Thank you for your reply. No apologies - please. Your help on this matter is much appreciated in any time frame.
This post answers the initial set of questions and actions requested with your first response:
I recently acquired the XP Security virus and used the suggestions on your site through use of your routines and manual removal of files. It seems most of it was removed, but I was left with a ping.exe issue that hogged computer resources to the point the system completely locked, except for mouse movements.
I have not taken much action on my problem since my initial post except to reboot a number of times in attempts to retrieve certain files I needed. The following describes the conditions I currently experience – in both normal and safe mode I have to start the system without an internet connection, otherwise ping.exe takes over and no commands can be executed.
In normal Windows mode, without internet access, the system takes about 3 times longer to boot than before the initial virus attack. After booting, most of the time I cannot execute any commands, open programs or do a normal shutdown ( I must power down). In about 1 boot out of 5, I am able to execute a few commands, open files or do file copies, but eventually the system stops responding except for mouse movements (not clicks). It was during one of these sessions that I was able to generate the new DDS log, and then the new GMER log during another session. The Windows session never lasted long enough to execute both routines. I also believe the system is more unstable if Malwarebyte and/or Norton is running.
Safe mode seems to be a little more stable, but will also lock up if an internet connection is present. I can normally do a regular system shutdown in Safe mode without the need for a power down.
After many boot attempts, I was able to generate the DDS log (enclosed) and execute GMER. The DDS process took about 8 minutes to complete, but GMER never completed. I repeatedly got a message that “GMER has encountered a problem and needs to close. Send a report to Microsoft?”. This always occurred when the program was looking at \device\NTPNP_PCI0013. I was able to save a copy of the log in one of these scans before the system locked up, and it is also follows. During one of the attempts to execute GMER, I did get a message in a separate window: “SPYWAREDR with AntiVirus blocked TROJANGEN.” I only got this message once.
This is a Dell 8300 computer (32 bit system), and I do have the XP Reinstallation CD (with SP1). Drivers and applications are on separate CDs. Unfortunately, I have Windows Restore disabled, so I do not have that option to do a restore to a previous date. However, I do have the system backed up with Seagate Replica to an external hard drive, which also allows a system restore. I am reluctant to use this process until I am certain the external drive is not infected. This drive has been disconnected during my troubleshooting procedures. It has not been recently scanned for viruses or other problems.
Gringo, per your second request, I will run ComboFix and report the results.
Thank you again for your assistance.
John
_____________________________
New DDS Log (Normal Windows mode):
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by User at 23:55:59 on 2011-12-31
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.829 [GMT -5:00]
.
AV: PC Tools Spyware Doctor with AntiVirus *Enabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
.
============== Running Processes ===============
.
C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\HPSIsvc.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\DOCUME~1\User\LOCALS~1\Temp\bwgo0001d685.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\svcs.exe
C:\Program Files\palmOne\Hotsync.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe
C:\Program Files\TrippLite\PowerAlert\console\pastatus.exe
C:\Program Files\Intellicast\Intellicast.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Seagate Replica\bin\ReplicaSysMon.exe
C:\Program Files\Seagate Replica\bin\Seagate-Replica-Autoplay.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\System32\ping.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.intellicast.com/National/Radar/Current.aspx?animate=true&location=USGA0210
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.dellnet.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.dellnet.com/
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll
uURLSearchHooks: N/A: {0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2} - c:\program files\asksbar\srchastt\1.bin\A2SRCHAS.DLL
uURLSearchHooks: H - No File
uURLSearchHooks: PC Tools Browser Defender: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools\pc tools security\bdt\PCTBrowserDefender.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll
BHO: Ask Search Assistant BHO: {0579b4b1-0293-4d73-b02d-5ebb0ba0f0a2} - c:\program files\asksbar\srchastt\1.bin\A2SRCHAS.DLL
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Ask Toolbar BHO: {f0d4b231-da4b-4daf-81e4-dfee4931a4aa} - c:\program files\asksbar\bar\1.bin\ASKSBAR.DLL
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: Ask Toolbar: {f0d4b239-da4b-4daf-81e4-dfee4931a4aa} - c:\program files\asksbar\bar\1.bin\ASKSBAR.DLL
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\program files\yahoo!\messenger\yhexbmes0521.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MoneyAgent] "c:\program files\microsoft money\system\mnyexpr.exe"
uRun: [NvMediaCenter] "c:\windows\system32\rundll32.exe" c:\windows\system32\NVMCTRAY.DLL,NvTaskbarInit
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [LDM] c:\program files\logitech\desktop messenger\8876480\program\BackWeb-8876480.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [WMPNSCFG] "c:\program files\windows media player\WMPNSCFG.exe"
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [Pando Media Booster] "c:\program files\pando networks\media booster\PMB.exe"
uRun: [Google Update] "c:\documents and settings\user\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [ServeMe.exe] "c:\program files\pure networks\network magic\support\serveme.exe"
mRun: [NvCplDaemon] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [diagent] "c:\program files\creative\sblive\diagnostics\diagent.exe" startup
mRun: [UpdReg] "c:\windows\UpdReg.EXE"
mRun: [DVDSentry] "c:\windows\system32\DSentry.exe"
mRun: [MMTray] "c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe"
mRun: [nwiz] "c:\windows\system32\nwiz.exe" /install
mRun: [mmtask] "c:\program files\musicmatch\musicmatch jukebox\mmtask.exe"
mRun: [RoxioEngineUtility] "c:\program files\common files\roxio shared\system\EngUtil.exe"
mRun: [RoxioDragToDisc] "c:\program files\roxio\easy cd creator 6\dragtodisc\DrgToDsc.exe"
mRun: [RoxioAudioCentral] "c:\program files\roxio\easy cd creator 6\audiocentral\RxMon.exe"
mRun: [POINTER] point32.exe
mRun: [IntelliType] "c:\program files\microsoft hardware\keyboard\type32.exe"
mRun: [masqform.exe] "c:\program files\pureedge\viewer 6.0\masqform.exe" -UpdateCurrentUser
mRun: [Microsoft Works Update Detection] "c:\program files\common files\microsoft shared\works shared\WkUFind.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [<NO NAME>]
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [UserFaultCheck] "%systemroot%\system32\dumprep" 0 -u
mRun: [dvd43] "c:\program files\dvd43\dvd43_tray.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [ISTray] "c:\program files\pc tools\pc tools security\pctsGui.exe" /hideGUI
dRunOnce: [WUAppSetup] c:\program files\common files\logishrd\WUApp32.exe -v 0x046d -p 0x08d7 -f video -m logitech -d 11.5.0.1145
StartupFolder: c:\docume~1\user\startm~1\programs\startup\intell~1.lnk - c:\program files\intellicast\Intellicast.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\americ~1.lnk - c:\program files\america online 8.0\aoltray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palmone\Hotsync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LDMConf.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\powera~1.lnk - c:\program files\tripplite\poweralert\console\pastatus.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{14fcfe7c-ab86-428a-9d2e-bfb6f5a7aa6e}\Icon3E5562ED7.ico
mPolicies-explorer: <NO NAME> =
IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
LSP: mswsock.dll
Trusted Zone: turbotax.com
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/3/9/8/398422c0-8d3e-40e1-a617-af65a72a0465/LegitCheckControl.cab
DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc2.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1208867312812
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - hxxp://acs.pandasoftware.com/activescan/as5free/asinst.cab
DPF: {9EF2BA47-C6A7-470D-9DD9-4323B0CB8353} - hxxp://71.204.108.198/WebClient.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab
DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://aolsvc.aol.com/onlinegames/bejeweled2/popcaploader_v10.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - hxxp://fdl.msn.com/zone/datafiles/heartbeat.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
============= SERVICES / DRIVERS ===============
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-12-24 331880]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-12-24 341656]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2011-12-24 660992]
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2008-8-9 29832]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [2011-12-24 185560]
R2 NAVAPEL;NAVAPEL;c:\program files\navnt\Navapel.sys [2001-12-4 8464]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-21 20464]
R3 nmserial;PCI Serial Port;c:\windows\system32\drivers\NmSerial.sys [2010-12-23 70016]
R3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\drivers\PCTBD.sys [2011-12-24 56840]
S3 L2XPSR;L2XPSR;\??\f:\release\l2xpsr.sys --> f:\release\L2XPSR.SYS [?]
S3 mvusbews;USB EWS Device;c:\windows\system32\drivers\mvusbews.sys [2010-12-22 17408]
S3 NmPar;Unusable Parallel Port;c:\windows\system32\drivers\NmPar.sys [2010-12-23 80256]
S3 PTDCWWAN;PANTECH PC Card WWAN Controller device driver;c:\windows\system32\drivers\PTDCWWAN.sys [2008-3-10 58240]
S3 pwi_bus;Curitel PC Card Composite Device driver (WDM);c:\windows\system32\drivers\pwi_bus.sys [2006-11-10 55344]
S3 pwi_mdfl;Curitel PC Card Filter;c:\windows\system32\drivers\pwi_mdfl.sys [2006-11-10 9200]
S3 pwi_mdm;Curitel PC Card Drivers;c:\windows\system32\drivers\pwi_mdm.sys [2006-11-10 89936]
S3 pwi_oflt;Curitel PC Card OHCI Filter;c:\windows\system32\drivers\pwi_oflt.sys [2006-11-10 9472]
S3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);c:\windows\system32\drivers\pwi_serd.sys [2006-11-10 69632]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]
.
=============== Created Last 30 ================
.
2011-12-24 14:11:32 56840 ----a-w- c:\windows\system32\drivers\PCTBD.sys
2011-12-24 14:11:30 767952 ----a-w- c:\windows\BDTSupport.dll
2011-12-24 14:11:28 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-12-24 14:11:26 2246608 ----a-w- c:\windows\PCTBDCore.dll
2011-12-24 14:11:25 1681360 ----a-w- c:\windows\PCTBDRes.dll
2011-12-24 14:08:33 253096 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-12-24 14:08:06 17848 ----a-w- c:\windows\system32\drivers\pctBTFix.sys
2011-12-24 14:07:39 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2011-12-24 14:07:03 -------- d-----w- c:\program files\PC Tools
2011-12-24 14:04:09 660992 ----a-w- c:\windows\system32\drivers\pctEFA.sys
2011-12-24 14:04:09 341656 ----a-w- c:\windows\system32\drivers\pctDS.sys
2011-12-24 14:04:02 331880 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2011-12-24 14:04:02 162584 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-12-24 14:03:56 185560 ----a-w- c:\windows\system32\drivers\PCTSD.sys
2011-12-24 14:03:56 -------- d-----w- c:\program files\common files\PC Tools
2011-12-24 14:03:08 -------- d-----w- c:\documents and settings\all users\application data\PC Tools
2011-12-24 14:03:03 -------- d-----w- c:\documents and settings\user\application data\TestApp
2011-12-22 14:51:04 508928 ----a-w- c:\windows\svcs.exe
2011-12-22 03:33:28 -------- d-----w- c:\documents and settings\user\application data\Malwarebytes
2011-12-22 03:33:14 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-12-22 03:33:11 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-22 03:33:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
.
==================== Find3M ====================
.
2011-11-23 13:25:32 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-14 12:04:14 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-04 19:20:51 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20:51 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20:51 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23:59 385024 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07:10 1288704 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:48 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37:08 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:02 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13:22 186880 ----a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-04 12:57:38 72080 ----a-w- c:\documents and settings\user\g2mdlhlpx.exe
.
============= FINISH: 0:04:02.04 ===============
New GMER Log (normal Windows mode):
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-01-01 01:54:38
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\uglorfob.sys
---- System - GMER 1.0.15 ----
SSDT 8A64ED50 ZwAllocateVirtualMemory
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateKey [0xF7884D3A]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xF7853C0C]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xF7853ED4]
SSDT 8A629170 ZwCreateThread
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteKey [0xF7885634]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteValueKey [0xF788594C]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwOpenKey [0xF7883EBE]
SSDT 8A64EDC8 ZwQueueApcThread
SSDT 8A64EC60 ZwReadVirtualMemory
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xF7885E16]
SSDT 8A64EEB8 ZwSetContextThread
SSDT 8A6511A8 ZwSetInformationKey
SSDT 8A62AFA8 ZwSetInformationProcess
SSDT 8A64EF30 ZwSetInformationThread
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwSetValueKey [0xF788509A]
SSDT 8A6291E8 ZwSuspendProcess
SSDT 8A64EE40 ZwSuspendThread
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xF785380A]
SSDT 8A64EFA8 ZwTerminateThread
SSDT 8A64ECD8 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!ZwYieldExecution + 3FE 804E4C58 2 Bytes [A8, 11] {TEST AL, 0x11}
.text ntoskrnl.exe!ZwYieldExecution + 46A 804E4CC4 8 Bytes CALL C0D8AF5A
.text C:\WINDOWS\System32\DRIVERS\nv4_mini.sys section is writeable [0xB8F87340, 0x121A5F, 0xF8000020]
.text C:\WINDOWS\System32\nv4_disp.dll section is writeable [0xBF012380, 0x25BA81, 0xF8000020]
.text C:\WINDOWS\system32\drivers\hardlock.sys section is writeable [0xAE467400, 0x7960C, 0xE8000020]
.protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".p" section [0xAE509420] C:\WINDOWS\system32\drivers\hardlock.sys entry point in ".protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".p" section [0xAE509420]
.protectÿÿÿÿhardlockunknown last code section [0xAE509200, 0x5049, 0xE0000020] C:\WINDOWS\system32\drivers\hardlock.sys unknown last code section [0xAE509200, 0x5049, 0xE0000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe[416] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003F0001
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe[416] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe[416] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe[416] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe[416] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe[416] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
? C:\WINDOWS\system32\cisvc.exe[500] C:\WINDOWS\system32\SHLWAPI.dll IMAGE_DOS_SIGNATURE not found;
.text C:\WINDOWS\Explorer.EXE[544] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 023A000A
.text C:\WINDOWS\Explorer.EXE[544] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 023B000A
.text C:\WINDOWS\Explorer.EXE[544] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0239000C
.text C:\WINDOWS\System32\DSentry.exe[940] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00C20001
.text C:\WINDOWS\System32\DSentry.exe[940] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\WINDOWS\System32\DSentry.exe[940] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\WINDOWS\System32\DSentry.exe[940] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\DSentry.exe[940] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\WINDOWS\System32\DSentry.exe[940] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe[980] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01220001
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe[980] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe[980] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe[980] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe[980] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe[980] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
.text C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe[1060] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01440001
.text C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe[1060] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe[1060] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe[1060] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe[1060] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe[1060] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
.text C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe[1360] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 014D0001
.text C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe[1360] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe[1360] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe[1360] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe[1360] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe[1360] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
.text C:\Program Files\Microsoft Hardware\Mouse\point32.exe[1368] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 010C0001
.text C:\Program Files\Microsoft Hardware\Mouse\point32.exe[1368] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\Program Files\Microsoft Hardware\Mouse\point32.exe[1368] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Microsoft Hardware\Mouse\point32.exe[1368] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Hardware\Mouse\point32.exe[1368] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\Program Files\Microsoft Hardware\Mouse\point32.exe[1368] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
.text C:\WINDOWS\System32\svchost.exe[1448] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 021B000A
.text C:\WINDOWS\System32\svchost.exe[1448] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 021C000A
.text C:\WINDOWS\System32\svchost.exe[1448] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 021A000C
.text C:\Program Files\Microsoft Hardware\Keyboard\type32.exe[1472] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01100001
.text C:\Program Files\Microsoft Hardware\Keyboard\type32.exe[1472] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\Program Files\Microsoft Hardware\Keyboard\type32.exe[1472] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Microsoft Hardware\Keyboard\type32.exe[1472] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Hardware\Keyboard\type32.exe[1472] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\Program Files\Microsoft Hardware\Keyboard\type32.exe[1472] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
.text C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe[1500] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003D0001
.text C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe[1500] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe[1500] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe[1500] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe[1500] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe[1500] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1532] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00C00001
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1532] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1532] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1532] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1532] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1532] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
.text C:\Program Files\dvd43\dvd43_tray.exe[1692] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00FD0001
.text C:\Program Files\dvd43\dvd43_tray.exe[1692] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\Program Files\dvd43\dvd43_tray.exe[1692] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\dvd43\dvd43_tray.exe[1692] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\dvd43\dvd43_tray.exe[1692] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\Program Files\dvd43\dvd43_tray.exe[1692] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[2080] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01430001
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[2080] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A20F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[2080] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[2080] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[2080] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A4, 71]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[2080] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 719F0F5A
.text C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe[2096] kernel32.dll!CreateThread + 1A 7C8106F1 4 Bytes CALL 0044CD69 C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe (PC Tools Security Component/PC Tools)
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[2112] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 027F0001
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[2112] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A10F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[2112] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[2112] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[2112] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A3, 71]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[2112] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 719E0F5A
.text C:\Program Files\DellSupport\DSAgnt.exe[2160] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 02360001
.text C:\Program Files\DellSupport\DSAgnt.exe[2160] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A20F5A
.text C:\Program Files\DellSupport\DSAgnt.exe[2160] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\DellSupport\DSAgnt.exe[2160] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellSupport\DSAgnt.exe[2160] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A4, 71]
.text C:\Program Files\DellSupport\DSAgnt.exe[2160] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 719F0F5A
.text C:\WINDOWS\system32\ctfmon.exe[2224] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00EB0001
.text C:\WINDOWS\system32\ctfmon.exe[2224] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\WINDOWS\system32\ctfmon.exe[2224] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\WINDOWS\system32\ctfmon.exe[2224] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[2224] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\WINDOWS\system32\ctfmon.exe[2224] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[2240] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00D20001
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[2240] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[2240] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[2240] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[2240] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[2240] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
.text C:\DOCUME~1\User\LOCALS~1\Temp\bwgo0001cd6d.exe[2404] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00BC0001
.text C:\DOCUME~1\User\LOCALS~1\Temp\bwgo0001cd6d.exe[2404] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\DOCUME~1\User\LOCALS~1\Temp\bwgo0001cd6d.exe[2404] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\DOCUME~1\User\LOCALS~1\Temp\bwgo0001cd6d.exe[2404] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\DOCUME~1\User\LOCALS~1\Temp\bwgo0001cd6d.exe[2404] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\DOCUME~1\User\LOCALS~1\Temp\bwgo0001cd6d.exe[2404] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
.text C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe[2424] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00C70001
.text C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe[2424] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe[2424] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe[2424] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe[2424] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe[2424] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
.text C:\Program Files\palmOne\Hotsync.exe[2536] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01260001
.text C:\Program Files\palmOne\Hotsync.exe[2536] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A20F5A
.text C:\Program Files\palmOne\Hotsync.exe[2536] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\palmOne\Hotsync.exe[2536] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\palmOne\Hotsync.exe[2536] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A4, 71]
.text C:\Program Files\palmOne\Hotsync.exe[2536] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 719F0F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2696] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01520001
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2696] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A10F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2696] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2696] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2696] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A3, 71]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[2696] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 719E0F5A
.text C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe[2784] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01540001
.text C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe[2784] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe[2784] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe[2784] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe[2784] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe[2784] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
.text C:\Program Files\TrippLite\PowerAlert\console\pastatus.exe[2844] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00ED0001
.text C:\Program Files\TrippLite\PowerAlert\console\pastatus.exe[2844] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\Program Files\TrippLite\PowerAlert\console\pastatus.exe[2844] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\TrippLite\PowerAlert\console\pastatus.exe[2844] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\TrippLite\PowerAlert\console\pastatus.exe[2844] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\Program Files\TrippLite\PowerAlert\console\pastatus.exe[2844] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
.text C:\Program Files\Intellicast\Intellicast.exe[2980] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01B20001
.text C:\Program Files\Intellicast\Intellicast.exe[2980] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 719D0F5A
.text C:\Program Files\Intellicast\Intellicast.exe[2980] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Intellicast\Intellicast.exe[2980] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intellicast\Intellicast.exe[2980] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [9F, 71]
.text C:\Program Files\Intellicast\Intellicast.exe[2980] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 719A0F5A
.text C:\Program Files\Microsoft Office\Office\1033\msoffice.exe[3084] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00F60001
.text C:\Program Files\Microsoft Office\Office\1033\msoffice.exe[3084] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A50F5A
.text C:\Program Files\Microsoft Office\Office\1033\msoffice.exe[3084] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Microsoft Office\Office\1033\msoffice.exe[3084] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office\1033\msoffice.exe[3084] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A7, 71]
.text C:\Program Files\Microsoft Office\Office\1033\msoffice.exe[3084] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A20F5A
.text C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe[3116] kernel32.dll!CreateThread + 1A 7C8106F1 4 Bytes CALL 0044C4B9 C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe (PC Tools Security Component/PC Tools)
.text C:\Program Files\Seagate Replica\bin\Seagate-Replica-Autoplay.exe[3212] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 02790001
.text C:\Program Files\Seagate Replica\bin\Seagate-Replica-Autoplay.exe[3212] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A20F5A
.text C:\Program Files\Seagate Replica\bin\Seagate-Replica-Autoplay.exe[3212] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\Seagate Replica\bin\Seagate-Replica-Autoplay.exe[3212] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Seagate Replica\bin\Seagate-Replica-Autoplay.exe[3212] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A4, 71]
.text C:\Program Files\Seagate Replica\bin\Seagate-Replica-Autoplay.exe[3212] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 719F0F5A
.text C:\Documents and Settings\User\Desktop\gmer.exe[3648] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003C0001
.text C:\Documents and Settings\User\Desktop\gmer.exe[3648] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 71A60F5A
.text C:\Documents and Settings\User\Desktop\gmer.exe[3648] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AF0F5A
.text C:\Documents and Settings\User\Desktop\gmer.exe[3648] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\User\Desktop\gmer.exe[3648] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A8, 71] {TEST AL, 0x71}
.text C:\Documents and Settings\User\Desktop\gmer.exe[3648] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 71A30F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe[4068] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 013C0001
.text C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe[4068] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 719E0F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe[4068] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 71AE0F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe[4068] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe[4068] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [A0, 71]
.text C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe[4068] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 719B0F5A
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs ssfs0bbc.sys (Spy Sweeper FileSystem Filter Driver/Webroot Software, Inc. (www.webroot.com))
Device \Driver\Tcpip \Device\Ip 8A205260
Device \Driver\Tcpip \Device\Ip 89E2FAC0
Device \Driver\Tcpip \Device\Ip 8A04DE68
Device \Driver\Tcpip \Device\Ip 89A76AC0
Device \Driver\Tcpip \Device\Ip 8A3A2E08
Device \Driver\Tcpip \Device\Ip 8A177728
Device \Driver\Tcpip \Device\Ip 8A63C948
Device \Driver\Tcpip \Device\Ip 89C24C68
Device \Driver\Tcpip \Device\Ip 89877120
Device \Driver\Tcpip \Device\Ip 89B46C70
Device \Driver\Tcpip \Device\Ip 899B55F0
Device \Driver\Tcpip \Device\Tcp 8A205260
Device \Driver\Tcpip \Device\Tcp 89E2FAC0
Device \Driver\Tcpip \Device\Tcp 8A04DE68
Device \Driver\Tcpip \Device\Tcp 89A76AC0
Device \Driver\Tcpip \Device\Tcp 8A3A2E08
Device \Driver\Tcpip \Device\Tcp 8A177728
Device \Driver\Tcpip \Device\Tcp 8A63C948
Device \Driver\Tcpip \Device\Tcp 89C24C68
Device \Driver\Tcpip \Device\Tcp 89877120
Device \Driver\Tcpip \Device\Tcp 89B46C70
Device \Driver\Tcpip \Device\Tcp 899B55F0
End of Reply