This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack.WindowsUpdates infection

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My daughter's laptop hasn't been able to connect to Windows Update and has been blocked at times from using spyware software. I finally was able to run Malwarebytes' Anti-Malware, and it showed two infections, both Hijack.WindowsUpdates. No spyware program seems to be able to remove this. I have included the logfile of a scan with HijackThis below. Thanks for any help.

—————————————–

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:12:58 PM, on 2/11/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\STacSV.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\DellTPad\Apntex.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Stickies\stickies.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2071213
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blackle.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2071213
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: ::1 localhost
O1 - Hosts: 94.232.248.66 antivir-service.microsoft.com
O1 - Hosts: 94.232.248.66 antivirussys2009.com
O1 - Hosts: 94.232.248.66 www.antivirussys2009.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: PriceGong - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files\PriceGong\2.1.0\PriceGongIE.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {6FB726BF-B07D-46C2-BE7C-47768FB12226} - (no file)
O2 - BHO: Search Toolbar - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Search Toolbar - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [dscactivate] "%ProgramFiles%\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -s
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Version Cue CS2] C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Protection] C:\Documents and Settings\Mia\Application Data\defender.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: Stickies.lnk = C:\Program Files\Stickies\stickies.exe
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1283803385781
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo…Uploader4_5.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.myspace.com/gameshell/games/c…ader_v10_en.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll, C:\WINDOWS\system32\vehotora.dll, C:\WINDOWS\system32\soviveri.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O20 - Winlogon Notify: urqRHxyV - urqRHxyV.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1ca1ec52259e42c) (gupdate1ca1ec52259e42c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Premier\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 13179 bytes
Hello honyock and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

Lets take a closer look at the machine with the following scans:

  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOTKIT" entries


Please post the DDS logs and the GMER log in your next reply. If you enconter any problems with the scan come back and let me know.
HI JonTom, thanks for helping with this. I ran the scans you requested. I'm posting the two DDS results below. While I was doing the GMER scan, I got a blue screen crash. The info on the screen said the file that was the problem leading to the crash was uxlyypod.sys . It said it was a page fault in a non page area issue. I'll run the GMER scan again - it takes quite awhile - and post the results of that scan if I can get it to scan successfully. First, here is the dds.txt file: DDS (Ver_10-12-12.02) - NTFSx86 Run by [removed] at 10:16:17.17 on Sat 02/12/2011 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_16 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1014.198 [GMT -6:00] AV: AVG Anti-Virus Free *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: COMODO Firewall Pro *Enabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\COMODO\Firewall\cmdagent.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\STacSV.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\DellTPad\Apoint.exe C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\WINDOWS\stsystra.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\COMODO\Firewall\cfp.exe C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe C:\Program Files\DellTPad\Apntex.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Stickies\stickies.exe C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\AVG\AVG8\avgui.exe C:\Documents and Settings\Mia\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.blackle.com/ uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2071213 uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: PriceGongBHO Class: {1631550f-191d-4826-b069-d9439253d926} - c:\program files\pricegong\2.1.0\PriceGongIE.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: {6FB726BF-B07D-46C2-BE7C-47768FB12226} - No File BHO: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - c:\program files\search toolbar\SearchToolbar.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - c:\program files\search toolbar\SearchToolbar.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Spyware Protection] c:\documents and settings\mia\application data\defender.exe mRun: [Apoint] c:\program files\delltpad\Apoint.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [dscactivate] "%ProgramFiles%\Dell Support Center\gs_agent\custom\dsca.exe" mRun: [COMODO Firewall Pro] "c:\program files\comodo\firewall\cfp.exe" -s mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe" mRun: [] mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [Adobe Version Cue CS2] c:\program files\adobe\adobe version cue cs2\controlpanel\VersionCueCS2Tray.exe dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\mia\startm~1\programs\startup\stickies.lnk - c:\program files\stickies\stickies.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1283803385781 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} - hxxp://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://games.myspace.com/gameshell/games/channel–110343720/lc–en/room–e8d118e7-9f2a-41f6-a3f5-8da718848895/online/peggle/en/popcaploader_v10_en.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxdev.dll Notify: urqRHxyV - urqRHxyV.dll AppInit_DLLs: c:\windows\system32\guard32.dll, c:\windows\system32\vehotora.dll, c:\windows\system32\soviveri.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll LSA: Authentication Packages = msv1_0 c:\windows\system32\opnkiffF LSA: Notification Packages = scecli c:\windows\system32\vehotora.dll c:\windows\system32\soviveri.dll Hosts: 94.232.248.66 antivir-service.microsoft.com Hosts: 94.232.248.66 antivirussys2009.com Hosts: 94.232.248.66 www.antivirussys2009.com ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\mia\applic~1\mozilla\firefox\profiles\1cmrp260.default\ FF - component: c:\program files\mozilla firefox\extensions\[removed]\components\Shim.dll FF - component: c:\program files\pricegong\2.1.0\ff\components\PriceGongFF.dll FF - plugin: c:\documents and settings\mia\application data\facebook\npfbplugin_1_0_3.dll FF - plugin: c:\documents and settings\mia\local settings\application data\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: The Browser Highlighter: [removed] - c:\program files\mozilla firefox\extensions\[removed] FF - Ext: Skype extension for Firefox: {B13721C7-F507-4982-B2E5-502A71474FED} - c:\program files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} FF - Ext: ImTranslator: {9AA46F4F-4DC7-4c06-97AF-5035170634FE} - %profile%\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE} FF - Ext: Go Green: [removed] - %profile%\extensions\[removed] FF - Ext: Screengrab: {02450954-cdd9-410f-b1da-db804e18c671} - %profile%\extensions\{02450954-cdd9-410f-b1da-db804e18c671} FF - Ext: Locator: {05f6a7ea-896b-11da-8bde-f66bad1e3fff} - %profile%\extensions\{05f6a7ea-896b-11da-8bde-f66bad1e3fff} FF - Ext: Personas: [removed] - %profile%\extensions\[removed] FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} FF - Ext: Search Toolbar: [removed] - %profile%\extensions\[removed] FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff FF - Ext: PriceGong: {8A9386B4-E958-4c4c-ADF4-8F26DB3E4829} - c:\program files\pricegong\2.1.0\FF —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-4-26 335240] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-12-25 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-26 108552] R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2007-12-25 81272] R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2007-12-25 23672] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-3-23 9968] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-3-23 72944] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-4-26 297752] R2 cmdAgent;COMODO Firewall Pro Helper Service;c:\program files\comodo\firewall\cmdagent.exe [2007-12-25 495360] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] S1 1c909efd;1c909efd;c:\windows\system32\drivers\1c909efd.sys [2009-6-15 0] S2 gupdate1ca1ec52259e42c;Google Update Service (gupdate1ca1ec52259e42c);c:\program files\google\update\GoogleUpdate.exe [2009-8-16 133104] S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-3-23 7408] S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2011-2-6 11520] =============== Created Last 30 ================ 2011-02-12 05:00:06 388096 —-a-r- c:\docume~1\mia\applic~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2011-02-12 05:00:05 ——– d—–w- c:\program files\Trend Micro 2011-02-06 19:00:43 ——– d—–w- c:\program files\EZBackitup 2011-02-06 18:45:39 11520 —-a-w- c:\windows\system32\drivers\wdcsam.sys ==================== Find3M ==================== ============= FINISH: 10:17:27.03 =============== ———————————————————————————————————— Now, the attach.txt file: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-12-12.02) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 12/24/2007 11:09:56 AM System Uptime: 2/12/2011 6:53:13 AM (4 hours ago) Motherboard: Dell Inc. | | 0TT347 Processor: Intel® Core™2 Duo CPU T5270 @ 1.40GHz | Microprocessor | 1396/200mhz Processor: Intel® Core™2 Duo CPU T5270 @ 1.40GHz | Microprocessor | 1396/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 146 GiB total, 36.304 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {6BDD1FC6-810F-11D0-BEC7-08002BE2092F} Description: Canon MX700 ser Network Device ID: ROOT\CANON_IJ_NETWORK\0000 Manufacturer: Canon Name: Canon MX700 ser Network PNP Device ID: ROOT\CANON_IJ_NETWORK\0000 Service: StillCam ==== System Restore Points =================== RP617: 1/1/2011 7:10:07 PM - System Checkpoint RP618: 1/2/2011 8:54:04 PM - System Checkpoint RP619: 1/3/2011 11:47:50 PM - System Checkpoint RP620: 1/5/2011 12:07:41 AM - System Checkpoint RP621: 1/6/2011 12:10:38 AM - System Checkpoint RP622: 1/7/2011 5:55:09 PM - System Checkpoint RP623: 1/8/2011 6:20:24 PM - System Checkpoint RP624: 1/9/2011 7:06:16 PM - System Checkpoint RP625: 1/10/2011 10:51:53 PM - System Checkpoint RP626: 1/12/2011 7:38:31 AM - System Checkpoint RP627: 1/13/2011 5:47:57 PM - System Checkpoint RP628: 1/14/2011 6:25:54 PM - System Checkpoint RP629: 1/15/2011 6:46:52 PM - System Checkpoint RP630: 1/16/2011 7:27:09 PM - System Checkpoint RP631: 1/17/2011 8:04:47 PM - System Checkpoint RP632: 1/18/2011 9:32:06 PM - System Checkpoint RP633: 1/19/2011 10:02:21 PM - System Checkpoint RP634: 1/20/2011 10:08:01 PM - System Checkpoint RP635: 1/21/2011 10:50:13 PM - System Checkpoint RP636: 1/22/2011 11:20:46 PM - System Checkpoint RP637: 1/24/2011 6:40:33 PM - System Checkpoint RP638: 1/25/2011 8:33:52 PM - System Checkpoint RP639: 1/26/2011 9:54:47 PM - System Checkpoint RP640: 1/27/2011 10:32:23 PM - System Checkpoint RP641: 1/30/2011 6:49:45 PM - System Checkpoint RP642: 1/31/2011 10:56:13 PM - System Checkpoint RP643: 2/1/2011 11:08:34 PM - System Checkpoint RP644: 2/3/2011 5:33:27 PM - System Checkpoint RP645: 2/4/2011 6:22:37 PM - System Checkpoint RP646: 2/5/2011 7:10:46 PM - System Checkpoint RP647: 2/6/2011 7:45:23 PM - System Checkpoint RP648: 2/7/2011 8:24:54 PM - System Checkpoint RP649: 2/8/2011 11:18:17 PM - System Checkpoint RP650: 2/9/2011 11:35:04 PM - System Checkpoint RP651: 2/11/2011 11:00:04 PM - Installed HiJackThis ==== Installed Programs ====================== AbiWord 2.6.8 AbiWord Importer/Exporter Plugins Adobe Acrobat 8 Professional Adobe Acrobat 8.1.2 Professional Adobe Acrobat 8.1.2 Security Update 1 (KB403742) Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) Adobe Bridge 1.0 Adobe Common File Installer Adobe Creative Suite 2 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe GoLive CS2 Adobe Help Center 1.0 Adobe Illustrator CS2 Adobe InDesign CS2 Adobe Photoshop CS2 Adobe Reader 8.1.2 Adobe Reader 8.1.2 Security Update 1 (KB403742) Adobe Stock Photos 1.0 Adobe SVG Viewer 3.0 Adobe Version Cue CS2 Advanced Audio FX Engine Advanced Video FX Engine America Online AOL Coach Version 1.0(Build:20020823.1) Apple Application Support Apple Mobile Device Support Apple Software Update AVG 8.5 Bonjour Broadcom Management Programs Browser Address Error Redirector Canon Camera Access Library Canon Camera Support Core Library Canon IJ Network Scan Utility Canon IJ Network Tool Canon MP Navigator EX 1.0 Canon MX700 series Canon MX700 series User Registration Canon My Printer Canon RAW Image Task for ZoomBrowser EX Canon S600 Canon SELPHY CP770 Canon Utilities CameraWindow Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX Canon Utilities Easy-PhotoPrint EX Canon Utilities EOS Utility Canon Utilities MyCamera Canon Utilities RemoteCapture Task for ZoomBrowser EX Canon Utilities Solution Menu Canon Utilities ZoomBrowser EX Canon ZoomBrowser EX Memory Card Utility CCleaner CodeStuff Starter COMODO Firewall Pro Conexant HDA D330 MDC V.92 Modem Dell Support Center Dell Touchpad Dell Webcam Center Dell Webcam Manager Dell Wireless WLAN Card Digital Line Detect EVEREST Home Edition v1.51 EZBack-it-up 2.0.1 Facebook Plug-In FairUse Wizard 2 Google Chrome Google Earth Google Toolbar for Internet Explorer Google Update Helper High Definition Audio Driver Package - KB835221 HiJackThis Hotfix for Microsoft .NET Framework 2.0 (KB922981) Hotfix for Windows XP (KB896256) Hotfix for Windows XP (KB906569) Hotfix for Windows XP (KB908673) Hotfix for Windows XP (KB909095) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB934428-v2) Hotfix for Windows XP (KB935448) Intel® Graphics Media Accelerator Driver IntelliSonic Speech Enhancement iTunes J2SE Runtime Environment 5.0 Update 6 Java™ 6 Update 16 Laptop Integrated Webcam Driver (1.03.02.0719) Live! Cam Avatar Creator Live! Cam Avatar v1.0 Macromedia Dreamweaver 8 Macromedia Extension Manager Malwarebytes' Anti-Malware MediaDirect Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft National Language Support Downlevel APIs Microsoft Office 2003 Web Components Microsoft Office 2007 Primary Interop Assemblies Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Professional 2007 Microsoft Office Professional 2007 Trial Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Small Business Connectivity Components Microsoft Office Word MUI (English) 2007 Microsoft Software Update for Web Folders (English) 12 Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Works MobileMe Control Panel Modem Diagnostic Tool Move Networks Media Player for Internet Explorer Mozilla Firefox (3.6.13) MSN MSXML 4.0 SP2 (KB936181) MSXML 6.0 Parser (KB933579) NetWaiting OutlookAddinSetup Peggle Deluxe Photo Express LE Presto! PageManager 7.15.16 PriceGong 2.1.0 QualxServ Service Agreement QuickSet QuickTime RealPlayer Basic Roxio Creator Audio Roxio Creator Copy Roxio Creator Data Roxio Creator Premier Roxio Creator Tools Roxio Drag-to-Disc Roxio EasyArchive Roxio Express Labeler Roxio MyDVD Premier Roxio Update Manager Safari ScanSoft OmniPage SE 4 SearchAssist Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB944653) Skype web features Skype™ 4.1 Sonic Activation Module Startup Manager 2.4.2 Stickies 6.5a Suite Specific SUPERAntiSpyware Free Edition TELL ME MORE The Game of Life - SpongeBob SquarePants Edition The Sims 2 The Sims™ 2 Bon Voyage The Sims™ 2 FreeTime Unity Web Player Update for Microsoft Office Word 2007 (KB974631) Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB912945) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Viewpoint Media Player (Remove Only) VLC media player 0.9.9 WebFldrs XP Windows Defender Windows Genuine Advantage Validation Tool (KB892130) Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format Runtime Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885855 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB889673 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 WinZip YASA MP4 Video Converter v3.2 (build 0051) ==== Event Viewer Messages From Past Week ======== 2/8/2011 11:37:00 PM, error: Service Control Manager [7000] - The Background Intelligent Transfer Service service failed to start due to the following error: The system cannot find the file specified. 2/8/2011 11:37:00 PM, error: DCOM [10005] - DCOM got error "%2" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097} 2/6/2011 12:47:04 PM, error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: This operation returned because the timeout period expired. 2/6/2011 1:48:01 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 2/11/2011 9:44:50 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: APPDRV AvgLdx86 AvgMfx86 cmdGuard Fips intelppm ohci1394 SASDIFSV SASKUTIL 2/11/2011 9:33:09 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: APPDRV AvgLdx86 AvgMfx86 cmdGuard Fips intelppm SASDIFSV SASKUTIL 2/11/2011 9:31:57 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 2/11/2011 10:39:56 PM, error: System Error [1003] - Error code 10000050, parameter1 ff732018, parameter2 00000000, parameter3 9d163ea8, parameter4 00000000. ==== End Of File ===========================
Hello honyock

I'll run the GMER scan again - it takes quite awhile

Long scan times are normal for GMER. If it is causing problems (not unheard of) lets try running it this way instead:


  • GMER


    • If you are having trouble getting GMER to complete a scan, please run it again, but this time uncheck everything EXCEPT "Sections" and "C:\".
    • If GMER does not produce a log please try running it from Safe Mode.

    • How to use the F8 method to Start Your Computer in Safe Mode

    • Restart your computer.
    • As soon as BIOS is loaded begin tapping the F8 key until the "Advanced Options" menu appears.
    • Use the arrow keys to select the Safe mode menu item.
    • Press Enter.

    • If GMER in safe mode does not work, please try Rootkit Unhooker:

  • Rootkit Unhooker


    • Please Download Rootkit Unhooker and Save it to your desktop.
    • Now double-click on RKUnhookerLE.exe to run it.
    • Click the Report tab, then click Scan.
    • Check (Tick) Drivers, Stealth. Uncheck the rest, then Click OK.
    • Wait till the scanner has finished and then click File, Save Report.
    • Save the report somewhere where you can find it. Click Close.

    Copy the entire contents of the report and paste it in your next reply here.

    Note: You may get the following warning, just click OK and continue.

    "Rootkit Unhooker has detected a parasite inside itself!
    It is recommended to remove parasite, okay?"


    Please provide the GMER/Rootkit Unhooker log in your next reply. If you are still having trouble, come back and let me know.
I got GMER to run. I disabled the computer's wireless connection and disabled the antivirus (AVG) and firewall (Comodo), which I should have done to begin with, and GMER ran fine. Here are the results:

——————————————————————–

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-02-12 19:40:16
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 ST916082 rev.3.CD
Running: kvjnsjeq.exe; Driver: C:\DOCUME~1\Mia\LOCALS~1\Temp\uxlyypod.sys


—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[180] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[204] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[260] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[272] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[576] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[688] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[696] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe[792] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[904] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[960] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1004] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1040] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1044] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1196] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Defender\MsMpEng.exe[1296] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1336] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1460] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1504] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\STacSV.exe[1624] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1764] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 00395330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00395250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 00391800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 003911D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 00391360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] USER32.dll!EndTask 7E459E75 5 Bytes JMP 00394B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 00394E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] USER32.dll!mouse_event 7E466515 5 Bytes JMP 00391670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] USER32.dll!keybd_event 7E466559 5 Bytes JMP 003914F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 00394F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 00394880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\bcmwltry.exe[1784] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 003949F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1852] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!??2@YAPAXI@Z 77C29CC5 5 Bytes JMP 0A90D480 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!??3@YAXPAX@Z 77C29CDD 5 Bytes JMP 0A90D2D0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!?set_new_handler@@YAP6AXXZP6AXXZ@Z 77C29D9F 5 Bytes JMP 0A90D500 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_aligned_offset_malloc 77C29DAF 5 Bytes JMP 0A90D3E0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_aligned_free 77C29E33 5 Bytes JMP 0A90D2D0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_aligned_malloc 77C29E52 5 Bytes JMP 0A90D3C0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_aligned_offset_realloc 77C29E6E 5 Bytes JMP 0A90D420 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_aligned_realloc 77C29FC6 5 Bytes JMP 0A90D400 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_expand 77C29FE5 5 Bytes JMP 0A90D3A0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_heapadd 77C2BC9F 5 Bytes JMP 0A90D550 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_heapchk 77C2BCB3 5 Bytes JMP 0A90D560 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_heapset + 1 77C2BD83 4 Bytes JMP 0A90D581 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_heapmin 77C2BD8C 5 Bytes JMP 0A90D650 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_heapused 77C2BE3A 5 Bytes JMP 0A90D620 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_heapwalk 77C2BE4D 5 Bytes JMP 0A90D590 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!_msize 77C2BF6C 5 Bytes JMP 0A90D2E0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!calloc 77C2C0C3 5 Bytes JMP 0A90D270 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!free 77C2C21B 5 Bytes JMP 0A90D2D0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!malloc 77C2C407 5 Bytes JMP 0A90D230 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] msvcrt.dll!realloc 77C2C437 5 Bytes JMP 0A90D2B0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1992] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[2064] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2184] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Mia\Desktop\kvjnsjeq.exe[2192] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2212] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Canon\CAL\CALMAIN.exe[2744] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 00365330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00365250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] USER32.dll!EndTask 7E459E75 5 Bytes JMP 00364B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 00364E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] USER32.dll!mouse_event 7E466515 5 Bytes JMP 00361670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] USER32.dll!keybd_event 7E466559 5 Bytes JMP 003614F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 00364F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 00361800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 003611D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 00361360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 00364880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\hkcmd.exe[2900] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 003649F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxpers.exe[2932] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\WLTRAY.exe[2952] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 003A5330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 003A5250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 003A1800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 003A11D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 003A1360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] USER32.dll!EndTask 7E459E75 5 Bytes JMP 003A4B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 003A4E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] USER32.dll!mouse_event 7E466515 5 Bytes JMP 003A1670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] USER32.dll!keybd_event 7E466559 5 Bytes JMP 003A14F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 003A4F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 003A4880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Dell\QuickSet\quickset.exe[2960] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 003A49F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 00365330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00365250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 00361800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 003611D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 00361360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] USER32.dll!EndTask 7E459E75 5 Bytes JMP 00364B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 00364E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] USER32.dll!mouse_event 7E466515 5 Bytes JMP 00361670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] USER32.dll!keybd_event 7E466559 5 Bytes JMP 003614F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 00364F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 00364880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\stsystra.exe[2980] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 003649F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\igfxsrvc.exe[3008] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3200] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3272] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DellTPad\ApMsgFwd.exe[3520] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe[3644] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[3776] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[4012] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] ntdll.dll!NtClose 7C90D586 5 Bytes JMP 10005330 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 10005250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] USER32.dll!EndTask 7E459E75 5 Bytes JMP 10004B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] USER32.dll!GetRawInputBuffer 7E460B9D 5 Bytes JMP 10004E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] USER32.dll!mouse_event 7E466515 5 Bytes JMP 10001670 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] USER32.dll!keybd_event 7E466559 5 Bytes JMP 100014F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] USER32.dll!GetRawInputData 7E46CA84 5 Bytes JMP 10004F70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 10001800 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] GDI32.dll!CreateDCA 77F1B221 5 Bytes JMP 100011D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] GDI32.dll!CreateDCW 77F1BE61 5 Bytes JMP 10001360 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] ole32.dll!CoCreateInstanceEx 774FFA6B 5 Bytes JMP 10004880 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Stickies\stickies.exe[4084] ole32.dll!CoGetClassObject 77515DB2 5 Bytes JMP 100049F0 C:\WINDOWS\system32\guard32.dll

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)

Device \FileSystem\Fastfat \Fat 9C863C8A

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL@
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI@
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS@

—- EOF - GMER 1.0.15 —-
Hello honyock

Thank you for the GMER log :)

We will begin with ComboFix. AVG is known to prevent ComboFix from running properly and must be completely uninstalled before we proceed. Once uninstalled please refrain from surfing the web except to post replies back to this thread.

  • Combofix


  • Download ComboFix from one of the following locations:

    Link 1
    Link 2

  • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • Should there be issues with internet afterward:

    In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.
Okay, AVG uninstalled and Combofix run, and the log file is below. The download of Microsoft Windows Recovery Console failed…not sure why. I do know that since being infected, we haven't been able to connect to and get any updates from Microsoft. Anyway, here is the logfile from Combofix:

———————————————————————————————————

ComboFix 11-02-12.01 - Mia 02/12/2011 23:37:19.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1014.434 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: COMODO Firewall Pro *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Mia\Application Data\PriceGong
c:\documents and settings\Mia\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\z.xml
c:\documents and settings\Mia\Local Settings\Temporary Internet Files\18J3mJ0ax.jpg
c:\documents and settings\Mia\Local Settings\Temporary Internet Files\68P77.jpg
c:\documents and settings\Mia\Local Settings\Temporary Internet Files\7ybJb.jpg
c:\documents and settings\Mia\Local Settings\Temporary Internet Files\a2OXM.jpg
c:\documents and settings\Mia\Start Menu\Spyware Protection .lnk
c:\program files\Common Files\Uninstall
c:\program files\Search Toolbar
c:\program files\Search Toolbar\icon.ico
c:\program files\Search Toolbar\SearchToolbar.dll
c:\program files\Search Toolbar\SearchToolbarUninstall.exe
c:\program files\Search Toolbar\SearchToolbarUpdater.exe
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\run.log
c:\windows\system32\dffamsbi.ini
c:\windows\system32\Fffiknpo.ini
c:\windows\system32\Fffiknpo.ini2
c:\windows\system32\ndisapi.dll

.
((((((((((((((((((((((((( Files Created from 2011-01-13 to 2011-02-13 )))))))))))))))))))))))))))))))
.

2011-02-12 05:00 . 2011-02-12 05:00 388096 —-a-r- c:\documents and settings\Mia\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-12 05:00 . 2011-02-12 05:00 ——– d—–w- c:\program files\Trend Micro
2011-02-12 03:32 . 2011-02-12 03:32 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2011-02-06 19:00 . 2011-02-06 19:00 ——– d—–w- c:\program files\EZBackitup
2011-02-06 18:45 . 2009-02-13 19:02 11520 —-a-w- c:\windows\system32\drivers\wdcsam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-21 00:09 . 2009-09-05 07:26 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-21 00:08 . 2009-09-05 07:26 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}]
2010-03-28 19:47 353656 —-a-w- c:\program files\PriceGong\2.1.0\PriceGongIE.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-09-24 159744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-24 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-24 137752]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-05-09 1392640]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-09-07 1236992]
"SigmatelSysTrayApp"="stsystra.exe" [2007-09-16 405504]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2007-12-25 1481472]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-12 623992]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-07-13 47904]
"Adobe Version Cue CS2"="c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-05 856064]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-27 434528]

c:\documents and settings\Mia\Start Menu\Programs\Startup\
Stickies.lnk - c:\program files\Stickies\stickies.exe [2008-1-16 757760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-13 50688]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [12/25/2007 1:02 PM 81272]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [12/25/2007 1:02 PM 23672]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [3/23/2009 1:07 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [3/23/2009 1:07 PM 72944]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S1 1c909efd;1c909efd;c:\windows\system32\drivers\1c909efd.sys [6/15/2009 10:48 PM 0]
S2 gupdate1ca1ec52259e42c;Google Update Service (gupdate1ca1ec52259e42c);c:\program files\Google\Update\GoogleUpdate.exe [8/16/2009 4:58 PM 133104]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [3/23/2009 1:07 PM 7408]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2/6/2011 12:45 PM 11520]

— Other Services/Drivers In Memory —

*Deregistered* - NDISRD
.
Contents of the 'Scheduled Tasks' folder

2011-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-16 22:58]

2011-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-16 22:58]

2011-02-13 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.blackle.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Mia\Application Data\Mozilla\Firefox\Profiles\1cmrp260.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: The Browser Highlighter: [removed] - c:\program files\Mozilla Firefox\extensions\[removed]
FF - Ext: Skype extension for Firefox: {B13721C7-F507-4982-B2E5-502A71474FED} - c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: ImTranslator: {9AA46F4F-4DC7-4c06-97AF-5035170634FE} - %profile%\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
FF - Ext: Go Green: [removed] - %profile%\extensions\[removed]
FF - Ext: Screengrab: {02450954-cdd9-410f-b1da-db804e18c671} - %profile%\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
FF - Ext: Locator: {05f6a7ea-896b-11da-8bde-f66bad1e3fff} - %profile%\extensions\{05f6a7ea-896b-11da-8bde-f66bad1e3fff}
FF - Ext: Personas: [removed] - %profile%\extensions\[removed]
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Search Toolbar: [removed] - %profile%\extensions\[removed]
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: PriceGong: {8A9386B4-E958-4c4c-ADF4-8F26DB3E4829} - c:\program files\PriceGong\2.1.0\FF
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -

BHO-{6FB726BF-B07D-46C2-BE7C-47768FB12226} - (no file)
HKCU-Run-Spyware Protection - c:\documents and settings\Mia\Application Data\defender.exe
HKLM-Run-dscactivate - %ProgramFiles%\Dell Support Center\gs_agent\custom\dsca.exe
Notify-urqRHxyV - urqRHxyV.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-12 23:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
@=""
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(944)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'explorer.exe'(1808)
c:\program files\Common Files\Microsoft Shared\OFFICE12\MSOXEV.DLL
.
———————— Other Running Processes ————————
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\COMODO\Firewall\cmdagent.exe
c:\program files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\system32\STacSV.exe
c:\windows\system32\wdfmgr.exe
c:\windows\wanmpsvc.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\stsystra.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\HidFind.exe
c:\program files\DellTPad\Apntex.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
.
**************************************************************************
.
Completion time: 2011-02-12 23:56:16 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-13 05:56

Pre-Run: 39,561,842,688 bytes free
Post-Run: 45,133,733,888 bytes free

- - End Of File - - E9CF01A809A200F730EB77C306668786
Hello honyock

Thank you for the log. We still have more work to do, but before we continue I would like to address the following issue:

The download of Microsoft Windows Recovery Console failed

It is always better to have the RC installed, you never know when you might need it. Lets try to get it installed this way:


  • Please download and Install the Windows Recovery Console


  • With malware infections being as they are today, it's strongly recommended to have the Windows Recovery Console pre-installed on your machine before removing any malware.
  • The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.
  • Download the tools needed to a flash drive or other removable media, and transfer them to the infected computer.
  • Go to Microsoft's website => http://support.microsoft.com/kb/310994
  • Select the download that's appropriate for your Operating System.

    [external image: Posted Image]
  • Download the file and save it as it's originally named.
  • Transfer all of the downloaded files to the desktop of the infected computer.
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
  • Refering to the image below, drag the setup package onto the ComboFix.exe icon and drop it.


    [external image: Posted Image]
  • Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.


    [external image: Posted Image]
  • At the next prompt, click 'Yes' to run the full ComboFix scan.
  • When the tool is finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt in your next reply.
Okay, that worked. Windows Recovery Console was successfully installed. Here is the latest ComboFix log:

————————————————————————————————-

ComboFix 11-02-12.01 - Mia 02/13/2011 9:34.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1014.564 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Mia\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
FW: COMODO Firewall Pro *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Mia\Application Data\PriceGong
c:\documents and settings\Mia\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\z.xml

.
((((((((((((((((((((((((( Files Created from 2011-01-13 to 2011-02-13 )))))))))))))))))))))))))))))))
.

2011-02-12 05:00 . 2011-02-12 05:00 388096 —-a-r- c:\documents and settings\Mia\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-12 05:00 . 2011-02-12 05:00 ——– d—–w- c:\program files\Trend Micro
2011-02-12 03:32 . 2011-02-12 03:32 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2011-02-06 19:00 . 2011-02-06 19:00 ——– d—–w- c:\program files\EZBackitup
2011-02-06 18:45 . 2009-02-13 19:02 11520 —-a-w- c:\windows\system32\drivers\wdcsam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-21 00:09 . 2009-09-05 07:26 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-21 00:08 . 2009-09-05 07:26 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}]
2010-03-28 19:47 353656 —-a-w- c:\program files\PriceGong\2.1.0\PriceGongIE.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-09-24 159744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-24 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-24 137752]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-05-09 1392640]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-09-07 1236992]
"SigmatelSysTrayApp"="stsystra.exe" [2007-09-16 405504]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2007-12-25 1481472]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-12 623992]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-07-13 47904]
"Adobe Version Cue CS2"="c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-05 856064]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-27 434528]

c:\documents and settings\Mia\Start Menu\Programs\Startup\
Stickies.lnk - c:\program files\Stickies\stickies.exe [2008-1-16 757760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-13 50688]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [12/25/2007 1:02 PM 81272]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [12/25/2007 1:02 PM 23672]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [3/23/2009 1:07 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [3/23/2009 1:07 PM 72944]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S1 1c909efd;1c909efd;c:\windows\system32\drivers\1c909efd.sys [6/15/2009 10:48 PM 0]
S2 gupdate1ca1ec52259e42c;Google Update Service (gupdate1ca1ec52259e42c);c:\program files\Google\Update\GoogleUpdate.exe [8/16/2009 4:58 PM 133104]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [3/23/2009 1:07 PM 7408]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2/6/2011 12:45 PM 11520]

— Other Services/Drivers In Memory —

*Deregistered* - NDISRD
.
Contents of the 'Scheduled Tasks' folder

2011-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-16 22:58]

2011-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-16 22:58]

2011-02-13 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.blackle.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Mia\Application Data\Mozilla\Firefox\Profiles\1cmrp260.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: The Browser Highlighter: [removed] - c:\program files\Mozilla Firefox\extensions\[removed]
FF - Ext: Skype extension for Firefox: {B13721C7-F507-4982-B2E5-502A71474FED} - c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: ImTranslator: {9AA46F4F-4DC7-4c06-97AF-5035170634FE} - %profile%\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
FF - Ext: Go Green: [removed] - %profile%\extensions\[removed]
FF - Ext: Screengrab: {02450954-cdd9-410f-b1da-db804e18c671} - %profile%\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
FF - Ext: Locator: {05f6a7ea-896b-11da-8bde-f66bad1e3fff} - %profile%\extensions\{05f6a7ea-896b-11da-8bde-f66bad1e3fff}
FF - Ext: Personas: [removed] - %profile%\extensions\[removed]
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Search Toolbar: [removed] - %profile%\extensions\[removed]
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: PriceGong: {8A9386B4-E958-4c4c-ADF4-8F26DB3E4829} - c:\program files\PriceGong\2.1.0\FF
FF - user.js: yahoo.homepage.dontask - true
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-13 09:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
@=""
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(948)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\System32\BCMLogon.dll
.
Completion time: 2011-02-13 09:42:30
ComboFix-quarantined-files.txt 2011-02-13 15:42
ComboFix2.txt 2011-02-13 05:56

Pre-Run: 45,163,307,008 bytes free
Post-Run: 45,153,943,552 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 7E4AD82F70BEE66F451422FAF0224D35
Hello honyock

Thank you for the log and good job with the RC :thumbup:

  • Please work through the following steps


    • Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
    • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
    • Copy and Paste the text in the quotebox below into the open Notepad window:

      File::
      c:\program files\PriceGong\2.1.0\PriceGongIE.dll
      c:\windows\system32\drivers\1c909efd.sys

      Folder::
      c:\program files\PriceGong

      Registry::
      [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}]

      Driver::
      1c909efd

      DDS::
      FF - Ext: PriceGong: {8A9386B4-E958-4c4c-ADF4-8F26DB3E4829} - c:\program files\PriceGong\2.1.0\FF
      FF - Ext: Search Toolbar: [removed] - %profile%\extensions\[removed]

      RegLock::
      [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
      [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
      [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]

    • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
    • Close any open browsers.
    • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Refering to the picture below, drag CFScript.txt into ComboFix.exe

      [external image: Posted Image]
    • When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

  • Clean out your temporary files


    • Please download ATF Cleaner by Atribune by clicking here and save the file (called ATF-Cleaner.exe) to your desktop.
    • Run the program by double clicking the ATF-Cleaner.exe icon located on your desktop.
    • Check the boxes to the left of the following:

    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Java Cache

    • The rest are optional. If you want to remove everything check the "Select All" box.
    • Click on "Empty Selected" to begin cleaning.
    • Once the "Done Cleaning" message appears, click OK.
    • If you use Firefox, Click on the Firefox tab and repeat the above process.
    • When you have finished cleaning, click on the "Exit" button in the main menu.

  • MalwareBytes AntiMalware:


    • I can see that you have MBAM installed.
    • Double click on your MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

    Please post the ComboFix log and ther MBAM log in your next reply.
I ran Combofix with the script you provided, and also ran MBAM (which found none of the bad guys, which sounds good to me, since MBAM was what found the infection in the first place). Both log files are below. One thing to note is that Combofix didn't seem to locate the recent install of Windows Recovery Console, and asked me to try to download it. I wasn't sure what to do, so let it try (it failed again), then it went ahead and completed its scan anyway. I'm pretty positive that RC is actually on her computer, because it appeared for a couple of seconds as I was booting the computer, like it said it would. So not sure what is up with that. Anyway, here are the logs, starting with Combofix:

—————————————————————————————-

ComboFix 11-02-12.01 - Mia 02/13/2011 18:51:45.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1014.564 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Mia\Desktop\CFScript.txt
FW: COMODO Firewall Pro *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

FILE ::
"c:\program files\PriceGong\2.1.0\PriceGongIE.dll"
"c:\windows\system32\drivers\1c909efd.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Mia\Application Data\PriceGong
c:\documents and settings\Mia\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Mia\Application Data\PriceGong\Data\z.xml
c:\program files\PriceGong
c:\program files\PriceGong\2.1.0\FF\chrome.manifest
c:\program files\PriceGong\2.1.0\FF\components\PriceGong.xpt
c:\program files\PriceGong\2.1.0\FF\components\PriceGongFF.dll
c:\program files\PriceGong\2.1.0\FF\content\options.js
c:\program files\PriceGong\2.1.0\FF\content\options.xul
c:\program files\PriceGong\2.1.0\FF\content\PriceGong.png
c:\program files\PriceGong\2.1.0\FF\install.rdf
c:\program files\PriceGong\2.1.0\PriceGongIE.dll
c:\program files\PriceGong\uninst.exe
c:\windows\system32\drivers\1c909efd.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_1c909efd


((((((((((((((((((((((((( Files Created from 2011-01-14 to 2011-02-14 )))))))))))))))))))))))))))))))
.

2011-02-12 05:00 . 2011-02-12 05:00 388096 —-a-r- c:\documents and settings\Mia\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-12 05:00 . 2011-02-12 05:00 ——– d—–w- c:\program files\Trend Micro
2011-02-12 03:32 . 2011-02-12 03:32 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2011-02-06 19:00 . 2011-02-06 19:00 ——– d—–w- c:\program files\EZBackitup
2011-02-06 18:45 . 2009-02-13 19:02 11520 —-a-w- c:\windows\system32\drivers\wdcsam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-21 00:09 . 2009-09-05 07:26 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-21 00:08 . 2009-09-05 07:26 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-09-24 159744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-24 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-24 137752]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-05-09 1392640]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-09-07 1236992]
"SigmatelSysTrayApp"="stsystra.exe" [2007-09-16 405504]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2007-12-25 1481472]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-12 623992]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-07-13 47904]
"Adobe Version Cue CS2"="c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-05 856064]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-27 434528]

c:\documents and settings\Mia\Start Menu\Programs\Startup\
Stickies.lnk - c:\program files\Stickies\stickies.exe [2008-1-16 757760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-13 50688]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [12/25/2007 1:02 PM 81272]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [12/25/2007 1:02 PM 23672]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [3/23/2009 1:07 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [3/23/2009 1:07 PM 72944]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S2 gupdate1ca1ec52259e42c;Google Update Service (gupdate1ca1ec52259e42c);c:\program files\Google\Update\GoogleUpdate.exe [8/16/2009 4:58 PM 133104]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [3/23/2009 1:07 PM 7408]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2/6/2011 12:45 PM 11520]

— Other Services/Drivers In Memory —

*Deregistered* - NDISRD
.
Contents of the 'Scheduled Tasks' folder

2011-02-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-16 22:58]

2011-02-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-16 22:58]

2011-02-14 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.blackle.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Mia\Application Data\Mozilla\Firefox\Profiles\1cmrp260.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: The Browser Highlighter: [removed] - c:\program files\Mozilla Firefox\extensions\[removed]
FF - Ext: Skype extension for Firefox: {B13721C7-F507-4982-B2E5-502A71474FED} - c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: ImTranslator: {9AA46F4F-4DC7-4c06-97AF-5035170634FE} - %profile%\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
FF - Ext: Go Green: [removed] - %profile%\extensions\[removed]
FF - Ext: Screengrab: {02450954-cdd9-410f-b1da-db804e18c671} - %profile%\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
FF - Ext: Locator: {05f6a7ea-896b-11da-8bde-f66bad1e3fff} - %profile%\extensions\{05f6a7ea-896b-11da-8bde-f66bad1e3fff}
FF - Ext: Personas: [removed] - %profile%\extensions\[removed]
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Search Toolbar: [removed] - %profile%\extensions\[removed]
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -

AddRemove-PriceGong - c:\program files\PriceGong\uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-13 19:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(764)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'explorer.exe'(3376)
c:\program files\Common Files\Microsoft Shared\OFFICE12\MSOXEV.DLL
.
———————— Other Running Processes ————————
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\COMODO\Firewall\cmdagent.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\system32\STacSV.exe
c:\windows\system32\wdfmgr.exe
c:\windows\wanmpsvc.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\windows\stsystra.exe
c:\program files\DellTPad\HidFind.exe
c:\program files\DellTPad\Apntex.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
.
**************************************************************************
.
Completion time: 2011-02-13 19:06:23 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-14 01:06
ComboFix2.txt 2011-02-13 15:42
ComboFix3.txt 2011-02-13 05:56

Pre-Run: 45,150,953,472 bytes free
Post-Run: 45,112,692,736 bytes free

- - End Of File - - 58A79E0C76240AF69CA84FAE0BD15921



———————————————————————————-

Now the MBAM log file:


Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5756

Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13

2/13/2011 7:48:08 PM
mbam-log-2011-02-13 (19-48-08).txt

Scan type: Quick scan
Objects scanned: 161730
Time elapsed: 3 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hello honyock

Thank you for the logs.

Not to worry about the RC :) As the machine does not have a resident AV or Service Pack 3 installed at this time please stay off the net except to download tools and post logs back here.

Lets get your Java updated and run an Online Scan:

  • Please un-install J2SE Runtime Environment 5.0 Update 6


    • Click on "Start" then on "Control Panel" and then on "Add or remove programs".
    • Click on "remove a program". A list of currently installed programs will be displayed.
    • Find the "J2SE Runtime Environment 5.0 Update 6" program, click on it once and then click on the "uninstall" button.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.
    • NOTE: Do not uninstall Java™ 6 Update 16.

  • Please update your Java


    • To update your Java, Click on "Start" then on "Control Panel" and then on the Java icon (looks like a coffee cup).
    • In the window that opens, click on the "Update" tab, and then on "Update Now".
    • Your Java should begin to update. Please follow any prompts that you receive.

  • Please run the following scan


    • Note: You will need to use Internet Explorer for this scan.
    • Note for Vista/Windows 7 Users: ESET is compatible but Internet Explorer must be run as Administrator. To do this, right-click on your Internet Explorer icon and select "Run as Administrator".
    • Please disable your real time security programs before performing the scan.


    • Scan your system with Eset Online Scanner
    • Place a check mark in the box YES, I accept the Terms Of Use.
    • Click the [external image: Posted Image] button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps).
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.


    • Check [external image: Posted Image]
    • Click the [external image: Posted Image] button.
    • Accept any security warnings from your browser.
    • Check [external image: Posted Image]
    • Make sure that the option to "Remove Found Threats" is UN checked.
    • Push the "Start" button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push [external image: Posted Image]
    • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Push the [external image: Posted Image] button.
    • Push [external image: Posted Image]

    Please post the ESET log along with a new DDS log in your next reply and let me know how the machine is running now.
Good morning. I was unsuccessful at getting Java updated. I kept getting the following message: "Java Update cannot proceed with the current Internet connection settings of your system. In your Windows Control Panel, please check Internet Options –> Connections to make sure the settings and proxy information are correct." I looked in the indicated site in Internet Options and couldn't see anything wrong, although I wasn't exactly sure what I should be looking for. So that isn't updated at this moment. Here is the logfile of the Eset scan (it found 17infections), and the dds file and dds attach.txt file: ————————————————————— C:\Documents and Settings\Mia\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{1AECECF0-FF44-46A4-B486-21AA3C9759C5} Win32/Qhost trojan C:\Documents and Settings\Mia\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{4DE69E2E-41C2-4F1D-B6D8-DAB01DD45A2E} Win32/Qhost trojan C:\Documents and Settings\Mia\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{6238FF8C-C2CB-4261-82F3-5ED492BD82B5} Win32/Qhost trojan C:\Documents and Settings\Mia\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{74266101-C8BC-43F3-A738-EA0D584FCC85} Win32/Qhost trojan C:\Documents and Settings\Mia\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{8DBDFC06-700D-41FC-BE73-893ADDFF3827} Win32/Qhost trojan C:\Documents and Settings\Mia\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{A18228A8-A742-4669-B016-C8CE1858AD08} Win32/Qhost trojan C:\Documents and Settings\Mia\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{A363F699-B5EF-4159-8A50-41026C804924} Win32/Qhost trojan C:\Documents and Settings\Mia\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{BA867007-0D41-4AD3-889D-85AC937832B4} Win32/Qhost trojan C:\Documents and Settings\Mia\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{BD95B40B-72AA-4D5E-BB41-100230FD0172} Win32/Qhost trojan C:\Documents and Settings\Mia\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{C70C3244-25AA-4265-BCDE-6E8973E51B1B} Win32/Qhost trojan C:\Documents and Settings\Mia\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{E99FA9DE-17ED-45D6-8975-F323D57D151E} Win32/Qhost trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\dffamsbi.ini.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\Fffiknpo.ini.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\Fffiknpo.ini2.vir Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP650\A0449525.exe Win32/Adware.SafetyAntiSpyware.A application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP652\A0453018.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP652\A0453019.ini Win32/Adware.Virtumonde.NEO application ———————————————————————— the dds log: DDS (Ver_10-12-12.02) - NTFSx86 Run by [removed] at 10:14:26.96 on Mon 02/14/2011 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_16 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1014.397 [GMT -6:00] FW: COMODO Firewall Pro *Enabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\COMODO\Firewall\cmdagent.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\STacSV.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\wanmpsvc.exe C:\Program Files\DellTPad\Apoint.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\WINDOWS\stsystra.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Stickies\stickies.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Mia\Desktop\fix files and logs\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.blackle.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" mRun: [Apoint] c:\program files\delltpad\Apoint.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [COMODO Firewall Pro] "c:\program files\comodo\firewall\cfp.exe" -s mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [Adobe Version Cue CS2] c:\program files\adobe\adobe version cue cs2\controlpanel\VersionCueCS2Tray.exe mRun: [SunJavaUpdateSched] c:\program files\java\jre6\bin\jusched.exe dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\mia\startm~1\programs\startup\stickies.lnk - c:\program files\stickies\stickies.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1283803385781 DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} - hxxp://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://games.myspace.com/gameshell/games/channel–110343720/lc–en/room–e8d118e7-9f2a-41f6-a3f5-8da718848895/online/peggle/en/popcaploader_v10_en.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: igfxcui - igfxdev.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\mia\applic~1\mozilla\firefox\profiles\1cmrp260.default\ FF - component: c:\program files\mozilla firefox\extensions\[removed]\components\Shim.dll FF - plugin: c:\documents and settings\mia\application data\facebook\npfbplugin_1_0_3.dll FF - plugin: c:\documents and settings\mia\local settings\application data\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: The Browser Highlighter: [removed] - c:\program files\mozilla firefox\extensions\[removed] FF - Ext: Skype extension for Firefox: {B13721C7-F507-4982-B2E5-502A71474FED} - c:\program files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} FF - Ext: ImTranslator: {9AA46F4F-4DC7-4c06-97AF-5035170634FE} - %profile%\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE} FF - Ext: Go Green: [removed] - %profile%\extensions\[removed] FF - Ext: Screengrab: {02450954-cdd9-410f-b1da-db804e18c671} - %profile%\extensions\{02450954-cdd9-410f-b1da-db804e18c671} FF - Ext: Locator: {05f6a7ea-896b-11da-8bde-f66bad1e3fff} - %profile%\extensions\{05f6a7ea-896b-11da-8bde-f66bad1e3fff} FF - Ext: Personas: [removed] - %profile%\extensions\[removed] FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} FF - Ext: Search Toolbar: [removed] - %profile%\extensions\[removed] FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2007-12-25 81272] R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2007-12-25 23672] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-3-23 9968] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-3-23 72944] R2 cmdAgent;COMODO Firewall Pro Helper Service;c:\program files\comodo\firewall\cmdagent.exe [2007-12-25 495360] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] S2 gupdate1ca1ec52259e42c;Google Update Service (gupdate1ca1ec52259e42c);c:\program files\google\update\GoogleUpdate.exe [2009-8-16 133104] S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-3-23 7408] S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2011-2-6 11520] =============== Created Last 30 ================ 2011-02-14 14:06:02 ——– d—–w- c:\program files\ESET 2011-02-14 08:00:55 2321288 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\windows defender\definition updates\backup\mpengine.dll 2011-02-14 08:00:52 5890896 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\windows defender\definition updates\{e08785a4-bc47-4aa2-97b4-88a161cc4146}\mpengine.dll 2011-02-14 08:00:51 222080 ——w- c:\windows\system32\MpSigStub.exe 2011-02-13 15:29:09 ——– d-sha-r- C:\cmdcons 2011-02-13 05:31:30 98816 —-a-w- c:\windows\sed.exe 2011-02-13 05:31:30 89088 —-a-w- c:\windows\MBR.exe 2011-02-13 05:31:30 256512 —-a-w- c:\windows\PEV.exe 2011-02-13 05:31:30 161792 —-a-w- c:\windows\SWREG.exe 2011-02-12 05:00:06 388096 —-a-r- c:\docume~1\mia\applic~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2011-02-12 05:00:05 ——– d—–w- c:\program files\Trend Micro 2011-02-06 19:00:43 ——– d—–w- c:\program files\EZBackitup 2011-02-06 18:45:39 11520 —-a-w- c:\windows\system32\drivers\wdcsam.sys ==================== Find3M ==================== ============= FINISH: 10:15:10.17 =============== ———————————————————– the dds attach.txt log (not sure if you needed this but here it is anyway): UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-12-12.02) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 12/24/2007 11:09:56 AM System Uptime: 2/14/2011 10:03:56 AM (0 hours ago) Motherboard: Dell Inc. | | 0TT347 Processor: Intel® Core™2 Duo CPU T5270 @ 1.40GHz | Microprocessor | 1396/200mhz Processor: Intel® Core™2 Duo CPU T5270 @ 1.40GHz | Microprocessor | 1396/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 146 GiB total, 41.914 GiB free. D: is CDROM () F: is Removable ==== Disabled Device Manager Items ============= Class GUID: {6BDD1FC6-810F-11D0-BEC7-08002BE2092F} Description: Canon MX700 ser Network Device ID: ROOT\CANON_IJ_NETWORK\0000 Manufacturer: Canon Name: Canon MX700 ser Network PNP Device ID: ROOT\CANON_IJ_NETWORK\0000 Service: StillCam ==== System Restore Points =================== RP617: 1/1/2011 7:10:07 PM - System Checkpoint RP618: 1/2/2011 8:54:04 PM - System Checkpoint RP619: 1/3/2011 11:47:50 PM - System Checkpoint RP620: 1/5/2011 12:07:41 AM - System Checkpoint RP621: 1/6/2011 12:10:38 AM - System Checkpoint RP622: 1/7/2011 5:55:09 PM - System Checkpoint RP623: 1/8/2011 6:20:24 PM - System Checkpoint RP624: 1/9/2011 7:06:16 PM - System Checkpoint RP625: 1/10/2011 10:51:53 PM - System Checkpoint RP626: 1/12/2011 7:38:31 AM - System Checkpoint RP627: 1/13/2011 5:47:57 PM - System Checkpoint RP628: 1/14/2011 6:25:54 PM - System Checkpoint RP629: 1/15/2011 6:46:52 PM - System Checkpoint RP630: 1/16/2011 7:27:09 PM - System Checkpoint RP631: 1/17/2011 8:04:47 PM - System Checkpoint RP632: 1/18/2011 9:32:06 PM - System Checkpoint RP633: 1/19/2011 10:02:21 PM - System Checkpoint RP634: 1/20/2011 10:08:01 PM - System Checkpoint RP635: 1/21/2011 10:50:13 PM - System Checkpoint RP636: 1/22/2011 11:20:46 PM - System Checkpoint RP637: 1/24/2011 6:40:33 PM - System Checkpoint RP638: 1/25/2011 8:33:52 PM - System Checkpoint RP639: 1/26/2011 9:54:47 PM - System Checkpoint RP640: 1/27/2011 10:32:23 PM - System Checkpoint RP641: 1/30/2011 6:49:45 PM - System Checkpoint RP642: 1/31/2011 10:56:13 PM - System Checkpoint RP643: 2/1/2011 11:08:34 PM - System Checkpoint RP644: 2/3/2011 5:33:27 PM - System Checkpoint RP645: 2/4/2011 6:22:37 PM - System Checkpoint RP646: 2/5/2011 7:10:46 PM - System Checkpoint RP647: 2/6/2011 7:45:23 PM - System Checkpoint RP648: 2/7/2011 8:24:54 PM - System Checkpoint RP649: 2/8/2011 11:18:17 PM - System Checkpoint RP650: 2/9/2011 11:35:04 PM - System Checkpoint RP651: 2/11/2011 11:00:04 PM - Installed HiJackThis RP652: 2/12/2011 11:15:19 PM - Removed AVG Free 8.5 RP653: 2/13/2011 11:16:16 PM - System Checkpoint RP654: 2/14/2011 2:00:47 AM - Software Distribution Service 3.0 RP655: 2/14/2011 7:49:26 AM - Removed J2SE Runtime Environment 5.0 Update 6 ==== Installed Programs ====================== AbiWord 2.6.8 AbiWord Importer/Exporter Plugins Adobe Acrobat 8 Professional Adobe Acrobat 8.1.2 Professional Adobe Acrobat 8.1.2 Security Update 1 (KB403742) Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) Adobe Bridge 1.0 Adobe Common File Installer Adobe Creative Suite 2 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe GoLive CS2 Adobe Help Center 1.0 Adobe Illustrator CS2 Adobe InDesign CS2 Adobe Photoshop CS2 Adobe Reader 8.1.2 Adobe Reader 8.1.2 Security Update 1 (KB403742) Adobe Stock Photos 1.0 Adobe SVG Viewer 3.0 Adobe Version Cue CS2 Advanced Audio FX Engine Advanced Video FX Engine America Online AOL Coach Version 1.0(Build:20020823.1) Apple Application Support Apple Mobile Device Support Apple Software Update Bonjour Broadcom Management Programs Browser Address Error Redirector Canon Camera Access Library Canon Camera Support Core Library Canon IJ Network Scan Utility Canon IJ Network Tool Canon MP Navigator EX 1.0 Canon MX700 series Canon MX700 series User Registration Canon My Printer Canon RAW Image Task for ZoomBrowser EX Canon S600 Canon SELPHY CP770 Canon Utilities CameraWindow Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX Canon Utilities Easy-PhotoPrint EX Canon Utilities EOS Utility Canon Utilities MyCamera Canon Utilities RemoteCapture Task for ZoomBrowser EX Canon Utilities Solution Menu Canon Utilities ZoomBrowser EX Canon ZoomBrowser EX Memory Card Utility CCleaner CodeStuff Starter COMODO Firewall Pro Conexant HDA D330 MDC V.92 Modem Dell Support Center Dell Touchpad Dell Webcam Center Dell Webcam Manager Dell Wireless WLAN Card Digital Line Detect ESET Online Scanner v3 EVEREST Home Edition v1.51 EZBack-it-up 2.0.1 Facebook Plug-In FairUse Wizard 2 Google Chrome Google Earth Google Toolbar for Internet Explorer Google Update Helper High Definition Audio Driver Package - KB835221 HiJackThis Hotfix for Microsoft .NET Framework 2.0 (KB922981) Hotfix for Windows XP (KB896256) Hotfix for Windows XP (KB906569) Hotfix for Windows XP (KB908673) Hotfix for Windows XP (KB909095) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB934428-v2) Hotfix for Windows XP (KB935448) Intel® Graphics Media Accelerator Driver IntelliSonic Speech Enhancement iTunes Java™ 6 Update 16 Laptop Integrated Webcam Driver (1.03.02.0719) Live! Cam Avatar Creator Live! Cam Avatar v1.0 Macromedia Dreamweaver 8 Macromedia Extension Manager Malwarebytes' Anti-Malware MediaDirect Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft National Language Support Downlevel APIs Microsoft Office 2003 Web Components Microsoft Office 2007 Primary Interop Assemblies Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Professional 2007 Microsoft Office Professional 2007 Trial Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Small Business Connectivity Components Microsoft Office Word MUI (English) 2007 Microsoft Software Update for Web Folders (English) 12 Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Works MobileMe Control Panel Modem Diagnostic Tool Move Networks Media Player for Internet Explorer Mozilla Firefox (3.6.13) MSN MSXML 4.0 SP2 (KB936181) MSXML 6.0 Parser (KB933579) NetWaiting OutlookAddinSetup Peggle Deluxe Photo Express LE Presto! PageManager 7.15.16 QualxServ Service Agreement QuickSet QuickTime RealPlayer Basic Roxio Creator Audio Roxio Creator Copy Roxio Creator Data Roxio Creator Premier Roxio Creator Tools Roxio Drag-to-Disc Roxio EasyArchive Roxio Express Labeler Roxio MyDVD Premier Roxio Update Manager Safari ScanSoft OmniPage SE 4 SearchAssist Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB944653) Skype web features Skype™ 4.1 Sonic Activation Module Startup Manager 2.4.2 Stickies 6.5a Suite Specific SUPERAntiSpyware Free Edition TELL ME MORE The Game of Life - SpongeBob SquarePants Edition The Sims 2 The Sims™ 2 Bon Voyage The Sims™ 2 FreeTime Unity Web Player Update for Microsoft Office Word 2007 (KB974631) Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB912945) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Viewpoint Media Player (Remove Only) VLC media player 0.9.9 WebFldrs XP Windows Defender Windows Genuine Advantage Validation Tool (KB892130) Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format Runtime Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885855 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB889673 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 WinZip YASA MP4 Video Converter v3.2 (build 0051) ==== Event Viewer Messages From Past Week ======== 2/14/2011 7:49:41 AM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found. 2/12/2011 4:01:06 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 2/12/2011 3:43:51 PM, error: Service Control Manager [7000] - The Background Intelligent Transfer Service service failed to start due to the following error: The system cannot find the file specified. 2/12/2011 3:43:51 PM, error: DCOM [10005] - DCOM got error "%2" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097} 2/12/2011 3:43:29 PM, error: System Error [1003] - Error code 10000050, parameter1 ff778000, parameter2 00000000, parameter3 9ccd2ffb, parameter4 00000000. 2/12/2011 12:18:44 PM, error: System Error [1003] - Error code 10000050, parameter1 f8420038, parameter2 00000000, parameter3 9cf8beed, parameter4 00000000. 2/12/2011 11:37:12 PM, error: Service Control Manager [7034] - The Dell Wireless WLAN Tray Service service terminated unexpectedly. It has done this 1 time(s). 2/11/2011 9:54:21 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 2/11/2011 9:44:50 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: APPDRV AvgLdx86 AvgMfx86 cmdGuard Fips intelppm ohci1394 SASDIFSV SASKUTIL 2/11/2011 9:33:09 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: APPDRV AvgLdx86 AvgMfx86 cmdGuard Fips intelppm SASDIFSV SASKUTIL 2/11/2011 9:16:38 PM, error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: This operation returned because the timeout period expired. 2/11/2011 10:39:56 PM, error: System Error [1003] - Error code 10000050, parameter1 ff732018, parameter2 00000000, parameter3 9d163ea8, parameter4 00000000. ==== End Of File ===========================
Hello honyock

The items detected by ESET will be taken care of when we remove ComboFix.

I was unsuccessful at getting Java updated.

Lets try to update it manually:

  • Please update your Java

    • Download the latest version of Java by clicking here
    • Scroll down the page until you reach "Java Platform Standard Edition".
    • Beneath this and to the right, you will see a button marked "Download JRE".
    • Click the "Download JRE" button.
    • Select the platform (Windows, in your case), multi language.
    • Accept the license agreement and click on "Continue".
    • You do not have to register if you do not want to (the registration step is optional).
    • Scroll down and click on the file called jre-6u23-windows-i586.exe located under "Windows Offline Installation".
    • Save the file to your desktop.
    • Do not select Run.
    • Double click on the saved file (jre-6u23-windows-i586.exe) to install the update.
    • Delete the downloaded installation file after completing the above procedure and reboot your system if not prompted to do so.

  • Please work through the following steps


    • Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
    • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
    • Copy and Paste the text in the quotebox below into the open Notepad window:

      DDS::
      FF - Ext: Search Toolbar: [removed] - %profile%\extensions\[removed]

      SkipFix::

    • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
    • Close any open browsers.
    • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Refering to the picture below, drag CFScript.txt into ComboFix.exe

      [external image: Posted Image]
    • When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

    Please post the ComboFix log in your next reply and let me know how you get on with Java :)
Hi - we got half the job done…got Java update installed successfully. I had to leave for the week and am now having to talk my daughter through the steps over the phone. I got her through the Java update and that was all she was up for tonight - swamped with homework. :wacko: I'll have her do the Combofix step tomorrow night and send it to you then. It looks like I may only be able to get in touch maybe once a day, given the vagaries of phone instructions and the motivation level of teenage girls. I hope that works okay for you…thanks for your patience as we work through this. In the meantime, just to check…was the script you wanted us to create as "CFScript.txt" just the three lines included in the quote? It looked like such a short script that I wasn't sure if it may have been truncated in the quote. Thanks again for your help so far in this!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI