  This topic is locked
8 replies to this topic

#1 Cutex


  • Members
  • 4 posts
  • Local time:05:26 PM

Posted 28 February 2011 - 09:17 PM

My computer is infected with a google redirect virus. I have tried removing it with Malware Bytes, Kaspersky, tds killer,hitman pro, adaware and others but the virus still resurfaces although all these report there is no virus detected. Here is my report

DDS (Ver_10-12-12.02) - NTFSx86
Run by myname at 12:29:50.65 on Mon 02/28/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2459 [GMT 11:00]

AV: Malware Defense *Enabled/Outdated* {28e00e3b-806e-4533-925c-f4c3d79514b9}
AV: Kaspersky Internet Security *Enabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
AV: Internet Security Essentials *Enabled/Updated* {EAD3BE53-A23B-4940-A476-143F4A99200B}
FW: Internet Security Essentials *Enabled*
FW: Kaspersky Internet Security *Enabled*

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
C:\Program Files\D-Link\DSL-200\dslstat.exe
C:\Program Files\D-Link\DSL-200\dslagent.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtblfs.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\myname\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://au.yahoo.com/
uDefault_Page_URL = hxxp://www.dodo.com.au/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: DeviceVM Url Search Hook: {0063bf63-bfff-4b8f-9d26-4267df7f17dd} - c:\windows\system32\dvmurl.dll
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
mURLSearchHooks: H - No File
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2011\ievkbd.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: PCTools Site Guard: {5c8b2a36-3db1-42a4-a3cb-d426709bbfeb} - c:\progra~1\spywar~1\tools\iesdsg.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2011\klwtbbho.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [AdobeBridge]
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\Wcescomm.exe"
uRun: [Spyware Doctor] c:\documents and settings\myname\desktop\sdsetup.exe -min
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [SigmatelSysTrayApp] sttray.exe
mRun: [IntelAudioStudio] "c:\program files\intel audio studio\IntelAudioStudio.exe" TRAY
mRun: [CHotkey] c:\apps\chicony\chicony.bat
mRun: [RemoteControl] c:\apps\cyberlink\powerdvd\PDVDServ.exe
mRun: [Logitech Utility] Logi_MwX.Exe
mRun: [DSLSTATEXE] c:\program files\d-link\dsl-200\dslstat.exe icon
mRun: [DSLAGENTEXE] c:\program files\d-link\dsl-200\dslagent.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe
mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe
mRun: [ControlCenter2.0] c:\program files\brother\controlcenter2\brctrcen.exe /autorun
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [Alcmtr] ALCMTR.EXE
mRun: [NeroCheck] c:\windows\system32\\NeroCheck.exe
mRun: [MessengerPlus3] "c:\program files\messengerplus! 3\MsgPlus.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2011\avp.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\myname\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wddmst~1.lnk - c:\program files\western digital\wd smartware\wd drive manager\WDDMStatus.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wdsmar~1.lnk - c:\program files\western digital\wd smartware\front parlor\WDSmartWare.exe
uPolicies-explorer: DisallowRun = 1 (0x1)
IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2011\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
IE: {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - c:\casino\europa casino\casino.exe
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partygaming\partypoker\RunApp.exe
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\myname\start menu\programs\imvu\Run IMVU.lnk
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - c:\program files\yahoo!\messenger\YahooMessenger.exe
IE: {F4430FE8-2638-42e5-B849-800749B94EED} - c:\documents and settings\myname\my documents\cards\partypokernet\RunPF.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2011\klwtbbho.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2011\klwtbbho.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1268864681921
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1268864670421
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} - hxxps://register3.valueactive.com/414/webolr/OCX/FlashAX.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F1D54B0B-B6EA-43B5-BD26-A79D3DBF47E3} - hxxp://bigpondmusic.com/activex/multidownx.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~1\kloehk.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, xlibgfl254.dll
IFEO: image file execution options - svchost.exe
IFEO: OLT.exe - svchost.exe
Hosts: google.com
Hosts: google.com.au
Hosts: www.google.com.au
Hosts: google.be
Hosts: www.google.be

Note: multiple HOSTS entries found. Please refer to Attach.txt

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\myname\applic~1\mozilla\firefox\profiles\01e51oq3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2418376&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - search
FF - prefs.js: browser.startup.homepage - hxxp://au.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=GRxdm116YYAU&ptb=bHbr2s9LdQhsGnWYUyAhww&psa=&ind=2010072913&ptnrS=GRxdm116YYAU&si=&st=kwd&n=77cf4751&searchfor=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\myname\application data\mozilla\firefox\profiles\01e51oq3.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\myname\application data\mozilla\firefox\profiles\01e51oq3.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar-ff3.dll
FF - component: c:\program files\mozilla firefox\extensions\kavantibanner@kaspersky.ru\components\abhelperxpcom.dll
FF - component: c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll
FF - plugin: c:\program files\tabletplugins\npwacom.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Anti-Banner: KavAntiBanner@Kaspersky.ru - c:\program files\mozilla firefox\extensions\KavAntiBanner@Kaspersky.ru
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\documents and settings\all users\application data\google\toolbar for firefox\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff

============= SERVICES / DRIVERS ===============

R0 KL1;kl1;c:\windows\system32\drivers\kl1.sys [2010-6-9 132184]
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2010-6-9 11352]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2011-2-25 475736]
R2 AVP;Kaspersky Anti-Virus Service;c:\program files\kaspersky lab\kaspersky internet security 2011\avp.exe [2010-10-5 365336]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-11-28 54752]
R2 GEST Service;GEST Service for program management.;c:\program files\gigabyte\energysaver\GSvr.exe [2009-7-25 68136]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 TabletServiceWacom;TabletServiceWacom;c:\program files\tablet\wacom\Wacom_Tablet.exe [2010-12-14 4807536]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\western digital\wd smartware\wd drive manager\WDDMService.exe [2009-11-13 110592]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\western digital\wd smartware\front parlor\WDSmartWareBackgroundService.exe [2009-6-16 20480]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2010-5-7 32856]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-11-2 19472]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\tffsmon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\tfsysmon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]
S3 brfilt;Brother MFC Filter Driver;c:\windows\system32\drivers\BrFilt.sys [2006-10-2 2944]
S3 brparimg;Brother Multi Function Parallel Image driver;c:\windows\system32\drivers\BrParImg.sys [2006-10-2 3168]
S3 BrParWdm;Brother WDM Parallel Driver;c:\windows\system32\drivers\BrParwdm.sys [2006-10-2 39552]
S3 BrSerWDM;Brother WDM Serial driver;c:\windows\system32\drivers\BrSerWdm.sys [2006-10-2 61440]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys --> c:\windows\system32\drivers\ivusb.sys [?]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [2010-9-27 91496]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\tfnetmon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2010-12-14 10752]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2010-7-2 11520]

=============== Created Last 30 ================

2011-02-25 02:25:27 109240 ----a-w- c:\program files\mozilla firefox\extensions\kavantibanner@kaspersky.ru\components\abhelperxpcom.dll
2011-02-25 02:25:14 150200 ----a-w- c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
2011-02-25 01:55:38 97859 ----a-w- c:\windows\system32\drivers\klick.dat
2011-02-25 01:55:38 114243 ----a-w- c:\windows\system32\drivers\klin.dat
2011-02-25 01:53:59 -------- d-----w- c:\program files\Kaspersky Lab
2011-02-25 01:53:58 -------- d-----w- c:\docume~1\alluse~1\applic~1\Kaspersky Lab
2011-02-24 19:00:09 -------- d-----w- c:\docume~1\alluse~1\applic~1\XoftSpySE
2011-02-24 19:00:05 -------- d-----w- c:\program files\XoftSpySE6
2011-02-24 18:35:25 12872 ----a-w- c:\windows\system32\bootdelete.exe
2011-02-24 18:07:05 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-02-24 18:06:34 -------- d-----w- c:\docume~1\alluse~1\applic~1\Hitman Pro
2011-02-23 01:17:32 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-02-22 02:01:24 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-02-22 01:59:57 -------- d-----w- c:\docume~1\myname\locals~1\applic~1\Sunbelt Software
2011-02-18 11:42:57 -------- d-sh--w- c:\docume~1\alluse~1\applic~1\ISDQXGE
2011-02-18 11:42:14 -------- d-sh--w- c:\docume~1\alluse~1\applic~1\acae7c
2011-02-11 06:00:00 -------- d-----w- c:\program files\iPod
2011-02-11 05:59:56 -------- d-----w- c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-02-11 05:54:34 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll

==================== Find3M ====================

2011-02-27 22:52:06 17488 ----a-w- c:\windows\gdrv.sys
2009-02-03 14:45:57 279888 ----a-w- c:\program files\npmusicn.dll
2007-10-18 02:42:51 774144 ----a-w- c:\program files\RngInterstitial.dll
2006-10-17 22:39:21 19666504 ----a-w- c:\program files\QuickTimeInstaller.exe
2004-01-30 01:45:00 44842 ----a-w- c:\program files\SXUNINST.EXE

============= FINISH: 12:32:23.70 ===============

I have changed username to myname. Basically the virus redirects me whenever i use google search, the search list comes up then I click on a link and then I am diverted to all different sites such as trusearch.net/o.htm, deliciousnet.com, to name a few. I have tried running gmer but it keeps freezing up, I tried it several times.
If anyone can help me it would be much appreciated.

Edited post to include information about gmer crashing and added attach.txt file. Attached File  Attach.txt   17.11KB   0 downloads

Edited by Cutex, 01 March 2011 - 02:50 PM.

#2 SweetTech


    Agent ST

  • Members
  • 13,421 posts
  • Gender:Male
  • Location:Antarctica
  • Local time:03:26 AM

Posted 03 March 2011 - 08:10 PM

Hello and welcome to the forums!

My secret agent name on the forums is SweetTech (you can call me ST for short), it's a pleasure to meet you. :)

I would be glad to take a look at your log and help you with solving any malware problems.

If you have since resolved the issues you were originally experiencing, or have received help elsewhere, please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post. Please remember, I am a volunteer, and I do have a life outside of these forums.
  • Please make sure to carefully read any instruction that I give you. Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • In Windows Vista and Windows 7, all tools need to be started by right clicking and selecting Run as Administrator!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic.
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.


Running OTM

We need to execute an OTM script
  • Please download OTM by OldTimer and save it to your desktop.
  • Double click the Posted Image icon on your desktop.
  • Paste the following code under the Posted Image area. Do not include the word "Code".
  • Push the large Posted Image button.
  • OTM may ask to reboot the machine. Please do so if asked.
  • Copy/Paste the contents under the Posted Image line here in your next reply.
  • If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Rootkit UnHooker (RkU)
Please download Rootkit Unhooker from one of the following links and save it to your desktop.
Link 1 (.exe file)
Link 2 (zipped file)
Link 3 (.rar file)In order to use this tool if you downloaded from either of the second two links, you will need to extract the RKUnhookerLE.exe file using a program capable of extracing ZIP and RAR compressed files. If you don't have an extraction program, you can downlaod, install and use the free 7-zip utility.

  • Double-click on RKUnhookerLE.exe to start the program.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • Click the Report tab, then click Scan.
  • Check Drivers, Stealth, and uncheck the rest.
  • Click OK.
  • Wait until it's finished and then go to File > Save Report.
  • Save the report to your Desktop.
  • Copy and paste the contents of the report into your next reply.
-- Note: You may get this warning...just ignore it, click OK and continue: "Rootkit Unhooker has detected a parasite inside itself! It is recommended to remove parasite, okay?".


Running OTL

We need to create an OTL Report
  • Please download OTL from one of the following mirrors:
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <-- Will be opened
    • Extra.txt <-- Will be minimized


Please be sure to include an update on how your computer is currently running.

Have I helped you? If you'd like to assist in the fight against malware, click here Posted Image

The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.

#3 Cutex

  • Topic Starter

  • Members
  • 4 posts
  • Local time:05:26 PM

Posted 03 March 2011 - 09:40 PM

hi Sweetech,
I ran the OTM report as instructed and it was going ok then a message came up in another window saying mentioning not being able to move host file. I clicked ok. The report had paused and the last line of the report mentioned about the host file will not be removed until the computer is rebooted. I rebooted the computer then went to look for the OTM report as mentioned in your instructions, I opened the folder but there was no report. I am not sure whether to run the OTM again, please let me know. Thanks.

#4 SweetTech


    Agent ST

  • Members
  • 13,421 posts
  • Gender:Male
  • Location:Antarctica
  • Local time:03:26 AM

Posted 03 March 2011 - 09:45 PM


Download this file and run it, and then re-run the OTM fix.

Link: http://download.bleepingcomputer.com/bats/hosts-perm.bat

Have I helped you? If you'd like to assist in the fight against malware, click here Posted Image

The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.

#5 Cutex

  • Topic Starter

  • Members
  • 4 posts
  • Local time:05:26 PM

Posted 03 March 2011 - 11:29 PM

hi Sweetech,
I am attaching the OTM report and the Rootkit report. I have checked google search and everything now seems to be running ok.
I would refer not to submit the OTL and Extra Text reports in an open post.

All processes killed
========== PROCESSES ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========


User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 49286 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: suzy
->Temp folder emptied: 659983 bytes
->Temporary Internet Files folder emptied: 6640675 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 23740143 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 1097 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 218473 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 30.00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Restore point Set: OTM Restore Point (0)

OTM by OldTimer - Version log created on 03042011_143201

RkU Version: 3.8.388.590, Type LE (SR2)
OS Name: Windows XP
Version 5.1.2600 (Service Pack 3)
Number of processors #4
0xB71D1000 C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 5726208 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Miniport Driver)
0xB7A85000 kl1.sys 5382144 bytes (Kaspersky Lab ZAO, Kaspersky Unified Driver)
0xA4198000 C:\WINDOWS\system32\drivers\RtkHDAud.sys 5197824 bytes (Realtek Semiconductor Corp., Realtek® High Definition Audio Function Driver)
0xBD216000 C:\WINDOWS\System32\ati3duag.dll 3928064 bytes (ATI Technologies Inc. , ati3duag.dll)
0xBD5D5000 C:\WINDOWS\System32\ativvaxx.dll 2605056 bytes (Advanced Micro Devices, Inc. , Radeon Video Acceleration Universal Driver)
0x804D7000 C:\WINDOWS\system32\ntkrnlpa.exe 2150400 bytes (Microsoft Corporation, NT Kernel & System)
0x804D7000 PnpManager 2150400 bytes
0x804D7000 RAW 2150400 bytes
0x804D7000 WMIxWDM 2150400 bytes
0xBF800000 Win32k 1847296 bytes
0xBF800000 C:\WINDOWS\System32\win32k.sys 1847296 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0xBD108000 C:\WINDOWS\System32\atikvmag.dll 692224 bytes (ATI Technologies Inc., Virtual Command And Memory Manager)
0xBD060000 C:\WINDOWS\System32\ati2cqag.dll 688128 bytes (ATI Technologies Inc., Central Memory Manager / Queue Server Module)
0xB789E000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver)
0xA4119000 C:\WINDOWS\system32\DRIVERS\klif.sys 520192 bytes (Kaspersky Lab, Klif Mini-Filter [fre_wnet_x86])
0xA3F82000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0xBD1B1000 C:\WINDOWS\System32\atiok3x2.dll 413696 bytes (Advanced Micro Devices, Inc., Ring 0 x2 component)
0xB070F000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver)
0xA408D000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver)
0xA0906000 C:\WINDOWS\system32\DRIVERS\srv.sys 335872 bytes (Microsoft Corporation, Server driver)
0xBD012000 C:\WINDOWS\System32\ati2dvag.dll 319488 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Display Driver)
0xBFFA0000 C:\WINDOWS\System32\ATMFD.DLL 286720 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)
0xA0A70000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack)
0xB076D000 C:\WINDOWS\system32\DRIVERS\rdpdr.sys 196608 bytes (Microsoft Corporation, Microsoft RDP Device redirector)
0xB7A57000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT)
0xA0E36000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0xB7871000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver)
0x9F7EA000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer)
0xA3FF2000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0xB083D000 C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 163840 bytes (Windows ® Server 2003 DDK provider, High Definition Audio Bus Driver v1.0a)
0xA403F000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver)
0xB7A01000 dmio.sys 155648 bytes (Microsoft Corp., Veritas Software, NT Disk Manager I/O Driver)
0xA4067000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator)
0xA468D000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0xB0819000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0xB07F6000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library)
0xA401D000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0x806E4000 ACPI_HAL 134400 bytes
0x806E4000 C:\WINDOWS\system32\hal.dll 134400 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0xB7954000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0xB7A27000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver)
0xB07D9000 C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 118784 bytes (Realtek Semiconductor Corporation , Realtek 10/100/1000 NDIS 5.1 Driver )
0xA46B1000 C:\WINDOWS\system32\drivers\AtiHdmi.sys 114688 bytes (ATI Technologies, Inc., ATI High Definition Audio Function Driver)
0xB7857000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver)
0xB79D1000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver)
0xA3F59000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes
0xB79E9000 C:\WINDOWS\system32\DRIVERS\SCSIPORT.SYS 98304 bytes (Microsoft Corporation, SCSI Port Driver)
0xB792B000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0xB07AE000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0xA0DF9000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper)
0xB07C5000 C:\WINDOWS\system32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver)
0xB0865000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver)
0xA40E6000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver)
0xBD000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver)
0xB7942000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver)
0xA3F71000 C:\WINDOWS\System32\Drivers\BrSerIf.sys 69632 bytes (Brother Industries Ltd., Brotehr Serial I/F Driver (WDM))
0xB7A46000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0xB079D000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler)
0xB8128000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver)
0xB0A7E000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0xB8228000 C:\WINDOWS\system32\DRIVERS\nic1394.sys 65536 bytes (Microsoft Corporation, IEEE1394 Ndis Miniport and Call Manager)
0xB81A8000 ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver)
0xB0A5E000 C:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver)
0xB8198000 C:\WINDOWS\system32\DRIVERS\arp1394.sys 61440 bytes (Microsoft Corporation, IP/1394 Arp Client)
0xB7807000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0xB0A6E000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver)
0xA0FC3000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter)
0xB8188000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB)
0xB81B8000 C:\WINDOWS\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver)
0xB8168000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll)
0xB0A4E000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver)
0xB0A1E000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0xB80C8000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0xB77D7000 C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys 49152 bytes (Microsoft Corporation, Family Safety Filter Driver (TDI))
0xB77B7000 C:\WINDOWS\System32\Drivers\pcouffin.sys 49152 bytes (VSO Software, low level access layer for CD/DVD/BD devices)
0xB09FE000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0xB80F8000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver)
0xB4CA3000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver)
0xB80B8000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager)
0xB0A0E000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0xB80A8000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver)
0xB0A2E000 C:\WINDOWS\system32\DRIVERS\klim5.sys 40960 bytes (Kaspersky Lab ZAO, Kaspersky Lab Intermediate Network Driver)
0xB8108000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy)
0xB77F7000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver)
0xB8158000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver)
0xB0A3E000 C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library)
0xB82B8000 C:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver)
0xB8118000 C:\WINDOWS\system32\DRIVERS\klmouflt.sys 36864 bytes (Kaspersky Lab, KLMOUFLT Mouse Device Filter [fre_wnet_x86])
0xB09EE000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier)
0xB81F8000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver)
0xB7837000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0xB8178000 PxHelp20.sys 36864 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)
0xB81C8000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0xB3D9D000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver)
0xB3D85000 C:\WINDOWS\system32\DRIVERS\usbccgp.sys 32768 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver)
0xB84B0000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0xB3D5D000 C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys 32768 bytes (Wacom Technology, Wacom Mouse Filter Driver)
0xB84A8000 C:\WINDOWS\system32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver)
0xB8470000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)
0xB8328000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0xB3D75000 C:\WINDOWS\system32\DRIVERS\usbprint.sys 28672 bytes (Microsoft Corporation, USB Printer driver)
0xB84A0000 C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter)
0xB83F0000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver)
0xB83F8000 C:\WINDOWS\system32\DRIVERS\kl2.sys 24576 bytes (Kaspersky Lab ZAO, Kaspersky Unified Driver)
0xB3D6D000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver)
0xB83B0000 C:\WINDOWS\system32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0xB8390000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0xB8400000 C:\WINDOWS\system32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver)
0xB8420000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver)
0xB8330000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager)
0xB4E29000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library)
0xB8358000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver)
0xB4E49000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper)
0xB4E39000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver)
0xB11E1000 C:\WINDOWS\System32\Drivers\BrScnUsb.sys 16384 bytes (Brother Industries Ltd., Brother USB Scanner Driver)
0xA0978000 C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 16384 bytes (Conexant, Diagnostic Interface DRIVER)
0xB777B000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver)
0xA1103000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver)
0xB776F000 C:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator)
0xB84B8000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver)
0xB11DD000 C:\WINDOWS\System32\Drivers\BrUsbSer.sys 12288 bytes (Brother Industries Ltd., Brother USB Serial Driver )
0xB0D1C000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver)
0xA0476000 C:\WINDOWS\gdrv.sys 12288 bytes (Windows ® 2000 DDK provider, GIGABYTE Tools)
0xB11F5000 C:\WINDOWS\system32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices)
0xB7753000 C:\WINDOWS\System32\Drivers\i2omgmt.SYS 12288 bytes (Microsoft Corporation, I2O Utility Filter)
0xB859C000 C:\WINDOWS\system32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver)
0xB778B000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0xB7747000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
0xB5D6D000 C:\WINDOWS\system32\DRIVERS\wacomvhid.sys 12288 bytes (Wacom Technology, Virtual Hid Device)
0xB8626000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver)
0xB85B6000 dmload.sys 8192 bytes (Microsoft Corp., Veritas Software., NT Disk Manager Startup Driver)
0xB8632000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes
0xB8624000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver)
0xB85A8000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
0xB862C000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator)
0xB862E000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport)
0xB861C000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0xB860C000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
0xB85AA000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0xB868E000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver)
0xB306C000 C:\WINDOWS\System32\Drivers\BANTExt.sys 4096 bytes
0xB871C000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk)
0xB86C8000 C:\WINDOWS\system32\mbmiodrvr.sys 4096 bytes (cansoft@livewiredev.com, MBMIO Driver)
0xB307B000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver)
0xB8670000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver)
0xB8703000 C:\WINDOWS\System32\Drivers\register.sys 4096 bytes
0x05590000 Hidden Image-->CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 102400 bytes
0x06C90000 Hidden Image-->CLI.Aspect.Radeon3D.Graphics.Wizard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 102400 bytes
0x040C0000 Hidden Image-->Tanagra.DataClad.dll [ EPROCESS 0x89F2CDA0 ] PID: 4044, 1077248 bytes
0x01250000 Hidden Image-->CLI.Foundation.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 110592 bytes
0x05640000 Hidden Image-->CLI.Aspect.MMVideo.Graphics.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 110592 bytes
0x00CF0000 Hidden Image-->MOM.Implementation.dll [ EPROCESS 0x89BFDDA0 ] PID: 1760, 118784 bytes
0x03850000 Hidden Image-->MOM.Implementation.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 118784 bytes
0x073B0000 Hidden Image-->CLI.Component.Dashboard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 1232896 bytes
0x053E0000 Hidden Image-->Tanagra.BMU.dll [ EPROCESS 0x89F2CDA0 ] PID: 4044, 1413120 bytes
0x04AA0000 Hidden Image-->CLI.Caste.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 167936 bytes
0x070D0000 Hidden Image-->CLI.Aspect.DisplaysManager.Graphics.Wizard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 1748992 bytes
0x07790000 Hidden Image-->CLI.Aspect.TransCode.Graphics.Dashboard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 192512 bytes
0x06A70000 Hidden Image-->CLI.Aspect.InfoCentre.Graphics.Dashboard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 208896 bytes
0x04E50000 Hidden Image-->CLI.Aspect.InfoCentre.Graphics.Wizard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 217088 bytes
0x06BE0000 Hidden Image-->CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 282624 bytes
0x01290000 Hidden Image-->MOM.Foundation.dll [ EPROCESS 0x89BFDDA0 ] PID: 1760, 28672 bytes
0x03620000 Hidden Image-->LOG.Foundation.Implementation.Private.dll [ EPROCESS 0x89BFDDA0 ] PID: 1760, 28672 bytes
0x05B40000 Hidden Image-->DEM.Graphics.I0906.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x04BA0000 Hidden Image-->ResourceManagement.Foundation.Private.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x01240000 Hidden Image-->MOM.Foundation.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x01270000 Hidden Image-->LOG.Foundation.Implementation.Private.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x03920000 Hidden Image-->CLI.Component.Runtime.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x03DF0000 Hidden Image-->AEM.Server.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x03E30000 Hidden Image-->AEM.Plugin.DPPE.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x03FB0000 Hidden Image-->AEM.Plugin.Hotkeys.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x040E0000 Hidden Image-->AEM.Plugin.WinMessages.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x04110000 Hidden Image-->DEM.Foundation.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x04120000 Hidden Image-->DEM.Graphics.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x04AF0000 Hidden Image-->DEM.Graphics.I0709.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x04B70000 Hidden Image-->AEM.Actions.CCAA.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x04B20000 Hidden Image-->AEM.Plugin.GD.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x04CF0000 Hidden Image-->DEM.Graphics.I0804.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x04E90000 Hidden Image-->CLI.Caste.HydraVision.Wizard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x04ED0000 Hidden Image-->CLI.Component.Dashboard.Shared.Private.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x04F00000 Hidden Image-->CLI.Caste.Graphics.Dashboard.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x04F30000 Hidden Image-->CLI.Caste.HydraVision.Dashboard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x053A0000 Hidden Image-->CLI.Caste.Graphics.Runtime.Shared.Private.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x05820000 Hidden Image-->CLI.Aspect.VPURecover.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x05860000 Hidden Image-->CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x05870000 Hidden Image-->CLI.Aspect.HotkeysHandling.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x05CA0000 Hidden Image-->DEM.Graphics.I0703.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x05BB0000 Hidden Image-->DEM.Graphics.I0712.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x05B80000 Hidden Image-->DEM.Graphics.I0706.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x05B50000 Hidden Image-->DEM.Graphics.I0912.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x05B60000 Hidden Image-->CLI.Aspect.Welcome.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x05C20000 Hidden Image-->DEM.Graphics.I0812.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x05C40000 Hidden Image-->DEM.Graphics.I0805.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x05D50000 Hidden Image-->atixclib.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x063C0000 Hidden Image-->CLI.Caste.HydraVision.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x06400000 Hidden Image-->APM.Foundation.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x06440000 Hidden Image-->CLI.Component.Runtime.Extension.EEU.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x06610000 Hidden Image-->AEM.Plugin.EEU.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x065E0000 Hidden Image-->AEM.Plugin.REG.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x067A0000 Hidden Image-->CLI.Component.Client.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x06880000 Hidden Image-->CLI.Component.Wizard.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x068B0000 Hidden Image-->CLI.Caste.Graphics.Wizard.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 28672 bytes
0x04D80000 Hidden Image-->System.Data.dll [ EPROCESS 0x89F2CDA0 ] PID: 4044, 2961408 bytes
0x04CE0000 Hidden Image-->Tanagra.DataClad.DataAccess.dll [ EPROCESS 0x89F2CDA0 ] PID: 4044, 299008 bytes
0x074E0000 Hidden Image-->CLI.Aspect.Radeon3D.Graphics.Dashboard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 364544 bytes
0x00A00000 Hidden Image-->MemeoRemoteCore.dll [ EPROCESS 0x89FB4BC0 ] PID: 2420, 36864 bytes
0x01100000 Hidden Image-->NEWAEM.Foundation.dll [ EPROCESS 0x89BFDDA0 ] PID: 1760, 36864 bytes
0x04B80000 Hidden Image-->XMLSettings.dll [ EPROCESS 0x89F2CDA0 ] PID: 4044, 36864 bytes
0x038A0000 Hidden Image-->CLI.Foundation.XManifest.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 36864 bytes
0x038E0000 Hidden Image-->AxInterop.WBOCXLib.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 36864 bytes
0x03A90000 Hidden Image-->NEWAEM.Foundation.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 36864 bytes
0x03E40000 Hidden Image-->Interop.WBOCXLib.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 36864 bytes
0x04EC0000 Hidden Image-->CLI.Component.Dashboard.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 36864 bytes
0x054D0000 Hidden Image-->CLI.Aspect.VPURecover.Graphics.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 36864 bytes
0x05530000 Hidden Image-->CLI.Aspect.DisplaysColour2.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 36864 bytes
0x05790000 Hidden Image-->CLI.Aspect.CustomFormats.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 36864 bytes
0x05660000 Hidden Image-->CLI.Aspect.Welcome.Graphics.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 36864 bytes
0x057A0000 Hidden Image-->CLI.Aspect.TransCode.Graphics.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 36864 bytes
0x05830000 Hidden Image-->CLI.Aspect.DisplaysOptions.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 36864 bytes
0x063B0000 Hidden Image-->CLI.Caste.HydraVision.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 36864 bytes
0x06890000 Hidden Image-->CLI.Component.Wizard.Shared.Private.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 36864 bytes
0x06C30000 Hidden Image-->CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 389120 bytes
0x04A30000 Hidden Image-->CLI.Caste.Graphics.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 397312 bytes
0x055B0000 Hidden Image-->CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 405504 bytes
0x06730000 Hidden Image-->CLI.Component.Wizard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 413696 bytes
0x06AB0000 Hidden Image-->CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 421888 bytes
0x06CB0000 Hidden Image-->CLI.Aspect.MMVideo.Graphics.Wizard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 421888 bytes
0x010F0000 Hidden Image-->CCC.Implementation.dll [ EPROCESS 0x89BFDDA0 ] PID: 1760, 45056 bytes
0x011F0000 Hidden Image-->LOG.Foundation.dll [ EPROCESS 0x89BFDDA0 ] PID: 1760, 45056 bytes
0x01260000 Hidden Image-->LOG.Foundation.Private.dll [ EPROCESS 0x89BFDDA0 ] PID: 1760, 45056 bytes
0x03930000 Hidden Image-->ATICCCom.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 45056 bytes
0x00D40000 Hidden Image-->CCC.Implementation.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 45056 bytes
0x01230000 Hidden Image-->LOG.Foundation.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 45056 bytes
0x032C0000 Hidden Image-->LOG.Foundation.Private.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 45056 bytes
0x04F20000 Hidden Image-->CLI.Aspect.DeviceLCD.Graphics.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 45056 bytes
0x054E0000 Hidden Image-->CLI.Aspect.DeviceLCD.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 45056 bytes
0x04250000 Hidden Image-->ATIDEMGX.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 487424 bytes
0x03900000 Hidden Image-->CLI.Foundation.Private.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 53248 bytes
0x03A80000 Hidden Image-->AEM.Server.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 53248 bytes
0x03E20000 Hidden Image-->AEM.Plugin.Source.Kit.Server.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 53248 bytes
0x040F0000 Hidden Image-->DEM.Graphics.I0601.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 53248 bytes
0x05260000 Hidden Image-->CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 53248 bytes
0x05250000 Hidden Image-->CLI.Aspect.DeviceCRT.Graphics.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 53248 bytes
0x05270000 Hidden Image-->CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 53248 bytes
0x05880000 Hidden Image-->CLI.Aspect.DeviceCV.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 53248 bytes
0x05A20000 Hidden Image-->CLI.Aspect.TransCode.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 53248 bytes
0x065F0000 Hidden Image-->CLI.Component.Client.Shared.Private.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 53248 bytes
0x068A0000 Hidden Image-->CLI.Caste.Graphics.Wizard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 53248 bytes
0x06450000 Hidden Image-->CLI.Component.Systemtray.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 585728 bytes
0x07540000 Hidden Image-->CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 585728 bytes
0x05560000 Hidden Image-->Tanagra.Interop.dll [ EPROCESS 0x89F2CDA0 ] PID: 4044, 61440 bytes
0x038F0000 Hidden Image-->CLI.Component.Runtime.Shared.Private.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 61440 bytes
0x05290000 Hidden Image-->CLI.Aspect.DeviceDFP.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 61440 bytes
0x05890000 Hidden Image-->CLI.Aspect.DeviceCRT.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 61440 bytes
0x05BF0000 Hidden Image-->CLI.Aspect.DeviceProperty.Graphics.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 61440 bytes
0x05BA0000 Hidden Image-->CLI.Aspect.DeviceProperty.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 61440 bytes
0x077C0000 Hidden Image-->CLI.Aspect.OverDrive5.Graphics.Dashboard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 667648 bytes
0x04B30000 Hidden Image-->Memeo.API.dll [ EPROCESS 0x89F2CDA0 ] PID: 4044, 69632 bytes
0x03880000 Hidden Image-->CLI.Component.SkinFactory.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 69632 bytes
0x038B0000 Hidden Image-->CLI.Component.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 69632 bytes
0x05840000 Hidden Image-->CLI.Aspect.Radeon3D.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 69632 bytes
0x059D0000 Hidden Image-->CLI.Aspect.OverDrive5.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 69632 bytes
0x063E0000 Hidden Image-->APM.Server.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 69632 bytes
0x06BC0000 Hidden Image-->CLI.Aspect.VPURecover.Graphics.Dashboard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 69632 bytes
0x068D0000 Hidden Image-->ResourceManagement.Foundation.Implementation.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 749568 bytes
0x01270000 Hidden Image-->LOG.Foundation.Implementation.dll [ EPROCESS 0x89BFDDA0 ] PID: 1760, 77824 bytes
0x05610000 Hidden Image-->SQLite.NET.dll [ EPROCESS 0x89F2CDA0 ] PID: 4044, 77824 bytes
0x01280000 Hidden Image-->LOG.Foundation.Implementation.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 77824 bytes
0x053B0000 Hidden Image-->CLI.Aspect.DeviceDFP.Graphics.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 77824 bytes
0x057E0000 Hidden Image-->CLI.Aspect.DeviceCV.Graphics.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 77824 bytes
0x054F0000 Hidden Image-->CLI.Aspect.Radeon3D.Graphics.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 77824 bytes
0x05A00000 Hidden Image-->CLI.Aspect.DeviceTV.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 77824 bytes
0x059A0000 Hidden Image-->CLI.Aspect.MMVideo.Graphics.Shared.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 77824 bytes
0x06A50000 Hidden Image-->CLI.Aspect.Welcome.Graphics.Dashboard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 77824 bytes
0x03960000 Hidden Image-->ADL.Foundation.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 86016 bytes
0x04EE0000 Hidden Image-->CLI.Caste.Graphics.Dashboard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 86016 bytes
0x05510000 Hidden Image-->CLI.Aspect.OverDrive5.Graphics.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 86016 bytes
0x05800000 Hidden Image-->CLI.Aspect.DeviceTV.Graphics.Runtime.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 86016 bytes
0x076B0000 Hidden Image-->CLI.Aspect.MMVideo.Graphics.Dashboard.dll [ EPROCESS 0x8A1AB7B8 ] PID: 3296, 888832 bytes
0x04730000 Hidden Image-->Tanagra.Utility.dll [ EPROCESS 0x89F2CDA0 ] PID: 4044, 913408 bytes

Everything appears to be working fine now. Thanks for your help

#6 SweetTech


    Agent ST

  • Members
  • 13,421 posts
  • Gender:Male
  • Location:Antarctica
  • Local time:03:26 AM

Posted 04 March 2011 - 08:42 AM

Okay, that's your decision.

OTM Clean-Up
  • Double-click OTM.exe to start the program.
  • Close all other programs apart from OTM as this step will require a reboot
  • On the OTM main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.


Your logs appear to be clean, so if you have no further issues with your computer, then please proceed with the following housekeeping procedures outlined below.


All Clean Speech

===> Make sure you've re-enabled any Security Programs that we may have disabled during the malware removal process. <===

Below I have included a number of recommendations for how to protect your computer against malware infections.

Updated Anti-Virus Program
It's essential that you have an updated anti-virus program running on your computer. You don't want to run more than one as it can cause program conflicts, as well as false positives

You can view an excellent list of Free Security Software programs that has been compiled by GeekstoGo.

Avoid P2P Programs

Remember that no matter how clean the program you're using for peer-to-peer filesharing may be, it offers no guarantees regarding the cleanliness of files you may choose to download. All files available via p2p filesharing carry a high risk, particularly those that offer you illegitimate methods of using legitimate software programs without paying for them. Some further readings on this subject, along the included links, are as follows: File-Sharing, otherwise known as Peer To Peer and Risks of File-Sharing Technology.

If you have any of these programs installed then I highly suggest you uninstall them.

NOTE: Take care when answering any questions posed by an uninstaller. Some questions may be worded to deceive you into keeping the program.

Internet Browsers

Many of the users that I assist here on the forums, ask me which programs they can use to prevent themselves from getting infected again in the future. The best answer I can give you is too practice safe browsing.

Please consider using an alternative browser such as Google Chrome or Opera. They are both much more secure than Internet Explorer, immune to almost all known browser hijackers, and also have great built-in pop-up blockers.

I also suggest you make your Internet Explore more secure.

Make Internet Explorer more secure

  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

Extra Goodies

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at: http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • You should run an updated scan with MalwareBytes' Anti-Malware weekly. Instructions are included below:

    • Open Malwarebytes' Anti-Malware
    • Select the Update tab
    • Click Check for Updates

  • Be weary of e-mails from unknown senders. Keep the following in mind as well: If it's to good to be true, then it more than likely is.

  • FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated. Its important to keep programs up to date so that malware doesn't exploit any old security flaws.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for Chrome and Opera.
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security--What Do I Need?.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.


Have I helped you? If you'd like to assist in the fight against malware, click here Posted Image

The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.

#7 Cutex

  • Topic Starter

  • Members
  • 4 posts
  • Local time:05:26 PM

Posted 04 March 2011 - 12:12 PM

hi SweetTech,
I have completed the cleanup, everything still appears to be running fine now. Thank you so much for your help.

#8 SweetTech


    Agent ST

  • Members
  • 13,421 posts
  • Gender:Male
  • Location:Antarctica
  • Local time:03:26 AM

Posted 04 March 2011 - 12:17 PM

You're more than welcome.

Take care.


Have I helped you? If you'd like to assist in the fight against malware, click here Posted Image

The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.

#9 SweetTech


    Agent ST

  • Members
  • 13,421 posts
  • Gender:Male
  • Location:Antarctica
  • Local time:03:26 AM

Posted 04 March 2011 - 12:17 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

Have I helped you? If you'd like to assist in the fight against malware, click here Posted Image

The instructions seen in this post have been specifically tailored to this user and the issues they are experiencing with their computer. If you think you have a similar problem, please first read this topic, and then begin your own, new thread. I do not offer private support via Private Message.

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users