This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Computer Infection - Lockdown

310 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello there, I tried to use ComboFix, but it still won't work. It will run, but once it starts to scan, a few moments later, it will just disappear. I have tried to re-download it and even use it on SafeMode, but to no avail. Thanks.
First thing to do is delete that executable Program Files folder. I just had it scanned and it's a baddie. Thanks for the copy by the way :)

Download F-Secure Blacklight (fsbl.exe) to the desktop from here.

Open it and click Accept Agreement.
Click Scan.
After the scan is complete, click Next, then Exit.
It will create a log on the desktop named fsbl-xxxxxxx.log (the xxxxxxx will be the date and time of the scan)
Save the log to your desktop. Paste the log in your next reply.
I have downloaded it, however, when I opened it, it tells me that the Evaluation Period has expired. This is the first time I've used the program though.
Okay, try this one.
  • Download GMER by GMER from here
  • Unzip it to a folder on your desktop
  • Double click on gmer.exe to launch GMER
  • If asked, allow the gmer.sys driver load
  • If it warns you about rootkit activity and asks if you want to run scan, click OK
  • If you don't get a warning then
    • Click the rootkit tab
    • Click Scan
  • Once the scan has finished, click copy
  • Paste the log into notepad using Ctrl+V
  • Save it to your desktop as gmerrk.txt
  • Click on the >>> tab
  • This will open up the rest of the tabs for you
  • Click on the Autostart tab
  • Click on Scan
  • Once the scan has finished, click copy
  • Paste the log into notepad using Ctrl+V
  • Save it to your desktop as gmerautos.txt
  • Copy and paste the contents of gmerautos.txt and gmerrk.txt as a reply to this topic


They may be long so you might have to split them over more than one reply.
gmerautos.txt

GMER 1.0.13.12551 - http://www.gmer.net
Autostart scan 2007-10-02 19:43:41
Windows 5.1.2600 Service Pack 2


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon >>>
@UserinitC:\WINDOWS\system32\userinit.exe, = C:\WINDOWS\system32\userinit.exe,
@Shellexplorer.exe winhelp32.exe = explorer.exe winhelp32.exe

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
Bonjour Service /*##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##*/@ = "C:\Program Files\Bonjour\mDNSResponder.exe"
CmdAgent /*Comodo Application Agent*/@ = C:\Program Files\Comodo\Firewall\cmdagent.exe
MDM /*Machine Debug Manager*/@ = "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
MSSQL$SQLEXPRESS /*SQL Server (SQLEXPRESS)*/@ = "c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
MySQL /*MySQL*/@ = "C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt" –defaults-file="C:\Program Files\MySQL\MySQL Server 5.0\my.ini" MySQL
NOD32krn /*NOD32 Kernel Service*/@ = "C:\Program Files\Eset\nod32krn.exe"
NVSvc /*NVIDIA Display Driver Service*/@ = %SystemRoot%\system32\nvsvc32.exe
PCAutoShutdown_Service /*PCAutoShutdown_Service*/@ = C:\Program Files\PC Auto Shutdown\ShutdownService.exe
Pml Driver HPZ12 /*Pml Driver HPZ12*/@ = C:\WINDOWS\system32\HPZipm12.exe
RichVideo /*Cyberlink RichVideo Service(CRVS)*/@ = "C:\Program Files\CyberLink\Shared files\RichVideo.exe" ??????????????????????????????????????????????????????
SDhelper /*PC Tools Spyware Doctor*/@ = C:\Program Files\Spyware Doctor\sdhelp.exe
Spooler /*Print Spooler*/@ = %SystemRoot%\system32\spoolsv.exe
SQLBrowser /*SQL Server Browser*/@ = "c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
SQLWriter /*SQL Server VSS Writer*/@ = "c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
UMWdf /*Windows User Mode Driver Framework*/@ = C:\WINDOWS\system32\wdfmgr.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@RTHDCPLRTHDCPL.EXE = RTHDCPL.EXE
@SkyTelSkyTel.EXE = SkyTel.EXE
@AlcmtrALCMTR.EXE = ALCMTR.EXE
@IMJPMIG8.1"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 = "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
@MSPY2002"C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNC = "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNC
@PHIME2002ASync"C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
@PHIME2002A"C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
@nod32kui"C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE = "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
@COMODO Firewall Pro"C:\Program Files\Comodo\Firewall\CPF.exe" /background = "C:\Program Files\Comodo\Firewall\CPF.exe" /background
@NvCplDaemonRUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
@nwiznwiz.exe /install = nwiz.exe /install
@NeroFilterCheckC:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe = C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
@NvMediaCenterRUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
@Windows LogonC:\Program Files\Common Files\System\winlogon.exe = C:\Program Files\Common Files\System\winlogon.exe
@ServiceHostC:\WINDOWS\Media\svchost.exe = C:\WINDOWS\Media\svchost.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\[removed] = C:\WINDOWS\system32\ctfmon.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Display Panning CPL Extension*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/%SystemRoot%\system32\extmgr.dll = %SystemRoot%\system32\extmgr.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Web Folders*/C:\Program Files\Common Files\Microsoft Shared\Web Folders\msonsext.dll = C:\Program Files\Common Files\Microsoft Shared\Web Folders\msonsext.dll
@{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} /*PowerISO*/C:\Program Files\PowerISO\PWRISOSH.DLL = C:\Program Files\PowerISO\PWRISOSH.DLL
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Program Files\WinRAR\rarext.dll = C:\Program Files\WinRAR\rarext.dll
@{B089FE88-FB52-11D3-BDF1-0050DA34150D} /*NOD32 Context Menu Shell Extension*/C:\Program Files\Eset\nodshex.dll = C:\Program Files\Eset\nodshex.dll
@{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} /*iTunes*/C:\Program Files\iTunes\iTunesMiniPlayer.dll = C:\Program Files\iTunes\iTunesMiniPlayer.dll
@{00020D75-0000-0000-C000-000000000046} /*Microsoft Office Outlook Desktop Icon Handler*/C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL = C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Office Outlook Custom Icon Handler*/C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL = C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Program Files\Microsoft Office\OFFICE11\msohev.dll = C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
@{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} /*Messenger Sharing Folders*/C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll = C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll
@{A70C977A-BF00-412C-90B7-034C51DA2439} /*NvCpl DesktopContext Class*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
@{1CDB2949-8F65-4355-8456-263E7C208A5D} /*Desktop Explorer*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A47} /*Desktop Explorer Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A48} /*nView Desktop Context Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{FFB699E0-306A-11d3-8BD1-00104B6F7516} /*Play on my TV helper*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
Autodesk.DWF.ContextMenu@{6C18531F-CA85-45F7-8278-FF33CF0A5964} = C:\Program Files\Common Files\Autodesk Shared\dwf Common\DWFShellExtension.dll
MagicISO@{DB85C504-C730-49DD-BEC1-7B39C6103B7A} = C:\Program Files\MagicISO\misosh.dll
NOD32 Context Menu Shell Extension@{B089FE88-FB52-11D3-BDF1-0050DA34150D} = C:\Program Files\Eset\nodshex.dll
PowerISO@{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} = C:\Program Files\PowerISO\PWRISOSH.DLL
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
MagicISO@{DB85C504-C730-49DD-BEC1-7B39C6103B7A} = C:\Program Files\MagicISO\misosh.dll
PowerISO@{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} = C:\Program Files\PowerISO\PWRISOSH.DLL
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
MagicISO@{DB85C504-C730-49DD-BEC1-7B39C6103B7A} = C:\Program Files\MagicISO\misosh.dll
NOD32 Context Menu Shell Extension@{B089FE88-FB52-11D3-BDF1-0050DA34150D} = C:\Program Files\Eset\nodshex.dll
PowerISO@{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} = C:\Program Files\PowerISO\PWRISOSH.DLL
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll = C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
@{31FF080D-12A3-439A-A2EF-4BA95A3148E8}C:\Program Files\GetRight\xx2gr.dll = C:\Program Files\GetRight\xx2gr.dll
@{3C6301ED-0F78-4AF2-8150-D9C052361A8E}C:\Program Files\ATLAS V13\ATLIECP.DLL = C:\Program Files\ATLAS V13\ATLIECP.DLL
@{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL = C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
@{53707962-6F74-2D53-2644-206D7942484F}C:\PROGRA~1\SPYBOT~1\SDHelper.dll = C:\PROGRA~1\SPYBOT~1\SDHelper.dll
@{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll = C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll = C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
@{B56A7D7D-6927-48C8-A975-17DF180C71AC}C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll = C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
@Start Pageabout:blank = about:blank
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm

HKCU\Software\Microsoft\Internet Explorer\Main@Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome

HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
livecall@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
ms-help@CLSID = C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
ms-itss@CLSID = C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
msnim@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mso-offdap@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
mso-offdap11@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\system32\wiascr.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\0000000004@LibraryPath = C:\Program Files\Bonjour\mdnsNSP.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
000000000001@PackedCatalogItem = C:\WINDOWS\system32\imon.dll
000000000002@PackedCatalogItem = C:\WINDOWS\system32\imon.dll
000000000003@PackedCatalogItem = C:\WINDOWS\system32\imon.dll
000000000004@PackedCatalogItem = C:\WINDOWS\system32\imon.dll
000000000005@PackedCatalogItem = C:\WINDOWS\system32\imon.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\0000000011@PackedCatalogItem = C:\WINDOWS\system32\imon.dll

—- EOF - GMER 1.0.13 —-
gmerrk.txt - Part 1


GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-10-02 19:30:14
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.13 —-

SSDT d347bus.sys ZwClose
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwConnectPort
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwCreateFile
SSDT d347bus.sys ZwCreateKey
SSDT d347bus.sys ZwCreatePagingFile
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwCreatePort
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwCreateSection
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwCreateThread
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwDeleteFile
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwDeleteKey
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwDeleteValueKey
SSDT d347bus.sys ZwEnumerateKey
SSDT d347bus.sys ZwEnumerateValueKey
SSDT d347bus.sys ZwOpenKey
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwOpenProcess
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwOpenSection
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwOpenThread
SSDT d347bus.sys ZwQueryKey
SSDT d347bus.sys ZwQueryValueKey
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwSetContextThread
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwSetInformationFile
SSDT d347bus.sys ZwSetSystemPowerState
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwSetValueKey
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwShutdownSystem
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwTerminateProcess
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwWriteFile
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwWriteFileGather

—- Kernel code sections - GMER 1.0.13 —-

? C:\WINDOWS\TEMP\mc26.tmp The system cannot find the file specified.

—- User code sections - GMER 1.0.13 —-

.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[268] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[268] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[268] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[268] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[268] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[284] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[284] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[284] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[284] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[284] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[380] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[380] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[380] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[380] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[380] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[380] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\WINDOWS\system32\wdfmgr.exe[580] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\wdfmgr.exe[580] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[580] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\wdfmgr.exe[580] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\wdfmgr.exe[580] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\wdfmgr.exe[580] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\WINDOWS\system32\csrss.exe[756] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[756] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\csrss.exe[756] KERNEL32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\csrss.exe[756] KERNEL32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\csrss.exe[756] KERNEL32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\winlogon.exe[780] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[780] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[780] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\winlogon.exe[780] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\winlogon.exe[780] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\services.exe[824] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[824] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\lsass.exe[836] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[836] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[1016] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1016] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1016] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[1016] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[1016] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[1080] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1080] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\System32\svchost.exe[1132] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1132] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[1228] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1228] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1228] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[1228] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[1228] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[1260] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1260] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\spoolsv.exe[1448] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1448] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1448] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\spoolsv.exe[1448] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\spoolsv.exe[1448] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1560] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1560] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1560] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1560] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1560] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Comodo\Firewall\cmdagent.exe[1588] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Comodo\Firewall\cmdagent.exe[1588] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Comodo\Firewall\cmdagent.exe[1588] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F08001E
.text C:\Program Files\Comodo\Firewall\cmdagent.exe[1588] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0B001E
.text C:\Program Files\Comodo\Firewall\cmdagent.exe[1588] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F05001E
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1656] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1656] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1656] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1656] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1656] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe[1744] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe[1744] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe[1744] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe[1744] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe[1744] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Eset\nod32krn.exe[1772] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Eset\nod32krn.exe[1772] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Eset\nod32krn.exe[1772] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Eset\nod32krn.exe[1772] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Eset\nod32krn.exe[1772] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\nvsvc32.exe[1824] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\nvsvc32.exe[1824] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[1824] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\nvsvc32.exe[1824] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[1824] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\PC Auto Shutdown\ShutdownService.exe[1844] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\PC Auto Shutdown\ShutdownService.exe[1844] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\PC Auto Shutdown\ShutdownService.exe[1844] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\PC Auto Shutdown\ShutdownService.exe[1844] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\PC Auto Shutdown\ShutdownService.exe[1844] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\HPZipm12.exe[1876] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\HPZipm12.exe[1876] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\HPZipm12.exe[1876] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\HPZipm12.exe[1876] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\HPZipm12.exe[1876] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[1932] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[1932] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[1932] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[1932] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\CyberLink\Shared files\RichVideo.exe[1932] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\System32\alg.exe[1992] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[1992] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\alg.exe[1992] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\System32\alg.exe[1992] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\System32\alg.exe[1992] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\System32\alg.exe[1992] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2172] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2172] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2172] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2172] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2172] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2172] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\WINDOWS\explorer.exe[2748] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[2748] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\explorer.exe[2748] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\explorer.exe[2748] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\explorer.exe[2748] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\explorer.exe[2748] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\WINDOWS\RTHDCPL.EXE[2836] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\RTHDCPL.EXE[2836] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\RTHDCPL.EXE[2836] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\RTHDCPL.EXE[2836] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\RTHDCPL.EXE[2836] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\RTHDCPL.EXE[2836] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\Program Files\Eset\nod32kui.exe[2928] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Eset\nod32kui.exe[2928] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Eset\nod32kui.exe[2928] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Eset\nod32kui.exe[2928] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Eset\nod32kui.exe[2928] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Eset\nod32kui.exe[2928] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\Program Files\Comodo\Firewall\CPF.exe[2960] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Comodo\Firewall\CPF.exe[2960] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Comodo\Firewall\CPF.exe[2960] ntdll.dll!LdrLoadDll 7C9161CA 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Comodo\Firewall\CPF.exe[2960] ntdll.dll!LdrLoadDll + 4 7C9161CE 2 Bytes [ 11, 5F ]
.text C:\Program Files\Comodo\Firewall\CPF.exe[2960] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F08001E
.text C:\Program Files\Comodo\Firewall\CPF.exe[2960] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0B001E
.text C:\Program Files\Comodo\Firewall\CPF.exe[2960] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F05001E
.text C:\Program Files\Comodo\Firewall\CPF.exe[2960] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[2992] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[2992] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[2992] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[2992] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[2992] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[2992] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\Program Files\Common Files\System\winlogon.exe[3000] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\System\winlogon.exe[3000] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\System\winlogon.exe[3000] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\System\winlogon.exe[3000] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\System\winlogon.exe[3000] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\System\winlogon.exe[3000] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\WINDOWS\Media\svchost.exe[3008] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Media\svchost.exe[3008] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\Media\svchost.exe[3008] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\Media\svchost.exe[3008] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\Media\svchost.exe[3008] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\Media\svchost.exe[3008] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\WINDOWS\system32\ctfmon.exe[3016] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[3016] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[3016] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\ctfmon.exe[3016] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3016] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\ctfmon.exe[3016] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\WINDOWS\system32\conime.exe[3648] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\conime.exe[3648] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\conime.exe[3648] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\conime.exe[3648] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\conime.exe[3648] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\conime.exe[3648] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[6096] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[6096] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[6096] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[6096] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[6096] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[6096] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\WINDOWS\system32\wuauclt.exe[19048] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\wuauclt.exe[19048] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[19048] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\wuauclt.exe[19048] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\wuauclt.exe[19048] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\wuauclt.exe[19048] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\Program Files\WinRAR\WinRAR.exe[19400] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\WinRAR\WinRAR.exe[19400] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Program Files\WinRAR\WinRAR.exe[19400] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\WinRAR\WinRAR.exe[19400] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\WinRAR\WinRAR.exe[19400] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\WinRAR\WinRAR.exe[19400] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]
.text C:\Documents and Settings\termite\Desktop\gmer.exe[20464] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\termite\Desktop\gmer.exe[20464] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\Documents and Settings\termite\Desktop\gmer.exe[20464] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Documents and Settings\termite\Desktop\gmer.exe[20464] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Documents and Settings\termite\Desktop\gmer.exe[20464] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Documents and Settings\termite\Desktop\gmer.exe[20464] kernel32.dll!FreeLibrary + 15 7C80AC13 4 Bytes [ 25, 54, 7F, E2 ]

—- Kernel IAT/EAT - GMER 1.0.13 —-

IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] [F75BF6D0] inspect.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [F75BF730] inspect.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] [F75BF950] inspect.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [F75BF910] inspect.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [F75BF910] inspect.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [F75BF730] inspect.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [F75BF6D0] inspect.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [F75BF950] inspect.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [F75BF950] inspect.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [F75BF910] inspect.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [F75BF730] inspect.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [F75BF6D0] inspect.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [F75BF910] inspect.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [F75BF6D0] inspect.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [F75BF730] inspect.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [F75BF950] inspect.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [F75BF6D0] inspect.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [F75BF730] inspect.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [F75BF910] inspect.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [F75BF950] inspect.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [F75BF910] inspect.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [F75BF730] inspect.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [F75BF6D0] inspect.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [F75BF910] inspect.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [F75BF950] inspect.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [F75BF6D0] inspect.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [F75BF730] inspect.sys

—- User IAT/EAT - GMER 1.0.13 —-

IAT C:\Program Files\Spyware Doctor\sdhelp.exe[1944] @ C:\WINDOWS\system32\user32.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[1944] @ C:\WINDOWS\system32\advapi32.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[1944] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[1944] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[1944] @ C:\WINDOWS\system32\shell32.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[1944] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[1944] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[1944] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe
IAT C:\WINDOWS\explorer.exe[2748] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINDOWS\system32\ShimEng.dll
IAT C:\WINDOWS\explorer.exe[2748] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINDOWS\system32\ShimEng.dll
IAT C:\WINDOWS\explorer.exe[2748] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINDOWS\system32\ShimEng.dll
IAT C:\WINDOWS\explorer.exe[2748] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINDOWS\system32\ShimEng.dll
IAT C:\WINDOWS\explorer.exe[2748] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINDOWS\system32\ShimEng.dll
IAT C:\WINDOWS\explorer.exe[2748] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINDOWS\system32\ShimEng.dll
IAT C:\WINDOWS\explorer.exe[2748] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINDOWS\system32\ShimEng.dll
IAT C:\WINDOWS\explorer.exe[2748] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINDOWS\system32\ShimEng.dll
IAT C:\WINDOWS\explorer.exe[2748] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINDOWS\system32\ShimEng.dll
IAT C:\WINDOWS\explorer.exe[2748] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINDOWS\system32\ShimEng.dll
IAT C:\WINDOWS\explorer.exe[2748] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINDOWS\system32\ShimEng.dll
IAT C:\WINDOWS\explorer.exe[2748] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINDOWS\system32\ShimEng.dll
IAT C:\WINDOWS\explorer.exe[2748] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINDOWS\system32\ShimEng.dll
IAT C:\WINDOWS\explorer.exe[2748] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINDOWS\system32\ShimEng.dll
IAT C:\WINDOWS\explorer.exe[2748] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINDOWS\system32\ShimEng.dll
IAT C:\WINDOWS\explorer.exe[2748] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINDOWS\system32\ShimEng.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [63602AE9] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [6360208F] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [63602065] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [63601FC4] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [636015C8] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [636015EF] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [63602AE9] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AnimateWindow] [63601740] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [636015EF] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcA] [6360208F] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColor] [63601FC4] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [63602065] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [636015C8] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe[5952] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [017D7376] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [017D7376] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [017D7376] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [017D7376] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [017D7376] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [017D7376] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [017D7376] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [017D7376] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [017D7376] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [017D7376] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [017D7376] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [017D7376] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\SAMLIB.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [017D7376] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [017D7376] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [017D7376] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [017D7376] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[6096] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017D73CC] C:\Program Files\Mozilla Firefox\extensions\[removed]\components\FULLSOFT.DLL
gmerrk.txt - Part II —- Devices - GMER 1.0.13 —- Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 873E0228 AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [F788E08C] ikhfile.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [BABEBFE2] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [BABEBBEC] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [BABEC3D4] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [BABEC67A] amon.sys AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [BABEC67A] amon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [F3D8EA6A] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_NAMED_PIPE [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [F3D8EA16] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_READ [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_WRITE [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_INFORMATION [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_INFORMATION [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_EA [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_EA [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_FLUSH_BUFFERS [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_VOLUME_INFORMATION [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_VOLUME_INFORMATION [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_DIRECTORY_CONTROL [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_FILE_SYSTEM_CONTROL [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [F3D8E94A] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F3D8E85E] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_LOCK_CONTROL [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [F3D8E9B8] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_MAILSLOT [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_SECURITY [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_SECURITY [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_POWER [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SYSTEM_CONTROL [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CHANGE [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_QUOTA [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_QUOTA [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [F3D8EA6A] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_NAMED_PIPE [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [F3D8EA16] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_READ [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_WRITE [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_INFORMATION [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_INFORMATION [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_EA [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_EA [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_FLUSH_BUFFERS [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_VOLUME_INFORMATION [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_VOLUME_INFORMATION [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_DIRECTORY_CONTROL [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_FILE_SYSTEM_CONTROL [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [F3D8E94A] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F3D8E85E] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_LOCK_CONTROL [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [F3D8E9B8] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_MAILSLOT [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_SECURITY [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_SECURITY [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_POWER [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SYSTEM_CONTROL [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CHANGE [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_QUOTA [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_QUOTA [F3D8EB12] cmdmon.sys Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 86E79C60 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 86E79C60 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 86BDA148 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 86E79C60 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 86E79C60 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_NAMED_PIPE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_READ 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_WRITE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_EA 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_EA 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FLUSH_BUFFERS 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_VOLUME_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_VOLUME_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DIRECTORY_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FILE_SYSTEM_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_LOCK_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLEANUP 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_MAILSLOT 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_SECURITY 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_SECURITY 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CHANGE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_QUOTA 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_QUOTA 86E79D68 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_NAMED_PIPE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_READ 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_WRITE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_EA 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_EA 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FLUSH_BUFFERS 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_VOLUME_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_VOLUME_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DIRECTORY_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FILE_SYSTEM_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SHUTDOWN 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_LOCK_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLEANUP 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_MAILSLOT 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_SECURITY 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_SECURITY 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CHANGE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_QUOTA 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_QUOTA 86E79D68 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CREATE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CREATE_NAMED_PIPE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CLOSE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_READ 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_WRITE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_EA 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_EA 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_FLUSH_BUFFERS 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_VOLUME_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_VOLUME_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_DIRECTORY_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_FILE_SYSTEM_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_DEVICE_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SHUTDOWN 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_LOCK_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CLEANUP 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CREATE_MAILSLOT 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_SECURITY 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_SECURITY 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_POWER 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SYSTEM_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_DEVICE_CHANGE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_QUOTA 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_QUOTA 86E79D68 Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_PNP 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CREATE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CREATE_NAMED_PIPE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CLOSE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_READ 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_WRITE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_QUERY_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SET_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_QUERY_EA 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SET_EA 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_FLUSH_BUFFERS 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_QUERY_VOLUME_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SET_VOLUME_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_DIRECTORY_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_FILE_SYSTEM_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_DEVICE_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SHUTDOWN 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_LOCK_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CLEANUP 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CREATE_MAILSLOT 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_QUERY_SECURITY 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SET_SECURITY 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_POWER 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SYSTEM_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_DEVICE_CHANGE 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_QUERY_QUOTA 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SET_QUOTA 86E79D68 Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_PNP 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_CREATE 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_CREATE_NAMED_PIPE 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_CLOSE 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_READ 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_WRITE 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_QUERY_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_SET_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_QUERY_EA 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_SET_EA 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_FLUSH_BUFFERS 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_QUERY_VOLUME_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_SET_VOLUME_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_DIRECTORY_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_FILE_SYSTEM_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_DEVICE_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_SHUTDOWN 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_LOCK_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_CLEANUP 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_CREATE_MAILSLOT 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_QUERY_SECURITY 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_SET_SECURITY 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_POWER 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_SYSTEM_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_DEVICE_CHANGE 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_QUERY_QUOTA 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_SET_QUOTA 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-10 IRP_MJ_PNP 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_CREATE 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_CREATE_NAMED_PIPE 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_CLOSE 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_READ 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_WRITE 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_QUERY_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_SET_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_QUERY_EA 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_SET_EA 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_FLUSH_BUFFERS 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_QUERY_VOLUME_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_SET_VOLUME_INFORMATION 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_DIRECTORY_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_FILE_SYSTEM_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_DEVICE_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_SHUTDOWN 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_LOCK_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_CLEANUP 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_CREATE_MAILSLOT 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_QUERY_SECURITY 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_SET_SECURITY 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_POWER 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_SYSTEM_CONTROL 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_DEVICE_CHANGE 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_QUERY_QUOTA 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_SET_QUOTA 86E79D68 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_PNP 86E79D68 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_NAMED_PIPE 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_INFORMATION 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_INFORMATION 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_EA 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_EA 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_VOLUME_INFORMATION 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_VOLUME_INFORMATION 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DIRECTORY_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FILE_SYSTEM_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_LOCK_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLEANUP 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_MAILSLOT 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_SECURITY 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_SECURITY 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CHANGE 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_QUOTA 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_QUOTA 86E79C60 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CREATE 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CREATE_NAMED_PIPE 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CLOSE 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_READ 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_WRITE 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_QUERY_INFORMATION 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SET_INFORMATION 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_QUERY_EA 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SET_EA 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_FLUSH_BUFFERS 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_QUERY_VOLUME_INFORMATION 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SET_VOLUME_INFORMATION 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_DIRECTORY_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_FILE_SYSTEM_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_DEVICE_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SHUTDOWN 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_LOCK_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CLEANUP 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CREATE_MAILSLOT 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_QUERY_SECURITY 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SET_SECURITY 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_POWER 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SYSTEM_CONTROL 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_DEVICE_CHANGE 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_QUERY_QUOTA 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SET_QUOTA 86E79C60 Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_PNP 86E79C60 Device \FileSystem\Srv \Device\LanmanServer IRP_MJ_READ 86A06C98 AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [F3D8EA6A] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_NAMED_PIPE [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [F3D8EA16] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_READ [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_WRITE [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_INFORMATION [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_INFORMATION [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_EA [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_EA [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_FLUSH_BUFFERS [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_VOLUME_INFORMATION [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_VOLUME_INFORMATION [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_DIRECTORY_CONTROL [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_FILE_SYSTEM_CONTROL [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [F3D8E94A] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F3D8E85E] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SHUTDOWN [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_LOCK_CONTROL [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [F3D8E9B8] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_MAILSLOT [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_SECURITY [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_SECURITY [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_POWER [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SYSTEM_CONTROL [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CHANGE [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_QUOTA [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_QUOTA [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [F3D8EA6A] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_NAMED_PIPE [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [F3D8EA16] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_READ [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_WRITE [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_INFORMATION [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SET_INFORMATION [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_EA [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SET_EA [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_FLUSH_BUFFERS [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_VOLUME_INFORMATION [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SET_VOLUME_INFORMATION [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_DIRECTORY_CONTROL [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_FILE_SYSTEM_CONTROL [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [F3D8E94A] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F3D8E85E] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SHUTDOWN [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_LOCK_CONTROL [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [F3D8E9B8] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_MAILSLOT [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_SECURITY [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SET_SECURITY [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_POWER [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SYSTEM_CONTROL [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CHANGE [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_QUOTA [F3D8EB12] cmdmon.sys AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SET_QUOTA [F3D8EB12] cmdmon.sys Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 86BDB148 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 86BDB148 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_READ 86C3CEA0 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_READ 86C8A1E8 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_CREATE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_CREATE_NAMED_PIPE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_CLOSE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_READ 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_WRITE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_QUERY_INFORMATION 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_SET_INFORMATION 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_QUERY_EA 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_SET_EA 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_FLUSH_BUFFERS 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_SET_VOLUME_INFORMATION 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_DIRECTORY_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_DEVICE_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_SHUTDOWN 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_LOCK_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_CLEANUP 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_CREATE_MAILSLOT 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_QUERY_SECURITY 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_SET_SECURITY 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_POWER 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_SYSTEM_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_DEVICE_CHANGE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_QUERY_QUOTA 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_SET_QUOTA 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 IRP_MJ_PNP 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_CREATE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_CREATE_NAMED_PIPE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_CLOSE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_READ 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_WRITE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_QUERY_INFORMATION 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_SET_INFORMATION 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_QUERY_EA 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_SET_EA 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_FLUSH_BUFFERS 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_SET_VOLUME_INFORMATION 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_DIRECTORY_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_DEVICE_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_SHUTDOWN 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_LOCK_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_CLEANUP 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_CREATE_MAILSLOT 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_QUERY_SECURITY 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_SET_SECURITY 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_POWER 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_SYSTEM_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_DEVICE_CHANGE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_QUERY_QUOTA 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_SET_QUOTA 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 IRP_MJ_PNP 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_CREATE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_CREATE_NAMED_PIPE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_CLOSE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_READ 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_WRITE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_QUERY_INFORMATION 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_SET_INFORMATION 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_QUERY_EA 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_SET_EA 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_FLUSH_BUFFERS 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_SET_VOLUME_INFORMATION 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_DIRECTORY_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_SHUTDOWN 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_LOCK_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_CLEANUP 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_CREATE_MAILSLOT 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_QUERY_SECURITY 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_SET_SECURITY 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_POWER 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_DEVICE_CHANGE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_QUERY_QUOTA 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_SET_QUOTA 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 IRP_MJ_PNP 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_CREATE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_CREATE_NAMED_PIPE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_CLOSE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_READ 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_WRITE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_QUERY_INFORMATION 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SET_INFORMATION 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_QUERY_EA 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SET_EA 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_FLUSH_BUFFERS 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_QUERY_VOLUME_INFORMATION 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SET_VOLUME_INFORMATION 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_DIRECTORY_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_FILE_SYSTEM_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_DEVICE_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SHUTDOWN 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_LOCK_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_CLEANUP 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_CREATE_MAILSLOT 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_QUERY_SECURITY 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SET_SECURITY 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_POWER 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SYSTEM_CONTROL 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_DEVICE_CHANGE 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_QUERY_QUOTA 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SET_QUOTA 86E7FF00 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_PNP 86E7FF00 Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_READ 86BEB7F0 Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_READ 86BEB7F0 Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_READ 86BEB7F0 Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_READ 86BEB7F0 Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_READ 86BEB7F0 Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 86D98A88 —- Modules - GMER 1.0.13 —- Module _________ F7399000-F73B1000 (98304 bytes) —- Registry - GMER 1.0.13 —- Reg \Registry\USER\S-1-5-21-682003330-261903793-839522115-1003\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY@?? 0x26 0xD8 0x0A 0x0B … Reg \Registry\USER\S-1-5-21-682003330-261903793-839522115-1003\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY@?? 0x35 0xFC 0xC6 0x3D … —- EOF - GMER 1.0.13 —-
Hello there, I couldn't find the edit button, so I posted a new one instead. I noticed that the entries we removed from HJT earlier is back - probably worth noting for. Thanks.
Hi

Go to http://www.virustotal.com/en/indexf.html
Copy the following line into the white textbox:
C:\WINDOWS\system32\conime.exe
Click Send.
Please post the results of this scan to this thread.


Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)


WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit HijackThis.
  • Double click OTMoveIt.exe to launch it.
  • Copy/Paste the contents of the box below into the left hand pane of OTMoveIt.

C:\Program Files\Common Files\System\winlogon.exe
C:\WINDOWS\Media\svchost.exe
C:\WINDOWS\TEMP\mc26.tmp

  • Click the Move It button.
  • The list will be processed and the results will appear in the right hand pane.
  • If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
  • When finished click Exit to exit the programme.
  • A log C:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log will be created (where mmddyyyy_hhmmss are numbers giving date and time the log was created).
  • Post the log back here please.

Download Superantispyware (SAS) free home version.

SAS Free

Install it and double-click the icon on your desktop to run it.
� It will ask if you want to update the program definitions, click Yes.

Reboot into SAFE MODEBy pressing the F8 key right when Windows starts, usually right after you hear your computer
beep when you reboot it (some versions of windows will display 'Starting Windows' with a grey progress bar)
you will be brought to a menu where you can choose to boot into safe mode.

If it does not work on the first try, reboot and try again, as you have to be quick when you press it.

I have found that during boot up, right after the computer displays the equipment , memory, etc
installed on your computer, if you start lightly tapping the F8 key, the system will usually display the menu.


Open SuperAntiSpyware
� Under Configuration and Preferences, click the Preferences button.
� Click the Scanning Control tab.
� Under Scanner Options make sure the following are checked:
  • Close browsers before scanning
  • Scan for tracking cookies
  • Terminate memory threats before quarantining.
  • Please leave the others unchecked.
  • Click the Close button to leave the control center screen.
� On the main screen, under Scan for Harmful Software click Scan your computer.
� On the left check C:\Fixed Drive.
� On the right, under Complete Scan, choose Perform Complete Scan.
� Click Next to start the scan. Please be patient while it scans your computer.
� After the scan is complete a summary box will appear. Click OK.
� Make sure everything in the white box has a check next to it, then click Next.
� It will quarantine what it found and if it asks if you want to reboot, click Yes.
� To retrieve the removal information for me please do the following:
  • After reboot, double-click the SUPERAntispyware icon on your desktop.
  • Click Preferences. Click the Statistics/Logs tab.
  • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
  • It will open in your default text editor (such as Notepad/Wordpad).
  • Please highlight everything in the notepad, then right-click and choose copy.
� Click close and close again to exit the program and reboot the computer.
� Please paste that information here for me with a new HijackThis log.
  • Please go HERE to run PandaActiveScan…

  • Once you are on the Panda site click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)

  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to your desktop.
Post that report too.
File conime.exe received on 10.02.2007 16:43:46 (CET)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED
Result: 0/32 (0%)


*************************
C:\Program Files\Common Files\System\winlogon.exe moved successfully.
C:\WINDOWS\Media\svchost.exe moved successfully.
File/Folder C:\WINDOWS\TEMP\mc26.tmp not found.

Created on 10-03-2007 20:32:07

************************
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/03/2007 at 08:25 PM

Application Version : 3.9.1008

Core Rules Database Version : 3318
Trace Rules Database Version: 1319

Scan type : Complete Scan
Total Scan Time : 01:32:37

Memory items scanned : 200
Memory threats detected : 0
Registry items scanned : 8625
Registry threats detected : 0
File items scanned : 78068
File threats detected : 25

Adware.Tracking Cookie
C:\Documents and Settings\termite\Cookies\[removed][2].txt
C:\Documents and Settings\termite\Cookies\[removed][2].txt
C:\Documents and Settings\termite\Cookies\termite@adbrite[2].txt
C:\Documents and Settings\Guess\Cookies\guess@advertising[2].txt
C:\Documents and Settings\Guess\Cookies\guess@atdmt[2].txt
C:\Documents and Settings\Guess\Cookies\guess@doubleclick[1].txt
C:\Documents and Settings\Guess\Cookies\guess@msnportal.112.2o7[1].txt

Adware.Search-Exe
C:\GAMES\BLOODOVER\SE\SE.EXE
C:\GAMES\BLOODOVER\SE.EXE

Virus.DirectX
C:\WINDOWS\SYSTEM32\DIRECTX\DIRECTX.EXE
C:\WINDOWS.1\SYSTEM32\DIRECTX\DIRECTX.EXE
C:\WINDOWS.1\SYSTEM32\DIRECTX.EXE
C:\WINDOWS.2\SYSTEM32\DIRECTX\DIRECTX.EXE
C:\WINDOWS.2\SYSTEM32\DIRECTX.EXE

Virus.GAOBOT
C:\WINDOWS\SYSTEM32\MICROSOFT\MICROSOFT.EXE
C:\WINDOWS.1\SYSTEM32\MICROSOFT\MICROSOFT.EXE
C:\WINDOWS.1\SYSTEM32\MICROSOFT.EXE
C:\WINDOWS.2\SYSTEM32\MICROSOFT\MICROSOFT.EXE
C:\WINDOWS.2\SYSTEM32\MICROSOFT.EXE

Trojan.System32
C:\WINDOWS.0\SYSTEM32\SYSTEM32.EXE
C:\WINDOWS.0\SYSTEM32.EXE
C:\WINDOWS.1\SYSTEM32\SYSTEM32.EXE
C:\WINDOWS.1\SYSTEM32.EXE
C:\WINDOWS.2\SYSTEM32\SYSTEM32.EXE
C:\WINDOWS.2\SYSTEM32.EXE


***********************
Logfile of HijackThis v1.99.1
Scan saved at 21:13, on 2007-10-03
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\PC Auto Shutdown\ShutdownService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\termite\Desktop\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: GetRight IE Download Helper - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: ATLAS Toolbar - {3C6301ED-0F78-4AF2-8150-D9C052361A8E} - C:\Program Files\ATLAS V13\ATLIECP.DLL
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: ATLAS Toolbar - {3C6301ED-0F78-4AF2-8150-D9C052361A8E} - C:\Program Files\ATLAS V13\ATLIECP.DLL
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: &Translate with ATLAS - C:\Program Files\ATLAS V13\Atlscript.html
O8 - Extra context menu item: ATLAS Translation &Editor - C:\Program Files\ATLAS V13\AtlscriptEdit.html
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ATLAS Translation - {B7707A72-4355-11D4-82BD-00000EBBEF8D} - C:\Program Files\ATLAS V13\Atlscript.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.getrightarcade.com/online/onlin…aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DCB04243-EBCE-4BCC-B350-C4CCAC9620B2}: NameServer = 210.4.2.9 202.78.97.41
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCAutoShutdown_Service - Unknown owner - C:\Program Files\PC Auto Shutdown\ShutdownService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

**********************
I am still beginning to start to scan with PandaActiveScan. I will post it soon.
Hello there, I'm still trying to scan with the PandaActiveScan, however, my unstable internet connection keeps disrupting the download. Are there any alternate steps? Also, I apologize for your demise :P Have you fixed your own computer though?
I havent started yet. It's a test partition anyway. At the moment, Im querying about the numerous duplicate folders that have been created. It may be the case where we both have to seek out all the bad ones and remove them manually. :P Leave the Pandascan for the moment. Ill get back to you soon.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI