nvm. deleted spybot and a few other programs then ran cc cleaner. not sure what worked but it did.
DDS.txt:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_18
Run by [removed] at 21:08:24 on 2011-11-25
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.663 [GMT -5:00]
.
AV: Spyware Doctor with AntiVirus *Enabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
AV: Malware Defense *Enabled/Outdated* {28e00e3b-806e-4533-925c-f4c3d79514b9}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe
C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = ;*.local
uURLSearchHooks: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aim search\AOLSearch.dll
uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: {0E3C6776-34EF-4BA2-8E5F-61043B87C44e} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aim search\AOLSearch.dll
BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [MSN Toolbar] "c:\program files\msn toolbar\platform\4.0.0379.0\mswinext.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [1A:Stardock TrayMonitor]
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRunServices: [JavaTMNative] c:\docume~1\g\locals~1\temp\qrub.exe
mRunServices: [jnidispatchNative] c:\docume~1\g\locals~1\temp\qrub.exe
mRunServices: [jnidispatchSetup3.2.1] c:\docume~1\g\locals~1\temp\qrub.exe
mRunServices: [Accessjnidispatch] c:\docume~1\g\locals~1\temp\qrub.exe
mRunServices: [JavaTMjnidispatch] c:\docume~1\g\locals~1\temp\qrub.exe
mRunServices: [jinstallAccess] c:\docume~1\g\locals~1\temp\qrub.exe
mRunServices: [AccessAccess] c:\docume~1\g\locals~1\temp\qrub.exe
mRunServices: [jnidispatchAccess] c:\docume~1\g\locals~1\temp\qrub.exe
mRunServices: [1A:Stardock TrayMonitor]
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {32564D57-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmv8dmo.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: Interfaces\{15E83E8B-2BC8-424E-A8EE-7A5693A9F170} : NameServer = 8.8.8.8
TCP: Interfaces\{15E83E8B-2BC8-424E-A8EE-7A5693A9F170} : DhcpNameServer = 192.168.1.1 [removed]
TCP: Interfaces\{C7FAE210-CA8D-4B58-9BCB-964BF8C8A213} : NameServer = 8.8.8.8
AppInit_DLLs: c:\windows\system32\kbduk32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\g\application data\mozilla\firefox\profiles\ofyymiss.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=ConduitEngine&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Conduit Engine Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - component: c:\documents and settings\g\application data\mozilla\firefox\profiles\ofyymiss.default\extensions\[removed]\components\RadioWMPCore.dll
FF - component: c:\documents and settings\g\application data\mozilla\firefox\profiles\ofyymiss.default\extensions\[removed]\components\RadioWMPCoreGecko19.dll
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\3.0.50106.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
.
—- FIREFOX POLICIES —-
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(yahoo.homepage.dontask, true
============= SERVICES / DRIVERS ===============
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-1-23 218592]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\spyware doctor\bdt\BDTUpdateService.exe [2010-2-10 112592]
R4 SDHookDriver;Spybot-S&D 2 Hook Driver;\??\c:\program files\spybot - search & destroy 2\sdhookdrv32.sys –> c:\program files\spybot - search & destroy 2\SDHookDrv32.sys [?]
S0 ahts;ahts;c:\windows\system32\drivers\coajp.sys –> c:\windows\system32\drivers\coajp.sys [?]
S0 boacw;boacw;c:\windows\system32\drivers\ugmlgjwg.sys –> c:\windows\system32\drivers\ugmlgjwg.sys [?]
S0 cxer;cxer;c:\windows\system32\drivers\xfioc.sys –> c:\windows\system32\drivers\xfioc.sys [?]
S0 vcraurjg;vcraurjg;c:\windows\system32\drivers\miboiph.sys –> c:\windows\system32\drivers\miboiph.sys [?]
S2 RasAuto32;Remote Access Auto Connection Manager ;c:\windows\system32\stobject32.exe –> c:\windows\system32\stobject32.exe [?]
S2 srv804;srv804;c:\windows\system32\svchost.exe -k netsvcs [2001-8-23 14336]
S3 Andbus;LGE Android Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [2010-3-8 14336]
S3 AndDiag;LGE Android USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [2010-3-8 20864]
S3 AndGps;LGE Android USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [2010-3-8 19968]
S3 ANDModem;LGE Android USB Modem;c:\windows\system32\drivers\lgandmodem.sys [2010-3-8 24960]
S3 androidusb;ADB Interface Driver;c:\windows\system32\drivers\lgandadb.sys [2010-1-11 25728]
S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\drivers\motfilt.sys [2010-9-10 6016]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2010-9-10 19712]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2010-9-10 8320]
S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\drivers\Motousbnet.sys [2010-9-10 23296]
S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\drivers\motusbdevice.sys [2010-9-10 6656]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2011-1-28 18432]
S3 pneteth;PdaNet Broadband;c:\windows\system32\drivers\pneteth.sys [2011-3-23 13312]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2010-2-10 366840]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2010-2-10 1142224]
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
2011-08-31 22:00:50 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-08-28 22:38:29 1180 —-a-w- c:\documents and settings\g\Quarantine.reg
.
============= FINISH: 21:08:47.82 ===============
Attach.txt:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 10/20/2009 12:51:47 PM
System Uptime: 11/25/2011 7:39:18 PM (2 hours ago)
.
Motherboard: Intel Corporation | | MPAD-MSAE Customer Reference Boards
Processor: Genuine Intel® CPU T2050 @ 1.60GHz | U1 | 1595/mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 74 GiB total, 13.266 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 233 GiB total, 116.397 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Video Controller (VGA Compatible)
Device ID: PCI\VEN_8086&DEV_27A2&SUBSYS_FF101179&REV_03\3&B1BFB68&0&10
Manufacturer:
Name: Video Controller (VGA Compatible)
PNP Device ID: PCI\VEN_8086&DEV_27A2&SUBSYS_FF101179&REV_03\3&B1BFB68&0&10
Service:
.
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Video Controller
Device ID: PCI\VEN_8086&DEV_27A6&SUBSYS_FF101179&REV_03\3&B1BFB68&0&11
Manufacturer:
Name: Video Controller
PNP Device ID: PCI\VEN_8086&DEV_27A6&SUBSYS_FF101179&REV_03\3&B1BFB68&0&11
Service:
.
Class GUID:
Description: Modem Device on High Definition Audio Bus
Device ID: HDAUDIO\FUNC_02&VEN_11C1&DEV_3026&SUBSYS_11790001&REV_1007\4&1E09AF89&0&0101
Manufacturer:
Name: Modem Device on High Definition Audio Bus
PNP Device ID: HDAUDIO\FUNC_02&VEN_11C1&DEV_3026&SUBSYS_11790001&REV_1007\4&1E09AF89&0&0101
Service:
.
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Mass Storage Controller
Device ID: PCI\VEN_104C&DEV_803B&SUBSYS_FF101179&REV_00\4&6B16D5B&0&32F0
Manufacturer:
Name: Mass Storage Controller
PNP Device ID: PCI\VEN_104C&DEV_803B&SUBSYS_FF101179&REV_00\4&6B16D5B&0&32F0
Service:
.
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: SM Bus Controller
Device ID: PCI\VEN_8086&DEV_27DA&SUBSYS_FF101179&REV_02\3&B1BFB68&0&FB
Manufacturer:
Name: SM Bus Controller
PNP Device ID: PCI\VEN_8086&DEV_27DA&SUBSYS_FF101179&REV_02\3&B1BFB68&0&FB
Service:
.
==== System Restore Points ===================
.
RP578: 8/27/2011 7:30:09 PM - System Checkpoint
RP579: 8/28/2011 9:53:50 PM - System Checkpoint
RP580: 8/30/2011 1:32:47 AM - System Checkpoint
RP581: 8/31/2011 1:51:57 AM - System Checkpoint
RP582: 9/1/2011 12:46:40 PM - System Checkpoint
RP583: 9/2/2011 1:15:46 PM - System Checkpoint
RP584: 9/3/2011 1:27:22 PM - System Checkpoint
RP585: 9/4/2011 1:28:52 PM - System Checkpoint
RP586: 9/5/2011 1:29:47 PM - System Checkpoint
RP587: 9/6/2011 1:36:36 PM - System Checkpoint
RP588: 9/7/2011 2:33:02 PM - System Checkpoint
RP589: 9/8/2011 3:08:26 PM - System Checkpoint
RP590: 9/9/2011 3:34:10 PM - System Checkpoint
RP591: 9/10/2011 4:34:17 PM - System Checkpoint
RP592: 9/11/2011 4:39:43 PM - System Checkpoint
RP593: 9/12/2011 4:40:46 PM - System Checkpoint
RP594: 9/13/2011 4:55:35 PM - System Checkpoint
RP595: 9/14/2011 5:42:49 PM - System Checkpoint
RP596: 9/15/2011 5:43:56 PM - System Checkpoint
RP597: 9/16/2011 7:32:58 PM - System Checkpoint
RP598: 9/19/2011 4:36:16 PM - System Checkpoint
RP599: 9/20/2011 4:38:45 PM - System Checkpoint
RP600: 9/21/2011 4:39:46 PM - System Checkpoint
RP601: 9/22/2011 6:02:50 PM - System Checkpoint
RP602: 9/23/2011 11:28:05 PM - System Checkpoint
RP603: 9/25/2011 12:26:06 AM - System Checkpoint
RP604: 9/26/2011 12:53:55 AM - System Checkpoint
RP605: 9/27/2011 2:02:04 AM - System Checkpoint
RP606: 9/28/2011 2:36:45 AM - System Checkpoint
RP607: 9/29/2011 3:39:43 AM - System Checkpoint
RP608: 9/30/2011 4:15:14 AM - System Checkpoint
RP609: 10/1/2011 12:58:51 PM - System Checkpoint
RP610: 10/2/2011 1:46:35 PM - System Checkpoint
RP611: 10/3/2011 3:00:22 PM - System Checkpoint
RP612: 10/4/2011 3:58:10 PM - System Checkpoint
RP613: 10/5/2011 4:04:57 PM - System Checkpoint
RP614: 10/6/2011 5:03:53 PM - System Checkpoint
RP615: 10/7/2011 5:04:48 PM - System Checkpoint
RP616: 10/8/2011 6:29:24 PM - System Checkpoint
RP617: 10/9/2011 7:14:53 PM - System Checkpoint
RP618: 10/10/2011 8:14:58 PM - System Checkpoint
RP619: 10/11/2011 8:16:21 PM - System Checkpoint
RP620: 10/12/2011 9:16:22 PM - System Checkpoint
RP621: 10/13/2011 10:16:22 PM - System Checkpoint
RP622: 10/14/2011 10:17:22 PM - System Checkpoint
RP623: 10/16/2011 12:19:16 AM - System Checkpoint
RP624: 10/17/2011 4:48:07 PM - System Checkpoint
RP625: 10/18/2011 5:20:30 PM - System Checkpoint
RP626: 10/19/2011 5:21:29 PM - System Checkpoint
RP627: 10/20/2011 6:21:26 PM - System Checkpoint
RP628: 10/21/2011 9:55:07 PM - System Checkpoint
RP629: 10/22/2011 10:19:07 PM - System Checkpoint
RP630: 10/23/2011 10:48:45 PM - System Checkpoint
RP631: 10/24/2011 11:49:49 PM - System Checkpoint
RP632: 10/26/2011 12:48:45 AM - System Checkpoint
RP633: 10/27/2011 12:49:47 AM - System Checkpoint
RP634: 10/28/2011 1:49:48 AM - System Checkpoint
RP635: 10/29/2011 2:47:07 AM - System Checkpoint
RP636: 10/31/2011 9:20:56 PM - System Checkpoint
RP637: 11/1/2011 11:19:52 PM - System Checkpoint
RP638: 11/2/2011 11:58:52 PM - System Checkpoint
RP639: 11/4/2011 12:46:15 AM - System Checkpoint
RP640: 11/5/2011 1:46:18 AM - System Checkpoint
RP641: 11/6/2011 12:56:18 AM - System Checkpoint
RP642: 11/7/2011 1:23:46 AM - System Checkpoint
RP643: 11/8/2011 2:23:52 AM - System Checkpoint
RP644: 11/9/2011 3:05:34 AM - System Checkpoint
RP645: 11/10/2011 4:05:33 AM - System Checkpoint
RP646: 11/11/2011 10:57:59 PM - System Checkpoint
RP647: 11/12/2011 11:32:03 PM - System Checkpoint
RP648: 11/14/2011 2:23:37 AM - System Checkpoint
RP649: 11/15/2011 2:35:38 AM - System Checkpoint
RP650: 11/16/2011 3:35:31 AM - System Checkpoint
RP651: 11/17/2011 3:36:34 AM - System Checkpoint
RP652: 11/18/2011 4:36:32 AM - System Checkpoint
RP653: 11/19/2011 5:36:39 AM - System Checkpoint
RP654: 11/20/2011 5:51:13 AM - System Checkpoint
RP655: 11/21/2011 5:51:44 AM - System Checkpoint
RP656: 11/22/2011 7:01:36 AM - System Checkpoint
RP657: 11/23/2011 9:26:29 PM - System Checkpoint
RP658: 11/24/2011 11:47:35 PM - System Checkpoint
RP659: 11/25/2011 9:03:18 PM - Removed BlackBerry Desktop Software 5.0.
.
==== Installed Programs ======================
.
µTorrent
7-Zip 4.65
ACDSee
Acrobat.com
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Reader 9.4.2 MUI
AIM Search
Amazon Kindle
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Bonjour
Browser Defender 2.0.6.15
CASIO USB Driver V1.2.2474.0623
CCleaner
Codec Pack - All In 1 6.0.3.0
Comical 0.8
Compatibility Pack for the 2007 Office system
Conduit Engine
DivX Setup
Download Updater (AOL LLC)
High Definition Audio Driver Package - KB888111
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Intel® PRO Network Connections Drivers
Intel® PROSet/Wireless Software
iTunes
Jasc Paint Shop Pro 9
Java Auto Updater
Java™ 6 Update 18
LG Android Drivers
LG USB Modem driver
LimeWire 5.5.16
Malwarebytes' Anti-Malware version 1.51.2.1300
mCore
mDrWiFi
Media Library Management Wizard
mHelp
Microsoft Default Manager
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft UI Engine
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft WinUsb 1.0
Microsoft Word 2000
Microsoft Works 2000
Microsoft Works 2000 Setup Launcher
mIWA
mLogView
mMHouse
Motorola Driver Installation 3.9.0
Movie Maker Background Music Files
Movie Maker Sound Effects
Movie Maker Title Images
Mozilla Firefox 5.0 (x86 en-US)
Mozilla Firefox 8.0 (x86 en-US)
mPfMgr
mPfWiz
mProSafe
MSN Toolbar
MSN Toolbar Platform
mWlsSafe
mXML
mZConfig
Pantech Handset Driver
PeerGuardian 2.0
Personal License Update Wizard for Windows Media Player
PicaView
Plus! MP3 Audio Converter LE
QuickTime
Realtek High Definition Audio Driver
SAMSUNG Mobile USB DRIVER(4.40.7.0) v1.6
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB976325)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB981349)
Spotify
Spyware Doctor 7.0
Steam
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB976749)
Update for Windows XP (KB978207)
Update for Windows XP (KB980182)
uTorrentBar Toolbar
VC80CRTRedist - 8.0.50727.4053
VLC media player 1.1.11
WebFldrs XP
Winamp
Winamp Detector Plug-in
Windows Live ID Sign-in Assistant
Windows Media Bonus Pack for Windows XP
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player Playlist Import to Excel Wizard
Windows Media Player Skin Importer
Windows Media Player Tray Control
Windows XP Service Pack 3
WModem Driver Installer
Word in Works Suite add-in
.
==== Event Viewer Messages From Past Week ========
.
11/25/2011 9:05:29 PM, error: Service Control Manager [7034] - The Spybot S&D 2 Live Protection Service service terminated unexpectedly. It has done this 1 time(s).
11/25/2011 8:40:02 PM, error: Service Control Manager [7034] - The PC Tools Security Service service terminated unexpectedly. It has done this 1 time(s).
11/21/2011 7:01:11 PM, error: Service Control Manager [7023] - The srv804 service terminated with the following error: The specified procedure could not be found.
11/21/2011 5:35:12 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
11/21/2011 4:01:55 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
11/20/2011 9:47:53 PM, error: Dhcp [1002] - The IP address lease 192.168.0.103 for the Network Card with network address 00A0D1582507 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
11/20/2011 12:47:40 PM, error: Dhcp [1002] - The IP address lease 192.168.0.102 for the Network Card with network address 00A0D1582507 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
11/20/2011 11:28:04 AM, error: Dhcp [1002] - The IP address lease 192.168.0.106 for the Network Card with network address 00A0D1582507 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
11/19/2011 5:05:18 PM, error: Dhcp [1002] - The IP address lease 192.168.0.105 for the Network Card with network address 0018DE47D054 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
.
==== End Of File ===========================
Gmer.txt:
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-11-25 21:18:05
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 HTS541080G9SA00 rev.MB4OC60R
Running: gmer.exe; Driver: C:\DOCUME~1\g\LOCALS~1\Temp\uwldiaod.sys
—- System - GMER 1.0.15 —-
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateKey [0xF736E112]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xF734D2D6]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xF734D4C8]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteKey [0xF736E900]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteValueKey [0xF736EBB4]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwOpenKey [0xF736CE12]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xF736F020]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwSetValueKey [0xF736E3D2]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xF734CF44]
—- Kernel code sections - GMER 1.0.15 —-
.text ntoskrnl.exe!ZwYieldExecution + 172 804E49CC 4 Bytes JMP A2804107
? C:\Program Files\Spybot - Search & Destroy 2\SDHookDrv32.sys The system cannot find the file specified. !
? C:\DOCUME~1\g\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\System32\svchost.exe[220] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00DB0001
.text C:\WINDOWS\system32\spoolsv.exe[436] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 015A0001
.text C:\DOCUME~1\g\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[608] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003C0001
.text C:\DOCUME~1\g\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[608] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0D0F5A
.text C:\DOCUME~1\g\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[608] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\DOCUME~1\g\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[608] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\DOCUME~1\g\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[608] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [0B, 5F]
.text C:\DOCUME~1\g\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[608] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F100F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[748] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00950001
.text C:\WINDOWS\System32\svchost.exe[824] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 008D0001
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[864] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00870001
.text C:\WINDOWS\Explorer.EXE[880] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00D90001
.text C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe[892] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 017C0001
.text …
.text C:\WINDOWS\System32\alg.exe[2140] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\System32\alg.exe[2140] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\System32\alg.exe[2140] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\alg.exe[2140] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [0B, 5F]
.text C:\WINDOWS\System32\alg.exe[2140] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F100F5A
.text C:\Program Files\iPod\bin\iPodService.exe[2688] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 008C0001
.text C:\Program Files\iPod\bin\iPodService.exe[2688] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\iPod\bin\iPodService.exe[2688] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\Program Files\iPod\bin\iPodService.exe[2688] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\iPod\bin\iPodService.exe[2688] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [0B, 5F]
.text C:\Program Files\iPod\bin\iPodService.exe[2688] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\wscntfy.exe[2824] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 009C0001
.text C:\WINDOWS\system32\wscntfy.exe[2824] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\wscntfy.exe[2824] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\wscntfy.exe[2824] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\wscntfy.exe[2824] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\wscntfy.exe[2824] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F100F5A
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3152] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00EA0001
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3152] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0B0F5A
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3152] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3152] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3152] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [09, 5F]
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3152] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F0E0F5A
.text C:\WINDOWS\System32\msiexec.exe[3980] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003B0001
.text C:\WINDOWS\System32\msiexec.exe[3980] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\System32\msiexec.exe[3980] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\System32\msiexec.exe[3980] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\msiexec.exe[3980] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [0B, 5F]
.text C:\WINDOWS\System32\msiexec.exe[3980] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F100F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[4324] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 013E2EC0 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[4324] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003D0001
.text C:\Program Files\Mozilla Firefox\firefox.exe[4324] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[4324] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[4324] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[4324] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [0B, 5F]
.text C:\Program Files\Mozilla Firefox\firefox.exe[4324] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\RTHDCPL.EXE[4804] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01C20001
.text C:\WINDOWS\RTHDCPL.EXE[4804] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0B0F5A
.text C:\WINDOWS\RTHDCPL.EXE[4804] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\RTHDCPL.EXE[4804] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\RTHDCPL.EXE[4804] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [09, 5F]
.text C:\WINDOWS\RTHDCPL.EXE[4804] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F0E0F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[4840] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01140001
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[4840] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0B0F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[4840] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[4840] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[4840] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [09, 5F]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[4840] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F0E0F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[4848] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01040001
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[4848] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0B0F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[4848] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[4848] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[4848] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [09, 5F]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[4848] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F0E0F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[4872] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00B90001
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[4872] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0B0F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[4872] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[4872] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[4872] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [09, 5F]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[4872] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F0E0F5A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4944] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00D40001
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4944] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0B0F5A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4944] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4944] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4944] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [09, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4944] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F0E0F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4980] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 007E0001
.text C:\Program Files\Winamp\winampa.exe[5032] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00AC0001
.text C:\Program Files\Winamp\winampa.exe[5032] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0B0F5A
.text C:\Program Files\Winamp\winampa.exe[5032] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\Program Files\Winamp\winampa.exe[5032] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Winamp\winampa.exe[5032] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [09, 5F]
.text C:\Program Files\Winamp\winampa.exe[5032] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F0E0F5A
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[5044] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00C90001
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[5044] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0B0F5A
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[5044] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[5044] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[5044] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [09, 5F]
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[5044] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F0E0F5A
.text C:\Program Files\iTunes\iTunesHelper.exe[5052] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00BB0001
.text C:\Program Files\iTunes\iTunesHelper.exe[5052] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0B0F5A
.text C:\Program Files\iTunes\iTunesHelper.exe[5052] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\Program Files\iTunes\iTunesHelper.exe[5052] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\iTunes\iTunesHelper.exe[5052] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [09, 5F]
.text C:\Program Files\iTunes\iTunesHelper.exe[5052] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F0E0F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[6068] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00AC0001
.text C:\WINDOWS\system32\NOTEPAD.EXE[6068] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[6068] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[6068] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\NOTEPAD.EXE[6068] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\NOTEPAD.EXE[6068] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[7104] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00AC0001
.text C:\WINDOWS\system32\NOTEPAD.EXE[7104] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[7104] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[7104] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\NOTEPAD.EXE[7104] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\NOTEPAD.EXE[7104] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F100F5A
.text C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe[7792] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003F0001
.text C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe[7792] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe[7792] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe[7792] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe[7792] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [0B, 5F]
.text C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe[7792] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F100F5A
—- Devices - GMER 1.0.15 —-
Device \Driver\PCTSDInjDriver32 \Device\PCTSDInjDriver32 PCTSDInj32.sys
—- EOF - GMER 1.0.15 —-