device \Driver\dmio \Device\DmControl\DmConfig 8AF721F8
Device \Driver\dmio \Device\DmControl\DmPnP 8AF721F8
Device \Driver\dmio \Device\DmControl\DmInfo 8AF721F8
Device \Driver\usbuhci \Device\USBPDO-1 8ACC01F8
Device \Driver\usbehci \Device\USBPDO-2 8ADA71F8
Device \Driver\usbuhci \Device\USBPDO-3 8ACC01F8
Device \Driver\usbuhci \Device\USBPDO-4 8ACC01F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 8AF001F8
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
Device \Driver\USBSTOR \Device\000000a3 8AD321F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8AF001F8
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
Device \Driver\Cdrom \Device\CdRom0 8AD5D1F8
Device \Driver\USBSTOR \Device\000000a4 8AD321F8
Device \Driver\Ftdisk \Device\HarddiskVolume3 8AF001F8
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 8AEFF1F8
Device \Driver\atapi \Device\Ide\IdePort0 8AEFF1F8
Device \Driver\atapi \Device\Ide\IdePort1 8AEFF1F8
Device \Driver\atapi \Device\Ide\IdePort2 8AEFF1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-19 8AEFF1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e 8AEFF1F8
Device \Driver\Ftdisk \Device\HarddiskVolume4 8AF001F8
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
Device \Driver\Ftdisk \Device\HarddiskVolume5 8AF001F8
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume5 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
Device \Driver\PCI_PNP9750 \Device\0000005e spgt.sys
Device \Driver\PCI_PNP9750 \Device\0000005e spgt.sys
Device \Driver\usbuhci \Device\USBFDO-0 8ACC01F8
Device \Driver\usbuhci \Device\USBFDO-1 8ACC01F8
Device \Driver\usbuhci \Device\USBFDO-2 8ACC01F8
Device \Driver\usbuhci \Device\USBFDO-3 8ACC01F8
Device \Driver\usbehci \Device\USBFDO-4 8ADA71F8
Device \Driver\Ftdisk \Device\FtControl 8AF001F8
Device \Driver\USBSTOR \Device\0000008a 8AD321F8
Device \Driver\USBSTOR \Device\0000008b 8AD321F8
Device \Driver\USBSTOR \Device\0000008c 8AD321F8
Device \Driver\USBSTOR \Device\0000008d 8AD321F8
Device \Driver\asfn81dq \Device\Scsi\asfn81dq1 8ACC1500
Device \FileSystem\Fastfat \Fat 8AB4F500
Device \FileSystem\Fastfat \Fat B9C061F9
Device \FileSystem\Cdfs \Cdfs 8ABBE1F8
Device \Driver\atapi -> \Driver\atapi \Device\Harddisk0\DR0 8AEFF1F8
---- EOF - GMER 1.0.15 ----
[quote name=\'guestolo\' post=\'466244\' date=\'Nov 11 2009, 05:20 PM\']Go ahead and post the most recent logs you have[/quote]