schlackeye
Topic Starter
The computer seems to work OK in normal but cannot enter any of the Windows Safe Modes. When trying to enter safe mode I receive this:
STOP: 0x0000007B (0xF789E524, 0xC0000034, 0x00000000, 0x00000000)
Please help! I am afraid of the problem getting worse!
Thanks!
Logs 2/22/10
Malwarebytes' Anti-Malware 1.42
Database version: 3289
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
2/22/2010 6:22:05 AM
mbam-log-2010-02-22 (06-22-05).txt
Scan type: Quick Scan
Objects scanned: 111808
Time elapsed: 4 minute(s), 18 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-22 07:34:48
Windows 5.1.2600 Service Pack 3
Running: GMER Rootkit Scanner.exe; Driver: C:\DOCUME~1\HUNTER~1\LOCALS~1\Temp\kxtdqpod.sys
—- System - GMER 1.0.15 —-
SSDT F7AB1346 ZwCreateKey
SSDT F7AB133C ZwCreateThread
SSDT F7AB134B ZwDeleteKey
SSDT F7AB1355 ZwDeleteValueKey
SSDT F7AB135A ZwLoadKey
SSDT F7AB1328 ZwOpenProcess
SSDT F7AB132D ZwOpenThread
SSDT F7AB1364 ZwReplaceKey
SSDT F7AB135F ZwRestoreKey
SSDT F7AB1350 ZwSetValueKey
SSDT F7AB1337 ZwTerminateProcess
—- Kernel code sections - GMER 1.0.15 —-
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF6D78360, 0x2456AE, 0xE8000020]
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!??2@YAPAXI@Z 77C29CC5 5 Bytes JMP 0A90B990 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!??3@YAXPAX@Z 77C29CDD 5 Bytes JMP 0A90B7B0 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!?set_new_handler@@YAP6AXXZP6AXXZ@Z 77C29D9F 5 Bytes JMP 0A90BA10 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_aligned_offset_malloc 77C29DAF 5 Bytes JMP 0A90B8F0 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_aligned_free 77C29E33 5 Bytes JMP 0A90B7B0 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_aligned_malloc 77C29E52 5 Bytes JMP 0A90B8D0 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_aligned_offset_realloc 77C29E6E 5 Bytes JMP 0A90B930 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_aligned_realloc 77C29FC6 5 Bytes JMP 0A90B910 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_expand 77C29FE5 5 Bytes JMP 0A90B8B0 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_heapadd 77C2BC9F 5 Bytes JMP 0A90BA60 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_heapchk 77C2BCB3 5 Bytes JMP 0A90BA70 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_heapset + 1 77C2BD83 4 Bytes JMP 0A90BA91 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_heapmin 77C2BD8C 5 Bytes JMP 0A90BB60 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_heapused 77C2BE3A 5 Bytes JMP 0A90BB30 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_heapwalk 77C2BE4D 5 Bytes JMP 0A90BAA0 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_msize 77C2BF6C 5 Bytes JMP 0A90B7C0 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!calloc 77C2C0C3 5 Bytes JMP 0A90B750 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!free 77C2C21B 5 Bytes JMP 0A90B7B0 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!malloc 77C2C407 5 Bytes JMP 0A90B710 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!realloc 77C2C437 5 Bytes JMP 0A90B790 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Fastfat \Fat B5FDCD20
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
—- EOF - GMER 1.0.15 —-
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 7:56:54.84 on Mon 02/22/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.525 [GMT -5:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Macromedia\runtime\bin\jrunsvc.exe
C:\Program Files\Macromedia\db\slserver52\bin\swagent.exe
C:\Program Files\Macromedia\db\slserver52\bin\swstrtr.exe
C:\Program Files\Macromedia\runtime\bin\jrun.exe
C:\Program Files\Macromedia\db\slserver52\bin\swsoc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Macromedia\Flash Communication Server MX\FlashComAdmin.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Microsoft Works\WkDStore.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Documents and Settings\Hunter Sims\My Documents\Software\New Security Proggies\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://insightbb.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070119
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
mPolicies-system: EnableLUA = 0 (0x0)
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partygaming\partypoker\RunApp.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - c:\program files\bodog poker\BPGame.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1253491739836
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-9-20 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-9-20 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-9-20 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-9-20 56816]
R2 ColdFusion MX ODBC Agent;ColdFusion MX ODBC Agent;c:\program files\macromedia\db\slserver52\bin\swagent.exe "coldfusion mx odbc agent" –> c:\program files\macromedia\db\slserver52\bin\swagent.exe ColdFusion MX ODBC Agent [?]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-1-19 1174152]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
=============== Created Last 30 ================
==================== Find3M ====================
2010-02-22 07:55 23,862 a——- c:\docume~1\hunter~1\applic~1\wklnhst.dat
2010-02-22 07:50 21 a——- C:\qpmd8376.bin
2010-01-14 11:12 181,120 ——– c:\windows\system32\MpSigStub.exe
2009-12-15 08:39 60,336 a——- c:\docume~1\hunter~1\applic~1\GDIPFONTCACHEV1.DAT
2009-08-03 16:29 88 —shr– c:\windows\system32\BAF6B4705F.sys
2009-08-03 16:29 2,516 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-09-29 09:50 16,384 a–sh— c:\windows\system32\config\systemprofile\ietldcache\index.dat
2009-09-21 01:44 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009091420090921\index.dat
2009-09-21 01:44 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009092120090922\index.dat
============= FINISH: 7:57:22.62 ===============
STOP: 0x0000007B (0xF789E524, 0xC0000034, 0x00000000, 0x00000000)
Please help! I am afraid of the problem getting worse!
Thanks!
Logs 2/22/10
Malwarebytes' Anti-Malware 1.42
Database version: 3289
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
2/22/2010 6:22:05 AM
mbam-log-2010-02-22 (06-22-05).txt
Scan type: Quick Scan
Objects scanned: 111808
Time elapsed: 4 minute(s), 18 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-22 07:34:48
Windows 5.1.2600 Service Pack 3
Running: GMER Rootkit Scanner.exe; Driver: C:\DOCUME~1\HUNTER~1\LOCALS~1\Temp\kxtdqpod.sys
—- System - GMER 1.0.15 —-
SSDT F7AB1346 ZwCreateKey
SSDT F7AB133C ZwCreateThread
SSDT F7AB134B ZwDeleteKey
SSDT F7AB1355 ZwDeleteValueKey
SSDT F7AB135A ZwLoadKey
SSDT F7AB1328 ZwOpenProcess
SSDT F7AB132D ZwOpenThread
SSDT F7AB1364 ZwReplaceKey
SSDT F7AB135F ZwRestoreKey
SSDT F7AB1350 ZwSetValueKey
SSDT F7AB1337 ZwTerminateProcess
—- Kernel code sections - GMER 1.0.15 —-
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF6D78360, 0x2456AE, 0xE8000020]
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!??2@YAPAXI@Z 77C29CC5 5 Bytes JMP 0A90B990 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!??3@YAXPAX@Z 77C29CDD 5 Bytes JMP 0A90B7B0 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!?set_new_handler@@YAP6AXXZP6AXXZ@Z 77C29D9F 5 Bytes JMP 0A90BA10 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_aligned_offset_malloc 77C29DAF 5 Bytes JMP 0A90B8F0 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_aligned_free 77C29E33 5 Bytes JMP 0A90B7B0 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_aligned_malloc 77C29E52 5 Bytes JMP 0A90B8D0 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_aligned_offset_realloc 77C29E6E 5 Bytes JMP 0A90B930 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_aligned_realloc 77C29FC6 5 Bytes JMP 0A90B910 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_expand 77C29FE5 5 Bytes JMP 0A90B8B0 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_heapadd 77C2BC9F 5 Bytes JMP 0A90BA60 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_heapchk 77C2BCB3 5 Bytes JMP 0A90BA70 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_heapset + 1 77C2BD83 4 Bytes JMP 0A90BA91 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_heapmin 77C2BD8C 5 Bytes JMP 0A90BB60 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_heapused 77C2BE3A 5 Bytes JMP 0A90BB30 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_heapwalk 77C2BE4D 5 Bytes JMP 0A90BAA0 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!_msize 77C2BF6C 5 Bytes JMP 0A90B7C0 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!calloc 77C2C0C3 5 Bytes JMP 0A90B750 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!free 77C2C21B 5 Bytes JMP 0A90B7B0 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!malloc 77C2C407 5 Bytes JMP 0A90B710 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe[2280] msvcrt.dll!realloc 77C2C437 5 Bytes JMP 0A90B790 C:\Program Files\Macromedia\Flash Communication Server MX\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Fastfat \Fat B5FDCD20
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
—- EOF - GMER 1.0.15 —-
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 7:56:54.84 on Mon 02/22/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.525 [GMT -5:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Macromedia\runtime\bin\jrunsvc.exe
C:\Program Files\Macromedia\db\slserver52\bin\swagent.exe
C:\Program Files\Macromedia\db\slserver52\bin\swstrtr.exe
C:\Program Files\Macromedia\runtime\bin\jrun.exe
C:\Program Files\Macromedia\db\slserver52\bin\swsoc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Macromedia\Flash Communication Server MX\FlashComAdmin.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Microsoft Works\WkDStore.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Documents and Settings\Hunter Sims\My Documents\Software\New Security Proggies\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://insightbb.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070119
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
mPolicies-system: EnableLUA = 0 (0x0)
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partygaming\partypoker\RunApp.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - c:\program files\bodog poker\BPGame.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1253491739836
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-9-20 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-9-20 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-9-20 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-9-20 56816]
R2 ColdFusion MX ODBC Agent;ColdFusion MX ODBC Agent;c:\program files\macromedia\db\slserver52\bin\swagent.exe "coldfusion mx odbc agent" –> c:\program files\macromedia\db\slserver52\bin\swagent.exe ColdFusion MX ODBC Agent [?]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-1-19 1174152]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
=============== Created Last 30 ================
==================== Find3M ====================
2010-02-22 07:55 23,862 a——- c:\docume~1\hunter~1\applic~1\wklnhst.dat
2010-02-22 07:50 21 a——- C:\qpmd8376.bin
2010-01-14 11:12 181,120 ——– c:\windows\system32\MpSigStub.exe
2009-12-15 08:39 60,336 a——- c:\docume~1\hunter~1\applic~1\GDIPFONTCACHEV1.DAT
2009-08-03 16:29 88 —shr– c:\windows\system32\BAF6B4705F.sys
2009-08-03 16:29 2,516 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-09-29 09:50 16,384 a–sh— c:\windows\system32\config\systemprofile\ietldcache\index.dat
2009-09-21 01:44 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009091420090921\index.dat
2009-09-21 01:44 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009092120090922\index.dat
============= FINISH: 7:57:22.62 ===============