This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] hjgruiwpiibptv.dll

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I got some weird blue screen when I start some application like game…
and sometime when make a research on Google and when I click on a link that send me to another page completely different kind of like a spam. I need help please 
Sorry for my English … I am not native speaker.
Here my DDS log and GMER log
Thank


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 22:21:26.56 on Mon 07/20/2009
Internet Explorer: 8.0.6001.18783
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3071.1964 [GMT -5:00]

SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\sdra64.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k iissvcs
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\taskeng.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\Users\Juleila\Desktop\186.18_desktop_win7_winvista_32bit_english_whql.exe
C:\NVIDIA\DisplayDriver\186.18\English\setup.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\System32\nvSCPAPISvr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Java\jre6\bin\jp2launcher.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Juleila\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH;=&Br;=EM&Loc;=ENG_US&Sys;=DTP&M;=T5274a
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH;=&Br;=EM&Loc;=ENG_US&Sys;=DTP&M;=T5274a
mDefault_Page_URL = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH;=&Br;=EM&Loc;=ENG_US&Sys;=DTP&M;=T5274a
mSearchAssistant = hxxp://www.gateway.com/g/sidepanel.html?Ch=Retail&SubCH;=&Br;=EM&Loc;=ENG_US&Sys;=DTP&M;=T5274a
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\sdra64.exe,
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: SYSTRAN Toolbar: {95daa571-4def-4a6d-97d8-98a346672a24} - mscoree.dll
uRun: [eyeBeam SIP Client]
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
StartupFolder: c:\users\juleila\appdata\roaming\micros~1\windows\startm~1\programs\startup\pnkbst~1.lnk - c:\windows\system32\PnkBstrA.exe
StartupFolder: c:\users\juleila\appdata\roaming\micros~1\windows\startm~1\programs\startup\pnkbst~2.lnk - c:\windows\system32\PnkBstrB.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Consulter les dictionnaires (SYSTRAN) - c:\program files\systran\6\\GUIres.dll/lookup.js
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Traduire (SYSTRAN) - c:\program files\systran\6\\GUIres.dll/translate.js
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/ZwinkyInitialSetup1.0.1.1.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - hxxp://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.21.0.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} - hxxp://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Notify: igfxcui - igfxdev.dll

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-7-18 64160]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\avira\antivir desktop\sched.exe [2009-7-5 108289]
R2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\drivers\RtNdPt60.sys [2009-4-3 27648]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\windows\system32\nvSCPAPISvr.exe [2009-6-10 232960]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 1029456]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2009-7-3 9728]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2009-7-3 3072]
S3 leafnets;Leaf Networks Adapter;c:\windows\system32\drivers\leafnets.sys [2007-5-2 55296]
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\drivers\NETw2v32.sys [2006-11-2 2589184]

=============== Created Last 30 ================

2009-07-18 23:26 15,688 a——- c:\windows\system32\lsdelete.exe
2009-07-18 21:08 64,160 a——- c:\windows\system32\drivers\Lbd.sys
2009-07-18 20:08 -cd-h— c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-07-18 20:08 -cd-h— c:\progra~2\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-07-18 15:49 209,508,599 a——- c:\windows\MEMORY.DMP
2009-07-18 15:47 139,152 a——- c:\users\juleila\appdata\roaming\PnkBstrK.sys
2009-07-18 15:47 794,408 a——- c:\windows\system32\pbsvc.exe
2009-07-18 15:27 –d—– c:\program files\EA Games
2009-07-15 15:44 –d—– c:\program files\Yahoo!
2009-07-15 12:40 156,672 a——- c:\windows\system32\t2embed.dll
2009-07-15 12:40 289,792 a——- c:\windows\system32\atmfd.dll
2009-07-15 12:40 72,704 a——- c:\windows\system32\fontsub.dll
2009-07-15 12:40 23,552 a——- c:\windows\system32\lpk.dll
2009-07-15 12:40 10,240 a——- c:\windows\system32\dciman32.dll
2009-07-15 12:28 –dsh— c:\windows\system32\lowsec
2009-07-09 01:05 –d—– c:\program files\CAPCOM
2009-07-08 00:26 –d—– c:\users\juleila\appdata\roaming\Reallusion
2009-07-08 00:17 –d—– c:\program files\common files\Reallusion
2009-07-05 00:53 55,640 a——- c:\windows\system32\drivers\avgntflt.sys
2009-07-05 00:53 –d—– c:\programdata\Avira
2009-07-05 00:53 –d—– c:\program files\Avira
2009-07-05 00:53 –d—– c:\progra~2\Avira
2009-07-03 20:24 1,663,488 a——- c:\windows\system32\BootMan.exe
2009-07-03 20:24 14,848 a——- c:\windows\system32\EuEpmGdi.dll
2009-07-03 20:24 86,408 a——- c:\windows\system32\setupempdrv03.exe
2009-07-03 20:24 9,728 a——- c:\windows\system32\epmntdrv.sys
2009-07-03 20:24 3,072 a——- c:\windows\system32\EuGdiDrv.sys
2009-07-03 20:24 –d—– c:\program files\EASEUS
2009-07-03 16:58 –d—– c:\users\juleila\appdata\roaming\PeerNetworking
2009-07-03 14:50 364,544 a——- c:\windows\system32\WDBtnMgr.exe
2009-06-29 13:25 –d—– c:\program files\common files\muvee Technologies
2009-06-29 13:25 –d—– c:\program files\NewTech Infosystems
2009-06-29 12:23 –d—– c:\windows\system32\eu-ES
2009-06-29 12:23 –d—– c:\windows\system32\ca-ES
2009-06-29 12:23 –d—– c:\windows\system32\vi-VN
2009-06-29 11:56 –d—– c:\windows\system32\EventProviders
2009-06-29 11:54 978,432 a——- c:\windows\system32\drmv2clt.dll
2009-06-29 11:53 153 a——- c:\windows\system32\RacUREx.xml
2009-06-29 11:53 265,728 a——- c:\windows\system32\wbem\esscli.dll
2009-06-29 11:53 189,440 a——- c:\windows\system32\wbem\mofd.dll
2009-06-29 11:53 83,968 a——- c:\windows\system32\wbem\wmiutils.dll
2009-06-29 11:53 30,208 a——- c:\windows\system32\wbem\wbemprox.dll
2009-06-29 11:53 744,448 a——- c:\windows\system32\wbem\wbemcore.dll
2009-06-29 11:53 614,912 a——- c:\windows\system32\wbem\fastprox.dll
2009-06-29 11:53 265,728 a——- c:\windows\system32\wbem\repdrvfs.dll
2009-06-29 11:53 705,536 a——- c:\windows\system32\SmiEngine.dll
2009-06-29 11:53 218,624 a——- c:\windows\system32\wdscore.dll
2009-06-29 11:53 130,560 a——- c:\windows\system32\PkgMgr.exe
2009-06-29 11:53 247,808 a——- c:\windows\system32\drvstore.dll
2009-06-21 20:31 2,464 a——- c:\windows\netdet.ini
2009-06-21 20:31 –d—– c:\program files\common files\Bcgsoft
2009-06-21 20:29 676,864 a——- c:\windows\system32\drivers\hardlock.sys
2009-06-21 20:29 2,577 a——- c:\windows\system32\config.hsp
2009-06-21 20:28 12,288 a——- c:\windows\system32\Msdaae67.rra
2009-06-21 20:28 1,046,288 ——– c:\windows\system32\Msjet35.dll
2009-06-21 20:28 368,912 ——– c:\windows\system32\Vbar332.dll
2009-06-21 20:28 290,816 ——– c:\windows\system32\Msxbse35.dll
2009-06-21 20:28 252,176 ——– c:\windows\system32\Msrd2x35.dll
2009-06-21 20:28 123,664 ——– c:\windows\system32\Msjint35.dll
2009-06-21 20:28 24,848 ——– c:\windows\system32\Msjter35.dll

==================== Find3M ====================

2009-07-20 22:08 143,360 a——- c:\windows\inf\infstrng.dat
2009-07-20 22:08 86,016 a——- c:\windows\inf\infstor.dat
2009-07-20 22:08 51,200 a——- c:\windows\inf\infpub.dat
2009-07-20 17:57 319,456 a——- c:\windows\DIFxAPI.dll
2009-07-19 14:34 139,152 a——- c:\windows\system32\drivers\PnkBstrK.sys
2009-07-19 14:34 111,928 a——- c:\windows\system32\PnkBstrB.exe
2009-07-09 12:19 0 a——- c:\windows\system32\drivers\lvuvc.hs
2009-06-29 12:23 665,600 a——- c:\windows\inf\drvindex.dat
2009-06-10 08:35 1,194,528 a——- c:\windows\system32\nvcplui.exe
2009-06-10 08:35 1,296,928 a——- c:\windows\system32\nvsvs.dll
2009-06-10 08:34 3,123,744 a——- c:\windows\system32\nvwss.dll
2009-06-10 08:34 4,045,344 a——- c:\windows\system32\nvvitvs.dll
2009-06-10 08:34 4,028,960 a——- c:\windows\system32\nvdisps.dll
2009-06-10 08:34 3,516,960 a——- c:\windows\system32\nvgames.dll
2009-06-10 08:34 1,288,736 a——- c:\windows\system32\nvmobls.dll
2009-06-10 08:34 211,488 a——- c:\windows\system32\nvvsvc.exe
2009-06-10 08:34 195,104 a——- c:\windows\system32\nvmccss.dll
2009-06-10 08:34 13,785,632 a——- c:\windows\system32\nvcpl.dll
2009-06-10 08:34 768,544 a——- c:\windows\system32\nvsvc.dll
2009-06-10 08:34 143,360 a——- c:\windows\system32\nvshext.dll
2009-06-10 08:34 92,704 a——- c:\windows\system32\nvmctray.dll
2009-06-10 06:33 244,736 a——- c:\windows\system32\nvStInst.exe
2009-06-10 06:33 467,968 a——- c:\windows\system32\nvstlink.exe
2009-06-10 06:33 3,953,152 a——- c:\windows\system32\nvstwiz.exe
2009-06-10 06:33 141,824 a——- c:\windows\system32\nvStereoApiI.dll
2009-06-10 06:33 171,520 a——- c:\windows\system32\nvStereoApiI64.dll
2009-06-10 06:33 232,960 a——- c:\windows\system32\nvSCPAPISvr.exe
2009-06-10 06:32 257,536 a——- c:\windows\system32\nvSCPAPI.dll
2009-06-10 06:32 301,568 a——- c:\windows\system32\nvSCPAPI64.dll
2009-06-10 06:32 3,293,184 a——- c:\windows\system32\nvstres.dll
2009-06-10 06:32 5,847 a——- c:\windows\system32\oglstreg.reg
2009-06-10 06:31 167,424 a——- c:\windows\system32\nvstreg.exe
2009-06-10 06:31 1,718,272 a——- c:\windows\system32\nvsttest.exe
2009-06-10 06:31 1,034,752 a——- c:\windows\system32\nvstview.exe
2009-06-10 06:31 89,088 a——- c:\windows\system32\nvimage.dll
2009-06-10 06:29 1,656 a——- c:\windows\system32\nvstdef.reg
2009-06-10 06:03 10,379,264 a——- c:\windows\system32\nvoglv32.dll
2009-06-10 06:03 9,899,296 a——- c:\windows\system32\drivers\nvlddmkm.sys
2009-06-10 06:03 7,611,904 a——- c:\windows\system32\nvd3dum.dll
2009-06-10 06:03 3,148,288 a——- c:\windows\system32\nvwgf2um.dll
2009-06-10 06:03 1,704,960 a——- c:\windows\system32\nvcuda.dll
2009-06-10 06:03 1,317,408 a——- c:\windows\system32\nvcuvenc.dll
2009-06-10 06:03 989,696 a——- c:\windows\system32\nvapi.dll
2009-06-10 06:03 678,432 a——- c:\windows\system32\nvcuvid.dll
2009-06-10 06:03 457,248 a——- c:\windows\system32\nvudisp.exe
2009-06-10 06:03 151,552 a——- c:\windows\system32\nvcod155.dll
2009-06-10 06:03 151,552 a——- c:\windows\system32\nvcod.dll
2009-06-10 06:03 4,224 a——- c:\windows\system32\drivers\nvBridge.kmd
2009-06-04 16:39 457,248 a——- c:\windows\system32\NVUNINST.EXE
2009-05-09 00:50 915,456 a——- c:\windows\system32\wininet.dll
2009-05-09 00:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-05-04 23:29 410,984 a——- c:\windows\system32\deploytk.dll
2009-04-28 09:55 70,936 a——- c:\windows\system32\PhysXLoader.dll
2009-04-23 07:15 784,896 a——- c:\windows\system32\rpcrt4.dll
2009-04-23 07:14 623,616 a——- c:\windows\system32\localspl.dll
2009-04-22 00:20 14,311,680 a——- c:\windows\system32\xlive.dll
2009-04-22 00:20 13,642,496 a——- c:\windows\system32\xlivefnt.dll
2009-02-24 20:54 1,754 a——- c:\users\juleila\appdata\roaming\SAS7_000.DAT
2008-08-17 12:01 48 a—h— c:\programdata\ezsidmv.dat
2008-08-17 12:01 48 a—h— c:\progra~2\ezsidmv.dat
2008-01-20 21:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 22:22:43.73 ===============









GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-20 22:40:57
Windows 6.0.6002 Service Pack 2


—- System - GMER 1.0.15 —-

INT 0x52 ? 865A4F00
INT 0x62 ? 865A4F00
INT 0x72 ? 84762BF8
INT 0x82 ? 84762BF8
INT 0x92 ? 84762BF8
INT 0x92 ? 84762BF8
INT 0x92 ? 865A4F00
INT 0x92 ? 84762BF8
INT 0xA2 ? 865A4F00

Code 86C14B78 ZwEnumerateKey
Code 86D85C28 ZwFlushInstructionCache
Code 86AE2BE5 IofCallDriver
Code 86B2A24E IofCompleteRequest

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!IofCallDriver 8225C912 5 Bytes JMP 86AE2BEA
.text ntkrnlpa.exe!IofCompleteRequest 8225C97F 5 Bytes JMP 86B2A253
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 823C7EF5 5 Bytes JMP 86D85C2C
PAGE ntkrnlpa.exe!ZwEnumerateKey 824150BA 5 Bytes JMP 86C14B7C
? System32\Drivers\spwv.sys The system cannot find the path specified. !
.text USBPORT.SYS!DllUnload 8EED641B 5 Bytes JMP 865A44E0

—- User code sections - GMER 1.0.15 —-

.text C:\Windows\system32\taskeng.exe[240] ntdll.dll!LdrLoadDll 77CF9390 5 Bytes JMP 0012000A
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[296] ntdll.dll!LdrLoadDll 77CF9390 5 Bytes JMP 0034000A
.text C:\Program Files\Internet Explorer\iexplore.exe[500] USER32.dll!SetWindowsHookExW 77E987AD 5 Bytes JMP 70909271 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[500] USER32.dll!CallNextHookEx 77E98E3B 5 Bytes JMP 708FC8B9 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[500] USER32.dll!UnhookWindowsHookEx 77E998DB 5 Bytes JMP 70874284 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[500] USER32.dll!CreateWindowExW 77EA1305 5 Bytes JMP 7090D2D4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[500] USER32.dll!DialogBoxParamW 77EC10B0 5 Bytes JMP 708351D5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[500] USER32.dll!DialogBoxIndirectParamW 77EC2EF5 5 Bytes JMP 70A2B6FB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[500] USER32.dll!DialogBoxParamA 77ED8152 5 Bytes JMP 70A2B698 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[500] USER32.dll!DialogBoxIndirectParamA 77ED847D 5 Bytes JMP 70A2B75E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[500] USER32.dll!MessageBoxIndirectA 77EED4D9 5 Bytes JMP 70A2B62D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[500] USER32.dll!MessageBoxIndirectW 77EED5D3 5 Bytes JMP 70A2B5C2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[500] USER32.dll!MessageBoxExA 77EED639 5 Bytes JMP 70A2B560 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[500] USER32.dll!MessageBoxExW 77EED65D 5 Bytes JMP 70A2B4FE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[500] ole32.dll!CoCreateInstance 773D9EA6 5 Bytes JMP 7090D330 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Windows\system32\lsm.exe[612] ntdll.dll!LdrLoadDll 77CF9390 5 Bytes JMP 001B000A
.text C:\Windows\system32\winlogon.exe[648] ntdll.dll!LdrLoadDll 77CF9390 5 Bytes JMP 0007000A
.text C:\Windows\System32\svchost.exe[956] ntdll.dll!LdrLoadDll 77CF9390 5 Bytes JMP 0024000A
.text C:\Windows\System32\svchost.exe[1112] ntdll.dll!LdrLoadDll 77CF9390 5 Bytes JMP 001C000A
.text C:\Windows\system32\svchost.exe[1252] ntdll.dll!LdrLoadDll 77CF9390 5 Bytes JMP 001C000A
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!SetWindowsHookExW 77E987AD 5 Bytes JMP 70909271 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!CallNextHookEx 77E98E3B 5 Bytes JMP 708FC8B9 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!UnhookWindowsHookEx 77E998DB 5 Bytes JMP 70874284 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!CreateWindowExW 77EA1305 5 Bytes JMP 7090D2D4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!DialogBoxParamW 77EC10B0 5 Bytes JMP 708351D5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!DialogBoxIndirectParamW 77EC2EF5 5 Bytes JMP 70A2B6FB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!DialogBoxParamA 77ED8152 5 Bytes JMP 70A2B698 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!DialogBoxIndirectParamA 77ED847D 5 Bytes JMP 70A2B75E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!MessageBoxIndirectA 77EED4D9 5 Bytes JMP 70A2B62D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!MessageBoxIndirectW 77EED5D3 5 Bytes JMP 70A2B5C2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!MessageBoxExA 77EED639 5 Bytes JMP 70A2B560 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!MessageBoxExW 77EED65D 5 Bytes JMP 70A2B4FE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ole32.dll!CoCreateInstance 773D9EA6 5 Bytes JMP 7090D330 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5164] USER32.dll!CreateWindowExW 77EA1305 5 Bytes JMP 7090D2D4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5164] USER32.dll!DialogBoxParamW 77EC10B0 5 Bytes JMP 708351D5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5164] USER32.dll!DialogBoxIndirectParamW 77EC2EF5 5 Bytes JMP 70A2B6FB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5164] USER32.dll!DialogBoxParamA 77ED8152 5 Bytes JMP 70A2B698 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5164] USER32.dll!DialogBoxIndirectParamA 77ED847D 5 Bytes JMP 70A2B75E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5164] USER32.dll!MessageBoxIndirectA 77EED4D9 5 Bytes JMP 70A2B62D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5164] USER32.dll!MessageBoxIndirectW 77EED5D3 5 Bytes JMP 70A2B5C2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5164] USER32.dll!MessageBoxExA 77EED639 5 Bytes JMP 70A2B560 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5164] USER32.dll!MessageBoxExW 77EED65D 5 Bytes JMP 70A2B4FE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Windows\system32\vssvc.exe[7936] ntdll.dll!LdrLoadDll 77CF9390 5 Bytes JMP 0085000A
.text C:\Windows\system32\notepad.exe[8476] ntdll.dll!LdrLoadDll 77CF9390 5 Bytes JMP 0041000A
.text C:\Windows\system32\notepad.exe[9164] ntdll.dll!LdrLoadDll 77CF9390 5 Bytes JMP 0030000A

—- Kernel IAT/EAT - GMER 1.0.15 —-

IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [8A28B6D2] \SystemRoot\System32\Drivers\spwv.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [8A28B040] \SystemRoot\System32\Drivers\spwv.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [8A28B7FC] \SystemRoot\System32\Drivers\spwv.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [8A28B0BE] \SystemRoot\System32\Drivers\spwv.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8A28B13C] \SystemRoot\System32\Drivers\spwv.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [8A29B048] \SystemRoot\System32\Drivers\spwv.sys

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Windows\System32\spoolsv.exe[124] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001453AA
IAT C:\Windows\System32\spoolsv.exe[124] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00145291
IAT C:\Windows\System32\spoolsv.exe[124] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001452F6
IAT C:\Windows\System32\spoolsv.exe[124] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0014566F
IAT C:\Windows\System32\spoolsv.exe[124] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00145919
IAT C:\Windows\System32\spoolsv.exe[124] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00145919
IAT C:\Windows\System32\spoolsv.exe[124] @ C:\Windows\system32\shell32.dll [USER32.dll!GetClipboardData] 0014566F
IAT C:\Windows\System32\spoolsv.exe[124] @ C:\Windows\system32\shell32.dll [USER32.dll!TranslateMessage] 00145919
IAT C:\Windows\System32\spoolsv.exe[124] @ C:\Windows\system32\shell32.dll [ntdll.dll!NtQueryDirectoryFile] 001453AA
IAT C:\Windows\System32\spoolsv.exe[124] @ C:\Windows\system32\ws2_32.dll [ntdll.dll!NtQueryDirectoryFile] 001453AA
IAT C:\Windows\system32\taskeng.exe[240] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 024D53AA
IAT C:\Windows\system32\taskeng.exe[240] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 024D5291
IAT C:\Windows\system32\taskeng.exe[240] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 024D52F6
IAT C:\Windows\system32\taskeng.exe[240] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 024D566F
IAT C:\Windows\system32\taskeng.exe[240] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 024D5919
IAT C:\Windows\system32\taskeng.exe[240] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 024D53AA
IAT C:\Windows\system32\taskeng.exe[240] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 024D5919
IAT C:\Windows\system32\taskeng.exe[240] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 024D566F
IAT C:\Windows\system32\taskeng.exe[240] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 024D5919
IAT C:\Windows\system32\taskeng.exe[240] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 024D53AA
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[296] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00B653AA
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[296] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00B65291
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[296] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00B652F6
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[296] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 00B653AA
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[296] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00B6566F
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[296] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00B65919
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[296] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 00B653AA
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[296] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00B65919
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[296] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00B6566F
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[296] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00B65919
IAT C:\PROGRA~1\Java\jre6\bin\jp2launcher.exe[336] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00802F30] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\Java\jre6\bin\jp2launcher.exe[336] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00802D00] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\Java\jre6\bin\jp2launcher.exe[336] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00802CA0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\Java\jre6\bin\jp2launcher.exe[336] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00802CD0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\svchost.exe[416] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00A053AA
IAT C:\Windows\system32\svchost.exe[416] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00A05291
IAT C:\Windows\system32\svchost.exe[416] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00A052F6
IAT C:\Windows\system32\svchost.exe[416] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00A0566F
IAT C:\Windows\system32\svchost.exe[416] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00A05919
IAT C:\Windows\system32\svchost.exe[416] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00A05919
IAT C:\Windows\system32\svchost.exe[416] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 00A053AA
IAT C:\Windows\system32\svchost.exe[416] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00A0566F
IAT C:\Windows\system32\svchost.exe[416] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00A05919
IAT C:\Windows\system32\svchost.exe[416] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 00A053AA
IAT C:\Program Files\Internet Explorer\iexplore.exe[500] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [002F2F30] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[500] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [002F2D00] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[500] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [002F2CA0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[500] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [002F2CD0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\wininit.exe[532] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 002153AA
IAT C:\Windows\system32\wininit.exe[532] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00215291
IAT C:\Windows\system32\wininit.exe[532] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 002152F6
IAT C:\Windows\system32\wininit.exe[532] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0021566F
IAT C:\Windows\system32\wininit.exe[532] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00215919
IAT C:\Windows\system32\wininit.exe[532] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00215919
IAT C:\Windows\system32\wininit.exe[532] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 002153AA
IAT C:\Windows\system32\wininit.exe[532] @ C:\Windows\system32\shell32.dll [USER32.dll!GetClipboardData] 0021566F
IAT C:\Windows\system32\wininit.exe[532] @ C:\Windows\system32\shell32.dll [USER32.dll!TranslateMessage] 00215919
IAT C:\Windows\system32\wininit.exe[532] @ C:\Windows\system32\shell32.dll [ntdll.dll!NtQueryDirectoryFile] 002153AA
IAT C:\Windows\system32\services.exe[576] @ C:\Windows\system32\services.exe [ntdll.dll!NtQueryDirectoryFile] 008053AA
IAT C:\Windows\system32\services.exe[576] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 008053AA
IAT C:\Windows\system32\services.exe[576] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00805291
IAT C:\Windows\system32\services.exe[576] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 008052F6
IAT C:\Windows\system32\services.exe[576] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0080566F
IAT C:\Windows\system32\services.exe[576] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00805919
IAT C:\Windows\system32\services.exe[576] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00805919
IAT C:\Windows\system32\services.exe[576] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 008053AA
IAT C:\Windows\system32\services.exe[576] @ C:\Windows\system32\shell32.dll [USER32.dll!GetClipboardData] 0080566F
IAT C:\Windows\system32\services.exe[576] @ C:\Windows\system32\shell32.dll [USER32.dll!TranslateMessage] 00805919
IAT C:\Windows\system32\services.exe[576] @ C:\Windows\system32\shell32.dll [ntdll.dll!NtQueryDirectoryFile] 008053AA
IAT C:\Windows\system32\lsass.exe[604] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001153AA
IAT C:\Windows\system32\lsass.exe[604] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00115291
IAT C:\Windows\system32\lsass.exe[604] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001152F6
IAT C:\Windows\system32\lsass.exe[604] @ C:\Windows\system32\LSASRV.dll [ntdll.dll!LdrLoadDll] 001152F6
IAT C:\Windows\system32\lsass.exe[604] @ C:\Windows\system32\SAMSRV.dll [ntdll.dll!LdrLoadDll] 001152F6
IAT C:\Windows\system32\lsass.exe[604] @ C:\Windows\system32\SAMSRV.dll [ntdll.dll!LdrGetProcedureAddress] 00115291
IAT C:\Windows\system32\lsass.exe[604] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 001153AA
IAT C:\Windows\system32\lsass.exe[604] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0011566F
IAT C:\Windows\system32\lsass.exe[604] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00115919
IAT C:\Windows\system32\lsass.exe[604] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00115919
IAT C:\Windows\system32\lsass.exe[604] @ C:\Windows\system32\shell32.dll [USER32.dll!GetClipboardData] 0011566F
IAT C:\Windows\system32\lsass.exe[604] @ C:\Windows\system32\shell32.dll [USER32.dll!TranslateMessage] 00115919
IAT C:\Windows\system32\lsass.exe[604] @ C:\Windows\system32\shell32.dll [ntdll.dll!NtQueryDirectoryFile] 001153AA
IAT C:\Windows\system32\lsm.exe[612] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 009953AA
IAT C:\Windows\system32\lsm.exe[612] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00995291
IAT C:\Windows\system32\lsm.exe[612] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 009952F6
IAT C:\Windows\system32\lsm.exe[612] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0099566F
IAT C:\Windows\system32\lsm.exe[612] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00995919
IAT C:\Windows\system32\lsm.exe[612] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00995919
IAT C:\Windows\system32\lsm.exe[612] @ C:\Windows\system32\shell32.dll [USER32.dll!GetClipboardData] 0099566F
IAT C:\Windows\system32\lsm.exe[612] @ C:\Windows\system32\shell32.dll [USER32.dll!TranslateMessage] 00995919
IAT C:\Windows\system32\lsm.exe[612] @ C:\Windows\system32\shell32.dll [ntdll.dll!NtQueryDirectoryFile] 009953AA
IAT C:\Windows\system32\lsm.exe[612] @ C:\Windows\system32\ws2_32.dll [ntdll.dll!NtQueryDirectoryFile] 009953AA
IAT C:\Windows\system32\svchost.exe[916] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 009853AA
IAT C:\Windows\system32\svchost.exe[916] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00985291
IAT C:\Windows\system32\svchost.exe[916] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 009852F6
IAT C:\Windows\system32\svchost.exe[916] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0098566F
IAT C:\Windows\system32\svchost.exe[916] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00985919
IAT C:\Windows\system32\svchost.exe[916] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00985919
IAT C:\Windows\system32\svchost.exe[916] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 009853AA
IAT C:\Windows\system32\svchost.exe[916] @ C:\Windows\system32\shell32.dll [USER32.dll!GetClipboardData] 0098566F
IAT C:\Windows\system32\svchost.exe[916] @ C:\Windows\system32\shell32.dll [USER32.dll!TranslateMessage] 00985919
IAT C:\Windows\system32\svchost.exe[916] @ C:\Windows\system32\shell32.dll [ntdll.dll!NtQueryDirectoryFile] 009853AA
IAT C:\Windows\System32\svchost.exe[956] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 017053AA
IAT C:\Windows\System32\svchost.exe[956] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 01705291
IAT C:\Windows\System32\svchost.exe[956] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 017052F6
IAT C:\Windows\System32\svchost.exe[956] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0170566F
IAT C:\Windows\System32\svchost.exe[956] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 01705919
IAT C:\Windows\System32\svchost.exe[956] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 01705919
IAT C:\Windows\System32\svchost.exe[956] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 0170566F
IAT C:\Windows\System32\svchost.exe[956] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 01705919
IAT C:\Windows\System32\svchost.exe[956] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 017053AA
IAT C:\Windows\System32\svchost.exe[956] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 017053AA
IAT C:\Windows\System32\svchost.exe[1048] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 009753AA
IAT C:\Windows\System32\svchost.exe[1048] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00975291
IAT C:\Windows\System32\svchost.exe[1048] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 009752F6
IAT C:\Windows\System32\svchost.exe[1048] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0097566F
IAT C:\Windows\System32\svchost.exe[1048] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00975919
IAT C:\Windows\System32\svchost.exe[1048] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00975919
IAT C:\Windows\System32\svchost.exe[1048] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 009753AA
IAT C:\Windows\System32\svchost.exe[1048] @ C:\Windows\system32\shell32.dll [USER32.dll!GetClipboardData] 0097566F
IAT C:\Windows\System32\svchost.exe[1048] @ C:\Windows\system32\shell32.dll [USER32.dll!TranslateMessage] 00975919
IAT C:\Windows\System32\svchost.exe[1048] @ C:\Windows\system32\shell32.dll [ntdll.dll!NtQueryDirectoryFile] 009753AA
IAT C:\Windows\System32\svchost.exe[1112] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00EF53AA
IAT C:\Windows\System32\svchost.exe[1112] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00EF5291
IAT C:\Windows\System32\svchost.exe[1112] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00EF52F6
IAT C:\Windows\System32\svchost.exe[1112] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00EF566F
IAT C:\Windows\System32\svchost.exe[1112] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00EF5919
IAT C:\Windows\System32\svchost.exe[1112] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00EF5919
IAT C:\Windows\System32\svchost.exe[1112] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 00EF53AA
IAT C:\Windows\System32\svchost.exe[1112] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00EF566F
IAT C:\Windows\System32\svchost.exe[1112] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00EF5919
IAT C:\Windows\System32\svchost.exe[1112] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 00EF53AA
IAT C:\Windows\system32\svchost.exe[1144] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 017753AA
IAT C:\Windows\system32\svchost.exe[1144] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 01775291
IAT C:\Windows\system32\svchost.exe[1144] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 017752F6
IAT C:\Windows\system32\svchost.exe[1144] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0177566F
IAT C:\Windows\system32\svchost.exe[1144] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 01775919
IAT C:\Windows\system32\svchost.exe[1144] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 01775919
IAT C:\Windows\system32\svchost.exe[1144] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 017753AA
IAT C:\Windows\system32\svchost.exe[1144] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 0177566F
IAT C:\Windows\system32\svchost.exe[1144] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 01775919
IAT C:\Windows\system32\svchost.exe[1144] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 017753AA
IAT C:\Windows\system32\svchost.exe[1252] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 002453AA
IAT C:\Windows\system32\svchost.exe[1252] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00245291
IAT C:\Windows\system32\svchost.exe[1252] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 002452F6
IAT C:\Windows\system32\svchost.exe[1252] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0024566F
IAT C:\Windows\system32\svchost.exe[1252] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00245919
IAT C:\Windows\system32\svchost.exe[1252] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00245919
IAT C:\Windows\system32\svchost.exe[1252] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 002453AA
IAT C:\Windows\system32\svchost.exe[1252] @ C:\Windows\system32\shell32.dll [USER32.dll!GetClipboardData] 0024566F
IAT C:\Windows\system32\svchost.exe[1252] @ C:\Windows\system32\shell32.dll [USER32.dll!TranslateMessage] 00245919
IAT C:\Windows\system32\svchost.exe[1252] @ C:\Windows\system32\shell32.dll [ntdll.dll!NtQueryDirectoryFile] 002453AA
IAT C:\Windows\system32\SLsvc.exe[1280] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00CD53AA
IAT C:\Windows\system32\SLsvc.exe[1280] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00CD5291
IAT C:\Windows\system32\SLsvc.exe[1280] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00CD52F6
IAT C:\Windows\system32\SLsvc.exe[1280] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 00CD53AA
IAT C:\Windows\system32\SLsvc.exe[1280] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00CD566F
IAT C:\Windows\system32\SLsvc.exe[1280] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00CD5919
IAT C:\Windows\system32\SLsvc.exe[1280] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00CD5919
IAT C:\Windows\system32\SLsvc.exe[1280] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00CD566F
IAT C:\Windows\system32\SLsvc.exe[1280] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00CD5919
IAT C:\Windows\system32\SLsvc.exe[1280] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 00CD53AA
IAT C:\Windows\system32\rundll32.exe[1340] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00FC53AA
IAT C:\Windows\system32\rundll32.exe[1340] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00FC5291
IAT C:\Windows\system32\rundll32.exe[1340] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00FC52F6
IAT C:\Windows\system32\rundll32.exe[1340] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00FC566F
IAT C:\Windows\system32\rundll32.exe[1340] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00FC5919
IAT C:\Windows\system32\rundll32.exe[1340] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 00FC53AA
IAT C:\Windows\system32\rundll32.exe[1340] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00FC5919
IAT C:\Windows\system32\rundll32.exe[1340] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00FC566F
IAT C:\Windows\system32\rundll32.exe[1340] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00FC5919
IAT C:\Windows\system32\rundll32.exe[1340] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 00FC53AA
IAT C:\Windows\system32\svchost.exe[1364] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00E253AA
IAT C:\Windows\system32\svchost.exe[1364] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00E25291
IAT C:\Windows\system32\svchost.exe[1364] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00E252F6
IAT C:\Windows\system32\svchost.exe[1364] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00E2566F
IAT C:\Windows\system32\svchost.exe[1364] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00E25919
IAT C:\Windows\system32\svchost.exe[1364] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00E25919
IAT C:\Windows\system32\svchost.exe[1364] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 00E253AA
IAT C:\Windows\system32\svchost.exe[1364] @ C:\Windows\system32\shell32.dll [USER32.dll!GetClipboardData] 00E2566F
IAT C:\Windows\system32\svchost.exe[1364] @ C:\Windows\system32\shell32.dll [USER32.dll!TranslateMessage] 00E25919
IAT C:\Windows\system32\svchost.exe[1364] @ C:\Windows\system32\shell32.dll [ntdll.dll!NtQueryDirectoryFile] 00E253AA
IAT C:\Users\Juleila\Desktop\186.18_desktop_win7_winvista_32bit_english_whql.exe[1744] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [001D2F30] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Users\Juleila\Desktop\186.18_desktop_win7_winvista_32bit_english_whql.exe[1744] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [001D2D00] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Users\Juleila\Desktop\186.18_desktop_win7_winvista_32bit_english_whql.exe[1744] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [001D2CA0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Users\Juleila\Desktop\186.18_desktop_win7_winvista_32bit_english_whql.exe[1744] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [001D2CD0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\sdra64.exe[1924] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 014F53AA
IAT C:\Windows\system32\sdra64.exe[1924] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 014F5291
IAT C:\Windows\system32\sdra64.exe[1924] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 014F52F6
IAT C:\Windows\system32\sdra64.exe[1924] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 014F566F
IAT C:\Windows\system32\sdra64.exe[1924] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 014F5919
IAT C:\Windows\system32\sdra64.exe[1924] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 014F5919
IAT C:\Windows\system32\sdra64.exe[1924] @ C:\Windows\system32\shell32.dll [USER32.dll!GetClipboardData] 014F566F
IAT C:\Windows\system32\sdra64.exe[1924] @ C:\Windows\system32\shell32.dll [USER32.dll!TranslateMessage] 014F5919
IAT C:\Windows\system32\sdra64.exe[1924] @ C:\Windows\system32\shell32.dll [ntdll.dll!NtQueryDirectoryFile] 014F53AA
IAT C:\Windows\system32\sdra64.exe[1924] @ C:\Windows\system32\ws2_32.dll [ntdll.dll!NtQueryDirectoryFile] 014F53AA
IAT C:\Windows\system32\Dwm.exe[1948] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 04DB53AA
IAT C:\Windows\system32\Dwm.exe[1948] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 04DB5291
IAT C:\Windows\system32\Dwm.exe[1948] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 04DB52F6
IAT C:\Windows\system32\Dwm.exe[1948] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 04DB566F
IAT C:\Windows\system32\Dwm.exe[1948] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 04DB5919
IAT C:\Windows\system32\Dwm.exe[1948] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 04DB5919
IAT C:\Windows\system32\Dwm.exe[1948] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 04DB53AA
IAT C:\Windows\system32\Dwm.exe[1948] @ C:\Windows\system32\shell32.dll [USER32.dll!GetClipboardData] 04DB566F
IAT C:\Windows\system32\Dwm.exe[1948] @ C:\Windows\system32\shell32.dll [USER32.dll!TranslateMessage] 04DB5919
IAT C:\Windows\system32\Dwm.exe[1948] @ C:\Windows\system32\shell32.dll [ntdll.dll!NtQueryDirectoryFile] 04DB53AA
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [USER32.dll!TranslateMessage] 061C5919
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74747817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [7479A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7474BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7473F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [747475E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [7473E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74778395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7474DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [7473FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [7473FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [747371CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [747CCAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [7476C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [7473D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74736853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [7473687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74742AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [037D2F30] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [037D2D00] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [037D2CA0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 061C53AA
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [037D2CD0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 061C5291
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 061C52F6
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 061C5919
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 061C566F
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 061C5919
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 061C53AA
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 061C566F
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 061C5919
IAT C:\Windows\Explorer.EXE[1980] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 061C53AA
IAT C:\Program Files\Windows Defender\MSASCui.exe[2132] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 01B753AA
IAT C:\Program Files\Windows Defender\MSASCui.exe[2132] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 01B75291
IAT C:\Program Files\Windows Defender\MSASCui.exe[2132] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 01B752F6
IAT C:\Program Files\Windows Defender\MSASCui.exe[2132] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 01B7566F
IAT C:\Program Files\Windows Defender\MSASCui.exe[2132] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 01B75919
IAT C:\Program Files\Windows Defender\MSASCui.exe[2132] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 01B753AA
IAT C:\Program Files\Windows Defender\MSASCui.exe[2132] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 01B75919
IAT C:\Program Files\Windows Defender\MSASCui.exe[2132] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 01B7566F
IAT C:\Program Files\Windows Defender\MSASCui.exe[2132] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 01B75919
IAT C:\Program Files\Windows Defender\MSASCui.exe[2132] @ C:\Windows\system32\ws2_32.dll [ntdll.dll!NtQueryDirectoryFile] 01B753AA
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2148] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 01A653AA
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2148] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 01A65291
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2148] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 01A652F6
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2148] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 01A65919
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2148] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 01A6566F
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2148] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 01A65919
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2148] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 01A653AA
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2148] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 01A6566F
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2148] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 01A65919
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2148] @ C:\Windows\system32\ws2_32.dll [ntdll.dll!NtQueryDirectoryFile] 01A653AA
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[2316] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00BE2F30] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[2316] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00BE2D00] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[2316] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00BE2CA0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[2316] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 020053AA
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[2316] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00BE2CD0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[2316] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 02005291
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[2316] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 020052F6
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[2316] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0200566F
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[2316] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 02005919
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[2316] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 02005919
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[2316] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 020053AA
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[2316] @ C:\Windows\system32\shell32.dll [USER32.dll!GetClipboardData] 0200566F
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[2316] @ C:\Windows\system32\shell32.dll [USER32.dll!TranslateMessage] 02005919
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[2316] @ C:\Windows\system32\shell32.dll [ntdll.dll!NtQueryDirectoryFile] 020053AA
IAT C:\Program Files\Windows Media Player\wmpnetwk.exe[2464] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 016553AA
IAT C:\Program Files\Windows Media Player\wmpnetwk.exe[2464] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 01655291
IAT C:\Program Files\Windows Media Player\wmpnetwk.exe[2464] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 016552F6
IAT C:\Program Files\Windows Media Player\wmpnetwk.exe[2464] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0165566F
IAT C:\Program Files\Windows Media Player\wmpnetwk.exe[2464] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 01655919
IAT C:\Program Files\Windows Media Player\wmpnetwk.exe[2464] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 016553AA
IAT C:\Program Files\Windows Media Player\wmpnetwk.exe[2464] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 01655919
IAT C:\Program Files\Windows Media Player\wmpnetwk.exe[2464] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 0165566F
IAT C:\Program Files\Windows Media Player\wmpnetwk.exe[2464] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 01655919
IAT C:\Program Files\Windows Media Player\wmpnetwk.exe[2464] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 016553AA
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2656] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 01D853AA
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2656] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 01D85291
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2656] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 01D852F6
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2656] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 01D8566F
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2656] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 01D85919
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2656] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 01D853AA
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2656] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 01D85919
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2656] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 01D8566F
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2656] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 01D85919
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2656] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 01D853AA
IAT C:\Windows\system32\svchost.exe[2688] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 009653AA
IAT C:\Windows\system32\svchost.exe[2688] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00965291
IAT C:\Windows\system32\svchost.exe[2688] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 009652F6
IAT C:\Windows\system32\svchost.exe[2688] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0096566F
IAT C:\Windows\system32\svchost.exe[2688] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00965919
IAT C:\Windows\system32\svchost.exe[2688] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00965919
IAT C:\Windows\system32\svchost.exe[2688] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 0096566F
IAT C:\Windows\system32\svchost.exe[2688] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00965919
IAT C:\Windows\system32\svchost.exe[2688] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 009653AA
IAT C:\Windows\system32\svchost.exe[2688] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 009653AA
IAT C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00B853AA
IAT C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00B85291
IAT C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00B852F6
IAT C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00B85919
IAT C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00B8566F
IAT C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00B85919
IAT C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 00B853AA
IAT C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00B8566F
IAT C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00B85919
IAT C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] @ C:\Windows\system32\ws2_32.dll [ntdll.dll!NtQueryDirectoryFile] 00B853AA
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2880] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 015253AA
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2880] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 01525291
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2880] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 015252F6
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2880] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0152566F
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2880] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 01525919
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2880] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 0152566F
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2880] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 01525919
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2880] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 015253AA
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2880] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 01525919
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2880] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 015253AA
IAT C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2896] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 003053AA
IAT C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2896] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00305291
IAT C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2896] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 003052F6
IAT C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2896] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0030566F
IAT C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2896] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00305919
IAT C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2896] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 0030566F
IAT C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2896] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00305919
IAT C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2896] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 003053AA
IAT C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2896] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00305919
IAT C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2896] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 003053AA
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2912] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 021053AA
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2912] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 02105291
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2912] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 021052F6
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2912] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0210566F
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2912] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 02105919
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2912] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 0210566F
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2912] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 02105919
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2912] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 021053AA
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2912] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 02105919
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2912] @ C:\Windows\system32\ws2_32.dll [ntdll.dll!NtQueryDirectoryFile] 021053AA
IAT C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2960] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004653AA
IAT C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2960] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00465291
IAT C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2960] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004652F6
IAT C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2960] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0046566F
IAT C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2960] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00465919
IAT C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2960] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00465919
IAT C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2960] @ C:\Windows\system32\shell32.dll [USER32.dll!GetClipboardData] 0046566F
IAT C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2960] @ C:\Windows\system32\shell32.dll [USER32.dll!TranslateMessage] 00465919
IAT C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2960] @ C:\Windows\system32\shell32.dll [ntdll.dll!NtQueryDirectoryFile] 004653AA
IAT C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2960] @ C:\Windows\system32\ws2_32.dll [ntdll.dll!NtQueryDirectoryFile] 004653AA
IAT C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2996] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtQueryDirectoryFile] 00FA53AA
IAT C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2996] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!LdrGetProcedureAddress] 00FA5291
IAT C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2996] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!LdrLoadDll] 00FA52F6
IAT C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2996] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00FA566F
IAT C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2996] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00FA5919
IAT C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2996] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00FA5919
IAT C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2996] @ C:\Windows\system32\shell32.dll [USER32.dll!GetClipboardData] 00FA566F
IAT C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2996] @ C:\Windows\system32\shell32.dll [USER32.dll!TranslateMessage] 00FA5919
IAT C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2996] @ C:\Windows\system32\shell32.dll [ntdll.dll!NtQueryDirectoryFile] 00FA53AA
IAT C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2996] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 00FA53AA
IAT C:\Windows\system32\PnkBstrA.exe[3044] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00BE53AA
IAT C:\Windows\system32\PnkBstrA.exe[3044] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00BE5291
IAT C:\Windows\system32\PnkBstrA.exe[3044] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00BE52F6
IAT C:\Windows\system32\PnkBstrA.exe[3044] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 00BE53AA
IAT C:\Windows\system32\PnkBstrA.exe[3044] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00BE566F
IAT C:\Windows\system32\PnkBstrA.exe[3044] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00BE5919
IAT C:\Windows\system32\PnkBstrA.exe[3044] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 00BE53AA
IAT C:\Windows\system32\PnkBstrA.exe[3044] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00BE5919
IAT C:\Windows\system32\PnkBstrA.exe[3044] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00BE566F
IAT C:\Windows\system32\PnkBstrA.exe[3044] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00BE5919
IAT C:\Windows\system32\svchost.exe[3068] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00F553AA
IAT C:\Windows\system32\svchost.exe[3068] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00F55291
IAT C:\Windows\system32\svchost.exe[3068] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00F552F6
IAT C:\Windows\system32\svchost.exe[3068] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00F5566F
IAT C:\Windows\system32\svchost.exe[3068] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00F55919
IAT C:\Windows\system32\svchost.exe[3068] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00F55919
IAT C:\Windows\system32\svchost.exe[3068] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 00F553AA
IAT C:\Windows\system32\svchost.exe[3068] @ C:\Windows\system32\shell32.dll [USER32.dll!GetClipboardData] 00F5566F
IAT C:\Windows\system32\svchost.exe[3068] @ C:\Windows\system32\shell32.dll [USER32.dll!TranslateMessage] 00F55919
IAT C:\Windows\system32\svchost.exe[3068] @ C:\Windows\system32\shell32.dll [ntdll.dll!NtQueryDirectoryFile] 00F553AA
IAT C:\Windows\system32\svchost.exe[3092] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00D853AA
IAT C:\Windows\system32\svchost.exe[3092] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00D85291
IAT C:\Windows\system32\svchost.exe[3092] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00D852F6
IAT C:\Windows\system32\svchost.exe[3092] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00D8566F
IAT C:\Windows\system32\svchost.exe[3092] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00D85919
IAT C:\Windows\system32\svchost.exe[3092] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00D85919
IAT C:\Windows\system32\svchost.exe[3092] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00D8566F
IAT C:\Windows\system32\svchost.exe[3092] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00D85919
IAT C:\Windows\system32\svchost.exe[3092] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 00D853AA
IAT C:\Windows\system32\svchost.exe[3092] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 00D853AA
IAT C:\Windows\system32\svchost.exe[3168] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 015E53AA
IAT C:\Windows\system32\svchost.exe[3168] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 015E5291
IAT C:\Windows\system32\svchost.exe[3168] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 015E52F6
IAT C:\Windows\system32\svchost.exe[3168] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 015E566F
IAT C:\Windows\system32\svchost.exe[3168] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 015E5919
IAT C:\Windows\system32\svchost.exe[3168] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 015E5919
IAT C:\Windows\system32\svchost.exe[3168] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 015E53AA
IAT C:\Windows\system32\svchost.exe[3168] @ C:\Windows\system32\shell32.dll [USER32.dll!GetClipboardData] 015E566F
IAT C:\Windows\system32\svchost.exe[3168] @ C:\Windows\system32\shell32.dll [USER32.dll!TranslateMessage] 015E5919
IAT C:\Windows\system32\svchost.exe[3168] @ C:\Windows\system32\shell32.dll [ntdll.dll!NtQueryDirectoryFile] 015E53AA
IAT C:\Windows\System32\svchost.exe[3228] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00D353AA
IAT C:\Windows\System32\svchost.exe[3228] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00D35291
IAT C:\Windows\System32\svchost.exe[3228] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00D352F6
IAT C:\Windows\System32\svchost.exe[3228] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00D3566F
IAT C:\Windows\System32\svchost.exe[3228] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00D35919
IAT C:\Windows\System32\svchost.exe[3228] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00D35919
IAT C:\Windows\System32\svchost.exe[3228] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00D3566F
IAT C:\Windows\System32\svchost.exe[3228] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00D35919
IAT C:\Windows\System32\svchost.exe[3228] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 00D353AA
IAT C:\Windows\System32\svchost.exe[3228] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 00D353AA
IAT C:\Windows\system32\SearchIndexer.exe[3308] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 020E53AA
IAT C:\Windows\system32\SearchIndexer.exe[3308] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 020E5291
IAT C:\Windows\system32\SearchIndexer.exe[3308] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 020E52F6
IAT C:\Windows\system32\SearchIndexer.exe[3308] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 020E566F
IAT C:\Windows\system32\SearchIndexer.exe[3308] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 020E5919
IAT C:\Windows\system32\SearchIndexer.exe[3308] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 020E5919
IAT C:\Windows\system32\SearchIndexer.exe[3308] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 020E566F
IAT C:\Windows\system32\SearchIndexer.exe[3308] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 020E5919
IAT C:\Windows\system32\SearchIndexer.exe[3308] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 020E53AA
IAT C:\Windows\system32\SearchIndexer.exe[3308] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 020E53AA
IAT C:\Users\Juleila\AppData\Local\Temp\Rar$EX00.778\gmer.exe[3932] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [01592F30] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Users\Juleila\AppData\Local\Temp\Rar$EX00.778\gmer.exe[3932] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [01592D00] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Users\Juleila\AppData\Local\Temp\Rar$EX00.778\gmer.exe[3932] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [01592CA0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Users\Juleila\AppData\Local\Temp\Rar$EX00.778\gmer.exe[3932] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [01592CD0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3968] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00902F30] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3968] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00902D00] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3968] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00902CA0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3968] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00902CD0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Java\jre6\bin\java.exe[4072] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00192F30] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Java\jre6\bin\java.exe[4072] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00192D00] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Java\jre6\bin\java.exe[4072] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00192CA0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Java\jre6\bin\java.exe[4072] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00192CD0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\System32\svchost.exe[4764] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 01C553AA
IAT C:\Windows\System32\svchost.exe[4764] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 01C55291
IAT C:\Windows\System32\svchost.exe[4764] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 01C552F6
IAT C:\Windows\System32\svchost.exe[4764] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 01C553AA
IAT C:\Windows\System32\svchost.exe[4764] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 01C5566F
IAT C:\Windows\System32\svchost.exe[4764] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 01C55919
IAT C:\Windows\System32\svchost.exe[4764] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 01C55919
IAT C:\Windows\System32\svchost.exe[4764] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 01C5566F
IAT C:\Windows\System32\svchost.exe[4764] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 01C55919
IAT C:\Windows\System32\svchost.exe[4764] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 01C553AA
IAT C:\Program Files\Internet Explorer\iexplore.exe[5164] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00582F30] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5164] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00582D00] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5164] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00582CA0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5164] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00582CD0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\taskeng.exe[5476] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 003353AA
IAT C:\Windows\system32\taskeng.exe[5476] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00335291
IAT C:\Windows\system32\taskeng.exe[5476] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 003352F6
IAT C:\Windows\system32\taskeng.exe[5476] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 0033566F
IAT C:\Windows\system32\taskeng.exe[5476] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00335919
IAT C:\Windows\system32\taskeng.exe[5476] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] 003353AA
IAT C:\Windows\system32\taskeng.exe[5476] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00335919
IAT C:\Windows\system32\taskeng.exe[5476] @ C:\Windows\system32\ole32.dll [USER32.dll!GetClipboardData] 0033566F
IAT C:\Windows\system32\taskeng.exe[5476] @ C:\Windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00335919
IAT C:\Windows\system32\taskeng.exe[5476] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!NtQueryDirectoryFile] 003353AA
IAT C:\Windows\system32\notepad.exe[8476] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [01502F30] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\notepad.exe[8476] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [01502D00] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\notepad.exe[8476] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [01502CA0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\notepad.exe[8476] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [01502CD0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\notepad.exe[9164] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00342F30] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\notepad.exe[9164] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00342D00] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\notepad.exe[9164] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00342CA0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\notepad.exe[9164] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00342CD0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 855231F8
Device \FileSystem\fastfat \FatCdrom 86EBF2C0
Device \FileSystem\udfs \UdfsCdRom 86CC5500
Device \FileSystem\udfs \UdfsDisk 86CC5500
Device \Driver\volmgr \Device\VolMgrControl 847641F8
Device \Driver\usbuhci \Device\USBPDO-0 865611F8
Device \Driver\usbuhci \Device\USBPDO-1 865611F8
Device \Driver\usbuhci \Device\USBPDO-2 865611F8
Device \Driver\usbuhci \Device\USBPDO-3 865611F8
Device \Driver\usbehci \Device\USBPDO-4 865681F8

AttachedDevice \Driver\tdx \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

Device \Driver\sptd \Device\1219416972 spwv.sys
Device \Driver\volmgr \Device\HarddiskVolume1 847641F8
Device \Driver\volmgr \Device\HarddiskVolume2 847641F8
Device \Driver\cdrom \Device\CdRom0 854B91F8
Device \Driver\volmgr \Device\HarddiskVolume3 847641F8
Device \Driver\USBSTOR \Device\00000066 86BFC1F8
Device \Driver\volmgr \Device\HarddiskVolume4 847641F8
Device \Driver\USBSTOR \Device\00000067 86BFC1F8
Device \Driver\USBSTOR \Device\00000069 86BFC1F8
Device \Driver\netbt \Device\NetBt_Wins_Export 86B3C1F8
Device \Driver\Smb \Device\NetbiosSmb 86B321F8
Device \Driver\PCI_PNP8964 \Device\0000004e spwv.sys
Device \Driver\iScsiPrt \Device\RaidPort0 8666C1F8
Device \Driver\USBSTOR \Device\0000006c 86BFC1F8
Device \Driver\usbuhci \Device\USBFDO-0 865611F8
Device \Driver\USBSTOR \Device\0000006d 86BFC1F8
Device \Driver\usbuhci \Device\USBFDO-1 865611F8
Device \Driver\USBSTOR \Device\0000006e 86BFC1F8
Device \Driver\usbuhci \Device\USBFDO-2 865611F8
Device \Driver\USBSTOR \Device\0000006f 86BFC1F8
Device \Driver\usbuhci \Device\USBFDO-3 865611F8
Device \Driver\usbehci \Device\USBFDO-4 865681F8
Device \Driver\netbt \Device\NetBT_Tcpip_{F5ED3C92-B228-4C67-8FC2-B28321898FD0} 86B3C1F8
Device \Driver\a4lh0311 \Device\Scsi\a4lh03111Port5Path0Target0Lun0 865641F8
Device \Driver\a4lh0311 \Device\Scsi\a4lh03111 865641F8
Device \Driver\a4lh0311 \Device\Scsi\a4lh03111Port5Path0Target1Lun0 865641F8
Device \FileSystem\fastfat \Fat 86EBF2C0

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\cdfs \Cdfs 874521F8

—- EOF - GMER 1.0.15 —-
Hi,

One of the infections on your computer is known as an info stealer. This has the ability to steal personal information from your computer.
From a clean computer you should change all your passwords and notify your financial institutions of the situation.

I can clean this computer, but of course cannot make guarantees that it will be 100% trustworthy again, the only way for that would be a total reformat/reinstall. Please advise your wishes.

If you wish to continue cleaning, please do the following:

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
thank a lot for looking at my problem and for your time :notworthy:

this is my combo fix log




ComboFix 09-07-20.05 - Juleila 07/21/2009 13:33.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3071.1945 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-3917738136-2676680180-1288316716-500
c:\windows\Installer\12610ae.msi
c:\windows\patch.exe
c:\windows\system32\drivers\hjgruiswfrrxcn.sys
c:\windows\system32\hjgruiptyditba.dat
c:\windows\system32\hjgruiqcnqnfao.dat
c:\windows\system32\hjgruitfceyvxc.dll
c:\windows\system32\hjgruiwpiibptv.dll
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_hjgruiigmufiib


((((((((((((((((((((((((( Files Created from 2009-06-21 to 2009-07-21 )))))))))))))))))))))))))))))))
.

2009-07-21 18:41 . 2009-07-21 18:41 ——– d—–w- c:\users\Juleila\AppData\Local\temp
2009-07-21 06:39 . 2009-07-21 06:39 ——– d—–w- c:\users\Juleila\AppData\Roaming\Malwarebytes
2009-07-21 06:39 . 2009-07-13 18:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-21 06:39 . 2009-07-21 06:39 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-21 06:39 . 2009-07-21 06:39 ——– d—–w- c:\programdata\Malwarebytes
2009-07-21 06:39 . 2009-07-13 18:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-19 04:26 . 2009-07-19 02:08 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-07-19 01:08 . 2009-07-19 01:08 ——– dc-h–w- c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-07-19 01:08 . 2009-01-18 21:43 2892112 -c–a-w- c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe
2009-07-18 20:47 . 2009-07-19 19:34 139152 —-a-w- c:\users\Juleila\AppData\Roaming\PnkBstrK.sys
2009-07-18 20:47 . 2009-07-19 19:34 794408 —-a-w- c:\windows\system32\pbsvc.exe
2009-07-18 20:27 . 2009-07-19 19:17 ——– d—–w- c:\program files\EA Games
2009-07-15 20:44 . 2009-07-20 19:51 ——– d—–w- c:\program files\Yahoo!
2009-07-15 17:40 . 2009-06-15 14:53 156672 —-a-w- c:\windows\system32\t2embed.dll
2009-07-15 17:40 . 2009-06-15 14:52 23552 —-a-w- c:\windows\system32\lpk.dll
2009-07-15 17:40 . 2009-06-15 14:52 72704 —-a-w- c:\windows\system32\fontsub.dll
2009-07-15 17:40 . 2009-06-15 14:51 10240 —-a-w- c:\windows\system32\dciman32.dll
2009-07-15 17:40 . 2009-06-15 12:42 289792 —-a-w- c:\windows\system32\atmfd.dll
2009-07-09 06:15 . 2009-07-09 06:15 ——– d—–w- c:\users\Juleila\AppData\Local\CAPCOM
2009-07-09 06:05 . 2009-07-09 06:05 ——– d—–w- c:\program files\CAPCOM
2009-07-09 05:15 . 2009-07-09 05:15 ——– d—–w- c:\program files\Smart Projects
2009-07-08 05:26 . 2009-07-08 05:26 ——– d—–w- c:\users\Juleila\AppData\Roaming\Reallusion
2009-07-08 05:17 . 2009-07-08 05:17 ——– d—–w- c:\program files\Common Files\Reallusion
2009-07-05 05:53 . 2009-03-30 15:32 96104 —-a-w- c:\windows\system32\drivers\avipbb.sys
2009-07-05 05:53 . 2009-03-24 21:07 55640 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-07-05 05:53 . 2009-07-05 05:53 ——– d—–w- c:\programdata\Avira
2009-07-05 05:53 . 2009-07-05 05:53 ——– d—–w- c:\program files\Avira
2009-07-04 01:24 . 2009-06-14 00:54 1663488 —-a-w- c:\windows\system32\BootMan.exe
2009-07-04 01:24 . 2009-04-22 19:27 14848 —-a-w- c:\windows\system32\EuEpmGdi.dll
2009-07-04 01:24 . 2009-04-22 19:28 9728 —-a-w- c:\windows\system32\epmntdrv.sys
2009-07-04 01:24 . 2009-04-22 19:28 86408 —-a-w- c:\windows\system32\setupempdrv03.exe
2009-07-04 01:24 . 2009-04-22 19:28 3072 —-a-w- c:\windows\system32\EuGdiDrv.sys
2009-07-04 01:24 . 2009-07-04 01:24 ——– d—–w- c:\program files\EASEUS
2009-07-03 21:58 . 2009-07-03 21:58 ——– d—–w- c:\users\Juleila\AppData\Roaming\PeerNetworking
2009-07-03 19:50 . 2009-07-03 19:53 364544 —-a-w- c:\windows\system32\WDBtnMgr.exe
2009-06-29 18:27 . 2009-06-29 18:27 ——– d—–w- c:\users\Juleila\AppData\Local\Downloaded Installations
2009-06-29 18:27 . 2009-06-29 18:27 ——– d—–w- c:\program files\Common Files\LightScribe
2009-06-29 18:25 . 2009-06-29 18:25 ——– d—–w- c:\program files\Common Files\muvee Technologies
2009-06-29 18:25 . 2009-06-29 18:25 ——– d—–w- c:\program files\NewTech Infosystems
2009-06-29 17:23 . 2009-06-29 17:24 ——– d—–w- c:\windows\system32\ca-ES
2009-06-29 17:23 . 2009-06-29 17:24 ——– d—–w- c:\windows\system32\eu-ES
2009-06-29 17:23 . 2009-06-29 17:24 ——– d—–w- c:\windows\system32\vi-VN
2009-06-29 16:56 . 2009-06-29 16:56 ——– d—–w- c:\windows\system32\EventProviders
2009-06-29 16:54 . 2009-04-11 06:28 164352 —-a-w- c:\windows\system32\spwizui.dll
2009-06-29 16:53 . 2009-04-11 06:28 83968 —-a-w- c:\windows\system32\wbem\wmiutils.dll
2009-06-29 16:53 . 2009-04-11 06:28 30208 —-a-w- c:\windows\system32\wbem\wbemprox.dll
2009-06-29 16:53 . 2009-04-11 06:28 189440 —-a-w- c:\windows\system32\wbem\mofd.dll
2009-06-29 16:53 . 2009-04-11 06:28 265728 —-a-w- c:\windows\system32\wbem\esscli.dll
2009-06-29 16:53 . 2009-04-11 06:28 744448 —-a-w- c:\windows\system32\wbem\wbemcore.dll
2009-06-29 16:53 . 2009-04-11 06:28 265728 —-a-w- c:\windows\system32\wbem\repdrvfs.dll
2009-06-29 16:53 . 2009-04-11 06:28 614912 —-a-w- c:\windows\system32\wbem\fastprox.dll
2009-06-29 16:53 . 2009-04-11 06:28 705536 —-a-w- c:\windows\system32\SmiEngine.dll
2009-06-29 16:53 . 2009-04-11 06:28 218624 —-a-w- c:\windows\system32\wdscore.dll
2009-06-29 16:53 . 2009-04-11 06:27 130560 —-a-w- c:\windows\system32\PkgMgr.exe
2009-06-29 16:53 . 2009-04-11 06:28 247808 —-a-w- c:\windows\system32\drvstore.dll
2009-06-28 16:01 . 2009-06-28 16:01 746744 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-06-22 01:31 . 2009-06-22 01:31 ——– d—–w- c:\program files\Common Files\Bcgsoft
2009-06-22 01:29 . 2004-07-14 17:54 676864 —-a-w- c:\windows\system32\drivers\hardlock.sys
2009-06-22 01:28 . 1999-04-13 04:00 1046288 ——w- c:\windows\system32\Msjet35.dll
2009-06-22 01:28 . 1998-04-24 04:00 368912 ——w- c:\windows\system32\Vbar332.dll
2009-06-22 01:28 . 1998-04-24 04:00 252176 ——w- c:\windows\system32\Msrd2x35.dll
2009-06-22 01:28 . 1998-04-24 04:00 24848 ——w- c:\windows\system32\Msjter35.dll
2009-06-22 01:28 . 1998-04-24 04:00 123664 ——w- c:\windows\system32\Msjint35.dll
2009-06-22 01:28 . 1996-11-17 05:00 290816 ——w- c:\windows\system32\Msxbse35.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-21 18:32 . 2009-07-21 05:54 32061 —-a-w- c:\programdata\nvModes.dat
2009-07-21 18:32 . 2008-07-08 20:36 ——– d—–w- c:\programdata\NVIDIA
2009-07-21 03:09 . 2008-07-26 21:43 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-07-21 03:09 . 2008-09-22 02:12 ——– d—–w- c:\program files\AGEIA Technologies
2009-07-21 01:06 . 2008-07-10 03:26 ——– d—–w- c:\users\Juleila\AppData\Roaming\GrabIt
2009-07-21 00:23 . 2008-07-08 20:57 ——– d—–w- c:\program files\Warcraft III
2009-07-20 22:57 . 2008-05-07 09:14 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-20 22:57 . 2008-05-07 09:14 319456 —-a-w- c:\windows\DIFxAPI.dll
2009-07-20 07:11 . 2008-09-06 18:28 ——– d—–w- c:\users\Juleila\AppData\Roaming\Gizmo5
2009-07-19 19:34 . 2008-07-12 19:05 139152 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-07-19 19:34 . 2008-07-12 19:05 111928 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-07-19 01:08 . 2008-08-20 18:29 ——– d—–w- c:\program files\Lavasoft
2009-07-18 20:57 . 2008-05-07 09:30 ——– d—–w- c:\program files\Google
2009-07-18 20:56 . 2008-05-07 09:35 ——– d—–w- c:\programdata\WildTangent
2009-07-18 20:55 . 2009-04-25 15:16 ——– d—–w- c:\program files\Astonsoft
2009-07-15 18:11 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-07-14 23:07 . 2008-12-25 07:38 ——– d—–w- c:\program files\Steam
2009-07-09 17:19 . 2008-08-05 04:54 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2009-07-06 22:55 . 2008-12-25 07:38 ——– d—–w- c:\program files\Common Files\Steam
2009-07-04 01:06 . 2008-05-07 09:13 ——– d—–w- c:\program files\Common Files\InstallShield
2009-06-29 17:24 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Calendar
2009-06-29 17:24 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Sidebar
2009-06-29 17:24 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Journal
2009-06-29 17:24 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Collaboration
2009-06-29 17:24 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Photo Gallery
2009-06-29 17:24 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Defender
2009-06-29 17:23 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-06-29 17:04 . 2006-11-02 12:37 37665 —-a-w- c:\windows\Fonts\GlobalUserInterface.CompositeFont
2009-06-27 01:31 . 2008-07-10 03:52 ——– d—–w- c:\users\Juleila\AppData\Roaming\Azureus
2009-06-23 15:25 . 2008-07-10 03:51 ——– d—–w- c:\program files\Vuze
2009-06-20 21:14 . 2009-04-29 04:21 ——– d—–w- c:\program files\a-squared HiJackFree
2009-06-20 18:18 . 2008-07-08 21:33 ——– d—–w- c:\program files\World of Warcraft
2009-06-13 16:13 . 2009-06-13 16:13 ——– d—–w- c:\users\Juleila\AppData\Roaming\TeamViewer
2009-06-13 00:31 . 2008-05-07 09:27 ——– d—–w- c:\programdata\Microsoft Help
2009-06-10 18:40 . 2009-06-10 18:37 ——– d—–w- c:\programdata\Yahoo!
2009-06-10 13:35 . 2009-06-10 13:35 1194528 —-a-w- c:\windows\system32\nvcplui.exe
2009-06-10 13:35 . 2009-06-10 13:35 1296928 —-a-w- c:\windows\system32\nvsvs.dll
2009-06-10 13:34 . 2009-06-10 13:34 3123744 —-a-w- c:\windows\system32\nvwss.dll
2009-06-10 13:34 . 2009-06-10 13:34 4045344 —-a-w- c:\windows\system32\nvvitvs.dll
2009-06-10 13:34 . 2009-06-10 13:34 4028960 —-a-w- c:\windows\system32\nvdisps.dll
2009-06-10 13:34 . 2009-06-10 13:34 3516960 —-a-w- c:\windows\system32\nvgames.dll
2009-06-10 13:34 . 2009-06-10 13:34 211488 —-a-w- c:\windows\system32\nvvsvc.exe
2009-06-10 13:34 . 2009-06-10 13:34 195104 —-a-w- c:\windows\system32\nvmccss.dll
2009-06-10 13:34 . 2009-06-10 13:34 1288736 —-a-w- c:\windows\system32\nvmobls.dll
2009-06-10 13:34 . 2009-06-10 13:34 92704 —-a-w- c:\windows\system32\nvmctray.dll
2009-06-10 13:34 . 2009-06-10 13:34 768544 —-a-w- c:\windows\system32\nvsvc.dll
2009-06-10 13:34 . 2009-06-10 13:34 143360 —-a-w- c:\windows\system32\nvshext.dll
2009-06-10 13:34 . 2009-06-10 13:34 13785632 —-a-w- c:\windows\system32\nvcpl.dll
2009-06-10 11:33 . 2009-06-10 11:33 244736 —-a-w- c:\windows\system32\nvStInst.exe
2009-06-10 11:33 . 2009-06-10 11:33 467968 —-a-w- c:\windows\system32\nvstlink.exe
2009-06-10 11:33 . 2009-06-10 11:33 3953152 —-a-w- c:\windows\system32\nvstwiz.exe
2009-06-10 11:33 . 2009-06-10 11:33 141824 —-a-w- c:\windows\system32\nvStereoApiI.dll
2009-06-10 11:33 . 2009-06-10 11:33 171520 —-a-w- c:\windows\system32\nvStereoApiI64.dll
2009-06-10 11:33 . 2009-06-10 11:33 232960 —-a-w- c:\windows\system32\nvSCPAPISvr.exe
2009-06-10 11:32 . 2009-06-10 11:32 257536 —-a-w- c:\windows\system32\nvSCPAPI.dll
2009-06-10 11:32 . 2009-06-10 11:32 301568 —-a-w- c:\windows\system32\nvSCPAPI64.dll
2009-06-10 11:32 . 2009-06-10 11:32 3293184 —-a-w- c:\windows\system32\nvstres.dll
2009-06-10 11:32 . 2009-06-10 11:32 5847 —-a-w- c:\windows\system32\oglstreg.reg
2009-06-10 11:31 . 2009-06-10 11:31 167424 —-a-w- c:\windows\system32\nvstreg.exe
2009-06-10 11:31 . 2009-06-10 11:31 1718272 —-a-w- c:\windows\system32\nvsttest.exe
2009-06-10 11:31 . 2009-06-10 11:31 1034752 —-a-w- c:\windows\system32\nvstview.exe
2009-06-10 11:31 . 2009-06-10 11:31 89088 —-a-w- c:\windows\system32\nvimage.dll
2009-06-10 11:29 . 2009-06-10 11:29 1656 —-a-w- c:\windows\system32\nvstdef.reg
2009-06-10 11:03 . 2009-06-10 11:03 9899296 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys
2009-06-10 11:03 . 2009-06-10 11:03 678432 —-a-w- c:\windows\system32\nvcuvid.dll
2009-06-10 11:03 . 2009-06-10 11:03 457248 —-a-w- c:\windows\system32\nvudisp.exe
2009-06-10 11:03 . 2009-06-10 11:03 4224 —-a-w- c:\windows\system32\drivers\nvBridge.kmd
2009-06-10 11:03 . 2009-06-10 11:03 3148288 —-a-w- c:\windows\system32\nvwgf2um.dll
2009-06-10 11:03 . 2009-06-10 11:03 1704960 —-a-w- c:\windows\system32\nvcuda.dll
2009-06-10 11:03 . 2009-06-10 11:03 151552 —-a-w- c:\windows\system32\nvcod155.dll
2009-06-10 11:03 . 2009-06-10 11:03 151552 —-a-w- c:\windows\system32\nvcod.dll
2009-06-10 11:03 . 2009-06-10 11:03 1317408 —-a-w- c:\windows\system32\nvcuvenc.dll
2009-06-10 11:03 . 2009-06-10 11:03 10379264 —-a-w- c:\windows\system32\nvoglv32.dll
2009-06-10 11:03 . 2008-05-16 21:01 989696 —-a-w- c:\windows\system32\nvapi.dll
2009-06-10 11:03 . 2008-05-16 21:01 7611904 —-a-w- c:\windows\system32\nvd3dum.dll
2009-06-04 21:39 . 2008-07-08 20:33 457248 —-a-w- c:\windows\system32\NVUNINST.EXE
2009-06-04 00:59 . 2008-05-07 09:25 ——– d—–w- c:\program files\Common Files\Adobe
2009-05-23 20:23 . 2008-07-08 08:59 100672 —-a-w- c:\users\Juleila\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-23 19:32 . 2009-05-23 19:32 ——– d—–w- c:\program files\Microsoft Silverlight
2009-05-23 19:32 . 2008-08-05 04:45 ——– d—–w- c:\program files\Common Files\LogiShrd
2009-05-23 19:28 . 2008-05-07 09:16 ——– d—–w- c:\program files\Microsoft Works
2009-05-23 18:49 . 2009-05-23 18:49 ——– d—–w- c:\program files\Microsoft
2009-05-23 18:49 . 2008-07-08 20:39 ——– d—–w- c:\program files\Windows Live
2009-05-23 18:49 . 2009-05-23 18:49 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-05-23 18:44 . 2009-05-23 18:44 ——– d—–w- c:\program files\Common Files\Windows Live
2009-05-15 23:47 . 2009-05-15 23:47 416128 —-a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2009-05-09 05:50 . 2009-06-11 23:52 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-11 23:51 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-05-05 04:29 . 2009-01-02 23:33 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-04-28 14:55 . 2009-04-28 14:55 70936 —-a-w- c:\windows\system32\PhysXLoader.dll
2009-04-23 12:15 . 2009-06-11 23:51 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:14 . 2009-06-11 23:52 623616 —-a-w- c:\windows\system32\localspl.dll
2009-03-25 17:05 . 2009-03-25 17:04 24 –sha-w- c:\windows\S82706D69.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-19 520024]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13785632]

c:\users\Juleila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
PnkBstrA - Shortcut.lnk - c:\windows\System32\PnkBstrA.exe [2008-7-12 66872]
PnkBstrB - Shortcut.lnk - c:\windows\System32\PnkBstrB.exe [2008-7-12 111928]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BigFix.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\BigFix.lnk
backup=c:\windows\pss\BigFix.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
backup=c:\windows\pss\Ralink Wireless Utility.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Juleila^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Juleila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"SerialNumber"="A109A-K13-3ZXD-BAP5-TE"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):84,9e,0b,6a,df,f8,c9,01

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{2FDC24FC-38B7-4E24-9CBF-10E45027AD74}"= UDP:c:\punkbuster\PB.EXE:PB
"{917DB984-BBD3-4D41-9E49-3E3EF02C6198}"= TCP:c:\punkbuster\PB.EXE:PB
"TCP Query User{B84C81B3-C59A-444C-9636-0C5E7E70CA20}c:\\program files\\warcraft iii\\war3.exe"= UDP:c:\program files\warcraft iii\war3.exe:Warcraft III
"UDP Query User{CEA7A199-1079-44B9-837A-0139567EFD4B}c:\\program files\\warcraft iii\\war3.exe"= TCP:c:\program files\warcraft iii\war3.exe:Warcraft III
"{3D61F270-B267-4604-BC39-CC95A8011F09}"= UDP:c:\program files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{AC178EE2-6917-49EE-A3E5-E69804E095E7}"= TCP:c:\program files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{056B3025-924C-459E-83A0-CD658B98A0E7}"= UDP:c:\program files\World of Warcraft\Launcher.exe:Midgar Launcher
"{D12E7D56-9B34-4190-A5B1-6A406733EFBF}"= TCP:c:\program files\World of Warcraft\Launcher.exe:Midgar Launcher
"{213DD519-AE22-4BDD-9A32-BF1F5DA84062}"= UDP:c:\program files\GrabIt\GrabIt.exe:GrabIt
"{F0FAD0FA-384E-4CB3-896C-F10F2E3BB606}"= TCP:c:\program files\GrabIt\GrabIt.exe:GrabIt
"TCP Query User{5819AC9B-07C8-4CB6-AECC-3D6CBBE1CE41}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{23056C45-D150-4215-B5AB-2436C439FAA2}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"{31F50491-E6A2-4BD8-87B9-F6C50F0513F4}"= UDP:c:\program files\WowCartographe\WowCartographe.exe:Wow Cartographe
"{92038FBB-714E-4023-BB63-82095824D25D}"= TCP:c:\program files\WowCartographe\WowCartographe.exe:Wow Cartographe
"{6F3ADFBE-CFB4-4CF5-B823-D1F6DDF35FDD}"= UDP:c:\program files\TomTom HOME 2\TomTomHOME.exe:TomTom HOME 2
"{BD056E37-4B1D-4F35-AD78-008067E31E16}"= TCP:c:\program files\TomTom HOME 2\TomTomHOME.exe:TomTom HOME 2
"{AB614AF2-1E70-4E2F-AC87-6416B60A7002}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{FE8AB8E2-A463-4761-946A-9C5596BC773C}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"TCP Query User{E3F4911D-6C91-496B-B72C-52B6A09FC088}c:\\program files\\dialsoft\\the 4th coming\\prophetie.exe"= UDP:c:\program files\dialsoft\the 4th coming\prophetie.exe:prophetie
"UDP Query User{95443F7C-FCF2-4D50-A252-0FC36098A26D}c:\\program files\\dialsoft\\the 4th coming\\prophetie.exe"= TCP:c:\program files\dialsoft\the 4th coming\prophetie.exe:prophetie
"{4AD0ADBF-845E-4CC7-A12B-89650D9A8050}"= UDP:c:\program files\Dialsoft\The 4th Coming\T4C.exe:The 4th Coming
"{7B5E5596-8A8B-4663-8032-87D3FC3D7783}"= TCP:c:\program files\Dialsoft\The 4th Coming\T4C.exe:The 4th Coming
"{BC016BFD-2EDE-4A4E-AC77-E83A16EE4806}"= Disabled:UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{03B853D9-0BE8-4F3A-A7CB-406F734481B5}"= Disabled:TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{87D194A0-90B0-4A80-861E-CC61EF5047F7}"= Disabled:UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{EE9E208C-7B89-4FAE-85C1-89DCD36523B4}"= Disabled:TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{F05D01C4-CB90-4546-B978-FCA350154088}"= Disabled:UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{46C5A45A-ED3E-449A-B7BC-0646CBD441FB}"= Disabled:TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B8088D13-00AA-44EC-8617-16DD917CFAC7}"= UDP:c:\program files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe:Ad-Aware 2007
"{463A1FEF-4228-4E54-811B-0159905690EA}"= TCP:c:\program files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe:Ad-Aware 2007
"{2B9E0081-3606-426B-A151-BCE1A9C4A112}"= UDP:c:\program files\Gizmo5\Gizmo5.exe:Gizmo5
"{E0FDFD37-C127-4963-854E-962A9EAB2141}"= TCP:c:\program files\Gizmo5\Gizmo5.exe:Gizmo5
"TCP Query User{60D5B432-3C70-480D-B052-1B8B7142B881}c:\\users\\juleila\\desktop\\fallout 3\\f3.exe"= UDP:c:\users\juleila\desktop\fallout 3\f3.exe:f3.exe
"UDP Query User{8CECB9C6-9C1D-465A-8965-96849BE7BE5F}c:\\users\\juleila\\desktop\\fallout 3\\f3.exe"= TCP:c:\users\juleila\desktop\fallout 3\f3.exe:f3.exe
"TCP Query User{F0560E1D-8DF6-40FF-9C9D-1D21078A9911}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{E6F9F58E-F111-4831-B6C7-E0FA5BCF17B0}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"TCP Query User{B4DF33BF-EFA9-44EC-A603-015B39F631D1}c:\\program files\\systran\\6\\systrandictionarymanager.exe"= UDP:c:\program files\systran\6\systrandictionarymanager.exe:SYSTRAN Dictionary Manager
"UDP Query User{569B1F7A-94EB-47A2-A033-2D5719E091A7}c:\\program files\\systran\\6\\systrandictionarymanager.exe"= TCP:c:\program files\systran\6\systrandictionarymanager.exe:SYSTRAN Dictionary Manager
"TCP Query User{8929B867-B771-4041-9FD9-D0A70134A965}c:\\program files\\systran\\6\\systrantoolbar.exe"= UDP:c:\program files\systran\6\systrantoolbar.exe:SYSTRAN Translation Toolbar
"UDP Query User{1F98FA33-515C-462E-8077-7A43EC02859E}c:\\program files\\systran\\6\\systrantoolbar.exe"= TCP:c:\program files\systran\6\systrantoolbar.exe:SYSTRAN Translation Toolbar
"TCP Query User{75428348-D5F6-4850-8BF6-0A98A2A75FB5}c:\\program files\\systran\\6\\dicts\\systrantranslationengine.exe"= UDP:c:\program files\systran\6\dicts\systrantranslationengine.exe:Systran Translation Engine
"UDP Query User{5E0D72A9-321E-4B5D-A9D2-F11E0B6D8357}c:\\program files\\systran\\6\\dicts\\systrantranslationengine.exe"= TCP:c:\program files\systran\6\dicts\systrantranslationengine.exe:Systran Translation Engine
"{E86522B2-1D36-4C94-8C9C-DA4C50535C5A}"= UDP:c:\program files\Dialsoft\The 4th Coming\WebPatch.exe:WebPatch
"{757886F2-E1D6-4629-8A96-544980499111}"= TCP:c:\program files\Dialsoft\The 4th Coming\WebPatch.exe:WebPatch
"TCP Query User{87FDF4FB-FE4F-4F7B-B40D-76DB133EB82B}c:\\program files\\gizmo5\\gizmo5.exe"= UDP:c:\program files\gizmo5\gizmo5.exe:Gizmo5
"UDP Query User{EE599444-A7C9-464A-9148-2723571B21E2}c:\\program files\\gizmo5\\gizmo5.exe"= TCP:c:\program files\gizmo5\gizmo5.exe:Gizmo5
"TCP Query User{0E0CA0F0-8CE7-459E-BCCA-58CB4E32CC90}c:\\program files\\warcraft iii\\war3.exe"= UDP:c:\program files\warcraft iii\war3.exe:Warcraft III
"UDP Query User{4055F60E-E451-4CF5-99EC-AA045C5701F4}c:\\program files\\warcraft iii\\war3.exe"= TCP:c:\program files\warcraft iii\war3.exe:Warcraft III
"TCP Query User{076468F2-A489-48FC-83BB-E0B51E15B356}c:\\program files\\systran\\6\\systrantranslationprojectmanager.exe"= UDP:c:\program files\systran\6\systrantranslationprojectmanager.exe:SystranTranslationProjectManager
"UDP Query User{6EECB6B2-AD0D-4CB9-B4FC-C2BDD69DFFAC}c:\\program files\\systran\\6\\systrantranslationprojectmanager.exe"= TCP:c:\program files\systran\6\systrantranslationprojectmanager.exe:SystranTranslationProjectManager
"TCP Query User{94FBB679-630E-4B29-A7DD-4FF5DA96611A}c:\\program files\\systran\\6\\systrandictionarymanager.exe"= UDP:c:\program files\systran\6\systrandictionarymanager.exe:SYSTRAN Dictionary Manager
"UDP Query User{CA7BA89E-9969-49F5-AAB4-0536C43E2481}c:\\program files\\systran\\6\\systrandictionarymanager.exe"= TCP:c:\program files\systran\6\systrandictionarymanager.exe:SYSTRAN Dictionary Manager
"TCP Query User{40D60EFB-0550-45BF-98E1-53DF196CEA62}c:\\program files\\systran\\6\\dicts\\systrantranslationengine.exe"= UDP:c:\program files\systran\6\dicts\systrantranslationengine.exe:Systran Translation Engine
"UDP Query User{23CD75F7-EE93-48A1-AF00-1C2E043ABF14}c:\\program files\\systran\\6\\dicts\\systrantranslationengine.exe"= TCP:c:\program files\systran\6\dicts\systrantranslationengine.exe:Systran Translation Engine
"TCP Query User{D006E1C4-834A-4B50-A64C-03567CC0C779}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{28C17CA5-C819-45AA-BCED-826D103D22F3}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"{7463C5AD-79E8-4407-B9D2-FBFA28C78761}"= UDP:c:\program files\Gizmo Project\Gizmo.exe:Gizmo Project
"{772040DF-BE78-4627-922F-2CC52C28035D}"= TCP:c:\program files\Gizmo Project\Gizmo.exe:Gizmo Project
"TCP Query User{0467111F-4A7E-41CA-8E3C-AB2C3B038B17}c:\\program files\\left 4 dead\\left4dead.exe"= UDP:c:\program files\left 4 dead\left4dead.exe:left4dead
"UDP Query User{AF842A24-A442-43FD-AFC2-79D63697AF4D}c:\\program files\\left 4 dead\\left4dead.exe"= TCP:c:\program files\left 4 dead\left4dead.exe:left4dead
"{FAA6BE71-A216-4F26-8578-4ED58BF502D6}"= UDP:c:\program files\Steam\steam.exe:Steam
"{96DE2211-2B93-44FE-B6BB-75405C93BB23}"= TCP:c:\program files\Steam\steam.exe:Steam
"TCP Query User{49E002DA-E1C1-4220-890D-8062980B647D}c:\\program files\\electronic arts\\battlefield 2142\\bf2142.exe"= UDP:c:\program files\electronic arts\battlefield 2142\bf2142.exe:BF2142
"UDP Query User{D4ACF567-DF53-4261-8AC6-160DD3F85EA7}c:\\program files\\electronic arts\\battlefield 2142\\bf2142.exe"= TCP:c:\program files\electronic arts\battlefield 2142\bf2142.exe:BF2142
"TCP Query User{072B9C31-430E-42ED-A123-66BB36D4C525}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{41DE71E8-FE2C-4C33-9AE1-E91F89A47F73}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{5CA35AAB-017A-47D4-957C-DE32E21E0786}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{7853282D-6B2F-4687-A883-B64E3459C86A}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{0B3DAFF1-5398-4BA8-B50C-8561189798A9}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{EC7E8511-DD29-4A27-9445-DCF1C00AC2DE}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{C115F1D5-F261-40CC-8461-3CD9CFF2844C}f:\\program files\\starcraft\\starcraft.exe"= UDP:f:\program files\starcraft\starcraft.exe:StarCraft
"UDP Query User{73DCBF1D-137A-462C-A7F4-21B59515B633}f:\\program files\\starcraft\\starcraft.exe"= TCP:f:\program files\starcraft\starcraft.exe:StarCraft
"TCP Query User{6CE46C31-A2A1-4229-911A-2F35C50A957E}c:\\program files\\leaf networks\\leaf\\bin\\leaf.exe"= UDP:c:\program files\leaf networks\leaf\bin\leaf.exe:Leaf
"UDP Query User{D7B42489-BF1D-475F-9178-060A46156886}c:\\program files\\leaf networks\\leaf\\bin\\leaf.exe"= TCP:c:\program files\leaf networks\leaf\bin\leaf.exe:Leaf
"TCP Query User{63EE85B6-1513-4D5A-8A90-37A6582FB1BA}c:\\program files\\java\\jre6\\bin\\java.exe"= UDP:c:\program files\java\jre6\bin\java.exe:Java™ Platform SE binary
"UDP Query User{E9184F67-5963-4754-B808-6B74D526B08C}c:\\program files\\java\\jre6\\bin\\java.exe"= TCP:c:\program files\java\jre6\bin\java.exe:Java™ Platform SE binary
"TCP Query User{C31D219F-F289-4D2F-8915-895118D175CE}f:\\program files\\mirc\\mirc.exe"= UDP:f:\program files\mirc\mirc.exe:mIRC
"UDP Query User{BC31CB2F-E039-4B27-BB27-7507B0F9AFA8}f:\\program files\\mirc\\mirc.exe"= TCP:f:\program files\mirc\mirc.exe:mIRC
"TCP Query User{32109515-EE3E-49D8-BFF9-FC65B8A91ADD}c:\\users\\juleila\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\y46l33a9\\war_europe_trial_downloader[1].exe"= UDP:c:\users\juleila\appdata\local\microsoft\windows\temporary internet files\content.ie5\y46l33a9\war_europe_trial_downloader[1].exe:war_europe_trial_downloader[1].exe
"UDP Query User{B7C06DDB-D446-4D5B-9435-D8FB6A262F93}c:\\users\\juleila\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\y46l33a9\\war_europe_trial_downloader[1].exe"= TCP:c:\users\juleila\appdata\local\microsoft\windows\temporary internet files\content.ie5\y46l33a9\war_europe_trial_downloader[1].exe:war_europe_trial_downloader[1].exe
"TCP Query User{3F5C34CE-5A4B-4D73-8B75-C756B73B1EB9}c:\\users\\juleila\\downloads\\grabit downloads\\1238349103[1]\\starcraft + brood war v1.16.1 fr-exodus\\starcraft + brood war v1.16.1 fr-exodus\\starcraft.exe"= UDP:c:\users\juleila\downloads\grabit downloads\1238349103[1]\starcraft + brood war v1.16.1 fr-exodus\starcraft + brood war v1.16.1 fr-exodus\starcraft.exe:starcraft.exe
"UDP Query User{46E2EE5E-017D-4EBC-AFDC-969A2A65AE6D}c:\\users\\juleila\\downloads\\grabit downloads\\1238349103[1]\\starcraft + brood war v1.16.1 fr-exodus\\starcraft + brood war v1.16.1 fr-exodus\\starcraft.exe"= TCP:c:\users\juleila\downloads\grabit downloads\1238349103[1]\starcraft + brood war v1.16.1 fr-exodus\starcraft + brood war v1.16.1 fr-exodus\starcraft.exe:starcraft.exe
"TCP Query User{9264E6EA-E520-4907-BD10-499A7BFE1A1C}c:\\users\\juleila\\desktop\\starcraft + brood war v1.16.1 fr-exodus\\starcraft + brood war v1.16.1 fr-exodus\\starcraft.exe"= UDP:c:\users\juleila\desktop\starcraft + brood war v1.16.1 fr-exodus\starcraft + brood war v1.16.1 fr-exodus\starcraft.exe:starcraft.exe
"UDP Query User{875D72CE-86A0-4016-A540-8D89660A2837}c:\\users\\juleila\\desktop\\starcraft + brood war v1.16.1 fr-exodus\\starcraft + brood war v1.16.1 fr-exodus\\starcraft.exe"= TCP:c:\users\juleila\desktop\starcraft + brood war v1.16.1 fr-exodus\starcraft + brood war v1.16.1 fr-exodus\starcraft.exe:starcraft.exe
"{843F1CD0-9B3A-4034-AE16-DCFA126011A5}"= UDP:c:\program files\Warcraft III\Frozen Throne.exe:Warcraft III - The Frozen Throne
"{58273509-FADC-4826-BB00-ED384A70FB20}"= TCP:c:\program files\Warcraft III\Frozen Throne.exe:Warcraft III - The Frozen Throne
"TCP Query User{B1F53EA1-DAC3-4372-808F-EF777DBB1B67}c:\\program files\\gamespy arcade\\aphex.exe"= Disabled:UDP:c:\program files\gamespy arcade\aphex.exe:GameSpy Arcade 1.0, Public Beta 4
"UDP Query User{4B7DF164-7B2A-424B-9FA4-7C752727FCB7}c:\\program files\\gamespy arcade\\aphex.exe"= Disabled:TCP:c:\program files\gamespy arcade\aphex.exe:GameSpy Arcade 1.0, Public Beta 4
"{8E1403D7-DBF7-4EB9-9A5A-A21995F540F4}"= Disabled:UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{9A1D6420-D8CF-4441-94B1-2E96A074C413}"= Disabled:TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{ECE1EE10-7F5D-44F0-A60E-B39AFF345744}"= Disabled:UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{4DFE02C4-B7F1-4496-8B21-3F8059EFD8F6}"= Disabled:TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"TCP Query User{EF218BD0-4DC6-4193-A958-1B0E006E6213}c:\\program files\\dialsoft\\the 4th coming\\prophetie.exe"= Disabled:UDP:c:\program files\dialsoft\the 4th coming\prophetie.exe:prophetie
"UDP Query User{10C914A6-70D0-42D2-A337-32087200CD21}c:\\program files\\dialsoft\\the 4th coming\\prophetie.exe"= Disabled:TCP:c:\program files\dialsoft\the 4th coming\prophetie.exe:prophetie
"{A0DDA6E9-66EE-4559-8B6F-C3EDFA9CB42C}"= Disabled:UDP:c:\program files\Deep Silver\Sacred 2 - Fallen Angel\system\sacred2.exe:Sacred 2
"{259A9ACE-C295-41D5-89EA-160E269619B0}"= Disabled:TCP:c:\program files\Deep Silver\Sacred 2 - Fallen Angel\system\sacred2.exe:Sacred 2
"{98E6BDDC-E8C8-439B-9FD8-1E40A745B217}"= Disabled:UDP:c:\program files\Deep Silver\Sacred 2 - Fallen Angel\system\s2gs.exe:Sacred 2 Game Server
"{30B78DF1-8541-4A33-BBC1-38D5A4F95F3B}"= Disabled:TCP:c:\program files\Deep Silver\Sacred 2 - Fallen Angel\system\s2gs.exe:Sacred 2 Game Server
"{3D03EFA3-E3ED-4542-BDFD-1B41B607FCA7}"= UDP:c:\warhammer online - age of reckoning\warpatch.exe:Warhammer Online - Age of Reckoning
"{33BE34F2-3F2F-4AFC-939E-B3F8A1A74F6F}"= TCP:c:\warhammer online - age of reckoning\warpatch.exe:Warhammer Online - Age of Reckoning
"TCP Query User{87DDEAFA-E734-4BDB-B795-98F3DF832E39}c:\\program files\\bitcomet\\bitcomet.exe"= Disabled:UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{8D63769F-4B69-47E7-B3E0-E9D2572E2015}c:\\program files\\bitcomet\\bitcomet.exe"= Disabled:TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"TCP Query User{0688FE98-3EB5-4933-B7E2-2E6FD034CED0}c:\\program files\\emule\\emule.exe"= Disabled:UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{368F4AB7-9031-45BD-87CD-3E2B2F6EB7B0}c:\\program files\\emule\\emule.exe"= Disabled:TCP:c:\program files\emule\emule.exe:eMule
"TCP Query User{FA581A9B-B55B-4E23-8E24-5918D05C57D9}c:\\program files\\counterpath\\x-lite\\x-lite.exe"= Disabled:UDP:c:\program files\counterpath\x-lite\x-lite.exe:X-Lite
"UDP Query User{3D2F3EAB-C615-4701-9AFF-18F796FDC6F7}c:\\program files\\counterpath\\x-lite\\x-lite.exe"= Disabled:TCP:c:\program files\counterpath\x-lite\x-lite.exe:X-Lite
"TCP Query User{BEB7D48A-5D02-4FD6-8BF3-C683699CD927}c:\\users\\juleila\\desktop\\starcraft + brood war v1.16.1 fr-exodus\\starcraft + brood war v1.16.1 fr-exodus\\starcraft.exe"= UDP:c:\users\juleila\desktop\starcraft + brood war v1.16.1 fr-exodus\starcraft + brood war v1.16.1 fr-exodus\starcraft.exe:starcraft.exe
"UDP Query User{3B7B832B-690B-4DD9-82F6-C4989BA964D3}c:\\users\\juleila\\desktop\\starcraft + brood war v1.16.1 fr-exodus\\starcraft + brood war v1.16.1 fr-exodus\\starcraft.exe"= TCP:c:\users\juleila\desktop\starcraft + brood war v1.16.1 fr-exodus\starcraft + brood war v1.16.1 fr-exodus\starcraft.exe:starcraft.exe
"{A8380A56-294A-43EF-9909-300333FB0097}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{E3177E84-A7C3-4EF4-8317-35F2C21DE083}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C7A06BCC-F491-45AD-83A9-F5C7434E6DC4}"= UDP:c:\program files\Leaf Networks\Leaf\bin\Leaf.exe:Leaf
"{9F55596F-E3A0-4342-B46B-B1C6C7D2B67F}"= TCP:c:\program files\Leaf Networks\Leaf\bin\Leaf.exe:Leaf
"TCP Query User{E9A0207C-47E9-48D1-904D-3F525ACB9F45}c:\\windows\\system32\\dplaysvr.exe"= UDP:c:\windows\system32\dplaysvr.exe:Microsoft DirectPlay Helper
"UDP Query User{47F3E711-3CEC-4546-84FF-4600F85C347F}c:\\windows\\system32\\dplaysvr.exe"= TCP:c:\windows\system32\dplaysvr.exe:Microsoft DirectPlay Helper
"TCP Query User{36C00F98-61E0-40A4-BB07-5429D3FE7456}c:\\users\\juleila\\appdata\\local\\temp\\rar$ex00.065\\volley\\volley\\volley.exe"= UDP:c:\users\juleila\appdata\local\temp\rar$ex00.065\volley\volley\volley.exe:volley.exe
"UDP Query User{ABB9B013-1960-4380-9476-405F7FE08FAD}c:\\users\\juleila\\appdata\\local\\temp\\rar$ex00.065\\volley\\volley\\volley.exe"= TCP:c:\users\juleila\appdata\local\temp\rar$ex00.065\volley\volley\volley.exe:volley.exe
"{8BE88125-C3BC-4ABE-B108-3649A326DB84}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C4133FC4-7CD7-482D-B55F-E46013E3DD36}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{7149FB04-3BC1-4AFA-B79A-6960F6FC098A}"= UDP:c:\program files\Steam\steamapps\common\left 4 dead\left4dead.exe:Left 4 Dead
"{69A40C87-D2DD-4821-A5D3-1B91EFE7E397}"= TCP:c:\program files\Steam\steamapps\common\left 4 dead\left4dead.exe:Left 4 Dead
"{C63D0074-9333-463B-B499-1D146B68FBF0}"= UDP:c:\program files\CAPCOM\STREETFIGHTERIV\StreetFighterIV.exe:STREET FIGHTER IV
"{FDC8CD2D-3DF6-4705-9CB7-D233623C1C8B}"= TCP:c:\program files\CAPCOM\STREETFIGHTERIV\StreetFighterIV.exe:STREET FIGHTER IV

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [7/18/2009 9:08 PM 64160]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [7/5/2009 12:53 AM 108289]
R2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\System32\drivers\RtNdPt60.sys [4/3/2009 9:42 AM 27648]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\windows\System32\nvSCPAPISvr.exe [6/10/2009 6:33 AM 232960]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 4:34 PM 1029456]
S3 epmntdrv;epmntdrv;c:\windows\System32\epmntdrv.sys [7/3/2009 8:24 PM 9728]
S3 EuGdiDrv;EuGdiDrv;c:\windows\System32\EuGdiDrv.sys [7/3/2009 8:24 PM 3072]
S3 leafnets;Leaf Networks Adapter;c:\windows\System32\drivers\leafnets.sys [5/2/2007 6:48 PM 55296]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\System32\drivers\mbamswissarmy.sys [7/21/2009 1:39 AM 38160]
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\System32\drivers\NETw2v32.sys [11/2/2006 5:25 AM 2589184]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-19 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 02:08]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-eyeBeam SIP Client - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH;=&Br;=EM&Loc;=ENG_US&Sys;=DTP&M;=T5274a
IE: Consulter les dictionnaires (SYSTRAN) - c:\program files\SYSTRAN\6\\GUIres.dll/lookup.js
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE12\EXCEL.EXE/3000
IE: Traduire (SYSTRAN) - c:\program files\SYSTRAN\6\\GUIres.dll/translate.js
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.21.0.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-21 13:41
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3917738136-2676680180-1288316716-1000\Software\SecuROM\License information*]
"datasecu"=hex:26,dd,be,0a,b7,68,0f,a7,fb,77,14,07,98,16,f9,fc,2c,45,85,53,dc,
80,49,cf,3d,31,4d,ef,df,c3,37,71,ec,48,81,ff,61,7f,3d,0c,30,9f,b5,b8,3f,4f,\
"rkeysecu"=hex:fb,db,71,c0,8b,34,8f,2a,41,77,d7,5c,d0,99,3d,09
.
Completion time: 2009-07-21 13:42
ComboFix-quarantined-files.txt 2009-07-21 18:42

Pre-Run: 127,956,922,368 bytes free
Post-Run: 128,200,462,336 bytes free

405 — E O F — 2009-07-20 16:42
Hi,

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT



**Vista users - right click on the IE icon and run as administrator

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
ok MalwareBytes AntiMalware Program was update here the log : i am still waiting for kaspersky online to finnish the scan thank again Malwarebytes' Anti-Malware 1.39 Version de la base de données: 2475 Windows 6.0.6002 Service Pack 2 7/21/2009 4:55:02 PM mbam-log-2009-07-21 (16-55-02).txt Type de recherche: Examen rapide Eléments examinés: 81487 Temps écoulé: 6 minute(s), 13 second(s) Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 0 Clé(s) du Registre infectée(s): 0 Valeur(s) du Registre infectée(s): 0 Elément(s) de données du Registre infecté(s): 0 Dossier(s) infecté(s): 0 Fichier(s) infecté(s): 0 Processus mémoire infecté(s): (Aucun élément nuisible détecté) Module(s) mémoire infecté(s): (Aucun élément nuisible détecté) Clé(s) du Registre infectée(s): (Aucun élément nuisible détecté) Valeur(s) du Registre infectée(s): (Aucun élément nuisible détecté) Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté) Dossier(s) infecté(s): (Aucun élément nuisible détecté) Fichier(s) infecté(s): (Aucun élément nuisible détecté)
sorry i post the same one in englsih that time not in french :) Still waiting for kaspersky online. Malwarebytes' Anti-Malware 1.39 Version de la base de données: 2475 Windows 6.0.6002 Service Pack 2 7/21/2009 4:55:02 PM mbam-log-2009-07-21 (16-55-02).txt Type de recherche: Examen rapide Eléments examinés: 81487 Temps écoulé: 6 minute(s), 13 second(s) Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 0 Clé(s) du Registre infectée(s): 0 Valeur(s) du Registre infectée(s): 0 Elément(s) de données du Registre infecté(s): 0 Dossier(s) infecté(s): 0 Fichier(s) infecté(s): 0 Processus mémoire infecté(s): (Aucun élément nuisible détecté) Module(s) mémoire infecté(s): (Aucun élément nuisible détecté) Clé(s) du Registre infectée(s): (Aucun élément nuisible détecté) Valeur(s) du Registre infectée(s): (Aucun élément nuisible détecté) Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté) Dossier(s) infecté(s): (Aucun élément nuisible détecté) Fichier(s) infecté(s): (Aucun élément nuisible détecté)
Arf sorry .. again the one in english … :( Malwarebytes' Anti-Malware 1.39 Database version: 2475 Windows 6.0.6002 Service Pack 2 7/21/2009 5:20:28 PM mbam-log-2009-07-21 (17-20-28).txt Scan type: Quick Scan Objects scanned: 81516 Time elapsed: 4 minute(s), 23 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
ok both log now :) when I did all the tests i had my external hard drive unplug all the time should I scan it too when i plug it back ? :P THANK :) Malwarebytes' Anti-Malware 1.39 Database version: 2475 Windows 6.0.6002 Service Pack 2 7/21/2009 7:32:29 PM mbam-log-2009-07-21 (19-32-29).txt Scan type: Full Scan (C:\|D:\|E:\|G:\|H:\|I:\|J:\|K:\|L:\|) Objects scanned: 248151 Time elapsed: 2 hour(s), 6 minute(s), 51 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\Qoobox\quarantine\C\Windows\System32\hjgruitfceyvxc.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully. ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Tuesday, July 21, 2009 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Tuesday, July 21, 2009 19:36:35 Records in database: 2508191 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ G:\ H:\ I:\ J:\ K:\ L:\ Scan statistics: Files scanned: 155139 Threat name: 0 Infected objects: 0 Suspicious objects: 0 Duration of the scan: 05:00:57 No malware has been detected. The scan area is clean. The selected area was scanned.
Yes, you should run the scans on your external hard drive. Please run a fresh DDS log and advise how your computer is running now and if you have any outstanding issues
Everything seems to work perfectly now thank you so much for your help :) Here the DDS UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 5/7/2008 4:08:22 AM System Uptime: 7/21/2009 10:39:12 PM (0 hours ago) Motherboard: ELITEGROUP | | 945GCT-M3 Processor: Intel® Pentium® Dual CPU E2180 @ 2.00GHz | Socket 775 | 2000/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 287 GiB total, 117.208 GiB free. D: is FIXED (NTFS) - 11 GiB total, 5.19 GiB free. E: is CDROM () G: is Removable H: is Removable I: is Removable J: is CDROM () K: is CDROM () L: is Removable ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP721: 7/21/2009 1:01:58 PM - ComboFix created restore point RP722: 7/21/2009 8:57:34 PM - Windows Update RP724: 7/21/2009 10:32:37 PM - Installed Realtek High Definition Audio Driver RP725: 7/21/2009 10:33:09 PM - Device Driver Package Install: Realtek Semiconductor Corp. Sound, video and game controllers ==== Installed Programs ====================== 7-Zip 4.58 beta a-squared HiJackFree 3.1 Ad-Aware Adobe Flash Player 10 ActiveX Adobe Reader 8.1.4 AutoUpdate Avira AntiVir Personal - Free Antivirus Battlefield 2142 Battlefield Heroes Choice Guard Classic Menu 3.x for Office 2007 DivX Codec DivX Player DivX Web Player EASEUS Partition Master 4.0 Home Edition eMachines Recovery Center Installer eMule Fallout 3 GearDrvs Gizmo5 Google Earth Google Toolbar for Internet Explorer GrabIt 1.7.1 Beta (build 960) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) ImagXpress Intel® PRO Network Connections Drivers IsoBuster 2.5 Ivalice Launcher Version 11 Java™ 6 Update 12 K-Lite Codec Pack 4.0.0 (Full) Left 4 Dead LightScribe 1.4.142.1 Logitech Desktop Messenger Logitech QuickCam Logitech QuickCam Driver Package Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB929729) Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Games for Windows - LIVE Microsoft Games for Windows - LIVE Redistributable Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Excel 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office PowerPoint 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Midgar Launcher mIRC MSVCRT MSXML 4.0 SP2 (KB954430) neroxml NTI Media Maker 8 NVIDIA Drivers NVIDIA PhysX NVIDIA Stereoscopic 3D Driver OpenOffice.org Installer 1.0 PCFriendly PunkBuster Services Quick Zip 4.60.019 QuickPar 0.9 QuickTime Ralink Wireless LAN Realtek 8139 and 8139C+ Ethernet Network Card Driver for Windows Vista Realtek Ethernet Network Card Diagnostic tool for Windows Vista Realtek High Definition Audio Driver Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB969679) Security Update for Microsoft Office Excel 2007 (KB969682) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office Word 2007 (KB969604) Steam STREET FIGHTER IV SYSTRAN TeamSpeak 2 RC2 TELL ME MORE The 4th Coming v1.61 by Dialsoft TomTom HOME Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) VideoLAN VLC media player 0.8.6h Vuze Warcraft III Warcraft III: All Products Warhammer Online - Age of Reckoning Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Live Sign-in Assistant Windows Live Upload Tool WinRAR archiver World of Warcraft Wow Cartographe 1.08 ==== Event Viewer Messages From Past Week ======== 7/21/2009 10:40:03 PM, Error: Service Control Manager [7000] - The Agere Systems Soft Modem service failed to start due to the following error: The system cannot find the file specified. 7/21/2009 1:49:43 PM, Error: bowser [8003] - The master browser has received a server announcement from the computer MAC0016CBAEBE1E that believes that it is the master browser for the domain on transport NetBT_Tcpip_{F5ED3C92-B228-4C67-8FC2-B2. The master browser is stopping or an election is being forced. 7/21/2009 1:41:17 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 7/21/2009 1:41:17 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the PEVSystemStart service to connect. 7/21/2009 1:33:59 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Cryptographic Services service, but this action failed with the following error: An instance of the service is already running. 7/21/2009 1:32:59 AM, Error: Service Control Manager [7031] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 7/21/2009 1:32:59 AM, Error: Service Control Manager [7031] - The Telephony service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 7/21/2009 1:32:59 AM, Error: Service Control Manager [7031] - The Network Location Awareness service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service. 7/21/2009 1:32:59 AM, Error: Service Control Manager [7031] - The KtmRm for Distributed Transaction Coordinator service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service. 7/21/2009 1:32:59 AM, Error: Service Control Manager [7031] - The DNS Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 7/21/2009 1:32:59 AM, Error: Service Control Manager [7031] - The Cryptographic Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 7/21/2009 1:32:56 PM, Error: Service Control Manager [7034] - The Process Monitor service terminated unexpectedly. It has done this 1 time(s). 7/20/2009 6:15:22 PM, Error: EventLog [6008] - The previous system shutdown at 6:13:12 PM on 7/20/2009 was unexpected. 7/20/2009 6:05:21 PM, Error: EventLog [6008] - The previous system shutdown at 6:03:53 PM on 7/20/2009 was unexpected. 7/20/2009 5:53:31 PM, Error: EventLog [6008] - The previous system shutdown at 5:52:10 PM on 7/20/2009 was unexpected. 7/20/2009 5:46:30 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Media Player Network Sharing Service service to connect. 7/20/2009 5:46:30 PM, Error: Service Control Manager [7000] - The Windows Media Player Network Sharing Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/20/2009 2:09:41 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Telephony service to connect. 7/20/2009 2:09:41 AM, Error: Service Control Manager [7000] - The Telephony service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/20/2009 2:09:11 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Cryptographic Services service to connect. 7/20/2009 2:09:11 AM, Error: Service Control Manager [7000] - The Cryptographic Services service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/20/2009 2:08:11 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Terminal Services service to connect. 7/20/2009 2:08:11 AM, Error: Service Control Manager [7000] - The Terminal Services service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/20/2009 2:07:10 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Network Location Awareness service to connect. 7/20/2009 2:07:10 AM, Error: Service Control Manager [7000] - The Network Location Awareness service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/20/2009 10:08:11 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Microsoft Software Shadow Copy Provider service to connect. 7/20/2009 10:08:11 PM, Error: Service Control Manager [7000] - The Microsoft Software Shadow Copy Provider service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/20/2009 10:08:11 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service swprv with arguments "" in order to run the server: {65EE1DBA-8FF4-4A58-AC1C-3470EE2F376A} 7/20/2009 10:00:13 PM, Error: EventLog [6008] - The previous system shutdown at 9:58:16 PM on 7/20/2009 was unexpected. 7/20/2009 1:25:51 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Peer Networking Identity Manager service, but this action failed with the following error: An instance of the service is already running. 7/20/2009 1:22:51 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the DHCP Client service, but this action failed with the following error: An instance of the service is already running. 7/19/2009 2:20:14 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the DNS Client service to connect. 7/19/2009 2:20:14 PM, Error: Service Control Manager [7000] - The DNS Client service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/19/2009 2:14:01 PM, Error: EventLog [6008] - The previous system shutdown at 2:12:19 PM on 7/19/2009 was unexpected. 7/18/2009 9:51:54 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows CardSpace service to connect. 7/18/2009 9:51:54 AM, Error: Service Control Manager [7000] - The Windows CardSpace service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/18/2009 9:07:41 PM, Error: Service Control Manager [7030] - The Lavasoft Ad-Aware Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 7/18/2009 3:57:10 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046} 7/18/2009 3:52:58 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD avgio avipbb DfsC NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr ssmdrv tdx Wanarpv6 7/18/2009 3:52:58 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 7/18/2009 3:52:58 PM, Error: Service Control Manager [7001] - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning. 7/18/2009 3:52:58 PM, Error: Service Control Manager [7001] - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error: The dependency service or group failed to start. 7/18/2009 3:52:58 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 7/18/2009 3:52:58 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning. 7/18/2009 3:52:58 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 7/18/2009 3:52:58 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 7/18/2009 3:52:58 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service service which failed to start because of the following error: A device attached to the system is not functioning. 7/18/2009 3:52:58 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 7/18/2009 3:52:58 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start. 7/18/2009 3:52:58 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 7/18/2009 3:52:58 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning. 7/18/2009 3:52:58 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 7/18/2009 3:52:58 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 7/18/2009 3:52:47 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 7/18/2009 3:52:45 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 7/18/2009 3:52:10 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89} 7/18/2009 3:52:10 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E} 7/18/2009 3:52:10 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF} 7/18/2009 3:52:06 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 7/18/2009 3:51:58 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 7/18/2009 3:51:52 PM, Error: EventLog [6008] - The previous system shutdown at 3:50:06 PM on 7/18/2009 was unexpected. 7/15/2009 12:24:36 PM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 7/15/2009 12:24:36 PM, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 7/15/2009 12:24:36 PM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 7/15/2009 12:24:36 PM, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 7/15/2009 12:24:36 PM, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 7/15/2009 12:24:36 PM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 7/15/2009 12:24:36 PM, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 7/15/2009 12:24:36 PM, Error: Service Control Manager [7031] - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 7/15/2009 12:24:36 PM, Error: Service Control Manager [7031] - The Extensible Authentication Protocol service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 7/15/2009 12:24:36 PM, Error: Service Control Manager [7031] - The Computer Browser service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 7/15/2009 12:24:36 PM, Error: Service Control Manager [7031] - The Application Experience service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 7/15/2009 12:24:36 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Windows Management Instrumentation service which failed to start because of the following error: The pipe state is invalid. 7/15/2009 12:24:36 PM, Error: Service Control Manager [7000] - The Secondary Logon service failed to start due to the following error: The pipe state is invalid. ==== End Of File ===========================
Hi, there should be a DDS.txt file, if you could post that please.

In the meantime, please do the following:

Visit ADOBEand download the latest version of Acrobat Reader (version 9.1)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT


[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 12 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.
it's that one ? DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 1:08:15.28 on Wed 07/22/2009 Internet Explorer: 8.0.6001.18783 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3071.1920 [GMT -5:00] SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Windows\system32\svchost.exe -k apphost C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe C:\Windows\system32\PnkBstrA.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\System32\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k iissvcs C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\taskeng.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\Java\jre6\bin\jp2launcher.exe C:\Program Files\Java\jre6\bin\java.exe C:\Users\Juleila\AppData\Local\temp\jkos-Juleila\binaries\ScanningProcess.exe C:\Users\Juleila\AppData\Local\temp\jkos-Juleila\binaries\ScanningProcess.exe C:\Windows\system32\NOTEPAD.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Juleila\Desktop\anti virus malware\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=&Br=EM&Loc=ENG_US&Sys=DTP&M=T5274a BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: SYSTRAN Toolbar: {95daa571-4def-4a6d-97d8-98a346672a24} - mscoree.dll uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [RtHDVCpl] RtHDVCpl.exe StartupFolder: c:\users\juleila\appdata\roaming\micros~1\windows\startm~1\programs\startup\pnkbst~1.lnk - c:\windows\system32\PnkBstrA.exe StartupFolder: c:\users\juleila\appdata\roaming\micros~1\windows\startm~1\programs\startup\pnkbst~2.lnk - c:\windows\system32\PnkBstrB.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Consulter les dictionnaires (SYSTRAN) - c:\program files\systran\6\\GUIres.dll/lookup.js IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Traduire (SYSTRAN) - c:\program files\systran\6\\GUIres.dll/translate.js IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - hxxp://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.21.0.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} - hxxp://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll Notify: igfxcui - igfxdev.dll ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-7-18 64160] R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\avira\antivir desktop\sched.exe [2009-7-5 108289] R2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\drivers\RtNdPt60.sys [2009-4-3 27648] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\windows\system32\nvSCPAPISvr.exe [2009-6-10 232960] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 1029456] S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2009-7-3 9728] S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2009-7-3 3072] S3 leafnets;Leaf Networks Adapter;c:\windows\system32\drivers\leafnets.sys [2007-5-2 55296] S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\drivers\NETw2v32.sys [2006-11-2 2589184] =============== Created Last 30 ================ 2009-07-21 22:36 318,976 a——- c:\windows\system32\CF30800.exe 2009-07-21 22:36 –ds—- C:\ComboFix 2009-07-21 22:32 –d—– c:\program files\Realtek 2009-07-21 21:33 189,488 a——- c:\windows\system32\PnkBstrB.xtr 2009-07-21 21:16 1,905 a——- c:\windows\diagwrn.xml 2009-07-21 21:16 1,905 a——- c:\windows\diagerr.xml 2009-07-21 13:42 –dsh— C:\$RECYCLE.BIN 2009-07-21 13:01 219,648 a——- c:\windows\PEV.exe 2009-07-21 13:01 161,792 a——- c:\windows\SWREG.exe 2009-07-21 13:01 98,816 a——- c:\windows\sed.exe 2009-07-21 01:39 –d—– c:\users\juleila\appdata\roaming\Malwarebytes 2009-07-21 01:39 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-21 01:39 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-21 01:39 –d—– c:\programdata\Malwarebytes 2009-07-21 01:39 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-21 01:39 –d—– c:\progra~2\Malwarebytes 2009-07-21 00:54 32,061 a——- c:\programdata\nvModes.dat 2009-07-21 00:54 32,061 a——- c:\progra~2\nvModes.dat 2009-07-18 23:26 15,688 a——- c:\windows\system32\lsdelete.exe 2009-07-18 21:08 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-07-18 20:08 -cd-h— c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800} 2009-07-18 20:08 -cd-h— c:\progra~2\{83C91755-2546-441D-AC40-9A6B4B860800} 2009-07-18 15:49 209,508,599 a——- c:\windows\MEMORY.DMP 2009-07-18 15:47 139,152 a——- c:\users\juleila\appdata\roaming\PnkBstrK.sys 2009-07-18 15:47 794,408 a——- c:\windows\system32\pbsvc.exe 2009-07-18 15:27 –d—– c:\program files\EA Games 2009-07-15 15:44 –d—– c:\program files\Yahoo! 2009-07-15 12:40 156,672 a——- c:\windows\system32\t2embed.dll 2009-07-15 12:40 289,792 a——- c:\windows\system32\atmfd.dll 2009-07-15 12:40 72,704 a——- c:\windows\system32\fontsub.dll 2009-07-15 12:40 23,552 a——- c:\windows\system32\lpk.dll 2009-07-15 12:40 10,240 a——- c:\windows\system32\dciman32.dll 2009-07-09 01:05 –d—– c:\program files\CAPCOM 2009-07-08 00:26 –d—– c:\users\juleila\appdata\roaming\Reallusion 2009-07-08 00:17 –d—– c:\program files\common files\Reallusion 2009-07-05 00:53 55,640 a——- c:\windows\system32\drivers\avgntflt.sys 2009-07-05 00:53 –d—– c:\programdata\Avira 2009-07-05 00:53 –d—– c:\program files\Avira 2009-07-05 00:53 –d—– c:\progra~2\Avira 2009-07-03 20:24 1,663,488 a——- c:\windows\system32\BootMan.exe 2009-07-03 20:24 14,848 a——- c:\windows\system32\EuEpmGdi.dll 2009-07-03 20:24 86,408 a——- c:\windows\system32\setupempdrv03.exe 2009-07-03 20:24 9,728 a——- c:\windows\system32\epmntdrv.sys 2009-07-03 20:24 3,072 a——- c:\windows\system32\EuGdiDrv.sys 2009-07-03 20:24 –d—– c:\program files\EASEUS 2009-07-03 16:58 –d—– c:\users\juleila\appdata\roaming\PeerNetworking 2009-07-03 14:50 364,544 a——- c:\windows\system32\WDBtnMgr.exe 2009-06-29 13:25 –d—– c:\program files\common files\muvee Technologies 2009-06-29 13:25 –d—– c:\program files\NewTech Infosystems 2009-06-29 12:23 –d—– c:\windows\system32\eu-ES 2009-06-29 12:23 –d—– c:\windows\system32\ca-ES 2009-06-29 12:23 –d—– c:\windows\system32\vi-VN 2009-06-29 11:56 –d—– c:\windows\system32\EventProviders 2009-06-29 11:54 978,432 a——- c:\windows\system32\drmv2clt.dll 2009-06-29 11:53 153 a——- c:\windows\system32\RacUREx.xml 2009-06-29 11:53 265,728 a——- c:\windows\system32\wbem\esscli.dll 2009-06-29 11:53 189,440 a——- c:\windows\system32\wbem\mofd.dll 2009-06-29 11:53 83,968 a——- c:\windows\system32\wbem\wmiutils.dll 2009-06-29 11:53 30,208 a——- c:\windows\system32\wbem\wbemprox.dll 2009-06-29 11:53 744,448 a——- c:\windows\system32\wbem\wbemcore.dll 2009-06-29 11:53 614,912 a——- c:\windows\system32\wbem\fastprox.dll 2009-06-29 11:53 265,728 a——- c:\windows\system32\wbem\repdrvfs.dll 2009-06-29 11:53 705,536 a——- c:\windows\system32\SmiEngine.dll 2009-06-29 11:53 218,624 a——- c:\windows\system32\wdscore.dll 2009-06-29 11:53 130,560 a——- c:\windows\system32\PkgMgr.exe 2009-06-29 11:53 247,808 a——- c:\windows\system32\drvstore.dll ==================== Find3M ==================== 2009-07-21 23:03 137,992 a——- c:\windows\system32\drivers\PnkBstrK.sys 2009-07-21 22:59 201,816 a——- c:\windows\system32\PnkBstrB.exe 2009-07-21 22:33 143,360 a——- c:\windows\inf\infstrng.dat 2009-07-21 22:33 51,200 a——- c:\windows\inf\infpub.dat 2009-07-21 22:33 86,016 a——- c:\windows\inf\infstor.dat 2009-07-21 22:32 319,456 a——- c:\windows\DIFxAPI.dll 2009-07-21 21:21 75,064 a——- c:\windows\system32\PnkBstrA.exe 2009-07-09 12:19 0 a——- c:\windows\system32\drivers\lvuvc.hs 2009-06-29 12:23 665,600 a——- c:\windows\inf\drvindex.dat 2009-06-10 08:35 1,194,528 a——- c:\windows\system32\nvcplui.exe 2009-06-10 08:35 1,296,928 a——- c:\windows\system32\nvsvs.dll 2009-06-10 08:34 3,123,744 a——- c:\windows\system32\nvwss.dll 2009-06-10 08:34 4,045,344 a——- c:\windows\system32\nvvitvs.dll 2009-06-10 08:34 4,028,960 a——- c:\windows\system32\nvdisps.dll 2009-06-10 08:34 3,516,960 a——- c:\windows\system32\nvgames.dll 2009-06-10 08:34 1,288,736 a——- c:\windows\system32\nvmobls.dll 2009-06-10 08:34 211,488 a——- c:\windows\system32\nvvsvc.exe 2009-06-10 08:34 195,104 a——- c:\windows\system32\nvmccss.dll 2009-06-10 08:34 13,785,632 a——- c:\windows\system32\nvcpl.dll 2009-06-10 08:34 768,544 a——- c:\windows\system32\nvsvc.dll 2009-06-10 08:34 143,360 a——- c:\windows\system32\nvshext.dll 2009-06-10 08:34 92,704 a——- c:\windows\system32\nvmctray.dll 2009-06-10 06:33 244,736 a——- c:\windows\system32\nvStInst.exe 2009-06-10 06:33 467,968 a——- c:\windows\system32\nvstlink.exe 2009-06-10 06:33 3,953,152 a——- c:\windows\system32\nvstwiz.exe 2009-06-10 06:33 141,824 a——- c:\windows\system32\nvStereoApiI.dll 2009-06-10 06:33 171,520 a——- c:\windows\system32\nvStereoApiI64.dll 2009-06-10 06:33 232,960 a——- c:\windows\system32\nvSCPAPISvr.exe 2009-06-10 06:32 257,536 a——- c:\windows\system32\nvSCPAPI.dll 2009-06-10 06:32 301,568 a——- c:\windows\system32\nvSCPAPI64.dll 2009-06-10 06:32 3,293,184 a——- c:\windows\system32\nvstres.dll 2009-06-10 06:32 5,847 a——- c:\windows\system32\oglstreg.reg 2009-06-10 06:31 167,424 a——- c:\windows\system32\nvstreg.exe 2009-06-10 06:31 1,718,272 a——- c:\windows\system32\nvsttest.exe 2009-06-10 06:31 1,034,752 a——- c:\windows\system32\nvstview.exe 2009-06-10 06:31 89,088 a——- c:\windows\system32\nvimage.dll 2009-06-10 06:29 1,656 a——- c:\windows\system32\nvstdef.reg 2009-06-10 06:03 10,379,264 a——- c:\windows\system32\nvoglv32.dll 2009-06-10 06:03 9,899,296 a——- c:\windows\system32\drivers\nvlddmkm.sys 2009-06-10 06:03 7,611,904 a——- c:\windows\system32\nvd3dum.dll 2009-06-10 06:03 3,148,288 a——- c:\windows\system32\nvwgf2um.dll 2009-06-10 06:03 1,704,960 a——- c:\windows\system32\nvcuda.dll 2009-06-10 06:03 1,317,408 a——- c:\windows\system32\nvcuvenc.dll 2009-06-10 06:03 989,696 a——- c:\windows\system32\nvapi.dll 2009-06-10 06:03 678,432 a——- c:\windows\system32\nvcuvid.dll 2009-06-10 06:03 457,248 a——- c:\windows\system32\nvudisp.exe 2009-06-10 06:03 151,552 a——- c:\windows\system32\nvcod155.dll 2009-06-10 06:03 151,552 a——- c:\windows\system32\nvcod.dll 2009-06-10 06:03 4,224 a——- c:\windows\system32\drivers\nvBridge.kmd 2009-06-04 16:39 457,248 a——- c:\windows\system32\NVUNINST.EXE 2009-05-09 00:50 915,456 a——- c:\windows\system32\wininet.dll 2009-05-09 00:34 71,680 a——- c:\windows\system32\iesetup.dll 2009-05-04 23:29 410,984 a——- c:\windows\system32\deploytk.dll 2009-04-28 09:55 70,936 a——- c:\windows\system32\PhysXLoader.dll 2009-04-23 07:15 784,896 a——- c:\windows\system32\rpcrt4.dll 2009-04-23 07:14 623,616 a——- c:\windows\system32\localspl.dll 2009-02-24 20:54 1,754 a——- c:\users\juleila\appdata\roaming\SAS7_000.DAT 2008-08-17 12:01 48 a—h— c:\programdata\ezsidmv.dat 2008-08-17 12:01 48 a—h— c:\progra~2\ezsidmv.dat 2008-01-20 21:43 174 a–sh— c:\program files\desktop.ini 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 1:08:39.41 ===============
Hi,

You are clean, just some housekeeping to do to make sure you stay that way.

P2P - I see you have P2P software emule and vuse installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.


NEXT



Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.


  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Well everything work just fine now thank you so much I will read all the advices you gave me and delete all the bad program Thank again for your time 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI