This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

VBS/Generic Win32 Zbot.g Virus

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

My Laptop has been infected with the VBS/Generic Win32 Zbot.g Virus. It is running windows XP and Firefox 4.

I have run malwarebytes & spybot S+D and healed any infections they found, but it wont allow AVG to run at all?? When i try to do an AVG whole computer scan it starts, then after 1 second it comes back to say "scan completed - no files are infected"

Also tried to start the computer in safe mode, but it crashes and a blue screen appears so i have to restart. Windows seems to run ok if i start in normal mode.

I can still connect to the internet through Firefox (i havent tried connecting through explorer) but as i was scared of what might happen, i have now disabled my internet connection.

Any help and suggestions would be appreciated.
Hello and welcome to What The Tech.

I am currently assessing your situation and will be back with a fix for your problem as soon as possible.

Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this, click Options, then click Track this topic. Please select Immediate Email Notification for the topic subscription, then click Proceed.

Please be patient with me during this time.

Meanwhile, please make a reply to this topic to acknowledge that you have read this and is still with me to tackle the problem until the end. If I do not get any response within 3 days, this topic will be closed.
Hello supersub14 :),

Welcome to What The Tech. I am Jack&Jill, and I will be helping you out.

Before we go further, there are a few things that I would like to make clear so that we are share the same understanding.
  • Please observe and follow these Terms of Use and the rules in Are you Infected? Getting Started: How To Get Help.
  • Any advice is for your computer only and is taken at your own risk. Fixes sometimes will cause unexpected results, but I will do my best to assist you.
  • Please read the instructions carefully and follow them closely, in the order they are presented to you.
  • If you have any doubts or problems during the fix, please stop and ask.
  • All the tools that I will ask you to download and use are safe. Please allow if prompted by any of your security softwares.
  • Do not use or run any malware cleaning tools without supervision as they may cause more harm if improperly used.
  • Refrain from installing any new programs except those that I request during the fix to prevent interference to my diagnosis of the problem.
  • Lack of malware symptoms does not mean your computer is clean. Stick to this topic until I give the All Clear.
  • If you do not reply within 3 days, this topic will be closed.
If you are agreeable to the above, then everything should go smoothly :) . We may begin.

——————–

Please download DDS from one of the links below and save it to your desktop.

Link 1
Link 2
Link 3

Please disable any script blocker before running DDS.

  • Double click on dds file and a command window will appear. This is normal.
  • Shortly after, two logs will appear:
    • DDS.txt
    • Attach.txt
  • A window will open instructing you save and post the logs.
  • Save the logs to a convenient location such as your desktop.
  • Copy the contents of both logs and post them in your next reply.
——————–

Please close all programs and do not run any others before and during the Rootkit Unhooker scan. Do not use the computer for anything else until after the scan is completed.

Please download Rootkit Unhooker and save it to your desktop. Click here.
  • Double click RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Ensure the following are checked (ticked):
    • Drivers
    • Stealth Code
    • Files
    • Code Hooks
  • Uncheck the rest, then click OK. An initial scan will be performed.
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK.
  • Wait until the scanner is done, then click on File at the pull down menu, followed by Save Report.
  • Save the report somewhere you can find it. Click Close to exit.
  • Copy the entire contents of the report and paste it in your next reply.
You may get a warning about parasite detection. Please click OK to continue.

——————–

You have Malwarebytes' Anti-Malware (MBAM) on your machine. I wish to take a look at the most recent log file. Open MBAM and click on the Logs tab. Open the file at the bottom of the list and post the contents back here. If there is no log or you have yet to run MBAM, please let me know.

——————–

We need to diagnose the blue screen (BSOD) your computer is experiencing.

Please provide the error message information as shown in the picture:

[external image: Posted Image]

The stop error will be always be displayed, but the other information may or may not be available. Just provide whatever is available.

——————–

Please post back:
1. the DDS logs (DDS.txt and Attach.txt)
2. Rootkit Unhooker result
3. previous MBAM log
4. BSOD information
As requested:

DDS

.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by [removed] at 18:59:37 on 2011-05-30
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1373 [GMT 1:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Documents and Settings\User\Desktop\dds.pif
C:\WINDOWS\system32\WSCRIPT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = https://signin.ebay.co.uk/ws/eBayISAPI.dll?…p;pageType=1883
uInternet Connection Wizard,ShellNext = hxxp://www.google.ie/ig/dell?hl=en&client;=dell-row&channel;=ie&ibd;=0071120
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\program files\weamsstf\fkrydvdv.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
BHO: isoHunt Toolbar: {a6e4a4eb-d169-4e99-8988-250fcbafe767} - c:\program files\isohunt\tbisoH.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.6209.1142\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: isoHunt Toolbar: {a6e4a4eb-d169-4e99-8988-250fcbafe767} - c:\program files\isohunt\tbisoH.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\shortc~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
IE: Add to AMV Converter… - c:\program files\mp3 player utilities 4.13\amvconverter\grab.html
IE: Add to Media Manager… - c:\program files\mp3 player utilities 4.13\mediamanager\grab.html
IE: Download All Files by HiDownload - c:\program files\streamingstar\hidownload\HDGetAll.htm
IE: Download by HiDownload - c:\program files\streamingstar\hidownload\HDGet.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Send to &Bluetooth; Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
Trusted Zone: o2.co.uk\*.broadband
DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - hxxp://www.ipix.com/viewers/ipixx.cab
DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} - hxxp://www.bebo.com/files/BeboUploader.5.8.05.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1195808952937
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} - hxxps://ebanking.northernbank.co.uk/html/activex/e-Safekey/NB/e-Safekey.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: GoToAssist - c:\program files\citrix\gotoassist\570\G2AWinLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\user\application data\mozilla\firefox\profiles\hykfae61.default\
FF - prefs.js: browser.startup.homepage - hxxps://signin.ebay.co.uk/ws/eBayISAPI.dll?SignIn&UsingSSL;=1&pUserId;=&co;_partnerId=2&siteid;=3&ru;=http%3A%2F%2Fmy.ebay.co.uk%3A80%2Fws%2FeBayISAPI.dll%3FMyeBay%26gbh%3D1%26MyEbay%3D%26_trksid%3Dm37%26guest%3D1&pageType;=1883
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-1-19 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-2-10 297168]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-4-18 7398752]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-3-30 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 27216]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-7-15 136176]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-4-25 947528]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-7-15 136176]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\drivers\s1018bus.sys [2010-3-4 86824]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\drivers\s1018mdfl.sys [2010-3-4 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\drivers\s1018mdm.sys [2010-3-4 114728]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1018mgmt.sys [2010-3-4 106208]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1018nd5.sys [2010-3-4 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\drivers\s1018obex.sys [2010-3-4 104744]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1018unic.sys [2010-3-4 109864]
.
=============== File Associations ===============
.
.scr=AutoCADScriptFile
.
=============== Created Last 30 ================
.
2011-05-26 22:40:25 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-05-26 22:40:25 ——– d—–w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
2011-05-25 23:37:24 ——– d—–w- c:\program files\weamsstf
2011-05-14 08:46:00 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-12 22:05:12 781272 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-05-12 22:05:12 1874904 —-a-w- c:\program files\mozilla firefox\mozjs.dll
2011-05-12 22:05:11 89048 —-a-w- c:\program files\mozilla firefox\libEGL.dll
2011-05-12 22:05:11 465880 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-05-12 22:05:11 1892184 —-a-w- c:\program files\mozilla firefox\d3dx9_42.dll
2011-05-12 22:05:11 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-05-12 22:05:10 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-05-12 22:05:09 1974616 —-a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll
.
==================== Find3M ====================
.
2011-04-14 20:28:42 134480 —-a-w- c:\windows\system32\drivers\AVGIDSDriver.sys
2011-04-04 23:59:56 297168 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2011-03-16 15:03:20 32592 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-03-07 05:33:50 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37:06 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21:11 1857920 —-a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 19:00:54.14 ===============

RootUnhook

RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows XP
Version 5.1.2600 (Service Pack 3)
Number of processors #2
==============================================
>Drivers
==============================================
0xB9398000 C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 6348800 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Miniport Driver, Version 101.28 )
0xBF012000 C:\WINDOWS\System32\nv4_disp.dll 5468160 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Display driver, Version 101.28 )
0xB911E000 C:\WINDOWS\system32\DRIVERS\NETw4x32.sys 2203648 bytes (Intel Corporation, Intel® Wireless WiFi Link Driver)
0x804D7000 C:\WINDOWS\system32\ntkrnlpa.exe 2154496 bytes (Microsoft Corporation, NT Kernel & System)
0x804D7000 PnpManager 2154496 bytes
0x804D7000 RAW 2154496 bytes
0x804D7000 WMIxWDM 2154496 bytes
0xBF800000 Win32k 1859584 bytes
0xBF800000 C:\WINDOWS\System32\win32k.sys 1859584 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0xB7BB2000 C:\WINDOWS\system32\drivers\sthda.sys 1171456 bytes (SigmaTel, Inc., NDRC)
0xB7A4F000 C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys 991232 bytes (Conexant Systems, Inc., HSF_DP driver)
0xB8F84000 C:\WINDOWS\system32\DRIVERS\btkrnl.sys 835584 bytes (Broadcom Corporation., Bluetooth Bus Enumerator)
0xB9E4D000 iaStor.sys 778240 bytes (Intel Corporation, Intel Matrix Storage Manager driver - ia32)
0xB799C000 C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 733184 bytes (Conexant Systems, Inc., HSF_CNXT driver)
0xB9D64000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver)
0xB76AE000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0xB8E06000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver)
0xB7828000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver)
0xB4553000 C:\WINDOWS\system32\DRIVERS\srv.sys 360448 bytes (Microsoft Corporation, Server driver)
0xB90A5000 C:\WINDOWS\system32\DRIVERS\rixdptsk.sys 331776 bytes (REDC, RICOH XD SM Driver)
0xB8DB8000 C:\WINDOWS\system32\drivers\btaudio.sys 319488 bytes (Broadcom Corporation., Bluetooth Audio Device)
0xBF549000 C:\WINDOWS\System32\ATMFD.DLL 290816 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)
0xB77E1000 C:\WINDOWS\system32\DRIVERS\avgtdix.sys 290816 bytes (AVG Technologies CZ, s.r.o., AVG Network connection watcher)
0xB3D22000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack)
0xB764A000 C:\WINDOWS\system32\DRIVERS\avgldx86.sys 245760 bytes (AVG Technologies CZ, s.r.o., AVG AVI Loader Driver)
0xB75F2000 C:\WINDOWS\system32\DRIVERS\OEM02Dev.sys 237568 bytes (Creative Technology Ltd., Video Capture Device Driver)
0xB7B41000 C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys 212992 bytes (Conexant Systems, Inc., HSF_HWAZL WDM driver)
0xB9073000 C:\WINDOWS\system32\DRIVERS\SynTP.sys 204800 bytes (Synaptics, Inc., Synaptics Touchpad Driver)
0xB8E8C000 C:\WINDOWS\system32\DRIVERS\rdpdr.sys 196608 bytes (Microsoft Corporation, Microsoft RDP Device redirector)
0xB9F79000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT)
0xB49C9000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0xB9D37000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver)
0xB390F000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer)
0xB771E000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0xB9338000 C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 163840 bytes (Windows ® Server 2003 DDK provider, High Definition Audio Bus Driver v1.0a)
0xB7793000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver)
0xB9F23000 dmio.sys 155648 bytes (Microsoft Corp., Veritas Software, NT Disk Manager I/O Driver)
0xB77BB000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator)
0xB8D94000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0xB9360000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0xB9050000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library)
0xB7B75000 C:\WINDOWS\system32\Drivers\OEM02Afx.sys 143360 bytes (Creative Technology Ltd., Advanced Audio FX Driver)
0xB7771000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0x806E5000 ACPI_HAL 134400 bytes
0x806E5000 C:\WINDOWS\system32\hal.dll 134400 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0xB419B000 C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys 131072 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Driver.)
0xB9E2D000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0xB9F49000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver)
0xB762C000 C:\WINDOWS\system32\DRIVERS\btwdndis.sys 122880 bytes (Broadcom Corporation., Bluetooth LAN Access Server Driver)
0xB7B98000 C:\WINDOWS\system32\drivers\dxec02.sys 106496 bytes (Knowles Acoustics, dxec02.sys)
0xB9D1D000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver)
0xB9F0B000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver)
0xB74C2000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes
0xB9E04000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0xB8F6D000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0xB48F9000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper)
0xB90F6000 C:\WINDOWS\system32\DRIVERS\rimsptsk.sys 81920 bytes (REDC, RICOH MS Driver)
0xB910A000 C:\WINDOWS\system32\DRIVERS\sdbus.sys 81920 bytes (Microsoft Corporation, SecureDigital Bus Driver)
0xB9384000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver)
0xB7881000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver)
0xB9DF1000 WudfPf.sys 77824 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver)
0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver)
0xB9E1B000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver)
0xB9F68000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0xB8F5C000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler)
0xBA298000 C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys 65536 bytes (Broadcom Corporation, Broadcom Corporation NDIS 5.1 ethernet driver)
0xBA208000 C:\WINDOWS\System32\Drivers\btwusb.sys 65536 bytes (Broadcom Corporation., Driver for Bluetooth USB Devices)
0xBA308000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver)
0xBA2D8000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0xBA138000 C:\WINDOWS\system32\DRIVERS\nic1394.sys 65536 bytes (Microsoft Corporation, IEEE1394 Ndis Miniport and Call Manager)
0xBA108000 ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver)
0xBA238000 C:\WINDOWS\system32\DRIVERS\arp1394.sys 61440 bytes (Microsoft Corporation, IP/1394 Arp Client)
0xBA178000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0xBA2E8000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver)
0xB4A86000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter)
0xBA198000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB)
0xBA118000 C:\WINDOWS\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver)
0xBA2A8000 C:\WINDOWS\system32\DRIVERS\rimmptsk.sys 57344 bytes (REDC, RICOH MMC Driver)
0xBA0E8000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll)
0xBA2B8000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver)
0xBA2F8000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0xBA0C8000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0xBA1C8000 C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 49152 bytes (AVG Technologies CZ, s.r.o., AVG Resident Shield Minifilter Driver)
0xBA148000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0xBA1F8000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver)
0xBA2C8000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver)
0xBA0B8000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager)
0xBA318000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0xBA0A8000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver)
0xBA188000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy)
0xBA168000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver)
0xBA0D8000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver)
0xBA218000 C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library)
0xBA288000 C:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver)
0xBA158000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier)
0xBA1D8000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver)
0xB8F0C000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0xBA0F8000 PxHelp20.sys 36864 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)
0xBA228000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0xBA448000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver)
0xBA478000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver)
0xBA480000 C:\WINDOWS\System32\Drivers\SCDEmu.SYS 32768 bytes (PowerISO Computing, Inc., PowerISO Virtual Drive)
0xBA490000 C:\WINDOWS\system32\DRIVERS\usbccgp.sys 32768 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver)
0xBA410000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0xBA338000 avgrkx86.sys 28672 bytes (AVG Technologies CZ, s.r.o., AVG Anti-Rootkit Driver)
0xBA4A0000 C:\WINDOWS\system32\DRIVERS\btport.sys 28672 bytes (Broadcom Corporation., Bluetooth BTPORT Driver for Windows 2000)
0xBA498000 C:\WINDOWS\system32\DRIVERS\btwmodem.sys 28672 bytes (Broadcom Corporation., Bluetooth BTPORT Driver for Windows 2000)
0xBA460000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)
0xBA3C8000 C:\DOCUME~1\User\LOCALS~1\Temp\mbr.sys 28672 bytes
0xBA328000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0xBA400000 C:\WINDOWS\system32\drivers\btserial.sys 24576 bytes (Broadcom Corporation., Bluetooth Serial Driver for Windows 2000)
0xBA420000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver)
0xBA418000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver)
0xBA408000 C:\WINDOWS\system32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0xBA468000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0xBA4A8000 C:\WINDOWS\system32\DRIVERS\AegisP.sys 20480 bytes (Meetinghouse Data Communications, IEEE 802.1X Protocol Driver)
0xBA370000 C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys 20480 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Filter Driver.)
0xBA3D8000 C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys 20480 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Loader Driver.)
0xBA470000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver)
0xBA330000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager)
0xBA430000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library)
0xBA438000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver)
0xBA428000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper)
0xBA378000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver)
0xB775D000 C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS 16384 bytes (Dell Inc, App Support Driver)
0xBA4C4000 AVGIDSEH.Sys 16384 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Helper Driver.)
0xBA4C0000 C:\WINDOWS\system32\DRIVERS\BATTC.SYS 16384 bytes (Microsoft Corporation, Battery Class Driver)
0xB9CF1000 C:\WINDOWS\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)
0xB7CE4000 C:\WINDOWS\system32\DRIVERS\kbdhid.sys 16384 bytes (Microsoft Corporation, HID Mouse Filter Driver)
0xB45DB000 C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 16384 bytes (Conexant, Diagnostic Interface x86 Driver)
0xB99C6000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver)
0xB4D52000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver)
0xB4F56000 C:\WINDOWS\system32\DRIVERS\s24trans.sys 16384 bytes (Intel Corporation, Intel WLAN Packet Driver)
0xBA4B8000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver)
0xBA4BC000 compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver)
0xB7546000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver)
0xB7CEC000 C:\WINDOWS\system32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices)
0xBA588000 C:\WINDOWS\System32\Drivers\i2omgmt.SYS 12288 bytes (Microsoft Corporation, I2O Utility Filter)
0xB7CDC000 C:\WINDOWS\system32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver)
0xB9CE9000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0xBA590000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
0xB9CED000 C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 12288 bytes (Microsoft Corporation, Windows Management Interface for ACPI)
0xBA5F0000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver)
0xBA66E000 C:\WINDOWS\system32\DRIVERS\dsunidrv.sys 8192 bytes (Gteko Ltd., GUniDriver)
0xBA642000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes
0xBA5EE000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver)
0xBA5A8000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
0xBA5F2000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator)
0xBA5F8000 C:\WINDOWS\system32\DRIVERS\OEM02Vfx.sys 8192 bytes (EyePower Games Pte. Ltd., Advanced Video FX Filter
Driver (Win2K based))
0xBA5F4000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport)
0xBA5D4000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0xBA5D0000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
0xBA5AA000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0xBA6E3000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver)
0xBA718000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk)
0xBA7BF000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver)
0xBA670000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver)
==============================================
>Stealth
==============================================
==============================================
>Files
==============================================
==============================================
>Hooks
==============================================
ntkrnlpa.exe+0x0006ECEE, Type: Inline - RelativeJump 0x80545CEE–>80545CF5 [ntkrnlpa.exe]
[1112]DLG.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[1112]DLG.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[1112]DLG.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[1112]DLG.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[1112]DLG.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[1112]DLG.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[1112]DLG.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[1112]DLG.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[1112]DLG.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[1112]DLG.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[1112]DLG.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[1112]DLG.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[1112]DLG.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[1120]csrss.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[1120]csrss.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[1120]csrss.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[1120]csrss.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[1184]winlogon.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[1184]winlogon.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[1184]winlogon.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[1184]winlogon.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[1184]winlogon.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[1184]winlogon.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[1184]winlogon.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[1184]winlogon.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[1184]winlogon.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[1184]winlogon.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[1184]winlogon.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[1184]winlogon.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[1184]winlogon.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[1232]services.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[1232]services.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[1232]services.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[1232]services.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[1232]services.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[1232]services.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[1232]services.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[1232]services.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[1232]services.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[1232]services.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[1232]services.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[1232]services.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[1232]services.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[1244]lsass.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[1244]lsass.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[1244]lsass.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[1244]lsass.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[1244]lsass.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[1244]lsass.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[1244]lsass.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[1244]lsass.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[1244]lsass.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[1244]lsass.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[1244]lsass.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[1244]lsass.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[1244]lsass.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[1424]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[1424]svchost.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[1424]svchost.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[1424]svchost.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[1424]svchost.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[1424]svchost.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[1424]svchost.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[1424]svchost.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[1424]svchost.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[1424]svchost.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[1424]svchost.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[1424]svchost.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[1424]svchost.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[1472]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[1472]svchost.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[1472]svchost.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[1472]svchost.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[1472]svchost.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[1472]svchost.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[1472]svchost.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[1472]svchost.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[1472]svchost.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[1472]svchost.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[1472]svchost.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[1472]svchost.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[1472]svchost.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[1512]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[1512]svchost.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[1512]svchost.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[1512]svchost.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[1512]svchost.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[1512]svchost.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[1512]svchost.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[1512]svchost.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[1512]svchost.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[1512]svchost.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[1512]svchost.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[1512]svchost.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[1512]svchost.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[1552]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[1552]svchost.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[1552]svchost.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[1552]svchost.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[1600]EvtEng.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[1600]EvtEng.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[1600]EvtEng.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[1600]EvtEng.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[1600]EvtEng.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[1600]EvtEng.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[1600]EvtEng.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[1600]EvtEng.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[1600]EvtEng.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[1600]EvtEng.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[1600]EvtEng.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[1600]EvtEng.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[1600]EvtEng.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[1748]spoolsv.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[1748]spoolsv.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[1748]spoolsv.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[1748]spoolsv.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[1848]alg.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[1848]alg.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[1848]alg.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[1848]alg.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[1848]alg.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[1848]alg.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[1848]alg.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[1848]alg.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[1848]alg.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[1848]alg.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[1848]alg.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[1848]alg.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[1848]alg.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[1880]explorer.exe–>advapi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77DD1218–>00000000 [shimeng.dll]
[1880]explorer.exe–>gdi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77F110B4–>00000000 [shimeng.dll]
[1880]explorer.exe–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x01001268–>00000000 [shimeng.dll]
[1880]explorer.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[1880]explorer.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[1880]explorer.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[1880]explorer.exe–>shell32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7C9C15A4–>00000000 [shimeng.dll]
[1880]explorer.exe–>user32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7E41133C–>00000000 [shimeng.dll]
[1880]explorer.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[1880]explorer.exe–>wininet.dll–>HttpOpenRequestA, Type: Inline - RelativeJump 0x3D94D508–>00000000 [unknown_code_page]
[1880]explorer.exe–>wininet.dll–>HttpOpenRequestW, Type: Inline - RelativeJump 0x3D94FBFB–>00000000 [unknown_code_page]
[1880]explorer.exe–>wininet.dll–>HttpSendRequestA, Type: Inline - RelativeJump 0x3D95EE89–>00000000 [unknown_code_page]
[1880]explorer.exe–>wininet.dll–>HttpSendRequestExA, Type: Inline - RelativeJump 0x3D9BA642–>00000000 [unknown_code_page]
[1880]explorer.exe–>wininet.dll–>HttpSendRequestExW, Type: Inline - RelativeJump 0x3D9BA69B–>00000000 [unknown_code_page]
[1880]explorer.exe–>wininet.dll–>HttpSendRequestW, Type: Inline - RelativeJump 0x3D94FABE–>00000000 [unknown_code_page]
[1880]explorer.exe–>wininet.dll–>InternetCloseHandle, Type: Inline - RelativeJump 0x3D949088–>00000000 [unknown_code_page]
[1880]explorer.exe–>wininet.dll–>InternetOpenUrlA, Type: Inline - RelativeJump 0x3D95F3A4–>00000000 [unknown_code_page]
[1880]explorer.exe–>wininet.dll–>InternetOpenUrlW, Type: Inline - RelativeJump 0x3D9A6D5F–>00000000 [unknown_code_page]
[1880]explorer.exe–>wininet.dll–>InternetQueryDataAvailable, Type: Inline - RelativeJump 0x3D94BF83–>00000000 [unknown_code_page]
[1880]explorer.exe–>wininet.dll–>InternetReadFile, Type: Inline - RelativeJump 0x3D94654B–>00000000 [unknown_code_page]
[1880]explorer.exe–>wininet.dll–>InternetReadFileExA, Type: Inline - RelativeJump 0x3D963259–>00000000 [unknown_code_page]
[1880]explorer.exe–>wininet.dll–>InternetReadFileExW, Type: Inline - RelativeJump 0x3D963221–>00000000 [unknown_code_page]
[1880]explorer.exe–>wininet.dll–>InternetWriteFile, Type: Inline - RelativeJump 0x3D9A6076–>00000000 [unknown_code_page]
[1880]explorer.exe–>wininet.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x3D9314B0–>00000000 [shimeng.dll]
[1880]explorer.exe–>ws2_32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x71AB109C–>00000000 [shimeng.dll]
[1912]S24EvMon.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[1912]S24EvMon.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[1912]S24EvMon.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[1912]S24EvMon.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[1912]S24EvMon.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[1912]S24EvMon.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[1912]S24EvMon.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[1912]S24EvMon.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[1912]S24EvMon.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[1912]S24EvMon.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[1912]S24EvMon.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[1912]S24EvMon.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[1912]S24EvMon.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[200]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[200]svchost.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[200]svchost.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[200]svchost.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[2012]WLKEEPER.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[2012]WLKEEPER.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[2012]WLKEEPER.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[2012]WLKEEPER.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[2012]WLKEEPER.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[2012]WLKEEPER.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[2012]WLKEEPER.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[2012]WLKEEPER.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[2012]WLKEEPER.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[2012]WLKEEPER.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[2012]WLKEEPER.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[2012]WLKEEPER.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[2012]WLKEEPER.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[2320]jqs.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[2320]jqs.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[2320]jqs.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[2320]jqs.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[2320]jqs.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[2320]jqs.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[2320]jqs.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[2320]jqs.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[2320]jqs.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[2320]jqs.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[2320]jqs.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[2320]jqs.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[2320]jqs.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[2480]McciCMService.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[2480]McciCMService.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[2480]McciCMService.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[2480]McciCMService.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>wininet.dll–>HttpOpenRequestA, Type: Inline - RelativeJump 0x3D94D508–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>wininet.dll–>HttpOpenRequestW, Type: Inline - RelativeJump 0x3D94FBFB–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>wininet.dll–>HttpSendRequestA, Type: Inline - RelativeJump 0x3D95EE89–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>wininet.dll–>HttpSendRequestExA, Type: Inline - RelativeJump 0x3D9BA642–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>wininet.dll–>HttpSendRequestExW, Type: Inline - RelativeJump 0x3D9BA69B–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>wininet.dll–>HttpSendRequestW, Type: Inline - RelativeJump 0x3D94FABE–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>wininet.dll–>InternetCloseHandle, Type: Inline - RelativeJump 0x3D949088–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>wininet.dll–>InternetOpenUrlA, Type: Inline - RelativeJump 0x3D95F3A4–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>wininet.dll–>InternetOpenUrlW, Type: Inline - RelativeJump 0x3D9A6D5F–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>wininet.dll–>InternetQueryDataAvailable, Type: Inline - RelativeJump 0x3D94BF83–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>wininet.dll–>InternetReadFile, Type: Inline - RelativeJump 0x3D94654B–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>wininet.dll–>InternetReadFileExA, Type: Inline - RelativeJump 0x3D963259–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>wininet.dll–>InternetReadFileExW, Type: Inline - RelativeJump 0x3D963221–>00000000 [unknown_code_page]
[2672]TeaTimer.exe–>wininet.dll–>InternetWriteFile, Type: Inline - RelativeJump 0x3D9A6076–>00000000 [unknown_code_page]
[2680]AVGIDSMonitor.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[2680]AVGIDSMonitor.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[2680]AVGIDSMonitor.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[2680]AVGIDSMonitor.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[2684]GoogleToolbarNotifier.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[2684]GoogleToolbarNotifier.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[2684]GoogleToolbarNotifier.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[2684]GoogleToolbarNotifier.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[2704]MDM.EXE–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[2704]MDM.EXE–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[2704]MDM.EXE–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[2704]MDM.EXE–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[2784]NBService.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[2784]NBService.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[2784]NBService.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[2784]NBService.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[288]ADCDLicSvc.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[288]ADCDLicSvc.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[288]ADCDLicSvc.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[288]ADCDLicSvc.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[2908]nvsvc32.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[2908]nvsvc32.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[2908]nvsvc32.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[2908]nvsvc32.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[2992]RegSrvc.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[2992]RegSrvc.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[2992]RegSrvc.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[2992]RegSrvc.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[3012]stsystra.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[3012]stsystra.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[3012]stsystra.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[3012]stsystra.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>wininet.dll–>HttpOpenRequestA, Type: Inline - RelativeJump 0x3D94D508–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>wininet.dll–>HttpOpenRequestW, Type: Inline - RelativeJump 0x3D94FBFB–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>wininet.dll–>HttpSendRequestA, Type: Inline - RelativeJump 0x3D95EE89–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>wininet.dll–>HttpSendRequestExA, Type: Inline - RelativeJump 0x3D9BA642–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>wininet.dll–>HttpSendRequestExW, Type: Inline - RelativeJump 0x3D9BA69B–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>wininet.dll–>HttpSendRequestW, Type: Inline - RelativeJump 0x3D94FABE–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>wininet.dll–>InternetCloseHandle, Type: Inline - RelativeJump 0x3D949088–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>wininet.dll–>InternetOpenUrlA, Type: Inline - RelativeJump 0x3D95F3A4–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>wininet.dll–>InternetOpenUrlW, Type: Inline - RelativeJump 0x3D9A6D5F–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>wininet.dll–>InternetQueryDataAvailable, Type: Inline - RelativeJump 0x3D94BF83–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>wininet.dll–>InternetReadFile, Type: Inline - RelativeJump 0x3D94654B–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>wininet.dll–>InternetReadFileExA, Type: Inline - RelativeJump 0x3D963259–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>wininet.dll–>InternetReadFileExW, Type: Inline - RelativeJump 0x3D963221–>00000000 [unknown_code_page]
[3168]RoxWatch9.exe–>wininet.dll–>InternetWriteFile, Type: Inline - RelativeJump 0x3D9A6076–>00000000 [unknown_code_page]
[3244]BTSTAC~1.EXE–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[3244]BTSTAC~1.EXE–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[3244]BTSTAC~1.EXE–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[3244]BTSTAC~1.EXE–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[3244]BTSTAC~1.EXE–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[3244]BTSTAC~1.EXE–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[3244]BTSTAC~1.EXE–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[3244]BTSTAC~1.EXE–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[3244]BTSTAC~1.EXE–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[3244]BTSTAC~1.EXE–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[3244]BTSTAC~1.EXE–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[3244]BTSTAC~1.EXE–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[3244]BTSTAC~1.EXE–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[3512]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[3512]svchost.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[3512]svchost.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[3512]svchost.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[352]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[352]svchost.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[352]svchost.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[352]svchost.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[352]svchost.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[352]svchost.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[352]svchost.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[352]svchost.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[352]svchost.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[352]svchost.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[352]svchost.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[352]svchost.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[352]svchost.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[3600]avgnsx.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[3600]avgnsx.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[3600]avgnsx.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[3600]avgnsx.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[3708]SynTPEnh.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[3708]SynTPEnh.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[3708]SynTPEnh.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[3708]SynTPEnh.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[4020]BTTray.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[4020]BTTray.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[4020]BTTray.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[4020]BTTray.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[4020]BTTray.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[4020]BTTray.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[4020]BTTray.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[4020]BTTray.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[4020]BTTray.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[4020]BTTray.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[4020]BTTray.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[4020]BTTray.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[4020]BTTray.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[460]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[460]svchost.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[460]svchost.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[460]svchost.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[460]svchost.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[460]svchost.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[460]svchost.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[460]svchost.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[460]svchost.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[460]svchost.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[460]svchost.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[460]svchost.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[460]svchost.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[572]firefox.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[572]firefox.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[572]firefox.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[572]firefox.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[572]firefox.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[572]firefox.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[572]firefox.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[572]firefox.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[572]firefox.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[572]firefox.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[572]firefox.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[572]firefox.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[572]firefox.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[580]firefox.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[580]firefox.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[580]firefox.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[580]firefox.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[580]firefox.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[580]firefox.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[580]firefox.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[580]firefox.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[580]firefox.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[580]firefox.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[580]firefox.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[580]firefox.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[580]firefox.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]
[636]btwdins.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [unknown_code_page]
[636]btwdins.exe–>ntdll.dll–>NtQueryDirectoryFile, Type: Inline - RelativeJump 0x7C90D76E–>00000000 [unknown_code_page]
[636]btwdins.exe–>ntdll.dll–>NtResumeThread, Type: Inline - RelativeJump 0x7C90DB3E–>00000000 [unknown_code_page]
[636]btwdins.exe–>user32.dll–>TranslateMessage, Type: Inline - RelativeJump 0x7E418BF6–>00000000 [unknown_code_page]
[636]btwdins.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [unknown_code_page]
[636]btwdins.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [unknown_code_page]
[636]btwdins.exe–>ws2_32.dll–>recvfrom, Type: Inline - RelativeJump 0x71AB2FF7–>00000000 [unknown_code_page]
[636]btwdins.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [unknown_code_page]
[636]btwdins.exe–>ws2_32.dll–>sendto, Type: Inline - RelativeJump 0x71AB2F51–>00000000 [unknown_code_page]
[636]btwdins.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00000000 [unknown_code_page]
[636]btwdins.exe–>ws2_32.dll–>WSARecvFrom, Type: Inline - RelativeJump 0x71ABF66A–>00000000 [unknown_code_page]
[636]btwdins.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00000000 [unknown_code_page]
[636]btwdins.exe–>ws2_32.dll–>WSASendTo, Type: Inline - RelativeJump 0x71AC0AAD–>00000000 [unknown_code_page]


MBAM

Malwarebytes' Anti-Malware 1.44
Database version: 3510
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

30/05/2011 18:31:56
mbam-log-2011-05-30 (18-31-56).txt

Scan type: Quick Scan
Objects scanned: 122031
Time elapsed: 6 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



BSOD

🖼Click to load external image (Posted Image)

Attachments:

  • [attachment removed: attach.zip]
Its a Dell Vostro Laptop i bought of the dell website a few years ago. My dads a farmer so i was able to buy a business one from them and claim the VAT back. It has never left my bedroom since then lol ^_^
Hello supersub14 :),

Remove P2P software
  • IMPORTANT: I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

    BitComet 1.25

  • Our policy as pointed out in the Terms of Use:

    We will not support or allow the discussion of any peer to peer (P2P) applications, except for their removal.

  • Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
  • Go to Control Panel > Add/Remove Programs and uninstall the P2P program(s) listed above (in red).
  • Please remove them before we continue with fixing your computer.
Please rerun DDS and post a new Attach.txt by copy and pasting the contents.

——————–

Check for additional security risks
  • Please download CKScanner© by askey127 and save to your desktop. Click here.
  • Double click on CKScanner.exe and click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File. You will be prompted, click OK.
  • Post the contents of ckfiles.txt in your reply, it is located on your desktop.
——————–

Validate Windows
  • Please download MGADiag.exe from Microsoft and save it to a convenient location. Click here.
  • Double click on MGADiag.exe to run it.
  • Click Continue.
  • The program will run. It takes a while to finish the diagnosis, please be patient.
  • Once done, click on Copy.
  • Open Notepad and paste the contents in. Save this file and post it in your next reply.
——————–

Please post back:
1. new Attach.txt
2. CKScanner log
3. MGADiag result
Bitcomet removed (had been meaning to do that for ages anyway!)

ok heres the results:

new Attach.txt

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-05-19.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 22/11/2007 22:47:43
System Uptime: 01/06/2011 23:21:59 (0 hours ago)
.
Motherboard: Dell Inc. | | 0WY040
Processor: Intel® Core™2 Duo CPU T5470 @ 1.60GHz | Microprocessor | 1595/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 143 GiB total, 75.842 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP601: 20/02/2011 23:58:14 - System Checkpoint
RP602: 23/02/2011 22:57:35 - System Checkpoint
RP603: 25/02/2011 22:00:58 - System Checkpoint
RP604: 10/03/2011 22:20:35 - System Checkpoint
RP605: 11/03/2011 03:00:20 - Software Distribution Service 3.0
RP606: 14/03/2011 23:33:25 - Avg Update
RP607: 14/03/2011 23:39:10 - Avg Update
RP608: 15/03/2011 00:01:23 - Software Distribution Service 3.0
RP609: 15/03/2011 23:13:08 - Software Distribution Service 3.0
RP610: 17/03/2011 01:49:45 - System Checkpoint
RP611: 19/03/2011 00:05:31 - System Checkpoint
RP612: 20/03/2011 12:24:34 - System Checkpoint
RP613: 23/03/2011 01:30:09 - System Checkpoint
RP614: 26/03/2011 15:11:37 - System Checkpoint
RP615: 26/03/2011 16:28:58 - Software Distribution Service 3.0
RP616: 30/03/2011 22:21:13 - System Checkpoint
RP617: 02/04/2011 00:48:43 - System Checkpoint
RP618: 07/04/2011 22:37:09 - System Checkpoint
RP619: 10/04/2011 11:47:54 - System Checkpoint
RP620: 13/04/2011 00:42:41 - Software Distribution Service 3.0
RP621: 13/04/2011 23:46:06 - Software Distribution Service 3.0
RP622: 15/04/2011 00:42:09 - Software Distribution Service 3.0
RP623: 16/04/2011 15:38:24 - Software Distribution Service 3.0
RP624: 18/04/2011 23:43:42 - System Checkpoint
RP625: 21/04/2011 00:44:19 - System Checkpoint
RP626: 22/04/2011 09:30:21 - System Checkpoint
RP627: 23/04/2011 18:49:31 - System Checkpoint
RP628: 25/04/2011 16:13:40 - System Checkpoint
RP629: 25/04/2011 17:12:52 - Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
RP630: 25/04/2011 17:13:11 - Installed AVG 2011
RP631: 25/04/2011 17:15:56 - Removed AVG Free 9.0
RP632: 25/04/2011 17:22:30 - Installed AVG 2011
RP633: 27/04/2011 00:12:59 - System Checkpoint
RP634: 27/04/2011 23:50:41 - Software Distribution Service 3.0
RP635: 03/05/2011 19:51:57 - System Checkpoint
RP636: 07/05/2011 15:00:06 - System Checkpoint
RP637: 11/05/2011 21:43:03 - System Checkpoint
RP638: 12/05/2011 00:55:55 - Software Distribution Service 3.0
RP639: 18/05/2011 22:42:29 - Software Distribution Service 3.0
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X (10.0.1)
Adobe Shockwave Player 11.5
Advanced Audio FX Engine
Advanced Video FX Engine
ALO RM to MP3 Converter 7.0
Apple Software Update
Audacity 1.2.6
AutoCAD Electrical 2008
Autodesk DWF Viewer 7
AutoDWG DWG to PDF Converter
AVG 2011
Broadcom Management Programs
Browser Address Error Redirector
BT Broadband Desktop Help
BTHomeHub
CCleaner
Compatibility Pack for the 2007 Office system
Conexant HDA D330 MDC V.92 Modem
Critical Update for Windows Media Player 11 (KB959772)
Defraggler
Dell System Restore
Dell Touchpad
Dell Webcam Center
Dell Webcam Manager
DellSupport
Digital Line Detect
DWG TrueView 2007
EPSON Printer Software
Facebook Plug-In
Free WMA to MP3 Converter 1.16
Google Toolbar for Internet Explorer
Google Update Helper
GoToAssist Corporate
HiDownload
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976002-v5)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
Intel® PROSet/Wireless Software
IntelliSonic Speech Enhancement
isoHunt Toolbar
Java™ 6 Update 14
Laptop Integrated Webcam Driver (1.04.01.1011)
Live! Cam Avatar Creator
Live! Cam Avatar v1.0
Malwarebytes' Anti-Malware
mCore
mDrWiFi
MediaDirect
mHlpDell
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
Microsoft WSE 3.0 Runtime
Microsoft XML Parser
mIWA
mLogView
mMHouse
Modem Diagnostic Tool
Mozilla Firefox 4.0.1 (x86 en-GB)
MP3 Player Utilities 4.13
mPfMgr
mPfWiz
mProSafe
mSCfg
mSSO
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser (KB933579)
mWlsSafe
mWMI
mZConfig
Nero 8 Demo
neroxml
NetWaiting
NVIDIA Drivers
O2InstV3Win7UpdateV1
OGA Notifier 2.0.0048.0
OutlookAddinSetup
PowerISO
QuickSet
QuickTime
RealPlayer
Replay Media Catcher
Roxio Creator Audio
Roxio Creator BDAV Plugin
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator Tools
Roxio Express Labeler
Roxio MyDVD DE
Roxio Update Manager
SearchAssist
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2491683)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002)
Skype web features
Skype™ 4.1
Sonic Activation Module
Spybot - Search & Destroy
TVUPlayer [removed]
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 8 (KB971930)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB978506)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VBA (2627.01)
VCRedistSetup
VideoLAN VLC media player 0.8.6c
WebFldrs XP
WIDCOMM Bluetooth Software
WinAce Archiver
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live installer
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 11
Windows PowerShell™ 1.0
Windows XP Service Pack 3
WinRAR archiver
.
==== Event Viewer Messages From Past Week ========
.
30/05/2011 19:07:53, error: Service Control Manager [7000] - The 4720CD47 service failed to start due to the following error: Access is denied.
26/05/2011 20:38:27, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: iaStor
26/05/2011 20:16:33, error: Service Control Manager [7000] - The SupportSoft RemoteAssist service failed to start due to the following error: The system cannot find the file specified.
26/05/2011 00:09:37, error: NETw4x32 [5005] - \DEVICE\{491BE81E-EB0D-4EF0-B6E7-BB138DF09CDD} : Has encountered an internal error and has failed.
26/05/2011 00:09:37, error: NETw4x32 [5002] - Intel® PRO/Wireless 3945ABG Network Connection : Has determined that the adapter is not functioning properly.
26/05/2011 00:09:37, error: NETw4x32 [5002] - \DEVICE\{491BE81E-EB0D-4EF0-B6E7-BB138DF09CDD} : Has determined that the adapter is not functioning properly.
.
==== End Of File ===========================


CKScanner.log


CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11
—– EOF —–


MGADiag.txt

Diagnostic Report (1.9.0027.0):
—————————————–
Windows Validation Data–>
Validation Status: Genuine
Validation Code: 0
Cached Validation Code: N/A
Windows Product Key: *****-*****-T6DFB-Y934T-YD4YT
Windows Product Key Hash: 3g4CZGFEDgbKmn/oB4pa2FZsssU=
Windows Product ID: 76487-OEM-2211906-00102
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 5.1.2600.2.00010100.3.0.pro
ID: {60C93E39-477C-4241-904F-766283E2A706}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: Registered, 1.9.40.0
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-230-1
Resolution Status: N/A

Vista WgaER Data–>
ThreatID(s): N/A
Version: N/A

Windows XP Notifications Data–>
Cached Result: 0
File Exists: Yes
Version: 1.9.40.0
WgaTray.exe Signed By: Microsoft
WgaLogon.dll Signed By: Microsoft

OGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
Version: 2.0.48.0
OGAExec.exe Signed By: Microsoft
OGAAddin.dll Signed By: Microsoft

OGA Data–>
Office Status: 114 Blocked VLK 2
Microsoft Office Professional Edition 2003 - 114 Blocked VLK 2
OGA Version: Registered, 2.0.48.0
Signed By: Microsoft
Office Diagnostics: 025D1FF3-230-1

Browser Data–>
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data–>

Other data–>
Office Details: {60C93E39-477C-4241-904F-766283E2A706}1.9.0027.05.1.2600.2.00010100.3.0.prox32*****-*****-*****-*****-YD4YT76487-OEM-2211906-001022S-1-5-21-3914213219-631083849-1714028050Dell Inc.Vostro 1500 Dell Inc.A0120070802000000.000000+000Dell System,Dell Computer,Dell System,Dell System2E9D35AF0184607A08090409GMT Standard Time(GMT+00:00)02Dell Vostro 1500114

Licensing Data–>
N/A

Windows Activation Technologies–>
N/A

HWID Data–>
N/A

OEM Activation 1.0 Data–>
BIOS string matches: yes
Marker string from BIOS: 175A9:Dell Inc|175A9:Microsoft Corporation
Marker string from OEMBIOS.DAT: Dell System,Dell Computer,Dell System,Dell System

OEM Activation 2.0 Data–>
N/A









Im concerned - it seems like your spending alot of time trying to figure out if my laptop is genuine????? I can assure you it is!!

Have you any ideas how to remove this virus?? Its nearly been a week now since i first posted :unsure:
Hello supersub14 :),

Im concerned - it seems like your spending alot of time trying to figure out if my laptop is genuine????? I can assure you it is!!

Have you any ideas how to remove this virus?? Its nearly been a week now since i first posted

What I am trying to do is to ensure the forum policy is strictly adhered to (due to legal implications) and also as part of education to users like you asking for help.

Knowledge is key to better and useful utilization of the computer and prevention of future infections. Removing non genuine programs is a first step to eliminate the source of malware problems because that is where they mostly originate from. Another thing to note is not all computer problems are malware related.

Maybe things are not so clear for you now, but when we get to the end, you will know what I mean.

——————–

Your computer has/had some serious infections with rootkit/backdoor capabilities.
Sorry for the bad news. Backdoors provide outsiders full access to your computer, enabling them to record key strokes, steal passwords, spread malwares, and even using it for other illegal activities.

If your computer has been used for important or sensitive data such as online banking, shopping or any other financial transactions, I strongly recommend you to do the following:
  • Disconnect from the Internet and any network immediately.
  • Inform your financial institutions that you may be a victim of identity theft and to put a watch on all your accounts or change them.
  • Change all your online passwords from a clean computer.
  • Take any other steps that you may think is necessary to prevent financial distress due to identity theft.
Due to the backdoor functionality, your computer is compromised and can no longer be fully trusted. Many experts in the security community believe that once tainted with this type of infections, the best course of action would be a reformat and reinstall of the OS. I too strongly recommend you to format your computer. We can still attempt to clean it if you wish, but due to the severity of the infections, I cannot guarantee it will be safe or clean afterwards. It is up to you to decide. Please let me know which course of action you wish to take.

Here are some read to help you decide:
How to respond to possible ID theft and Internet fraud
When should I reformat?

——————–

Whatever decision you make, in order for me to continue helping, please complete the following steps.

The Microsoft Office Professional Edition 2003 on your computer is a non-genuine copy. It was installed with a now blocked Volume Licensing Key (VLK) that was valid and only available to corporations, education entities and government agencies. VLKs are blocked by Microsoft at the request and consent of the original keyholder for such reasons as the key was lost, stolen, compromised, misused, or expired. Also, Microsoft may have blocked the key if it notices a pattern of misuse, that is more installations of XP using that key than authorized.
A VL Product Key is non-transferable to individuals.

Please read our Terms of Use.

The posting of links or references to warez or any other type of illegal software is strictly forbidden. By doing so you risk having your user account terminated without warning. We will NOT help anyone we suspect of having obtained their software illegally.

If you still want help, please remove the illegal items from your computer, and if you still need the softwares, get legal ones from legitimate sources.
If you advised that the illegal softwares have been removed and I find it otherwise (the tools we use can and will detect them), then I will have no choice but to have this topic closed.
If there are more such new findings after this, the topic will also be closed.

You may return to the seller to demand for a replacement with a genuine copy or get a full refund. Have a read here to see if you qualify for Genuince Office Offer. As an alternative, you can also try OpenOffice.

Post back a new MGADiag result when you are done.

——————–

Please post back:
1. your decision how to proceed
2. new positive MGADiag result if you still require my assistance
oh right. dosent sound good!! Didint realise my office was wrong as it wasnt me who installed it. Ill remove it and repost my MGAdiag list. I then want to try to clean my machine rather than reformat. I understand the risks. Unfortunately i am away on holiday now for a week. I will resume contact with you when i return. Can you please leave this topic open until then?? Thanks
Hello supersub14 :),

Didint realise my office was wrong as it wasnt me who installed it. Ill remove it and repost my MGAdiag list.

A good decision. Thank you.

I will keep the topic open until you are back. Have a good time.
Im back. I tried to uninstal Office by the Add/Remove programs command window but it brings up the error message: "This patch package could not be opened. Verify that the patch package exists and that you can access it, or contact the application vendor to verify that this is a valid Windows Installer patch package." I dont have the orginal cd or anyway to get it. Is there any other way to remove it? Is the virus blocking me from removing it?
that fix it didnt work so i downloaded another one and it looks like its been removed now! Here my new MGADiag report: Diagnostic Report (1.9.0027.0): —————————————– Windows Validation Data–> Validation Status: Genuine Validation Code: 0 Cached Validation Code: N/A Windows Product Key: *****-*****-T6DFB-Y934T-YD4YT Windows Product Key Hash: 3g4CZGFEDgbKmn/oB4pa2FZsssU= Windows Product ID: 76487-OEM-2211906-00102 Windows Product ID Type: 2 Windows License Type: OEM SLP Windows OS version: 5.1.2600.2.00010100.3.0.pro ID: {60C93E39-477C-4241-904F-766283E2A706}(3) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: Registered, 1.9.40.0 Signed By: Microsoft Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: 025D1FF3-230-1 Resolution Status: N/A Vista WgaER Data–> ThreatID(s): N/A Version: N/A Windows XP Notifications Data–> Cached Result: 0 File Exists: Yes Version: 1.9.40.0 WgaTray.exe Signed By: Microsoft WgaLogon.dll Signed By: Microsoft OGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 Version: 2.0.48.0 OGAExec.exe Signed By: Microsoft OGAAddin.dll Signed By: Microsoft OGA Data–> Office Status: 109 N/A OGA Version: Registered, 2.0.48.0 Signed By: Microsoft Office Diagnostics: 025D1FF3-230-1 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data–> Other data–> Office Details: {60C93E39-477C-4241-904F-766283E2A706}1.9.0027.05.1.2600.2.00010100.3.0.prox32*****-*****-*****-*****-YD4YT76487-OEM-2211906-001022S-1-5-21-3914213219-631083849-1714028050Dell Inc.Vostro 1500 Dell Inc.A0120070802000000.000000+000Dell System,Dell Computer,Dell System,Dell System2E9D35AF0184607A08090409GMT Standard Time(GMT+00:00)02Dell Vostro 1500109 Licensing Data–> N/A Windows Activation Technologies–> N/A HWID Data–> N/A OEM Activation 1.0 Data–> BIOS string matches: yes Marker string from BIOS: 175A9:Dell Inc|175A9:Microsoft Corporation Marker string from OEMBIOS.DAT: Dell System,Dell Computer,Dell System,Dell System OEM Activation 2.0 Data–> N/A

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI