This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Virtumonde and Vundo Infection

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I really hope you can help me, these infections are destroying my laptop.

History:
-Went to a music site, didn't download anything, and the next thing I knew my computer was infected.
-I keep getting registry change requests from Spybot S&D/Teatimer, which I manually decline, but it doesn't do anything.
-My browser, Firefox, will randomly open and go ot random websites.
-When I was first infected it turned off my automatic updates and firewall.
-It still turns off auto-protection from my anti virus on start up.
-Spybot has found the Virtumonde and Vundo infections, but it can't remove them.
-Like other users that have had this problem, I've ran Vundofix, but it hasn't found it so I can't remove it.

Here's my HiJackThis log, I've never used it before so if I did something wrong please let me know:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:53:20 PM, on 1/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bradford Networks\Client Security Agent\bnpagent.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\PHAROS~1\Core\CTskMstr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\StacSV.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
c:\Program Files\Zune\ZuneNss.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.framingham.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\temp\ntdll64.dll
O10 - Unknown file in Winsock LSP: c:\windows\temp\ntdll64.dll
O15 - Trusted Zone: *.antimalwareguard.com
O15 - Trusted Zone: *.antimalwareguard.com (HKLM)
O15 - Trusted Zone: *.gomyhit.com (HKLM)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1177525140296
O16 - DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF} (JInitiator 1.3.1.22) - http://testdevapp1:7777/forms/jinitiator/jinit.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Client Security Agent (BNPagent) - Bradford Networks - C:\Program Files\Bradford Networks\Client Security Agent\bnpagent.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pharos Systems ComTaskMaster - Pharos Systems International - C:\PROGRA~1\PHAROS~1\Core\CTskMstr.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\StacSV.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 9866 bytes


-Thanks for your help!

*********Oh and my browser now says something like this "18 Trojans WERE found on your machine! !!!FREE VIRUS SCAN!!! !!!Warning!!! your system is at risk! " on every tab.
hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.
For some reason whenever I click on the SDFix link my network times out, I tried searching for a mirror to get it, but I didn't have any luck. Any suggestions? Thank you for the help by the way.
hello

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
Thank you,
I found a mirror finally for the SDFix should I also follow the instructions you previously posted a long with the Combofix ones?

***Oh and this is going to sound ridiculous, but I can't find an option to turn off my anti-virus program.

Software including: Symantec AntiVirus and Spybot: S/D
——————
UPDATE: 12:12 PM

I just finished doing the SDFix instructions you gave me here are the results from the report.txt


SDFix: Version 1.240
Run by [removed] on Sat 01/17/2009 at 11:35 AM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\DOCUME~1\ADMINI~1\Desktop\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\system32\xxyawttU.dll - Deleted
C:\WINDOWS\SYSTEM32\TDSSWHCT.dat - Deleted



Folder C:\Program Files\GetModule - Removed


Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-17 12:06:41
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

disk error: C:\WINDOWS\system32\config\system, 0
scanning hidden registry entries …

disk error: C:\WINDOWS\system32\config\software, 0
disk error: C:\Documents and Settings\Administrator\ntuser.dat, 0
scanning hidden files …

disk error: C:\WINDOWS\

please note that you need administrator rights to perform deep scan

Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\PharosSystems\\Core\\CTskMstr.exe"="C:\\Program Files\\PharosSystems\\Core\\CTskMstr.exe:*:Enabled:Pharos Com Task Master "
"C:\\Program Files\\Bradford Networks\\Client Security Agent\\bnpagent.exe"="C:\\Program Files\\Bradford Networks\\Client Security Agent\\bnpagent.exe"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\WINDOWS\\system32\\drivers\\svchost.exe"="C:\\WINDOWS\\system32\\drivers\\svchost.exe:*:Disabled:svchost"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\PharosSystems\\Core\\CTskMstr.exe"="C:\\Program Files\\PharosSystems\\Core\\CTskMstr.exe:*:Enabled:Pharos Com Task Master "
"C:\\Program Files\\Bradford Networks\\Client Security Agent\\bnpagent.exe"="C:\\Program Files\\Bradford Networks\\Client Security Agent\\bnpagent.exe"

Remaining Files :


File Backups: - C:\DOCUME~1\ADMINI~1\Desktop\SDFix\backups\backups.zip

Files with Hidden Attributes :

Wed 22 Oct 2008 949,072 A.SHR — "C:\Program Files\Spybot - Search & Destroy\advcheck.dll"
Mon 15 Sep 2008 1,562,960 A.SHR — "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll"
Thu 14 Aug 2008 1,429,840 A.SHR — "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Wed 30 Jul 2008 4,891,984 A.SHR — "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Tue 16 Sep 2008 1,833,296 A.SHR — "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Wed 22 Oct 2008 962,896 A.SH. — "C:\Program Files\Spybot - Search & Destroy\Tools.dll"
Mon 18 Aug 2008 1,832,272 A.SHR — "C:\Program Files\TeaTimer (Spybot - Search & Destroy)\TeaTimer.exe"
Wed 25 Apr 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Sun 2 Sep 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Tue 15 May 2007 34,107,349 A..H. — "C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Media Player\MTVN\Downloads\002010FC\BITC.tmp"
Tue 15 May 2007 34,107,349 A..H. — "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Media Player\MTVN\Downloads\002010FC\BITC.tmp"

Finished!
Here's the ComboFix log, it turned my virus protection off and I'm not sure if you want me to enable it again or not.

ComboFix 09-01-17.02 - Administrator 2009-01-17 15:10:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1579 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.


Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\system32\init32.exe


.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SENEKA


((((((((((((((((((((((((( Files Created from 2008-12-17 to 2009-01-17 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-05-24 15:52 32,768 -csha-w c:\windows\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\UserData\index.dat
2007-05-24 15:51 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3C88CAC8-3425-48E4-87BB-315ACF4C9082}]
2008-12-31 15:57 290304 –a—— c:\windows\system32\urqPfEtQ.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-03-25 50528]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-27 125168]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-28 8429568]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-28 81920]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-01-25 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-12-11 286720]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-11-10 157312]
"Yworucowo"="c:\windows\avokeyibewereco.dll" [2009-01-16 134144]
"Qgoteci"="c:\windows\Akuderulatoq.dll" [2009-01-16 41984]
"nwiz"="nwiz.exe" [2007-04-28 c:\windows\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [2007-04-28 c:\windows\system32\nvhotkey.dll]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 c:\windows\stsystra.exe]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
–a–c— 2004-07-27 15:50 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\PharosSystems\\Core\\CTskMstr.exe"=
"c:\program files\Bradford Networks\Client Security Agent\bnpagent.exe"= c:\program files\Bradford Networks\Client Security Agent\bnpagent.exe
"c:\\Program Files\\AIM6\\aim6.exe"=


R3 npkycryp;npkycryp; [x]
R3 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2006-09-27 116464]
S2 BNPagent;Client Security Agent;c:\program files\Bradford Networks\Client Security Agent\bnpagent.exe [2007-03-22 1879432]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-02 99376]

.
Contents of the 'Scheduled Tasks' folder

2008-12-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
- - - - ORPHANS REMOVED - - - -

BHO-{1a07e793-223e-42b2-b178-8a90eb4997a7} - (no file)
BHO-{4AE13AC7-D466-481B-8754-560A779A6E1C} - (no file)
BHO-{7b41722c-a281-48ab-9b74-d54d50c0b4fb} - c:\windows\system32\xagxxl.dll
BHO-{ED59F7AE-9FAE-480A-8055-3DB559F00CAF} - (no file)
HKCU-Run-SVCHOST.EXE - c:\windows\system32\drivers\svchost.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.framingham.edu/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\TEMP\ntdll64.dll
Trusted Zone: *.antimalwareguard.com
Trusted Zone: *.antimalwareguard.com
Trusted Zone: *.gomyhit.com

O16 -: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF} - hxxp://testdevapp1:7777/forms/jinitiator/jinit.exe
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-17 16:50:53
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\windows\TEMP\mc21.tmp"
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\windows\system32\scardsvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\progra~1\PHAROS~1\Core\CTskMstr.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\stacsv.exe
c:\windows\system32\ZuneBusEnum.exe
c:\program files\Zune\ZuneNss.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\windows\system32\rundll32.exe
c:\program files\Apoint\ApMsgFwd.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\Apoint\hidfind.exe
c:\program files\Java\jre1.6.0_07\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2009-01-17 16:58:12 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-17 21:58:08

Pre-Run: 9,513,250,816 bytes free
Post-Run: 9,446,817,792 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

158 — E O F — 2008-12-18 18:39:01
hello

Please download the OTMoveIt3 by OldTimer
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    npkycryp
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised by a trained Security Analyst

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is Unchecked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
Here are the OTMoveIt3 and GMER results

Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
========== SERVICES/DRIVERS ==========
Service npkycryp stopped successfully.
Service npkycryp deleted successfully.
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_4ni8zSCYFqUtUAEquaLJ scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Pharos\UpdaterLog.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ntdll64.dll scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01182009_092739

Files moved on Reboot…
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_4ni8zSCYFqUtUAEquaLJ not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\Pharos\UpdaterLog.txt scheduled to be moved on reboot.
LoadLibrary failed for C:\WINDOWS\temp\ntdll64.dll
C:\WINDOWS\temp\ntdll64.dll NOT unregistered.
C:\WINDOWS\temp\ntdll64.dll moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\XUL.mfl moved successfully.
—————-
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-01-18 10:52:24
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.14 —-

SSDT 8A499008 ZwConnectPort
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xB7FD4350]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xB7FD4580]

—- Kernel code sections - GMER 1.0.14 —-

? C:\WINDOWS\TEMP\mc21.tmp The system cannot find the file specified. !

—- User code sections - GMER 1.0.14 —-

.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[780] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text c:\WINDOWS\system32\ZuneBusEnum.exe[832] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text c:\Program Files\Zune\ZuneNss.exe[1456] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Administrator\Desktop\gmer\gmer.exe[1528] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1536] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\alg.exe[1692] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1748] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\RocketDock\RocketDock.exe[2160] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\RocketDock\RocketDock.exe[2160] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\RocketDock\RocketDock.exe[2160] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\RocketDock\RocketDock.exe[2160] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\RocketDock\RocketDock.exe[2160] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\RocketDock\RocketDock.exe[2160] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\RocketDock\RocketDock.exe[2160] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\RocketDock\RocketDock.exe[2160] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\RocketDock\RocketDock.exe[2160] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\RocketDock\RocketDock.exe[2160] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\RocketDock\RocketDock.exe[2160] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\RocketDock\RocketDock.exe[2160] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Apoint\ApMsgFwd.exe[2228] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Apoint\HidFind.exe[2384] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Apoint\HidFind.exe[2384] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Apoint\HidFind.exe[2384] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Apoint\HidFind.exe[2384] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Apoint\HidFind.exe[2384] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Apoint\HidFind.exe[2384] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Apoint\HidFind.exe[2384] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Apoint\HidFind.exe[2384] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Apoint\HidFind.exe[2384] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Apoint\HidFind.exe[2384] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Apoint\HidFind.exe[2384] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Apoint\HidFind.exe[2384] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Apoint\Apntex.exe[2408] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Apoint\Apntex.exe[2408] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Apoint\Apntex.exe[2408] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Apoint\Apntex.exe[2408] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Apoint\Apntex.exe[2408] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Apoint\Apntex.exe[2408] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Apoint\Apntex.exe[2408] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Apoint\Apntex.exe[2408] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Apoint\Apntex.exe[2408] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Apoint\Apntex.exe[2408] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Apoint\Apntex.exe[2408] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Apoint\Apntex.exe[2408] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\svchost.exe[2676] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\Explorer.EXE[2844] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\Explorer.EXE[2844] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\Explorer.EXE[2844] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\Explorer.EXE[2844] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\Explorer.EXE[2844] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\Explorer.EXE[2844] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\Explorer.EXE[2844] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\Explorer.EXE[2844] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\Explorer.EXE[2844] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[2844] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\Explorer.EXE[2844] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[2844] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\wscntfy.exe[2864] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\wscntfy.exe[2864] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\wscntfy.exe[2864] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\wscntfy.exe[2864] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\wscntfy.exe[2864] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\wscntfy.exe[2864] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\wscntfy.exe[2864] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\wscntfy.exe[2864] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\wscntfy.exe[2864] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\wscntfy.exe[2864] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\wscntfy.exe[2864] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\wscntfy.exe[2864] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3240] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[3596] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe[3640] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\SYMANT~1\VPTray.exe[3692] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3792] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[3796] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3804] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3844] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\rundll32.exe[3844] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\rundll32.exe[3844] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\rundll32.exe[3844] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\rundll32.exe[3844] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\rundll32.exe[3844] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\rundll32.exe[3844] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\rundll32.exe[3844] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\rundll32.exe[3844] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3844] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3844] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3844] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[3860] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[3880] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3888] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[3896] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\stsystra.exe[3904] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\stsystra.exe[3904] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\stsystra.exe[3904] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\stsystra.exe[3904] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\stsystra.exe[3904] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\stsystra.exe[3904] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\stsystra.exe[3904] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\stsystra.exe[3904] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\stsystra.exe[3904] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\stsystra.exe[3904] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\stsystra.exe[3904] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\stsystra.exe[3904] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[3916] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Apoint\Apoint.exe[3916] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Apoint\Apoint.exe[3916] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Apoint\Apoint.exe[3916] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Apoint\Apoint.exe[3916] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Apoint\Apoint.exe[3916] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Apoint\Apoint.exe[3916] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Apoint\Apoint.exe[3916] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Apoint\Apoint.exe[3916] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Apoint\Apoint.exe[3916] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Apoint\Apoint.exe[3916] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Apoint\Apoint.exe[3916] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Zune\ZuneLauncher.exe[3948] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3976] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\rundll32.exe[3976] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\rundll32.exe[3976] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\rundll32.exe[3976] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\rundll32.exe[3976] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\rundll32.exe[3976] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\rundll32.exe[3976] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\rundll32.exe[3976] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\rundll32.exe[3976] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3976] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3976] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3976] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[3988] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\ctfmon.exe[3988] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3988] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\ctfmon.exe[3988] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\ctfmon.exe[3988] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\ctfmon.exe[3988] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\ctfmon.exe[3988] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\ctfmon.exe[3988] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3988] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[3988] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[3988] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[3988] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[4088] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Program Files\Messenger\msmsgs.exe[4088] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Messenger\msmsgs.exe[4088] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Program Files\Messenger\msmsgs.exe[4088] kernel32.dll!ExitProcess 7C81CAFA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Messenger\msmsgs.exe[4088] GDI32.dll!EndPage 77F2DC61 6 Bytes JMP 5F190F5A
.text C:\Program Files\Messenger\msmsgs.exe[4088] GDI32.dll!EndDoc 77F2DEF1 6 Bytes JMP 5F130F5A
.text C:\Program Files\Messenger\msmsgs.exe[4088] GDI32.dll!StartPage 77F2F49E 6 Bytes JMP 5F160F5A
.text C:\Program Files\Messenger\msmsgs.exe[4088] GDI32.dll!AbortDoc 77F44CD2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Messenger\msmsgs.exe[4088] GDI32.dll!StartDocW 77F45962 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Messenger\msmsgs.exe[4088] GDI32.dll!StartDocW + 4 77F45966 2 Bytes [ 11, 5F ]
.text C:\Program Files\Messenger\msmsgs.exe[4088] GDI32.dll!StartDocA 77F45E79 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Messenger\msmsgs.exe[4088] GDI32.dll!StartDocA + 4 77F45E7D 2 Bytes [ 0E, 5F ]

—- Devices - GMER 1.0.14 —-

AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \FileSystem\Fastfat \Fat B405AD20

AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

—- EOF - GMER 1.0.14 —-




*********Again thank you for all the help you're giving me
hello

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
Here are the Malwarebytes and Kaspersky scan logs. Malwarebytes' Anti-Malware 1.33 Database version: 1666 Windows 5.1.2600 Service Pack 3 1/18/2009 10:51:21 PM mbam-log-2009-01-18 (22-51-21).txt Scan type: Quick Scan Objects scanned: 58878 Time elapsed: 7 minute(s), 33 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 3 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 60 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost.exe (Trojan.Agent) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yworucowo (Trojan.Agent) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\qgoteci (Trojan.Agent) -> Delete on reboot. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\Administrator\Application Data\GetModule (Trojan.Agent) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\system32\awkhapqs.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\sqpahkwa.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\bmpalhkj.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\jkhlapmb.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\chbtfmtf.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ftmftbhc.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\daybcdcd.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\dcdcbyad.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\dckyqfxr.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\rxfqykcd.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\degtinvt.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tvnitged.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ejduqfxl.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\lxfqudje.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\knokrihd.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\dhirkonk.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\myjswetg.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\gtewsjym.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\scdlnbpy.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ypbnldcs.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tmlhnkxs.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\sxknhlmt.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\uhmilsvu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\uvslimhu.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wcomrxgx.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\xgxrmocw.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\yboerfjp.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\pjfreoby.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ieuioc.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\orxfqjwb.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\otmkdkbs.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\otvfxm.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ovyvtbav.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\owcujd.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\panoymub.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\fboupc.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ffkuz.dll (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\system32\pvgagbdt.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\rozlzr.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\rrkgqjyf.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\sidkndyt.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\beflslmy.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\emfgzx.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\guedhu.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\hamknxxl.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\xlmdjtct.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\xscako.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\yyyesttq.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tutpdr.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\sewljm.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\kvttnr.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\avokeyibewereco.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\Akuderulatoq.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\senekadf.dat (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\senekalog.dat (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\drivers\seneka.sys (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\warning.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ahtn.htm (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\frmwrk32.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\TDSSqksa.dll (Rootkit.Agent) -> Quarantined and deleted successfully. ————- ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Monday, January 19, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Monday, January 19, 2009 02:50:20 Records in database: 1644994 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Files scanned: 67406 Threat name: 26 Infected objects: 56 Suspicious objects: 0 Duration of the scan: 02:05:26 File name / Threat name / Threats count C:\Documents and Settings\Administrator\Desktop\SDFix\backups\backups.zip Infected: Packed.Win32.PolyCrypt.d 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\00F40000\49FF1B10.VBN Infected: Trojan.Win32.Monder.abke 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01EC0000\49ECF5A7.VBN Infected: Rootkit.Win32.Clbd.lc 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01EC0001\49ECF61F.VBN Infected: Backdoor.Win32.UltimateDefender.a 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01EC0002\49ECF63D.VBN Infected: Backdoor.Win32.UltimateDefender.a 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03880000\4BC852E2.VBN Infected: Trojan-Downloader.Win32.Agent.atga 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03880001\4BC85FE9.VBN Infected: Trojan.Win32.Monder.abke 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03880002\4BC8791A.VBN Infected: Trojan.Win32.Monder.abnh 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03880003\4BC887A7.VBN Infected: Trojan.Win32.Monder.abnp 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05B00000\4DBFE718.VBN Infected: Trojan.Win32.Monder.abnp 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07A40000.VBN Infected: Backdoor.Win32.UltimateDefender.a 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07A40001.VBN Infected: Backdoor.Win32.TDSS.bkw 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07A40002.VBN Infected: Backdoor.Win32.TDSS.bkw 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A480000\4B7B36EF.VBN Infected: Trojan-Downloader.Win32.Agent.auhc 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AD00000.VBN Infected: Trojan-Downloader.Win32.Small.agtx 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AD00001.VBN Infected: Trojan-Downloader.Win32.Small.aguh 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AD00007.VBN Infected: not-a-virus:AdWare.Win32.Agent.hza 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BD00000\4BFFF19E.VBN Infected: Trojan.Win32.Monder.abke 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BF80000\4BFA90F8.VBN Infected: Trojan.Win32.Monder.abke 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BF80001\4BFA9FB1.VBN Infected: Trojan.Win32.Monder.abna 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C5C0000\4D5C4886.VBN Infected: Trojan.Win32.Monder.abke 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CA00000\4DE6CA5B.VBN Infected: Trojan.Win32.Monder.abke 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CC40000.VBN Infected: Trojan.Win32.Monder.abke 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CDC0000\4DDDA385.VBN Infected: Trojan.Win32.Monder.abke 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CDC0001\4DDDB158.VBN Infected: Trojan.Win32.Monder.abke 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D100000\4D3622B3.VBN Infected: Rootkit.Win32.Clbd.lc 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D300001\4D3D43D2.VBN Infected: Trojan.Win32.Monder.abke 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D300002\4D3D448E.VBN Infected: Trojan-Downloader.Win32.Agent.atga 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0ED80000\4FD9C492.VBN Infected: Trojan.Win32.Monder.abke 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0FE40000\4FE5A810.VBN Infected: Trojan.Win32.Monder.abna 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\13A00003.VBN Infected: Backdoor.Win32.UltimateDefender.a 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\13A00004.VBN Infected: Backdoor.Win32.UltimateDefender.a 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\13A00005.VBN Infected: Backdoor.Win32.UltimateDefender.a 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\13A00006.VBN Infected: Backdoor.Win32.TDSS.bkw 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\13A00007.VBN Infected: Backdoor.Win32.TDSS.bkw 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\13A00008.VBN Infected: Trojan-Downloader.Win32.FraudLoad.vdoj 1 C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\13A00009.VBN Infected: Trojan-Downloader.Win32.FraudLoad.vdoj 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\senekaehivldpu.sys.vir Infected: Rootkit.Win32.Agent.gjw 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_seneka_.sys.zip Infected: Rootkit.Win32.Agent.gjw 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\senekaoachanat.dll.vir Infected: Trojan-Downloader.Win32.Agent.bdqo 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\senekauqffgggi.dll.vir Infected: Trojan.Win32.Small.brl 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\userinit.exe.vir Infected: Trojan-Dropper.Win32.Agent.afdc 1 C:\WINDOWS\system32\998.exe Infected: Trojan-PSW.Win32.Papras.hz 1 C:\WINDOWS\system32\bjhfzh.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.gbc 1 C:\WINDOWS\system32\chert5-998.exe Infected: Trojan-Downloader.Win32.Agent.bdlh 1 C:\WINDOWS\system32\eqarwdsi.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.gbe 1 C:\WINDOWS\system32\ffnwxi.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.fys 1 C:\WINDOWS\system32\hcuvyd.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.gad 1 C:\WINDOWS\system32\ipkflv.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.gbe 1 C:\WINDOWS\system32\k9261108.exe Infected: Trojan-Dropper.Win32.Agent.adhp 1 C:\WINDOWS\system32\nyktarca.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.gbc 1 C:\WINDOWS\system32\oqrfoluj.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.gbc 1 C:\WINDOWS\system32\uyxffscq.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.fys 1 C:\WINDOWS\system32\wbsyqras.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.gad 1 C:\WINDOWS\system32\wbyxcn.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.gbc 1 C:\_OTMoveIt\MovedFiles\01182009_092739\WINDOWS\temp\ntdll64.dll Infected: Exploit.Win32.IMG-WMF.os 1 The selected area was scanned.
hello




1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\998.exe
C:\WINDOWS\system32\bjhfzh.dll
C:\WINDOWS\system32\chert5-998.exe
C:\WINDOWS\system32\eqarwdsi.dll
C:\WINDOWS\system32\ffnwxi.dll
C:\WINDOWS\system32\hcuvyd.dll
C:\WINDOWS\system32\ipkflv.dll
C:\WINDOWS\system32\k9261108.exe
C:\WINDOWS\system32\nyktarca.dll
C:\WINDOWS\system32\oqrfoluj.dll
C:\WINDOWS\system32\uyxffscq.dll
C:\WINDOWS\system32\wbsyqras.dll
C:\WINDOWS\system32\wbyxcn.dll

Folder::

Registry::

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Here's the ComboFix log from the last step you gave me.
ComboFix 09-01-19.01 - Administrator 2009-01-19 12:10:54.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1360 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
c:\windows\system32\998.exe
c:\windows\system32\bjhfzh.dll
c:\windows\system32\chert5-998.exe
c:\windows\system32\eqarwdsi.dll
c:\windows\system32\ffnwxi.dll
c:\windows\system32\hcuvyd.dll
c:\windows\system32\ipkflv.dll
c:\windows\system32\k9261108.exe
c:\windows\system32\nyktarca.dll
c:\windows\system32\oqrfoluj.dll
c:\windows\system32\uyxffscq.dll
c:\windows\system32\wbsyqras.dll
c:\windows\system32\wbyxcn.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\nah_hyuf.exe
c:\windows\system32\998.exe
c:\windows\system32\bjhfzh.dll
c:\windows\system32\bwkxbuer.ini
c:\windows\system32\chert5-998.exe
c:\windows\system32\dfjwlyri.ini
c:\windows\system32\eqarwdsi.dll
c:\windows\system32\ffnwxi.dll
c:\windows\system32\hcuvyd.dll
c:\windows\system32\hgoonwar.ini
c:\windows\system32\ipkflv.dll
c:\windows\system32\k9261108.exe
c:\windows\system32\nyktarca.dll
c:\windows\system32\oqrfoluj.dll
c:\windows\system32\QtEfPqru.ini
c:\windows\system32\QtEfPqru.ini2
c:\windows\system32\qwbewe.dll
c:\windows\system32\segvrhcl.ini
c:\windows\system32\test.ttt
c:\windows\system32\uniq.tll
c:\windows\system32\uyxffscq.dll
c:\windows\system32\viyrscrv.dll
c:\windows\system32\vxajrgcq.ini
c:\windows\system32\wbsyqras.dll
c:\windows\system32\wbyxcn.dll
c:\windows\system32\win32hlp.cnf
c:\windows\system32\yaaywnhy.ini
c:\windows\system32\ysfoymej.ini
c:\windows\wiaserviv.log

.
((((((((((((((((((((((((( Files Created from 2008-12-19 to 2009-01-19 )))))))))))))))))))))))))))))))
.

2009-01-18 22:42 . 2009-01-18 22:42 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-18 22:42 . 2009-01-18 22:42 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-18 22:42 . 2009-01-18 22:42 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-01-18 22:42 . 2009-01-14 16:11 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-18 22:42 . 2009-01-14 16:11 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-18 10:22 . 2009-01-18 10:22 250 –a—— c:\windows\gmer.ini
2009-01-18 09:27 . 2009-01-18 09:27 d——– C:\_OTMoveIt
2009-01-17 19:28 . 2009-01-17 19:28 118 –a—— c:\windows\system32\MRT.INI
2009-01-17 11:32 . 2009-01-17 11:32 578,560 –a–c— c:\windows\system32\dllcache\user32.dll
2009-01-17 11:24 . 2009-01-17 11:25 d——– c:\windows\ERUNT
2009-01-16 17:53 . 2009-01-16 17:53 d——– c:\program files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-18 00:30 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-31 20:51 ——— d—–w c:\program files\Symantec AntiVirus
2008-12-29 19:50 ——— d—–w c:\program files\Common Files\Adobe
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
2008-11-19 21:25 ——— d—–w c:\program files\Zune
2008-11-10 17:23 60,032 —-a-w c:\windows\system32\ZuneBusEnum.exe
2008-11-10 17:23 243,840 —-a-w c:\windows\system32\ZuneWlanCfgSvc.exe
2008-11-10 17:09 73,728 —-a-w c:\windows\system32\ZuneUsbTransport.dll
2008-11-10 17:09 57,344 —-a-w c:\windows\system32\ZuneRegUtil.dll
2008-11-10 17:09 310,272 —-a-w c:\windows\system32\ZuneNetProxy.dll
2008-11-10 17:09 18,944 —-a-w c:\windows\system32\ZuneTcp2Udp.dll
2008-11-10 17:09 145,920 —-a-w c:\windows\system32\ZuneMTPZ.dll
2008-11-10 17:09 12,800 —-a-w c:\windows\system32\ZunePTDNS.dll
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2007-05-24 15:52 32,768 -csha-w c:\windows\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\UserData\index.dat
2007-05-24 15:51 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
.

((((((((((((((((((((((((((((( snapshot@2009-01-17_16.56.42.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-18 15:22:36 884,736 —-a-w c:\windows\gmer.dll
+ 2008-04-18 02:13:02 811,008 —-a-w c:\windows\gmer.exe
- 2008-12-10 20:09:02 1,165,584 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-01-18 00:30:31 1,165,584 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2008-12-10 20:09:03 20,240 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-01-18 00:30:32 20,240 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-12-10 20:09:03 159,504 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2009-01-18 00:30:31 159,504 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2008-12-10 20:09:03 184,080 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-01-18 00:30:31 184,080 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2008-12-10 20:09:03 217,864 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-01-18 00:30:32 217,864 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2008-12-10 20:09:03 18,704 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-01-18 00:30:32 18,704 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-12-10 20:09:03 35,088 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-01-18 00:30:32 35,088 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-12-10 20:09:03 845,584 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2009-01-18 00:30:31 845,584 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2008-12-10 20:09:03 922,384 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-01-18 00:30:31 922,384 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2008-12-10 20:09:03 272,648 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2009-01-18 00:30:32 272,648 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2008-12-10 20:09:03 888,080 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-01-18 00:30:32 888,080 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-12-10 20:09:02 1,172,240 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-01-18 00:30:31 1,172,240 —-a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-09-08 10:41:42 333,824 -c—-w c:\windows\system32\dllcache\srv.sys
+ 2008-12-11 10:57:09 333,952 -c—-w c:\windows\system32\dllcache\srv.sys
+ 2009-01-18 15:22:36 85,969 —-a-w c:\windows\system32\drivers\gmer.sys
- 2008-12-01 18:40:41 1,556,904 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-01-18 14:42:35 1,556,904 —-a-w c:\windows\system32\FNTCACHE.DAT
- 2008-12-09 23:24:37 17,593,280 —-a-w c:\windows\system32\MRT.exe
+ 2009-01-10 01:35:28 20,853,704 —-a-w c:\windows\system32\MRT.exe
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-03-25 50528]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-27 125168]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-28 8429568]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-28 81920]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-01-25 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-12-11 286720]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-11-10 157312]
"nwiz"="nwiz.exe" [2007-04-28 c:\windows\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [2007-04-28 c:\windows\system32\nvhotkey.dll]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 c:\windows\stsystra.exe]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
–a–c— 2004-07-27 15:50 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\PharosSystems\\Core\\CTskMstr.exe"=
"c:\program files\Bradford Networks\Client Security Agent\bnpagent.exe"= c:\program files\Bradford Networks\Client Security Agent\bnpagent.exe
"c:\\Program Files\\AIM6\\aim6.exe"=

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-03 99376]
R4 BNPagent;Client Security Agent;c:\program files\Bradford Networks\Client Security Agent\bnpagent.exe [2007-03-22 1879432]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-11-06 24652]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2006-09-27 116464]

— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder

2008-12-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
- - - - ORPHANS REMOVED - - - -

BHO-{1a07e793-223e-42b2-b178-8a90eb4997a7} - (no file)
BHO-{4AE13AC7-D466-481B-8754-560A779A6E1C} - (no file)
BHO-{7b41722c-a281-48ab-9b74-d54d50c0b4fb} - (no file)
BHO-{ED59F7AE-9FAE-480A-8055-3DB559F00CAF} - (no file)
HKLM-Run-Yworucowo - c:\windows\avokeyibewereco.dll
HKLM-Run-Qgoteci - c:\windows\Akuderulatoq.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.framingham.edu/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: *.antimalwareguard.com
Trusted Zone: *.antimalwareguard.com
Trusted Zone: *.gomyhit.com
DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF} - hxxp://testdevapp1:7777/forms/jinitiator/jinit.exe
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jsnu979p.default\
FF - prefs.js: browser.startup.homepage - hxxp://digg.com/
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJinit13122.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-19 12:13:17
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\windows\TEMP\mc21.tmp"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(896)
c:\windows\system32\igfxdev.dll
.
Completion time: 2009-01-19 12:15:35
ComboFix-quarantined-files.txt 2009-01-19 17:15:32
ComboFix2.txt 2009-01-17 21:58:13

Pre-Run: 9,359,986,688 bytes free
Post-Run: 9,399,586,816 bytes free

232 — E O F — 2009-01-18 00:30:36
————-

For some reason the Windows Security says my Virus protection is off, but I still have Symantec AntiVirus running is that normal?
Here's a new HiJackThis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:54:11 PM, on 1/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bradford Networks\Client Security Agent\bnpagent.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\PHAROS~1\Core\CTskMstr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\StacSV.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Apoint\Apoint.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Zune\Zune.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.framingham.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {1a07e793-223e-42b2-b178-8a90eb4997a7} - (no file)
O2 - BHO: (no name) - {4AE13AC7-D466-481B-8754-560A779A6E1C} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7b41722c-a281-48ab-9b74-d54d50c0b4fb} - (no file)
O2 - BHO: (no name) - {ED59F7AE-9FAE-480A-8055-3DB559F00CAF} - (no file)
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [Yworucowo] rundll32.exe "C:\WINDOWS\avokeyibewereco.dll",e
O4 - HKLM\..\Run: [Qgoteci] rundll32.exe "C:\WINDOWS\Akuderulatoq.dll",e
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe
O4 - HKUS\S-1-5-21-938136298-1729868018-2570642418-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O15 - Trusted Zone: *.antimalwareguard.com
O15 - Trusted Zone: *.antimalwareguard.com (HKLM)
O15 - Trusted Zone: *.gomyhit.com (HKLM)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1177525140296
O16 - DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF} (JInitiator 1.3.1.22) - http://testdevapp1:7777/forms/jinitiator/jinit.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Client Security Agent (BNPagent) - Bradford Networks - C:\Program Files\Bradford Networks\Client Security Agent\bnpagent.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pharos Systems ComTaskMaster - Pharos Systems International - C:\PROGRA~1\PHAROS~1\Core\CTskMstr.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\StacSV.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 10006 bytes


*****I also keep getting this pop-up whenever I start my system back up that says "symantec AntiVirus auto-protect is off"

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI