This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Searches Redirected

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A couple of weeks ago, my google in both IE and Firefox searches were jumping to other sites. I downloaded Spybot, SuperSpyware, and Malwarebytes. Through that combination, I was able to get rid of whatever was causing the problem.

Yesterday, my Google searches in Firefox started redirected to advertisement sites or "help us find this fraud by clicking this" type of sites. Sometimes the first click after a new search takes me to the right page. So far, searches in IE are still working just fine. *EDIT: IE is no longer working either! *I ran all three programs again and it still redirects. I also used SD Fix, but it didn't find any trojans. So I just used HijackThis and here are my logs for Hijack and Starup (I can post my SDFix log if needed):

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:12:49 PM, on 7/14/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\PHAROS~1\Core\CTskMstr.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
c:\Toshiba\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\TDispVol.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bungie.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://site.ebrary.com/lib/uncch/support/p…s/ebraryRdr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1221255116468
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = kenan-flagler.unc.edu,business.unc.edu,unc.edu
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = kenan-flagler.unc.edu,business.unc.edu,unc.edu
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pharos Systems ComTaskMaster - Pharos Systems International - C:\PROGRA~1\PHAROS~1\Core\CTskMstr.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 8568 bytes










StartupList report, 7/14/2009, 12:25:00 PM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\PHAROS~1\Core\CTskMstr.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
c:\Toshiba\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\TDispVol.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe

————————————————–

Listing of startup folders:

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

SunJavaUpdateSched = "C:\Program Files\Java\jre6\bin\jusched.exe"
Pinger = c:\toshiba\ivp\ism\pinger.exe /run
TDispVol = TDispVol.exe
TCtryIOHook = TCtrlIOHook.exe
SmoothView = C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
TPSMain = TPSMain.exe
CeEKEY = C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
SVPWUTIL = C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
HWSetup = C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
Apoint = C:\Program Files\Apoint2K\Apoint.exe
IntelWireless = "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
IntelZeroConfig = "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
igfxpers = C:\WINDOWS\system32\igfxpers.exe
igfxtray = C:\WINDOWS\system32\igfxtray.exe
TFncKy = TFncKy.exe
USB2Check = RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
GrooveMonitor = "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

Malwarebytes' Anti-Malware = C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\scrnsave.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\WINDOWS\System32\DLA\DLASHX_W.DLL - {5CA3D70E-1895-11CF-8E15-001234567890}
(no name) - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL - {72853161-30C5-4D22-B7F9-0BBC1D38A37E}
(no name) - C:\Program Files\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9}
JQSIEStartDetectorImpl - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll - {E7E6F031-17CE-4C07-BC86-EABFE594F69C}

————————————————–

Enumerating Task Scheduler jobs:

Registration reminder 2.job

————————————————–

Enumerating Download Program Files:

[Infotl Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\EBRARY~1.OCX
CODEBASE = http://site.ebrary.com/lib/uncch/support/p…s/ebraryRdr.cab

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\legitcheckcontrol.dll
CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204

[{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}]
CODEBASE = http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab

[MUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\muweb.dll
CODEBASE = http://update.microsoft.com/microsoftupdat…b?1221255116468

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx
CODEBASE = http://active.macromedia.com/flash5/cabs/swflash.cab

————————————————–

Enumerating Winsock LSP files:

NameSpace #4: C:\Program Files\Bonjour\mdnsNSP.dll

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll

————————————————–
End of report, 7,539 bytes
Report generated in 0.921 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only



Any help is greaty appreciated! Thank you

EDIT: IE is experiencing the same problem now and is being redirected.
Hi,

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Right-click gmer.exe and select Run As Administrator. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
Hey jpshortstuff, thanks for getting back to me. I ran into a couple of problems (I think) while running these programs. The first is that the DDS command box said "not enough main memory to complete" twice, but then did it anyway. The second is I don't know what my Admin password is, so I ran GMER with just my account. But here are the results.

cd
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 9:14:19.39 on Wed 07/15/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1389 [GMT -4:00]

AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\PHAROS~1\Core\CTskMstr.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\Toshiba\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\TDispVol.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\Alex\Desktop\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.bungie.net/
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
mDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
mRun: [TDispVol] TDispVol.exe
mRun: [TCtryIOHook] TCtrlIOHook.exe
mRun: [SmoothView] c:\program files\toshiba\toshiba zooming utility\SmoothView.exe
mRun: [TPSMain] TPSMain.exe
mRun: [CeEKEY] c:\program files\toshiba\e-key\CeEKey.exe
mRun: [SVPWUTIL] c:\program files\toshiba\windows utilities\SVPWUTIL.exe SVPwUTIL
mRun: [HWSetup] c:\program files\toshiba\toshiba applet\HWSetup.exe hwSetUP
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [TFncKy] TFncKy.exe
mRun: [USB2Check] RUNDLL32.EXE "c:\windows\system32\PCLECoInst.dll",CheckUSBController
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ramasst.lnk - c:\windows\system32\RAMASST.exe
uPolicies-system: EnableProfileQuota = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: plaxo.com\www
DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} - hxxp://site.ebrary.com/lib/uncch/support/plugins/ebraryRdr.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1221255116468
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://active.macromedia.com/flash5/cabs/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath -
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-6-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-6-23 72944]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R2 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2007-6-6 116928]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-5-25 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20080609.003\naveng.sys [2008-6-9 82256]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20080609.003\navex15.sys [2008-6-9 895408]
S0 tclondrv;tclondrv;c:\windows\system32\drivers\tclondrv.sys –> c:\windows\system32\drivers\tclondrv.sys [?]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-6-23 7408]
S3 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2007-6-6 1821376]
S4 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2007-5-29 192104]
S4 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2007-5-29 169576]

=============== Created Last 30 ================

2009-07-14 12:12 –d—– c:\program files\Trend Micro
2009-07-09 10:33 –d—– c:\program files\Kenan-Flagler
2009-07-01 13:54 –d—– c:\program files\SUPERAntiSpyware
2009-07-01 13:54 –d—– c:\docume~1\alex\applic~1\SUPERAntiSpyware.com
2009-07-01 11:00 –d—– c:\program files\common files\Wise Installation Wizard
2009-07-01 10:57 –d—– c:\docume~1\alex\applic~1\Malwarebytes
2009-07-01 10:57 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-01 10:57 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-07-01 09:24 –d—– c:\program files\sys
2009-06-21 23:31 –d—– c:\program files\FreeByte
2009-06-20 18:00 –d—– c:\program files\Smilebox

==================== Find3M ====================

2006-05-03 05:06 163,328 a–shr– c:\windows\system32\flvDX.dll
2007-02-21 06:47 31,232 —shr– c:\windows\system32\msfDX.dll
2007-12-17 08:43 27,648 —sh— c:\windows\system32\Smab0.dll

============= FINISH: 9:15:52.06 ===============












GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-15 09:44:55
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.15 —-

Code 89AFC2B0 ZwEnumerateKey
Code 88AD7C30 ZwFlushInstructionCache
Code 88AE621E IofCallDriver
Code 88AD770E IofCompleteRequest

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!IofCallDriver 804E13A7 5 Bytes JMP 88AE6223
.text ntoskrnl.exe!IofCompleteRequest 804E17BD 5 Bytes JMP 88AD7713
PAGE ntoskrnl.exe!ZwEnumerateKey 80578EE4 5 Bytes JMP 89AFC2B4
PAGE ntoskrnl.exe!ZwFlushInstructionCache 805873DB 5 Bytes JMP 88AD7C34
? C:\WINDOWS\TEMP\mc21.tmp The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\TDispVol.exe[384] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00A2000A
.text C:\WINDOWS\system32\TDispVol.exe[384] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\TDispVol.exe[384] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\TDispVol.exe[384] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\TDispVol.exe[384] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\TDispVol.exe[384] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\TDispVol.exe[384] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\TDispVol.exe[384] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\TDispVol.exe[384] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\TDispVol.exe[384] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\TDispVol.exe[384] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\TDispVol.exe[384] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\TDispVol.exe[384] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\wscntfy.exe[424] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 009B000A
.text C:\WINDOWS\system32\wscntfy.exe[424] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\wscntfy.exe[424] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\wscntfy.exe[424] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\wscntfy.exe[424] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\wscntfy.exe[424] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\wscntfy.exe[424] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\wscntfy.exe[424] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\wscntfy.exe[424] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\wscntfy.exe[424] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\wscntfy.exe[424] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\wscntfy.exe[424] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\wscntfy.exe[424] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text c:\Toshiba\IVP\swupdate\swupdtmr.exe[464] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 0090000A
.text C:\WINDOWS\Explorer.EXE[544] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00AF000A
.text C:\WINDOWS\Explorer.EXE[544] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\Explorer.EXE[544] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\Explorer.EXE[544] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\Explorer.EXE[544] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\Explorer.EXE[544] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\Explorer.EXE[544] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\Explorer.EXE[544] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\Explorer.EXE[544] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[544] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\Explorer.EXE[544] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[544] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[776] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 0075000A
.text C:\WINDOWS\system32\winlogon.exe[920] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 0066000A
.text C:\WINDOWS\system32\services.exe[968] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 0065000A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08BE000A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00BC000A
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\SearchIndexer.exe[1408] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00BE000A
.text C:\WINDOWS\system32\SearchIndexer.exe[1408] kernel32.dll!WriteFile 7C810D97 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\WINDOWS\System32\alg.exe[1508] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08BA000A
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 003F000A
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Apoint2K\Apoint.exe[1756] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00BC000A
.text C:\Program Files\Apoint2K\Apoint.exe[1756] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Apoint2K\Apoint.exe[1756] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Apoint2K\Apoint.exe[1756] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Apoint2K\Apoint.exe[1756] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Apoint2K\Apoint.exe[1756] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\Apoint2K\Apoint.exe[1756] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\Apoint2K\Apoint.exe[1756] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\Apoint2K\Apoint.exe[1756] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Apoint2K\Apoint.exe[1756] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Apoint2K\Apoint.exe[1756] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\Apoint2K\Apoint.exe[1756] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Apoint2K\Apoint.exe[1756] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\DVDRAMSV.exe[1916] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 007B000A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08BA000A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\igfxpers.exe[2068] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 009A000A
.text C:\WINDOWS\system32\igfxpers.exe[2068] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\igfxpers.exe[2068] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\igfxpers.exe[2068] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\igfxpers.exe[2068] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\igfxpers.exe[2068] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\igfxpers.exe[2068] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\igfxpers.exe[2068] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\igfxpers.exe[2068] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\igfxpers.exe[2068] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\igfxpers.exe[2068] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\igfxpers.exe[2068] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\igfxpers.exe[2068] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\igfxtray.exe[2092] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00BE000A
.text C:\WINDOWS\system32\igfxtray.exe[2092] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\igfxtray.exe[2092] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\igfxtray.exe[2092] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\igfxtray.exe[2092] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\igfxtray.exe[2092] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\igfxtray.exe[2092] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\igfxtray.exe[2092] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\igfxtray.exe[2092] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\igfxtray.exe[2092] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\igfxtray.exe[2092] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\igfxtray.exe[2092] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\igfxtray.exe[2092] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00A7000A
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00A7000A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 003B000A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\TPSBattM.exe[2200] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08C6000A
.text C:\WINDOWS\system32\TPSBattM.exe[2200] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\TPSBattM.exe[2200] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\TPSBattM.exe[2200] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\TPSBattM.exe[2200] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\TPSBattM.exe[2200] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\TPSBattM.exe[2200] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\TPSBattM.exe[2200] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\TPSBattM.exe[2200] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\TPSBattM.exe[2200] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\TPSBattM.exe[2200] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\TPSBattM.exe[2200] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\TPSBattM.exe[2200] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\ctfmon.exe[2300] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08A4000A
.text C:\WINDOWS\system32\ctfmon.exe[2300] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\ctfmon.exe[2300] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\ctfmon.exe[2300] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\ctfmon.exe[2300] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\ctfmon.exe[2300] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\ctfmon.exe[2300] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\ctfmon.exe[2300] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\ctfmon.exe[2300] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\ctfmon.exe[2300] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[2300] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\ctfmon.exe[2300] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[2300] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08C2000A
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Apoint2K\Apntex.exe[2496] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08A6000A
.text C:\Program Files\Apoint2K\Apntex.exe[2496] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Apoint2K\Apntex.exe[2496] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Apoint2K\Apntex.exe[2496] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Apoint2K\Apntex.exe[2496] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Apoint2K\Apntex.exe[2496] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\Apoint2K\Apntex.exe[2496] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\Apoint2K\Apntex.exe[2496] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\Apoint2K\Apntex.exe[2496] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Apoint2K\Apntex.exe[2496] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Apoint2K\Apntex.exe[2496] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\Apoint2K\Apntex.exe[2496] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Apoint2K\Apntex.exe[2496] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\RAMASST.exe[2516] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00A3000A
.text C:\WINDOWS\system32\RAMASST.exe[2516] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\RAMASST.exe[2516] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\RAMASST.exe[2516] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\RAMASST.exe[2516] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\RAMASST.exe[2516] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\RAMASST.exe[2516] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\RAMASST.exe[2516] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\RAMASST.exe[2516] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\RAMASST.exe[2516] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RAMASST.exe[2516] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\RAMASST.exe[2516] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RAMASST.exe[2516] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\wuauclt.exe[2752] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08A3000A
.text C:\WINDOWS\system32\wuauclt.exe[2752] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\wuauclt.exe[2752] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\wuauclt.exe[2752] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\wuauclt.exe[2752] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\wuauclt.exe[2752] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\wuauclt.exe[2752] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\wuauclt.exe[2752] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\wuauclt.exe[2752] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\wuauclt.exe[2752] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\wuauclt.exe[2752] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\wuauclt.exe[2752] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\wuauclt.exe[2752] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\System32\svchost.exe[2900] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 0075000A
.text C:\WINDOWS\System32\svchost.exe[2900] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)

Device \FileSystem\Udfs \UdfsCdRom DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\meiudf \MeiUDF_Disk DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\meiudf \MeiUDF_CdRom DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Udfs \UdfsDisk DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

—- EOF - GMER 1.0.15 —-

Attachments:

I don't know what my Admin password is

This may be a problem. Is there any way in which you can access any Admin account at all? Is there anyone else with an Admin password?

Pretty much all Malware Removal tools are most effective when run under Admin accounts, and some make it a requirement. Has MalwareBytes' found anything when you've run it?

How often do these redirects occur, every search? Close all Firefox windows, and then click Start >> All Programs >> Mozilla Firefox >> Mozilla Firefox (Safe Mode) and check it you get redirects there.

Thanks.
I'll see if I can reset the password or something. Malware bytes found some stuff yesterday (as did Spybot and SuperAntiSpyware) but nothing today and it's still redirecting. Sometimes the first link I click in a Google search works fine. But if I go back and try another link, it will redirect me. And if I try the first link again, it will also redirect me. This still happens in Mozilla Firefox Safe Mode. Thanks
This may or may not work without an Admin account. Click Start >> Run, type cmd and hit Enter. When the CMD prompt appears, type (or copy/paste) the following:
sc delete tclondrv
and the hit Enter.

Let me know what it says.

Let me know if you manage to get into your Admin account, as that is really what we need. Do you have a Windows Installation Disk?
I typed it in, hit enter and it says "SUCCESS" I think I have a Windows Installation Disk, but it may be hidden somewhere… I'll check. Thanks
So I went to create a new admin account and it turns out I never made a password for the original account. So I set one up for it as well as one for the new admin account. I tried running it as admin and it didn't work for the original account, but it worked for the new one. Here are the results

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-15 09:44:55
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.15 —-

Code 89AFC2B0 ZwEnumerateKey
Code 88AD7C30 ZwFlushInstructionCache
Code 88AE621E IofCallDriver
Code 88AD770E IofCompleteRequest

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!IofCallDriver 804E13A7 5 Bytes JMP 88AE6223
.text ntoskrnl.exe!IofCompleteRequest 804E17BD 5 Bytes JMP 88AD7713
PAGE ntoskrnl.exe!ZwEnumerateKey 80578EE4 5 Bytes JMP 89AFC2B4
PAGE ntoskrnl.exe!ZwFlushInstructionCache 805873DB 5 Bytes JMP 88AD7C34
? C:\WINDOWS\TEMP\mc21.tmp The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\TDispVol.exe[384] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00A2000A
.text C:\WINDOWS\system32\TDispVol.exe[384] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\TDispVol.exe[384] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\TDispVol.exe[384] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\TDispVol.exe[384] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\TDispVol.exe[384] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\TDispVol.exe[384] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\TDispVol.exe[384] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\TDispVol.exe[384] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\TDispVol.exe[384] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\TDispVol.exe[384] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\TDispVol.exe[384] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\TDispVol.exe[384] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\wscntfy.exe[424] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 009B000A
.text C:\WINDOWS\system32\wscntfy.exe[424] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\wscntfy.exe[424] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\wscntfy.exe[424] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\wscntfy.exe[424] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\wscntfy.exe[424] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\wscntfy.exe[424] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\wscntfy.exe[424] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\wscntfy.exe[424] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\wscntfy.exe[424] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\wscntfy.exe[424] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\wscntfy.exe[424] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\wscntfy.exe[424] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text c:\Toshiba\IVP\swupdate\swupdtmr.exe[464] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 0090000A
.text C:\WINDOWS\Explorer.EXE[544] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00AF000A
.text C:\WINDOWS\Explorer.EXE[544] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\Explorer.EXE[544] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\Explorer.EXE[544] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\Explorer.EXE[544] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\Explorer.EXE[544] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\Explorer.EXE[544] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\Explorer.EXE[544] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\Explorer.EXE[544] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[544] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\Explorer.EXE[544] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[544] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Java\jre6\bin\jusched.exe[748] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[776] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 0075000A
.text C:\WINDOWS\system32\winlogon.exe[920] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 0066000A
.text C:\WINDOWS\system32\services.exe[968] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 0065000A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08BE000A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[1048] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00BC000A
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\TCtrlIOHook.exe[1356] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\SearchIndexer.exe[1408] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00BE000A
.text C:\WINDOWS\system32\SearchIndexer.exe[1408] kernel32.dll!WriteFile 7C810D97 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\WINDOWS\System32\alg.exe[1508] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08BA000A
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[1532] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 003F000A
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe[1708] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Apoint2K\Apoint.exe[1756] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00BC000A
.text C:\Program Files\Apoint2K\Apoint.exe[1756] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Apoint2K\Apoint.exe[1756] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Apoint2K\Apoint.exe[1756] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Apoint2K\Apoint.exe[1756] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Apoint2K\Apoint.exe[1756] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\Apoint2K\Apoint.exe[1756] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\Apoint2K\Apoint.exe[1756] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\Apoint2K\Apoint.exe[1756] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Apoint2K\Apoint.exe[1756] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Apoint2K\Apoint.exe[1756] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\Apoint2K\Apoint.exe[1756] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Apoint2K\Apoint.exe[1756] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\DVDRAMSV.exe[1916] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 007B000A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08BA000A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1984] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\igfxpers.exe[2068] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 009A000A
.text C:\WINDOWS\system32\igfxpers.exe[2068] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\igfxpers.exe[2068] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\igfxpers.exe[2068] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\igfxpers.exe[2068] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\igfxpers.exe[2068] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\igfxpers.exe[2068] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\igfxpers.exe[2068] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\igfxpers.exe[2068] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\igfxpers.exe[2068] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\igfxpers.exe[2068] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\igfxpers.exe[2068] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\igfxpers.exe[2068] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\igfxtray.exe[2092] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00BE000A
.text C:\WINDOWS\system32\igfxtray.exe[2092] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\igfxtray.exe[2092] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\igfxtray.exe[2092] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\igfxtray.exe[2092] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\igfxtray.exe[2092] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\igfxtray.exe[2092] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\igfxtray.exe[2092] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\igfxtray.exe[2092] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\igfxtray.exe[2092] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\igfxtray.exe[2092] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\igfxtray.exe[2092] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\igfxtray.exe[2092] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00A7000A
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[2120] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00A7000A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2152] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 003B000A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2188] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\TPSBattM.exe[2200] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08C6000A
.text C:\WINDOWS\system32\TPSBattM.exe[2200] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\TPSBattM.exe[2200] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\TPSBattM.exe[2200] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\TPSBattM.exe[2200] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\TPSBattM.exe[2200] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\TPSBattM.exe[2200] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\TPSBattM.exe[2200] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\TPSBattM.exe[2200] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\TPSBattM.exe[2200] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\TPSBattM.exe[2200] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\TPSBattM.exe[2200] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\TPSBattM.exe[2200] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\ctfmon.exe[2300] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08A4000A
.text C:\WINDOWS\system32\ctfmon.exe[2300] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\ctfmon.exe[2300] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\ctfmon.exe[2300] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\ctfmon.exe[2300] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\ctfmon.exe[2300] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\ctfmon.exe[2300] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\ctfmon.exe[2300] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\ctfmon.exe[2300] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\ctfmon.exe[2300] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[2300] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\ctfmon.exe[2300] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[2300] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08C2000A
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\Alex\Desktop\gmer\gmer.exe[2472] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Apoint2K\Apntex.exe[2496] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08A6000A
.text C:\Program Files\Apoint2K\Apntex.exe[2496] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Apoint2K\Apntex.exe[2496] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Apoint2K\Apntex.exe[2496] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Apoint2K\Apntex.exe[2496] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Apoint2K\Apntex.exe[2496] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\Program Files\Apoint2K\Apntex.exe[2496] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\Program Files\Apoint2K\Apntex.exe[2496] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\Program Files\Apoint2K\Apntex.exe[2496] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Apoint2K\Apntex.exe[2496] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Apoint2K\Apntex.exe[2496] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\Program Files\Apoint2K\Apntex.exe[2496] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Apoint2K\Apntex.exe[2496] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\RAMASST.exe[2516] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00A3000A
.text C:\WINDOWS\system32\RAMASST.exe[2516] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\RAMASST.exe[2516] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\RAMASST.exe[2516] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\RAMASST.exe[2516] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\RAMASST.exe[2516] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\RAMASST.exe[2516] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\RAMASST.exe[2516] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\RAMASST.exe[2516] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\RAMASST.exe[2516] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RAMASST.exe[2516] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\RAMASST.exe[2516] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RAMASST.exe[2516] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\wuauclt.exe[2752] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08A3000A
.text C:\WINDOWS\system32\wuauclt.exe[2752] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\wuauclt.exe[2752] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\wuauclt.exe[2752] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\wuauclt.exe[2752] kernel32.dll!ExitProcess 7C81CDEA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\wuauclt.exe[2752] GDI32.dll!EndPage 77F2DD49 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\wuauclt.exe[2752] GDI32.dll!EndDoc 77F2DFD9 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\wuauclt.exe[2752] GDI32.dll!StartPage 77F2F0AE 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\wuauclt.exe[2752] GDI32.dll!AbortDoc 77F444DF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\wuauclt.exe[2752] GDI32.dll!StartDocW 77F4516F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\wuauclt.exe[2752] GDI32.dll!StartDocW + 4 77F45173 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\wuauclt.exe[2752] GDI32.dll!StartDocA 77F45689 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\wuauclt.exe[2752] GDI32.dll!StartDocA + 4 77F4568D 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\System32\svchost.exe[2900] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 0075000A
.text C:\WINDOWS\System32\svchost.exe[2900] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)

Device \FileSystem\Udfs \UdfsCdRom DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\meiudf \MeiUDF_Disk DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\meiudf \MeiUDF_CdRom DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Udfs \UdfsDisk DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

—- EOF - GMER 1.0.15 —-



Thanks!
OK, now we may be in business.

Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2
Link 3

[external image: Posted Image]

[external image: Posted Image]

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on Combo-Fix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Just finished running ComboFix and got the log. A couple things to note: while Combofix was running, apparently a program called pev.cfexe was not responding and had to shut down. Also, ComboFix had to restart and told me to write down the following things just in case:

C:\WINDOWS\System32\drivers\hjgruitqytctbo.sys
C:\WINDOWS\System32\hjgruitadaviox.dll
C:\WINDOWS\System32\hjgruiusbbdrln.dat
C:\WINDOWS\System32\hjgruilamjukpc.dll
C:\WINDOWS\System32\hjgruijwfvbtrn.dat


ComboFix 09-07-14.08 - Alex 07/15/2009 12:35.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1621 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\hjgruitqytctbo.sys
c:\windows\system32\hjgruijwfvbtru.dat
c:\windows\system32\hjgruilamjukpc.dll
c:\windows\system32\hjgruitadaviox.dll
c:\windows\system32\hjgruiusbbdrln.dat

c:\windows\system32\proquota.exe was missing
Restored copy from - c:\system volume information\_restore{46E98557-65C7-4066-9D61-A12588985258}\RP998\A0202010.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_hjgruiilwuwfwd
——-\Legacy_SYS
——-\Legacy_SYSDRV


((((((((((((((((((((((((( Files Created from 2009-06-15 to 2009-07-15 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-24 13:26 . 2008-08-26 14:11 137208 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2006-05-03 09:06 . 2007-06-23 20:49 163328 –sha-r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2008-05-10 18:37 31232 –sh–r- c:\windows\system32\msfDX.dll
2007-12-17 12:43 . 2008-05-10 18:37 27648 –sh–w- c:\windows\system32\Smab0.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-04-01 08:14 1163264 —-a-w- c:\program files\Dropbox\DropboxExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-04-01 08:14 1163264 —-a-w- c:\program files\Dropbox\DropboxExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-04-01 08:14 1163264 —-a-w- c:\program files\Dropbox\DropboxExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-05 148888]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-18 151552]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-27 122880]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2005-12-01 671744]
"SVPWUTIL"="c:\program files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2004-05-01 65536]
"HWSetup"="c:\program files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-05-01 28672]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-03-24 196608]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"USB2Check"="c:\windows\system32\PCLECoInst.dll" [2006-11-06 81920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-01-28 185896]
"TDispVol"="TDispVol.exe" - c:\windows\system32\TDispVol.exe [2005-12-28 73728]
"TCtryIOHook"="TCtrlIOHook.exe" - c:\windows\system32\TCtrlIOHook.exe [2005-12-05 28672]
"TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-06-01 282624]
"TFncKy"="TFncKy.exe" [BU]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2005-12-29 155648]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Alex^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\documents and settings\Alex\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Alex^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\Alex\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PinnacleSys.MediaServer"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"SQLAgent$PINNACLESYS"=3 (0x3)
"iPod Service"=3 (0x3)
"DefWatch"=3 (0x3)
"ccSetMgr"=3 (0x3)
"ccEvtMgr"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"MSSQL$PINNACLESYS"=2 (0x2)
"NMSAccessU"=3 (0x3)
"C-DillaCdaC11BA"=3 (0x3)
"Viewpoint Manager Service"=2 (0x2)
"avg8wd"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"TOSCDSPD"=c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"LaunchList"=c:\program files\Pinnacle\Studio 11\LaunchList2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"DLA"=c:\windows\System32\DLA\DLACTRLW.EXE
"USB2Check"=RUNDLL32.EXE "c:\windows\system32\PCLECoInst.dll",CheckUSBController
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"NDSTray.exe"=NDSTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Toshiba\\ConfigFree\\CFXFER.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\KeyHoleTV\\KeyHoleTV.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\PharosSystems\\Core\\CTskMstr.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7001:UDP"= 7001:UDP:AFS CacheManager Callback (UDP)
"7001:TCP"= 7001:TCP:AFS CacheManager Callback (TCP)
"8085:TCP"= 8085:TCP:sys


R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-06-23 7408]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-06-23 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-06-23 72944]
S2 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2007-06-06 116928]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-05-13 101936]


— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder

2006-04-27 c:\windows\Tasks\Registration reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2005-12-29 12:00]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bungie.net/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: plaxo.com\www
FF - ProfilePath - c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\ynba4nh2.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=&query=
FF - prefs.js: browser.startup.homepage - hxxp://digg.com/all/popular/24hours
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-15 12:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\windows\TEMP\mc21.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,56,67,ad,9c,bd,
fd,70,60,2e,e8,e1,00,eb,16,2b,de,f9,b3,01,61,ec,87,eb,23,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,5e,7f,01,26,31,
de,27,3e,46,47,15,b0,92,4b,c7,ef,5c,88,99,45,69,ef,24,ff,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,aa,5a,b7,39,dd,
77,5f,d1,7a,45,05,fd,91,e8,6f,31,bd,57,e6,2f,f4,b3,70,cb,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,b2,99,c8,7c,cb,
ce,31,e4,6b,65,49,6a,7e,99,74,f7,69,79,65,26,31,ef,e2,9b,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,75,1e,dd,03,e5,
19,43,ef,e9,02,6c,fa,fb,1d,47,57,86,0a,2f,70,a7,f8,da,66,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:50,93,e5,ab,ec,6a,4e,ab,37,59,c8,d0,8b,
e3,b8,95,50,93,e5,ab,ec,6a,4e,ab,c7,3e,5e,1e,1e,cf,56,76,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,b6,2f,c6,47,e1,
54,94,86,97,20,4e,9a,c7,f1,35,ee,50,f6,1d,48,35,4d,8c,e1,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,c6,23,e4,16,78,
13,74,d7,aa,52,c6,00,84,3c,26,64,99,b0,99,ba,ef,22,d8,cf,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:b2,46,9a,e2,1b,fe,1b,94,9b,a7,42,ba,61,
b3,ba,c0,b2,46,9a,e2,1b,fe,1b,94,49,24,db,0a,e8,bf,41,58,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,8b,b8,57,5f,49,
5f,b7,71,37,a4,aa,c3,a6,15,56,0a,9f,e9,ac,65,e7,7b,96,a8,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,ad,39,68,4c,02,
71,c8,a2,f8,31,0f,a9,5f,a0,ec,fb,9e,74,4c,35,1a,ae,f5,b9,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,0b,14,54,3a,45,
c6,b4,88,05,73,21,dd,54,d8,4a,c5,e9,b8,fa,8d,42,c4,68,83,6c,43,2d,1e,aa,22,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(924)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(2160)
c:\progra~1\PHAROS~1\Core\PRNTRACK.DLL
c:\program files\Dropbox\DropboxExt.dll
c:\windows\system32\TDispVol.dll
c:\windows\system32\shdoclc.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\Software Suite\PhotoImpression\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\TPwrCfg.DLL
c:\windows\system32\TPwrReg.dll
c:\windows\system32\TPSTrace.DLL
c:\windows\system32\browselc.dll
c:\program files\Microsoft Office\Office12\1033\GrooveIntlResource.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\DVDRAMSV.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\PHAROS~1\Core\CTskMstr.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\TPSBattM.exe
c:\program files\Toshiba\TOSHIBA Controls\TFncKy.exe
c:\program files\Apoint2K\ApntEx.exe
c:\windows\system32\taskmgr.exe
.
**************************************************************************
.
Completion time: 2009-07-15 12:59 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-15 16:59

Pre-Run: 24,340,934,656 bytes free
Post-Run: 24,396,210,176 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

336 — E O F — 2009-06-10 05:33




Thanks again for all your help. I really, really appreciate it!
That's looking much better :thumbup:

OK, let's just get a second opinion with this thorough general scan.

Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Let me know if you are having any more problems.
Tried running it last night, but internet got cut off midway through and had to restart. I'll try to do it later tonight when I get a chance and will let you know. Thanks!!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI