This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow Internet Explorer after loss of click sound

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, New to the forum here and looks to be a great place. The issue I'm having is about 4 days ago I lost the click sound while browsing with I.E. I was able to turn the sound back on, but I was left with a slow browser and now when i click on any item , there is a delay in the click sound and I.E has slowed down while browsing and while loading. I logged off and switched users and found that my wifes side of the computer and I.E are working fine. The second issue is loading pictures or videos as I receive a message "Windows Host Process wants to open" and asking allow or not. I have run Malwarebytes, but had no change. I'm having trouble downloading Hijackthis as I can't run as adminstrator. Here is the 2 copys of the DDS files. Thank you in advance


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 11:54:59.96 on Fri 08/20/2010
Internet Explorer: 8.0.6001.18943
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1002 [GMT -4:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\dldtcoms.exe
C:\Program Files\iolo\common\lib\ioloServiceManager.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\lxdqcoms.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files\Dell V305\dldtmon.exe
C:\Program Files\Dell V305\dldtMsdMon.exe
C:\Program Files\MSN Toolbar\Platform\4.0.0334.0\mswinext.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\PictureMover\Bin\PictureMover.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10i_ActiveX.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Eddie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZIISGOGC\downloads[2].scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.xfinity.com/?cid=xfactiv_tech_main
uSearch Bar = Preserve
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=93&bd=Presario&pf=cndt
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=93&bd=Presario&pf=cndt
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\16.8.0.41\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\16.8.0.41\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0334.0\npwinext.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\16.8.0.41\coIEPlg.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0334.0\npwinext.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [hpsysdrv] c:\program files\hewlett-packard\hp odometer\hpsysdrv.exe
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [dldtmon.exe] "c:\program files\dell v305\dldtmon.exe"
mRun: [dldtamon] "c:\program files\dell v305\dldtamon.exe"
mRun: [Dell PC TuneUp Startup] "c:\program files\iolo\common\lib\ioloLManager.exe"
mRun: [MSN Toolbar] "c:\program files\msn toolbar\platform\4.0.0334.0\mswinext.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe"
mRun: []
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [DVDAgent] "c:\program files\hewlett-packard\media\dvd\DVDAgent.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\pictur~1.lnk - c:\program files\picturemover\bin\PictureMover.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton internet security\engine\16.8.0.41\CoIEPlg.dll

============= SERVICES / DRIVERS ===============

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1008000.029\SymEFA.sys [2010-1-27 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nis\1008000.029\BHDrvx86.sys [2010-1-27 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nis\1008000.029\cchpx86.sys [2010-1-27 482432]
R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\elrawdsk.sys [2009-9-5 20392]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100818.002\IDSvix86.sys [2010-8-20 344112]
R2 dldt_device;dldt_device;c:\windows\system32\dldtcoms.exe -service –> c:\windows\system32\dldtcoms.exe -service [?]
R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2009-9-5 600944]
R2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2009-9-5 600944]
R2 lxdq_device;lxdq_device;c:\windows\system32\lxdqcoms.exe -service –> c:\windows\system32\lxdqcoms.exe -service [?]
R2 Norton Internet Security;Norton Internet Security;c:\program files\norton internet security\engine\16.8.0.41\ccSvcHst.exe [2010-1-27 117640]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2010-5-14 249136]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2010-6-24 92008]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-8-17 102448]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\nis\1008000.029\symndisv.sys [2010-1-27 48688]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 dldtCATSCustConnectService;dldtCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\dldtserv.exe [2009-7-9 98984]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 PCDSRVC{4F253FFC-7957E8FC-06000000}_0;PCDSRVC{4F253FFC-7957E8FC-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor for windows\pcdsrvc.pkms [2009-2-2 20848]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2008-1-20 16896]
S4 nvrd32;NVIDIA nForce RAID Driver;c:\windows\system32\drivers\nvrd32.sys [2009-4-28 133152]

============== File Associations ===============

VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1

=============== Created Last 30 ================

2010-08-19 18:21 –d—– c:\program files\Trend Micro
2010-08-19 06:24 52 a——- c:\windows\system32\ashttpstats.csv
2010-08-19 00:54 385 a——- c:\windows\system32\user_gensett.xml
2010-08-19 00:54 –d—– c:\programdata\BitDefender
2010-08-19 00:54 –d—– c:\progra~2\BitDefender
2010-08-19 00:35 –d—– c:\users\eddie\appdata\roaming\Auslogics
2010-08-19 00:35 –d—– c:\programdata\Auslogics
2010-08-19 00:35 –d—– c:\program files\common files\Auslogics
2010-08-19 00:35 –d—– c:\program files\Auslogics
2010-08-19 00:35 –d—– c:\progra~2\Auslogics
2010-08-19 00:33 –d—– c:\program files\common files\BitDefender
2010-08-18 23:53 –d—– c:\users\eddie\appdata\roaming\Malwarebytes
2010-08-18 23:53 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-18 23:53 20,952 a——- c:\windows\system32\drivers\mbam.sys
2010-08-18 23:53 –d—– c:\programdata\Malwarebytes
2010-08-18 23:53 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-08-18 23:53 –d—– c:\progra~2\Malwarebytes
2010-08-18 21:34 221,568 ——– c:\windows\system32\MpSigStub.exe
2010-08-18 18:54 –d—– c:\users\eddie\appdata\roaming\System Tweaker
2010-08-18 18:40 –d—– c:\program files\Uniblue
2010-08-18 18:08 –d—– c:\program files\MSXML 4.0
2010-08-18 02:00 –d—– c:\programdata\SUPERAntiSpyware.com
2010-08-18 02:00 –d—– c:\progra~2\SUPERAntiSpyware.com
2010-08-18 01:37 420,352 a——- c:\windows\system32\vbscript.dll
2010-08-18 01:23 385,024 a——- c:\windows\system32\html.iec
2010-08-18 01:23 169,472 a——- c:\windows\system32\iexpress.exe
2010-08-18 01:23 45,568 a——- c:\windows\system32\mshta.exe
2010-08-18 01:23 107,520 a——- c:\windows\system32\RegisterIEPKEYs.exe
2010-08-18 01:23 103,936 a——- c:\windows\system32\SetDepNx.exe
2010-08-18 01:23 109,568 a——- c:\windows\system32\PDMSetup.exe
2010-08-18 01:23 107,008 a——- c:\windows\system32\SetIEInstalledDate.exe
2010-08-17 23:09 9,592 a——- c:\windows\system32\drivers\kgpcpy.cfg
2010-08-17 22:15 –d—– c:\programdata\STOPzilla!
2010-08-17 22:15 –d—– c:\progra~2\STOPzilla!
2010-08-17 21:55 –d—– c:\program files\Microsoft ATS
2010-08-16 19:14 –d—– c:\programdata\Uniblue
2010-08-16 19:14 –d—– c:\progra~2\Uniblue
2010-08-16 19:14 –d—– c:\users\eddie\appdata\roaming\Uniblue
2010-08-11 17:13 81,920 a——- c:\windows\system32\iccvid.dll
2010-08-11 17:13 274,944 a——- c:\windows\system32\schannel.dll
2010-08-11 17:13 1,248,768 a——- c:\windows\system32\msxml3.dll
2010-08-11 17:13 2,037,760 a——- c:\windows\system32\win32k.sys
2010-08-11 17:13 36,864 a——- c:\windows\system32\rtutils.dll
2010-08-11 17:13 3,600,768 a——- c:\windows\system32\ntkrnlpa.exe
2010-08-11 17:13 3,548,040 a——- c:\windows\system32\ntoskrnl.exe
2010-08-11 17:13 302,080 a——- c:\windows\system32\drivers\srv.sys
2010-08-11 17:13 144,896 a——- c:\windows\system32\drivers\srv2.sys
2010-08-11 17:12 905,088 a——- c:\windows\system32\drivers\tcpip.sys
2010-07-26 18:44 –d—– c:\program files\iPod
2010-07-26 18:44 –d—– c:\program files\iTunes

==================== Find3M ====================

2010-08-18 15:26 143,360 a——- c:\windows\inf\infstrng.dat
2010-08-18 15:26 143,360 a——- c:\windows\inf\infstor.dat
2010-08-18 15:26 86,016 a——- c:\windows\inf\infpub.dat
2010-08-18 13:15 665,600 a——- c:\windows\inf\drvindex.dat
2010-08-16 22:02 3,684 a——- c:\users\eddie\appdata\roaming\wklnhst.dat
2010-07-17 05:00 423,656 a——- c:\windows\system32\deployJava1.dll
2010-06-30 00:12 13,312 a——- c:\windows\LPRES.DLL
2010-06-26 02:05 916,480 a——- c:\windows\system32\wininet.dll
2010-06-26 02:02 109,056 a——- c:\windows\system32\iesysprep.dll
2010-06-26 02:02 71,680 a——- c:\windows\system32\iesetup.dll
2010-06-26 00:25 133,632 a——- c:\windows\system32\ieUnatt.exe
2010-06-05 13:14 3 a——- c:\program files\option.txt
2010-05-26 13:06 34,304 a——- c:\windows\system32\atmlib.dll
2010-05-26 10:47 289,792 a——- c:\windows\system32\atmfd.dll
2008-01-20 22:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2010-04-27 11:51 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat
2010-04-27 11:51 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat
2010-04-27 11:51 32,768 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat
2009-04-28 21:11 8,192 a–sh— c:\windows\users\default\NTUSER.DAT

============= FINISH: 11:55:27.28 ===============

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 5/21/2009 1:38:02 PM
System Uptime: 8/20/2010 2:05:11 AM (9 hours ago)

Motherboard: PEGATRON CORPORATION | | NARRA5
Processor: AMD Athlon™ 7550 Dual-Core Processor | Socket AM2 | 2500/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 287 GiB total, 196.607 GiB free.
D: is FIXED (NTFS) - 11 GiB total, 1.554 GiB free.
E: is CDROM ()
F: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP373: 8/10/2010 7:16:10 PM - Device Driver Package Install: Research In Motion Universal Serial Bus controllers
RP374: 8/11/2010 3:00:14 PM - Scheduled Checkpoint
RP375: 8/11/2010 5:41:43 PM - Windows Update
RP376: 8/12/2010 12:11:12 PM - Scheduled Checkpoint
RP377: 8/14/2010 4:41:08 AM - Scheduled Checkpoint
RP378: 8/15/2010 12:00:04 AM - Scheduled Checkpoint
RP379: 8/16/2010 12:46:40 PM - Scheduled Checkpoint
RP380: 8/17/2010 1:09:55 AM - Scheduled Checkpoint
RP381: 8/17/2010 5:29:22 PM - Restore Operation
RP382: 8/17/2010 9:11:13 PM - Restore Operation
RP383: 8/17/2010 10:15:26 PM - Installed STOPzilla. Available with Windows Installer version 1.2 and later.
RP385: 8/17/2010 10:27:53 PM - StopZILLA! Restore Point.
RP386: 8/18/2010 12:55:23 AM - Removed STOPzilla. Available with Windows Installer version 1.2 and later.
RP387: 8/18/2010 1:04:43 AM - Windows Modules Installer
RP388: 8/18/2010 1:22:50 AM - Windows Update
RP389: 8/18/2010 1:38:04 AM - Windows Update
RP391: 8/18/2010 12:58:53 PM - Installed MediaSmart DVD
RP392: 8/18/2010 1:02:12 PM - Windows Update
RP393: 8/18/2010 3:26:01 PM - Device Driver Package Install: Microsoft Network Protocol
RP394: 8/18/2010 6:08:30 PM - Windows Update
RP395: 8/18/2010 7:56:07 PM - Removed Safari
RP396: 8/18/2010 9:34:14 PM - Windows Update
RP397: 8/19/2010 12:34:49 AM - Installed Auslogics Antivirus
RP398: 8/19/2010 8:43:15 AM - Removed Auslogics Antivirus
RP399: 8/19/2010 8:44:29 AM - Removed Auslogics Antivirus
RP400: 8/19/2010 1:07:44 PM - Windows Update
RP401: 8/19/2010 7:24:25 PM - Installed HiJackThis
RP402: 8/19/2010 7:39:49 PM - Removed HiJackThis
RP403: 8/19/2010 11:40:10 PM - Installed HiJackThis
RP404: 8/19/2010 11:45:10 PM - Removed HiJackThis
RP405: 8/19/2010 11:46:10 PM - Installed HiJackThis
RP406: 8/19/2010 11:59:03 PM - Removed HiJackThis
RP407: 8/20/2010 12:03:07 AM - Installed HiJackThis

==== Installed Programs ======================

ABBYY FineReader 6.0 Sprint
Acrobat.com
Activation Assistant for the 2007 Microsoft Office suites
ActiveCheck component for HP Active Support Library
Adobe Flash Player 10 ActiveX
Adobe Reader 9.3.3
Apple Application Support
Apple Mobile Device Support
Apple Software Update
BlackBerry Desktop Software 6.0
BlackBerry Device Software Updater
Bonjour
Canon DIGITAL CAMERA Solution Disk Software Guide
CANON iMAGE GATEWAY Task for ZoomBrowser EX
Canon Internet Library for ZoomBrowser EX
Canon MOV Decoder
Canon MOV Encoder
Canon MovieEdit Task for ZoomBrowser EX
Canon Personal Printing Guide
Canon PowerShot SD980 IS_IXUS 200 IS Camera User Guide
Canon Utilities CameraWindow
Canon Utilities CameraWindow DC
Canon Utilities CameraWindow DC 8
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
Canon Utilities MyCamera
Canon Utilities MyCamera DC
Canon Utilities PhotoStitch
Canon Utilities RemoteCapture Task for ZoomBrowser EX
Canon Utilities ZoomBrowser EX
Canon ZoomBrowser EX Memory Card Utility
Comcast Desktop Software (v1.2.0.9)
Compatibility Pack for the 2007 Office system
CyberLink DVD Suite Deluxe
Dell Driver Download Manager
Dell PC TuneUp
Dell V305
Desktop Doctor
DHTML Editing Component
DirectX for Managed Code Update (Summer 2004)
Hardware Diagnostic Tools
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Advisor
HP Customer Experience Enhancements
HP Games
HP MediaSmart DVD
HP Odometer
HP Recovery Manager RSS
HP Support Information
HP Total Care Setup
HP Update
HPAsset component for HP Active Support Library
Internet Explorer (Enable DEP)
iTunes
Japanese Fonts Support For Adobe Reader 9
Java Auto Updater
Java™ 6 Update 21
Java™ 6 Update 3
Junk Mail filter update
LabelPrint
LG USB Modem driver
LightScribe System Software
Linksys EasyLink Advisor
Malwarebytes' Anti-Malware
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office Excel MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
MSN Toolbar
MSN Toolbar Platform
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Norton Internet Security
NVIDIA Drivers
OGA Notifier 2.0.0048.0
PictureMover
Power2Go
PowerDirector
Pure Networks Platform
Python 2.6 pywin32-212
Python 2.6.1
QuickTime
Realtek High Definition Audio Driver
Shipping Assistant 3.6
TomTom HOME 2.7.5.2014
TomTom HOME Visual Studio Merge Modules
Turbo Lister 2
Uniblue RegistryBooster
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
WebEx Support Manager for Internet Explorer
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live OneCare safety scanner
Windows Live Photo Gallery

==== Event Viewer Messages From Past Week ========

8/19/2010 8:16:49 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Media Player Network Sharing Service service to connect.
8/19/2010 8:16:49 AM, Error: Service Control Manager [7000] - The Windows Media Player Network Sharing Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/19/2010 6:21:23 AM, Error: Service Control Manager [7034] - The dldt_device service terminated unexpectedly. It has done this 1 time(s).
8/19/2010 12:57:00 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the HP Health Check Service service to connect.
8/19/2010 12:57:00 AM, Error: Service Control Manager [7000] - The HP Health Check Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/19/2010 12:39:30 AM, Error: Service Control Manager [7031] - The Windows Defender service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/19/2010 12:21:29 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
8/19/2010 12:21:29 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: i8042prt
8/19/2010 12:21:29 PM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error 2147749155 (0x80040D23).
8/19/2010 12:21:29 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the dldtCATSCustConnectService service to connect.
8/19/2010 12:21:29 PM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
8/19/2010 12:21:29 PM, Error: Service Control Manager [7000] - The dldtCATSCustConnectService service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/18/2010 9:24:49 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user eddie-maria\Eddie SID (S-1-5-21-1119333972-2933176690-2880281189-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
8/18/2010 12:56:20 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the szserver service.
8/18/2010 1:44:56 AM, Error: Service Control Manager [7001] - The Windows Image Acquisition (WIA) service depends on the Shell Hardware Detection service which failed to start because of the following error: The operation completed successfully.
8/17/2010 9:24:51 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
8/17/2010 6:35:23 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.0.2 for the Network Card with network address 00248CF8EFF0 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
8/17/2010 10:26:51 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
8/17/2010 10:26:51 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/17/2010 10:26:51 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
8/17/2010 10:26:27 PM, Error: Service Control Manager [7022] - The KtmRm for Distributed Transaction Coordinator service hung on starting.
8/17/2010 10:22:14 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: i8042prt is3srv
8/16/2010 7:41:49 PM, Error: Service Control Manager [7030] - The dldt_device service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
8/16/2010 3:34:50 PM, Error: Microsoft-Windows-PrintSpooler [6161] - The document https://ibdswebp25-ext.pb.com/images/USPS/H…lders/HTML15/f3, owned by Eddie, failed to print on printer Dell V305. Try to print the document again, or restart the print spooler. Data type: LEMF. Size of the spool file in bytes: 185102. Number of bytes printed: 185102. Total number of pages in the document: 1. Number of pages printed: 0. Client computer: \\EDDIE-MARIA. Win32 error code returned by the print processor: 0. The operation completed successfully.
8/15/2010 9:48:27 PM, Error: Microsoft-Windows-PrintSpooler [6161] - The document http://mail.aol.com/32447-111/aol-1/en-us/…rintMessage.asp, owned by Eddie, failed to print on printer Dell V305. Try to print the document again, or restart the print spooler. Data type: LEMF. Size of the spool file in bytes: 77560. Number of bytes printed: 77560. Total number of pages in the document: 1. Number of pages printed: 0. Client computer: \\EDDIE-MARIA. Win32 error code returned by the print processor: 0. The operation completed successfully.

==== End Of File ===========================
Hi

Please do the following:



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.


NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hello Catbyte, Many thanks for reply. Here are the copies of the 2 files requested.

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: PEGATRON CORPORATION
BIOS Manufacturer: Phoenix Technologies, LTD
System Manufacturer: Compaq-Presario
System Product Name: NP185AA-ABA CQ5110F
Logical Drives Mask: 0x0000003c

Kernel Drivers (total 154):
0x81E1F000 \SystemRoot\system32\ntkrnlpa.exe
0x821D8000 \SystemRoot\system32\hal.dll
0x8040C000 \SystemRoot\system32\kdcom.dll
0x80413000 \SystemRoot\system32\PSHED.dll
0x80424000 \SystemRoot\system32\BOOTVID.dll
0x8042C000 \SystemRoot\system32\CLFS.SYS
0x8046D000 \SystemRoot\system32\CI.dll
0x8054D000 \SystemRoot\system32\drivers\Wdf01000.sys
0x805C9000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x80601000 \SystemRoot\system32\drivers\acpi.sys
0x80647000 \SystemRoot\system32\drivers\WMILIB.SYS
0x80650000 \SystemRoot\system32\drivers\msisadrv.sys
0x80658000 \SystemRoot\system32\drivers\pci.sys
0x8067F000 \SystemRoot\System32\drivers\partmgr.sys
0x8068E000 \SystemRoot\system32\drivers\volmgr.sys
0x8069D000 \SystemRoot\System32\drivers\volmgrx.sys
0x806E7000 \SystemRoot\System32\drivers\mountmgr.sys
0x806F7000 \SystemRoot\system32\drivers\nvraid.sys
0x80712000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x80733000 \SystemRoot\system32\drivers\nvstor32.sys
0x80759000 \SystemRoot\system32\drivers\storport.sys
0x8079A000 \SystemRoot\system32\drivers\fltmgr.sys
0x807CC000 \SystemRoot\system32\drivers\fileinfo.sys
0x89802000 \SystemRoot\system32\drivers\NIS\1008000.029\SYMEFA.SYS
0x89851000 \SystemRoot\System32\Drivers\ksecdd.sys
0x898C2000 \SystemRoot\system32\drivers\ndis.sys
0x899CD000 \SystemRoot\system32\drivers\msrpc.sys
0x89A06000 \SystemRoot\system32\drivers\NETIO.SYS
0x89A41000 \SystemRoot\System32\drivers\tcpip.sys
0x89B2B000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x89C03000 \SystemRoot\System32\Drivers\Ntfs.sys
0x89D13000 \SystemRoot\system32\drivers\volsnap.sys
0x89D4C000 \SystemRoot\System32\Drivers\spldr.sys
0x89D54000 \SystemRoot\System32\Drivers\mup.sys
0x89D63000 \SystemRoot\System32\drivers\ecache.sys
0x89D8A000 \SystemRoot\system32\drivers\disk.sys
0x89D9B000 \SystemRoot\system32\drivers\crcdisk.sys
0x89DE1000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x89DEC000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x89B46000 \SystemRoot\system32\DRIVERS\processr.sys
0x89DF5000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x89B55000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x89B93000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8DC00000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8DC8D000 \SystemRoot\system32\DRIVERS\nvmfdx32.sys
0x8DD8D000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8DDA5000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x8DE06000 \SystemRoot\system32\DRIVERS\AGRSM.sys
0x8DF23000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8DF25000 \SystemRoot\system32\drivers\modem.sys
0x8E00A000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x8E772000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
0x8DF32000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8E774000 \SystemRoot\System32\drivers\watchdog.sys
0x8E780000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8E7AF000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8E7BA000 \SystemRoot\System32\Drivers\RootMdm.sys
0x8E7C2000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8E7D9000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8DFD3000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8E7E4000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8DDAB000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8DDBF000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8E7F3000 \SystemRoot\system32\DRIVERS\RimSerial.sys
0x8DDD4000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8DDE4000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8DDEF000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8E7FA000 \SystemRoot\system32\DRIVERS\swenum.sys
0x89BA2000 \SystemRoot\system32\DRIVERS\ks.sys
0x8E000000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x89BCC000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8EC0F000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8EC44000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8EE05000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x8F03C000 \SystemRoot\system32\drivers\portcls.sys
0x8F069000 \SystemRoot\system32\drivers\drmk.sys
0x8F08E000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x8F097000 \SystemRoot\System32\Drivers\Null.SYS
0x8F09E000 \SystemRoot\System32\Drivers\Beep.SYS
0x8F0C1000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8F0C8000 \SystemRoot\System32\drivers\vga.sys
0x8F0D4000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8F0F5000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8F0FD000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8F105000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8F110000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8F11E000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8F127000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8F13D000 \SystemRoot\System32\Drivers\NIS\1008000.029\SYMTDI.SYS
0x8F171000 \??\C:\Windows\system32\Drivers\SYMEVENT.SYS
0x8F196000 \SystemRoot\System32\Drivers\NIS\1008000.029\SYMNDISV.SYS
0x8F1A4000 \SystemRoot\System32\Drivers\NIS\1008000.029\SYMFW.SYS
0x8F1B9000 \SystemRoot\system32\DRIVERS\smb.sys
0x8EC55000 \SystemRoot\system32\drivers\afd.sys
0x8F1CD000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8F0A5000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8EC9D000 \SystemRoot\system32\DRIVERS\SymIMv.sys
0x8ECA6000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x8ECBD000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8ECCB000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8ECDE000 \SystemRoot\system32\DRIVERS\usbscan.sys
0x8ECEB000 \SystemRoot\system32\drivers\NIS\1008000.029\SRTSPX.SYS
0x8ECF5000 \SystemRoot\system32\DRIVERS\usbprint.sys
0x8ECFF000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8ED3B000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x8ED50000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8EDB2000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x8EDBB000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8F0BB000 \??\C:\Windows\system32\drivers\elrawdsk.sys
0x8F806000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
0x8F864000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
0x8F881000 \SystemRoot\System32\Drivers\dfsc.sys
0x8F898000 \SystemRoot\System32\Drivers\NIS\1008000.029\ccHPx86.sys
0x8F913000 \SystemRoot\System32\Drivers\NIS\1008000.029\BHDrvx86.sys
0x8F955000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x8F95E000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x8F966000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8F973000 \SystemRoot\System32\Drivers\dump_diskdump.sys
0x8F97D000 \SystemRoot\System32\Drivers\dump_nvstor32.sys
0x98AC0000 \SystemRoot\System32\win32k.sys
0x8F9A3000 \SystemRoot\System32\drivers\Dxapi.sys
0x8F9AD000 \SystemRoot\system32\DRIVERS\monitor.sys
0x98CE0000 \SystemRoot\System32\TSDDD.dll
0x98D10000 \SystemRoot\System32\ATMFD.DLL
0x8F9BC000 \SystemRoot\system32\drivers\luafv.sys
0x9CC03000 \SystemRoot\system32\drivers\spsys.sys
0x9CCB3000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x9CCC3000 \SystemRoot\system32\DRIVERS\pnarp.sys
0x9CCCD000 \SystemRoot\system32\DRIVERS\purendis.sys
0x9CCD7000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9CCEA000 \SystemRoot\system32\drivers\HTTP.sys
0x9CD57000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x9CD74000 \SystemRoot\system32\DRIVERS\bowser.sys
0x9CD8D000 \SystemRoot\System32\drivers\mpsdrv.sys
0x9CDA2000 \SystemRoot\system32\drivers\mrxdav.sys
0x9CDC3000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x89DA4000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x9CDE2000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x8F9D7000 \SystemRoot\System32\DRIVERS\srv2.sys
0x9D807000 \SystemRoot\System32\DRIVERS\srv.sys
0x9D86D000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0x9D871000 \SystemRoot\system32\drivers\peauth.sys
0x9D94F000 \SystemRoot\System32\Drivers\secdrv.SYS
0x9D959000 \SystemRoot\System32\drivers\tcpipreg.sys
0x9D965000 \SystemRoot\system32\DRIVERS\xaudio.sys
0x9D96D000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0x9D982000 \SystemRoot\system32\DRIVERS\WUDFPf.sys
0x9D994000 \SystemRoot\System32\Drivers\NIS\1008000.029\SRTSP.SYS
0xA3365000 \SystemRoot\system32\DRIVERS\cdfs.sys
0xA337B000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100820.001\IDSvix86.sys
0x98A20000 \SystemRoot\System32\cdd.dll
0xA3200000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100822.007\NAVEX15.SYS
0xA334C000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100822.007\NAVENG.SYS
0x776C0000 \Windows\System32\ntdll.dll

Processes (total 77):
0 System Idle Process
4 System
452 C:\Windows\System32\smss.exe
520 csrss.exe
572 C:\Windows\System32\wininit.exe
580 csrss.exe
616 C:\Windows\System32\services.exe
628 C:\Windows\System32\lsass.exe
636 C:\Windows\System32\lsm.exe
716 C:\Windows\System32\winlogon.exe
820 C:\Windows\System32\svchost.exe
864 C:\Windows\System32\nvvsvc.exe
892 C:\Windows\System32\svchost.exe
932 C:\Windows\System32\svchost.exe
996 C:\Windows\System32\svchost.exe
1104 C:\Windows\System32\svchost.exe
1124 C:\Windows\System32\svchost.exe
1200 C:\Windows\System32\audiodg.exe
1224 C:\Windows\System32\svchost.exe
1240 C:\Windows\System32\SLsvc.exe
1280 C:\Windows\System32\svchost.exe
1456 C:\Windows\System32\rundll32.exe
1468 C:\Windows\System32\svchost.exe
1660 C:\Windows\System32\spoolsv.exe
1684 C:\Windows\System32\svchost.exe
1952 C:\Program Files\LSI SoftModem\agrsmsvc.exe
1984 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1996 C:\Program Files\Bonjour\mDNSResponder.exe
2028 C:\Windows\System32\dldtcoms.exe
288 C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
632 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
940 C:\Windows\System32\lxdqcoms.exe
1268 C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
1184 C:\Windows\System32\svchost.exe
2068 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
2108 C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
2140 C:\Windows\System32\svchost.exe
2168 C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
2216 C:\Windows\System32\svchost.exe
2344 C:\Windows\System32\drivers\XAudio.exe
2396 C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
2480 C:\Windows\System32\taskeng.exe
2496 WUDFHost.exe
3392 C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
3432 C:\Windows\System32\taskeng.exe
3504 C:\Windows\System32\taskeng.exe
3524 C:\Windows\System32\dwm.exe
3628 C:\Windows\explorer.exe
3984 C:\Program Files\Hewlett-Packard\HP Odometer\hpsysdrv.exe
4004 C:\Program Files\Dell V305\dldtmon.exe
4076 C:\Program Files\Dell V305\dldtmsdmon.exe
4092 C:\Program Files\MSN Toolbar\Platform\4.0.0334.0\mswinext.exe
2204 C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
2316 C:\Program Files\iTunes\iTunesHelper.exe
1892 C:\Program Files\Common Files\Java\Java Update\jusched.exe
2672 C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
2792 C:\Program Files\Windows Sidebar\sidebar.exe
2756 C:\Program Files\Windows Media Player\wmpnscfg.exe
2748 C:\Program Files\PictureMover\Bin\PictureMover.exe
3216 C:\Program Files\Windows Sidebar\sidebar.exe
3852 C:\Program Files\Windows Media Player\wmpnetwk.exe
4064 dllhost.exe
988 C:\Windows\System32\SearchIndexer.exe
4964 C:\Program Files\iPod\bin\iPodService.exe
5304 C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
7084 C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
7584 C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
6540 C:\Program Files\Internet Explorer\iexplore.exe
7252 C:\Program Files\Internet Explorer\iexplore.exe
5696 C:\Windows\System32\Macromed\Flash\FlashUtil10i_ActiveX.exe
4376 C:\Program Files\Windows Defender\MSASCui.exe
4292 C:\Program Files\Internet Explorer\iexplore.exe
5532 C:\Windows\System32\SearchProtocolHost.exe
3712 C:\Windows\System32\SearchFilterHost.exe
7060 dllhost.exe
4288 dllhost.exe
6756 C:\Users\Eddie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\20DMHW9A\MBRCheck[1].exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: –> \\.\PhysicalDrive0 at offset 0x00000047`b4020200 (NTFS)

PhysicalDrive0 Model Number: ST3320813AS, Rev: HP22

Size Device Name MBR Status
——————————————–
298 GB \\.\PhysicalDrive0 Hewlett-Packard MBR code detected
SHA1: F362CE084BC77B454330005C1657154A64FB9456


Done!




AND THE OTHER:


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-22 18:31:04
Windows 6.0.6002 Service Pack 2
Running: download[1].exe; Driver: C:\Users\Eddie\AppData\Local\Temp\kwtdrpod.sys


—- System - GMER 1.0.15 —-

SSDT 8807FC70 ZwAlertResumeThread
SSDT 8807FD30 ZwAlertThread
SSDT 8796AB40 ZwAllocateVirtualMemory
SSDT 8775E768 ZwAlpcConnectPort
SSDT 880E1FD0 ZwAssignProcessToJobObject
SSDT 879C58B0 ZwCreateMutant
SSDT 8791EFC0 ZwCreateSymbolicLinkObject
SSDT 87966C80 ZwCreateThread
SSDT 87A2CFD0 ZwDebugActiveProcess
SSDT 8796BD58 ZwDuplicateObject
SSDT 880B0F80 ZwFreeVirtualMemory
SSDT 8807F7F0 ZwImpersonateAnonymousToken
SSDT 8807FBB0 ZwImpersonateThread
SSDT 8775E6F0 ZwLoadDriver
SSDT 880B0EA0 ZwMapViewOfSection
SSDT 879CD150 ZwOpenEvent
SSDT 8796A620 ZwOpenProcess
SSDT 879E4558 ZwOpenProcessToken
SSDT 87C16C48 ZwOpenSection
SSDT 8796BE28 ZwOpenThread
SSDT 880E1F48 ZwProtectVirtualMemory
SSDT 87920110 ZwResumeThread
SSDT 87940AE0 ZwSetContextThread
SSDT 8807FFC0 ZwSetInformationProcess
SSDT 8801FF00 ZwSetSystemInformation
SSDT 87943A98 ZwSuspendProcess
SSDT 8807FDF0 ZwSuspendThread
SSDT 87941808 ZwTerminateProcess
SSDT 879456D8 ZwTerminateThread
SSDT 87AE34A8 ZwUnmapViewOfSection
SSDT 8796AA70 ZwWriteVirtualMemory
SSDT 880E1E48 ZwCreateThreadEx

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!KeSetEvent + 11D 81ECB880 8 Bytes [70, FC, 07, 88, 30, FD, 07, …]
.text ntkrnlpa.exe!KeSetEvent + 131 81ECB894 4 Bytes [40, AB, 96, 87]
.text ntkrnlpa.exe!KeSetEvent + 13D 81ECB8A0 4 Bytes [68, E7, 75, 87]
.text ntkrnlpa.exe!KeSetEvent + 191 81ECB8F4 4 Bytes [D0, 1F, 0E, 88]
.text ntkrnlpa.exe!KeSetEvent + 1F5 81ECB958 4 Bytes [B0, 58, 9C, 87]
.text …
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8E00A340, 0x4128C7, 0xE8000020]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\iexplore.exe[6540] USER32.dll!CreateWindowExW 76E01305 5 Bytes JMP 6D3FDB24 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6540] USER32.dll!DialogBoxParamW 76E210B0 5 Bytes JMP 6D325501 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6540] USER32.dll!DialogBoxIndirectParamW 76E22EF5 5 Bytes JMP 6D4F4B4F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6540] USER32.dll!DialogBoxParamA 76E38152 5 Bytes JMP 6D4F4AEC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6540] USER32.dll!DialogBoxIndirectParamA 76E3847D 5 Bytes JMP 6D4F4BB2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6540] USER32.dll!MessageBoxIndirectA 76E4D4D9 5 Bytes JMP 6D4F4A81 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6540] USER32.dll!MessageBoxIndirectW 76E4D5D3 5 Bytes JMP 6D4F4A16 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6540] USER32.dll!MessageBoxExA 76E4D639 5 Bytes JMP 6D4F49B4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6540] USER32.dll!MessageBoxExW 76E4D65D 5 Bytes JMP 6D4F4952 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] ntdll.dll!RtlEncodeSystemPointer + 873 776E938B 10 Bytes JMP 052F003A
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!CreateDialogParamW 76DF72A2 5 Bytes JMP 6D3FDEB0 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!GetAsyncKeyState 76DF863C 5 Bytes JMP 6D318F37 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!SetWindowsHookExW 76DF87AD 5 Bytes JMP 6D3F9AD5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!CallNextHookEx 76DF8E3B 5 Bytes JMP 6D3ED135 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!UnhookWindowsHookEx 76DF98DB 5 Bytes JMP 6D364666 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!EnableWindow 76DFCD8B 5 Bytes JMP 6D3FDD3D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!CreateWindowExW 76E01305 5 Bytes JMP 6D3FDB24 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!GetKeyState 76E08CB1 5 Bytes JMP 6D3FD2EB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!IsDialogMessageW 76E10745 5 Bytes JMP 6D325A13 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!CreateDialogParamA 76E117AA 5 Bytes JMP 6D4F57D6 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!IsDialogMessage 76E11847 5 Bytes JMP 6D4F5072 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!CreateDialogIndirectParamA 76E126F1 5 Bytes JMP 6D4F580D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!CreateDialogIndirectParamW 76E19A62 5 Bytes JMP 6D4F5844 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!SetKeyboardState 76E20987 5 Bytes JMP 6D4F53E1 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!DialogBoxParamW 76E210B0 5 Bytes JMP 6D325501 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!DialogBoxIndirectParamW 76E22EF5 5 Bytes JMP 6D4F4B4F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!SendInput 76E22F75 5 Bytes JMP 6D4F5F9F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!EndDialog 76E2326E 5 Bytes JMP 6D327EBA C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!SetCursorPos 76E36FB2 5 Bytes JMP 6D4F5FF3 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!DialogBoxParamA 76E38152 5 Bytes JMP 6D4F4AEC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!DialogBoxIndirectParamA 76E3847D 5 Bytes JMP 6D4F4BB2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!MessageBoxIndirectA 76E4D4D9 5 Bytes JMP 6D4F4A81 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!MessageBoxIndirectW 76E4D5D3 5 Bytes JMP 6D4F4A16 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!MessageBoxExA 76E4D639 5 Bytes JMP 6D4F49B4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!MessageBoxExW 76E4D65D 5 Bytes JMP 6D4F4952 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] USER32.dll!keybd_event 76E4D972 5 Bytes JMP 6D4F6323 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] SHELL32.dll!SHRestricted + D95 75E689A8 4 Bytes [4D, 30, DD, 73]
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] SHELL32.dll!SHRestricted + D9D 75E689B0 8 Bytes [57, 2F, DD, 73, 9C, 5B, DC, …]
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] ole32.dll!OleLoadFromStream 771A1E12 5 Bytes JMP 6D4F4ED0 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] ole32.dll!CoGetTreatAsClass + D2F 771BFAB7 7 Bytes JMP 052F01A9
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] ole32.dll!CoCreateInstance 771D9EA6 5 Bytes JMP 6D3FDB80 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7252] ole32.dll!CoCreateInstance + 3E 771D9EE4 7 Bytes JMP 052F00F3

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74547817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [7459A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7454BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7453F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [745475E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [7453E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74578395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7454DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [7453FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [7453FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [745371CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [745CCAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [7456C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [7453D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74536853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [7453687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3628] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74542AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [73DB82F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [73DB82F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SearchPathW] [73DC1AEC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [73DC007C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CopyFileW] [73DBE1E9] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!MoveFileW] [73DC0994] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!DeleteFileW] [73DBEE46] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [73DBA3FB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetCurrentDirectoryW] [73DC1D56] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindClose] [73DC3ADC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindNextFileW] [73DC2999] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindFirstFileW] [73DC3035] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [73DBFBE1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateFileW] [73DBE860] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!WritePrivateProfileStringW] [73DBDC5C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [73DBFD66] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [73DB82F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetPrivateProfileStringW] [73DBD4B8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [73DCFBB3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegEnumValueW] [73DD051D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegOpenKeyExW] [73DCEB3D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryValueExW] [73DCF817] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegDeleteKeyW] [73DCEF31] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCreateKeyExW] [73DCE5C5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCloseKey] [73DCED95] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [73DC007C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [73DBFBE1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CopyFileW] [73DBE1E9] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [73DB82F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [73DBFD66] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW] [73DBE860] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SearchPathW] [73DC1AEC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] [73DBEE46] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindClose] [73DC3ADC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileA] [73DC2CD2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileA] [73DC2926] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileW] [73DC3035] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileW] [73DC2999] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA] [73DBBD77] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryA] [73DC173F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesA] [73DBBFCD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryA] [73DC0F0F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryA] [73DC14E9] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA] [73DBED1B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW] [73DBBEA2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryW] [73DC1D56] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesW] [73DBC0FB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryW] [73DC103D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW] [73DBEE46] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileW] [73DC0994] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryW] [73DC1614] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileA] [73DC0921] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [73DB82F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [73DBFBE1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [73DBA073] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [73DBA3FB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileA] [73DBE717] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileW] [73DBE860] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW] [73DBFD66] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [73DBFD66] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!ReplaceFileW] [73DC0C95] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!WritePrivateProfileStringW] [73DBDC5C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringW] [73DBD4B8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringA] [73DBD361] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] [73DBEE46] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [73DC007C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesW] [73DBC0FB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW] [73DBE860] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileW] [73DC3035] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileW] [73DC2999] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathW] [73DC1AEC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW] [73DBBEA2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesA] [73DBBFCD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA] [73DBE717] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileA] [73DC2CD2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileA] [73DC2926] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindClose] [73DC3ADC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathA] [73DC23A5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA] [73DBBD77] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [73DBFBE1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [73DB82F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpW] [73DBFAAA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpA] [73DBF973] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey] [73DCED95] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA] [73DCE43D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyA] [73DCEDE8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyA] [73DCF9B7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA] [73DCE9C5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW] [73DCE5C5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW] [73DCEB3D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExW] [73DD020D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueW] [73DCF4DB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyW] [73DCEF31] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyW] [73DCFBB3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExW] [73DCF817] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueW] [73DD051D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyW] [73DCFF19] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExA] [73DD0085] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueA] [73DD0395] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyA] [73DCFDAF] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExA] [73DCF677] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionW] [73DBCFA8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindNextFileW] [73DC2999] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!ReplaceFileW] [73DC0C95] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionNamesW] [73DBD22A] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileSectionW] [73DBD9DA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileStringW] [73DBDC5C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateHardLinkW] [73DBEB68] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetCurrentDirectoryW] [73DC1D56] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] [73DBE1E9] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetBinaryTypeW] [73DBCAA7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [73DC007C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [73DBA3FB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] [73DC0994] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindFirstFileW] [73DC3035] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindClose] [73DC3ADC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameA] [73DBC709] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA] [73DBBD77] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SearchPathW] [73DC1AEC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileIntW] [73DBCD20] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileStringW] [73DBD4B8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!RemoveDirectoryW] [73DC1614] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateDirectoryW] [73DC103D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] [73DBEE46] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetFileAttributesW] [73DBC0FB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW] [73DBBEA2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] [73DC09B9] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameW] [73DBC848] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [73DBFD66] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateFileW] [73DBE860] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW] [73DBC368] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [73DBFBE1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetLongPathNameW] [73DBC5D8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [USER32.dll!LoadImageW] [73DBF0D0] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [USER32.dll!WinHelpW] [73DBFAAA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [USER32.dll!PrivateExtractIconsW] [73DBF5C5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!AssocQueryStringByKeyW] [73DC620B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHCreateStreamOnFileW] [73DC7595] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!AssocQueryKeyW] [73DC60AE] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!AssocQueryStringW] [73DC615B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHDeleteKeyA] [73DC75E7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathCombineW] [73DC6533] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHOpenRegStream2W] [73DC799A] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsDirectoryW] [73DC684F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsURLW] [73DC6E45] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsRootA] [73DC6AFB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsRootW] [73DC6B47] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathStripToRootW] [73DC7281] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathFindOnPathW] [73DC6716] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathStripPathW] [73DC71ED] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathRemoveArgsW] [73DC7021] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetBoolUSValueW] [73DC7FBE] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathSkipRootW] [73DC7159] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsDirectoryEmptyW] [73DC68E7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsSystemFolderW] [73DC6BE2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsDirectoryA] [73DC6803] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathRelativePathToW] [73DC6F81] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathBuildRootA] [73DC63A5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetPathW] [73DC80BD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegSetPathW] [73DC8513] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetUSValueW] [73DC8176] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathCreateFromUrlW] [73DC65DA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHQueryValueExW] [73DC7BA4] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetValueW] [73DC8235] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsNetworkPathW] [73DC697F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsUNCServerShareW] [73DC6DAD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsUNCServerW] [73DC6D15] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathUnExpandEnvStringsW] [73DC731F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathMakeSystemFolderW] [73DC6EDD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsUNCW] [73DC6C7D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsRelativeW] [73DC6AAF] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHGetValueW] [73DC78EA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathBuildRootW] [73DC63F4] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHDeleteValueW] [73DC76D7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHSetValueW] [73DC8732] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHEnumKeyExW] [73DC777E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHEnumValueW] [73DC7831] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathFileExistsW] [73DC667B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHDeleteKeyW] [73DC7636] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] [73DBBB38] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindClose] [73DC3ADC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] [73DC3035] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [73DC007C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SearchPathW] [73DC1AEC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [73DBA3FB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DeleteFileW] [73DBEE46] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetShortPathNameW] [73DBC848] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] [73DBC368] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW] [73DBE860] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [73DBFD66] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] [73DBBEA2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [73DBFBE1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [73DB82F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [73DB82F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [73DB82F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetValueW] [73DC8235] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetValueA] [73DC81D7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!PathUnExpandEnvStringsA] [73DC72CD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHDeleteKeyA] [73DC75E7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHDeleteValueW] [73DC76D7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!PathCreateFromUrlW] [73DC65DA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHGetValueA] [73DC788F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHSetValueA] [73DC86D7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHGetValueW] [73DC78EA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHSetValueW] [73DC8732] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!PathCombineW] [73DC6533] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [73DB82F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\ws2_32.dll [KERNEL32.dll!GetProcAddress] [73DB82F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\SAMLIB.dll [KERNEL32.dll!GetProcAddress] [73DB82F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [73DB82F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[7252] @ C:\Windows\system32\IPHLPAPI.DLL [KERNEL32.dll!GetProcAddress] [73DB82F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

—- Files - GMER 1.0.15 —-

File C:\Users\Eddie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZIISGOGC\GetXML[2].aspx 6170 bytes

—- EOF - GMER 1.0.15 —-
Hi

please do the following:

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Here are the results of Combofix-

ComboFix 10-08-22.05 - Eddie 08/22/2010 21:23:49.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1187 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\COMBOFIX\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2010-07-23 to 2010-08-23 )))))))))))))))))))))))))))))))
.

2010-08-23 01:30 . 2010-08-23 01:30 ——– d—–w- c:\users\Maria\AppData\Local\temp
2010-08-23 01:30 . 2010-08-23 01:30 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-08-21 03:00 . 2010-08-23 01:19 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2010-08-21 03:00 . 2010-08-23 01:19 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-08-20 04:03 . 2010-08-20 04:03 388096 —-a-r- c:\users\Eddie\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-19 22:21 . 2010-08-19 22:21 ——– d—–w- c:\program files\Trend Micro
2010-08-19 04:54 . 2010-08-19 04:54 ——– d—–w- c:\programdata\BitDefender
2010-08-19 04:35 . 2010-08-19 04:37 ——– d—–w- c:\users\Eddie\AppData\Roaming\Auslogics
2010-08-19 04:35 . 2010-08-19 12:52 ——– d—–w- c:\programdata\Auslogics
2010-08-19 04:35 . 2010-08-19 04:36 ——– d—–w- c:\program files\Common Files\Auslogics
2010-08-19 04:35 . 2010-08-19 04:35 ——– d—–w- c:\program files\Auslogics
2010-08-19 04:33 . 2010-08-19 04:33 ——– d—–w- c:\program files\Common Files\BitDefender
2010-08-19 03:53 . 2010-08-19 03:53 ——– d—–w- c:\users\Eddie\AppData\Roaming\Malwarebytes
2010-08-19 03:53 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-19 03:53 . 2010-08-19 03:53 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-19 03:53 . 2010-08-19 03:53 ——– d—–w- c:\programdata\Malwarebytes
2010-08-19 03:53 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-08-19 01:34 . 2010-05-21 18:14 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-08-18 22:54 . 2010-08-18 22:54 ——– d—–w- c:\users\Eddie\AppData\Roaming\System Tweaker
2010-08-18 22:40 . 2010-08-19 04:07 ——– d—–w- c:\program files\Uniblue
2010-08-18 22:08 . 2010-08-18 22:08 ——– d—–w- c:\program files\MSXML 4.0
2010-08-18 16:59 . 2010-08-18 16:58 36864 —-a-w- c:\programdata\Temp\{DCCAD079-F92C-44DA-B258-624FC6517A5A}\PostBuild.exe
2010-08-18 06:00 . 2010-08-18 06:00 ——– d—–w- c:\programdata\SUPERAntiSpyware.com
2010-08-18 05:37 . 2010-03-05 14:01 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-08-18 05:23 . 2009-03-08 11:32 169472 —-a-w- c:\windows\system32\iexpress.exe
2010-08-18 05:23 . 2009-03-08 11:31 45568 —-a-w- c:\windows\system32\mshta.exe
2010-08-18 05:23 . 2009-03-08 11:33 107520 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2010-08-18 05:23 . 2009-03-08 11:33 103936 —-a-w- c:\windows\system32\SetDepNx.exe
2010-08-18 05:23 . 2009-03-08 11:33 109568 —-a-w- c:\windows\system32\PDMSetup.exe
2010-08-18 05:23 . 2009-03-08 11:33 107008 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2010-08-18 02:15 . 2010-08-19 12:29 ——– d—–w- c:\programdata\STOPzilla!
2010-08-18 01:56 . 2010-08-18 16:33 ——– d—–w- c:\users\Eddie\AppData\Local\ElevatedDiagnostics
2010-08-18 01:55 . 2010-08-18 01:55 ——– d—–w- c:\program files\Microsoft ATS
2010-08-16 23:14 . 2010-08-16 23:14 ——– d—–w- c:\programdata\Uniblue
2010-08-16 23:14 . 2010-08-18 22:40 ——– d—–w- c:\users\Eddie\AppData\Roaming\Uniblue
2010-08-11 21:13 . 2010-05-27 20:08 81920 —-a-w- c:\windows\system32\iccvid.dll
2010-08-11 21:13 . 2010-06-11 16:16 274944 —-a-w- c:\windows\system32\schannel.dll
2010-08-11 21:13 . 2010-06-11 16:15 1248768 —-a-w- c:\windows\system32\msxml3.dll
2010-08-11 21:13 . 2010-06-21 13:37 2037760 —-a-w- c:\windows\system32\win32k.sys
2010-08-11 21:13 . 2010-06-18 17:31 36864 —-a-w- c:\windows\system32\rtutils.dll
2010-08-11 21:13 . 2010-06-08 17:35 3600768 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-08-11 21:13 . 2010-06-08 17:35 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-08-11 21:13 . 2010-06-18 15:04 302080 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-11 21:13 . 2010-06-18 15:04 144896 —-a-w- c:\windows\system32\drivers\srv2.sys
2010-08-11 21:12 . 2010-06-16 16:04 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-08-10 23:12 . 2010-08-10 23:14 102135128 —-a-w- c:\users\Eddie\AppData\Roaming\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\Extractor.exe
2010-08-06 03:53 . 2010-08-06 03:53 ——– d—–w- c:\users\Maria\AppData\Roaming\Research In Motion
2010-08-04 01:38 . 2010-08-04 01:38 1821192 —-a-w- c:\users\Eddie\AppData\Roaming\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\vcredist_x86.exe
2010-08-04 01:38 . 2010-08-04 01:38 400728 —-a-w- c:\users\Eddie\AppData\Roaming\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\BBDesktopInstaller.exe
2010-08-04 01:38 . 2010-08-04 01:38 2959376 —-a-w- c:\users\Eddie\AppData\Roaming\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\dotnetfx35setup.exe
2010-08-04 01:38 . 2010-08-04 01:38 128472 —-a-w- c:\users\Eddie\AppData\Roaming\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\Helper.exe
2010-07-26 22:44 . 2010-07-26 22:44 ——– d—–w- c:\program files\iPod
2010-07-26 22:44 . 2010-07-26 22:45 ——– d—–w- c:\program files\iTunes
2010-07-26 22:41 . 2010-07-26 22:41 73000 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-19 18:51 . 2009-09-04 03:23 ——– d—–w- c:\programdata\dl_Cats
2010-08-18 18:57 . 2009-04-29 00:35 ——– d—–w- c:\program files\PC-Doctor for Windows
2010-08-18 17:15 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2010-08-18 17:10 . 2009-04-29 00:22 ——– d—–w- c:\program files\Hewlett-Packard
2010-08-18 17:01 . 2009-04-29 00:47 ——– d—–w- c:\programdata\Hewlett-Packard
2010-08-18 17:00 . 2009-04-29 00:34 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-08-18 03:10 . 2010-08-18 03:09 9592 —-a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-08-18 01:20 . 2010-07-16 21:22 ——– d—–w- c:\program files\Common Files\Research In Motion
2010-08-18 01:20 . 2009-09-05 22:05 ——– d—–w- c:\users\Eddie\AppData\Roaming\iolo
2010-08-18 01:20 . 2010-05-20 06:09 ——– d—–w- c:\programdata\lx_Cats
2010-08-18 01:20 . 2009-09-04 04:04 ——– d—–w- c:\program files\Dell V305
2010-08-18 01:20 . 2009-09-04 01:48 ——– d—–w- c:\program files\Microsoft Works
2010-08-18 01:20 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-08-17 14:48 . 2010-05-21 16:00 518 —-a-w- c:\users\Eddie\AppData\Roaming\iolo\Registry\Last\restore.bat
2010-08-17 02:02 . 2009-10-28 02:42 3684 —-a-w- c:\users\Eddie\AppData\Roaming\wklnhst.dat
2010-08-17 01:51 . 2009-09-07 00:41 ——– d—–w- c:\users\Eddie\AppData\Roaming\Dell Imaging Toolbox
2010-08-10 23:17 . 2010-07-16 21:29 ——– d—–w- c:\users\Eddie\AppData\Roaming\Research In Motion
2010-08-10 23:17 . 2010-07-16 21:22 ——– d—–w- c:\program files\Research In Motion
2010-08-10 23:17 . 2010-07-16 21:22 ——– d—–w- c:\programdata\Research In Motion
2010-08-10 20:21 . 2010-02-16 17:54 ——– d—–w- c:\program files\Windows Live Safety Center
2010-08-09 23:12 . 2009-09-05 22:28 1184 —-a-w- c:\users\Eddie\AppData\Roaming\iolo\restore.bat
2010-08-03 03:45 . 2010-05-20 05:06 ——– d—–w- c:\program files\Common Files\Java
2010-08-03 03:45 . 2009-09-15 00:30 ——– d—–w- c:\program files\Java
2010-07-26 22:44 . 2010-05-23 02:15 ——– d—–w- c:\program files\Common Files\Apple
2010-07-19 02:28 . 2010-07-19 02:28 690952 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-07-19 02:24 . 2010-07-19 02:22 256 —-a-w- c:\windows\system32\pool.bin
2010-07-17 16:29 . 2010-07-17 16:29 ——– d—–w- c:\programdata\App4rTemp
2010-07-17 09:00 . 2010-05-21 19:30 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-07-16 22:16 . 2010-07-16 22:16 53248 —-a-r- c:\users\Eddie\AppData\Roaming\Microsoft\Installer\{3360D505-B0AA-4284-92DF-F872AF90A448}\ARPPRODUCTICON.exe
2010-06-30 04:12 . 2010-06-30 04:12 13312 —-a-w- c:\windows\LPRES.DLL
2010-06-28 23:55 . 2010-05-23 02:20 ——– d—–w- c:\users\Eddie\AppData\Roaming\Apple Computer
2010-06-28 23:46 . 2010-06-28 23:46 ——– d—–w- c:\program files\Bonjour
2010-06-26 06:05 . 2010-08-18 05:25 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-26 06:02 . 2010-08-18 05:25 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-06-26 06:02 . 2010-08-18 05:25 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-06-26 04:25 . 2010-08-18 05:25 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2010-06-25 18:25 . 2010-06-25 18:25 ——– d—–w- c:\users\Eddie\AppData\Roaming\WildTangent
2010-06-25 18:25 . 2009-04-29 00:50 ——– d—–w- c:\programdata\WildTangent
2010-06-25 02:01 . 2010-06-25 02:01 ——– d—–w- c:\program files\Microsoft.NET
2010-06-05 17:14 . 2010-06-05 17:14 3 —-a-w- c:\program files\option.txt
2010-05-26 17:06 . 2010-06-10 05:44 34304 —-a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-10 05:44 289792 —-a-w- c:\windows\system32\atmfd.dll
2009-04-29 01:11 . 2009-04-29 01:10 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\program files\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-12-04 75016]
"dldtmon.exe"="c:\program files\Dell V305\dldtmon.exe" [2010-02-10 672424]
"dldtamon"="c:\program files\Dell V305\dldtamon.exe" [2010-02-10 16040]
"Dell PC TuneUp Startup"="c:\program files\iolo\Common\Lib\ioloLManager.exe" [2009-06-23 314224]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0334.0\mswinext.exe" [2009-10-16 240976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"DVDAgent"="c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2009-09-09 1148200]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
PictureMover.lnk - c:\program files\PictureMover\Bin\PictureMover.exe [2009-2-9 430080]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):7f,9b,af,a4,26,34,ca,01

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 dldtCATSCustConnectService;dldtCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\dldtserv.exe [2009-07-09 98984]
R3 PCDSRVC{4F253FFC-7957E8FC-06000000}_0;PCDSRVC{4F253FFC-7957E8FC-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor for windows\pcdsrvc.pkms [2009-02-02 20848]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-21 16896]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1008000.029\SYMEFA.SYS [2009-08-26 310320]
S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\Drivers\NIS\1008000.029\BHDrvx86.sys [2009-08-26 259632]
S1 ccHP;Symantec Hash Provider;c:\windows\System32\Drivers\NIS\1008000.029\ccHPx86.sys [2010-01-28 482432]
S1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\elrawdsk.sys [2008-12-09 20392]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100820.001\IDSvix86.sys [2010-05-28 344112]
S2 dldt_device;dldt_device;c:\windows\system32\dldtcoms.exe [2009-07-09 594600]
S2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2009-06-23 600944]
S2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2009-06-23 600944]
S2 lxdq_device;lxdq_device;c:\windows\system32\lxdqcoms.exe [2007-11-28 589824]
S2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [2009-08-26 117640]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2010-06-24 92008]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-05-26 102448]
S3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\Drivers\NIS\1008000.029\SYMNDISV.SYS [2009-08-26 48688]


— Other Services/Drivers In Memory —

*NewlyCreated* - KWTDRPOD
*Deregistered* - kwtdrpod

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-08-18 c:\windows\Tasks\HPCeeScheduleForEddie.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2009-04-29 01:17]

2010-08-22 c:\windows\Tasks\RegistryBooster.job
- c:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2010-08-18 15:11]

2010-08-22 c:\windows\Tasks\User_Feed_Synchronization-{7248517B-FBA4-4447-BF1C-185AC419A6C8}.job
- c:\windows\system32\msfeedssync.exe [2010-08-18 04:24]

2010-08-23 c:\windows\Tasks\User_Feed_Synchronization-{EB66F886-C34F-4064-ADB0-16A5917DD0E2}.job
- c:\windows\system32\msfeedssync.exe [2010-08-18 04:24]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.xfinity.com/?cid=xfactiv_tech_main
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=en_us&c;=93&bd;=Presario&pf;=cndt
uInternet Settings,ProxyOverride = *.local
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
AddRemove-Linksys EasyLink Advisor - c:\programdata\{35ACA973-70F0-495F-9092-74A130711865}\setup.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-22 21:31
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll SYMEVENT.SYS >>UNKNOWN [0x8775E7AA]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x80717d24
\Driver\ACPI -> acpi.sys @ 0x80609d68
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCDSRVC{4F253FFC-7957E8FC-06000000}_0]
"ImagePath"="\??\c:\program files\pc-doctor for windows\pcdsrvc.pkms"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-08-22 21:35:09
ComboFix-quarantined-files.txt 2010-08-23 01:35

Pre-Run: 207,390,330,880 bytes free
Post-Run: 207,394,390,016 bytes free

- - End Of File - - D9C4BCDBD628D2516983DAA4500EF8D0
Hi,

Please do the following:


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
Hello Again, Here is the Report: 2010/08/22 23:35:17.0018 TDSS rootkit removing tool 2.4.1.2 Aug 16 2010 09:46:23 2010/08/22 23:35:17.0018 ================================================================================ 2010/08/22 23:35:17.0018 SystemInfo: 2010/08/22 23:35:17.0018 2010/08/22 23:35:17.0018 OS Version: 6.0.6002 ServicePack: 2.0 2010/08/22 23:35:17.0018 Product type: Workstation 2010/08/22 23:35:17.0018 ComputerName: EDDIE-MARIA 2010/08/22 23:35:17.0019 UserName: Eddie 2010/08/22 23:35:17.0019 Windows directory: C:\Windows 2010/08/22 23:35:17.0019 System windows directory: C:\Windows 2010/08/22 23:35:17.0019 Processor architecture: Intel x86 2010/08/22 23:35:17.0019 Number of processors: 2 2010/08/22 23:35:17.0019 Page size: 0x1000 2010/08/22 23:35:17.0019 Boot type: Normal boot 2010/08/22 23:35:17.0019 ================================================================================ 2010/08/22 23:36:09.0219 Initialize success 2010/08/22 23:36:14.0574 ================================================================================ 2010/08/22 23:36:14.0574 Scan started 2010/08/22 23:36:14.0574 Mode: Manual; 2010/08/22 23:36:14.0574 ================================================================================ 2010/08/22 23:36:15.0286 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 2010/08/22 23:36:15.0701 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 2010/08/22 23:36:16.0150 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 2010/08/22 23:36:16.0513 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 2010/08/22 23:36:16.0892 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 2010/08/22 23:36:17.0284 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys 2010/08/22 23:36:17.0946 AgereSoftModem (7560f465f1ce69c53bf17559ee195548) C:\Windows\system32\DRIVERS\AGRSM.sys 2010/08/22 23:36:18.0378 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 2010/08/22 23:36:18.0741 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 2010/08/22 23:36:19.0060 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 2010/08/22 23:36:19.0673 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 2010/08/22 23:36:20.0051 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 2010/08/22 23:36:20.0554 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 2010/08/22 23:36:20.0941 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys 2010/08/22 23:36:21.0656 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 2010/08/22 23:36:22.0141 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 2010/08/22 23:36:22.0675 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 2010/08/22 23:36:23.0243 atapi (2d9c903dc76a66813d350a562de40ed9) C:\Windows\system32\drivers\atapi.sys 2010/08/22 23:36:23.0784 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 2010/08/22 23:36:24.0169 BHDrvx86 (76154fa6a742c613b44bb636b1a7c057) C:\Windows\System32\Drivers\NIS\1008000.029\BHDrvx86.sys 2010/08/22 23:36:24.0716 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 2010/08/22 23:36:25.0071 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys 2010/08/22 23:36:25.0406 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 2010/08/22 23:36:25.0720 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 2010/08/22 23:36:25.0956 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 2010/08/22 23:36:26.0189 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 2010/08/22 23:36:26.0780 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 2010/08/22 23:36:27.0049 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 2010/08/22 23:36:27.0620 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 2010/08/22 23:36:28.0439 ccHP (8973ff34b83572d867b5b928905ad5ac) C:\Windows\System32\Drivers\NIS\1008000.029\ccHPx86.sys 2010/08/22 23:36:29.0020 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 2010/08/22 23:36:29.0248 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 2010/08/22 23:36:29.0900 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 2010/08/22 23:36:30.0375 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 2010/08/22 23:36:30.0692 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 2010/08/22 23:36:31.0127 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys 2010/08/22 23:36:32.0051 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 2010/08/22 23:36:32.0616 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 2010/08/22 23:36:33.0085 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys 2010/08/22 23:36:33.0510 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 2010/08/22 23:36:33.0894 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 2010/08/22 23:36:34.0294 DXGKrnl (5c7e2097b91d689ded7a6ff90f0f3a25) C:\Windows\System32\drivers\dxgkrnl.sys 2010/08/22 23:36:34.0797 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 2010/08/22 23:36:35.0331 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 2010/08/22 23:36:35.0748 eeCtrl (089296aedb9b72b4916ac959752bdc89) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 2010/08/22 23:36:36.0209 ElRawDisk (9c64c2a950195f9bc3a09a499648b01c) C:\Windows\system32\drivers\elrawdsk.sys 2010/08/22 23:36:36.0726 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 2010/08/22 23:36:36.0943 EraserUtilRebootDrv (850259334652d392e33ee3412562e583) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 2010/08/22 23:36:37.0271 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 2010/08/22 23:36:37.0649 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 2010/08/22 23:36:37.0953 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 2010/08/22 23:36:38.0505 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 2010/08/22 23:36:38.0964 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 2010/08/22 23:36:39.0491 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 2010/08/22 23:36:40.0139 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 2010/08/22 23:36:40.0731 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 2010/08/22 23:36:41.0285 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 2010/08/22 23:36:41.0910 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 2010/08/22 23:36:42.0420 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 2010/08/22 23:36:43.0001 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 2010/08/22 23:36:43.0371 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 2010/08/22 23:36:43.0662 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 2010/08/22 23:36:44.0131 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 2010/08/22 23:36:44.0462 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 2010/08/22 23:36:44.0927 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 2010/08/22 23:36:45.0487 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 2010/08/22 23:36:45.0974 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 2010/08/22 23:36:46.0436 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 2010/08/22 23:36:46.0982 IDSVix86 (2edd3504457691a10328079da011d0b8) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100820.001\IDSvix86.sys 2010/08/22 23:36:47.0193 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 2010/08/22 23:36:48.0000 IntcAzAudAddService (84ed2154239f9d013bbd3220755ada8b) C:\Windows\system32\drivers\RTKVHDA.sys 2010/08/22 23:36:48.0411 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 2010/08/22 23:36:48.0678 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 2010/08/22 23:36:48.0980 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2010/08/22 23:36:49.0719 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 2010/08/22 23:36:50.0341 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 2010/08/22 23:36:50.0903 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 2010/08/22 23:36:51.0541 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 2010/08/22 23:36:52.0282 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 2010/08/22 23:36:52.0839 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 2010/08/22 23:36:53.0414 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 2010/08/22 23:36:53.0958 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 2010/08/22 23:36:54.0539 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 2010/08/22 23:36:54.0998 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 2010/08/22 23:36:55.0640 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 2010/08/22 23:36:56.0219 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 2010/08/22 23:36:56.0745 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 2010/08/22 23:36:57.0066 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 2010/08/22 23:36:57.0739 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 2010/08/22 23:36:57.0983 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys 2010/08/22 23:36:58.0460 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 2010/08/22 23:36:58.0947 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 2010/08/22 23:36:59.0471 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 2010/08/22 23:36:59.0701 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 2010/08/22 23:37:00.0063 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 2010/08/22 23:37:00.0586 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 2010/08/22 23:37:00.0996 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 2010/08/22 23:37:01.0539 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 2010/08/22 23:37:01.0927 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 2010/08/22 23:37:02.0307 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 2010/08/22 23:37:02.0667 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 2010/08/22 23:37:02.0992 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys 2010/08/22 23:37:03.0666 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2010/08/22 23:37:03.0939 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2010/08/22 23:37:04.0630 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys 2010/08/22 23:37:04.0894 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 2010/08/22 23:37:05.0473 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 2010/08/22 23:37:05.0955 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 2010/08/22 23:37:06.0413 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 2010/08/22 23:37:06.0830 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 2010/08/22 23:37:07.0094 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 2010/08/22 23:37:07.0577 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 2010/08/22 23:37:07.0931 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 2010/08/22 23:37:08.0601 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 2010/08/22 23:37:09.0222 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 2010/08/22 23:37:09.0636 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 2010/08/22 23:37:09.0879 NAVENG (0953bb24c1e70a99c315f44f15993c17) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100822.007\NAVENG.SYS 2010/08/22 23:37:10.0419 NAVEX15 (3ddb0bef60b65df6b110c23e17cd67dc) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100822.007\NAVEX15.SYS 2010/08/22 23:37:11.0007 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 2010/08/22 23:37:11.0602 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 2010/08/22 23:37:11.0954 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 2010/08/22 23:37:12.0426 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 2010/08/22 23:37:12.0881 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 2010/08/22 23:37:13.0234 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 2010/08/22 23:37:13.0705 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 2010/08/22 23:37:14.0198 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 2010/08/22 23:37:14.0596 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 2010/08/22 23:37:15.0010 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 2010/08/22 23:37:15.0632 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 2010/08/22 23:37:16.0232 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 2010/08/22 23:37:16.0800 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 2010/08/22 23:37:17.0161 NVENETFD (d958a2b5f6ad5c3b8ccdc4d7da62466c) C:\Windows\system32\DRIVERS\nvmfdx32.sys 2010/08/22 23:37:18.0021 nvlddmkm (09f5e33f91e186037262355b0ba72913) C:\Windows\system32\DRIVERS\nvlddmkm.sys 2010/08/22 23:37:18.0621 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 2010/08/22 23:37:19.0100 nvrd32 (5dd1242cabc1ef8dce4438d72d72a436) C:\Windows\system32\drivers\nvrd32.sys 2010/08/22 23:37:19.0671 nvsmu (62754e376185eacbb73d06fea0ffc54a) C:\Windows\system32\drivers\nvsmu.sys 2010/08/22 23:37:20.0102 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 2010/08/22 23:37:20.0667 nvstor32 (bb4dd678706510d9249eed1da0219900) C:\Windows\system32\drivers\nvstor32.sys 2010/08/22 23:37:21.0047 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 2010/08/22 23:37:21.0768 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys 2010/08/22 23:37:22.0074 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 2010/08/22 23:37:22.0597 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 2010/08/22 23:37:23.0021 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 2010/08/22 23:37:23.0756 PCDSRVC{4F253FFC-7957E8FC-06000000}_0 (a88f42ad20418620d08a13ad1a70c083) c:\program files\pc-doctor for windows\pcdsrvc.pkms 2010/08/22 23:37:24.0257 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 2010/08/22 23:37:24.0770 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys 2010/08/22 23:37:25.0021 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 2010/08/22 23:37:25.0474 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 2010/08/22 23:37:25.0991 pnarp (63200893c9d5934a7504d20f68276cc7) C:\Windows\system32\DRIVERS\pnarp.sys 2010/08/22 23:37:26.0275 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 2010/08/22 23:37:26.0810 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\DRIVERS\processr.sys 2010/08/22 23:37:27.0330 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 2010/08/22 23:37:27.0966 purendis (748bcab4eff5959ed347c05a1c1a0af8) C:\Windows\system32\DRIVERS\purendis.sys 2010/08/22 23:37:28.0827 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 2010/08/22 23:37:29.0292 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 2010/08/22 23:37:29.0753 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 2010/08/22 23:37:30.0222 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 2010/08/22 23:37:30.0723 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 2010/08/22 23:37:31.0447 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 2010/08/22 23:37:32.0077 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 2010/08/22 23:37:32.0286 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 2010/08/22 23:37:32.0503 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 2010/08/22 23:37:32.0952 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 2010/08/22 23:37:33.0319 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 2010/08/22 23:37:33.0797 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 2010/08/22 23:37:34.0595 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\Windows\system32\DRIVERS\RimSerial.sys 2010/08/22 23:37:34.0997 ROOTMODEM (75e8a6bfa7374aba833ae92bf41ae4e6) C:\Windows\system32\Drivers\RootMdm.sys 2010/08/22 23:37:35.0363 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 2010/08/22 23:37:35.0721 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 2010/08/22 23:37:36.0189 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2010/08/22 23:37:36.0656 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 2010/08/22 23:37:37.0088 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 2010/08/22 23:37:37.0614 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 2010/08/22 23:37:37.0922 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys 2010/08/22 23:37:38.0388 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 2010/08/22 23:37:38.0890 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys 2010/08/22 23:37:39.0363 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 2010/08/22 23:37:39.0812 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 2010/08/22 23:37:40.0368 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 2010/08/22 23:37:40.0816 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 2010/08/22 23:37:41.0362 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 2010/08/22 23:37:41.0976 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 2010/08/22 23:37:42.0744 SRTSP (e81f6caeab9ad5732e94c07c97866aa2) C:\Windows\System32\Drivers\NIS\1008000.029\SRTSP.SYS 2010/08/22 23:37:43.0164 SRTSPX (e28de499d942b08058bffac69d4122b6) C:\Windows\system32\drivers\NIS\1008000.029\SRTSPX.SYS 2010/08/22 23:37:43.0654 srv (96a5e2c642af8f591a7366429809506b) C:\Windows\system32\DRIVERS\srv.sys 2010/08/22 23:37:44.0237 srv2 (71da2d64880c97e5ffc3c81761632751) C:\Windows\system32\DRIVERS\srv2.sys 2010/08/22 23:37:44.0826 srvnet (0c5ab1892ae0fa504218db094bf6d041) C:\Windows\system32\DRIVERS\srvnet.sys 2010/08/22 23:37:45.0288 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 2010/08/22 23:37:45.0751 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 2010/08/22 23:37:46.0902 SymEFA (d0885f6e24259a6c65e68d6ad749910a) C:\Windows\system32\drivers\NIS\1008000.029\SYMEFA.SYS 2010/08/22 23:37:47.0410 SymEvent (a54ff04bd6e75dc4d8cb6f3e352635e0) C:\Windows\system32\Drivers\SYMEVENT.SYS 2010/08/22 23:37:48.0016 SYMFW (1e825026436c4eac3e1a11d1e9c33f2c) C:\Windows\System32\Drivers\NIS\1008000.029\SYMFW.SYS 2010/08/22 23:37:48.0628 SymIM (34f1c9d5dcc19df1e824d6b73767b8af) C:\Windows\system32\DRIVERS\SymIMv.sys 2010/08/22 23:37:49.0328 SYMNDISV (dcbf73da96cce94933c8cc6eded3c98b) C:\Windows\System32\Drivers\NIS\1008000.029\SYMNDISV.SYS 2010/08/22 23:37:50.0218 SYMTDI (e4fa8bbb96e314e9508865de1a767538) C:\Windows\System32\Drivers\NIS\1008000.029\SYMTDI.SYS 2010/08/22 23:37:50.0591 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 2010/08/22 23:37:51.0038 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 2010/08/22 23:37:51.0997 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys 2010/08/22 23:37:52.0649 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys 2010/08/22 23:37:53.0136 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 2010/08/22 23:37:53.0791 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 2010/08/22 23:37:54.0064 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 2010/08/22 23:37:54.0356 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 2010/08/22 23:37:54.0712 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 2010/08/22 23:37:55.0106 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 2010/08/22 23:37:55.0623 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 2010/08/22 23:37:56.0040 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 2010/08/22 23:37:56.0666 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 2010/08/22 23:37:56.0994 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 2010/08/22 23:37:57.0556 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 2010/08/22 23:37:58.0016 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 2010/08/22 23:37:58.0541 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 2010/08/22 23:37:58.0996 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 2010/08/22 23:37:59.0352 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 2010/08/22 23:37:59.0907 usbbus (9419faac6552a51542dbba02971c841c) C:\Windows\system32\DRIVERS\lgusbbus.sys 2010/08/22 23:38:00.0347 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 2010/08/22 23:38:00.0816 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 2010/08/22 23:38:01.0435 UsbDiag (c0a466fa4ffec464320e159bc1bbdc0c) C:\Windows\system32\DRIVERS\lgusbdiag.sys 2010/08/22 23:38:01.0984 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 2010/08/22 23:38:02.0475 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 2010/08/22 23:38:02.0957 USBModem (f74a54774a9b0afeb3c40adec68aa600) C:\Windows\system32\DRIVERS\lgusbmodem.sys 2010/08/22 23:38:03.0427 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys 2010/08/22 23:38:03.0945 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 2010/08/22 23:38:04.0582 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 2010/08/22 23:38:04.0727 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2010/08/22 23:38:04.0958 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 2010/08/22 23:38:05.0505 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 2010/08/22 23:38:05.0861 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 2010/08/22 23:38:06.0147 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 2010/08/22 23:38:06.0590 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 2010/08/22 23:38:06.0954 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 2010/08/22 23:38:07.0329 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 2010/08/22 23:38:07.0842 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 2010/08/22 23:38:08.0499 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 2010/08/22 23:38:08.0953 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 2010/08/22 23:38:09.0504 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 2010/08/22 23:38:09.0896 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2010/08/22 23:38:09.0919 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2010/08/22 23:38:10.0475 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 2010/08/22 23:38:10.0971 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 2010/08/22 23:38:11.0716 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys 2010/08/22 23:38:12.0026 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys 2010/08/22 23:38:12.0785 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 2010/08/22 23:38:13.0114 WSDPrintDevice (4422ac5ed8d4c2f0db63e71d4c069dd7) C:\Windows\system32\DRIVERS\WSDPrint.sys 2010/08/22 23:38:13.0707 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 2010/08/22 23:38:13.0948 XAudio (bfcc507eca58f11c5fed96e192b878cb) C:\Windows\system32\DRIVERS\xaudio.sys 2010/08/22 23:38:14.0030 ================================================================================ 2010/08/22 23:38:14.0030 Scan finished 2010/08/22 23:38:14.0030 ================================================================================
Hi

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista/Win7 users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Hello Again, Wow that was a 4 hour scan but it did not show anything. Here are the copys of both scans: MALWAREBYTES: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4466 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18943 8/23/2010 12:25:46 PM mbam-log-2010-08-23 (12-25-46).txt Scan type: Quick scan Objects scanned: 140797 Time elapsed: 5 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) KASPERSKY: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Monday, August 23, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Monday, August 23, 2010 14:43:11 Records in database: 4138022 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 189502 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 03:19:59 No threats found. Scanned area is clean. Selected area has been scanned.
Good,

please do the following:

  • Hold down the Windows key and press R to open a run box
  • type the following text into the run box

    appwiz.cpl

  • This will open your Programs And Features
  • A list of installed programs will populate
  • Remove the following program:


Java™ 6 Update 3


NEXT

please advise how the computer is running and if there are any outstanding issues.
I tried to remove but got this message "Error 1719. Windows installer service not be accessed. This can occur if the windows installer is not correctly installed. Contact support personel" ???
1. Open a Command Window in Administrator mode:
  • click Start
  • click All Programs, then Accessories
  • right click on the Command Prompt option,
  • on the drop down menu which appears, click on the Run as Administrator option.

Then start the System File Checker

  • In the Command Prompt window, type: sfc /scannow
  • press Enter.
  • You’ll see “the system scan will begin”.

The scan may take some time and windows will repair/replace any corrupt or missing files. You will be asked to insert your Vista DVD if it’s needed.

Close the Command Prompt Window when the job is finished.

Let me know how that goes
Here is a copy of what was scanned. Looks like some repairs could not be fixed. I tried to uninstall Java update 3 again but received the same message. Microsoft Windows [Version 6.0.6002] Copyright © 2006 Microsoft Corporation. All rights reserved. C:\Windows\system32>sfc/scannow Beginning system scan. This process will take some time. Beginning verification phase of system scan. Verification 100% complete. Windows Resource Protection found corrupt files but was unable to fix some of th em. Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log C:\Windows\system32>
OK

I think it would be best to start a new topic in out Hardware forum for that and let the expert techs assist.

I'll clean up the tools we used, link back to this topic so they can see you are clean of malware

Please do the following:

You can delete the MBRCheck, DDS and GMER logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


If there are any logs/tools remaining > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.
Ok, Many Thanks for all your help with this. I will follow your instructions and post a new topic in the hardware forum. Thank you once again! :thumbup: BigEd

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI