Hello,
Here are the requested logs again.
And I have a question: Can I reenable the CD Emulation now? What effect does it have on the computer if left disabled?
Thank you for your help.
DDS.txt
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18372
Run by Owner at 15:49:20 on 2011-10-05
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.581 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: ZoneAlarm Firewall *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\TradeStation 8.6 (Build 2696)\Program\ORPlat.exe
C:\PROGRA~1\TRADES~3.6(B\Program\ordllhst.exe
C:\PROGRA~1\TRADES~3.6(B\Program\whserver.exe
C:\PROGRA~1\TRADES~3.6(B\Program\orcal.exe
C:\PROGRA~1\TRADES~3.6(B\Program\orclprxy.exe
C:\PROGRA~1\TRADES~3.6(B\Program\TSSCAN~1.EXE
C:\PROGRA~1\TRADES~3.6(B\Program\orchart.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = <local>
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
IE: Atomic Email Hunter - c:\program files\atompark\atomic email hunter\ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1280857019828
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1280882643609
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
TCP: Interfaces\{7D7DBF66-DF3C-4DB0-BF20-6BE61764BDDD} : NameServer = 68.94.156.1,151.164.8.201
Notify: igfxcui - igfxdev.dll
Notify: TPSvc - TPSvc.dll
LSA: Notification Packages = :\windows\system32\srrstr.dll cecli scecli
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R1 MpKsl64d4357e;MpKsl64d4357e;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3c5b9a44-6537-438b-8c37-e31e203bc14b}\MpKsl64d4357e.sys [2011-10-2 28752]
S1 b7ed4ce0;b7ed4ce0;c:\windows\system32\drivers\b7ed4ce0.sys [2009-7-3 0]
S1 MpKsl9e0ea756;MpKsl9e0ea756;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3a21c3b1-d244-4a99-b130-9121e8a45d01}\mpksl9e0ea756.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3a21c3b1-d244-4a99-b130-9121e8a45d01}\MpKsl9e0ea756.sys [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\ambfilt.sys --> c:\windows\system32\drivers\Ambfilt.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-7-7 14904]
.
=============== Created Last 30 ================
.
2011-10-05 02:17:26 -------- d-----w- c:\program files\Microsoft Image Composer
2011-10-03 04:12:25 28752 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3c5b9a44-6537-438b-8c37-e31e203bc14b}\MpKsl64d4357e.sys
2011-10-03 04:12:23 56200 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3c5b9a44-6537-438b-8c37-e31e203bc14b}\offreg.dll
2011-10-03 01:16:03 16896 ----a-w- c:\windows\system32\SET1396.tmp
2011-10-03 01:16:01 177152 ----a-w- c:\windows\system32\SET1375.tmp
2011-10-03 01:15:58 80896 ----a-w- c:\windows\system32\SET1355.tmp
2011-10-03 01:15:58 354304 ----a-w- c:\windows\system32\SET1358.tmp
2011-10-03 01:15:57 121856 ----a-w- c:\windows\system32\SET1349.tmp
2011-10-03 01:15:57 1135616 ----a-w- c:\windows\system32\SET134E.tmp
2011-10-03 01:11:59 58368 ----a-w- c:\windows\system32\SET5CF.tmp
2011-10-03 01:10:59 49664 ----a-w- c:\windows\system32\SET350.tmp
2011-10-03 01:08:56 19569 ----a-w- c:\windows\003500_.tmp
2011-10-03 01:06:59 58880 ----a-w- c:\windows\system32\dllcache\agentdpv.dll
2011-10-02 21:09:08 -------- d-----w- c:\documents and settings\all users\application data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-10-02 16:40:17 7269712 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3c5b9a44-6537-438b-8c37-e31e203bc14b}\mpengine.dll
2011-10-01 00:59:00 -------- d-----w- c:\program files\PFPortChecker
2011-09-30 12:35:46 73728 ----a-w- c:\windows\system32\TOverlay.ax
2011-09-30 12:35:46 630784 ----a-w- c:\windows\system32\AxisToolBar.ocx
2011-09-30 12:35:46 53248 ----a-w- c:\windows\system32\DSTimeStamp.ax
2011-09-30 12:35:46 420240 ----a-w- c:\windows\system32\mpg4c32.dll
2011-09-30 12:35:46 40960 ----a-w- c:\windows\system32\wavdest.ax
2011-09-30 12:35:46 36864 ----a-w- c:\windows\system32\Sof2FFTPrj.ocx
2011-09-30 12:35:46 28672 ----a-w- c:\windows\system32\SpecBarPrj.ocx
2011-09-30 12:35:46 28672 ----a-w- c:\windows\system32\PCWinSoftPBar.ocx
2011-09-30 12:35:46 126976 ----a-w- c:\windows\system32\ArielColorCtrl.ocx
2011-09-30 12:35:45 438976 ----a-w- c:\windows\system32\MSHFLXGD.OCX
2011-09-30 12:35:45 188416 ----a-w- c:\windows\system32\UScreenCapture.ax
2011-09-30 12:35:40 -------- d-----w- c:\program files\1AVStreamer
2011-09-29 23:08:19 -------- d-----w- c:\documents and settings\owner\local settings\application data\PackageAware
2011-09-28 19:11:11 -------- d-----w- c:\program files\AutoHotkey
2011-09-27 22:52:15 -------- d-----w- c:\documents and settings\owner\local settings\application data\CrashRpt
2011-09-27 22:52:01 -------- d-----w- c:\documents and settings\owner\local settings\application data\Procaster
2011-09-27 22:52:00 -------- d-----w- c:\program files\Livestream Procaster
2011-09-27 21:54:28 -------- d-----w- c:\program files\NCH Swift Sound
2011-09-26 03:12:20 -------- d-----w- c:\documents and settings\owner\application data\NCH Software
2011-09-19 12:40:10 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-09-19 12:40:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-09-18 18:49:01 388096 ----a-r- c:\documents and settings\owner\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-09-17 22:41:26 -------- d--h--w- c:\windows\system32\GroupPolicy
2011-09-17 15:24:20 -------- d-----w- c:\program files\common files\iS3
2011-09-17 15:24:19 -------- d-----w- c:\documents and settings\all users\application data\STOPzilla!
2011-09-17 15:01:55 7152464 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\updates\mpengine.dll
2011-09-17 12:52:38 -------- dc-h--w- c:\windows\ie8
2011-09-17 12:38:18 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-09-17 12:38:18 -------- d-----w- c:\windows\system32\wbem\Repository
2011-09-17 12:38:03 -------- d-----w- c:\program files\Microsoft Security Client
2011-09-17 02:36:41 -------- d-----w- C:\5d7fe6c27d8a27d474a36cdcc31f
2011-09-17 02:06:49 -------- d-----w- c:\program files\Microsoft Security Client(2)
.
==================== Find3M ====================
.
2010-12-09 12:48:29 37794 ----a-w- c:\program files\Uninstal.exe
2001-10-30 19:14:40 124416 ----a-w- c:\program files\decks.exe
2000-12-22 16:13:34 275968 ----a-w- c:\program files\winamp11.exe
1999-08-31 10:26:12 376320 ----a-w- c:\program files\Msvcrtd.dll
1999-04-23 22:22:00 176128 ----a-w- c:\program files\COMDLG32.DLL
1998-07-29 18:00:06 266293 ----a-w- c:\program files\MSVCRT.DLL
.
============= FINISH: 15:50:41.70 ===============
Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 8/3/2010 5:58:52 PM
System Uptime: 10/2/2011 11:11:58 PM (64 hours ago)
.
Motherboard: Intel Corporation | | D945GCNL
Processor: Intel® Pentium® Dual CPU E2200 @ 2.20GHz | LGA 775 | 2194/200mhz
Processor: Intel® Pentium® Dual CPU E2200 @ 2.20GHz | LGA 775 | 2194/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 229 GiB total, 179.394 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 37 GiB total, 10.399 GiB free.
F: is Removable
G: is Removable
H: is Removable
I: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP1: 9/28/2011 9:36:13 AM - System Checkpoint
RP2: 9/29/2011 4:04:14 PM - System Checkpoint
RP3: 9/30/2011 7:54:54 AM - Removed Adobe Reader 9.3.3.
RP4: 10/1/2011 8:18:59 AM - System Checkpoint
RP5: 10/2/2011 10:10:52 AM - System Checkpoint
RP6: 10/2/2011 4:24:03 PM - Removed upapp
RP7: 10/2/2011 5:25:02 PM - Removed HP Update
RP8: 10/2/2011 8:09:06 PM - Installed Windows XP Service Pack 3.
RP9: 10/3/2011 8:18:15 PM - System Checkpoint
RP10: 10/4/2011 10:28:41 PM - System Checkpoint
.
==== Installed Programs ======================
.
1AVStreamer version 1.9.3.00
2007 Microsoft Office system
32 Bit HP CIO Components Installer
4500_Help
Activation Assistant for the 2007 Microsoft Office suites
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.4.6
Atomic Email Hunter 4.75
Atomic Mail Verifier 5.30
AutoHotkey 1.0.48.05
BESTDirect 8
BPD_HPSU
bpd_scan
BPDSoftware
BPDSoftware_Ini
BufferChm
CustomerResearchQFolder
CyberPower PowerPanel Personal Edition
Decks v1.20
Destination Component
DeviceDiscovery
Digital Ear
DocMgr
DocProc
DocProcQFolder
Doxillion Document Converter
Easy Karaoke Player version 3.33
Easy Songwriter (Version 1.2)
Email Marketing Professional 2011 (Free Version)
Emex 3
eSupportQFolder
Fax
Free Mp3 Wma Converter V 1.91
Google Talk Plugin
GPBaseService
H&R Block Deluxe + Efile + State 2009
HiJackThis
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB970653-v3)
HP Customer Participation Program 10.0
hp deskjet 3320 series
hp deskjet 3320 series (Remove only)
HP Document Manager 1.0
HP Imaging Device Functions 10.0
hp instant support
HP Officejet J4500 Series
HP Photosmart Essential 2.5
HP Smart Web Printing
HP Solution Center 10.0
HPProductAssistant
HPSSupply
Intel® Graphics Media Accelerator Driver
J4500
Java Auto Updater
Java 6 Update 21
KaraFun Player 1.20.67-beta
KaraFun Studio 1.20.75-beta
Karaoke CD+G Creator
Karaoke Island's MP3 karaoke Player
Lightscreen
LightScribe 1.4.97.1
Livestream Procaster
Malwarebytes' Anti-Malware version 1.51.2.1300
MarketResearch
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Image Composer 1.5
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office FrontPage 2003
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Hybrid 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft Visual C++ 2005 Redistributable
Microsoft Windows Journal Viewer
MP3 Audio Recorder
MSN
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6.0 Parser (KB933579)
Music Editor Free
Music MasterWorks v3.94
NCH Toolbox
Nero Suite
NinjaTrader 6.5
Noderator
OCR Software by I.R.I.S. 10.0
PCI Audio Driver
PFPortChecker 1.0.39
PhotoPad Image Editor
ProductContext
PSSWCORE
Ralink Wireless LAN
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.1
Scan
ScreenStream
Secunia PSI
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows XP (KB923789)
Shop for HP Supplies
Siglos Karaoke Player/Recorder
SmartWebPrintingOC
SolutionCenter
Status
TaxCut Premium + State + Efile 2008
Toolbox
Trader Workstation 4.0
TradeStation 8.6 (Build 2525)
TradeStation 8.6 (Build 2612)
TradeStation 8.6 (Build 2696)
TradeStation Futures
TrayApp
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Office 2007 (KB934528)
Update for Office System 2007 Setup (KB929722)
Update for Windows XP (KB914882)
Update for Windows XP (KB932823-v3)
VC 9.0 Runtime
VideoToolkit01
VOCALOID Demo Miriam
VocalRemover Setup
Vogone Demo
WebFldrs XP
WebReg
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Internet Explorer 8 Release Candidate 1
Windows Media Format Runtime
Windows Media Player 10
.
==== Event Viewer Messages From Past Week ========
.
9/30/2011 9:26:00 AM, error: Service Control Manager [7000] - The Background Intelligent Transfer Service service failed to start due to the following error: The system cannot find the file specified.
9/30/2011 7:52:48 AM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery Service service hung on starting.
9/30/2011 7:51:25 AM, error: Service Control Manager [7000] - The Upload Manager service failed to start due to the following error: The account specified for this service is different from the account specified for other services running in the same process.
9/30/2011 7:51:25 AM, error: Service Control Manager [7000] - The Automatic Updates service failed to start due to the following error: The system cannot find the file specified.
9/30/2011 2:26:32 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC90.DebugCRT. Reference error message: The referenced assembly is not installed on your system. .
9/30/2011 2:26:32 PM, error: SideBySide [59] - Generate Activation Context failed for C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll. Reference error message: The operation completed successfully. .
9/30/2011 2:26:32 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC90.DebugCRT could not be found and Last Error was The referenced assembly is not installed on your system.
9/30/2011 1:30:07 PM, error: DCOM [10005] - DCOM got error "%2" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
9/29/2011 9:47:56 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.126.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
9/29/2011 9:47:56 AM, error: DCOM [10005] - DCOM got error "%2" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
9/28/2011 9:52:57 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.126.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/4/2011 11:22:26 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/4/2011 11:17:26 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/3/2011 11:22:27 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/3/2011 11:17:27 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/2/2011 9:52:48 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/2/2011 9:41:55 AM, error: atapi [9] - The device, \Device\Ide\IdePort1, did not respond within the timeout period.
10/2/2011 9:00:57 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/2/2011 8:36:50 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/2/2011 8:24:25 PM, error: NtServicePack [4374] - Windows XP Service Pack 3 installation failed, leaving Windows XP partially updated.
Service Pack 3 installation did not complete.
10/2/2011 8:16:23 PM, error: NtServicePack [4373] - Windows XP Service Pack 3 installation failed.
Access is denied.
10/2/2011 8:01:37 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/2/2011 7:56:37 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/2/2011 6:32:28 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/2/2011 5:15:19 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/2/2011 5:03:09 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/2/2011 4:10:28 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/2/2011 11:22:26 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/2/2011 10:54:21 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/1/2011 8:01:36 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/1/2011 7:56:36 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
10/1/2011 10:44:26 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.113.570.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error code: 0x80070002 Error description: The system cannot find the file specified.
.
==== End Of File ===========================
GMER.log
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-10-05 19:01:30
Windows 5.1.2600 Service Pack 2 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T0L0-17 Hitachi_HDT725025VLA380 rev.V5DOA73A
Running: gmer.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\afncapod.sys
---- Kernel code sections - GMER 1.0.15 ----
? C:\DOCUME~1\Owner\LOCALS~1\Temp\aswMBR.sys The system cannot find the file specified. !
? C:\DOCUME~1\Owner\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[1012] USER32.dll!CallNextHookEx 77D4ED6E 5 Bytes JMP 0151D5B4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1012] USER32.dll!CreateWindowExW 77D51AD5 5 Bytes JMP 015267BD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1012] USER32.dll!DialogBoxParamW 77D56702 5 Bytes JMP 01454315 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1012] USER32.dll!DialogBoxParamA 77D588E1 5 Bytes JMP 01646318 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1012] USER32.dll!DialogBoxIndirectParamW 77D62598 5 Bytes JMP 0164637B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1012] USER32.dll!MessageBoxIndirectA 77D6AEF1 5 Bytes JMP 016462AD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1012] USER32.dll!SetWindowsHookExW 77D6E621 5 Bytes JMP 01521D31 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1012] USER32.dll!UnhookWindowsHookEx 77D6F29F 5 Bytes JMP 014970D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1012] USER32.dll!MessageBoxExW 77D80559 5 Bytes JMP 0164617E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1012] USER32.dll!MessageBoxExA 77D8057D 5 Bytes JMP 016461E0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1012] USER32.dll!DialogBoxIndirectParamA 77D86CED 3 Bytes JMP 016463DE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1012] USER32.dll!DialogBoxIndirectParamA + 4 77D86CF1 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[1012] USER32.dll!MessageBoxIndirectW 77D960B7 3 Bytes JMP 01646242 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1012] USER32.dll!MessageBoxIndirectW + 4 77D960BB 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[1012] ole32.dll!CoCreateInstance 77526009 5 Bytes JMP 015274D1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1940] USER32.dll!CallNextHookEx 77D4ED6E 5 Bytes JMP 0151D5B4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1940] USER32.dll!CreateWindowExW 77D51AD5 5 Bytes JMP 015267BD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1940] USER32.dll!DialogBoxParamW 77D56702 5 Bytes JMP 01454315 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1940] USER32.dll!DialogBoxParamA 77D588E1 5 Bytes JMP 01646318 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1940] USER32.dll!DialogBoxIndirectParamW 77D62598 5 Bytes JMP 0164637B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1940] USER32.dll!MessageBoxIndirectA 77D6AEF1 5 Bytes JMP 016462AD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1940] USER32.dll!SetWindowsHookExW 77D6E621 5 Bytes JMP 01521D31 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1940] USER32.dll!UnhookWindowsHookEx 77D6F29F 5 Bytes JMP 014970D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1940] USER32.dll!MessageBoxExW 77D80559 5 Bytes JMP 0164617E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1940] USER32.dll!MessageBoxExA 77D8057D 5 Bytes JMP 016461E0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1940] USER32.dll!DialogBoxIndirectParamA 77D86CED 3 Bytes JMP 016463DE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1940] USER32.dll!DialogBoxIndirectParamA + 4 77D86CF1 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[1940] USER32.dll!MessageBoxIndirectW 77D960B7 3 Bytes JMP 01646242 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1940] USER32.dll!MessageBoxIndirectW + 4 77D960BB 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[1940] ole32.dll!CoCreateInstance 77526009 5 Bytes JMP 015274D1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!CallNextHookEx 77D4ED6E 5 Bytes JMP 0151D5B4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!CreateWindowExW 77D51AD5 5 Bytes JMP 015267BD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!DialogBoxParamW 77D56702 5 Bytes JMP 01454315 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!DialogBoxParamA 77D588E1 5 Bytes JMP 01646318 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!DialogBoxIndirectParamW 77D62598 5 Bytes JMP 0164637B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!MessageBoxIndirectA 77D6AEF1 5 Bytes JMP 016462AD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!SetWindowsHookExW 77D6E621 5 Bytes JMP 01521D31 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!UnhookWindowsHookEx 77D6F29F 5 Bytes JMP 014970D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!MessageBoxExW 77D80559 5 Bytes JMP 0164617E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!MessageBoxExA 77D8057D 5 Bytes JMP 016461E0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!DialogBoxIndirectParamA 77D86CED 3 Bytes JMP 016463DE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!DialogBoxIndirectParamA + 4 77D86CF1 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!MessageBoxIndirectW 77D960B7 3 Bytes JMP 01646242 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!MessageBoxIndirectW + 4 77D960BB 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] ole32.dll!CoCreateInstance 77526009 5 Bytes JMP 015274D1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2132] USER32.dll!CallNextHookEx 77D4ED6E 5 Bytes JMP 0151D5B4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2132] USER32.dll!CreateWindowExW 77D51AD5 5 Bytes JMP 015267BD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2132] USER32.dll!DialogBoxParamW 77D56702 5 Bytes JMP 01454315 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2132] USER32.dll!DialogBoxParamA 77D588E1 5 Bytes JMP 01646318 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2132] USER32.dll!DialogBoxIndirectParamW 77D62598 5 Bytes JMP 0164637B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2132] USER32.dll!MessageBoxIndirectA 77D6AEF1 5 Bytes JMP 016462AD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2132] USER32.dll!SetWindowsHookExW 77D6E621 5 Bytes JMP 01521D31 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2132] USER32.dll!UnhookWindowsHookEx 77D6F29F 5 Bytes JMP 014970D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2132] USER32.dll!MessageBoxExW 77D80559 5 Bytes JMP 0164617E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2132] USER32.dll!MessageBoxExA 77D8057D 5 Bytes JMP 016461E0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2132] USER32.dll!DialogBoxIndirectParamA 77D86CED 3 Bytes JMP 016463DE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2132] USER32.dll!DialogBoxIndirectParamA + 4 77D86CF1 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[2132] USER32.dll!MessageBoxIndirectW 77D960B7 3 Bytes JMP 01646242 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2132] USER32.dll!MessageBoxIndirectW + 4 77D960BB 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[2132] ole32.dll!CoCreateInstance 77526009 5 Bytes JMP 015274D1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2224] USER32.dll!CreateWindowExW 77D51AD5 5 Bytes JMP 015267BD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2224] USER32.dll!DialogBoxParamW 77D56702 5 Bytes JMP 01454315 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2224] USER32.dll!DialogBoxParamA 77D588E1 5 Bytes JMP 01646318 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2224] USER32.dll!DialogBoxIndirectParamW 77D62598 5 Bytes JMP 0164637B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2224] USER32.dll!MessageBoxIndirectA 77D6AEF1 5 Bytes JMP 016462AD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2224] USER32.dll!MessageBoxExW 77D80559 5 Bytes JMP 0164617E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2224] USER32.dll!MessageBoxExA 77D8057D 5 Bytes JMP 016461E0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2224] USER32.dll!DialogBoxIndirectParamA 77D86CED 3 Bytes JMP 016463DE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2224] USER32.dll!DialogBoxIndirectParamA + 4 77D86CF1 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[2224] USER32.dll!MessageBoxIndirectW 77D960B7 3 Bytes JMP 01646242 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2224] USER32.dll!MessageBoxIndirectW + 4 77D960BB 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[3232] USER32.dll!CallNextHookEx 77D4ED6E 5 Bytes JMP 0151D5B4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3232] USER32.dll!CreateWindowExW 77D51AD5 5 Bytes JMP 015267BD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3232] USER32.dll!DialogBoxParamW 77D56702 5 Bytes JMP 01454315 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3232] USER32.dll!DialogBoxParamA 77D588E1 5 Bytes JMP 01646318 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3232] USER32.dll!DialogBoxIndirectParamW 77D62598 5 Bytes JMP 0164637B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3232] USER32.dll!MessageBoxIndirectA 77D6AEF1 5 Bytes JMP 016462AD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3232] USER32.dll!SetWindowsHookExW 77D6E621 5 Bytes JMP 01521D31 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3232] USER32.dll!UnhookWindowsHookEx 77D6F29F 5 Bytes JMP 014970D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3232] USER32.dll!MessageBoxExW 77D80559 5 Bytes JMP 0164617E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3232] USER32.dll!MessageBoxExA 77D8057D 5 Bytes JMP 016461E0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3232] USER32.dll!DialogBoxIndirectParamA 77D86CED 3 Bytes JMP 016463DE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3232] USER32.dll!DialogBoxIndirectParamA + 4 77D86CF1 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[3232] USER32.dll!MessageBoxIndirectW 77D960B7 3 Bytes JMP 01646242 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3232] USER32.dll!MessageBoxIndirectW + 4 77D960BB 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[3232] ole32.dll!CoCreateInstance 77526009 5 Bytes JMP 015274D1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3452] USER32.dll!CallNextHookEx 77D4ED6E 5 Bytes JMP 0151D5B4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3452] USER32.dll!CreateWindowExW 77D51AD5 5 Bytes JMP 015267BD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3452] USER32.dll!DialogBoxParamW 77D56702 5 Bytes JMP 01454315 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3452] USER32.dll!DialogBoxParamA 77D588E1 5 Bytes JMP 01646318 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3452] USER32.dll!DialogBoxIndirectParamW 77D62598 5 Bytes JMP 0164637B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3452] USER32.dll!MessageBoxIndirectA 77D6AEF1 5 Bytes JMP 016462AD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3452] USER32.dll!SetWindowsHookExW 77D6E621 5 Bytes JMP 01521D31 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3452] USER32.dll!UnhookWindowsHookEx 77D6F29F 5 Bytes JMP 014970D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3452] USER32.dll!MessageBoxExW 77D80559 5 Bytes JMP 0164617E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3452] USER32.dll!MessageBoxExA 77D8057D 5 Bytes JMP 016461E0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3452] USER32.dll!DialogBoxIndirectParamA 77D86CED 3 Bytes JMP 016463DE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3452] USER32.dll!DialogBoxIndirectParamA + 4 77D86CF1 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[3452] USER32.dll!MessageBoxIndirectW 77D960B7 3 Bytes JMP 01646242 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3452] USER32.dll!MessageBoxIndirectW + 4 77D960BB 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[3452] ole32.dll!CoCreateInstance 77526009 5 Bytes JMP 015274D1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3736] USER32.dll!CallNextHookEx 77D4ED6E 5 Bytes JMP 0151D5B4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3736] USER32.dll!CreateWindowExW 77D51AD5 5 Bytes JMP 015267BD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3736] USER32.dll!DialogBoxParamW 77D56702 5 Bytes JMP 01454315 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3736] USER32.dll!DialogBoxParamA 77D588E1 5 Bytes JMP 01646318 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3736] USER32.dll!DialogBoxIndirectParamW 77D62598 5 Bytes JMP 0164637B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3736] USER32.dll!MessageBoxIndirectA 77D6AEF1 5 Bytes JMP 016462AD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3736] USER32.dll!SetWindowsHookExW 77D6E621 5 Bytes JMP 01521D31 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3736] USER32.dll!UnhookWindowsHookEx 77D6F29F 5 Bytes JMP 014970D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3736] USER32.dll!MessageBoxExW 77D80559 5 Bytes JMP 0164617E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3736] USER32.dll!MessageBoxExA 77D8057D 5 Bytes JMP 016461E0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3736] USER32.dll!DialogBoxIndirectParamA 77D86CED 3 Bytes JMP 016463DE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3736] USER32.dll!DialogBoxIndirectParamA + 4 77D86CF1 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[3736] USER32.dll!MessageBoxIndirectW 77D960B7 3 Bytes JMP 01646242 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3736] USER32.dll!MessageBoxIndirectW + 4 77D960BB 1 Byte [89]
.text C:\Program Files\Internet Explorer\iexplore.exe[3736] ole32.dll!CoCreateInstance 77526009 5 Bytes JMP 015274D1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device A6542C8A
Device Cdfs.SYS (CD-ROM File System Driver/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet004\Services\BITS\Parameters@ServiceDll C:\WINDOWS\system32\qmgr.dll
Reg HKLM\SYSTEM\ControlSet004\Services\wuauserv\Parameters@ServiceDll C:\WINDOWS\system32\wuauserv.dll
Reg HKLM\SYSTEM\ControlSet005\Services\BITS\Parameters@ServiceDll C:\WINDOWS\system32\qmgr.dll
Reg HKLM\SYSTEM\ControlSet005\Services\wuauserv\Parameters@ServiceDll C:\WINDOWS\system32\wuauserv.dll
Reg HKLM\SYSTEM\ControlSet006\Services\BITS\Parameters@ServiceDll C:\WINDOWS\system32\qmgr.dll
Reg HKLM\SYSTEM\ControlSet006\Services\wuauserv\Parameters@ServiceDll C:\WINDOWS\system32\wuauserv.dll
---- EOF - GMER 1.0.15 ----