Alright did everything exactly as asked.
DDS log
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 7.0.5730.13
Run by [removed] at 10:31:56 on 2011-07-26
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1253 [GMT -7:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\System32\svchost.exe -k Akamai
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Ideazon\ZEngine\Zboard.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\BitTorrent\BitTorrent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wuauclt.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
TB: {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File
uRun: [Google Update] "c:\documents and settings\emmanuel\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [EasyDVDMon]
uRun: [BitTorrent] "c:\program files\bittorrent\BitTorrent.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [Zboard] c:\program files\ideazon\zengine\Zboard.exe
mRun: [Nikon Transfer Monitor] c:\program files\common files\nikon\monitor\NkMonitor.exe
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5.5ServiceManager] "c:\program files\common files\adobe\cs5.5servicemanager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [CanonSolutionMenuEx] c:\program files\canon\solution menu ex\CNSEMAIN.EXE /logon
mRun: [IJNetworkScanUtility] c:\program files\canon\canon ij network scan utility\CNMNSUT.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\emmanuel\startm~1\programs\startup\stardo~1.lnk - c:\program files\stardock\objectdockfree\ObjectDock.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: DhcpNameServer = [removed] [removed] [removed]
TCP: Interfaces\{2BF4A2AE-C20F-4579-B95F-F595CB1753BD} : DhcpNameServer = [removed] [removed] [removed]
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: ObjectDockShlExt Class: {1984d045-52cf-49cd-db77-08f378fea4db} - c:\program files\stardock\objectdockfree\ODMenu.dll
.
============= SERVICES / DRIVERS ===============
.
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2004-8-10 14336]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2009-12-30 10384]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-4-27 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-4-27 136176]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
.
=============== Created Last 30 ================
.
2011-07-26 01:48:40 ——– d—–w- c:\program files\Comical
2011-07-23 23:52:23 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll
2011-07-23 23:52:18 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll
2011-07-23 23:51:57 40960 -c—-w- c:\windows\system32\dllcache\ndproxy.sys
2011-07-23 23:51:34 105472 -c—-w- c:\windows\system32\dllcache\mup.sys
2011-07-23 23:50:31 45568 -c—-w- c:\windows\system32\dllcache\wab.exe
2011-07-23 09:22:59 512000 -c—-w- c:\windows\system32\dllcache\jscript.dll
2011-07-23 09:07:03 ——– d—–w- c:\windows\system32\scripting
2011-07-23 09:07:03 ——– d—–w- c:\windows\system32\en
2011-07-23 09:07:03 ——– d—–w- c:\windows\system32\bits
2011-07-23 09:07:03 ——– d—–w- c:\windows\l2schemas
2011-07-23 08:46:58 7680 —-a-w- c:\windows\system32\spdwnwxp.exe
2011-07-23 08:45:57 685056 ——w- c:\windows\system32\drivers\hsfcxts2.sys
2011-07-23 08:22:25 63488 -c—-w- c:\windows\system32\dllcache\icardie.dll
2011-07-23 08:22:25 6076416 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2011-07-23 08:22:25 52224 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-07-23 08:22:25 468480 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2011-07-23 08:22:25 380928 -c—-w- c:\windows\system32\dllcache\ieapfltr.dll
2011-07-23 08:22:25 268288 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2011-07-23 08:22:25 2452872 -c—-w- c:\windows\system32\dllcache\ieapfltr.dat
2011-07-23 08:22:25 13824 -c—-w- c:\windows\system32\dllcache\ieudinit.exe
2011-07-23 08:18:56 ——– d—–w- c:\windows\network diagnostic
2011-07-18 05:37:54 ——– d—–w- c:\documents and settings\all users\application data\CanonIJ
2011-07-18 05:37:05 ——– d–h–w- c:\documents and settings\all users\application data\CanonIJScan
2011-07-18 00:36:29 ——– d–h–w- c:\documents and settings\all users\application data\CanonIJEPPEX
2011-07-18 00:36:29 ——– d—–w- c:\documents and settings\emmanuel\local settings\application data\Canon Easy-PhotoPrint EX
2011-07-18 00:36:10 ——– d–h–w- c:\documents and settings\all users\application data\CanonIJSolutionMenuEX
2011-07-18 00:36:09 ——– d–h–w- c:\documents and settings\all users\application data\CanonIJMyPrinter
2011-07-18 00:36:09 ——– d–h–w- c:\documents and settings\all users\application data\CanonIJEPPEX2
2011-07-18 00:36:09 ——– d–h–w- c:\documents and settings\all users\application data\CanonEPP
2011-07-18 00:32:56 ——– d—–w- c:\documents and settings\all users\application data\CanonIJPLM
2011-07-18 00:32:50 ——– d—–w- c:\documents and settings\all users\application data\Canon IJ Network Tool
2011-07-18 00:32:41 307200 —-a-w- c:\windows\system32\CNC6100L.dll
2011-07-18 00:32:41 15872 —-a-w- c:\windows\system32\CNHMCA.dll
2011-07-18 00:32:41 1335296 —-a-w- c:\windows\system32\CNC6100C.dll
2011-07-18 00:32:41 114688 —-a-w- c:\windows\system32\CNC6100I.dll
2011-07-18 00:32:41 106496 —-a-w- c:\windows\system32\CNC6100U.dll
2011-07-18 00:32:02 ——– d—–w- c:\documents and settings\all users\application data\CanonIJMSetup
2011-07-18 00:31:52 ——– d—–w- c:\program files\common files\CANON
2011-07-18 00:31:23 ——– d—–w- c:\documents and settings\all users\application data\CanonIJWSpt
2011-07-18 00:28:17 73216 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\CNMPPAG.DLL
2011-07-18 00:28:17 290816 —-a-w- c:\windows\system32\CNMLMAG.DLL
2011-07-18 00:28:17 27648 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\CNMPDAG.DLL
2011-07-18 00:28:05 180224 —-a-w- c:\windows\system32\CNMIUAG.DLL
2011-07-18 00:27:46 34816 —-a-w- c:\windows\system32\CNMNPUI.DLL
2011-07-18 00:27:46 340992 —-a-w- c:\windows\system32\CNMNPPM.DLL
2011-07-18 00:27:46 ——– d—–w- c:\windows\system32\STRING
2011-07-18 00:26:08 ——– d—–w- c:\program files\Canon
2011-07-17 04:13:20 ——– d—–w- c:\windows\system32\Data
2011-07-15 01:27:06 ——– d—–w- C:\adobeTemp
2011-07-14 02:33:41 ——– d—–w- c:\documents and settings\emmanuel\Adobe Photoshop CS5.1
2011-07-14 01:58:04 ——– d—–w- c:\documents and settings\emmanuel\application data\com.adobe.downloadassistant.AdobeDownloadAssistant
2011-07-14 01:58:00 ——– d—–w- c:\program files\Adobe Download Assistant
2011-07-13 01:51:12 ——– d—–w- c:\documents and settings\emmanuel\local settings\application data\Structured_Designs
2011-07-06 03:15:31 ——– d—–w- c:\documents and settings\emmanuel\local settings\application data\ODUI
2011-07-06 03:15:18 ——– d—–w- c:\documents and settings\emmanuel\application data\Stardock
2011-07-06 03:15:11 ——– d—–w- c:\documents and settings\emmanuel\local settings\application data\Stardock
2011-07-06 03:14:59 ——– d—–w- c:\program files\Stardock
2011-07-06 03:14:49 ——– d—–w- c:\documents and settings\emmanuel\local settings\application data\PackageAware
2011-07-03 06:30:41 ——– d—–w- c:\program files\MonitorDriver
.
==================== Find3M ====================
.
2011-06-02 14:02:05 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-05-04 11:52:22 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-05-04 09:25:49 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-05-02 15:31:52 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25:27 151552 —-a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19:43 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
.
============= FINISH: 10:32:42.11 ===============
Gmer log
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-07-26 14:17:49
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 ST316081 rev.3.AD
Running: 4z9929q5.exe; Driver: C:\DOCUME~1\Emmanuel\LOCALS~1\Temp\fwtdruow.sys
—- Kernel code sections - GMER 1.0.15 —-
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB8D39360, 0x35363F, 0xE8000020]
? C:\DOCUME~1\Emmanuel\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
—- User code sections - GMER 1.0.15 —-
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1256] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2452] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Program Files\Ideazon\ZEngine\Zboard.exe[2560] KERNEL32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10005230 C:\Program Files\Ideazon\ZEngine\ZESystem.dll (rscoree/Remotesoft, Inc.)
.text C:\Program Files\Ideazon\ZEngine\Zboard.exe[2560] USER32.dll!GetSysColor 7E418E78 5 Bytes JMP 6305DA75 C:\WINDOWS\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock Corporation)
.text C:\Program Files\Ideazon\ZEngine\Zboard.exe[2560] USER32.dll!GetSysColorBrush 7E418EAB 5 Bytes JMP 6305CBDD C:\WINDOWS\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock Corporation)
.text C:\Program Files\Ideazon\ZEngine\Zboard.exe[2560] USER32.dll!DefWindowProcW 7E428D20 5 Bytes JMP 630019DB C:\WINDOWS\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock Corporation)
.text C:\Program Files\Ideazon\ZEngine\Zboard.exe[2560] USER32.dll!DefWindowProcA 7E42C17E 5 Bytes JMP 630019AC C:\WINDOWS\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock Corporation)
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Documents and Settings\Emmanuel\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3484] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Fastfat \Fat 8E74BD20
—- EOF - GMER 1.0.15 —-
and check up log
Results of screen317's Security Check version 0.99.17
Windows XP Service Pack 3
Internet Explorer 7
Out of date!
``````````````````````````````
Antivirus/Firewall Check:
Windows Firewall Enabled!
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:
Java™ 6 Update 26
Java 2 Runtime Environment, SE v1.4.2_03
Flash Player Out of Date!
Adobe Flash Player 10.1.53.64
````````````````````````````````
Process Check:
objlist.exe by Laurent
``````````End of Log````````````
and attached the file requested!
Thanks again for all your help thus far