This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

removing OuterInfo from my browser

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Yes, I have misread the log..

any other suggestions for the quarantined files?


Delete all the contents of this folder: C:\Program Files\Trend Micro\Internet Security 2007\Quarantine

Empty your recycle bin.

________________________________

Download Gmer
  • Disconnect from internet and close running programs.
  • There is a small chance this application may crash your computer so save any work you have open.
  • Double click gmer.exe
  • Let the gmer.sys driver load if asked.
  • If it gives you a warning at program start about rootkit activity and asks if you want to run scan…say Ok.
  • If no warning….
  • Click "Rootkit" tab and click "Scan"
  • Once done, click "Copy"
  • Open Notepad and hit "ctrl+v" to paste the log.
  • Reconnect to the internet and post the log back to this thread please.
Download, unzip and run 'RootkitRevealer' from Sysinternals:
http://www.sysinternals.com/Utilities/RootkitRevealer.html

Once the program has started, press Scan and let it run.
When the scan is done, use 'File' > 'Save' to place the logfile in a convenient location (such as the desktop). The default file name will be 'RootkitReveal.txt'.

Save your Log File.
Copy/Paste the contents of that logfile into your next reply.

DO NOT touch the PC at ALL for Whatever reason/s until it has 100% completed its scan, or attempted scan in case of some error etc. !

On your next reply, include a fresh HijackThis log along with the Gmer log and the rootkitrevealer log.
round five complete…

hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 11:57:17 AM, on 1/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\SPYWAR~1\swdoctor.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\twstuff\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://itreg.sel.sony.com/sonysrvysa.asp?M…ture=03/11/2005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [VZRemoteCommander] C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [TVTunerLib] C:\Program Files\Common Files\Sony Shared\TVTunerLib\TVTLInstTool.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [CreateCD_Reminder] C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Transfer by Image Converter 2 - C:\Program Files\Sony\Image Converter 2\menu.htm
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone: http://www.surveymonkey.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2B36F775-8CF5-4489-B454-2D1B80984CF2} (FXPluginCtl Object) - http://www.powerflasher.de/plugin/powerres.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1165985048703
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1165985029468
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\vaio entertainment\VzTaskScheduler.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)

gmer log:

GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2007-01-13 11:22:31
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.12 —-

SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess

—- User code sections - GMER 1.0.12 —-

.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[124] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[124] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[124] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[124] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[124] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[188] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[188] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[188] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[188] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[188] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[344] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[344] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[344] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[344] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[344] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[360] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[360] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[360] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[360] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[360] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\QuickTime\qttask.exe[372] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\QuickTime\qttask.exe[372] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\QuickTime\qttask.exe[372] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\QuickTime\qttask.exe[372] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\QuickTime\qttask.exe[372] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[420] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[420] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[420] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[420] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[420] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Common Files\Logitech\QCDriver3\lvcoms.exe[428] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Common Files\Logitech\QCDriver3\lvcoms.exe[428] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Common Files\Logitech\QCDriver3\lvcoms.exe[428] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Common Files\Logitech\QCDriver3\lvcoms.exe[428] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Common Files\Logitech\QCDriver3\lvcoms.exe[428] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[440] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[440] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[532] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[532] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[532] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[532] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[532] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Logitech\ImageStudio\LogiTray.exe[556] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Logitech\ImageStudio\LogiTray.exe[556] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Logitech\ImageStudio\LogiTray.exe[556] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Logitech\ImageStudio\LogiTray.exe[556] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Logitech\ImageStudio\LogiTray.exe[556] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\iTunes\iTunesHelper.exe[628] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\iTunes\iTunesHelper.exe[628] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\iTunes\iTunesHelper.exe[628] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\iTunes\iTunesHelper.exe[628] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\iTunes\iTunesHelper.exe[628] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[696] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[696] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[696] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[696] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[696] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\explorer.exe[764] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\explorer.exe[764] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\explorer.exe[764] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\explorer.exe[764] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\explorer.exe[764] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[808] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[808] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[808] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[808] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[808] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] KERNEL32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] KERNEL32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] KERNEL32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[836] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[836] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[836] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[836] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[836] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\services.exe[880] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\services.exe[880] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\services.exe[880] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\services.exe[880] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\services.exe[880] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\lsass.exe[892] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\lsass.exe[892] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\lsass.exe[892] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\lsass.exe[892] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\lsass.exe[892] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[1000] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[1000] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[1000] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[1000] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[1000] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1072] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1072] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[1080] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[1080] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[1080] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[1080] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[1080] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1144] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1144] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1180] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1180] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1216] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1216] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1216] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1216] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1216] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[1224] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[1224] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[1224] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[1224] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[1224] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1316] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1316] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1316] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1316] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1316] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1368] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1368] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1468] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1468] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1468] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1468] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1468] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[1608] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[1608] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[1608] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[1608] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[1608] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe[1620] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe[1620] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe[1620] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe[1620] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe[1620] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1720] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1720] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1720] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1720] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1720] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1816] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1816] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1816] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1816] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1816] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[1888] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, CC, 77 ]
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[1888] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, F8, 77 ]
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[1888] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, D2, 77 ]
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[1888] USER32.DLL!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, CF, 77 ]
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[1888] USER32.DLL!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, C9, 77 ]
.text C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe[1952] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe[1952] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe[1952] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe[1952] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe[1952] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[1976] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[1976] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[1976] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[1976] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[1976] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[1988] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 0A, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[1988] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 14, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[1988] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 10, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[1988] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0D, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[1988] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 07, 5F ]
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[1996] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[1996] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[1996] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[1996] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[1996] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[2076] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[2076] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[2076] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[2076] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[2076] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe[2116] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe[2116] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe[2116] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe[2116] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe[2116] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2312] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2312] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2312] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2312] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2312] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe[2324] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe[2324] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe[2324] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe[2324] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe[2324] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Apoint\ApntEx.exe[2364] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Apoint\ApntEx.exe[2364] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Apoint\ApntEx.exe[2364] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Apoint\ApntEx.exe[2364] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Apoint\ApntEx.exe[2364] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe[2544] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe[2544] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe[2544] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe[2544] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe[2544] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe[2824] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe[2824] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe[2824] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe[2824] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe[2824] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\iPod\bin\iPodService.exe[3096] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\iPod\bin\iPodService.exe[3096] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\iPod\bin\iPodService.exe[3096] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\iPod\bin\iPodService.exe[3096] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\iPod\bin\iPodService.exe[3096] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe[3164] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 0A, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe[3164] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 14, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe[3164] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 10, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe[3164] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0D, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe[3164] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 07, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3200] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3200] kernel32.dll!
thought i put it in, sorry… HKLM\SECURITY\Policy\Secrets\SAC* 3/9/2005 3:05 PM 0 bytes Key name contains embedded nulls (*) HKLM\SECURITY\Policy\Secrets\SAI* 3/9/2005 3:05 PM 0 bytes Key name contains embedded nulls (*) HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\VAIO_VEDB\MSSQLServer\uptime_time_utc 1/13/2007 11:26 AM 8 bytes Data mismatch between Windows API and raw hive data. HKLM\SOFTWARE\TrendMicro\PC-cillin\15\ScanInfo\LastScanFile 1/13/2007 11:27 AM 58 bytes Windows API length not consistent with raw hive data.
Sorry, I forgot to tell you earlier, the GMER log you posted was incomplete. Please ensure that you post the whole log. Use separate posts if needed.
gmer log:

GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2007-01-13 11:22:31
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.12 —-

SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess

—- User code sections - GMER 1.0.12 —-

.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[124] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[124] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[124] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[124] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[124] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[188] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[188] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[188] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[188] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Logitech\Video\LogiTray.exe[188] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[344] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[344] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[344] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[344] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[344] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[360] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[360] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[360] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[360] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[360] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\QuickTime\qttask.exe[372] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\QuickTime\qttask.exe[372] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\QuickTime\qttask.exe[372] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\QuickTime\qttask.exe[372] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\QuickTime\qttask.exe[372] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[420] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[420] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[420] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[420] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\LVCOMSX.EXE[420] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Common Files\Logitech\QCDriver3\lvcoms.exe[428] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Common Files\Logitech\QCDriver3\lvcoms.exe[428] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Common Files\Logitech\QCDriver3\lvcoms.exe[428] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Common Files\Logitech\QCDriver3\lvcoms.exe[428] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Common Files\Logitech\QCDriver3\lvcoms.exe[428] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[440] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[440] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[532] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[532] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[532] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[532] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe[532] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Logitech\ImageStudio\LogiTray.exe[556] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Logitech\ImageStudio\LogiTray.exe[556] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Logitech\ImageStudio\LogiTray.exe[556] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Logitech\ImageStudio\LogiTray.exe[556] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Logitech\ImageStudio\LogiTray.exe[556] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\iTunes\iTunesHelper.exe[628] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\iTunes\iTunesHelper.exe[628] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\iTunes\iTunesHelper.exe[628] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\iTunes\iTunesHelper.exe[628] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\iTunes\iTunesHelper.exe[628] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[696] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[696] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[696] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[696] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe[696] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\explorer.exe[764] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\explorer.exe[764] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\explorer.exe[764] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\explorer.exe[764] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\explorer.exe[764] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[808] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[808] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[808] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[808] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Java\jre1.6.0\bin\jusched.exe[808] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] KERNEL32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] KERNEL32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] KERNEL32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[836] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[836] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[836] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[836] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[836] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\services.exe[880] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\services.exe[880] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\services.exe[880] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\services.exe[880] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\services.exe[880] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\lsass.exe[892] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\lsass.exe[892] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\lsass.exe[892] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\lsass.exe[892] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\lsass.exe[892] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\twstuff\hijackthis\hosts_gmer\gmer.exe[952] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[1000] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[1000] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[1000] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[1000] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[1000] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1072] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1072] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[1080] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[1080] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[1080] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[1080] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Sony\ISB Utility\ISBMgr.exe[1080] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1144] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1144] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1144] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1180] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1180] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1216] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1216] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1216] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1216] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1216] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[1224] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[1224] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[1224] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[1224] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Sony\VAIO Event Service\VESMgr.exe[1224] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1316] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1316] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1316] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1316] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1316] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1368] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1368] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1468] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1468] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1468] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1468] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1468] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[1608] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[1608] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[1608] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[1608] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[1608] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe[1620] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe[1620] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe[1620] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe[1620] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe[1620] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1720] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1720] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1720] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1720] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1720] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1816] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1816] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1816] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1816] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1816] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[1888] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, CC, 77 ]
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[1888] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, F8, 77 ]
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[1888] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, D2, 77 ]
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[1888] USER32.DLL!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, CF, 77 ]
.text C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe[1888] USER32.DLL!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, C9, 77 ]
.text C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe[1952] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe[1952] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe[1952] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe[1952] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe[1952] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[1976] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[1976] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[1976] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[1976] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[1976] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[1988] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 0A, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[1988] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 14, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[1988] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 10, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[1988] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0D, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe[1988] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 07, 5F ]
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[1996] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[1996] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[1996] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[1996] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe[1996] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[2076] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[2076] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[2076] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[2076] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[2076] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe[2116] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe[2116] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe[2116] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe[2116] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe[2116] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2312] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2312] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2312] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2312] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Logitech\Video\FxSvr2.exe[2312] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe[2324] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe[2324] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe[2324] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe[2324] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe[2324] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Apoint\ApntEx.exe[2364] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Apoint\ApntEx.exe[2364] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Apoint\ApntEx.exe[2364] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Apoint\ApntEx.exe[2364] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Apoint\ApntEx.exe[2364] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe[2460] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe[2544] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe[2544] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe[2544] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe[2544] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe[2544] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe[2824] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe[2824] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe[2824] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe[2824] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe[2824] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\iPod\bin\iPodService.exe[3096] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Program Files\iPod\bin\iPodService.exe[3096] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Program Files\iPod\bin\iPodService.exe[3096] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\Program Files\iPod\bin\iPodService.exe[3096] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Program Files\iPod\bin\iPodService.exe[3096] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe[3164] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 0A, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe[3164] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 14, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe[3164] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 10, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe[3164] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0D, 5F ]
.text C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe[3164] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 07, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3200] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3200] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3200] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3200] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3200] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[3696] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[3696] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[3696] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[3696] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[3696] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRA~1\SPYWAR~1\swdoctor.exe[3796] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRA~1\SPYWAR~1\swdoctor.exe[3796] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\PROGRA~1\SPYWAR~1\swdoctor.exe[3796] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 0E, 5F ]
.text C:\PROGRA~1\SPYWAR~1\swdoctor.exe[3796] USER32.dll!SetWindowsHookExW 77D5E4AF 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRA~1\SPYWAR~1\swdoctor.exe[3796] USER32.dll!SetWindowsHookExA 77D611E9 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]

—- EOF - GMER 1.0.12 —-
Your logs really look good…I think your issues are no longer malware related..

You can register in this site for PC troubleshooting: www.pcpitstop.com


Configure Windows Xp to hide system files:
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading, select Do not show hidden files and folders.
  • Check the Hide protected operating system files option.
  • Click Yes to confirm.
  • Click OK.
_______________________
This is a good time to clear your existing system restore points and establish a new clean restore point:
  • Go to Start > All Programs > Accessories > System Tools > System Restore
  • Select Create a restore point, and Ok it.
  • Next, go to Start > Run and type in cleanmgr
  • Select the More options tab
  • Choose the option to clean up system restore and OK it.

    This will remove all restore points except the new one you just created.
______________________
Here are some free programs I recommend that could help you improve your pc's security.

Adaware
~You can download it from here
~There is a tutorial on how to use Adaware properly here

Install Spyware Guard
~You can download it from here
~You can read the tutorial on how to use Spyware Guard here

Install SpyWare Blaster
~You can download it from here
~You can read the tutorial on how to use Spyware Blaster here

Install WinPatrol
~You can download it from here
~You can get some information about how WinPatrol works here

Note: Make sure you update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Please check out Tony Klein's article "How did I get infected in the first place?"

Happy safe surfing!
excellent. now for a few more questions. do i keep the tools i downloaded to get stuff cleaned up? also, i have another pc that is more messed up than the first one; i assume that would require another discussion thread? would i start diagnosing the same way i did for this one? thanks for all your help. everything worked as prescribed.

do i keep the tools i downloaded to get stuff cleaned up?


You need to delete those tools but you may keep AVG Antispyware as it has a very good on-demand scanner that you can use weekly..You can also keep CCleaner to empty your temporary internet files which eats up a lot of space..Run it in a weekly basis too..

also, i have another pc that is more messed up than the first one; i assume that would require another discussion thread?


I would love to help if I could but I don't have the time right now.. You need to create a separate topic for it..

would i start diagnosing the same way i did for this one?


No..Wait for an authorized helper to answer your log and guide you through the process..Inappropriate actions can lead to dangers for your system..Some of those tools are dangerous if misused..

thanks for all your help.


You're most welcome :)
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI