Here is the first scan:
GMER 1.0.12.12244 -
http://www.gmer.net
Rootkit scan 2007-04-30 10:38:05
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.12 ----
SSDT E1AF2F30 ZwConnectPort
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
---- Kernel code sections - GMER 1.0.12 ----
? C:\WINDOWS\System32\DRIVERS\update.sys
---- User code sections - GMER 1.0.12 ----
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetDeviceCaps 77F15A7A 5 Bytes JMP 003293CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SelectObject 77F15B80 5 Bytes JMP 003262CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetTextColor 77F15D87 5 Bytes JMP 0032654C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetBkColor 77F15E39 5 Bytes JMP 003264CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetBkMode 77F15EEB 5 Bytes JMP 003268CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!CreateCompatibleDC 77F15FF0 5 Bytes JMP 00327B4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PolyPatBlt 77F162C1 5 Bytes JMP 0032C84C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!IntersectClipRect 77F16A66 5 Bytes JMP 0032A84C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetClipBox 77F16AB1 5 Bytes JMP 0032904C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetClipRgn 77F16AE6 5 Bytes JMP 003271CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetTextExtentPointW 77F16B1D 5 Bytes JMP 0032A5CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!BitBlt 77F16F89 5 Bytes JMP 003260CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!CreateCompatibleBitmap 77F1701A 5 Bytes JMP 00327ACC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!ExtSelectClipRgn 77F17884 5 Bytes JMP 0032C2CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SelectClipRgn 77F17AB0 5 Bytes JMP 0032724C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!OffsetWindowOrgEx 77F17ACB 5 Bytes JMP 0032AC4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetViewportOrgEx 77F17B5C 5 Bytes JMP 00326A4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetViewportOrgEx 77F17C11 5 Bytes JMP 00326ECC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetWindowExtEx 77F17C89 5 Bytes JMP 00326F4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetViewportExtEx 77F17D01 5 Bytes JMP 00326E4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetTextMetricsW 77F17DC9 5 Bytes JMP 0032A7CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!TextOutW 77F17EBC 5 Bytes JMP 0032BF4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetTextExtentPoint32W 77F17FAD 5 Bytes JMP 0032A4CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!ExtTextOutW 77F18036 5 Bytes JMP 003285CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!RectVisible 77F181CB 5 Bytes JMP 0032AECC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetCurrentObject 77F182ED 5 Bytes JMP 003272CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SelectPalette 77F1832A 5 Bytes JMP 0032B2CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetTextCharsetInfo 77F18444 5 Bytes JMP 0032A2CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PatBlt 77F18593 5 Bytes JMP 0032C44C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetBrushOrgEx 77F186E4 5 Bytes JMP 0032714C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!RestoreDC 77F18A11 5 Bytes JMP 003273CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SaveDC 77F18AD7 5 Bytes JMP 0032734C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetTextAlign 77F18B74 5 Bytes JMP 0032BBCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetWindowOrgEx 77F18CFD 5 Bytes JMP 00326B4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetMapMode 77F18DD5 5 Bytes JMP 00326CCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetDIBitsToDevice 77F1900C 5 Bytes JMP 0032C0CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!CreateDIBSection 77F19219 5 Bytes JMP 00327BCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetBkColor 77F193A5 5 Bytes JMP 003266CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetTextColor 77F193F9 5 Bytes JMP 0032674C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!ExcludeClipRect 77F19536 5 Bytes JMP 0032844C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetStretchBltMode 77F19581 5 Bytes JMP 0032BACC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetMapMode 77F199EA 5 Bytes JMP 0032684C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetTextFaceW 77F19A97 5 Bytes JMP 0032A6CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetTextCharset 77F1A089 5 Bytes JMP 0032A24C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetNearestColor 77F1A176 5 Bytes JMP 00329C4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetBrushOrgEx 77F1A29D 5 Bytes JMP 003270CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetDIBits 77F1A779 5 Bytes JMP 0032CCCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!CreateDIBitmap 77F1A905 5 Bytes JMP 00327C4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetDIBits 77F1AABB 5 Bytes JMP 0032934C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetDIBColorTable 77F1AC3D 5 Bytes JMP 003292CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!MaskBlt 77F1AC6A 5 Bytes JMP 0032614C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!MoveToEx 77F1ADC3 5 Bytes JMP 0032AACC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!StretchDIBits 77F1B03F 5 Bytes JMP 0032624C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!CreateHalftonePalette 77F1B2DD 5 Bytes JMP 00327D4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetSystemPaletteEntries 77F1B2F1 5 Bytes JMP 0032A04C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetPixel 77F1B441 5 Bytes JMP 00329E4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetPixel 77F1B4C7 5 Bytes JMP 0032B8CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetPixelV 77F1B590 5 Bytes JMP 0032B9CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!ModifyWorldTransform 77F1B7F6 5 Bytes JMP 0032AA4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetGraphicsMode 77F1B88B 5 Bytes JMP 003267CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetWorldTransform 77F1B956 5 Bytes JMP 00326BCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetWorldTransform 77F1B971 5 Bytes JMP 0032704C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!StretchBlt 77F1BAC2 5 Bytes JMP 003261CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!TextOutA 77F1BBDC 5 Bytes JMP 0032BECC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!EnumFontFamiliesExW 77F1BC22 5 Bytes JMP 0032814C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!FrameRgn 77F1BFB0 5 Bytes JMP 0032884C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!OffsetViewportOrgEx 77F1C03F 5 Bytes JMP 0032ABCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetDCBrushColor 77F1C22B 5 Bytes JMP 003263CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!ExtEscape 77F1C3F5 5 Bytes JMP 0032C24C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetBoundsRect 77F1D27A 5 Bytes JMP 003289CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetBoundsRect 77F1D29C 5 Bytes JMP 0032B3CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!ExtTextOutA 77F1D422 5 Bytes JMP 0032854C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetTextAlign 77F1D44F 5 Bytes JMP 0032A14C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!LPtoDP 77F1D4EF 5 Bytes JMP 0032A94C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetROP2 77F1D8F8 5 Bytes JMP 0032694C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!LineTo 77F1D9BF 5 Bytes JMP 0032A9CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetDCOrgEx 77F1DA17 5 Bytes JMP 0032924C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetWindowOrgEx 77F1DA46 5 Bytes JMP 00326FCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!InvertRgn 77F1DB47 5 Bytes JMP 0032A8CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetTextMetricsA 77F1DC1F 5 Bytes JMP 0032A74C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!FillRgn 77F1DCF5 5 Bytes JMP 0032C34C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!Polyline 77F1DD5D 5 Bytes JMP 0032CB4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetCharABCWidthsW 77F1DD99 5 Bytes JMP 00328BCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetTextExtentPointA 77F1DF7A 5 Bytes JMP 0032A54C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetOutlineTextMetricsW 77F1E42B 5 Bytes JMP 00329D4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetSystemPaletteUse 77F1E4D2 5 Bytes JMP 0032A0CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetICMMode 77F1E4F3 5 Bytes JMP 0032B5CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!Rectangle 77F1E649 5 Bytes JMP 0032AF4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!RealizePalette 77F1E6E6 5 Bytes JMP 0032AE4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!Polygon 77F1E714 5 Bytes JMP 0032CACC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetROP2 77F1E929 5 Bytes JMP 00326DCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!DPtoLP 77F1EA9E 5 Bytes JMP 00327DCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetTextCharacterExtra 77F1EB2A 5 Bytes JMP 0032BC4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetCharWidthA 77F1EDC8 5 Bytes JMP 00328D4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetFontData 77F1F258 5 Bytes JMP 003294CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetTextFaceA 77F1F2A9 5 Bytes JMP 0032A64C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetOutlineTextMetricsA 77F1F385 5 Bytes JMP 00329CCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetCharWidthW 77F1F7A9 5 Bytes JMP 00328ECC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!DeleteEnhMetaFile 77F1FE86 5 Bytes JMP 00325ECC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetEnhMetaFileHeader 77F20325 5 Bytes JMP 0032604C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetTextJustification 77F204B0 5 Bytes JMP 0032BCCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetMetaRgn 77F2053F 5 Bytes JMP 0032B7CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetPolyFillMode 77F20B04 5 Bytes JMP 0032BA4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetArcDirection 77F2116A 5 Bytes JMP 0032B34C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetMiterLimit 77F2118B 5 Bytes JMP 0032B84C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PlayEnhMetaFileRecord 77F21223 5 Bytes JMP 0032C4CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetPixelFormat 77F22901 5 Bytes JMP 00329ECC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!CreateEnhMetaFileW 77F22C2D 5 Bytes JMP 00325CCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!CloseEnhMetaFile 77F2319C 5 Bytes JMP 00325D4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetBkMode 77F23849 5 Bytes JMP 00326D4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetArcDirection 77F2389C 5 Bytes JMP 003288CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetPolyFillMode 77F238B6 5 Bytes JMP 00329F4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetMiterLimit 77F23A58 5 Bytes JMP 00329BCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetWindowExtEx 77F23B03 5 Bytes JMP 00326ACC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetViewportExtEx 77F23BAC 5 Bytes JMP 003269CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetGraphicsMode 77F23FA7 5 Bytes JMP 00326C4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!CreateEnhMetaFileA 77F24692 5 Bytes JMP 00325C4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PlayMetaFileRecord 77F248B2 5 Bytes JMP 0032C5CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!Escape 77F273B4 5 Bytes JMP 0032C1CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!EnumObjects 77F2766B 5 Bytes JMP 003283CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!CloseMetaFile 77F27E59 5 Bytes JMP 0032794C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!EnumFontFamiliesA 77F29B90 5 Bytes JMP 00327FCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!ResetDCW 77F2C209 5 Bytes JMP 0032B04C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetTextExtentPoint32A 77F2C2A7 5 Bytes JMP 0032A44C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetDIBColorTable 77F2C36D 5 Bytes JMP 0032CC4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetTextCharacterExtra 77F2C3BE 5 Bytes JMP 0032A1CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!Ellipse 77F2C48F 5 Bytes JMP 00327F4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetColorSpace 77F2CCE0 5 Bytes JMP 0032B4CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SelectClipPath 77F2CE71 5 Bytes JMP 0032B24C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!OffsetClipRgn 77F2CFB3 5 Bytes JMP 0032AB4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!BeginPath 77F2D682 5 Bytes JMP 0032764C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!EndPath 77F2D702 5 Bytes JMP 0032C14C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!CancelDC 77F2E17C 5 Bytes JMP 003276CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PolyBezierTo 77F2E83F 5 Bytes JMP 0032C74C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PolylineTo 77F2E8EC 5 Bytes JMP 0032CBCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!CloseFigure 77F2E988 5 Bytes JMP 003278CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!StrokeAndFillPath 77F2EA08 5 Bytes JMP 0032BD4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetCurrentPositionEx 77F2EAE3 5 Bytes JMP 003291CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetCharWidth32W 77F2EC6B 5 Bytes JMP 00328CCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PlayMetaFile 77F34BA9 5 Bytes JMP 0032C54C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetEnhMetaFileW 77F38FE2 5 Bytes JMP 00325E4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GdiComment 77F394C5 5 Bytes JMP 0032634C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PlayEnhMetaFile 77F39777 5 Bytes JMP 00325F4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!EnumEnhMetaFile 77F397A3 5 Bytes JMP 00325FCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!FixBrushOrgEx 77F3A8B5 5 Bytes JMP 003286CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetCharWidth32A 77F3B975 5 Bytes JMP 00328C4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!EnumFontsA 77F3BDAB 5 Bytes JMP 003281CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!RoundRect 77F3BDCE 5 Bytes JMP 0032B0CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PaintRgn 77F3BE99 5 Bytes JMP 0032C3CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!Pie 77F3C81E 5 Bytes JMP 0032AD4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!EnumFontFamiliesW 77F3CA71 5 Bytes JMP 0032804C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!ScaleViewportExtEx 77F3CCD7 5 Bytes JMP 0032B14C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!ScaleWindowExtEx 77F3CDB8 5 Bytes JMP 0032B1CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetMapperFlags 77F3D1FE 5 Bytes JMP 0032B74C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetSystemPaletteUse 77F3D288 5 Bytes JMP 0032BB4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetColorAdjustment 77F3D298 5 Bytes JMP 0032B44C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetAspectRatioFilterEx 77F3D2F8 5 Bytes JMP 0032894C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetCharacterPlacementA 77F3D313 5 Bytes JMP 00328F4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetCharWidthFloatA 77F3D640 5 Bytes JMP 00328DCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetCharWidthFloatW 77F3D664 5 Bytes JMP 00328E4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetGlyphIndicesA 77F3D6F3 5 Bytes JMP 0032964C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetTextExtentExPointA 77F3D888 5 Bytes JMP 0032A34C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetTextExtentExPointW 77F3DB43 5 Bytes JMP 0032A3CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetCharABCWidthsA 77F3DD2F 5 Bytes JMP 00328A4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetCharABCWidthsFloatA 77F3DD50 5 Bytes JMP 00328ACC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetCharABCWidthsFloatW 77F3DD71 5 Bytes JMP 00328B4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetGlyphOutlineW 77F3DDE1 5 Bytes JMP 0032984C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetGlyphOutline 77F3DECB 5 Bytes JMP 003297CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetKerningPairsW 77F3DF1F 5 Bytes JMP 00329ACC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetKerningPairs 77F3DF48 1 Byte [ E9 ]
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetKerningPairs + 2 77F3DF4A 3 Bytes [ BA, 3E, 88 ]
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetColorAdjustment 77F3E162 5 Bytes JMP 003290CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetCharacterPlacementW 77F3E2FC 5 Bytes JMP 00328FCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!EnumFontsW 77F3F4E6 5 Bytes JMP 0032824C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!EnumFontFamiliesExA 77F3F50B 5 Bytes JMP 003280CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetColorSpace 77F3FBD4 5 Bytes JMP 0032914C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!CheckColorsInGamut 77F3FCB6 5 Bytes JMP 0032774C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetDeviceGammaRamp 77F3FE3C 5 Bytes JMP 0032944C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetDeviceGammaRamp 77F3FE6B 5 Bytes JMP 0032B54C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!ColorCorrectPalette 77F408DB 5 Bytes JMP 003279CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!EnumICMProfilesA 77F40C25 5 Bytes JMP 003282CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!EnumICMProfilesW 77F40CA2 5 Bytes JMP 0032834C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetICMProfileW 77F41F18 5 Bytes JMP 0032994C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetICMProfileA 77F42022 5 Bytes JMP 0032B64C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetICMProfileW 77F4203F 5 Bytes JMP 0032B6CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetICMProfileA 77F4253C 5 Bytes JMP 003298CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!ColorMatchToTarget 77F42D69 5 Bytes JMP 00327A4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetDCBrushColor 77F42E72 5 Bytes JMP 003265CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetDCPenColor 77F42ED1 5 Bytes JMP 0032644C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetDCPenColor 77F43020 5 Bytes JMP 0032664C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetFontLanguageInfo 77F4307F 5 Bytes JMP 0032954C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetStretchBltMode 77F430D6 5 Bytes JMP 00329FCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetMetaRgn 77F43D39 5 Bytes JMP 00329B4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!ResetDCA 77F43E16 5 Bytes JMP 0032AFCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!CreateDiscardableBitmap 77F43E87 5 Bytes JMP 00327CCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!UpdateColors 77F43E97 5 Bytes JMP 0032BFCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!DrawEscape 77F441BA 5 Bytes JMP 00327ECC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!AngleArc 77F44256 5 Bytes JMP 003274CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!Arc 77F44308 5 Bytes JMP 0032754C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!ArcTo 77F443F4 5 Bytes JMP 003275CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!Chord 77F444B4 5 Bytes JMP 0032784C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PlgBlt 77F445A0 5 Bytes JMP 0032C64C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!ExtFloodFill 77F4469A 5 Bytes JMP 003284CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!FloodFill 77F447D0 5 Bytes JMP 003287CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PolyTextOutW 77F447F1 5 Bytes JMP 0032CA4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PolyTextOutA 77F448CE 5 Bytes JMP 0032C9CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!AbortPath 77F451F9 5 Bytes JMP 0032744C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!FlattenPath 77F45250 5 Bytes JMP 0032874C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!StrokePath 77F452A7 5 Bytes JMP 0032BDCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!FillPath 77F45334 5 Bytes JMP 0032864C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!WidenPath 77F453C1 5 Bytes JMP 0032C04C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PathToRegion 77F45418 5 Bytes JMP 0032ACCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetPath 77F4548C 5 Bytes JMP 00329DCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!ChoosePixelFormat 77F454E3 5 Bytes JMP 003277CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!DescribePixelFormat 77F45528 5 Bytes JMP 00327E4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SetPixelFormat 77F45573 5 Bytes JMP 0032B94C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!SwapBuffers 77F4560E 5 Bytes JMP 0032BE4C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PolyPolygon 77F45680 5 Bytes JMP 0032C8CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PolyPolyline 77F45725 5 Bytes JMP 0032C94C
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PolyBezier 77F457B9 5 Bytes JMP 0032C6CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PolyDraw 77F4586B 5 Bytes JMP 0032C7CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!PtVisible 77F459F7 5 Bytes JMP 0032ADCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetEnhMetaFileA 77F4A016 5 Bytes JMP 00325DCC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetGlyphIndicesW 77F5150E 5 Bytes JMP 003296CC
.text C:\Program Files\ArcGIS\Bin\ArcMap.exe[3436] GDI32.dll!GetFontUnicodeRanges 77F51660 5 Bytes JMP 003295CC
---- Processes - GMER 1.0.12 ----
Library C:\Program (*** hidden *** ) @ C:\WINDOWS\explorer.exe [2712] 0x62390000
Library C:\Program (*** hidden *** ) @ C:\WINDOWS\explorer.exe [2712] 0x60470000
Library C:\Program (*** hidden *** ) @ C:\WINDOWS\explorer.exe [2712] 0x61EF0000
Library C:\PROGRA~1\WIFD1F~1\MpShHook.dll (*** hidden *** ) @ C:\PROGRA~1\SYMANT~1\VPTray.exe [2992] 0x5F800000
Library C:\PROGRA~1\WIFD1F~1\MpShHook.dll (*** hidden *** ) @ C:\Program Files\OpenOffice.org 2.2\program\soffice.bin [3260] 0x5F800000
Library C:\PROGRA~1\WIFD1F~1\MpShHook.dll (*** hidden *** ) @ C:\WINDOWS\explorer.exe [3476] 0x5F800000
Library C:\Program (*** hidden *** ) @ C:\WINDOWS\explorer.exe [3476] 0x62390000
Library C:\Program (*** hidden *** ) @ C:\WINDOWS\explorer.exe [3476] 0x60470000
Library C:\Program (*** hidden *** ) @ C:\WINDOWS\explorer.exe [3476] 0x61EF0000
---- EOF - GMER 1.0.12 ----
Here is the autostart scan:
GMER 1.0.12.12244 -
http://www.gmer.net
Autostart scan 2007-04-30 10:39:35
Windows 5.1.2600 Service Pack 2
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
NavLogon@DLLName = C:\WINDOWS\system32\NavLogon.dll
WgaLogon@DLLName = WgaLogon.dll
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
ASANYm_coyotEYEPro /*MobiLink Synchronization - coyotEYEPro*/@ = C:\Program Files\Sybase\SQL Anywhere 9\win32\dbmlsrv9.exe -hvASANYm_coyotEYEPro /*file not found*/
AVG Anti-Spyware Guard /*AVG Anti-Spyware Guard*/@ = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
ccEvtMgr /*Symantec Event Manager*/@ = "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
ccSetMgr /*Symantec Settings Manager*/@ = "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
DefWatch /*Symantec AntiVirus Definition Watcher*/@ = "C:\Program Files\Symantec AntiVirus\DefWatch.exe"
LightScribeService /*LightScribeService Direct Disc Labeling Service*/@ = "C:\Program Files\Common Files\LightScribe\LSSrvc.exe"
NVSvc /*NVIDIA Display Driver Service*/@ = %SystemRoot%\system32\nvsvc32.exe
ScsiPort@ = %SystemRoot%\system32\drivers\scsiport.sys
SoundMAX Agent Service (default) /*SoundMAX Agent Service*/@ = C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Spooler /*Print Spooler*/@ = %SystemRoot%\system32\spoolsv.exe
sshd /*CYGWIN sshd*/@ = C:\cygwin\bin\cygrunsrv.exe
Symantec AntiVirus /*Symantec AntiVirus*/@ = "C:\Program Files\Symantec AntiVirus\Rtvscan.exe"
WMPNetworkSvc /*Windows Media Player Network Sharing Service*/@ = "C:\Program Files\Windows Media Player\WMPNetwk.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@Ptipbmfrundll32.exe ptipbmf.dll,SetWriteCacheMode = rundll32.exe ptipbmf.dll,SetWriteCacheMode
@SoundMAXPnPC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe = C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
@SoundMAX"C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray = "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
@ASUS ProbeC:\Program Files\ASUS\Probe\AsusProb.exe /*file not found*/ = C:\Program Files\ASUS\Probe\AsusProb.exe /*file not found*/
@ccApp"C:\Program Files\Common Files\Symantec Shared\ccApp.exe" = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
@vptrayC:\PROGRA~1\SYMANT~1\VPTray.exe = C:\PROGRA~1\SYMANT~1\VPTray.exe
@ISUSPM StartupC:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup /*file not found*/ = C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup /*file not found*/
@ISUSScheduler"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start /*file not found*/ = "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start /*file not found*/
@QuickTime Task"C:\Program Files\QuickTime\qttask.exe" -atboottime = "C:\Program Files\QuickTime\qttask.exe" -atboottime
@NvCplDaemonRUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
@nwiznwiz.exe /install = nwiz.exe /install
@NvMediaCenterRunDLL32.exe NvMCTray.dll,NvTaskbarInit = RunDLL32.exe NvMCTray.dll,NvTaskbarInit
@WatchDogC:\Program Files\mobile PhoneTools\WatchDog.exe /*file not found*/ = C:\Program Files\mobile PhoneTools\WatchDog.exe /*file not found*/
@!AVG Anti-Spyware"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
@SunJavaUpdateSched"C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" = "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
@NeroFilterCheckC:\WINDOWS\system32\NeroCheck.exe = C:\WINDOWS\system32\NeroCheck.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@Handy Backup 4.1C:\Program Files\Novosoft\Handy Backup\hbagent.exe -logon /*file not found*/ = C:\Program Files\Novosoft\Handy Backup\hbagent.exe -logon /*file not found*/
@AltDeskC:\Program Files\AltDesk\AltDesk.exe = C:\Program Files\AltDesk\AltDesk.exe
@WMPNSCFGC:\Program Files\Windows Media Player\WMPNSCFG.exe = C:\Program Files\Windows Media Player\WMPNSCFG.exe
@BitTorrent"C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized /*file not found*/ = "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized /*file not found*/
@Yahoo! Pager"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet = "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad@WPDShServiceObj = C:\WINDOWS\system32\WPDShServiceObj.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks >>>
@{182B90A3-F372-438A-800C-6814B4DE417B}(null) =
@{57B86673-276A-48B2-BAE7-C6DBB3020EB8}C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Display Panning CPL Extension*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{30D02401-6A81-11d0-8274-00C04FD5AE38} /*IE Search Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{32683183-48a0-441b-a342-7c2a440a9478} /*Media Band*/(null) =
@{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} /*Shell DocObject Viewer*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FBF23B40-E3F0-101B-8488-00AA003E56F8} /*InternetShortcut*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3C374A40-BAE4-11CF-BF7D-00AA006946EE} /*Microsoft Url History Service*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FF393560-C2A7-11CF-BFF4-444553540000} /*History*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E00-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E01-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{CFBFAE00-17A6-11D0-99CB-00C04FD64497} /*Microsoft Url Search Hook*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} /*The Internet*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{871C5380-42A0-1069-A2EA-08002B30309D} /*Internet Name Space*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} /*Adobe.Acrobat.ContextMenu*/C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll = C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll
@{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} /*Shell Extensions for RealOne Player*/C:\Program Files\Real\RealPlayer\rpshell.dll = C:\Program Files\Real\RealPlayer\rpshell.dll
@{68DD2975-D9B9-4530-846E-EFA41B7470ED} /*Handy Backup*/(null) =
@{2AA59FC0-31E8-42DA-9D3C-E9A52953853B} /*CopyToCD shell extension*/(null) =
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\system32\extmgr.dll = C:\WINDOWS\system32\extmgr.dll
@{BDA77241-42F6-11d0-85E2-00AA001FE28C} /*LDVP Shell Extensions*/C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Web Folders*/C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{A70C977A-BF00-412C-90B7-034C51DA2439} /*NvCpl DesktopContext Class*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
@{FFB699E0-306A-11d3-8BD1-00104B6F7516} /*Play on my TV helper*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
@{1CDB2949-8F65-4355-8456-263E7C208A5D} /*Desktop Explorer*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A47} /*Desktop Explorer Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A48} /*nView Desktop Context Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{35786D3C-B075-49b9-88DD-029876E11C01} /*Portable Devices*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} /*Portable Devices Menu*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{07C45BB1-4A8C-4642-A1F5-237E7215FF66} /*IE Microsoft BrowserBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{1C1EDB47-CE22-4bbb-B608-77B48F83C823} /*IE Fade Task*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{205D7A97-F16D-4691-86EF-F3075DCCA57D} /*IE Menu Desk Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3028902F-6374-48b2-8DC6-9725E775B926} /*IE AutoComplete*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{43886CD5-6529-41c4-A707-7B3C92C05E68} /*IE Navigation Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{44C76ECD-F7FA-411c-9929-1B77BA77F524} /*IE Menu Site*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{4B78D326-D922-44f9-AF2A-07805C2A3560} /*IE Menu Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6038EF75-ABFC-4e59-AB6F-12D397F6568D} /*IE Microsoft History AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE} /*IE Tracking Shell Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6CF48EF8-44CD-45d2-8832-A16EA016311B} /*IE IShellFolderBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{73CFD649-CD48-4fd8-A272-2070EA56526B} /*IE BandProxy*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8} /*IE MRU AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E} /*IE RSS Feeder Folder*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9D958C62-3954-4b44-8FAB-C4670C1DB4C2} /*IE Microsoft Shell Folder AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{B31C5FAE-961F-415b-BAF0-E697A5178B94} /*IE Microsoft Multiple AutoComplete List Container*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BC476F4C-D9D7-4100-8D4E-E043F6DEC409} /*Microsoft Browser Architecture*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A} /*IE Shell Rebar BandSite*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{E6EE9AAC-F76B-4947-8260-A9F136138E11} /*IE Shell Band Site Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F2CF5485-4E02-4f68-819C-B92DE9277049} /*&Links*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E} /*IE Registry Tree Options Utility*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} /*IE User Assist*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FDE7673D-2E19-4145-8376-BBD58C4BC7BA} /*IE Custom MRU AutoCompleted List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{45670FA8-ED97-4F44-BC93-305082590BFB} /*Microsoft.XPS.Shell.Metadata.1*/%SystemRoot%\System32\XPSSHHDR.DLL = %SystemRoot%\System32\XPSSHHDR.DLL
@{44121072-A222-48f2-A58A-6D9AD51EBBE9} /*Microsoft.XPS.Shell.Thumbnail.1*/%SystemRoot%\System32\XPSSHHDR.DLL = %SystemRoot%\System32\XPSSHHDR.DLL
@{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} /*OpenOffice.org Column Handler*/"C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll"
@{087B3AE3-E237-4467-B8DB-5A38AB959AC9} /*OpenOffice.org Infotip Handler*/"C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll"
@{63542C48-9552-494A-84F7-73AA6A7C99C1} /*OpenOffice.org Property Sheet Handler*/"C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll"
@{3B092F0C-7696-40E3-A80F-68D74DA84210} /*OpenOffice.org Thumbnail Viewer*/"C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll"
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved@{BDEADF00-C265-11d0-BCED-00A0C90AB50F} /*Web Folders*/ = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
Adobe.Acrobat.ContextMenu@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} = C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
LDVPMenu@{BDA77241-42F6-11d0-85E2-00AA001FE28C} = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
VIDEOTRANS@{548773BA-874E-4C02-9DC7-B7A096772C7D} = C:\Program Files\MP3 Player Utilities 3.57\AMVTools\SrcCount.dll
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\LDVPMenu@{BDA77241-42F6-11d0-85E2-00AA001FE28C} = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll = C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
@{53707962-6F74-2D53-2644-206D7942484F}C:\PROGRA~1\SPYBOT~1\SDHelper.dll = C:\PROGRA~1\SPYBOT~1\SDHelper.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll = C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
@{AE7CD045-E861-484f-8273-0445EE161910}C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll = C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
HKCU\Control Panel\Desktop@SCRNSAVE.EXE = C:\WINDOWS\System32\scrnsave.scr
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://go.microsoft.com/fwlink/?LinkId=69157 =
http://go.microsoft....k/?LinkId=69157
@Start Pagehttp://go.microsoft.com/fwlink/?LinkId=69157 =
http://go.microsoft....k/?LinkId=69157
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.yahoo.com/ =
http://www.yahoo.com/
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
lid@CLSID = C:\WINDOWS\System32\msvidctl.dll
mhtml@CLSID = %SystemRoot%\System32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\System32\wiascr.dll
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters@Domain = wru.umt.edu
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{94AD5894-E43C-46C8-9A51-8B9982915D10} /*Local Area Connection*/ >>>
@IPAddress10.8.19.34 = 10.8.19.34
@NameServer10.10.7.6,10.10.11.2 = 10.10.7.6,10.10.11.2
@DefaultGateway10.8.19.254 = 10.8.19.254
@Domain =
C:\Documents and Settings\All Users\Start Menu\Programs\Startup >>>
Acrobat Assistant.lnk = Acrobat Assistant.lnk
Adobe Reader Speed Launch.lnk = Adobe Reader Speed Launch.lnk
Adobe Reader Synchronizer.lnk = Adobe Reader Synchronizer.lnk
Acrobat Assistant.lnk = Acrobat Assistant.lnk
Adobe Reader Speed Launch.lnk = Adobe Reader Speed Launch.lnk
Adobe Reader Synchronizer.lnk = Adobe Reader Synchronizer.lnk
---- EOF - GMER 1.0.12 ----
Thanks Again!