I created a topic in another thread, see here:
http://www.bleepingcomputer.com/forums/topic438860.html/page__gopid__2562619
In there, they had me do all sorts of scans and post logs. After the last log posting, they directed me here.....
I followed the directions, but could not 'enable' the firewall. That is part of the problem I was having to begin with....
Here is the DSS Log:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.7601.17514
Run by Jason at 14:55:17 on 2012-01-26
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3062.2166 [GMT -8:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\UAService7.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Marketsplash by HP\HPLocalWebPrintAgent.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\eFax Messenger 4.4\J2GTray.exe
C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=veriton_m265&r=170501104016p0365u205z48m15391
mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=veriton_m265&r=170501104016p0365u205z48m15391
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=veriton_m265&r=170501104016p0365u205z48m15391
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
mURLSearchHooks: H - No File
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\10.0.0.7\AVG Secure Search_toolbar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\6.3.2291.0\npwinext.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: @c:\program files\msn toolbar\platform\6.3.2291.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\6.3.2291.0\npwinext.dll
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\10.0.0.7\AVG Secure Search_toolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [eFax 4.4] "c:\program files\efax messenger 4.4\J2GDllCmd.exe" /R
uRun: [MoneyAgent] "c:\program files\microsoft money\system\mnyexpr.exe"
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [vProt] "c:\program files\avg secure search\vprot.exe"
mRun: [ROC_roc_dec12] "c:\program files\avg secure search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12
StartupFolder: c:\users\jason\appdata\roaming\micros~1\windows\startm~1\programs\startup\efax44~1.lnk - c:\program files\efax messenger 4.4\J2GTray.exe
StartupFolder: c:\users\jason\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office14\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\market~1.lnk - c:\program files\hewlett-packard\marketsplash by hp\HPLocalWebPrintAgent.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
uPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
LSP: mswsock.dll
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {62789780-B744-11D0-986B-00609731A21D} - hxxp://www.modestogov.com/gis/home/maps/mgaxctrl.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{19F6FEEC-BF91-400D-BE33-B7FEDA9D4D05} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{341C048B-7FAF-4592-BF47-6AAE4CAF0DA3} : DhcpNameServer = 206.13.30.12 206.13.29.12
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\10.0.6\ViProtocol.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
LSA: Authentication Packages = msv1_0 wvauth
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\jason\appdata\roaming\mozilla\firefox\profiles\qcyzmb0c.default\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bb6ab000c-cc1a-4747-a166-15f605a35df7%7D&mid=1f8ab31d8a76cb12ac91033202a954ea-d4ce2ab78ec6c6cfadfe94445b4f25411bcd97c6&ds=AVG&v=9.0.0.18.1&lang=en&pr=fr&d=2011-09-19%2011%3A41%3A35&sap=ku&q=
FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPCltInst11.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPcol500.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\jason\appdata\local\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll
FF - plugin: c:\users\jason\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
.
---- FIREFOX POLICIES ----
FF - user.js: general.useragent.extra.brc - BRI/1
.
============= SERVICES / DRIVERS ===============
.
R0 AFS;AFS;c:\windows\system32\drivers\AFS.SYS [2010-1-24 79052]
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-10-7 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\adobe\photoshop elements 7.0\PhotoshopElementsFileAgent.exe [2008-9-16 169312]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R2 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2009-10-12 24576]
R2 FlipShareServer;FlipShare Server;c:\program files\flip video\flipshareserver\FlipShareServer.exe [2010-12-15 1085440]
R2 vToolbarUpdater;vToolbarUpdater;c:\program files\common files\avg secure search\vtoolbarupdater\10.0.6\ToolbarUpdater.exe [2012-1-19 909152]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134736]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-10-4 16720]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-10-12 167936]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-4-13 135664]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-5-20 1025352]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-23 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-22 1493352]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-4-13 135664]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-7-7 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-2-26 1343400]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2009-7-13 17920]
.
=============== Created Last 30 ================
.
2012-01-26 11:17:41 -------- d-----w- c:\users\jason\appdata\local\{930F5D9E-C8EA-4F71-B716-2341451A0E60}
2012-01-26 11:17:39 -------- d-----w- c:\users\jason\appdata\local\{83D8CD71-A97F-4CC7-952D-5C9128381C8D}
2012-01-25 17:58:10 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-25 17:58:10 369352 ----a-w- c:\windows\system32\drivers\cng.sys
2012-01-25 17:58:10 314880 ----a-w- c:\windows\system32\webio.dll
2012-01-25 17:58:10 22528 ----a-w- c:\windows\system32\lsass.exe
2012-01-25 17:58:10 224768 ----a-w- c:\windows\system32\schannel.dll
2012-01-25 17:58:10 22016 ----a-w- c:\windows\system32\secur32.dll
2012-01-25 17:58:10 15872 ----a-w- c:\windows\system32\sspisrv.dll
2012-01-25 17:58:10 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-01-25 17:58:10 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-25 17:58:10 100352 ----a-w- c:\windows\system32\sspicli.dll
2012-01-23 18:00:09 -------- d-----w- c:\users\jason\appdata\local\{95189C40-04AA-4151-BB80-9AAD5A985262}
2012-01-23 18:00:01 -------- d-----w- c:\users\jason\appdata\local\{1C5D2FB1-EB92-4F18-8780-29B66E21546C}
2012-01-23 14:49:43 -------- d-----w- c:\users\jason\appdata\local\{D2222DA8-36B6-467E-80AB-BAFE45808531}
2012-01-23 14:49:40 -------- d-----w- c:\users\jason\appdata\local\{C1ED8A08-B155-42B9-8F96-04B044CB69B7}
2012-01-19 03:01:42 -------- d-----w- c:\users\jason\appdata\local\{0E426CD8-B645-48D0-B60A-949FEE842F18}
2012-01-19 03:01:36 -------- d-----w- c:\users\jason\appdata\local\{67BEF74F-5B56-4BE5-B543-7EBBE09810A0}
2012-01-19 02:41:11 -------- d-----w- c:\program files\ESET
2012-01-18 22:21:19 -------- d-----w- c:\users\jason\appdata\local\{D4594489-87C9-4560-829B-1CCE73FAB12B}
2012-01-18 22:21:13 -------- d-----w- c:\users\jason\appdata\local\{B9B67C16-BFC5-4EF6-9743-DC71708BAA06}
2012-01-18 21:26:05 -------- d-----w- c:\users\jason\appdata\local\{5DA9BA64-DCBE-4E67-BE05-F2F787C24245}
2012-01-18 21:25:59 -------- d-----w- c:\users\jason\appdata\local\{E538D492-90EB-44BA-9B9B-579E992E9952}
2012-01-18 18:17:10 -------- d-----w- c:\users\jason\appdata\local\{CC48F0AA-56D4-412D-889E-C980C3C40D0D}
2012-01-18 18:17:05 -------- d-----w- c:\users\jason\appdata\local\{B8F3CD39-2DFC-4AE7-B327-656F13564820}
2012-01-18 18:02:47 -------- d-----w- c:\users\jason\appdata\local\{5A782BC1-D448-4F95-8C5C-873CDC41460E}
2012-01-18 18:02:42 -------- d-----w- c:\users\jason\appdata\local\{E3CE425B-1C78-4AC2-AD70-EB1E6CC9C030}
2012-01-18 17:47:11 -------- d-----w- c:\users\jason\appdata\local\{2D72CECC-900C-444F-8234-5087D1F7E196}
2012-01-18 17:47:04 -------- d-----w- c:\users\jason\appdata\local\{8FAE16F5-ACC6-4E33-8BBF-D2390E645C37}
2012-01-18 17:15:37 -------- d-----w- c:\users\jason\appdata\local\{8D473ACF-D930-4640-A1BC-3B94F4258C4F}
2012-01-18 17:15:32 -------- d-----w- c:\users\jason\appdata\local\{189C8820-FE21-4289-8F85-3A48B2927C9B}
2012-01-18 16:59:31 -------- d-----w- c:\users\jason\appdata\local\{A122F714-FAF7-483C-8473-B06B8FC1319C}
2012-01-18 16:59:26 -------- d-----w- c:\users\jason\appdata\local\{6A20E5CE-E425-455F-BB4E-9F1C8B73202D}
2012-01-18 16:25:36 -------- d-----w- c:\users\jason\appdata\local\{E364222A-D718-4F12-AD18-52CA5B9336A8}
2012-01-18 16:25:33 -------- d-----w- c:\users\jason\appdata\local\{CF8EA54D-881E-4BF8-9EC8-EB72E5849432}
2012-01-17 15:24:30 -------- d-----w- c:\users\jason\appdata\local\{8CA7076B-DFF7-454A-92D1-3FE78C6663C2}
2012-01-17 15:24:18 -------- d-----w- c:\users\jason\appdata\local\{07F91F9D-D5ED-48DF-81FD-48A442D94168}
2012-01-16 01:58:06 -------- d-----w- c:\users\jason\appdata\local\{36BF14E5-571B-4E8A-9F76-2A1B297997DF}
2012-01-16 01:57:59 -------- d-----w- c:\users\jason\appdata\local\{24E04571-DC3C-4866-992C-B8EF8E458C7E}
2012-01-16 01:57:48 -------- d-----w- c:\users\jason\appdata\local\{9460B045-8958-4973-BDFD-A128B9471D90}
2012-01-16 01:50:45 -------- d-----w- c:\users\jason\appdata\local\{F6E51A3F-D792-433B-885D-7E9D4640A289}
2012-01-16 01:50:33 -------- d-----w- c:\users\jason\appdata\local\{43A96E87-5851-4BDB-87B5-3FEA72AFE01F}
2012-01-16 01:50:22 -------- d-----w- c:\users\jason\appdata\local\{60376CF6-B018-4AF8-BE96-914752D1082B}
2012-01-16 01:50:11 -------- d-----w- c:\users\jason\appdata\local\{335127DC-966D-40F6-9809-5B04444E42DC}
2012-01-12 17:48:22 -------- d-----w- c:\users\jason\appdata\local\{FCFA620C-D0D8-45F4-BFCD-6864534B4F23}
2012-01-12 17:48:10 -------- d-----w- c:\users\jason\appdata\local\{5FD25E55-554B-4A0F-9418-12EF6933006A}
2012-01-12 11:20:32 -------- d-----w- c:\users\jason\appdata\local\{3B813FBC-AE89-403F-8624-E813F59D5862}
2012-01-12 11:20:20 -------- d-----w- c:\users\jason\appdata\local\{8C0C338D-C46C-489D-9E18-95F57154DEC0}
2012-01-11 14:59:46 1288472 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 14:59:46 -------- d--h--w- C:\Ex.CleanI
2012-01-11 14:59:44 67072 ----a-w- c:\windows\system32\packager.dll
2012-01-11 14:59:42 514560 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 14:59:42 1328128 ----a-w- c:\windows\system32\quartz.dll
2012-01-09 15:00:44 -------- d-----w- c:\users\jason\appdata\local\{FF6B4FFE-8A16-4F3A-A541-260C4FCD74B7}
2012-01-09 15:00:32 -------- d-----w- c:\users\jason\appdata\local\{EECA6024-909F-4C64-BDF6-F4D00393924B}
2012-01-08 01:33:12 548864 ----a-w- c:\program files\mozilla firefox\msvcp80.dll
2012-01-08 01:33:12 479232 ----a-w- c:\program files\mozilla firefox\msvcm80.dll
2012-01-08 01:33:12 43992 ----a-w- c:\program files\mozilla firefox\mozutils.dll
2012-01-08 01:33:11 626688 ----a-w- c:\program files\mozilla firefox\msvcr80.dll
2012-01-03 14:26:45 -------- d-----w- c:\users\jason\appdata\local\{D29ABA8C-E0F8-4BE3-867A-45B176451767}
2012-01-03 14:26:31 -------- d-----w- c:\users\jason\appdata\local\{B0EB4E75-8053-42CF-85D9-4D130F6D4EB7}
2012-01-03 13:10:44 182672 ----a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2012-01-03 13:10:44 182672 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2011-12-29 21:50:50 -------- d-----w- c:\users\jason\appdata\local\{9D3F40DA-BF6E-442A-A88A-0ED1D5A7551F}
2011-12-29 21:50:36 -------- d-----w- c:\users\jason\appdata\local\{F717202D-4368-473F-AD24-751E0351F185}
2011-12-29 05:50:50 -------- d-----w- c:\users\jason\appdata\local\{56A534E1-5473-445F-9563-2AAA371C82EA}
2011-12-28 17:50:47 -------- d-----w- c:\users\jason\appdata\local\{AFCB32C3-9E90-4EF5-8E94-A83A9F0C6CBE}
2011-12-28 17:16:09 -------- d-----w- c:\users\jason\appdata\local\{F5598C89-1683-4B74-B505-58DE39511A3A}
2011-12-28 17:15:53 -------- d-----w- c:\users\jason\appdata\local\{C41DA0E9-A0C5-416C-872B-EC1A5C8AE921}
2011-12-28 00:36:57 -------- d-----w- c:\users\jason\appdata\local\{DE78F706-00C0-49A0-ADF9-3B8A39C76BD5}
2011-12-28 00:33:36 -------- d-----w- c:\users\jason\appdata\local\{BC88B27B-081C-4709-8B9E-804ABE5C105C}
2011-12-28 00:33:24 -------- d-----w- c:\users\jason\appdata\local\{CF4B1909-DC7A-435C-88D0-AA76D682A47C}
2011-12-28 00:32:23 -------- d-----w- c:\users\jason\appdata\local\{F6716A2B-45AB-4700-BC2F-7B5098C3DD3B}
2011-12-28 00:32:11 -------- d-----w- c:\users\jason\appdata\local\{9CA55475-369D-4448-B17F-1C0AAD464178}
.
==================== Find3M ====================
.
2011-12-15 14:37:19 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-24 04:25:27 2342912 ----a-w- c:\windows\system32\win32k.sys
2011-11-05 04:35:00 981504 ----a-w- c:\windows\system32\wininet.dll
2011-11-05 04:26:03 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-05 02:48:51 1638912 ----a-w- c:\windows\system32\mshtml.tlb
.
============= FINISH: 14:55:42.75 ===============
I have attached the "attach" zip file
Here is the gmer log that was named ark.txt:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-26 15:23:50
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 Hitachi_HDT721016SLA380 rev.ST1OA31B
Running: gmer.exe; Driver: C:\Users\Jason\AppData\Local\Temp\fftcqaob.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0x9A3E5F3C]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0x9A3E5FE4]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0x9A3E6080]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0x9A3E611C]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 82C47369 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82C80D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 139F 82C88054 4 Bytes [3C, 5F, 3E, 9A]
.text ntkrnlpa.exe!KeRemoveQueueEx + 166F 82C88324 8 Bytes [E4, 5F, 3E, 9A, 80, 60, 3E, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 16E3 82C88398 4 Bytes [1C, 61, 3E, 9A]
? C:\Users\Jason\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !
PAGE spsys.sys!?SPRevision@@3PADA + 4F90 AD742000 290 Bytes [8B, FF, 55, 8B, EC, 33, C0, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 50B3 AD742123 486 Bytes [D5, 73, AD, FE, 05, 34, D5, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 529A AD74230A 142 Bytes [73, AD, 3B, 08, 77, 04, 3B, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 5329 AD742399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 538F AD7423FF 148 Bytes [18, 5D, C2, 14, 00, 8B, FF, ...]
PAGE ...
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtCreateFile + 6 774755CE 4 Bytes [28, 00, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtCreateFile + B 774755D3 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtCreateKey + 6 7747560E 4 Bytes [68, 01, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtCreateKey + B 77475613 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtCreateMutant + 6 7747564E 4 Bytes [68, 02, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtCreateMutant + B 77475653 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtCreateSection + 6 774756EE 4 Bytes [A8, 02, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtCreateSection + B 774756F3 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtDeleteValueKey + 6 7747584E 1 Byte [28]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtDeleteValueKey + 6 7747584E 4 Bytes [28, 03, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtDeleteValueKey + B 77475853 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtMapViewOfSection + 6 77475C2E 4 Bytes [28, 05, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtMapViewOfSection + B 77475C33 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenFile + 6 77475CDE 4 Bytes [68, 00, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenFile + B 77475CE3 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenKey + 6 77475D0E 4 Bytes [A8, 01, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenKey + B 77475D13 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenKeyEx + B 77475D23 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenMutant + 6 77475D5E 4 Bytes [28, 02, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenMutant + B 77475D63 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenProcess + 6 77475D8E 1 Byte [A8]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenProcess + 6 77475D8E 4 Bytes [A8, 03, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenProcess + B 77475D93 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenProcessToken + 6 77475D9E 1 Byte [E8]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenProcessToken + B 77475DA3 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenProcessTokenEx + 6 77475DAE 4 Bytes [A8, 04, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenProcessTokenEx + B 77475DB3 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenSection + B 77475DD3 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenThread + 6 77475E0E 1 Byte [68]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenThread + 6 77475E0E 4 Bytes [68, 03, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenThread + B 77475E13 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenThreadToken + 6 77475E1E 4 Bytes [68, 04, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenThreadToken + B 77475E23 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtOpenThreadTokenEx + B 77475E33 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtQueryAttributesFile + 6 77475F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtQueryAttributesFile + B 77475F43 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtQueryFullAttributesFile + B 77475FF3 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtSetInformationFile + 6 7747663E 4 Bytes [28, 01, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtSetInformationFile + B 77476643 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtSetInformationThread + 6 7747669E 4 Bytes [28, 04, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtSetInformationThread + B 774766A3 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtUnmapViewOfSection + 6 774769BE 4 Bytes [68, 05, 07, 00]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ntdll.dll!NtUnmapViewOfSection + B 774769C3 1 Byte [E2]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] kernel32.dll!CreateProcessW 7541204D 5 Bytes JMP 00010030
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] kernel32.dll!CreateProcessA 75412082 5 Bytes JMP 00010070
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!ActivateKeyboardLayout 76A68203 5 Bytes JMP 000904F0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!RegisterClipboardFormatA 76A6C091 5 Bytes JMP 000902F0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!RegisterClipboardFormatW 76A6DF8D 5 Bytes JMP 000902B0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!EmptyClipboard 76A8290C 5 Bytes JMP 00090130
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!SetClipboardData 76A82962 5 Bytes JMP 00090170
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!GetClipboardData 76A82BA7 5 Bytes JMP 00090030
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!GetClipboardFormatNameW 76A85FD2 5 Bytes JMP 00090230
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!SetClipboardViewer 76A86FF6 5 Bytes JMP 000904B0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!GetClipboardFormatNameA 76A8700A 5 Bytes JMP 00090270
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!ChangeClipboardChain 76A9147C 5 Bytes JMP 00090430
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!CloseClipboard 76A9446C 5 Bytes JMP 000900B0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!OpenClipboard 76A9447E 5 Bytes JMP 00090070
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!IsClipboardFormatAvailable 76A944FF 5 Bytes JMP 000900F0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!GetClipboardSequenceNumber 76A94513 5 Bytes JMP 00090330
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!GetClipboardOwner 76A94525 5 Bytes JMP 00090370
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!CountClipboardFormats 76A9470A 5 Bytes JMP 000901F0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!EnumClipboardFormats 76A947EC 5 Bytes JMP 000901B0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!GetOpenClipboardWindow 76A9480B 5 Bytes JMP 000903F0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!GetClipboardViewer 76AC4AF7 5 Bytes JMP 00090470
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] USER32.dll!GetPriorityClipboardFormat 76AC4BF9 5 Bytes JMP 000903B0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!DeleteObject 75085F14 5 Bytes JMP 000A01B0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!SelectObject 75086640 5 Bytes JMP 000A05B0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!SetTextColor 75086906 5 Bytes JMP 000A0970
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!SetBkMode 750869B1 5 Bytes JMP 000A0830
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!DeleteDC 75086EAA 5 Bytes JMP 000A0170
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!GetDeviceCaps 75086F7F 5 Bytes JMP 000A0370
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!ExtSelectClipRgn 75087114 5 Bytes JMP 000A02F0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!SelectClipRgn 75087242 5 Bytes JMP 000A0570
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!SetStretchBltMode 75087705 5 Bytes JMP 000A05F0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!GetTextMetricsW 75087B8F 5 Bytes JMP 000A0D30
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!IntersectClipRect 75087DFE 5 Bytes JMP 000A03B0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!ExtTextOutW 75088192 5 Bytes JMP 000A08B0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!SetTextAlign 7508828E 5 Bytes JMP 000A0930
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!GetClipBox 75088525 5 Bytes JMP 000A0330
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!MoveToEx 75088C21 5 Bytes JMP 000A0430
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!StretchDIBits 7508A53E 5 Bytes JMP 000A06B0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!RestoreDC 7508A67B 5 Bytes JMP 000A04F0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!SaveDC 7508A74B 5 Bytes JMP 000A0530
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!GetTextFaceW 7508B73A 2 Bytes JMP 000A0C70
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!GetTextFaceW + 3 7508B73D 2 Bytes [01, 8B]
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!GetFontData 7508BCC4 5 Bytes JMP 000A0BB0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!SetWorldTransform 7508C90A 5 Bytes JMP 000A0630
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!CreateDCA 7508CCA9 5 Bytes JMP 000A00B0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!CreateDCW 7508CF79 5 Bytes JMP 000A00F0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!CreateICW 7508CFD0 5 Bytes JMP 000A0130
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!GetTextMetricsA 7508D0F2 5 Bytes JMP 000A0CF0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!Rectangle 7508F1FF 5 Bytes JMP 000A08F0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!LineTo 7508F59B 5 Bytes JMP 000A03F0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!SetICMMode 7508FAA4 5 Bytes JMP 000A0CB0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!ExtTextOutA 750903F9 5 Bytes JMP 000A0870
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!ExtEscape 75092949 5 Bytes JMP 000A02B0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!Escape 75093939 5 Bytes JMP 000A0270
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!GetTextFaceA 75093E6A 5 Bytes JMP 000A0C30
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!SetPolyFillMode 7509D851 5 Bytes JMP 000A0A70
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!SetMiterLimit 7509DA0D 5 Bytes JMP 000A0AB0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!EndPage 750A00D7 5 Bytes JMP 000A0230
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!ResetDCW 750A050D 5 Bytes JMP 000A09F0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!GetGlyphOutlineW 750AC1BA 5 Bytes JMP 000A0BF0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!CreateScalableFontResourceW 750AE817 5 Bytes JMP 000A0AF0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!AddFontResourceW 750AEC13 5 Bytes JMP 000A0B30
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!RemoveFontResourceW 750AF109 5 Bytes JMP 000A0B70
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!AbortDoc 750B4C63 5 Bytes JMP 000A0030
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!EndDoc 750B50AA 5 Bytes JMP 000A01F0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!StartPage 750B5195 5 Bytes JMP 000A0670
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!StartDocW 750B5BB0 5 Bytes JMP 000A0730
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!BeginPath 750B635D 5 Bytes JMP 000A0770
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!SelectClipPath 750B63B4 5 Bytes JMP 000A0A30
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!CloseFigure 750B640F 5 Bytes JMP 000A0070
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!EndPath 750B6466 5 Bytes JMP 000A09B0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!StrokePath 750B6699 5 Bytes JMP 000A06F0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!FillPath 750B6726 5 Bytes JMP 000A07B0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!PolylineTo 750B6B94 5 Bytes JMP 000A04B0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!PolyBezierTo 750B6C25 5 Bytes JMP 000A0470
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] GDI32.dll!PolyDraw 750B6CD7 5 Bytes JMP 000A07F0
.text C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe[2724] ole32.dll!OleSetClipboard 75130045 5 Bytes JMP 000C0030
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4724] USER32.dll!SetWindowLongA 76A68BA3 5 Bytes JMP 5BCE3A89 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4724] USER32.dll!SetWindowLongW 76A74449 5 Bytes JMP 5BCE3A1B C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4724] USER32.dll!GetWindowInfo 76A74B5E 5 Bytes JMP 5BA8C909 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4724] USER32.dll!TrackPopupMenu 76A82228 5 Bytes JMP 5BA8CEBD C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[4920] ntdll.dll!LdrLoadDll 7749223E 5 Bytes JMP 5B90B750 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004c halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
---- Files - GMER 1.0.15 ----
File C:\Windows\$NtUninstallKB36206$\1054061501 0 bytes
File C:\Windows\$NtUninstallKB36206$\1054061501\Desktop.ini 4608 bytes
File C:\Windows\$NtUninstallKB36206$\1054061501\L 0 bytes
File C:\Windows\$NtUninstallKB36206$\1054061501\U 0 bytes
File C:\Windows\$NtUninstallKB36206$\2690190951 0 bytes
---- EOF - GMER 1.0.15 ----
Attached File(s)
-
Attach.zip (3.18K)
Number of downloads: 2
This post has been edited by Musicjunkie27: 26 January 2012 - 06:35 PM

Help
This topic is locked


Back to top












