This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] SkyMedia adware, maybe more?

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello. I've just discovered this website - it looks like an amazing online resource, and I hope somebody here will be able to help me (considering I'm barely beyond the "novice" stage - if that). First: here are a few basics about my system:

Manuf/Model: Dell Inspiron 530
Processor: Intel Core2 Quad CPU Q6600 @ 2.40GHz
RAM: 3.00 GB
OS: Win Vista Home Ultimate SP2 (32-bit)

Sometime back (maybe six months ago or so?) I seem to have picked up, without realizing it, some sort of add-on for IE8, while trying out some other software (which I didn't even decide to keep). I had opted not to take the add-on when it looked like it was trying to be installed, and when I uninstalled the other software, I thought (incorrectly) that it had removed everything it should have.

Recently, I thought I noticed that web pages were loading more slowly, and I got a couple of pop-up error messages that IE8 had stopped working and would need to be closed (even though that did not appear to be the case), and I was able to merely escape out of the "error messages". Windows also recently popped up with a "Problem Report and Solution" suggesting that issues with IE8 might be caused by add-ons. In taking a fresh look at what add-ons were installed, I noticed the pesky item that I thought had been removed was still listed (though it was shown as "disabled"). I tried to remove it, using the Program Uninstall feature from the Control Panel, and it disappeared from the IE8 menu.

At this point however, I discovered that there were still a folder and subfolder left behind on my C: drive, under the Program Files folder. I still wasn't unduly alarmed by that (it doesn't seem to be TOO unusual for an uninstll routine to leave behind a few stray files or folders). So, after navigating in Windows Explorer to the folder Program Files/SkymediaPack (and its subfolder "SkyToolbar"), I tried to "permanently" delete it. At that point, I saw the following series of prompts:

"Are you sure you want to permanently delete this folder? Yes/No"

Selecting "Yes" brought up:
"You need to confirm this operation. Continue/Skip/Cancel"

Selecting "Continue" brought up a UAC dialog:
"Windows needs your permission to continue. If you started this action, continue. File Operation Microsoft Windows
{3AD05575-8857-4850-9277-11B85BDI
Continue/Cancel"

Selecting "Continue" brought up this alarming prompt:
"Destination Folder Access Denied
You need permission to perform this action
SkyToolbar
Date created 5/19/2009 10:40 PM
Try Again/Skip/Cancel"

Selecting "Try Again" appears to result in and endless loop in which that same prompt just keeps re-appearing. Selecting "Skip" or "Cancel" has just the effect they would suggest - leaving the folders in place. And sure enough, now, when I try to open the SkyToolbar subfolder in Windows Explorer, I get a pop-up announcing "Location is not available. C:\Program Files\SkyMediaPack\SkyToolbar is not accessible. Access is Denied." The only option offered is "OK". I *WAS* able to look at the contents before, but of course, now I can't remember what it contained (one file, two? file name?).

Trying to follow the instructions in the "Are You Infected" topic, I ran ATF-Cleaner. I selected all and emptied them (though the pre-fetch choice was "disabled" - was that intended, or an anomaly?).

I ran SystemRestorePoint.exe successfully. Q: (just out of sheer curiosity) Is there a specific reason why it was necessary to download and run a special utility for this, instead of simply creating a restore point with the system's Backup/Restore function in the Control Panel?

ERUNT seemed to run successfully, so I should have a proper backup of the registry.

I downloaded MBAM; it sucessfully updated from V3510 to V3811. When run, it reported finding 6 items infected - 4 registry keys & 2 folders, all of which appeared to be related to that annoying SkyMedia stuff. After trying to remove the "selected" items, it reported that the 2 folders needed to be deleted on reboot; so I rebooted, and they appear to be gone (yay!). At this point, you folks are already my heroes. :lol:

I then downloaded GMER. At first, it seemed to be running OK, but then it seemed to get hung up while scanning something called: \device\HarddiskVolumeShadowCopy20. After more than 5 hours spent scanning that one item, I decided that it must have run into a problem, and hit the "STOP" button. I saved what there was into a logfile. The instructions in "Are You Infected" said DeFogger should be run "If GMER doesn't start". At risk of interpreting this too literally, I decided that, since GMER did start (it just didn't finish), I should hold off on DeFogger unless specifically instructed to use it by one of your experts.

Finally, I downloaded and ran DDS. For now, it looks like MBAM was enough, by itself, to deal with the specific item that first led me here. But now, after GMER failed to give me an all-clear, I have the heebie-jeebies thinking I may have something even more insidious quietly festering in my system. I look forward to your assistance in straightening this out; and thank you in advance for any additional assistance you may be able to provide. Here are the logfiles that "Are You Infected" requested that I post:

—– MBAM logfile —–
Malwarebytes' Anti-Malware 1.44
Database version: 3811
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865

3/1/2010 8:57:15 PM
mbam-log-2010-03-01 (20-57-15).txt

Scan type: Quick Scan
Objects scanned: 128876
Time elapsed: 7 minute(s), 35 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f334c7b0-8774-4d5b-bd7a-4f448d03a1ae} (Adware.SkyLab) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2863e737-dd3f-4280-9af8-e9e79c16f312} (Adware.SkyMediaPack) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{f334c7b0-8774-4d5b-bd7a-4f448d03a1ae} (Adware.SkyLab) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{2863e737-dd3f-4280-9af8-e9e79c16f312} (Adware.SkyMediaPack) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\SkyMediaPack (Adware.SkyMediaPack) -> Delete on reboot.
C:\Program Files\SkyMediaPack\SkyToolbar (Adware.SkyMediaPack) -> Quarantined and deleted successfully.

Files Infected:
(No malicious items detected)

—– GMER logfile (partial?)—–

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-02 02:48:17
Windows 6.0.6002 Service Pack 2
Running: v2xpwv9v.exe; Driver: C:\Users\LeeAd\AppData\Local\Temp\fxtdipow.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x8A411CDE]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x8A411ED0]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0x8A411984]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x8A4120D8]

Code 716FFFFB NtTestAlert
Code 716FFFFB ZwTestAlert

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!KeSetEvent + 209 822E194C 8 Bytes [DE, 1C, 41, 8A, D0, 1E, 41, …]
.text ntkrnlpa.exe!KeSetEvent + 621 822E1D64 4 Bytes [84, 19, 41, 8A]
.text ntkrnlpa.exe!KeSetEvent + 6E5 822E1E28 4 Bytes [D8, 20, 41, 8A]
? System32\drivers\gmfdtth.sys The system cannot find the path specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehmsas.exe[168] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\ehome\ehmsas.exe[168] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\smss.exe[448] ntdll.dll!NtTestAlert 76EC5514 5 Bytes JMP 71700000
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[512] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[512] KERNEL32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[596] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\wininit.exe[596] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[608] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[608] KERNEL32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[644] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\services.exe[644] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[672] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\winlogon.exe[672] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[704] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsass.exe[704] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsm.exe[720] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\ico.exe[784] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\ico.exe[784] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[872] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[876] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[876] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[984] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1112] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1112] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1144] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1144] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1188] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1188] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1204] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1372] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1372] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[1424] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\Ctxfihlp.exe[1424] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\SLsvc.exe[1432] ntdll.dll!NtTestAlert 76EC5514 5 Bytes JMP 71700000
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1500] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe[1516] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1608] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1632] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WinAmp\winampa.exe[1700] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\WinAmp\winampa.exe[1700] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\wbem\unsecapp.exe[1744] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Ati2evxx.exe[1792] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\Ati2evxx.exe[1792] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1884] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\spoolsv.exe[1884] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1916] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1916] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[2056] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2124] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[2124] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Pmxmiced.exe[2148] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\Pmxmiced.exe[2148] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[2168] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe[2236] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2260] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[2288] ntdll.dll!NtTestAlert 76EC5514 5 Bytes JMP 71700000
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[2288] kernel32.dll!CreateThread + 1A 7569C928 4 Bytes CALL 0044BC05 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[2368] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Secura Backup\securasvc.exe[2372] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2400] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2416] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2432] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2460] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[2460] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[2480] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe[2548] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[2628] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2700] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[2700] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[2740] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\SearchIndexer.exe[2740] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\DRIVERS\xaudio.exe[2820] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\ehome\ehtray.exe[2856] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\ehome\ehtray.exe[2856] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe[2900] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WUDFHost.exe[2992] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\WUDFHost.exe[2992] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3016] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\taskeng.exe[3016] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[3032] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe[3092] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe[3172] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe[3176] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3372] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe[3460] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe[3508] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[3556] ntdll.dll!NtTestAlert 76EC5514 5 Bytes JMP 71700000
.text C:\Program Files\Spyware Doctor\pctsTray.exe[3556] kernel32.dll!CreateThread + 1A 7569C928 4 Bytes CALL 0044B8D9 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Users\LeeAd\Desktop\v2xpwv9v.exe[3672] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3684] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3720] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe[3748] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3896] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\Dwm.exe[3896] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3940] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\taskeng.exe[3940] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3948] ntdll.dll!NtTestAlert 76EC5514 5 Bytes JMP 71700000
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe[3992] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[4004] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\Explorer.EXE[4004] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe[4184] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE[4760] KERNEL32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe[4768] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[4824] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[4988] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Windows\system32\wuauclt.exe[4988] kernel32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateProcess 76EC4494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateProcess + 4 76EC4498 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateProcessEx 76EC44A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateProcessEx + 4 76EC44A8 2 Bytes [11, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateSection 76EC44C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateSection + 4 76EC44C8 2 Bytes [05, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtTerminateProcess 76EC54F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtTerminateProcess + 4 76EC54F8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtWriteVirtualMemory 76EC5674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtWriteVirtualMemory + 4 76EC5678 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateUserProcess 76EC5804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] ntdll.dll!NtCreateUserProcess + 4 76EC5808 2 Bytes [0B, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[5096] KERNEL32.dll!LoadLibraryExW 75679109 6 Bytes JMP 5F070F5A

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[2288] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044BD5C] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[2288] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044BD5C] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[3556] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73D27817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73D7A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73D2BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73D1F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73D275E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73D1E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [73D58395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [73D2DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73D1FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73D1FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73D171CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [73DACAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [73D4C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73D1D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73D16853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73D1687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4004] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73D22AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\tdx \Device\Tcp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\PCTSDInjDriver32 \Device\PCTSDInjDriver32 PCTSDInj32.sys

AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume8 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)


—– DDS logfiles —–


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 3:52:28.18 on Tue 03/02/2010
Internet Explorer: 8.0.6001.18865
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3069.1759 [GMT -5:00]

AV: PC-cillin Internet Security - Virus Protection *On-access scanning enabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
SP: PC-cillin Internet Security - Spyware Protection *enabled* (Updated) {003DD9A8-02A6-43CF-81BA-5D403CAD001E}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Sunbelt Software Sunbelt CounterSpy 2.5.1043 *enabled* (Outdated) {9817B764-AE4E-4B29-AEE7-725B7A50BD48}
FW: PC-cillin Internet Security - Firewall *enabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Secura Backup\securasvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\Windows\System32\ico.exe
C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\WinAmp\winampa.exe
C:\Windows\System32\Ctxfihlp.exe
C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\PKWARE\PKZIPM\12.10.0012\PKTray.exe
C:\Windows\System32\Pmxmiced.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
C:\Windows\SYSTEM32\CTXFISPI.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\mobsync.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\LeeAd\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = about:blank
uWindow Title = Internet Explorer provided by Dell
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\programdata\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [DellAutomatedPCTuneUp] "c:\program files\dellautomatedpctuneup\PTAgnt.exe" /startup
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [Google Update] "c:\users\leead\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: []
mRun: [WrtMon.exe] c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanlu.exe" /r
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [SBCSTray] c:\program files\sunbelt software\counterspy\SBCSTray.exe
mRun: [PMX Daemon] ICO.EXE
mRun: [pccguide.exe] "c:\program files\trend micro\internet security 14\pccguide.exe"
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4.0\OpwareSE4.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [PKWARE Certificate Proxy Client] c:\progra~1\pkware\pkzipw\pkpcsr.exe
mRun: [SBRegRebootCleaner] c:\program files\sunbelt software\counterspy\SBRC.exe
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [Google Updater] "c:\program files\google\google updater\GoogleUpdater.exe" -systray -startup
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe"
dRun: [CtxfiReg] CTXFIREG.exe /FAIL2
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\boincm~1.lnk - c:\program files\boinc\boincmgr.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\secure~1.lnk - c:\program files\pkware\pkzipm\12.10.0012\PKTray.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\programdata\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL
STS: Windows DreamScene: {e31004d1-a431-41b8-826f-e902f9d95c81} - %SystemRoot%\System32\DreamScene.dll

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-12-29 207792]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\adobe\photoshop elements 6.0\PhotoshopElementsFileAgent.exe [2007-9-11 124832]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\microsoft small business\business contact manager\BcmSqlStartupSvc.exe [2008-1-11 30312]
R2 datunidr;DellAutomatedPCTuneUp UniDriver;c:\windows\system32\drivers\datunidr.sys [2007-8-23 5376]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-5-6 36368]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2009-7-13 198168]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2009-2-19 1353240]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2009-7-13 73752]
R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2008-5-6 18432]
R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2008-5-6 19008]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2008-5-6 280392]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2009-7-13 198168]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2009-2-19 1353240]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2009-7-13 73752]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-11 21504]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-5-6 30192]
S3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2009-2-19 1222680]
S3 HSXHWCD2;HSXHWCD2;c:\windows\system32\drivers\HSXHWCD2.sys [2008-6-10 243712]

=============== Created Last 30 ================

2010-03-01 20:45 –d—– c:\users\leead\appdata\roaming\Malwarebytes
2010-03-01 20:45 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-01 20:44 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-03-01 20:44 –d—– c:\programdata\Malwarebytes
2010-03-01 20:44 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-03-01 20:44 –d—– c:\progra~2\Malwarebytes
2010-02-23 17:11 –d—– C:\JAM Software
2010-02-12 20:50 21,163,478 a——- c:\windows\system32\SBSP.dat
2010-02-04 01:33 –d—– c:\windows\system32\appmgmt

==================== Find3M ====================

2010-02-16 21:36 143,360 a——- c:\windows\inf\infstrng.dat
2010-02-16 21:36 51,200 a——- c:\windows\inf\infpub.dat
2009-12-10 21:31 665,600 a——- c:\windows\inf\drvindex.dat
2009-12-10 21:31 143,360 a——- c:\windows\inf\infstor.dat
2008-07-18 22:08 174 a–sh— c:\program files\desktop.ini
2008-06-12 23:06 61,224 ——– c:\users\leead\GoToAssistDownloadHelper.exe
2006-11-02 07:40 287,440 ——– c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:40 287,440 ——– c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:40 30,674 ——– c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:40 30,674 ——– c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 ——– c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 ——– c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 ——– c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 ——– c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 3:54:14.48 ===============


"attach.txt" is attached in the file "attach_txt.zip"

Thanks again!

Attachments:

Hi,

Please do the following:

**Vista users - right click on the IE icon and run as administrator

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan.
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Hi CatByte - Thanks for getting back to me. I greatly appreciate any help you'll be able to provide. I see that the file I attached to my first post, per the instructions in the "Are You Infected" topic, has been downloaded three times. Was that you? I wasn't entirely sure why the initial guidelines called for that file to be zipped and attached, rather than posted like the rest of the material. Am I putting my system at any kind of (even moderate) ongoing risk by leaving that attachment available in this public forum? Am I asking too many silly questions yet? :wacko: Anyway, I ran the Kaspersky scan you requested (3.5 hours +, whew!), and I'm trying to follow your advice (and that of the Hitchiker's Guide): "DON'T PANIC". That said, when the infection it reported finding sounds as scary as "Trojan-Downloader", not panicking is taking considerable effort. :pullhair: Here's the text from the scan's report: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, March 3, 2010 Operating system: Microsoft Windows Vista Ultimate Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, March 03, 2010 15:48:42 Records in database: 3699435 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ K:\ Scan statistics: Objects scanned: 183321 Threats found: 1 Infected objects found: 2 Suspicious objects found: 0 Scan duration: 03:39:27 File name / Threat / Threats count C:\Program Files\Trend Micro\Internet Security 14\Quarantine\40D8.tmp Infected: Trojan-Downloader.JS.Gumblar.a 1 K:\HOMESYS\Backup Set 2010-02-17 025948\Backup Files 2010-02-17 025948\Backup files 17.zip Infected: Trojan-Downloader.JS.Gumblar.a 1 Selected area has been scanned. ——————————————————————– Please advise me on what comes next… thanks.
Hi,

Please do the following:

Go Start > Run and copy/paste the following single-line command into the Run box and click OK:

cmd /c del /f/a/q "K:\HOMESYS\Backup Set 2010-02-17 025948\Backup Files 2010-02-17 025948\Backup files 17.zip"


that files is in the backyps you made in your K drive, so you need to make a new set of back up files once I delete this zipped folder.

The other file is in quarantine already, so it can't harm your computer.

Update and run your Malwarebytes Program one more time, make sure it comes back clean.

Post the resulting log


(don't worry about what is posted here, nothing can be used or tracked)
CatByte - Thank you very much for the timely reply. I ran MBAM again as you requested (after updating it from V3811 to V3823), and it reported finding nothing malicious (though it looks like the "quick scan" is only checking the C:\ drive, not my external K:\ drive). I think I may still have a problem though; before running MBAM, again as you requested, I cut/pasted the command line you provided into the "Run box", and pressed OK. However, after curiosity got the better of me, and I navigated via Windows Explorer to the K:\ drive, I found that the file was still there - it didn't appear to have been deleted. I wasn't foolish/curious enough to actually try opening the file, but (if I understood your last post correctly) I thought the intent was to delete it, so I was a bit concerned to see it still there…. :huh: The latest MBAM log follows: Malwarebytes' Anti-Malware 1.44 Database version: 3823 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18865 3/3/2010 8:17:30 PM mbam-log-2010-03-03 (20-17-30).txt Scan type: Quick Scan Objects scanned: 130877 Time elapsed: 6 minute(s), 28 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi,

Navigate back to that file on your K drive and right click the file and choose "delete"

how is the computer running? are there any outstanding issues?

NEXT

Visit ADOBEand download the latest version of Acrobat Reader (version 9.3)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT

[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 18 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 18 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u18 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u18-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
Hello again CatByte (and thanks again for all your patience with me) -

The file on the K: drive is now deleted. My computer is basically running OK, aside from not being able to complete the GMER scan (which still somewhat concerns me), and aside from a problem I've had for some time now getting a USB-connected Canon ImageClass MF4150 multi-function scanner/copier/printer to actually print. It's weird - the USB cable seems to be fine - the scanner works OK and sends images to the computer - but even after downloading and installing the latest/greatest driver available from Canon, I have yet to be able to print even so much as a test page. :( So far, this has defeated the abilities of the best tech support Dell & Canon had/were willing to make available to me. However, I imagine this has already gotten to be TMI for this forum (though now I wonder… is there any chance this is less a "hardware" issue than I'd thought, and somehow related to interference from malware?).

As per your latest set of instructions: I attempted to update Adobe, but was unable to complete the process. I have attached jpg images of the two-part error message the installation routine presented.

I was able to update the Java (the only previously installed Java item I saw was Java SE Runtime Environment 6, which uninstalled without difficulty). I followed your instructions to delete the downloaded apps & applets, and that seemed to go without a hitch.

Any suggestions now as to how to get the Adobe update to work, and as to what I should do about completing the GMER scan?
Let's dig a little deeper.

Please do the following:

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
CatByte -

I just finished running ComboFix. The logfile it created is below; meanwhile it seems to have deleted nearly everything in my system tray - is that normal? Should I restart my antivirus/antispyware and/or reboot now? Thanks for all the help…

ComboFix 10-03-03.03 - LeeAd 03/03/2010 22:05:22.1.4 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3069.1733 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: PC-cillin Internet Security - Virus Protection *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: PC-cillin Internet Security - Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
SP: PC-cillin Internet Security - Spyware Protection *disabled* (Updated) {003DD9A8-02A6-43CF-81BA-5D403CAD001E}
SP: Sunbelt Software Sunbelt CounterSpy 2.5.1043 *disabled* (Outdated) {9817B764-AE4E-4B29-AEE7-725B7A50BD48}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-1499513834-3245736753-3590406765-500
c:\$recycle.bin\S-1-5-21-1663819663-2835008902-2856250938-500
c:\$recycle.bin\S-1-5-21-51003140-4199384537-3980697693-500
c:\users\LeeAd\AppData\Local\Microsoft\Windows\Temporary Internet Files\CSC2.5U-EN-837-I.sbr.sgn
K:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2010-02-04 to 2010-03-04 )))))))))))))))))))))))))))))))
.

2010-03-04 03:15 . 2010-03-04 03:15 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-03-04 03:15 . 2010-03-04 03:15 ——– d—–w- c:\users\no_one\AppData\Local\temp
2010-03-04 02:31 . 2010-03-04 02:31 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-03-04 01:50 . 2010-03-04 02:00 ——– d—–w- c:\users\LeeAd\AppData\Local\Adobe
2010-03-04 00:26 . 2010-03-04 00:26 1232496 —-a-w- c:\programdata\Google\Google Toolbar\Component\GoogleCld_D9AEC8D4D1915047.dll
2010-03-03 19:41 . 2010-03-03 19:41 ——– d—–w- c:\windows\Sun
2010-03-02 01:45 . 2010-03-02 01:45 ——– d—–w- c:\users\LeeAd\AppData\Roaming\Malwarebytes
2010-03-02 01:45 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-02 01:44 . 2010-03-02 01:45 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-02 01:44 . 2010-03-02 01:44 ——– d—–w- c:\programdata\Malwarebytes
2010-03-02 01:44 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-02 01:31 . 2010-03-02 01:32 ——– d—–w- c:\program files\ERUNT
2010-02-23 22:11 . 2010-02-23 22:11 ——– d—–w- C:\JAM Software
2010-02-13 01:50 . 2010-02-13 01:50 21163478 —-a-w- c:\windows\system32\SBSP.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-04 02:35 . 2009-12-29 06:25 ——– d—–w- c:\program files\Spyware Doctor
2010-03-04 02:32 . 2008-05-06 18:48 ——– d—–w- c:\program files\Common Files\Java
2010-03-04 02:31 . 2008-05-06 18:48 ——– d—–w- c:\program files\Java
2010-03-04 02:24 . 2008-06-06 05:56 8160 —-a-w- c:\users\LeeAd\AppData\Local\d3d9caps.dat
2010-03-04 00:25 . 2008-05-06 19:10 ——– d—–w- c:\program files\Google
2010-03-02 01:20 . 2008-07-10 07:26 ——– d—–w- c:\program files\BOINC
2010-02-17 02:35 . 2008-05-06 18:49 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-17 02:35 . 2008-07-16 01:09 ——– d—–w- c:\program files\Maxtor
2010-02-13 01:50 . 2009-05-23 06:00 115 —-a-w- c:\windows\system32\SBFC.dat
2010-02-07 05:33 . 2009-12-29 06:22 ——– d—–w- c:\programdata\Google Updater
2010-01-21 18:05 . 2009-02-05 21:05 ——– d—–w- c:\program files\PKWARE
2010-01-18 00:19 . 2008-05-06 19:10 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-15 18:28 . 2010-01-15 17:56 ——– d—–w- c:\program files\Color Pickers
2010-01-15 08:26 . 2010-01-15 08:07 ——– d—–w- c:\users\LeeAd\AppData\Roaming\ColorCop
2009-12-30 04:29 . 2008-06-06 02:14 116536 —-a-w- c:\users\LeeAd\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-29 08:50 . 2008-06-09 03:17 116536 —-a-w- c:\users\no_one\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-11 02:31 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2008-05-07 02:23 . 2008-05-07 02:12 8192 –sh–w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-06 68856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"DellAutomatedPCTuneUp"="c:\program files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 465136]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Google Update"="c:\users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-03-01 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WrtMon.exe"="c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2007-04-17 184320]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 185896]
"SBCSTray"="c:\program files\Sunbelt Software\CounterSpy\SBCSTray.exe" [2007-12-21 698864]
"PMX Daemon"="ICO.EXE" [2006-11-08 49152]
"pccguide.exe"="c:\program files\Trend Micro\Internet Security 14\pccguide.exe" [2006-11-21 1807960]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-11-23 30192]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-10-28 128296]
"PKWARE Certificate Proxy Client"="c:\progra~1\PKWARE\PKZIPW\pkpcsr.exe" [2008-03-28 226640]
"SBRegRebootCleaner"="c:\program files\Sunbelt Software\CounterSpy\SBRC.exe" [2007-12-21 141808]
"WinampAgent"="c:\program files\WinAmp\winampa.exe" [2009-04-10 37888]
"CTxfiHlp"="CTXFIHLP.EXE" [2009-02-19 24576]
"Google Updater"="c:\program files\Google\Google Updater\GoogleUpdater.exe" [2009-12-29 160752]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-11-18 1243088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2008-07-21 169312]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CtxfiReg"="CTXFIREG.exe" [2009-02-19 47104]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BOINC Manager.lnk - c:\program files\BOINC\boincmgr.exe [2008-3-4 4150016]
SecureZIP Attachments Status.lnk - c:\program files\PKWARE\PKZIPM\12.10.0012\PKTray.exe [2009-2-5 197968]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-05-06 19:27 10536 ——w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBCSSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):ab,63,a1,97,44,28,ca,01

R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [12/29/2009 1:25 AM 207792]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [12/29/2009 1:25 AM 359624]
R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [11/9/2007 5:19 AM 345696]
R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [11/9/2007 5:19 AM 923216]
R2 tmpreflt;tmpreflt;c:\windows\System32\drivers\tmpreflt.sys [5/6/2008 1:57 PM 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [11/9/2007 5:19 AM 566872]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.sys [7/13/2009 5:50 PM 198168]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.sys [2/19/2009 9:43 AM 1353240]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.sys [7/13/2009 5:51 PM 73752]
R3 pmxmouse;PMXMOUSE;c:\windows\System32\drivers\pmxmouse.sys [5/6/2008 1:49 PM 18432]
R3 pmxusblf;PMXUSBLF;c:\windows\System32\drivers\pmxusblf.sys [5/6/2008 1:49 PM 19008]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\System32\drivers\TM_CFW.sys [5/6/2008 1:57 PM 280392]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3/3/2010 7:25 PM 135664]
S2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [12/14/2007 2:25 PM 166384]
S2 SecuraService;SecuraService;c:\program files\Secura Backup\securasvc.exe [7/6/2008 9:56 PM 1367040]
S2 SessionLauncher;SessionLauncher;c:\users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe –> c:\users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [?]
S3 CT20XUT;CT20XUT;c:\windows\System32\drivers\CT20XUT.sys [7/13/2009 5:50 PM 198168]
S3 CTEXFIFX;CTEXFIFX;c:\windows\System32\drivers\CTEXFIFX.sys [2/19/2009 9:43 AM 1353240]
S3 CTHWIUT;CTHWIUT;c:\windows\System32\drivers\CTHWIUT.sys [7/13/2009 5:51 PM 73752]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [5/6/2008 2:10 PM 30192]
S3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\System32\drivers\ha20x22k.sys [2/19/2009 9:54 AM 1222680]
S3 HSXHWCD2;HSXHWCD2;c:\windows\System32\drivers\HSXHWCD2.sys [6/10/2008 1:33 AM 243712]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [12/14/2007 2:25 PM 1112560]

— Other Services/Drivers In Memory —

*Deregistered* - PCTSDInjDriver32

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
2008-04-11 21:23 38400 ——w- c:\windows\System32\SoundSchemes.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24}]
2008-08-28 14:50 30720 —-a-w- c:\windows\System32\soundschemes2.exe
.
Contents of the 'Scheduled Tasks' folder

2010-03-04 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-06 04:02]

2010-03-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-04 00:25]

2010-03-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-04 00:25]

2010-03-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1499513834-3245736753-3590406765-1003Core.job
- c:\users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-01 07:57]

2010-03-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1499513834-3245736753-3590406765-1003UA.job
- c:\users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-01 07:57]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -

AddRemove-Google Desktop - c:\program files\Google\Google Desktop Search\GoogleDesktopSetup.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-03 22:15
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTxfiHlp = CTXFIHLP.EXE?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD DX\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2010-03-03 22:19:02
ComboFix-quarantined-files.txt 2010-03-04 03:18

Pre-Run: 528,870,969,344 bytes free
Post-Run: 528,819,888,128 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=8 Sets=1,2,3,4,5,6,7,8
- - End Of File - - 2F41E190012E23DFBAE5B25A057B521A
Hi,

Please do the following:


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

FixCSet::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Ran ComboFix again with the text you supplied; what should I do next?

New ComboFix log:

ComboFix 10-03-03.03 - LeeAd 03/03/2010 23:33:11.2.4 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3069.1597 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\LeeAd\Desktop\CFScript.txt
AV: PC-cillin Internet Security - Virus Protection *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: PC-cillin Internet Security - Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
SP: PC-cillin Internet Security - Spyware Protection *disabled* (Updated) {003DD9A8-02A6-43CF-81BA-5D403CAD001E}
SP: Sunbelt Software Sunbelt CounterSpy 2.5.1043 *disabled* (Outdated) {9817B764-AE4E-4B29-AEE7-725B7A50BD48}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2010-02-04 to 2010-03-04 )))))))))))))))))))))))))))))))
.

2010-03-04 04:41 . 2010-03-04 04:41 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-03-04 04:41 . 2010-03-04 04:41 ——– d—–w- c:\users\no_one\AppData\Local\temp
2010-03-04 04:41 . 2010-03-04 04:41 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-03-04 02:31 . 2010-03-04 02:31 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-03-04 01:50 . 2010-03-04 02:00 ——– d—–w- c:\users\LeeAd\AppData\Local\Adobe
2010-03-04 00:26 . 2010-03-04 00:26 1232496 —-a-w- c:\programdata\Google\Google Toolbar\Component\GoogleCld_D9AEC8D4D1915047.dll
2010-03-03 19:41 . 2010-03-03 19:41 ——– d—–w- c:\windows\Sun
2010-03-02 01:45 . 2010-03-02 01:45 ——– d—–w- c:\users\LeeAd\AppData\Roaming\Malwarebytes
2010-03-02 01:45 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-02 01:44 . 2010-03-02 01:45 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-02 01:44 . 2010-03-02 01:44 ——– d—–w- c:\programdata\Malwarebytes
2010-03-02 01:44 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-02 01:31 . 2010-03-02 01:32 ——– d—–w- c:\program files\ERUNT
2010-02-23 22:11 . 2010-02-23 22:11 ——– d—–w- C:\JAM Software
2010-02-13 01:50 . 2010-02-13 01:50 21163478 —-a-w- c:\windows\system32\SBSP.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-04 04:48 . 2009-12-29 06:25 ——– d—–w- c:\program files\Spyware Doctor
2010-03-04 02:32 . 2008-05-06 18:48 ——– d—–w- c:\program files\Common Files\Java
2010-03-04 02:31 . 2008-05-06 18:48 ——– d—–w- c:\program files\Java
2010-03-04 02:24 . 2008-06-06 05:56 8160 —-a-w- c:\users\LeeAd\AppData\Local\d3d9caps.dat
2010-03-04 00:25 . 2008-05-06 19:10 ——– d—–w- c:\program files\Google
2010-03-02 01:20 . 2008-07-10 07:26 ——– d—–w- c:\program files\BOINC
2010-02-17 02:35 . 2008-05-06 18:49 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-17 02:35 . 2008-07-16 01:09 ——– d—–w- c:\program files\Maxtor
2010-02-13 01:50 . 2009-05-23 06:00 115 —-a-w- c:\windows\system32\SBFC.dat
2010-02-07 05:33 . 2009-12-29 06:22 ——– d—–w- c:\programdata\Google Updater
2010-01-21 18:05 . 2009-02-05 21:05 ——– d—–w- c:\program files\PKWARE
2010-01-18 00:19 . 2008-05-06 19:10 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-15 18:28 . 2010-01-15 17:56 ——– d—–w- c:\program files\Color Pickers
2010-01-15 08:26 . 2010-01-15 08:07 ——– d—–w- c:\users\LeeAd\AppData\Roaming\ColorCop
2009-12-30 04:29 . 2008-06-06 02:14 116536 —-a-w- c:\users\LeeAd\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-29 08:50 . 2008-06-09 03:17 116536 —-a-w- c:\users\no_one\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-11 02:31 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2008-05-07 02:23 . 2008-05-07 02:12 8192 –sh–w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-06 68856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"DellAutomatedPCTuneUp"="c:\program files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 465136]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Google Update"="c:\users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-03-01 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WrtMon.exe"="c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2007-04-17 184320]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 185896]
"SBCSTray"="c:\program files\Sunbelt Software\CounterSpy\SBCSTray.exe" [2007-12-21 698864]
"PMX Daemon"="ICO.EXE" [2006-11-08 49152]
"pccguide.exe"="c:\program files\Trend Micro\Internet Security 14\pccguide.exe" [2006-11-21 1807960]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-11-23 30192]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-10-28 128296]
"PKWARE Certificate Proxy Client"="c:\progra~1\PKWARE\PKZIPW\pkpcsr.exe" [2008-03-28 226640]
"SBRegRebootCleaner"="c:\program files\Sunbelt Software\CounterSpy\SBRC.exe" [2007-12-21 141808]
"WinampAgent"="c:\program files\WinAmp\winampa.exe" [2009-04-10 37888]
"CTxfiHlp"="CTXFIHLP.EXE" [2009-02-19 24576]
"Google Updater"="c:\program files\Google\Google Updater\GoogleUpdater.exe" [2009-12-29 160752]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-11-18 1243088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2008-07-21 169312]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CtxfiReg"="CTXFIREG.exe" [2009-02-19 47104]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BOINC Manager.lnk - c:\program files\BOINC\boincmgr.exe [2008-3-4 4150016]
SecureZIP Attachments Status.lnk - c:\program files\PKWARE\PKZIPM\12.10.0012\PKTray.exe [2009-2-5 197968]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-05-06 19:27 10536 ——w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBCSSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):ab,63,a1,97,44,28,ca,01

R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [12/29/2009 1:25 AM 207792]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [12/29/2009 1:25 AM 359624]
R2 SecuraService;SecuraService;c:\program files\Secura Backup\securasvc.exe [7/6/2008 9:56 PM 1367040]
R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [11/9/2007 5:19 AM 345696]
R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [11/9/2007 5:19 AM 923216]
R2 tmpreflt;tmpreflt;c:\windows\System32\drivers\tmpreflt.sys [5/6/2008 1:57 PM 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [11/9/2007 5:19 AM 566872]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.sys [7/13/2009 5:50 PM 198168]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.sys [2/19/2009 9:43 AM 1353240]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.sys [7/13/2009 5:51 PM 73752]
R3 pmxmouse;PMXMOUSE;c:\windows\System32\drivers\pmxmouse.sys [5/6/2008 1:49 PM 18432]
R3 pmxusblf;PMXUSBLF;c:\windows\System32\drivers\pmxusblf.sys [5/6/2008 1:49 PM 19008]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\System32\drivers\TM_CFW.sys [5/6/2008 1:57 PM 280392]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3/3/2010 7:25 PM 135664]
S2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [12/14/2007 2:25 PM 166384]
S2 SessionLauncher;SessionLauncher;c:\users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe –> c:\users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [?]
S3 CT20XUT;CT20XUT;c:\windows\System32\drivers\CT20XUT.sys [7/13/2009 5:50 PM 198168]
S3 CTEXFIFX;CTEXFIFX;c:\windows\System32\drivers\CTEXFIFX.sys [2/19/2009 9:43 AM 1353240]
S3 CTHWIUT;CTHWIUT;c:\windows\System32\drivers\CTHWIUT.sys [7/13/2009 5:51 PM 73752]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [5/6/2008 2:10 PM 30192]
S3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\System32\drivers\ha20x22k.sys [2/19/2009 9:54 AM 1222680]
S3 HSXHWCD2;HSXHWCD2;c:\windows\System32\drivers\HSXHWCD2.sys [6/10/2008 1:33 AM 243712]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [12/14/2007 2:25 PM 1112560]

— Other Services/Drivers In Memory —

*Deregistered* - PCTSDInjDriver32

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
2008-04-11 21:23 38400 ——w- c:\windows\System32\SoundSchemes.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24}]
2008-08-28 14:50 30720 —-a-w- c:\windows\System32\soundschemes2.exe
.
Contents of the 'Scheduled Tasks' folder

2010-03-04 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-06 04:02]

2010-03-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-04 00:25]

2010-03-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-04 00:25]

2010-03-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1499513834-3245736753-3590406765-1003Core.job
- c:\users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-01 07:57]

2010-03-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1499513834-3245736753-3590406765-1003UA.job
- c:\users\LeeAd\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-01 07:57]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-03 23:54
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTxfiHlp = CTXFIHLP.EXE?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD DX\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Maxtor\Sync\SyncServices.exe
c:\progra~1\TRENDM~1\INTERN~1\PcCtlCom.exe
c:\program files\Sunbelt Software\CounterSpy\SBCSSvc.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2010-03-03 23:57:54 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-04 04:57
ComboFix2.txt 2010-03-04 03:19

Pre-Run: 528,952,668,160 bytes free
Post-Run: 529,155,534,848 bytes free

- - End Of File - - 19CA728299875CD3F5B5A7E483AD36D1
CatByte -

I ran the Windows Cleanup Utility as you suggested; I'm not quite sure what it did. After that, I tried opening Adobe and having it check for updates from within the program; it found the updates, downloaded and installed them - the software now reports that it's version 9.3.1

I'll have to look for the printer disks (I know I still have them) - maybe I'll try that tomorrow. For now, I'm still a bit more concerned with understanding why GMER failed to complete its scan when I tried to run it before - is there a chance that I may have a rootkit infection?

Also, should I restart my antimalware programs now?

Thanks so much for all your help.
Will do; thanks! And, don't let me forget - I seem to recall that we trashed one of my backup files at some point (so I'll also want to figure out what to do about that, as well as the GMER thing). Do you have any suggestion as to when I should check back tomorrow? My schedule is all too flexible at the moment - when's good for you? :D

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI