This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HijackThis logs

122 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I will appreciate if someone would be able to help me with this. I think I have some problems with my pc being laden with some spywares and/or adwares. Lately, when I reboot my pc it looked for missing 'beatqx81.dll' and also ask to reboot so update can be completed, but after reboot it will still ask for reboot again and again. I just cancel it. Thanks for helping out.


Logfile of HijackThis v1.99.1
Scan saved at 10:18:14 PM, on 1/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe
C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe
C:\New Folder\NCHGBIOS2SVC.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\res.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\00THotkey.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\CTFMON.EXE
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://d.baidu.com/index.php?tn=LordFox
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://securityresponse.symantec.com/avcenter/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://client.jogo.cn/cdn/browser/sidesear…esearch-cn.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://client.jogo.cn/cdn/browser/customse…msearch-cn.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.baidu.com/s?wd=%s&cl=3&tn=LordFox&f=5
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
O2 - BHO: CNNIC ????Drag - {352E3B3A-CAB5-4DBC-B940-C7F84D0447D8} - (no file)
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll (file missing)
O2 - BHO: Schedule Class - {8B316DA1-9950-4926-B9EA-1AEC124AFA45} - (no file)
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FlashGet\getflash.dll
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - (no file)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [res] C:\WINDOWS\system32\res.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v2] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /runonce
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [dfsf] RUNDLL32.EXE C:\WINDOWS\system\Mvvp.dll,DImmcv
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: ???? - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll (file missing)
O9 - Extra 'Tools' menuitem: ???? - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll (file missing)
O9 - Extra button: ??? - {C1F0024B-8278-4999-B7E6-2718426D9FE6} - C:\Program Files\???\caifu.dll (file missing) (HKCU)
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\cdnns.dll' missing
O11 - Options group: [CDNCLIENT] ????
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122799085395
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149591663124
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.telewest.co.uk/motive/files/MotivePreQual.cab
O16 - DPF: {C946EF6D-296D-4907-A6E1-ED0E8E5AF024} (LycosMail Upload Control) - http://lycosmail.lycos.com/hanmail-ax/AttachMail.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{518C1918-DA95-4A79-B798-B8C2D34F9ABA}: NameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{55C7B976-17A7-4768-A31A-8BCD308FA9B2}: NameServer = 192.168.2.1
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WebSecurity - {3DD78ACF-0745-4532-94F8-A574457E1A81} - (no file)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Erdas - Macrovision Corporation - C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe
O23 - Service: ESRI License Manager - Unknown owner - C:\Program Files\ESRI\License\lmgrd.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: NCHGBIOS2SVC - TOSHIBA Corporation - C:\New Folder\NCHGBIOS2SVC.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hi meehailam and welcome to the Forums :)

You're infected…

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Hi, here is the log from combifix. Thanks. "Lam" - 07-01-29 10:25:09 Service Pack 2 ComboFix 07-01-25 - Running from: "C:\HJT" (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\spted.dll C:\WINDOWS\system32\drivers\kvpfuc44.sys C:\WINDOWS\system32\drivers\vj_nsp.sys C:\WINDOWS\system32\vj_nsp.dll C:\WINDOWS\system32\drivers\bdjaddji.sys C:\WINDOWS\system32\advport.dll C:\WINDOWS\system32\d3d1caps.SRG C:\WINDOWS\system32\drivers\acpidisk.sys C:\WINDOWS\system32\drivers\cdntran.sys C:\WINDOWS\system32\iexp_log.txt C:\WINDOWS\system32\mprmsgse.axz C:\WINDOWS\system32\mscpx32r.det C:\WINDOWS\system32\ncxml.dll C:\WINDOWS\system32\nt.sys C:\WINDOWS\system32\rundll.exe C:\WINDOWS\system32\scia.dll C:\WINDOWS\system32\SCIntruder32.dll C:\WINDOWS\system32\Score.txt C:\WINDOWS\system32\spted.dll C:\WINDOWS\system32\wbem\ocmor.dat C:\WINDOWS\system32\wbem\ocmor.dll C:\WINDOWS\Help\WinMail.chm C:\WINDOWS\inf\1394dbg.inf C:\WINDOWS\Debug\bmhrt.log C:\WINDOWS\system32\cryptig.dll C:\WINDOWS\system32\cryptimg.dll C:\WINDOWS\system32\drivers\voodoo.sys C:\DOCUME~1\Lam\Application Data\Macromedia\Flash Player\#SharedObjects\UWXDW87F\www.inter-focus.cn C:\DOCUME~1\Lam\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.inter-focus.cn C:\Program Files\CoolWebsite C:\WINDOWS\system32\wbem\IRJIT.DLL C:\\WINDOWS\system32\drivers\beatqx81.sys C:\WINDOWS\system32\wbem\IRJIT.DLL C:\WINDOWS\system32\wbem\smtpconfs.dll C:\WINDOWS\Temp\~my1.tmp C:\WINDOWS\system32\cdnprot.dat C:\WINDOWS\system32\drivers\cdnprot.sys ((((((((((((((((((((((((((((((( Files Created from 2006-12-29 to 2007-01-29 )))))))))))))))))))))))))))))))))) 2007-01-29 10:29 d——– C:\WINDOWS\erdnt 2007-01-28 22:17 d——– C:\Program Files\Hijackthis 2007-01-28 22:15 d——– C:\HJT 2007-01-28 21:05 d——– C:\Program Files\Common Files\bpfe 2007-01-28 20:43 d——– C:\Program Files\Registry Mechanic 2007-01-28 19:20 8 -r-hs—- C:\WINDOWS\system32\432282CA19.sys 2007-01-28 18:43 d——– C:\Program Files\WinHTTrack 2007-01-27 01:09 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Logs 2007-01-24 09:24 d——– C:\DOCUME~1\ALLUSE~1\Application Data\espionServerData 2007-01-16 08:45 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Adobe 2007-01-12 09:36 d——– C:\WINDOWS\ie7updates 2007-01-08 11:39 11,776 –a—— C:\WINDOWS\system\Mvvp.dll 2007-01-04 15:38 d——– C:\Program Files\PDF2Word v1.4 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-01-29 10:35 ——– d——– C:\Program Files\symantec antivirus 2007-01-29 00:40 ——– d——– C:\Documents and Settings\Lam\Application Data\skype 2007-01-28 21:27 ——– d——– C:\Program Files\selteco 2007-01-28 20:53 ——– d——– C:\Program Files\emule 2007-01-28 19:25 7362 –ahsc— C:\WINDOWS\system32\kgygaavl.sys 2007-01-28 19:15 ——– d–h—– C:\Program Files\installshield installation information 2007-01-28 19:15 ——– d——– C:\Program Files\fileamigo 6.0 2007-01-28 19:03 ——– d——– C:\Documents and Settings\Lam\Application Data\toshiba 2007-01-28 18:54 ——– d——– C:\Program Files\mp3 file editor 2007-01-28 18:42 ——– d——– C:\Program Files\Common Files\adobe 2007-01-28 18:42 ——– d——– C:\Documents and Settings\Lam\Application Data\adobe 2007-01-27 16:33 268 -r-h—– C:\Documents and Settings\Lam\Application Data\stingers 2007-01-27 01:08 ——– d——– C:\Documents and Settings\Lam\Application Data\nikon 2007-01-27 00:54 ——– d——– C:\Program Files\Common Files\nikon 2007-01-27 00:53 ——– d——– C:\Program Files\nikon 2007-01-21 01:22 ——– d——– C:\Program Files\flashget 2007-01-16 08:40 ——– d——– C:\Documents and Settings\Lam\Application Data\adobeum 2006-12-31 14:20 ——– d——– C:\Program Files\freecommander 2006-12-12 11:36 ——– d——– C:\Program Files\lavasoft 2006-12-12 11:36 ——– d——– C:\Documents and Settings\Lam\Application Data\lavasoft 2006-12-07 05:29 2374472 –a—— C:\WINDOWS\system32\wmvcore.dll 2006-12-03 00:12 160384 –a—— C:\WINDOWS\system32\drivers\feachida.sys 2006-11-08 05:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll 2006-11-04 14:14 1245696 –a—— C:\WINDOWS\system32\msxml4.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" "LogitechSoftwareUpdate"="\"C:\\Program Files\\Logitech\\Video\\ManifestEngine.exe\" boot" "Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe" "HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe" "SmoothView"="C:\\Program Files\\TOSHIBA\\TOSHIBA Zooming Utility\\SmoothView.exe" "SigmaTel StacMon"="C:\\Program Files\\SigmaTel\\SigmaTel AC97 Audio Drivers\\stacmon.exe" "Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Enterprise" "ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\"" "vptray"="C:\\PROGRA~1\\SYMANT~1\\VPTray.exe" "PadTouch"="C:\\Program Files\\TOSHIBA\\Touch and Launch\\PadExe.exe" "00THotkey"="C:\\WINDOWS\\system32\\00THotkey.exe" "LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE" "LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe " "LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe" "pdfFactory Pro Dispatcher v2"="\"C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\fppdis2a.exe\" /runonce" "KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\ 65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00 "dfsf"="RUNDLL32.EXE C:\\WINDOWS\\system\\Mvvp.dll,DImmcv" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^blueyonder Instant Support Tool.lnk] "backup"="C:\\WINDOWS\\pss\\blueyonder Instant Support Tool.lnkCommon Startup" "location"="Common Startup" "item"="blueyonder Instant Support Tool" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Cisco Systems VPN Client.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Cisco Systems VPN Client.lnk" "backup"="C:\\WINDOWS\\pss\\Cisco Systems VPN Client.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\CISCOS~1\\VPNCLI~1\\vpngui.exe \"-user_logon\"" "item"="Cisco Systems VPN Client" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk] "backup"="C:\\WINDOWS\\pss\\Logitech Desktop Messenger.lnkCommon Startup" "location"="Common Startup" "item"="Logitech Desktop Messenger" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] "backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup" "location"="Common Startup" "command"="\"C:\\Program Files\\Microsoft Office\\Office\\OSA9.EXE\" -b -l" "item"="Microsoft Office" "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkvMon.exe.lnk] "backup"="C:\\WINDOWS\\pss\\NkvMon.exe.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Nikon\\NkView5\\NkvMon.exe " "item"="NkvMon.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Lam^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk] "backup"="C:\\WINDOWS\\pss\\Microsoft Office OneNote 2003 Quick Launch.lnkStartup" "location"="Startup" "command"="\"C:\\Program Files\\Microsoft Office\\OFFICE11\\ONENOTEM.EXE\" /tsr" "item"="Microsoft Office OneNote 2003 Quick Launch" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\000StTHK] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="000StTHK" "hkey"="HKLM" "command"="000StTHK.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="AGRSMMSG" "hkey"="HKLM" "command"="AGRSMMSG.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Apoint" "hkey"="HKLM" "command"="C:\\Program Files\\Apoint2K\\Apoint.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="InCD" "hkey"="HKLM" "command"="C:\\Program Files\\Ahead\\InCD\\InCD.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iPrint Tray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="iPrint Tray" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\iprntctl.exe TRAY_ICON" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="LanguageShortcut" "hkey"="HKLM" "command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\Language\\Language.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="BackWeb-8876480" "hkey"="HKCU" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ManifestEngine" "hkey"="HKCU" "inimapping"="0" "command"="\"C:\\Program Files\\Logitech\\Video\\ManifestEngine.exe\" boot" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ISStart" "hkey"="HKLM" "inimapping"="0" "command"="C:\\Program Files\\Logitech\\Video\\ISStart.exe " [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="LogiTray" "hkey"="HKLM" "inimapping"="0" "command"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="LVCOMSX" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\LVCOMSX.EXE" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="blueyonder-istnotifier" "hkey"="HKLM" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="msmsgs" "hkey"="HKCU" "command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NeroCheck" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\NeroCheck.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfFactory Pro Dispatcher v2] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="pdfFactory Pro Dispatcher v2" "hkey"="HKLM" "command"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\fppdis2a.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="qttask" "hkey"="HKLM" "command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegClean Expert Scheduler] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RegClean Expert Scheduler" "hkey"="HKCU" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="" "hkey"="HKLM" "command"="" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RemoteControl" "hkey"="HKLM" "command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sdafdsafds] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="D;]XJOEPXT]ufnq]te265/fyf" "hkey"="HKLM" "command"="D;]XJOEPXT]ufnq]te265/fyf" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Skype" "hkey"="HKCU" "command"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TFNF5] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TFNF5" "hkey"="HKLM" "command"="TFNF5.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TkBellExe" "hkey"="HKLM" "command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSCDSPD] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TOSCDSPD" "hkey"="HKCU" "command"="C:\\Program Files\\TOSHIBA\\TOSCDSPD\\toscdspd.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TouchED] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TouchED" "hkey"="HKLM" "command"="C:\\Program Files\\TOSHIBA\\TouchED\\TouchED.Exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPSMain] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TPSMain" "hkey"="HKLM" "command"="TPSMain.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="updateMgr" "hkey"="HKCU" "command"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_8 -reboot 1" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UUPLAYER] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="UUPlayer" "hkey"="HKLM" "command"="C:\\Program Files\\UUSee\\\\UUPlayer.exe -v vermini_x_hy.ini" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Workflow] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Workflow" "hkey"="HKLM" "command"="D:\\Workflow.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ypager" "hkey"="HKCU" "command"="C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe -quiet" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"="Eudora's Shell Extension" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] Source REG_SZ C:\Documents and Settings\Lam\My Documents\Digi Cam Picture\New Folder\DSCN6494.JPG [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 HKLM\software\Microsoft\Windows NT\CurrentVersion\Svchost *netsvcs* Live [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{233e5c60-9086-11db-b755-000cf153e66d}] Shell\Auto\command AdobeR.exe e Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e Completion time: 07-01-29 10:36:27
Hi again, we'll continue :)

You should print these instructions or save these to a text file. Follow these instructions carefully.

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

Download ATF Cleaner by Atribune to your desktop.
Do NOT run yet.

Make your hidden files visible:
  • Go to My Computer
  • Select the Tools menu and click Folder Options
  • Click the View tab.
  • Checkmark the "Display the contents of system folders"
  • Under the Hidden files and folders select "Show hidden files and folders"
  • Uncheck "Hide protected operating system files"
  • Click Apply and then the OK and close My Computer.
==================

Backup your registry:
  • Start
  • Run
  • Type the following to the box and hit Ok: regedit
  • A window opens, click on File
  • Choose Export form the menu
  • Change the save location to C:\
  • Give the filename, RegBackUp
  • Make sure that the filetype is set to Registryfiles (*.reg)
  • Click on Save and Close the window
Open Notepad (NOT WORDPAD!) and copy the following lines from the quote box below into a new document, leaving a blank line at the end. (don't forget to copy and paste the word REGEDIT4) :

REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sdafdsafds]


Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.

Save the document to your desktop as Fix.reg and filetype: All Files
Go to your desktop and double click on the file to run Fix.reg and when it asks you if you want to merge the contents to the registry, click yes/ok.

Run HijackThis, click Do a system scan only, and check the box next to each of these entries if still present. Close all other windows and press Fix checked. If something isn't there, please continue with the next entry in the list. Fix the O6 entry if you haven't locked Internet Explorer settings on purpose.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://d.baidu.com/index.php?tn=LordFox
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://client.jogo.cn/cdn/browser/sidesear…esearch-cn.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://client.jogo.cn/cdn/browser/customse…msearch-cn.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.baidu.com/s?wd=%s&cl=3&tn=LordFox&f=5
O2 - BHO: (no name) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
O2 - BHO: CNNIC ????Drag - {352E3B3A-CAB5-4DBC-B940-C7F84D0447D8} - (no file)
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll (file missing)
O2 - BHO: Schedule Class - {8B316DA1-9950-4926-B9EA-1AEC124AFA45} - (no file)
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - (no file)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [dfsf] RUNDLL32.EXE C:\WINDOWS\system\Mvvp.dll,DImmcv
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: ???? - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll (file missing)
O9 - Extra 'Tools' menuitem: ???? - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll (file missing)
O9 - Extra button: ??? - {C1F0024B-8278-4999-B7E6-2718426D9FE6} - C:\Program Files\???\caifu.dll (file missing) (HKCU)
O11 - Options group: [CDNCLIENT] ????
O21 - SSODL: WebSecurity - {3DD78ACF-0745-4532-94F8-A574457E1A81} - (no file)

Restart your computer to the safe mode:
  • Restart your computer
  • Start tapping the F8 key when the computer restarts.
  • When the start menu opens, choose Safe mode
  • Press Enter. The computer then begins to start in Safe mode.
Go to the My Computer and delete the following files (if present):
C:\WINDOWS\system32\432282CA19.sys
C:\WINDOWS\system\Mvvp.dll

Go to the My Computer and delete the following folders (if present):
C:\Program Files\Common Files\bpfe

Run ATF Cleaner Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.

================

Go to virustotal.com
Copy the following to the box next to "Browse" button:
C:\WINDOWS\system32\drivers\feachida.sys
Click on Send
Wait for the scan to end.

Go to virustotal.com
Copy the following to the box next to "Browse" button:
C:\WINDOWS\system32\res.exe
Click on Send
Wait for the scan to end.

Copy & Paste the scan results to here.

When you're ready, please post the following logs to here:
- AVG's report
- a fresh HijackThis log
- Virustotal results
Hi, done as instructed. When rebooting to normal mode, error loading Mvvp.dll came out. Then proceed to scan the system with virustotal.com. Below are the results for each scan:

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 10:59:11 PM 2/2/2007

+ Scan result:



C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP164\A0100371.sys -> Adware.BDSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP167\A0102139.sys -> Adware.BDSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP167\A0102170.sys -> Adware.BDSearch : Cleaned with backup (quarantined).
C:\WINDOWS\system32\drivers\feachida.sys -> Adware.BDSearch : Cleaned with backup (quarantined).
C:\WINDOWS\system32\wbem\setupcnn.exe -> Adware.Cdnup : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP167\A0102136.sys -> Adware.NewWeb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP167\A0102148.dll -> Adware.NewWeb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP167\A0102168.sys -> Adware.NewWeb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP167\A0102151.dll -> Downloader.Agent.bcd : Cleaned with backup (quarantined).
C:\WINDOWS\system32\drivers\nwlnksipx.sys -> Hijacker.StartPage.amo : Cleaned with backup (quarantined).
C:\Program Files\WinRAR\Patch.exe -> Not-A-Virus.VirTool.Win32.AvSpoffer.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP167\A0102153.sys -> Rootkit.Agent.di : Cleaned with backup (quarantined).
:mozilla.10:C:\Documents and Settings\Lam\Application Data\Mozilla\Firefox\Profiles\u6ac8b2v.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.36:C:\Documents and Settings\Lam\Application Data\Mozilla\Firefox\Profiles\u6ac8b2v.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:C:\Documents and Settings\Lam\Application Data\Mozilla\Firefox\Profiles\u6ac8b2v.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.25:C:\Documents and Settings\Lam\Application Data\Mozilla\Firefox\Profiles\u6ac8b2v.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.43:C:\Documents and Settings\Lam\Application Data\Mozilla\Firefox\Profiles\u6ac8b2v.default\cookies.txt -> TrackingCookie.Centrport : Cleaned.
:mozilla.50:C:\Documents and Settings\Lam\Application Data\Mozilla\Firefox\Profiles\u6ac8b2v.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.27:C:\Documents and Settings\Lam\Application Data\Mozilla\Firefox\Profiles\u6ac8b2v.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.28:C:\Documents and Settings\Lam\Application Data\Mozilla\Firefox\Profiles\u6ac8b2v.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.7:C:\Documents and Settings\Lam\Application Data\Mozilla\Firefox\Profiles\u6ac8b2v.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.


::Report end



Fresh HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 11:23:33 PM, on 2/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\00THotkey.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe
C:\WINDOWS\system\SVCH0ST.EXE
C:\New Folder\NCHGBIOS2SVC.exe
C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shef.ac.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://securityresponse.symantec.com/avcenter/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IEHelp Class - {ED863792-FADB-4D21-8B20-409DA940B7A2} - C:\WINDOWS\system\PDFAid.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FlashGet\getflash.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v2] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /runonce
O4 - HKLM\..\Run: [dfsf] RUNDLL32.EXE C:\WINDOWS\system\Mvvp.dll,DImmcv
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SGMIGEX] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system\WINS0C~1.DLL,Run
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122799085395
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149591663124
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.telewest.co.uk/motive/files/MotivePreQual.cab
O16 - DPF: {C946EF6D-296D-4907-A6E1-ED0E8E5AF024} (LycosMail Upload Control) - http://lycosmail.lycos.com/hanmail-ax/AttachMail.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{518C1918-DA95-4A79-B798-B8C2D34F9ABA}: NameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{55C7B976-17A7-4768-A31A-8BCD308FA9B2}: NameServer = 192.168.2.1
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Erdas - Macrovision Corporation - C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe
O23 - Service: ESRI License Manager - Unknown owner - C:\Program Files\ESRI\License\lmgrd.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MICR0SOFT SVCH0ST (MS_SVCH0ST) - Unknown owner - C:\WINDOWS\system\SVCH0ST.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: NCHGBIOS2SVC - TOSHIBA Corporation - C:\New Folder\NCHGBIOS2SVC.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


Virustotal.com Result for: C:\WINDOWS\system32\drivers\feachida.sys

Antivirus Version Update Result
AntiVir 7.3.1.34 02.02.2007 no virus found
Authentium 4.93.8 02.02.2007 no virus found
Avast 4.7.936.0 02.01.2007 no virus found
AVG 386 02.02.2007 no virus found
BitDefender 7.2 02.02.2007 no virus found
CAT-QuickHeal 9.00 02.02.2007 no virus found
ClamAV devel-20060426 02.02.2007 no virus found
DrWeb 4.33 02.02.2007 no virus found
eSafe 7.0.14.0 02.02.2007 no virus found
eTrust-InoculateIT 30.4.3364 02.02.2007 no virus found
eTrust-Vet 30.4.3364 02.02.2007 no virus found
Ewido 4.0 02.02.2007 no virus found
Fortinet 2.85.0.0 02.02.2007 no virus found
F-Prot 4.2.1.29 02.02.2007 no virus found
Ikarus T3.1.0.31 02.03.2007 no virus found
Kaspersky 4.0.2.24 02.02.2007 no virus found
McAfee 4955 02.02.2007 no virus found
Microsoft 1.2101 02.02.2007 no virus found
NOD32v2 2032 02.02.2007 no virus found
Norman 5.80.02 02.02.2007 no virus found
Panda 9.0.0.4 02.02.2007 no virus found
Prevx1 V2 02.03.2007 no virus found
Sophos 4.13.0 02.02.2007 no virus found
Sunbelt 2.2.907.0 02.02.2007 no virus found
Symantec 10 02.02.2007 no virus found
TheHacker [removed] 02.02.2007 no virus found
UNA 1.83 02.01.2007 no virus found
VBA32 3.11.2 02.02.2007 no virus found
VirusBuster 4.3.19:9 02.02.2007 no virus found


Aditional Information
File size: 0 bytes
MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709



Virustotal.com Result for: C:\WINDOWS\system32\res.exe

Antivirus Version Update Result
AntiVir 7.3.1.34 02.02.2007 TR/Dldr.Agent.aen
Authentium 4.93.8 02.02.2007 no virus found
Avast 4.7.936.0 02.01.2007 Win32:Agent-QC
AVG 386 02.02.2007 no virus found
BitDefender 7.2 02.02.2007 no virus found
CAT-QuickHeal 9.00 02.02.2007 (Suspicious) - DNAScan
ClamAV devel-20060426 02.02.2007 no virus found
DrWeb 4.33 02.02.2007 DLOADER.Trojan
eSafe 7.0.14.0 02.02.2007 no virus found
eTrust-InoculateIT 30.4.3364 02.02.2007 no virus found
eTrust-Vet 30.4.3364 02.02.2007 no virus found
Ewido 4.0 02.02.2007 no virus found
Fortinet 2.85.0.0 02.02.2007 suspicious
F-Prot 4.2.1.29 02.02.2007 no virus found
Ikarus T3.1.0.31 02.03.2007 no virus found
Kaspersky 4.0.2.24 02.02.2007 Trojan-Downloader.Win32.QQHelper.da
McAfee 4955 02.02.2007 no virus found
Microsoft 1.2101 02.02.2007 no virus found
NOD32v2 2032 02.02.2007 a variant of Win32/TrojanDownloader.QQHelper
Norman 5.80.02 02.02.2007 no virus found
Panda 9.0.0.4 02.02.2007 Suspicious file
Prevx1 V2 02.03.2007 no virus found
Sophos 4.13.0 02.02.2007 no virus found
Sunbelt 2.2.907.0 02.02.2007 no virus found
Symantec 10 02.02.2007 no virus found
TheHacker [removed] 02.02.2007 no virus found
UNA 1.83 02.01.2007 no virus found
VBA32 3.11.2 02.02.2007 no virus found
VirusBuster 4.3.19:9 02.02.2007 no virus found


Aditional Information
File size: 199872 bytes
MD5: ca74533e5335f798fae3a45af418059e
SHA1: 41bd6aadcaaf303d0ba5cb9e99947900475258c7


Thanks for your kind help. Looking forward to kill all the infections.
Hi again :)

You're still infected. One of the infections looks like a backdoor trojan. If this system is used for online banking or has credit card information on it, all passwords should be changed immediately by using a different computer (not the infected one!) to make the changes. Banking and credit card institutions, if any, should be notified of the possible security breech. I suggest that you read this article too.

Go to virustotal.com
Copy the following to the box next to "Browse" button:
C:\WINDOWS\system\SVCH0ST.EXE
Click on Send
Wait for the scan to end.

Copy & Paste the scan results to here.

:thumbup:
Hi, here is the result from the scan on 'SVCH0ST.EXE'. Please advice on the next steps. Thank you very much.


Antivirus Version Update Result
AntiVir 7.3.1.34 02.03.2007 TR/Spy.Agent.PV.2
Authentium 4.93.8 02.03.2007 no virus found
Avast 4.7.936.0 02.03.2007 no virus found
AVG 386 02.03.2007 no virus found
BitDefender 7.2 02.03.2007 Trojan.Spy.Agent.PV
CAT-QuickHeal 9.00 02.03.2007 no virus found
ClamAV devel-20060426 02.03.2007 no virus found
DrWeb 4.33 02.03.2007 Trojan.Starter.152
eSafe 7.0.14.0 02.02.2007 no virus found
eTrust-InoculateIT 30.4.3364 02.02.2007 no virus found
eTrust-Vet 30.3.3366 02.03.2007 no virus found
Ewido 4.0 02.03.2007 no virus found
Fortinet 2.85.0.0 02.03.2007 no virus found
F-Prot 4.2.1.29 02.03.2007 no virus found
Ikarus T3.1.0.31 02.03.2007 Trojan.Spy.Agent.PV
Kaspersky 4.0.2.24 02.03.2007 no virus found
McAfee 4955 02.02.2007 no virus found
Microsoft 1.2101 02.03.2007 no virus found
NOD32v2 2035 02.03.2007 no virus found
Norman 5.80.02 02.02.2007 no virus found
Panda 9.0.0.4 02.03.2007 Suspicious file
Prevx1 V2 02.03.2007 Trojan.SystemPoser
Sophos 4.13.0 02.02.2007 no virus found
Sunbelt 2.2.907.0 02.02.2007 no virus found
Symantec 10 02.03.2007 no virus found
TheHacker [removed] 02.02.2007 no virus found
UNA 1.83 02.03.2007 no virus found
VBA32 3.11.2 02.03.2007 no virus found
VirusBuster 4.3.19:9 02.03.2007 no virus found


Aditional Information
File size: 86016 bytes
MD5: d4e2909714cc55dd1c8c91ad4dac0e3e
SHA1: 614dd35147574124222b4eb3f1764380f20a4412
Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PXC=fc6c74818594
Hi again :)

I would like you to upload a malware file for further inspection.

Please go here to upload a suspicious file for analysis.
  • Enter your username from this forum
  • Copy and paste the link to this thread
    • Click "Browse" on the 1. field.
      Browse to the following file and click the file with your mouse, press "Open"
      C:\WINDOWS\system\SVCH0ST.EXE
  • In the comments, please mention that I asked you to upload this file
  • Click on Send File
Thank you :)

Your Norton doesn't have a friewall ? You don't seem to have a third-party firewall installed. You must install one firewall.
It is possible that you're using the Windows XP firewall. That is of course better than nothing but I recommend that you install a more advanced firewall that gives more protection. Windows firewall doesn't eg protect your computer from inbound threats. This means that any malware on your computer is free to "phone home" for more instructions. Remember to use only one firewall at the same time. I'll give you a few alternatives if you want to install a third-party firewall:

These are good (free) firewalls: You should print these instructions or save these to a text file. Follow these instructions carefully.

Download Dr.Web CureIt to the desktop -> ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
Don't use it yet.

Disable the bad service
  • Start
  • Run
  • Type services.msc to the field and press enter.
  • A window opens, scroll down to MICR0SOFT SVCH0ST (MS_SVCH0ST)
  • Rightclick it and choose Stop
  • Then choose Properties
  • Set Startup to Disabled
  • Click Apply and OK.
Then, open HijackThis.
  • Open the Misc Tools section
  • Delete an NT service
  • Copy the following line to the box and press OK; MS_SVCH0ST
  • Answer Yes
  • Close HIjackThis
Run HijackThis, click Do a system scan only, and check the box next to each of these entries if still present. Close all other windows and press Fix checked. If something isn't there, please continue with the next entry in the list.
O4 - HKLM\..\Run: [dfsf] RUNDLL32.EXE C:\WINDOWS\system\Mvvp.dll,DImmcv
O4 - HKCU\..\Run: [SGMIGEX] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system\WINS0C~1.DLL,Run

Continue with HijackThis
  • Open the Misc Tools section
  • Delete a file on Reboot
  • Copy the following line to the filenamebox and press Open; C:\WINDOWS\system\SVCH0ST.EXE
  • Answer NO at the reboot prompt
  • Delete a file on Reboot
  • Copy the following line to the filenamebox and press Open; C:\WINDOWS\system32\res.exe
  • Answer YES at the reboot prompt
  • Reboot the computer if it isn't restarted automatically
Restart your computer to the safe mode:
  • Restart your computer
  • Start tapping the F8 key when the computer restarts.
  • When the start menu opens, choose Safe mode
  • Press Enter. The computer then begins to start in Safe mode.
Run a scan with Dr.Web CureIt
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, you should now mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found [external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable
  • After the scan, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot the computer in Normal Mode,
  • Post the Cure-it report and a fresh HijackThis log
Go to Start >Run and type "Notepad" without the quotes
Copy the text from the quotebox to Notepad.
Go to the menu at the top of the Notepad file and Save as:
  • Name the file peek.bat
  • Save as Type: All files
  • Select the desktop icon on the left to save it on the desktop.
Double click on check.bat and let it run.
When finished it will open a file in Notepad.
That file will be named check.txt, post the contents to here.

if not exist Files MkDir Files

cd \ & dir /s /a /b WINS0C* > check.txt

Start Notepad check.txt

Hi, here are the logs for DrWeb and HijackThis scan:

DrWeb's result:

A0100158.dll;C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP162;Adware.QQHelp;Incurable.Moved.;
A0102135.dll;C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP167;Probably DLOADER.Trojan;Incurable.Moved.;
A0102144.dll;C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP167;Trojan.Proxy.1375;Deleted.;
A0102167.DLL;C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP167;Adware.QQHelp;Incurable.Moved.;
A0102169.dll;C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP167;Adware.QQHelp;Incurable.Moved.;
A0102459.dll;C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP170;Trojan.DownLoader.17349;Deleted.;
A0102468.dll;C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP170;Adware.Minibug;Incurable.Moved.;
A0102469.sys;C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP170;Adware.Cdn;Incurable.Moved.;
A0102470.exe;C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP170;Adware.Cdn;Incurable.Moved.;
A0102530.EXE;C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP172;Trojan.Starter.152;Deleted.;
A0102544.EXE;C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP172;Trojan.Starter.152;Deleted.;
A0102545.exe;C:\System Volume Information\_restore{BF993101-CA26-412C-AE98-70DA6D2FC8DC}\RP172;Probably DLOADER.Trojan;Incurable.Moved.;
MS453.ttf;C:\WINDOWS\Fonts;Trojan.Starter.152;Deleted.;
szdj.dll;C:\WINDOWS\system32;Adware.QQHelp;Incurable.Moved.;
ta.tmp;C:\WINDOWS\system32;Probably DLOADER.Trojan;Incurable.Moved.;
ta.tmp;C:\WINDOWS\system32\wbem;Adware.QQHelp;Incurable.Moved.;


Fresh HJT scan:

Logfile of HijackThis v1.99.1
Scan saved at 9:03:09 PM, on 2/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\00THotkey.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe
C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe
C:\New Folder\NCHGBIOS2SVC.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office\EXCEL.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.7255.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://securityresponse.symantec.com/avcenter/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IEHelp Class - {ED863792-FADB-4D21-8B20-409DA940B7A2} - C:\WINDOWS\system\PDFAid.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FlashGet\getflash.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v2] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /runonce
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122799085395
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149591663124
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.telewest.co.uk/motive/files/MotivePreQual.cab
O16 - DPF: {C946EF6D-296D-4907-A6E1-ED0E8E5AF024} (LycosMail Upload Control) - http://lycosmail.lycos.com/hanmail-ax/AttachMail.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{518C1918-DA95-4A79-B798-B8C2D34F9ABA}: NameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{55C7B976-17A7-4768-A31A-8BCD308FA9B2}: NameServer = 192.168.2.1
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Erdas - Macrovision Corporation - C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe
O23 - Service: ESRI License Manager - Unknown owner - C:\Program Files\ESRI\License\lmgrd.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: NCHGBIOS2SVC - TOSHIBA Corporation - C:\New Folder\NCHGBIOS2SVC.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

I noticed that everytime the laptop rebooted, the webpage is set to something else (such as this time it is : http://www.7255.com/).

Another thing is the final instruction about the "peek.bat" thing, which I figured it may meant to be "check.bat". So I created the file 'check.bat' as per instruction, run it and here is the result:

C:\WINDOWS\system\WINS0CK32.dll

Hope this information is useful. Otherwise please let me know what are the things to do next. Thanks.
Hi again :)

Yes it should have been check.bat, sorry :)

We'll continue…do you have a firewall installed ?

Fix this with HijackThis:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.7255.com/


Open HijackThis.
  • Open the Misc Tools section
  • Delete a file on Reboot
  • Copy the following line to the filenamebox and press Open; C:\WINDOWS\system\WINS0CK32.dll
  • Answer Yes
  • Reboot the computer if it isn't restarted automatically
Please run a GMER Rootkit scan:

Download GMER's application from here:
http://www.gmer.net/gmer.zip

Unzip it and start the GMER.exe
Click the Rootkit tab and click the Scan button.

Once done, click the Copy button.
This will copy the results to your clipboard.
Paste the results in your next reply.

Warning ! Please, do not select the "Show all" checkbox during the scan.

Go to virustotal.com
Copy the following to the box next to "Browse" button:
C:\WINDOWS\system\PDFAid.dll
Click on Send
Wait for the scan to end.

Copy & Paste the scan results to here.

Also post a fresh HijackThis log :thumbup:
Hi, here are the logs:

From Gmer (due to the limit of post length, this result will be divided into several post):

GMER 1.0.12.12027 - http://www.gmer.net
Rootkit scan 2007-02-05 15:59:59
Windows 5.1.2600 Service Pack 2

—- System - GMER 1.0.12 —-

SSDT 893A2F48 ZwAlertResumeThread
SSDT 892F4E40 ZwAlertThread
SSDT 8931AA80 ZwAllocateVirtualMemory
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwClose
SSDT 89342AC8 ZwConnectPort
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwCreateFile
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwCreateKey
SSDT 892FFED0 ZwCreateMutant
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwCreateProcess
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwCreateProcessEx
SSDT 893228F0 ZwCreateThread
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwDeleteFile
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwDeleteKey
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS ZwDeleteValueKey
SSDT 8931A930 ZwFreeVirtualMemory
SSDT 892FFF90 ZwImpersonateAnonymousToken
SSDT 893A2E88 ZwImpersonateThread
SSDT \SystemRoot\system32\drivers\khips.sys ZwLoadDriver
SSDT \SystemRoot\system32\drivers\khips.sys ZwMapViewOfSection
SSDT 89343FD0 ZwOpenEvent
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwOpenFile
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwOpenKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT 89323F48 ZwOpenProcessToken
SSDT 89337ED0 ZwOpenThreadToken
SSDT 89343F00 ZwQueryValueKey
SSDT 892EF898 ZwResumeThread
SSDT 89350FD0 ZwSetContextThread
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwSetInformationFile
SSDT 89337F90 ZwSetInformationProcess
SSDT 89350F10 ZwSetInformationThread
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS ZwSetValueKey
SSDT 89343E40 ZwSuspendProcess
SSDT 892F4F48 ZwSuspendThread
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
SSDT 89350E50 ZwTerminateThread
SSDT 8933BE80 ZwUnmapViewOfSection
SSDT \SystemRoot\system32\drivers\fwdrv.sys ZwWriteFile
SSDT 8931A9B0 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.12 —-

PAGENDSM NDIS.sys!NdisMIndicateStatus F785DA5F 6 Bytes [ FF, 25, 88, 65, 73, B2 ]

—- User code sections - GMER 1.0.12 —-

.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] WS2_32.Dll!socket 71AB3B91 5 Bytes JMP 001308C4
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] WS2_32.Dll!bind 71AB3E00 5 Bytes JMP 00130838
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe[280] WS2_32.Dll!connect 71AB406A 5 Bytes JMP 00130950
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] WS2_32.Dll!socket 71AB3B91 5 Bytes JMP 001308C4
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] WS2_32.Dll!bind 71AB3E00 5 Bytes JMP 00130838
.text C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe[324] WS2_32.Dll!connect 71AB406A 5 Bytes JMP 00130950
.text C:\WINDOWS\system32\LVCOMSX.EXE[336] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8
.text C:\WINDOWS\system32\LVCOMSX.EXE[336] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090
.text C:\WINDOWS\system32\LVCOMSX.EXE[336] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694
.text C:\WINDOWS\system32\LVCOMSX.EXE[336] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0
.text C:\WINDOWS\system32\LVCOMSX.EXE[336] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234
.text C:\WINDOWS\system32\LVCOMSX.EXE[336] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004
.text C:\WINDOWS\system32\LVCOMSX.EXE[336] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C
.text C:\WINDOWS\system32\LVCOMSX.EXE[336] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0
.text C:\WINDOWS\system32\LVCOMSX.EXE[336] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C
.text C:\WINDOWS\system32\LVCOMSX.EXE[336] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8
.text C:\WINDOWS\system32\LVCOMSX.EXE[336] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C
.text C:\WINDOWS\system32\LVCOMSX.EXE[336] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464
.text C:\WINDOWS\system32\LVCOMSX.EXE[336] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608
.text C:\WINDOWS\system32\LVCOMSX.EXE[336] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC
.text C:\WINDOWS\system32\LVCOMSX.EXE[336] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720
.text C:\WINDOWS\system32\alg.exe[340] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000801A8
.text C:\WINDOWS\system32\alg.exe[340] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00080090
.text C:\WINDOWS\system32\alg.exe[340] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00080694
.text C:\WINDOWS\system32\alg.exe[340] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000802C0
.text C:\WINDOWS\system32\alg.exe[340] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00080234
.text C:\WINDOWS\system32\alg.exe[340] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00080004
.text C:\WINDOWS\system32\alg.exe[340] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0008011C
.text C:\WINDOWS\system32\alg.exe[340] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000804F0
.text C:\WINDOWS\system32\alg.exe[340] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0008057C
.text C:\WINDOWS\system32\alg.exe[340] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000803D8
.text C:\WINDOWS\system32\alg.exe[340] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0008034C
.text C:\WINDOWS\system32\alg.exe[340] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00080464
.text C:\WINDOWS\system32\alg.exe[340] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00080608
.text C:\WINDOWS\system32\alg.exe[340] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000807AC
.text C:\WINDOWS\system32\alg.exe[340] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00080720
.text C:\WINDOWS\system32\alg.exe[340] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 000808C4
.text C:\WINDOWS\system32\alg.exe[340] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00080838
.text C:\WINDOWS\system32\alg.exe[340] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00080950
.text C:\WINDOWS\system32\00THotkey.exe[368] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8
.text C:\WINDOWS\system32\00THotkey.exe[368] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090
.text C:\WINDOWS\system32\00THotkey.exe[368] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694
.text C:\WINDOWS\system32\00THotkey.exe[368] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0
.text C:\WINDOWS\system32\00THotkey.exe[368] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234
.text C:\WINDOWS\system32\00THotkey.exe[368] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004
.text C:\WINDOWS\system32\00THotkey.exe[368] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C
.text C:\WINDOWS\system32\00THotkey.exe[368] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0
.text C:\WINDOWS\system32\00THotkey.exe[368] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C
.text C:\WINDOWS\system32\00THotkey.exe[368] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8
.text C:\WINDOWS\system32\00THotkey.exe[368] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C
.text C:\WINDOWS\system32\00THotkey.exe[368] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464
.text C:\WINDOWS\system32\00THotkey.exe[368] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608
.text C:\WINDOWS\system32\00THotkey.exe[368] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC
.text C:\WINDOWS\system32\00THotkey.exe[368] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720
.text C:\WINDOWS\system32\svchost.exe[432] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000801A8
.text C:\WINDOWS\system32\svchost.exe[432] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00080090
.text C:\WINDOWS\system32\svchost.exe[432] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00080694
.text C:\WINDOWS\system32\svchost.exe[432] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000802C0
.text C:\WINDOWS\system32\svchost.exe[432] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00080234
.text C:\WINDOWS\system32\svchost.exe[432] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00080004
.text C:\WINDOWS\system32\svchost.exe[432] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0008011C
.text C:\WINDOWS\system32\svchost.exe[432] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000804F0
.text C:\WINDOWS\system32\svchost.exe[432] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0008057C
.text C:\WINDOWS\system32\svchost.exe[432] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000803D8
.text C:\WINDOWS\system32\svchost.exe[432] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0008034C
.text C:\WINDOWS\system32\svchost.exe[432] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00080464
.text C:\WINDOWS\system32\svchost.exe[432] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00080608
.text C:\WINDOWS\system32\svchost.exe[432] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000807AC
.text C:\WINDOWS\system32\svchost.exe[432] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00080720
.text C:\WINDOWS\system32\svchost.exe[432] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 000808C4
.text C:\WINDOWS\system32\svchost.exe[432] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00080838
.text C:\WINDOWS\system32\svchost.exe[432] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00080950
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000301A8
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00030090
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00030694
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000302C0
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00030234
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00030004
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0003011C
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000304F0
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0003057C
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000303D8
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0003034C
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00030464
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00030608
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000307AC
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00030720
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 000308C4
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00030838
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00030950
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] WININET.dll!InternetConnectA 771C1C6A 5 Bytes JMP 00030F54
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] WININET.dll!InternetConnectW 771C2B63 5 Bytes JMP 00030FE0
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00030D24
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00030DB0
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00030E3C
.text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe[480] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00030EC8
.text C:\New Folder\nchgbios2svc.exe[556] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8
.text C:\New Folder\nchgbios2svc.exe[556] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090
.text C:\New Folder\nchgbios2svc.exe[556] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694
.text C:\New Folder\nchgbios2svc.exe[556] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0
.text C:\New Folder\nchgbios2svc.exe[556] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234
.text C:\New Folder\nchgbios2svc.exe[556] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004
.text C:\New Folder\nchgbios2svc.exe[556] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C
.text C:\New Folder\nchgbios2svc.exe[556] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0
.text C:\New Folder\nchgbios2svc.exe[556] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C
.text C:\New Folder\nchgbios2svc.exe[556] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8
.text C:\New Folder\nchgbios2svc.exe[556] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C
.text C:\New Folder\nchgbios2svc.exe[556] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464
.text C:\New Folder\nchgbios2svc.exe[556] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608
.text C:\WINDOWS\system32\svchost.exe[616] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000801A8
.text C:\WINDOWS\system32\svchost.exe[616] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00080090
.text C:\WINDOWS\system32\svchost.exe[616] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00080694
.text C:\WINDOWS\system32\svchost.exe[616] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000802C0
.text C:\WINDOWS\system32\svchost.exe[616] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00080234
.text C:\WINDOWS\system32\svchost.exe[616] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00080004
.text C:\WINDOWS\system32\svchost.exe[616] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0008011C
.text C:\WINDOWS\system32\svchost.exe[616] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000804F0
.text C:\WINDOWS\system32\svchost.exe[616] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0008057C
.text C:\WINDOWS\system32\svchost.exe[616] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000803D8
.text C:\WINDOWS\system32\svchost.exe[616] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0008034C
.text C:\WINDOWS\system32\svchost.exe[616] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00080464
.text C:\WINDOWS\system32\svchost.exe[616] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00080608
.text C:\WINDOWS\system32\svchost.exe[616] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000807AC
.text C:\WINDOWS\system32\svchost.exe[616] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00080720
.text C:\WINDOWS\system32\svchost.exe[616] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 000808C4
.text C:\WINDOWS\system32\svchost.exe[616] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00080838
.text C:\WINDOWS\system32\svchost.exe[616] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00080950
.text C:\WINDOWS\system32\svchost.exe[616] WININET.dll!InternetConnectA 771C1C6A 5 Bytes JMP 00080F54
.text C:\WINDOWS\system32\svchost.exe[616] WININET.dll!InternetConnectW 771C2B63 5 Bytes JMP 00080FE0
.text C:\WINDOWS\system32\svchost.exe[616] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00080D24
.text C:\WINDOWS\system32\svchost.exe[616] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00080DB0
.text C:\WINDOWS\system32\svchost.exe[616] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00080E3C
.text C:\WINDOWS\system32\svchost.exe[616] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00080EC8
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[644] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[644] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[644] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[644] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[644] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[644] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[644] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[644] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[644] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[644] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[644] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[644] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[644] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[644] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[644] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000801A8
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00080090
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00080694
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000802C0
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00080234
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00080004
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0008011C
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000804F0
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0008057C
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000803D8
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0008034C
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00080464
.text C:\WINDOWS\system32\svchost.exe[680] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00080608
.text C:\WINDOWS\system32\svchost.exe[680] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000807AC
.text C:\WINDOWS\system32\svchost.exe[680] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00080720
.text C:\WINDOWS\system32\rundll32.exe[716] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000801A8
.text C:\WINDOWS\system32\rundll32.exe[716] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00080090
.text C:\WINDOWS\system32\rundll32.exe[716] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00080694
.text C:\WINDOWS\system32\rundll32.exe[716] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000802C0
.text C:\WINDOWS\system32\rundll32.exe[716] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00080234
.text C:\WINDOWS\system32\rundll32.exe[716] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00080004
.text C:\WINDOWS\system32\rundll32.exe[716] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0008011C
.text C:\WINDOWS\system32\rundll32.exe[716] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000804F0
.text C:\WINDOWS\system32\rundll32.exe[716] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0008057C
.text C:\WINDOWS\system32\rundll32.exe[716] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000803D8
.text C:\WINDOWS\system32\rundll32.exe[716] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0008034C
.text C:\WINDOWS\system32\rundll32.exe[716] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00080464
.text C:\WINDOWS\system32\rundll32.exe[716] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00080608
.text C:\WINDOWS\system32\rundll32.exe[716] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000807AC
.text C:\WINDOWS\system32\rundll32.exe[716] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00080720
.text C:\WINDOWS\system32\rundll32.exe[716] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 000808C4
.text C:\WINDOWS\system32\rundll32.exe[716] WS2_32.dll!bind
(continued - Gmer's log) 71AB3E00 5 Bytes JMP 00080838 .text C:\WINDOWS\system32\rundll32.exe[716] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00080950 .text C:\WINDOWS\system32\rundll32.exe[716] WININET.dll!InternetConnectA 771C1C6A 5 Bytes JMP 00080F54 .text C:\WINDOWS\system32\rundll32.exe[716] WININET.dll!InternetConnectW 771C2B63 5 Bytes JMP 00080FE0 .text C:\WINDOWS\system32\rundll32.exe[716] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00080D24 .text C:\WINDOWS\system32\rundll32.exe[716] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00080DB0 .text C:\WINDOWS\system32\rundll32.exe[716] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00080E3C .text C:\WINDOWS\system32\rundll32.exe[716] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00080EC8 .text C:\Program Files\Internet Explorer\iexplore.exe[900] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\Internet Explorer\iexplore.exe[900] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\Internet Explorer\iexplore.exe[900] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\Internet Explorer\iexplore.exe[900] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\Internet Explorer\iexplore.exe[900] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\Internet Explorer\iexplore.exe[900] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\Internet Explorer\iexplore.exe[900] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\Internet Explorer\iexplore.exe[900] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\Internet Explorer\iexplore.exe[900] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\Internet Explorer\iexplore.exe[900] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\Internet Explorer\iexplore.exe[900] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\Internet Explorer\iexplore.exe[900] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\Internet Explorer\iexplore.exe[900] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Program Files\Internet Explorer\iexplore.exe[900] USER32.dll!SetWindowLongA 77D4D60D 5 Bytes JMP 7E38C60B C:\WINDOWS\system32\IEFRAME.dll .text C:\Program Files\Internet Explorer\iexplore.exe[900] USER32.dll!SetWindowLongW 77D4D62B 5 Bytes JMP 7E38C63C C:\WINDOWS\system32\IEFRAME.dll .text C:\Program Files\Internet Explorer\iexplore.exe[900] USER32.dll!DialogBoxParamW 77D5662C 5 Bytes JMP 7E1F5415 C:\WINDOWS\system32\IEFRAME.dll .text C:\Program Files\Internet Explorer\iexplore.exe[900] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\Internet Explorer\iexplore.exe[900] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\Program Files\Internet Explorer\iexplore.exe[900] USER32.dll!DialogBoxIndirectParamW 77D62043 5 Bytes JMP 7E38C510 C:\WINDOWS\system32\IEFRAME.dll .text C:\Program Files\Internet Explorer\iexplore.exe[900] USER32.dll!MessageBoxIndirectA 77D6A05A 5 Bytes JMP 7E38C491 C:\WINDOWS\system32\IEFRAME.dll .text C:\Program Files\Internet Explorer\iexplore.exe[900] USER32.dll!DialogBoxParamA 77D6B11C 5 Bytes JMP 7E38C4D5 C:\WINDOWS\system32\IEFRAME.dll .text C:\Program Files\Internet Explorer\iexplore.exe[900] USER32.dll!MessageBoxExW 77D80538 5 Bytes JMP 7E38C3D9 C:\WINDOWS\system32\IEFRAME.dll .text C:\Program Files\Internet Explorer\iexplore.exe[900] USER32.dll!MessageBoxExA 77D8055C 5 Bytes JMP 7E38C413 C:\WINDOWS\system32\IEFRAME.dll .text C:\Program Files\Internet Explorer\iexplore.exe[900] USER32.dll!DialogBoxIndirectParamA 77D86CAD 5 Bytes JMP 7E38C54B C:\WINDOWS\system32\IEFRAME.dll .text C:\Program Files\Internet Explorer\iexplore.exe[900] USER32.dll!MessageBoxIndirectW 77D96093 5 Bytes JMP 7E38C44D C:\WINDOWS\system32\IEFRAME.dll .text C:\Program Files\Internet Explorer\iexplore.exe[900] WININET.dll!InternetConnectA 771C1C6A 5 Bytes JMP 00130F54 .text C:\Program Files\Internet Explorer\iexplore.exe[900] WININET.dll!InternetConnectW 771C2B63 5 Bytes JMP 00130FE0 .text C:\Program Files\Internet Explorer\iexplore.exe[900] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00130D24 .text C:\Program Files\Internet Explorer\iexplore.exe[900] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00130DB0 .text C:\Program Files\Internet Explorer\iexplore.exe[900] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00130E3C .text C:\Program Files\Internet Explorer\iexplore.exe[900] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00130EC8 .text C:\Program Files\Internet Explorer\iexplore.exe[900] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 001308C4 .text C:\Program Files\Internet Explorer\iexplore.exe[900] ws2_32.dll!bind 71AB3E00 5 Bytes JMP 00130838 .text C:\Program Files\Internet Explorer\iexplore.exe[900] ws2_32.dll!connect 71AB406A 5 Bytes JMP 00130950 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 001308C4 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00130838 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00130950 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] WININET.dll!InternetConnectA 771C1C6A 5 Bytes JMP 00130F54 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] WININET.dll!InternetConnectW 771C2B63 5 Bytes JMP 00130FE0 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00130D24 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00130DB0 .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00130E3C .text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[912] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00130EC8 .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 001308C4 .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00130838 .text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[928] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00130950 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 001308C4 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00130838 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[956] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00130950 .text C:\WINDOWS\system32\wdfmgr.exe[1060] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000701A8 .text C:\WINDOWS\system32\wdfmgr.exe[1060] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00070090 .text C:\WINDOWS\system32\wdfmgr.exe[1060] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00070694 .text C:\WINDOWS\system32\wdfmgr.exe[1060] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000702C0 .text C:\WINDOWS\system32\wdfmgr.exe[1060] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00070234 .text C:\WINDOWS\system32\wdfmgr.exe[1060] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00070004 .text C:\WINDOWS\system32\wdfmgr.exe[1060] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0007011C .text C:\WINDOWS\system32\wdfmgr.exe[1060] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000704F0 .text C:\WINDOWS\system32\wdfmgr.exe[1060] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0007057C .text C:\WINDOWS\system32\wdfmgr.exe[1060] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000703D8 .text C:\WINDOWS\system32\wdfmgr.exe[1060] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0007034C .text C:\WINDOWS\system32\wdfmgr.exe[1060] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00070464 .text C:\WINDOWS\system32\wdfmgr.exe[1060] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00070608 .text C:\WINDOWS\system32\wdfmgr.exe[1060] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000707AC .text C:\WINDOWS\system32\wdfmgr.exe[1060] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00070720 .text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1124] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000701A8 .text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1124] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00070090 .text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1124] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00070694 .text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1124] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000702C0 .text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1124] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00070234 .text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1124] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00070004 .text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1124] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0007011C .text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1124] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000704F0 .text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1124] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0007057C .text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1124] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000703D8 .text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1124] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0007034C .text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1124] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00070464 .text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1124] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00070608 .text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1124] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000707AC .text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1124] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00070720 .text C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe[1204] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe[1204] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe[1204] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe[1204] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe[1204] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe[1204] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe[1204] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe[1204] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe[1204] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe[1204] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe[1204] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe[1204] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe[1204] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe[1204] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe[1204] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\WINDOWS\system32\spoolsv.exe[1404] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000801A8 .text C:\WINDOWS\system32\spoolsv.exe[1404] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00080090 .text C:\WINDOWS\system32\spoolsv.exe[1404] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00080694 .text C:\WINDOWS\system32\spoolsv.exe[1404] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000802C0 .text C:\WINDOWS\system32\spoolsv.exe[1404] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00080234 .text C:\WINDOWS\system32\spoolsv.exe[1404] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00080004 .text C:\WINDOWS\system32\spoolsv.exe[1404] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0008011C .text C:\WINDOWS\system32\spoolsv.exe[1404] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000804F0 .text C:\WINDOWS\system32\spoolsv.exe[1404] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0008057C .text C:\WINDOWS\system32\spoolsv.exe[1404] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000803D8 .text C:\WINDOWS\system32\spoolsv.exe[1404] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0008034C .text C:\WINDOWS\system32\spoolsv.exe[1404] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00080464 .text C:\WINDOWS\system32\spoolsv.exe[1404] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00080608 .text C:\WINDOWS\system32\spoolsv.exe[1404] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000807AC .text C:\WINDOWS\system32\spoolsv.exe[1404] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00080720 .text C:\WINDOWS\system32\spoolsv.exe[1404] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 000808C4 .text C:\WINDOWS\system32\spoolsv.exe[1404] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00080838 .text C:\WINDOWS\system32\spoolsv.exe[1404] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00080950 .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 001308C4 .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00130838 .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00130950 .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe[1452] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\WINDOWS\system32\csrss.exe[1492] KERNEL32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001601A8 .text C:\WINDOWS\system32\csrss.exe[1492] KERNEL32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00160090 .text C:\WINDOWS\system32\csrss.exe[1492] KERNEL32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00160694 .text C:\WINDOWS\system32\csrss.exe[1492] KERNEL32.dll!CreateProcessW 7C802332 5 Bytes JMP 001602C0 .text C:\WINDOWS\system32\csrss.exe[1492] KERNEL32.dll!CreateProcessA 7C802367 5 Bytes JMP 00160234 .text C:\WINDOWS\system32\csrss.exe[1492] KERNEL32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00160004 .text C:\WINDOWS\system32\csrss.exe[1492] KERNEL32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0016011C .text C:\WINDOWS\system32\csrss.exe[1492] KERNEL32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001604F0 .text C:\WINDOWS\system32\csrss.exe[1492] KERNEL32.dll!CreateThread 7C810637 5 Bytes JMP 0016057C .text C:\WINDOWS\system32\csrss.exe[1492] KERNEL32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001603D8 .text C:\WINDOWS\system32\csrss.exe[1492] KERNEL32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0016034C .text C:\WINDOWS\system32\csrss.exe[1492] KERNEL32.dll!WinExec 7C86136D 5 Bytes JMP 00160464 .text C:\WINDOWS\system32\csrss.exe[1492] KERNEL32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00160608 .text C:\WINDOWS\system32\csrss.exe[1492] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001607AC .text C:\WINDOWS\system32\csrss.exe[1492] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00160720 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1496] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1496] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1496] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1496] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1496] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1496] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1496] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1496] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1496] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1496] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1496] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1496] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1496] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1496] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1496] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\WINDOWS\system32\winlogon.exe[1520] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000701A8 .text C:\WINDOWS\system32\winlogon.exe[1520] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00070090 .text C:\WINDOWS\system32\winlogon.exe[1520] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00070694 .text C:\WINDOWS\system32\winlogon.exe[1520] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000702C0 .text C:\WINDOWS\system32\winlogon.exe[1520] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00070234 .text C:\WINDOWS\system32\winlogon.exe[1520] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00070004 .text C:\WINDOWS\system32\winlogon.exe[1520] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0007011C .text C:\WINDOWS\system32\winlogon.exe[1520] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000704F0 .text C:\WINDOWS\system32\winlogon.exe[1520] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0007057C .text C:\WINDOWS\system32\winlogon.exe[1520] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000703D8 .text C:\WINDOWS\system32\winlogon.exe[1520] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0007034C .text C:\WINDOWS\system32\winlogon.exe[1520] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00070464 .text C:\WINDOWS\system32\winlogon.exe[1520] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00070608 .text C:\WINDOWS\system32\winlogon.exe[1520] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000707AC .text C:\WINDOWS\system32\winlogon.exe[1520] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00070720 .text C:\WINDOWS\system32\winlogon.exe[1520] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 000708C4 .text C:\WINDOWS\system32\winlogon.exe[1520] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00070838 .text C:\WINDOWS\system32\winlogon.exe[1520] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00070950 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] WININET.dll!InternetConnectA
(Continued - Gmer's log) 771C1C6A 5 Bytes JMP 00130F54 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] WININET.dll!InternetConnectW 771C2B63 5 Bytes JMP 00130FE0 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00130D24 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00130DB0 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00130E3C .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00130EC8 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 001308C4 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00130838 .text C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe[1532] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00130950 .text C:\WINDOWS\system32\services.exe[1576] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000801A8 .text C:\WINDOWS\system32\services.exe[1576] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00080090 .text C:\WINDOWS\system32\services.exe[1576] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00080694 .text C:\WINDOWS\system32\services.exe[1576] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000802C0 .text C:\WINDOWS\system32\services.exe[1576] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00080234 .text C:\WINDOWS\system32\services.exe[1576] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00080004 .text C:\WINDOWS\system32\services.exe[1576] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0008011C .text C:\WINDOWS\system32\services.exe[1576] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000804F0 .text C:\WINDOWS\system32\services.exe[1576] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0008057C .text C:\WINDOWS\system32\services.exe[1576] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000803D8 .text C:\WINDOWS\system32\services.exe[1576] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0008034C .text C:\WINDOWS\system32\services.exe[1576] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00080464 .text C:\WINDOWS\system32\services.exe[1576] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00080608 .text C:\WINDOWS\system32\services.exe[1576] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000807AC .text C:\WINDOWS\system32\services.exe[1576] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00080720 .text C:\WINDOWS\system32\services.exe[1576] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 000808C4 .text C:\WINDOWS\system32\services.exe[1576] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00080838 .text C:\WINDOWS\system32\services.exe[1576] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00080950 .text C:\WINDOWS\system32\lsass.exe[1592] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000801A8 .text C:\WINDOWS\system32\lsass.exe[1592] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00080090 .text C:\WINDOWS\system32\lsass.exe[1592] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00080694 .text C:\WINDOWS\system32\lsass.exe[1592] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000802C0 .text C:\WINDOWS\system32\lsass.exe[1592] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00080234 .text C:\WINDOWS\system32\lsass.exe[1592] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00080004 .text C:\WINDOWS\system32\lsass.exe[1592] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0008011C .text C:\WINDOWS\system32\lsass.exe[1592] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000804F0 .text C:\WINDOWS\system32\lsass.exe[1592] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0008057C .text C:\WINDOWS\system32\lsass.exe[1592] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000803D8 .text C:\WINDOWS\system32\lsass.exe[1592] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0008034C .text C:\WINDOWS\system32\lsass.exe[1592] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00080464 .text C:\WINDOWS\system32\lsass.exe[1592] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00080608 .text C:\WINDOWS\system32\lsass.exe[1592] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000807AC .text C:\WINDOWS\system32\lsass.exe[1592] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00080720 .text C:\WINDOWS\system32\lsass.exe[1592] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 000808C4 .text C:\WINDOWS\system32\lsass.exe[1592] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00080838 .text C:\WINDOWS\system32\lsass.exe[1592] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00080950 .text C:\Documents and Settings\Lam\My Documents\For HJT\gmer\gmer.exe[1676] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Documents and Settings\Lam\My Documents\For HJT\gmer\gmer.exe[1676] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Documents and Settings\Lam\My Documents\For HJT\gmer\gmer.exe[1676] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Documents and Settings\Lam\My Documents\For HJT\gmer\gmer.exe[1676] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Documents and Settings\Lam\My Documents\For HJT\gmer\gmer.exe[1676] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Documents and Settings\Lam\My Documents\For HJT\gmer\gmer.exe[1676] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Documents and Settings\Lam\My Documents\For HJT\gmer\gmer.exe[1676] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Documents and Settings\Lam\My Documents\For HJT\gmer\gmer.exe[1676] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Documents and Settings\Lam\My Documents\For HJT\gmer\gmer.exe[1676] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Documents and Settings\Lam\My Documents\For HJT\gmer\gmer.exe[1676] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Documents and Settings\Lam\My Documents\For HJT\gmer\gmer.exe[1676] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Documents and Settings\Lam\My Documents\For HJT\gmer\gmer.exe[1676] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Documents and Settings\Lam\My Documents\For HJT\gmer\gmer.exe[1676] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Documents and Settings\Lam\My Documents\For HJT\gmer\gmer.exe[1676] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Documents and Settings\Lam\My Documents\For HJT\gmer\gmer.exe[1676] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\WINDOWS\system32\svchost.exe[1744] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000801A8 .text C:\WINDOWS\system32\svchost.exe[1744] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00080090 .text C:\WINDOWS\system32\svchost.exe[1744] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00080694 .text C:\WINDOWS\system32\svchost.exe[1744] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000802C0 .text C:\WINDOWS\system32\svchost.exe[1744] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00080234 .text C:\WINDOWS\system32\svchost.exe[1744] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00080004 .text C:\WINDOWS\system32\svchost.exe[1744] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0008011C .text C:\WINDOWS\system32\svchost.exe[1744] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000804F0 .text C:\WINDOWS\system32\svchost.exe[1744] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0008057C .text C:\WINDOWS\system32\svchost.exe[1744] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000803D8 .text C:\WINDOWS\system32\svchost.exe[1744] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0008034C .text C:\WINDOWS\system32\svchost.exe[1744] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00080464 .text C:\WINDOWS\system32\svchost.exe[1744] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00080608 .text C:\WINDOWS\system32\svchost.exe[1744] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000807AC .text C:\WINDOWS\system32\svchost.exe[1744] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00080720 .text C:\WINDOWS\system32\svchost.exe[1744] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 000808C4 .text C:\WINDOWS\system32\svchost.exe[1744] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00080838 .text C:\WINDOWS\system32\svchost.exe[1744] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00080950 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 001308C4 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00130838 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00130950 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] WININET.dll!InternetConnectA 771C1C6A 5 Bytes JMP 00130F54 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] WININET.dll!InternetConnectW 771C2B63 5 Bytes JMP 00130FE0 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00130D24 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00130DB0 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00130E3C .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00130EC8 .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe[1780] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000801A8 .text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00080090 .text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00080694 .text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000802C0 .text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00080234 .text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00080004 .text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0008011C .text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000804F0 .text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0008057C .text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000803D8 .text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0008034C .text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00080464 .text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00080608 .text C:\WINDOWS\system32\svchost.exe[1868] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000807AC .text C:\WINDOWS\system32\svchost.exe[1868] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00080720 .text C:\WINDOWS\system32\svchost.exe[1868] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 000808C4 .text C:\WINDOWS\system32\svchost.exe[1868] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00080838 .text C:\WINDOWS\system32\svchost.exe[1868] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00080950 .text C:\WINDOWS\system32\svchost.exe[1924] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000801A8 .text C:\WINDOWS\system32\svchost.exe[1924] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00080090 .text C:\WINDOWS\system32\svchost.exe[1924] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00080694 .text C:\WINDOWS\system32\svchost.exe[1924] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000802C0 .text C:\WINDOWS\system32\svchost.exe[1924] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00080234 .text C:\WINDOWS\system32\svchost.exe[1924] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00080004 .text C:\WINDOWS\system32\svchost.exe[1924] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0008011C .text C:\WINDOWS\system32\svchost.exe[1924] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000804F0 .text C:\WINDOWS\system32\svchost.exe[1924] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0008057C .text C:\WINDOWS\system32\svchost.exe[1924] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000803D8 .text C:\WINDOWS\system32\svchost.exe[1924] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0008034C .text C:\WINDOWS\system32\svchost.exe[1924] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00080464 .text C:\WINDOWS\system32\svchost.exe[1924] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00080608 .text C:\WINDOWS\system32\svchost.exe[1924] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000807AC .text C:\WINDOWS\system32\svchost.exe[1924] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00080720 .text C:\WINDOWS\system32\svchost.exe[1924] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 000808C4 .text C:\WINDOWS\system32\svchost.exe[1924] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00080838 .text C:\WINDOWS\system32\svchost.exe[1924] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00080950 .text C:\WINDOWS\system32\svchost.exe[1924] WININET.dll!InternetConnectA 771C1C6A 5 Bytes JMP 00080F54 .text C:\WINDOWS\system32\svchost.exe[1924] WININET.dll!InternetConnectW 771C2B63 5 Bytes JMP 00080FE0 .text C:\WINDOWS\system32\svchost.exe[1924] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00080D24 .text C:\WINDOWS\system32\svchost.exe[1924] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00080DB0 .text C:\WINDOWS\system32\svchost.exe[1924] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00080E3C .text C:\WINDOWS\system32\svchost.exe[1924] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00080EC8 .text C:\Program Files\Ahead\InCD\InCDsrv.exe[1948] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000701A8 .text C:\Program Files\Ahead\InCD\InCDsrv.exe[1948] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00070090 .text C:\Program Files\Ahead\InCD\InCDsrv.exe[1948] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00070694 .text C:\Program Files\Ahead\InCD\InCDsrv.exe[1948] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000702C0 .text C:\Program Files\Ahead\InCD\InCDsrv.exe[1948] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00070234 .text C:\Program Files\Ahead\InCD\InCDsrv.exe[1948] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00070004 .text C:\Program Files\Ahead\InCD\InCDsrv.exe[1948] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0007011C .text C:\Program Files\Ahead\InCD\InCDsrv.exe[1948] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000704F0 .text C:\Program Files\Ahead\InCD\InCDsrv.exe[1948] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0007057C .text C:\Program Files\Ahead\InCD\InCDsrv.exe[1948] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000703D8 .text C:\Program Files\Ahead\InCD\InCDsrv.exe[1948] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0007034C .text C:\Program Files\Ahead\InCD\InCDsrv.exe[1948] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00070464 .text C:\Program Files\Ahead\InCD\InCDsrv.exe[1948] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00070608 .text C:\Program Files\Ahead\InCD\InCDsrv.exe[1948] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000707AC .text C:\Program Files\Ahead\InCD\InCDsrv.exe[1948] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00070720 .text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1964] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1964] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1964] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1964] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1964] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1964] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1964] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1964] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1964] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1964] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1964] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1964] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1964] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1964] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1964] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\Program Files\Logitech\Video\FxSvr2.exe[2104] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\Logitech\Video\FxSvr2.exe[2104] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\Logitech\Video\FxSvr2.exe[2104] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\Logitech\Video\FxSvr2.exe[2104] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\Logitech\Video\FxSvr2.exe[2104] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\Logitech\Video\FxSvr2.exe[2104] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\Logitech\Video\FxSvr2.exe[2104] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\Logitech\Video\FxSvr2.exe[2104] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\Logitech\Video\FxSvr2.exe[2104] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\Logitech\Video\FxSvr2.exe[2104] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\Logitech\Video\FxSvr2.exe[2104] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\Logitech\Video\FxSvr2.exe[2104] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\Logitech\Video\FxSvr2.exe[2104] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Program Files\Logitech\Video\FxSvr2.exe[2104] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\Logitech\Video\FxSvr2.exe[2104] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\Program Files\Logitech\Video\LogiTray.exe[2340] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\Logitech\Video\LogiTray.exe[2340] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\Logitech\Video\LogiTray.exe[2340] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\Logitech\Video\LogiTray.exe[2340] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\Logitech\Video\LogiTray.exe[2340] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\Logitech\Video\LogiTray.exe[2340] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\Logitech\Video\LogiTray.exe[2340] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\Logitech\Video\LogiTray.exe[2340] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\Logitech\Video\LogiTray.exe[2340] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\Logitech\Video\LogiTray.exe[2340] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\Logitech\Video\LogiTray.exe[2340] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\Logitech\Video\LogiTray.exe[2340] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\Logitech\Video\LogiTray.exe[2340] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Program Files\Logitech\Video\LogiTray.exe[2340] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\Logitech\Video\LogiTray.exe[2340] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis2a.exe[2460] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis2a.exe[2460] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis2a.exe[2460] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis2a.exe[2460] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis2a.exe[2460] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis2a.exe[2460] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis2a.exe[2460] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis2a.exe[2460] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis2a.exe[2460] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis2a.exe[2460] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis2a.exe[2460] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis2a.exe[2460] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis2a.exe[2460] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis2a.exe[2460] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis2a.exe[2460] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\WINDOWS\system32\ctfmon.exe[2524] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000801A8 .text C:\WINDOWS\system32\ctfmon.exe[2524] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00080090 .text C:\WINDOWS\system32\ctfmon.exe[2524] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00080694 .text C:\WINDOWS\system32\ctfmon.exe[2524] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000802C0 .text C:\WINDOWS\system32\ctfmon.exe[2524] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00080234 .text C:\WINDOWS\system32\ctfmon.exe[2524] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00080004 .text C:\WINDOWS\system32\ctfmon.exe[2524] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0008011C .text C:\WINDOWS\system32\ctfmon.exe[2524] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000804F0 .text C:\WINDOWS\system32\ctfmon.exe[2524] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0008057C .text C:\WINDOWS\system32\ctfmon.exe[2524] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000803D8 .text C:\WINDOWS\system32\ctfmon.exe[2524] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0008034C .text C:\WINDOWS\system32\ctfmon.exe[2524] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00080464 .text C:\WINDOWS\system32\ctfmon.exe[2524] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00080608 .text C:\WINDOWS\system32\ctfmon.exe[2524] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000807AC .text C:\WINDOWS\system32\ctfmon.exe[2524] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00080720 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608
(Continued - Gmer's log - final part) .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 001308C4 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00130838 .text C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe[3140] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00130950 .text C:\Program Files\Skype\Phone\Skype.exe[3164] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\Skype\Phone\Skype.exe[3164] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\Skype\Phone\Skype.exe[3164] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\Skype\Phone\Skype.exe[3164] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\Skype\Phone\Skype.exe[3164] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\Skype\Phone\Skype.exe[3164] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\Skype\Phone\Skype.exe[3164] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\Skype\Phone\Skype.exe[3164] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\Skype\Phone\Skype.exe[3164] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\Skype\Phone\Skype.exe[3164] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\Skype\Phone\Skype.exe[3164] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\Skype\Phone\Skype.exe[3164] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\Skype\Phone\Skype.exe[3164] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Program Files\Skype\Phone\Skype.exe[3164] user32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\Skype\Phone\Skype.exe[3164] user32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\Program Files\Skype\Phone\Skype.exe[3164] wininet.dll!InternetConnectA 771C1C6A 5 Bytes JMP 00130F54 .text C:\Program Files\Skype\Phone\Skype.exe[3164] wininet.dll!InternetConnectW 771C2B63 5 Bytes JMP 00130FE0 .text C:\Program Files\Skype\Phone\Skype.exe[3164] wininet.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00130D24 .text C:\Program Files\Skype\Phone\Skype.exe[3164] wininet.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00130DB0 .text C:\Program Files\Skype\Phone\Skype.exe[3164] wininet.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00130E3C .text C:\Program Files\Skype\Phone\Skype.exe[3164] wininet.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00130EC8 .text C:\Program Files\Skype\Phone\Skype.exe[3164] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 001308C4 .text C:\Program Files\Skype\Phone\Skype.exe[3164] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00130838 .text C:\Program Files\Skype\Phone\Skype.exe[3164] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00130950 .text C:\WINDOWS\system32\wuauclt.exe[3440] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000801A8 .text C:\WINDOWS\system32\wuauclt.exe[3440] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00080090 .text C:\WINDOWS\system32\wuauclt.exe[3440] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00080694 .text C:\WINDOWS\system32\wuauclt.exe[3440] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000802C0 .text C:\WINDOWS\system32\wuauclt.exe[3440] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00080234 .text C:\WINDOWS\system32\wuauclt.exe[3440] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00080004 .text C:\WINDOWS\system32\wuauclt.exe[3440] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0008011C .text C:\WINDOWS\system32\wuauclt.exe[3440] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000804F0 .text C:\WINDOWS\system32\wuauclt.exe[3440] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0008057C .text C:\WINDOWS\system32\wuauclt.exe[3440] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000803D8 .text C:\WINDOWS\system32\wuauclt.exe[3440] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0008034C .text C:\WINDOWS\system32\wuauclt.exe[3440] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00080464 .text C:\WINDOWS\system32\wuauclt.exe[3440] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00080608 .text C:\WINDOWS\system32\wuauclt.exe[3440] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000807AC .text C:\WINDOWS\system32\wuauclt.exe[3440] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00080720 .text C:\WINDOWS\system32\wuauclt.exe[3440] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 000808C4 .text C:\WINDOWS\system32\wuauclt.exe[3440] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00080838 .text C:\WINDOWS\system32\wuauclt.exe[3440] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00080950 .text C:\WINDOWS\explorer.exe[3696] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000801A8 .text C:\WINDOWS\explorer.exe[3696] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00080090 .text C:\WINDOWS\explorer.exe[3696] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00080694 .text C:\WINDOWS\explorer.exe[3696] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000802C0 .text C:\WINDOWS\explorer.exe[3696] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00080234 .text C:\WINDOWS\explorer.exe[3696] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00080004 .text C:\WINDOWS\explorer.exe[3696] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0008011C .text C:\WINDOWS\explorer.exe[3696] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000804F0 .text C:\WINDOWS\explorer.exe[3696] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0008057C .text C:\WINDOWS\explorer.exe[3696] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000803D8 .text C:\WINDOWS\explorer.exe[3696] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0008034C .text C:\WINDOWS\explorer.exe[3696] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00080464 .text C:\WINDOWS\explorer.exe[3696] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00080608 .text C:\WINDOWS\explorer.exe[3696] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000807AC .text C:\WINDOWS\explorer.exe[3696] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00080720 .text C:\WINDOWS\explorer.exe[3696] WININET.dll!InternetConnectA 771C1C6A 5 Bytes JMP 00080F54 .text C:\WINDOWS\explorer.exe[3696] WININET.dll!InternetConnectW 771C2B63 5 Bytes JMP 00080FE0 .text C:\WINDOWS\explorer.exe[3696] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00080D24 .text C:\WINDOWS\explorer.exe[3696] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00080DB0 .text C:\WINDOWS\explorer.exe[3696] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00080E3C .text C:\WINDOWS\explorer.exe[3696] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00080EC8 .text C:\WINDOWS\explorer.exe[3696] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 000808C4 .text C:\WINDOWS\explorer.exe[3696] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00080838 .text C:\WINDOWS\explorer.exe[3696] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00080950 .text C:\WINDOWS\system32\igfxtray.exe[3908] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\WINDOWS\system32\igfxtray.exe[3908] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\WINDOWS\system32\igfxtray.exe[3908] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\WINDOWS\system32\igfxtray.exe[3908] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\WINDOWS\system32\igfxtray.exe[3908] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\WINDOWS\system32\igfxtray.exe[3908] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\WINDOWS\system32\igfxtray.exe[3908] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\WINDOWS\system32\igfxtray.exe[3908] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\WINDOWS\system32\igfxtray.exe[3908] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\WINDOWS\system32\igfxtray.exe[3908] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\WINDOWS\system32\igfxtray.exe[3908] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\WINDOWS\system32\igfxtray.exe[3908] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\WINDOWS\system32\igfxtray.exe[3908] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\WINDOWS\system32\igfxtray.exe[3908] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\WINDOWS\system32\igfxtray.exe[3908] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\WINDOWS\system32\hkcmd.exe[3916] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\WINDOWS\system32\hkcmd.exe[3916] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\WINDOWS\system32\hkcmd.exe[3916] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\WINDOWS\system32\hkcmd.exe[3916] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\WINDOWS\system32\hkcmd.exe[3916] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\WINDOWS\system32\hkcmd.exe[3916] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\WINDOWS\system32\hkcmd.exe[3916] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\WINDOWS\system32\hkcmd.exe[3916] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\WINDOWS\system32\hkcmd.exe[3916] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\WINDOWS\system32\hkcmd.exe[3916] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\WINDOWS\system32\hkcmd.exe[3916] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\WINDOWS\system32\hkcmd.exe[3916] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\WINDOWS\system32\hkcmd.exe[3916] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\WINDOWS\system32\hkcmd.exe[3916] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\WINDOWS\system32\hkcmd.exe[3916] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe[3924] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe[3924] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe[3924] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe[3924] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe[3924] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe[3924] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe[3924] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe[3924] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe[3924] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe[3924] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe[3924] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe[3924] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe[3924] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe[3924] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe[3924] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe[3932] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe[3932] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe[3932] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe[3932] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe[3932] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe[3932] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe[3932] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe[3932] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe[3932] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe[3932] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe[3932] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe[3932] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe[3932] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe[3932] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe[3932] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 000701A8 .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00070090 .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00070694 .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000702C0 .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00070234 .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00070004 .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0007011C .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 000704F0 .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0007057C .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 000703D8 .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0007034C .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00070464 .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00070608 .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 000707AC .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00070720 .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 000708C4 .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00070838 .text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3948] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00070950 .text C:\PROGRA~1\SYMANT~1\VPTray.exe[4016] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\PROGRA~1\SYMANT~1\VPTray.exe[4016] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\PROGRA~1\SYMANT~1\VPTray.exe[4016] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\PROGRA~1\SYMANT~1\VPTray.exe[4016] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\PROGRA~1\SYMANT~1\VPTray.exe[4016] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\PROGRA~1\SYMANT~1\VPTray.exe[4016] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\PROGRA~1\SYMANT~1\VPTray.exe[4016] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\PROGRA~1\SYMANT~1\VPTray.exe[4016] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\PROGRA~1\SYMANT~1\VPTray.exe[4016] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\PROGRA~1\SYMANT~1\VPTray.exe[4016] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\PROGRA~1\SYMANT~1\VPTray.exe[4016] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\PROGRA~1\SYMANT~1\VPTray.exe[4016] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\PROGRA~1\SYMANT~1\VPTray.exe[4016] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\PROGRA~1\SYMANT~1\VPTray.exe[4016] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\PROGRA~1\SYMANT~1\VPTray.exe[4016] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001301A8 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00130090 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] kernel32.dll!WriteProcessMemory 7C80220F 5 Bytes JMP 00130694 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001302C0 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00130234 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] kernel32.dll!VirtualAlloc 7C809A51 5 Bytes JMP 00130004 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] kernel32.dll!VirtualAllocEx 7C809A72 5 Bytes JMP 0013011C .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] kernel32.dll!CreateRemoteThread 7C81042C 5 Bytes JMP 001304F0 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] kernel32.dll!CreateThread 7C810637 5 Bytes JMP 0013057C .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] kernel32.dll!CreateProcessInternalW 7C819513 5 Bytes JMP 001303D8 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] kernel32.dll!CreateProcessInternalA 7C81DDD6 5 Bytes JMP 0013034C .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00130464 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] kernel32.dll!SetThreadContext 7C862AA5 5 Bytes JMP 00130608 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] USER32.dll!SetWindowsHookExW 77D5E4AF 5 Bytes JMP 001307AC .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] USER32.dll!SetWindowsHookExA 77D611E9 5 Bytes JMP 00130720 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 001308C4 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] WS2_32.dll!bind 71AB3E00 5 Bytes JMP 00130838 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00130950 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] WININET.dll!InternetConnectA 771C1C6A 5 Bytes JMP 00130F54 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] WININET.dll!InternetConnectW 771C2B63 5 Bytes JMP 00130FE0 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00130D24 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00130DB0 .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00130E3C .text C:\Program Files\Toshiba\Touch and Launch\PadExe.exe[4072] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00130EC8 —- Registry - GMER 1.0.12 —- Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{18D6E519-4C27-E4AD-074C5D1F171B40FB}\{8D7A772B-93EE-6905-4C751BA1B544AFC9}\{7029C73E-0020-BA9C-F3FADF03D99AF0E6}@{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1 0x01 0x00 0x01 0x00 … Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{4D36E769-B7A1-49B0-7FF57AC1710650DC}\{A2C50D74-0103-0472-B4B4032F319B5A49}\{CF55CBC2-03B6-AE3E-9F7994016B214C0B}@{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1 0x01 0x00 0x01 0x00 … Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{E4568B1F-886D-9AB5-1E4B01E7F0FA32FF}\{B2981650-D0BF-E14F-9D9AB95C0FC2939B}\{CDC4F2F4-402E-87A1-4EFD68E3BEB8F4B3}@NRDFOBLVNAUE2QOGEQXAH1Y2DD1 0x01 0x00 0x01 0x00 … Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{FE8DBE89-D247-CDA0-331071706D351D5D}\{D7E03019-A44C-9829-6C33C3798CE56E87}\{A96D9761-82B1-07BB-8B5956B67D5931EC}@NRDFOBLVNAUE2QOGEQXAH1Y2DD1 0x01 0x00 0x01 0x00 … —- Files - GMER 1.0.12 —- ADS C:\Documents and Settings\Lam\Favorites\comic\good-:favicon ADS C:\Documents and Settings\Lam\Favorites\comic\good-:favicon ADS C:\Documents and Settings\Lam\Favorites\comic\good-:favicon ADS C:\Documents and Settings\Lam\Favorites\comic\:favicon ADS C:\Documents and Settings\Lam\Favorites\comic\:favicon ADS C:\Documents and Settings\Lam\Favorites\comic\:favicon ADS C:\Documents and Settings\Lam\Favorites\comic\:favicon ADS C:\Documents and Settings\Lam\Favorites\comic\:favicon ADS C:\Documents and Settings\Lam\Favorites\comic\:favicon ADS C:\Documents and Settings\Lam\Favorites\comic\:favicon ADS C:\Documents and Settings\Lam\Favorites\comic\:favicon ADS … —- EOF - GMER 1.0.12 —-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI