Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Need Help think infected [RESOLVED]


  • This topic is locked This topic is locked

#1
sreynaga

sreynaga

    Member

  • Member
  • PipPip
  • 31 posts
Here is my hi jack this log, I'm not sure what is going on any help would be appreciated!

Logfile of HijackThis v1.99.1
Scan saved at 7:48:20 PM, on 8/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ProcessGuard\dcsuserprot.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\ProcessGuard\pgaccount.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ProcessGuard\procguard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft IntelliPoint\Point32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\default\Desktop\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [!1_pgaccount] "C:\Program Files\ProcessGuard\pgaccount.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKCU\..\Run: [!1_ProcessGuard_Startup] "C:\Program Files\ProcessGuard\procguard.exe" -minimize
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search - http://km.bar.need2f...earch.html?p=KM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} - http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...790/mcfscan.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: DiamondCS Process Guard Service v3.000 (DCSPGSRV) - DiamondCS - C:\Program Files\ProcessGuard\dcsuserprot.exe
O23 - Service: GFI LANguard N.S.S. 7.0 Attendant Service - Unknown owner - C:\Program Files\GFI\LANguard Network Security Scanner 7.0\lnssatt.exe" -service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
  • 0

Advertisements


#2
coachwife6

coachwife6

    SuperStar

  • Retired Staff
  • 11,413 posts
Hi sreynaga. Welcome to GTG. :blink: Are you still experiencing difficulty? If so, please run hijack this again and post a new log in this thread along with any additional problems you may be having. I look forward to working with you. :whistling:
  • 0

#3
sreynaga

sreynaga

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
Hi sorry it has taken me so long to reply, i appreciate your help. I am at work right now and cannot post a hijack this log just yet, but as soon as I get home I will. The problem that I am having is that it has been taking forever to start up my computer. I have a selective startup that only starts the programs I want which is my virus software and graphics card stuff. Also, when I get onto the internet ( I have high speed through cox communications) it runs slower than dial up. I have ran several virus, malware, spyware programs and it detects nothing, so I am not sure what is going, but in a few hours I will post the log and maybe you can make some sense of it for me. Again, thanks so much for your time.
Stephanie
  • 0

#4
coachwife6

coachwife6

    SuperStar

  • Retired Staff
  • 11,413 posts
Did you disable everything except those two items that you mentioned? You may have disabled items from start-up that need to be enabled.
  • 0

#5
coachwife6

coachwife6

    SuperStar

  • Retired Staff
  • 11,413 posts
What antiviral are you running? I see you have trendmicro, but it's not in the startup section, which is identified by the 04 entries.
  • 0

#6
coachwife6

coachwife6

    SuperStar

  • Retired Staff
  • 11,413 posts
To Get StartupList:
  • Please download StartupList to your desktop.
  • Double click the startuplist.zip to extract the files inside.
  • When the new window opens, please double click on StartupList.exe
  • A window will open that will begin listing all of the startups with icons and text. In the lower left hand corner, it will show the status. When it says "ready" in the bottom left corner, it has finished running.
  • At the top of the window, click File>Save As and save startuplist.txt to your desktop.
  • Close startuplist.exe window
  • Post a copy of startuplist.txt in your next reply

  • 0

#7
sreynaga

sreynaga

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
This is my hijack this log. Hopefully it helps.
Logfile of HijackThis v1.99.1
Scan saved at 7:48:20 PM, on 9/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ProcessGuard\dcsuserprot.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\ProcessGuard\pgaccount.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ProcessGuard\procguard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft IntelliPoint\Point32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\default\Desktop\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [!1_pgaccount] "C:\Program Files\ProcessGuard\pgaccount.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKCU\..\Run: [!1_ProcessGuard_Startup] "C:\Program Files\ProcessGuard\procguard.exe" -minimize
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search - http://km.bar.need2f...earch.html?p=KM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} - http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...790/mcfscan.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: DiamondCS Process Guard Service v3.000 (DCSPGSRV) - DiamondCS - C:\Program Files\ProcessGuard\dcsuserprot.exe
O23 - Service: GFI LANguard N.S.S. 7.0 Attendant Service - Unknown owner - C:\Program Files\GFI\LANguard Network Security Scanner 7.0\lnssatt.exe" -service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
  • 0

#8
coachwife6

coachwife6

    SuperStar

  • Retired Staff
  • 11,413 posts
Can you give me a start-up list?
  • 0

#9
sreynaga

sreynaga

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
I thought I had posted this start up list earlier sorry

StartupList report, 9/10/2006, 12:26:59 AM
StartupList version 2.01.0
Started from: C:\DOCUME~1\Jessica\LOCALS~1\Temp\Temporary Directory 1 for startuplist[1].zip\StartupList.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Logged on as 'Jessica' to 'VAIO'
* Using default options (see end of log for possible options)
==================================================

Running processes (26):

[C:\DOCUME~1\Jessica\LOCALS~1\Temp\Temporary Directory 1 for startuplist[1].zip\StartupList.exe (41)]
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\asycfilt.dll
C:\WINDOWS\system32\CLBCATQ.DLL
C:\WINDOWS\system32\COMCTL32.dll
C:\WINDOWS\system32\comdlg32.dll
C:\WINDOWS\system32\COMRes.dll
C:\WINDOWS\system32\DNSAPI.dll
C:\WINDOWS\system32\GDI32.dll
C:\WINDOWS\system32\kernel32.dll
C:\WINDOWS\system32\MSCOMCTL.OCX
C:\WINDOWS\system32\MSCTF.dll
C:\WINDOWS\system32\msi.dll
C:\WINDOWS\system32\mslbui.dll
C:\WINDOWS\system32\MSVBVM60.DLL
C:\WINDOWS\system32\MSVCP60.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\NETAPI32.dll
C:\WINDOWS\system32\ntdll.dll
C:\WINDOWS\system32\NTDSAPI.dll
C:\WINDOWS\system32\ole32.dll
C:\WINDOWS\system32\OLEAUT32.dll
C:\WINDOWS\system32\PSAPI.DLL
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\Secur32.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\SHLWAPI.dll
C:\WINDOWS\system32\SXS.DLL
C:\WINDOWS\system32\USER32.dll
C:\WINDOWS\system32\uxtheme.dll
C:\WINDOWS\system32\VERSION.dll
C:\WINDOWS\system32\wbem\fastprox.dll
C:\WINDOWS\system32\wbem\wbemcomn.dll
C:\WINDOWS\system32\wbem\wbemdisp.dll
C:\WINDOWS\system32\wbem\wbemprox.dll
C:\WINDOWS\system32\wbem\wbemsvc.dll
C:\WINDOWS\system32\wbem\wmiutils.dll
C:\WINDOWS\system32\WLDAP32.dll
C:\WINDOWS\system32\WS2_32.dll
C:\WINDOWS\system32\WS2HELP.dll
C:\WINDOWS\system32\xpsp2res.dll
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

[C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe (36)]
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlPS.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\tmdbg.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\tmdp.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TMOACfg.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfwApi.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\tmpp.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmProxy.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmpxCfg.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\Apphelp.dll
C:\WINDOWS\system32\CLBCATQ.DLL
C:\WINDOWS\system32\comctl32.dll
C:\WINDOWS\system32\COMRes.dll
C:\WINDOWS\system32\GDI32.dll
C:\WINDOWS\system32\hnetcfg.dll
C:\WINDOWS\system32\iphlpapi.dll
C:\WINDOWS\system32\kernel32.dll
C:\WINDOWS\system32\msv1_0.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\ntdll.dll
C:\WINDOWS\system32\ole32.dll
C:\WINDOWS\system32\OLEAUT32.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\rsaenh.dll
C:\WINDOWS\system32\SECUR32.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\SHLWAPI.dll
C:\WINDOWS\system32\USER32.dll
C:\WINDOWS\system32\VERSION.dll
C:\WINDOWS\system32\WS2_32.dll
C:\WINDOWS\system32\WS2HELP.dll
C:\WINDOWS\System32\wshtcpip.dll
C:\WINDOWS\system32\WSOCK32.dll
C:\WINDOWS\system32\xpsp2res.dll
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

[C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe (21)]
C:\PROGRA~1\TRENDM~1\INTERN~1\PccScan.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\pewnt2.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\tmdbg.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\CLBCATQ.DLL
C:\WINDOWS\system32\comctl32.dll
C:\WINDOWS\system32\COMRes.dll
C:\WINDOWS\system32\GDI32.dll
C:\WINDOWS\system32\kernel32.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\ntdll.dll
C:\WINDOWS\system32\ole32.dll
C:\WINDOWS\system32\OLEAUT32.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\SHLWAPI.dll
C:\WINDOWS\system32\USER32.dll
C:\WINDOWS\system32\USERENV.dll
C:\WINDOWS\system32\VERSION.dll
C:\WINDOWS\system32\xpsp2res.dll
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

[C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe (42)]
C:\PROGRA~1\TRENDM~1\INTERN~1\tmCfwApi.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\tmdbg.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\tmHash.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfwHlp.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfwLog.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfwRul.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\CLBCATQ.DLL
C:\WINDOWS\system32\COMCTL32.dll
C:\WINDOWS\system32\comdlg32.dll
C:\WINDOWS\system32\COMRes.dll
C:\WINDOWS\system32\GDI32.dll
C:\WINDOWS\system32\hnetcfg.dll
C:\WINDOWS\system32\iphlpapi.dll
C:\WINDOWS\system32\kernel32.dll
C:\WINDOWS\system32\msv1_0.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\NETAPI32.dll
C:\WINDOWS\system32\ntdll.dll
C:\WINDOWS\system32\ole32.dll
C:\WINDOWS\system32\OLEAUT32.dll
C:\WINDOWS\system32\PSAPI.DLL
C:\WINDOWS\system32\rasapi32.dll
C:\WINDOWS\system32\rasman.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\rtutils.dll
C:\WINDOWS\system32\secur32.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\SHLWAPI.dll
C:\WINDOWS\system32\TAPI32.dll
C:\WINDOWS\system32\USER32.dll
C:\WINDOWS\system32\uxtheme.dll
C:\WINDOWS\system32\VERSION.dll
C:\WINDOWS\system32\WINMM.dll
C:\WINDOWS\system32\WINSPOOL.DRV
C:\WINDOWS\system32\WS2_32.dll
C:\WINDOWS\system32\WS2HELP.dll
C:\WINDOWS\System32\wshtcpip.dll
C:\WINDOWS\system32\WSOCK32.dll
C:\WINDOWS\system32\xpsp2res.dll
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

[C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe (45)]
C:\PROGRA~1\TRENDM~1\INTERN~1\icuin18.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\icuuc18.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmAsEng.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmcfScan.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\tmdbg.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmMsg.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmpeASpm.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmpeHosF.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmpePDP.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmpeURLF.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmpeVS.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmphAim.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmphHttp.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmphIcq.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmphMsn.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmphPop3.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmphSMTP.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmpxCfg.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmpxHelp.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmsmHttp.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmsmIm.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\TmsmMail.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\tmtdi.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmufeng.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\vsapi32.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\DNSAPI.dll
C:\WINDOWS\system32\GDI32.dll
C:\WINDOWS\system32\hnetcfg.dll
C:\WINDOWS\system32\kernel32.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\ntdll.dll
C:\WINDOWS\system32\rasadhlp.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\SECUR32.dll
C:\WINDOWS\system32\security.dll
C:\WINDOWS\system32\USER32.dll
C:\WINDOWS\system32\WINMM.dll
C:\WINDOWS\System32\winrnr.dll
C:\WINDOWS\system32\WLDAP32.dll
C:\WINDOWS\system32\WS2_32.dll
C:\WINDOWS\system32\WS2HELP.dll
C:\WINDOWS\System32\wshtcpip.dll
C:\WINDOWS\system32\WSOCK32.dll

[C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (140)]
c:\program files\ati technologies\ati.ace\aem.foundation.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt2.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt2.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp2.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp2.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty2.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour2.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour2.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.displaysmanager.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.displaysoptions.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.displaysoptions.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.integratedumaframebuffer.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.integratedumaframebuffer.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.multivpu.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.multivpu.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.multivpu2.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.multivpu2.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.overdrive2.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.overdrive2.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.overdrive3.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.overdrive3.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.powerplay3.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.powerplay3.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.radeon3dlegacy.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.radeon3dlegacy.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.smartgart.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.smartgart.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.verylargedesktop.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.verylargedesktop.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.videooverlay.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.videooverlay.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.vpurecover.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.vpurecover.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.welcome.local.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.workstationconfig.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.aspect.workstationconfig.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.caste.graphics.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.caste.graphics.dashboard.shared.dll
c:\program files\ati technologies\ati.ace\cli.caste.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.caste.local.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.component.dashboard.dll
c:\program files\ati technologies\ati.ace\cli.component.dashboard.shared.dll
c:\program files\ati technologies\ati.ace\cli.component.runtime.dll
c:\program files\ati technologies\ati.ace\cli.foundation.clients.dll
c:\program files\ati technologies\ati.ace\cli.foundation.dll
c:\program files\ati technologies\ati.ace\cli.foundation.xmanifestation.dll
c:\program files\ati technologies\ati.ace\cli.implementation.dll
c:\program files\ati technologies\ati.ace\dem.graphics.displaysmanager.shared.dll
c:\program files\ati technologies\ati.ace\log.foundation.dll
c:\program files\ati technologies\ati.ace\log.foundation.service.dll
c:\program files\ati technologies\ati.ace\log.foundation.shared.dll
C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll
c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll
c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll
c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_0ed7d6e8\mscorlib.dll
c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_cf1f553b\system.drawing.dll
c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_ee512dff\system.windows.forms.dll
c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_4d0357f5\system.xml.dll
c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_456223c3\system.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL
c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\perfcounter.dll
C:\WINDOWS\system32\ACTIVEDS.dll
C:\WINDOWS\system32\adsldpc.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\ATL.DLL
C:\WINDOWS\system32\comctl32.dll
C:\WINDOWS\system32\DNSAPI.dll
C:\WINDOWS\system32\GDI32.dll
C:\WINDOWS\system32\hnetcfg.dll
C:\WINDOWS\system32\iphlpapi.dll
C:\WINDOWS\system32\KERNEL32.dll
C:\WINDOWS\system32\MPRAPI.dll
C:\WINDOWS\system32\mscoree.dll
C:\WINDOWS\system32\MSCTF.dll
C:\WINDOWS\system32\msv1_0.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\NETAPI32.dll
C:\WINDOWS\system32\ntdll.dll
C:\WINDOWS\system32\NTMARTA.DLL
C:\WINDOWS\system32\ole32.dll
C:\WINDOWS\system32\OLEAUT32.dll
C:\WINDOWS\system32\perfproc.dll
C:\WINDOWS\system32\rasman.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\rsaenh.dll
C:\WINDOWS\system32\rtutils.dll
C:\WINDOWS\system32\SAMLIB.dll
C:\WINDOWS\system32\secur32.dll
C:\WINDOWS\system32\SETUPAPI.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\shfolder.dll
C:\WINDOWS\system32\SHLWAPI.dll
C:\WINDOWS\system32\tapi32.dll
C:\WINDOWS\system32\USER32.dll
C:\WINDOWS\system32\USERENV.dll
C:\WINDOWS\system32\uxtheme.dll
C:\WINDOWS\system32\WINMM.dll
C:\WINDOWS\System32\winrnr.dll
C:\WINDOWS\system32\WLDAP32.dll
C:\WINDOWS\system32\ws2_32.dll
C:\WINDOWS\system32\WS2HELP.dll
C:\WINDOWS\System32\wshtcpip.dll
C:\WINDOWS\system32\xpsp2res.dll
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

[C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (188)]
c:\program files\ati technologies\ati.ace\aem.foundation.dll
c:\program files\ati technologies\ati.ace\apm.foundation.dll
c:\program files\ati technologies\ati.ace\atidemgr.dll
c:\program files\ati technologies\ati.ace\cli.aspect.customformats.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt2.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp2.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp2.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty2.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour2.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour2.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.displaysoptions.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.displaysoptions.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.hotkeyshandling.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.hotkeyshandling.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.integratedumaframebuffer.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.multivpu.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.multivpu.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.multivpu2.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.multivpu2.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.overdrive2.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.overdrive3.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.overdrive3.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.powerplay3.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.powerplay3.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.radeon3dlegacy.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.radeon3dlegacy.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.smartgart.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.smartgart.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.verylargedesktop.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.verylargedesktop.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.videooverlay.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.videooverlay.graphics.runtime.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.videooverlay.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.vpurecover.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.aspect.vpurecover.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.aspect.workstationconfig.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.caste.graphics.runtime.dll
c:\program files\ati technologies\ati.ace\cli.caste.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.component.runtime.dll
c:\program files\ati technologies\ati.ace\cli.component.runtime.shared.dll
c:\program files\ati technologies\ati.ace\cli.foundation.dll
c:\program files\ati technologies\ati.ace\cli.foundation.xmanifestation.dll
c:\program files\ati technologies\ati.ace\cli.implementation.dll
c:\program files\ati technologies\ati.ace\dem.foundation.dll
c:\program files\ati technologies\ati.ace\dem.graphics.dematiadapterinfo.dll
c:\program files\ati technologies\ati.ace\dem.graphics.dematidisplaysmanagersettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demdevicecommon2settings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demdevicecommonsettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demdevicecomponentvideosettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demdevicecrtsettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demdevicedfp2settings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demdevicedfpsettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demdevicelcdsettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demdevicetv2settings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demdevicetvsettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demdisplayscoloursettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demdisplaysmanageroptionssettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demdriversettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demmultivpusettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demosadapterinfo.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demosinfo.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demosmodeinfo.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demoverdrive3settings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demoverdrivesettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.dempowerplaysettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demsmartgartsettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demumaframebuffersettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demverylargedesktopsettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demvideooverlaysettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demvideotheatermodesettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.demvpurecoverinfo.dll
c:\program files\ati technologies\ati.ace\dem.graphics.displaysmanager.shared.dll
c:\program files\ati technologies\ati.ace\dem.graphics.mmdeintlacingsettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.mmoverlaysettings.dll
c:\program files\ati technologies\ati.ace\dem.graphics.videooverlay.shared.dll
c:\program files\ati technologies\ati.ace\dem.graphics.workstationsettings.dll
c:\program files\ati technologies\ati.ace\log.foundation.dll
c:\program files\ati technologies\ati.ace\log.foundation.service.dll
c:\program files\ati technologies\ati.ace\log.foundation.shared.dll
C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll
c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll
c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll
c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll
c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_0ed7d6e8\mscorlib.dll
c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_cf1f553b\system.drawing.dll
c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_ee512dff\system.windows.forms.dll
c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_4d0357f5\system.xml.dll
c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_456223c3\system.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL
c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\perfcounter.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\WMINet_Utils.dll
C:\WINDOWS\system32\ACTIVEDS.dll
C:\WINDOWS\system32\adsldpc.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\appHelp.dll
C:\WINDOWS\system32\ATL.DLL
C:\WINDOWS\system32\CLBCATQ.DLL
C:\WINDOWS\system32\comctl32.dll
C:\WINDOWS\system32\COMRes.dll
C:\WINDOWS\system32\CRYPT32.dll
C:\WINDOWS\system32\CRYPTUI.dll
C:\WINDOWS\system32\DNSAPI.dll
C:\WINDOWS\system32\GDI32.dll
C:\WINDOWS\system32\hnetcfg.dll
C:\WINDOWS\system32\IMAGEHLP.dll
C:\WINDOWS\system32\iphlpapi.dll
C:\WINDOWS\system32\KERNEL32.dll
C:\WINDOWS\system32\MPRAPI.dll
C:\WINDOWS\system32\MSASN1.dll
C:\WINDOWS\system32\mscoree.dll
C:\WINDOWS\system32\MSCTF.dll
C:\WINDOWS\system32\msv1_0.dll
C:\WINDOWS\system32\MSVCP60.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\NETAPI32.dll
C:\WINDOWS\system32\ntdll.dll
C:\WINDOWS\system32\NTDSAPI.dll
C:\WINDOWS\system32\NTMARTA.DLL
C:\WINDOWS\system32\ole32.dll
C:\WINDOWS\system32\OLEAUT32.dll
C:\WINDOWS\system32\perfproc.dll
C:\WINDOWS\system32\rasman.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\rsaenh.dll
C:\WINDOWS\system32\rtutils.dll
C:\WINDOWS\system32\SAMLIB.dll
C:\WINDOWS\system32\secur32.dll
C:\WINDOWS\system32\SETUPAPI.dll
C:\WINDOWS\system32\shdocvw.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\shfolder.dll
C:\WINDOWS\system32\SHLWAPI.dll
C:\WINDOWS\system32\tapi32.dll
C:\WINDOWS\system32\urlmon.dll
C:\WINDOWS\system32\USER32.dll
C:\WINDOWS\system32\USERENV.dll
C:\WINDOWS\system32\uxtheme.dll
C:\WINDOWS\system32\VERSION.dll
C:\WINDOWS\system32\wbem\fastprox.dll
C:\WINDOWS\system32\wbem\wbemcomn.dll
C:\WINDOWS\system32\wbem\wbemprox.dll
C:\WINDOWS\system32\wbem\wbemsvc.dll
C:\WINDOWS\system32\wbem\wmiutils.dll
C:\WINDOWS\system32\WININET.dll
C:\WINDOWS\system32\WINMM.dll
C:\WINDOWS\System32\winrnr.dll
C:\WINDOWS\system32\WINTRUST.dll
C:\WINDOWS\system32\WLDAP32.dll
C:\WINDOWS\system32\ws2_32.dll
C:\WINDOWS\system32\WS2HELP.dll
C:\WINDOWS\System32\wshtcpip.dll
C:\WINDOWS\system32\xpsp2res.dll
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\gdiplus.dll

[C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (76)]
c:\program files\ati technologies\ati.ace\apm.foundation.dll
c:\program files\ati technologies\ati.ace\cli.caste.graphics.shared.dll
c:\program files\ati technologies\ati.ace\cli.component.runtime.dll
c:\program files\ati technologies\ati.ace\cli.component.systemtray.dll
c:\program files\ati technologies\ati.ace\cli.foundation.dll
c:\program files\ati technologies\ati.ace\cli.foundation.xmanifestation.dll
c:\program files\ati technologies\ati.ace\cli.implementation.dll
c:\program files\ati technologies\ati.ace\dem.graphics.displaysmanager.shared.dll
c:\program files\ati technologies\ati.ace\log.foundation.dll
c:\program files\ati technologies\ati.ace\log.foundation.service.dll
c:\program files\ati technologies\ati.ace\log.foundation.shared.dll
C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll
c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll
c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll
c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_0ed7d6e8\mscorlib.dll
c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_cf1f553b\system.drawing.dll
c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_ee512dff\system.windows.forms.dll
c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_4d0357f5\system.xml.dll
c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_456223c3\system.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL
c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\perfcounter.dll
C:\WINDOWS\system32\ACTIVEDS.dll
C:\WINDOWS\system32\adsldpc.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\ATL.DLL
C:\WINDOWS\system32\comctl32.dll
C:\WINDOWS\system32\DNSAPI.dll
C:\WINDOWS\system32\GDI32.dll
C:\WINDOWS\system32\hnetcfg.dll
C:\WINDOWS\system32\iphlpapi.dll
C:\WINDOWS\system32\KERNEL32.dll
C:\WINDOWS\system32\MPRAPI.dll
C:\WINDOWS\system32\mscoree.dll
C:\WINDOWS\system32\MSCTF.dll
C:\WINDOWS\system32\msv1_0.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\NETAPI32.dll
C:\WINDOWS\system32\ntdll.dll
C:\WINDOWS\system32\NTMARTA.DLL
C:\WINDOWS\system32\ole32.dll
C:\WINDOWS\system32\OLEAUT32.dll
C:\WINDOWS\system32\perfproc.dll
C:\WINDOWS\system32\rasman.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\rsaenh.dll
C:\WINDOWS\system32\rtutils.dll
C:\WINDOWS\system32\SAMLIB.dll
C:\WINDOWS\system32\secur32.dll
C:\WINDOWS\system32\SETUPAPI.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\shfolder.dll
C:\WINDOWS\system32\SHLWAPI.dll
C:\WINDOWS\system32\tapi32.dll
C:\WINDOWS\system32\USER32.dll
C:\WINDOWS\system32\USERENV.dll
C:\WINDOWS\system32\uxtheme.dll
C:\WINDOWS\system32\WINMM.dll
C:\WINDOWS\System32\winrnr.dll
C:\WINDOWS\system32\WLDAP32.dll
C:\WINDOWS\system32\ws2_32.dll
C:\WINDOWS\system32\WS2HELP.dll
C:\WINDOWS\System32\wshtcpip.dll
C:\WINDOWS\system32\xpsp2res.dll
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\gdiplus.dll

[C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (18)]
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\CLBCATQ.DLL
C:\WINDOWS\system32\comctl32.dll
C:\WINDOWS\system32\COMRes.dll
C:\WINDOWS\system32\GDI32.dll
C:\WINDOWS\system32\kernel32.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\ntdll.dll
C:\WINDOWS\system32\ole32.dll
C:\WINDOWS\system32\OLEAUT32.dll
C:\WINDOWS\system32\psapi.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\SHLWAPI.dll
C:\WINDOWS\system32\USER32.dll
C:\WINDOWS\system32\VERSION.dll
C:\WINDOWS\system32\xpsp2res.dll
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

[C:\Program Files\Internet Explorer\IEXPLORE.EXE (102)]
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
C:\Program Files\Common Files\Microsoft Shared\INK\SKCHUI.DLL
C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSXML5.DLL
C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\mtbres.dll
C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
C:\WINDOWS\IME\SPGRMR.DLL
C:\WINDOWS\ime\sptip.dll
C:\WINDOWS\system32\actxprxy.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\appHelp.dll
C:\WINDOWS\system32\ATL.DLL
C:\WINDOWS\system32\browselc.dll
C:\WINDOWS\system32\BROWSEUI.dll
C:\WINDOWS\system32\CLBCATQ.DLL
C:\WINDOWS\system32\comctl32.dll
C:\WINDOWS\system32\comdlg32.dll
C:\WINDOWS\system32\COMRes.dll
C:\WINDOWS\system32\CRYPT32.dll
C:\WINDOWS\system32\CRYPTUI.dll
C:\WINDOWS\System32\CSCDLL.dll
C:\WINDOWS\System32\cscui.dll
C:\WINDOWS\system32\DCIMAN32.dll
C:\WINDOWS\system32\DDRAW.dll
C:\WINDOWS\system32\ddrawex.dll
C:\WINDOWS\system32\DNSAPI.dll
C:\WINDOWS\system32\dxtrans.dll
C:\WINDOWS\system32\GDI32.dll
C:\WINDOWS\system32\hnetcfg.dll
C:\WINDOWS\system32\iepeers.dll
C:\WINDOWS\system32\IMAGEHLP.dll
C:\WINDOWS\system32\ImgUtil.dll
C:\WINDOWS\system32\iphlpapi.dll
C:\WINDOWS\system32\jscript.dll
C:\WINDOWS\system32\kernel32.dll
C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx
C:\WINDOWS\system32\midimap.dll
C:\WINDOWS\system32\mlang.dll
C:\WINDOWS\system32\MSACM32.dll
C:\WINDOWS\system32\msacm32.drv
C:\WINDOWS\system32\MSASN1.dll
C:\WINDOWS\system32\MSCTF.dll
C:\WINDOWS\system32\mshtml.dll
C:\WINDOWS\system32\mshtmled.dll
C:\WINDOWS\system32\msi.dll
C:\WINDOWS\system32\msimtf.dll
C:\WINDOWS\system32\mslbui.dll
C:\WINDOWS\system32\msls31.dll
C:\WINDOWS\system32\msv1_0.dll
C:\WINDOWS\system32\MSVCP60.dll
C:\WINDOWS\system32\MSVCR71.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\msxml3.dll
C:\WINDOWS\system32\NETAPI32.dll
C:\WINDOWS\system32\ntdll.dll
C:\WINDOWS\system32\ole32.dll
C:\WINDOWS\system32\OLEACC.dll
C:\WINDOWS\system32\OLEAUT32.dll
C:\WINDOWS\system32\olepro32.dll
C:\WINDOWS\system32\pngfilt.dll
C:\WINDOWS\system32\PSAPI.DLL
C:\WINDOWS\system32\PSTOREC.DLL
C:\WINDOWS\system32\rasadhlp.dll
C:\WINDOWS\system32\RASAPI32.DLL
C:\WINDOWS\system32\rasman.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\rtutils.dll
C:\WINDOWS\system32\schannel.dll
C:\WINDOWS\system32\Secur32.dll
C:\WINDOWS\system32\SensApi.dll
C:\WINDOWS\system32\SETUPAPI.dll
C:\WINDOWS\system32\sfc_os.dll
C:\WINDOWS\system32\shdoclc.dll
C:\WINDOWS\system32\SHDOCVW.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\SHLWAPI.dll
C:\WINDOWS\system32\SXS.DLL
C:\WINDOWS\system32\TAPI32.dll
C:\WINDOWS\system32\urlmon.dll
C:\WINDOWS\system32\USER32.dll
C:\WINDOWS\system32\USERENV.dll
C:\WINDOWS\system32\uxtheme.dll
C:\WINDOWS\system32\VERSION.dll
C:\WINDOWS\system32\wdmaud.drv
C:\WINDOWS\system32\WINHTTP.dll
C:\WINDOWS\system32\WININET.dll
C:\WINDOWS\system32\WINMM.dll
C:\WINDOWS\System32\winrnr.dll
C:\WINDOWS\system32\WINSPOOL.DRV
C:\WINDOWS\system32\WINTRUST.dll
C:\WINDOWS\system32\WLDAP32.dll
C:\WINDOWS\system32\WS2_32.dll
C:\WINDOWS\system32\WS2HELP.dll
C:\WINDOWS\System32\wshtcpip.dll
C:\WINDOWS\system32\wsock32.dll
C:\WINDOWS\system32\wuapi.dll
C:\WINDOWS\system32\xpsp2res.dll
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

[C:\Program Files\Mozilla Firefox\firefox.exe (78)]
C:\PROGRA~1\MOZILL~1\nssckbi.dll
C:\Program Files\Mozilla Firefox\components\jar50.dll
C:\Program Files\Mozilla Firefox\js3250.dll
C:\Program Files\Mozilla Firefox\nspr4.dll
C:\Program Files\Mozilla Firefox\nss3.dll
C:\Program Files\Mozilla Firefox\plc4.dll
C:\Program Files\Mozilla Firefox\plds4.dll
C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
C:\Program Files\Mozilla Firefox\smime3.dll
C:\Program Files\Mozilla Firefox\softokn3.dll
C:\Program Files\Mozilla Firefox\ssl3.dll
C:\Program Files\Mozilla Firefox\xpcom_compat.dll
C:\Program Files\Mozilla Firefox\xpcom_core.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\CLBCATQ.DLL
C:\WINDOWS\system32\comdlg32.dll
C:\WINDOWS\system32\COMRes.dll
C:\WINDOWS\system32\CRYPT32.dll
C:\WINDOWS\system32\D3DIM700.DLL
C:\WINDOWS\system32\DCIMAN32.dll
C:\WINDOWS\system32\DDRAW.DLL
C:\WINDOWS\system32\DNSAPI.dll
C:\WINDOWS\system32\DSOUND.dll
C:\WINDOWS\system32\GDI32.dll
C:\WINDOWS\system32\hnetcfg.dll
C:\WINDOWS\system32\IMAGEHLP.dll
C:\WINDOWS\system32\IMM32.DLL
C:\WINDOWS\system32\iphlpapi.dll
C:\WINDOWS\system32\kernel32.dll
C:\WINDOWS\system32\Macromed\Common\SwSupport.dll
C:\WINDOWS\system32\midimap.dll
C:\WINDOWS\system32\mlang.dll
C:\WINDOWS\system32\MSACM32.dll
C:\WINDOWS\system32\msacm32.drv
C:\WINDOWS\system32\MSASN1.dll
C:\WINDOWS\system32\MSCTF.dll
C:\WINDOWS\system32\msimg32.dll
C:\WINDOWS\system32\msimtf.dll
C:\WINDOWS\system32\mslbui.dll
C:\WINDOWS\system32\msv1_0.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\NETAPI32.dll
C:\WINDOWS\system32\ntdll.dll
C:\WINDOWS\system32\ole32.dll
C:\WINDOWS\system32\OLEAUT32.dll
C:\WINDOWS\system32\rasadhlp.dll
C:\WINDOWS\system32\RASAPI32.DLL
C:\WINDOWS\system32\rasman.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\rtutils.dll
C:\WINDOWS\system32\Secur32.dll
C:\WINDOWS\system32\sensapi.dll
C:\WINDOWS\system32\SETUPAPI.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\SHLWAPI.dll
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\hpz2ku10.dll
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\hpzpm310.dll
C:\WINDOWS\system32\TAPI32.dll
C:\WINDOWS\system32\urlmon.dll
C:\WINDOWS\system32\USER32.dll
C:\WINDOWS\system32\USERENV.dll
C:\WINDOWS\system32\uxtheme.dll
C:\WINDOWS\system32\VERSION.dll
C:\WINDOWS\system32\wdmaud.drv
C:\WINDOWS\system32\WININET.dll
C:\WINDOWS\system32\WINMM.dll
C:\WINDOWS\System32\winrnr.dll
C:\WINDOWS\system32\WINSPOOL.DRV
C:\WINDOWS\system32\WINTRUST.dll
C:\WINDOWS\system32\WLDAP32.dll
C:\WINDOWS\system32\WS2_32.dll
C:\WINDOWS\system32\WS2HELP.dll
C:\WINDOWS\System32\wshtcpip.dll
C:\WINDOWS\system32\WSOCK32.dll
C:\WINDOWS\system32\xpsp2res.dll
C:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\COMCTL32.dll

[C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe (36)]
C:\PROGRA~1\TRENDM~1\INTERN~1\PccAltUi.dll
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlPS.dll
C:\Program Files\Trend Micro\Internet Security 2006\tmdbg.dll
C:\Program Files\Trend Micro\Internet Security 2006\TmProxy.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\Apphelp.dll
C:\WINDOWS\system32\CLBCATQ.DLL
C:\WINDOWS\system32\comdlg32.dll
C:\WINDOWS\system32\COMRes.dll
C:\WINDOWS\system32\GDI32.dll
C:\WINDOWS\system32\kernel32.dll
C:\WINDOWS\system32\MSCTF.dll
C:\WINDOWS\system32\mslbui.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\MSVFW32.dll
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\NETAPI32.dll
C:\WINDOWS\system32\ntdll.dll
C:\WINDOWS\system32\ole32.dll
C:\WINDOWS\system32\OLEAUT32.dll
C:\WINDOWS\system32\oledlg.dll
C:\WINDOWS\system32\OLEPRO32.DLL
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\Secur32.dll
C:\WINDOWS\system32\SETUPAPI.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\SHLWAPI.dll
C:\WINDOWS\system32\USER32.dll
C:\WINDOWS\system32\uxtheme.dll
C:\WINDOWS\system32\VERSION.dll
C:\WINDOWS\system32\WINMM.dll
C:\WINDOWS\system32\WINSPOOL.DRV
C:\WINDOWS\system32\WS2_32.dll
C:\WINDOWS\system32\WS2HELP.dll
C:\WINDOWS\system32\xpsp2res.dll
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\COMCTL32.dll

[C:\WINDOWS\Explorer.EXE (84)]
C:\WINDOWS\AppPatch\AcGenral.DLL
C:\WINDOWS\system32\actxprxy.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\appHelp.dll
C:\WINDOWS\system32\ATL.DLL
C:\WINDOWS\system32\BatMeter.dll
C:\WINDOWS\system32\browselc.dll
C:\WINDOWS\system32\BROWSEUI.dll
C:\WINDOWS\system32\CLBCATQ.DLL
C:\WINDOWS\system32\comctl32.dll
C:\WINDOWS\system32\COMRes.dll
C:\WINDOWS\system32\credui.dll
C:\WINDOWS\system32\CRYPT32.dll
C:\WINDOWS\system32\CRYPTUI.dll
C:\WINDOWS\System32\CSCDLL.dll
C:\WINDOWS\System32\cscui.dll
C:\WINDOWS\System32\davclnt.dll
C:\WINDOWS\System32\drprov.dll
C:\WINDOWS\system32\DUSER.dll
C:\WINDOWS\system32\GDI32.dll
C:\WINDOWS\system32\hnetcfg.dll
C:\WINDOWS\system32\IMAGEHLP.dll
C:\WINDOWS\system32\iphlpapi.dll
C:\WINDOWS\system32\kernel32.dll
C:\WINDOWS\system32\LINKINFO.dll
C:\WINDOWS\system32\midimap.dll
C:\WINDOWS\system32\MPR.dll
C:\WINDOWS\system32\MSACM32.dll
C:\WINDOWS\system32\msacm32.drv
C:\WINDOWS\system32\MSASN1.dll
C:\WINDOWS\system32\MSCTF.dll
C:\WINDOWS\system32\msi.dll
C:\WINDOWS\system32\MSIMG32.dll
C:\WINDOWS\system32\mslbui.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\NETAPI32.dll
C:\WINDOWS\System32\NETRAP.dll
C:\WINDOWS\system32\NETSHELL.dll
C:\WINDOWS\System32\NETUI0.dll
C:\WINDOWS\System32\NETUI1.dll
C:\WINDOWS\system32\ntdll.dll
C:\WINDOWS\System32\ntlanman.dll
C:\WINDOWS\system32\ntshrui.dll
C:\WINDOWS\system32\ole32.dll
C:\WINDOWS\system32\OLEAUT32.dll
C:\WINDOWS\system32\POWRPROF.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\rsaenh.dll
C:\WINDOWS\system32\rtutils.dll
C:\WINDOWS\system32\SAMLIB.dll
C:\WINDOWS\system32\Secur32.dll
C:\WINDOWS\system32\SETUPAPI.dll
C:\WINDOWS\system32\shdoclc.dll
C:\WINDOWS\system32\SHDOCVW.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\ShimEng.dll
C:\WINDOWS\system32\SHLWAPI.dll
C:\WINDOWS\system32\SSDPAPI.dll
C:\WINDOWS\system32\stobject.dll
C:\WINDOWS\system32\SXS.DLL
C:\WINDOWS\system32\themeui.dll
C:\WINDOWS\system32\upnp.dll
C:\WINDOWS\system32\upnpui.dll
C:\WINDOWS\system32\urlmon.dll
C:\WINDOWS\system32\USER32.dll
C:\WINDOWS\system32\USERENV.dll
C:\WINDOWS\system32\UxTheme.dll
C:\WINDOWS\system32\VERSION.dll
C:\WINDOWS\system32\wdmaud.drv
C:\WINDOWS\system32\webcheck.dll
C:\WINDOWS\system32\WINHTTP.dll
C:\WINDOWS\system32\WININET.dll
C:\WINDOWS\system32\WINMM.dll
C:\WINDOWS\system32\WINSTA.dll
C:\WINDOWS\system32\WINTRUST.dll
C:\WINDOWS\system32\WLDAP32.dll
C:\WINDOWS\system32\WS2_32.dll
C:\WINDOWS\system32\WS2HELP.dll
C:\WINDOWS\System32\wshtcpip.dll
C:\WINDOWS\system32\WSOCK32.dll
C:\WINDOWS\system32\WTSAPI32.dll
C:\WINDOWS\system32\xpsp2res.dll
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

[C:\WINDOWS\system32\Ati2evxx.exe (12
  • 0

#10
coachwife6

coachwife6

    SuperStar

  • Retired Staff
  • 11,413 posts
Please disable Spyware Guard and PCDoctor.

Close all programs and all windows, leaving only HijackThis running. Please disconnect from the internet. Place a check mark against each of the following, making sure you get each one and not any others by mistake:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O8 - Extra context menu item: &Search - http://km.bar.need2f...earch.html?p=KM


Click on Fix Checked when finished and exit HijackThis. Reboot and post a new log.
  • 0

Advertisements


#11
sreynaga

sreynaga

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
Ok here is the new hijack this log file, but I do not know how to disable the pcguard and the spy subtract because they were removed from my computer about a month ago...

Logfile of HijackThis v1.99.1
Scan saved at 8:05:08 PM, on 9/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jessica\Desktop\HijackThis.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1155696642571
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} - http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...790/mcfscan.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: GFI LANguard N.S.S. 7.0 Attendant Service - Unknown owner - C:\Program Files\GFI\LANguard Network Security Scanner 7.0\lnssatt.exe" -service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
  • 0

#12
coachwife6

coachwife6

    SuperStar

  • Retired Staff
  • 11,413 posts
Run hijack this again and put check marks next to these:

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present


Reboot and run hijack this again and place a new log in this thread. :whistling:
  • 0

#13
sreynaga

sreynaga

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
ok here is the new log file
Logfile of HijackThis v1.99.1
Scan saved at 11:06:14 PM, on 9/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jessica\Desktop\HijackThis.exe

O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=58813
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1155696642571
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} - http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...790/mcfscan.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: GFI LANguard N.S.S. 7.0 Attendant Service - Unknown owner - C:\Program Files\GFI\LANguard Network Security Scanner 7.0\lnssatt.exe" -service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
  • 0

#14
coachwife6

coachwife6

    SuperStar

  • Retired Staff
  • 11,413 posts
How is it working now?
  • 0

#15
sreynaga

sreynaga

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
It's working just fine thanks so much
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP