Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Win32/Heur + many other virus infections


  • This topic is locked This topic is locked

#1
Jon7

Jon7

    Member

  • Member
  • PipPip
  • 10 posts
Hi!

I'm a bit of a novice at this, so I'll try to be as helpful to you as I can!

Yesterday I encountered a lot of viruses on my laptop; I opened up AVG Anti-Virus and did a scan, found 10 viruses and moved them to the Virus Vault.

Majority of these viruses are: Win32/Heur.

This morning, I rebooted up my laptop (on Windows XP) and my AVG Resident Shield picked up even more viruses - and having read about this Win32/Heur virus I can only assume they were caused by it.

I am totally lost on what to do, I can rescan my computer with AVG but more just seems to pop up later.

Any help would be greatly appreciated!

Thank you
  • 0

Advertisements


#2
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hello Jon7

Welcome to G2Go. :)
=====================
  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.

  • 0

#3
Jon7

Jon7

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Thank you, thank you so much for taking the time to help me kahdah!

I was starting to panic a bit because AVG and Sophos keep telling me every now and then more they've discovered more problems!

Here are the results of the scans:

OTListIt.Txt

OTListIt logfile created on: 4/10/2009 1:37:18 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.12.2 Folder = C:\Documents and Settings\Hong Zhu\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.06 Gb Available Physical Memory | 53.15% Memory free
2.60 Gb Paging File | 1.71 Gb Available in Paging File | 65.77% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.79 Gb Total Space | 16.70 Gb Free Space | 11.61% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NOTEBOOKT60
Current User Name: Hong Zhu
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\ibmpmsvc.exe ()
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Plc)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\WINDOWS\system32\IPSSVC.EXE (Lenovo Group Limited)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe ()
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
PRC - C:\WINDOWS\system32\lxctcoms.exe ( )
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Plc)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
PRC - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe (Sophos Plc)
PRC - c:\program files\lenovo\system update\suservice.exe ( )
PRC - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe ()
PRC - C:\WINDOWS\System32\TPHDEXLG.EXE (Lenovo.)
PRC - C:\WINDOWS\system32\TpKmpSVC.exe ()
PRC - C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe (IBM)
PRC - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe (Lenovo Group Limited)
PRC - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe (Lenovo Group Limited)
PRC - C:\Program Files\Common Files\Lenovo\Logger\logmon.exe ()
PRC - C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe ()
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe (Diskeeper Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Program Files\ThinkPad\Utilities\EZEJMNAP.EXE (Lenovo Group Limited)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe ()
PRC - C:\WINDOWS\system32\TpShocks.exe (Lenovo, Ltd. and IBM Corporation.)
PRC - C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe ()
PRC - C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe ()
PRC - C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe (Lenovo Group Limited)
PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\Program Files\ThinkVantage\PrdCtr\LPMGR.EXE (Lenovo Group Limited)
PRC - C:\WINDOWS\System32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Program Files\Lenovo\AwayTask\AwaySch.EXE (Lenovo Group Limited)
PRC - C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe (Lenovo Group Limited)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe ()
PRC - C:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.)
PRC - C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe (Utimaco Safeware AG)
PRC - C:\Program Files\Lenovo\Client Security Solution\cssauth.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lexmark 5400 Series\lxctmon.exe ()
PRC - C:\Program Files\Lexmark 5400 Series\ezprint.exe (Lexmark International Inc.)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\WINDOWS\system32\SafeSignCertReg.exe (A.E.T. Europe B.V.)
PRC - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\kdx\KHost.exe (Kontiki Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
PRC - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB)
PRC - C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Plc)
PRC - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files\ThinkPad\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Documents and Settings\Hong Zhu\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aawservice [Auto | Running]) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (AcPrfMgrSvc [Auto | Running]) -- C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe ()
SRV - (AcSvc [Auto | Running]) -- C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo)
SRV - (afisicx [Auto | Stopped]) -- C:\WINDOWS\system32\afisicx.exe ()
SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (avg8emc [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (btwdins [Auto | Running]) -- C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Diskeeper [Auto | Running]) -- C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
SRV - (EvtEng [Auto | Running]) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Running]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IBMPMSVC [Auto | Running]) -- C:\WINDOWS\system32\ibmpmsvc.exe ()
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (IPSSVC [Auto | Running]) -- C:\WINDOWS\system32\IPSSVC.EXE (Lenovo Group Limited)
SRV - (Irmon [Auto | Running]) -- C:\WINDOWS\System32\irmon.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KService [Auto | Running]) -- C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (lxct_device [Auto | Running]) -- C:\WINDOWS\system32\lxctcoms.exe ( )
SRV - (MDM [Auto | Running]) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PsaSrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\PsaSrv.exe ()
SRV - (RegSrvc [Auto | Running]) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (S24EventMonitor [Auto | Running]) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (SAVAdminService [Auto | Running]) -- C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Plc)
SRV - (SAVService [Auto | Running]) -- C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Plc)
SRV - (SeaPort [Auto | Running]) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
SRV - (Sophos AutoUpdate Service [Auto | Running]) -- C:\Program Files\Sophos\AutoUpdate\ALsvc.exe (Sophos Plc)
SRV - (SUService [Auto | Running]) -- c:\program files\lenovo\system update\suservice.exe ( )
SRV - (ThinkVantage Registry Monitor Service [Auto | Running]) -- C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe ()
SRV - (TPHDEXLGSVC [Auto | Running]) -- C:\WINDOWS\System32\TPHDEXLG.EXE (Lenovo.)
SRV - (TpKmpSVC [Auto | Running]) -- C:\WINDOWS\system32\TpKmpSVC.exe ()
SRV - (TSSCoreService [Auto | Running]) -- C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe (IBM)
SRV - (TVT Backup Service [Auto | Running]) -- C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe (Lenovo Group Limited)
SRV - (TVT Scheduler [Auto | Running]) -- C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe (Lenovo Group Limited)
SRV - (tvtnetwk [Auto | Running]) -- C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe ()
SRV - (WMPNetworkSvc [Auto | Running]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (a016bus [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\a016bus.sys (MCCI Corporation)
DRV - (a016mdfl [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\a016mdfl.sys (MCCI Corporation)
DRV - (a016mdm [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\a016mdm.sys (MCCI Corporation)
DRV - (a016mgmt [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\a016mgmt.sys (MCCI Corporation)
DRV - (a016obex [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\a016obex.sys (MCCI Corporation)
DRV - (ADIHdAudAddService [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (AEAudioService [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\AEAudio.sys (Andrea Electronics Corporation)
DRV - (AegisP [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\AegisP.sys (Meetinghouse Data Communications)
DRV - (AliIde [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (ANC [System | Running]) -- C:\WINDOWS\System32\drivers\ANC.SYS (IBM Corp.)
DRV - (asc [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ati2mtag [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (atmeltpm [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\atmeltpm.sys (Atmel, Inc.)
DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (btaudio [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTDriver [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\btport.sys (Broadcom Corporation.)
DRV - (BTKRNL [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWDNDIS [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\btwdndis.sys (Broadcom Corporation.)
DRV - (BTWUSB [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\btwusb.sys (Broadcom Corporation.)
DRV - (CMB8100 [Auto | Running]) -- C:\WINDOWS\system32\Drivers\CertClient.dat ()
DRV - (CMBProtector [Auto | Running]) -- C:\WINDOWS\system32\Drivers\CMBProtector.dat ()
DRV - (CmdIde [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DLABOIOM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLACDBHM [System | Running]) -- C:\WINDOWS\System32\Drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLADResN [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLAIFS_M [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLAOPIOM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLARTL_N [System | Running]) -- C:\WINDOWS\System32\Drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (DLAUDFAM [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M [Auto | Running]) -- C:\WINDOWS\System32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DRVMCDB [Boot | Running]) -- C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (DRVNDDM [Auto | Running]) -- C:\WINDOWS\System32\Drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (E100B [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (e1express [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\e1e5132.sys (Intel Corporation)
DRV - (EGATHDRV [Auto | Running]) -- C:\WINDOWS\SYSTEM32\EGATHDRV.SYS (IBM Corporation)
DRV - (ft2kEnum [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ic2kenum.sys (OEM Corporation)
DRV - (G400 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\G400m.sys (Matrox Graphics Inc.)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (hamachi [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\hamachi.sys (LogMeIn, Inc.)
DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSF_DPV [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\hsx_dpv.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\hsxhwazl.sys (Conexant Systems, Inc.)
DRV - (iaStor [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (IBMPMDRV [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys (Lenovo.)
DRV - (IBMTPCHK [System | Running]) -- C:\WINDOWS\system32\Drivers\IBMBLDID.sys ()
DRV - (Iviaspi [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\iviaspi.sys (InterVideo, Inc.)
DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (mraid35x [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (NETw3x32 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\NETw3x32.sys (Intel® Corporation)
DRV - (NSCIRDA [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\nscirda.sys (National Semiconductor Corporation)
DRV - (pmem [Auto | Running]) -- C:\WINDOWS\System32\drivers\pmemnt.sys (Microsoft Corporation)
DRV - (PrivateDisk [Auto | Running]) -- C:\Program Files\Lenovo\SafeGuard PrivateDisk\PrivateDiskM.sys (Utimaco Safeware AG)
DRV - (PROCDD [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\PROCDD.SYS (Lenovo Group Limited)
DRV - (psadd [On_Demand | Stopped]) -- C:\WINDOWS\system32\Drivers\psadd.sys (Lenovo)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (Reader_Device [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\usbic2k.sys (OEM)
DRV - (s24trans [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\s24trans.sys (Intel Corporation)
DRV - (SAVOnAccessControl [System | Running]) -- C:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys (Sophos Plc)
DRV - (SAVOnAccessFilter [System | Running]) -- C:\WINDOWS\system32\DRIVERS\savonaccessfilter.sys (Sophos Plc)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (ShockMgr [System | Running]) -- C:\WINDOWS\System32\drivers\ShockMgr.sys (Lenovo.)
DRV - (Shockprf [Boot | Running]) -- C:\WINDOWS\System32\drivers\shockprf.sys (Lenovo)
DRV - (sisagp [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Smapint [System | Running]) -- C:\WINDOWS\System32\drivers\Smapint.sys (Microsoft Corporation)
DRV - (smi2 [Auto | Running]) -- C:\Program Files\SMI2\smi2.sys (IBM Corp.)
DRV - (smihlp [Auto | Running]) -- C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys (UPEK Inc.)
DRV - (SophosBootDriver [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\SophosBootDriver.sys (Sophos Plc)
DRV - (Sparrow [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sptd [Boot | Running]) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (symc810 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (SynTP [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (TcUsb [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\tcusb.sys (UPEK Inc.)
DRV - (TDSMAPI [System | Running]) -- C:\WINDOWS\System32\drivers\TDSMAPI.SYS ()
DRV - (token [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\eps2kt1.sys ()
DRV - (TPHKDRV [System | Running]) -- C:\WINDOWS\System32\drivers\TPHKDRV.sys (IBM Corporation)
DRV - (TPPWRIF [System | Running]) -- C:\WINDOWS\System32\drivers\Tppwrif.sys ()
DRV - (TSMAPIP [System | Running]) -- C:\WINDOWS\System32\drivers\TSMAPIP.SYS ()
DRV - (tvtfilter [Auto | Running]) -- C:\WINDOWS\system32\drivers\tvtfilter.sys (Lenovo)
DRV - (TVTPktFilter [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\tvtpktfilter.sys (Lenovo Group Limited)
DRV - (ultra [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (V0250Dev [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\V0250Dev.sys (Creative Technology Ltd.)
DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\hsx_cnxt.sys (Conexant Systems, Inc.)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SE...S01?FORM=TOOLBR
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...m...tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2009/02/12 19:01:48 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008/11/30 23:12:41 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/29 11:18:19 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/29 11:18:19 | 00,000,000 | ---D | M]

[2009/03/28 17:56:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\mozilla\Extensions
[2009/03/28 17:56:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2007/08/07 14:02:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\mozilla\Firefox\Profiles\8r6dv5bl.default\extensions
[2007/08/07 14:02:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\mozilla\Firefox\Profiles\8r6dv5bl.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2008/06/10 23:56:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\mozilla\Firefox\Profiles\m0spy3uc.default\extensions
[2009/04/10 01:09:33 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/03/29 11:18:19 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/08/02 14:58:08 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2008/11/30 23:13:01 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2009/01/01 22:54:53 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/03/29 11:18:13 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/29 11:18:13 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/07/12 09:53:16 | 00,053,248 | ---- | M] (Thunder Networking Technologies,LTD) -- C:\Program Files\mozilla firefox\components\ThunderComponent.dll
[2008/10/24 16:12:52 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/10/24 16:12:52 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/10/24 16:12:52 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/14 00:32:34 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/10/24 16:12:52 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/10/24 16:12:52 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/10/24 16:12:52 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (750 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 jL.chura.pl
O1 - Hosts: 127.0.0.1 www.virustotal.com
O1 - Hosts: 127.0.0.1 virustotal
O1 - Hosts: 127.0.0.1 virscan.com
O1 - Hosts: 127.0.0.1 www.virscan.com
O1 - Hosts: 127.0.0.1 virscan
O1 - Hosts: 127.0.0.1 http://virscan.com
O1 - Hosts: 127.0.0.1 virustotal
O1 - Hosts: 127.0.0.1 virscan
O1 - Hosts: 127.0.0.1 http://virusscan.jotti.org/
O1 - Hosts: 127.0.0.1 virusscan.jotti.org/
O1 - Hosts: 127.0.0.1 www.virusscan.jotti.org/
O1 - Hosts: 127.0.0.1 scanner.novirusthanks.org/
O1 - Hosts: 127.0.0.1 http://scanner.novirusthanks.org/
O1 - Hosts: 127.0.0.1 www.scanner.novirusthanks.org/
O2 - BHO: (C:\WINDOWS\system32\ds43g4nfjkn93.dll) - {D5BF49A0-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\ds43g4nfjkn93.dll ()
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Veoh Browser Plug-in) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" (Adobe Systems Inc.)
O4 - HKLM..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe ()
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" ()
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog ()
O4 - HKLM..\Run: [CertificateRegistration] SafeSignCertReg.exe (A.E.T. Europe B.V.)
O4 - HKLM..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent (Lenovo Group Limited)
O4 - HKLM..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" (Diskeeper Corporation)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe (Lenovo Group Limited)
O4 - HKLM..\Run: [EzPrint] "C:\Program Files\Lexmark 5400 Series\ezprint.exe" (Lexmark International Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 (Microsoft Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start (InstallShield Software Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Lexmark 5400 Series Fax Server] "C:\Program Files\Lexmark 5400 Series\fm3032.exe" /s ()
O4 - HKLM..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [LXCTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16 (Lexmark International Inc.)
O4 - HKLM..\Run: [lxctmon.exe] "C:\Program Files\Lexmark 5400 Series\lxctmon.exe" ()
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC ()
O4 - HKLM..\Run: [PDService.exe] "C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe" (Utimaco Safeware AG)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC (Microsoft Corporation)
O4 - HKLM..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.)
O4 - HKLM..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor (Lenovo Group Limited)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [TP4EX] tp4ex.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe ()
O4 - HKLM..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper (Lenovo)
O4 - HKLM..\Run: [TpShocks] TpShocks.exe (Lenovo, Ltd. and IBM Corporation.)
O4 - HKLM..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe (Lenovo Group Limited)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all (Kontiki Inc.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon (Sony Ericsson Mobile Communications AB)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0 File not found
O4 - HKCU..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide File not found
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Plc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm File not found
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O8 - Extra context menu item: ʹÓĂѸÀ×ÏÂÔØ - C:\Program Files\Thunder Network\Thunder\Program\geturl.htm File not found
O8 - Extra context menu item: ʹÓĂѸÀ×ÏÂÔØÈ«²¿Á´½Ó - C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm File not found
O8 - Extra context menu item: ̀í¼Óµ½QQ±íÇé - C:\Program Files\Tencent\QQ\AddEmotion.htm File not found
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra 'Tools' menuitem : ThinkVantage Password Manager... - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: System Update - {DA320635-F48C-4613-8325-D75A933C549E} - C:\Program Files\Lenovo\System Update\sulauncher.exe ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [Tcpip] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [NTDS] - C:\WINDOWS\System32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [Network Location Awareness (NLA) Namespace] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: com.cn ([www.icbc] http in Trusted sites)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.micr.../OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0EB487C8-E9AC-43A6-8C4C-083999B0622F} https://mybank.icbc....certInStall.dll (InfosecCertInstall Class)
O16 - DPF: {3AA9CF07-DF20-48FF-98BE-DED276E40146} https://mybank.icbc....c/GDReadPub.cab (GDGetTokenInfo Class)
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} https://moneymanager...unttracking.cab (Egg Money Manager Digital Safe)
O16 - DPF: {5CB840B5-A94E-4AD9-B785-4866E3B04476} https://mybank.icbc....CBCNetSignG.dll (InfoSecNetSign Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} https://mybank.icbc....afeControls.cab (AxSubmitControl Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zon...ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C35D7AE1-0865-4A30-BF07-29FA29324155} https://mybank.icbc....nk/GDSetLET.cab (CSetLET Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.micros...ntent/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Plc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\ACNotify: DllName - ACNotify.dll - C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll ()
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\AwayNotify: DllName - C:\Program Files\Lenovo\AwayTask\AwayNotify.dll - C:\Program Files\Lenovo\AwayTask\AwayNotify.dll (Lenovo Group Limited)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\System32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\psfus: DllName - psqlpwd.dll - C:\WINDOWS\system32\psqlpwd.dll (UPEK Inc.)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\system32\WlNotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\tpfnf2: DllName - notifyf2.dll - C:\WINDOWS\system32\notifyf2.dll ()
O20 - Winlogon\Notify\tphotkey: DllName - tphklock.dll - C:\WINDOWS\system32\tphklock.dll ()
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {D5BF49A0-94F3-42BD-F434-3604812C8955} - lkjf9873jhifjnsfi8w3fe - C:\WINDOWS\system32\ds43g4nfjkn93.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\System32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - C:\autorun.inf.tmp () - [ NTFS ]
O33 - MountPoints2\{6c9ef72d-4404-11dc-b1d1-001a6b68e736}\Shell - "" = AutoRun
O33 - MountPoints2\{6c9ef72d-4404-11dc-b1d1-001a6b68e736}\Shell\1\Command - "" = .\recycled\info.exe
O33 - MountPoints2\{6c9ef72d-4404-11dc-b1d1-001a6b68e736}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6c9ef72d-4404-11dc-b1d1-001a6b68e736}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\Shell32.DLL -- [2008/06/17 20:02:19 | 08,461,312 | ---- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[12 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/04/10 13:35:44 | 00,521,728 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Hong Zhu\Desktop\OTListIt2.exe
[2009/04/10 11:05:05 | 00,030,208 | ---- | C] () -- C:\jacgl.exe
[2009/04/10 11:04:58 | 00,104,688 | ---- | C] () -- C:\frlnrr.exe
[2009/04/10 00:39:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hong Zhu\Local Settings\Application Data\Sophos
[2009/04/09 21:24:22 | 00,083,968 | ---- | C] () -- C:\WINDOWS\System32\drivers\ovfsthurepocbcxvsiwtxvkswtpebrppavramu.sys
[2009/04/09 21:23:25 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Client Security
[2009/04/09 21:23:21 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Client Security Solution
[2009/04/09 21:22:22 | 00,232,448 | ---- | C] () -- C:\WINDOWS\System32\w.exe
[2009/04/09 21:22:22 | 00,000,008 | ---- | C] () -- C:\WINDOWS\System32\comsa32.sys
[2009/04/09 21:22:17 | 00,015,000 | ---- | C] () -- C:\WINDOWS\System32\ds43g4nfjkn93.dll
[2009/04/09 21:21:51 | 00,102,400 | ---- | C] ( ) -- C:\WINDOWS\instsSD.exe
[2009/04/09 21:21:45 | 00,110,592 | -HS- | C] ( ) -- C:\WINDOWS\61175.exe
[2009/04/09 20:42:10 | 00,507,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAudio2_1.dll
[2009/04/09 20:42:10 | 00,065,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAPOFX1_0.dll
[2009/04/09 20:42:08 | 00,238,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine3_1.dll
[2009/04/09 20:42:01 | 00,025,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\X3DAudio1_4.dll
[2009/04/09 20:41:59 | 01,491,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_38.dll
[2009/04/09 20:41:59 | 00,467,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_38.dll
[2009/04/09 20:41:58 | 03,850,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_38.dll
[2009/04/09 20:41:55 | 00,479,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAudio2_0.dll
[2009/04/09 20:41:53 | 00,238,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine3_0.dll
[2009/04/09 20:41:51 | 00,025,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\X3DAudio1_3.dll
[2009/04/09 20:41:49 | 01,420,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_37.dll
[2009/04/09 20:41:49 | 00,462,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_37.dll
[2009/04/09 20:41:46 | 03,786,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_37.dll
[2009/04/09 20:41:45 | 00,267,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_10.dll
[2009/04/09 20:41:43 | 01,374,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_36.dll
[2009/04/09 20:41:43 | 00,444,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_36.dll
[2009/04/09 20:41:41 | 03,734,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_36.dll
[2009/04/09 20:41:40 | 00,267,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_9.dll
[2009/04/09 20:41:39 | 01,358,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_35.dll
[2009/04/09 20:41:39 | 00,444,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_35.dll
[2009/04/09 20:41:38 | 03,727,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_35.dll
[2009/04/09 20:41:36 | 00,266,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_8.dll
[2009/04/09 20:41:36 | 00,017,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\X3DAudio1_2.dll
[2009/04/09 20:41:35 | 01,124,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_34.dll
[2009/04/09 20:41:35 | 00,443,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_34.dll
[2009/04/09 20:41:34 | 03,497,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_34.dll
[2009/04/09 20:41:32 | 00,081,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_3.dll
[2009/04/09 20:41:24 | 00,261,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_7.dll
[2009/04/09 20:41:20 | 01,123,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_33.dll
[2009/04/09 20:41:20 | 00,443,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_33.dll
[2009/04/09 20:41:07 | 03,495,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_33.dll
[2009/04/09 20:41:05 | 00,255,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_6.dll
[2009/04/09 20:41:04 | 00,251,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_5.dll
[2009/04/09 20:41:02 | 03,426,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_32.dll
[2009/04/09 20:41:00 | 00,237,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_4.dll
[2009/04/09 20:41:00 | 00,015,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\x3daudio1_1.dll
[2009/04/09 20:40:59 | 02,414,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_31.dll
[2009/04/09 20:40:58 | 00,236,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_3.dll
[2009/04/09 20:40:57 | 00,062,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_2.dll
[2009/04/09 20:40:56 | 00,230,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_2.dll
[2009/04/09 20:40:55 | 00,062,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_1.dll
[2009/04/09 20:40:53 | 00,229,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_1.dll
[2009/04/09 20:40:29 | 02,388,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_30.dll
[2009/04/09 20:40:27 | 00,230,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_0.dll
[2009/04/09 20:40:27 | 00,014,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\x3daudio1_0.dll
[2009/04/09 20:40:26 | 02,332,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_29.dll
[2009/04/09 20:40:24 | 02,323,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_28.dll
[2009/04/09 20:40:23 | 00,061,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput9_1_0.dll
[2009/04/09 20:40:22 | 02,319,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_27.dll
[2009/04/09 20:40:21 | 02,297,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_26.dll
[2009/04/09 20:40:19 | 02,337,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_25.dll
[2009/04/09 20:40:12 | 02,222,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_24.dll
[2009/04/09 20:39:05 | 00,000,000 | ---D | C] -- C:\WINDOWS\Logs
[2009/04/09 20:19:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2009/04/06 21:20:13 | 00,000,000 | ---D | C] -- C:\Program Files\Spotify
[2009/03/28 18:10:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hong Zhu\Desktop\Visa Statements
[2009/03/13 22:34:33 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
[2009/03/13 22:32:54 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2009/03/13 22:32:41 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive
[2009/03/13 20:03:30 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
[2008/11/09 20:57:04 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008/08/16 18:09:18 | 00,000,115 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007/09/26 22:53:35 | 00,000,071 | ---- | C] () -- C:\WINDOWS\SCRCFG.ini
[2007/09/12 23:02:38 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\GDReadPub.dll
[2007/08/31 13:26:21 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/08/09 00:05:33 | 00,019,200 | ---- | C] () -- C:\WINDOWS\System32\drivers\eps2kt1.sys
[2007/08/09 00:05:33 | 00,004,608 | ---- | C] () -- C:\WINDOWS\System32\ft2kco.dll
[2007/08/08 17:01:24 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxctvs.dll
[2007/08/08 17:01:21 | 00,344,064 | ---- | C] () -- C:\WINDOWS\System32\lxctcoin.dll
[2007/08/08 17:00:54 | 00,692,224 | ---- | C] () -- C:\WINDOWS\System32\lxctdrs.dll
[2007/08/08 17:00:54 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\lxctcaps.dll
[2007/08/08 17:00:54 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\lxctcnv4.dll
[2007/08/08 17:00:32 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\lxctpmon.dll
[2007/08/08 17:00:32 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\LXCTFXPU.DLL
[2007/08/08 16:57:25 | 00,274,432 | ---- | C] () -- C:\WINDOWS\System32\LXCTinst.dll
[2007/08/08 16:57:24 | 00,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctinpa.dll
[2007/08/08 16:57:24 | 00,323,584 | ---- | C] ( ) -- C:\WINDOWS\System32\LXCThcp.dll
[2007/08/08 16:57:23 | 00,991,232 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctusb1.dll
[2007/08/08 16:57:23 | 00,397,312 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctiesc.dll
[2007/08/08 16:57:22 | 01,224,704 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctserv.dll
[2007/08/08 16:57:21 | 00,643,072 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctpmui.dll
[2007/08/08 16:57:21 | 00,585,728 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctlmpm.dll
[2007/08/08 16:57:21 | 00,163,840 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctprox.dll
[2007/08/08 16:57:21 | 00,094,208 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctpplc.dll
[2007/08/08 16:57:19 | 00,696,320 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcthbn3.dll
[2007/08/08 16:57:19 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\lxctgrd.dll
[2007/08/08 16:57:17 | 00,684,032 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctcomc.dll
[2007/08/08 16:57:17 | 00,421,888 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctcomm.dll
[2007/08/06 14:49:00 | 00,364,544 | ---- | C] () -- C:\WINDOWS\System32\CMBEdit.dll
[2007/08/06 14:48:57 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\PBHttpComm.dll
[2007/08/06 14:48:57 | 00,094,208 | ---- | C] () -- C:\WINDOWS\System32\CmbSafeBase.dll
[2007/07/31 21:57:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2007/06/26 10:59:11 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2007/06/26 10:34:08 | 00,006,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\IBMBLDID.sys
[2007/06/26 10:25:27 | 00,000,156 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2007/06/26 10:23:42 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2007/06/26 10:23:42 | 00,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2007/06/26 10:23:42 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2007/06/26 10:23:42 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2007/06/26 10:23:42 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2007/06/26 10:23:42 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2007/06/26 10:15:01 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\FPCALL.dll
[2007/06/26 10:13:55 | 00,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\TSMAPIP.SYS
[2007/06/26 10:12:22 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\SynTPCoI.dll
[2007/06/26 10:12:09 | 00,004,442 | ---- | C] () -- C:\WINDOWS\System32\drivers\TPPWRIF.SYS
[2007/06/26 10:11:56 | 00,009,343 | ---- | C] () -- C:\WINDOWS\System32\drivers\TDSMAPI.SYS
[2007/03/05 13:34:28 | 00,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2006/08/17 09:00:13 | 00,009,930 | ---- | C] () -- C:\WINDOWS\System32\PROCDB.INI
[2006/08/17 09:00:09 | 00,000,487 | ---- | C] () -- C:\WINDOWS\System32\IPSCTRL.INI
[2006/08/03 02:27:54 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\tphklock.dll
[2006/08/03 02:27:52 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\notifyf2.dll
[2006/06/14 17:26:54 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2006/06/12 20:27:00 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\DEVMAN.DLL
[2006/05/31 22:37:38 | 00,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2006/04/30 07:05:41 | 00,004,670 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/04/30 06:48:13 | 00,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2006/04/30 06:11:22 | 00,000,624 | ---- | C] () -- C:\WINDOWS\win.ini
[2006/04/30 06:11:18 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[2005/02/17 20:41:32 | 00,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005/02/17 20:41:30 | 00,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2003/01/07 15:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/11/14 21:56:00 | 01,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[1997/06/14 03:56:08 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[12 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/04/10 13:35:50 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Hong Zhu\Desktop\OTListIt2.exe
[2009/04/10 13:26:13 | 00,000,934 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-765243075-2163651610-3221528316-1017.job
[2009/04/10 11:14:37 | 00,009,930 | ---- | M] () -- C:\WINDOWS\System32\PROCDB.INI
[2009/04/10 11:14:27 | 00,000,300 | ---- | M] () -- C:\WINDOWS\tasks\PMTask.job
[2009/04/10 11:12:45 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/04/10 11:12:23 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/04/10 11:12:21 | 21,458,32960 | -HS- | M] () -- C:\hiberfil.sys
[2009/04/10 11:05:06 | 00,030,208 | ---- | M] () -- C:\jacgl.exe
[2009/04/10 11:05:00 | 00,104,688 | ---- | M] () -- C:\frlnrr.exe
[2009/04/10 11:04:52 | 00,102,400 | ---- | M] ( ) -- C:\WINDOWS\instsSD.exe
[2009/04/10 11:04:35 | 00,110,592 | -HS- | M] ( ) -- C:\WINDOWS\61175.exe
[2009/04/09 23:01:01 | 35,007,839 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/04/09 23:01:01 | 00,092,925 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/04/09 21:24:22 | 00,083,968 | ---- | M] () -- C:\WINDOWS\System32\drivers\ovfsthurepocbcxvsiwtxvkswtpebrppavramu.sys
[2009/04/09 21:22:17 | 00,015,000 | ---- | M] () -- C:\WINDOWS\System32\ds43g4nfjkn93.dll
[2009/04/09 21:17:14 | 00,409,800 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/04/09 21:17:14 | 00,064,774 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/04/09 21:17:13 | 00,481,674 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/09 18:57:04 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/09 05:41:50 | 00,232,448 | ---- | M] () -- C:\WINDOWS\System32\w.exe
[2009/04/06 21:47:05 | 00,000,008 | ---- | M] () -- C:\WINDOWS\System32\comsa32.sys
[2009/03/11 18:32:46 | 00,330,920 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/11 15:47:09 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK

========== LOP Check ==========

[2009/04/09 20:19:12 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2008/11/27 20:32:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2007/08/08 17:00:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\5400 Series
[2008/12/19 15:19:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2008/05/19 10:22:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple
[2008/05/19 10:23:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/02/05 23:25:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg8
[2008/10/28 13:27:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2008/08/10 23:33:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2009/03/28 17:57:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google
[2007/06/26 10:25:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallShield
[2007/06/26 10:13:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intel
[2009/04/10 13:38:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kontiki
[2008/06/20 18:35:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2007/06/26 10:23:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Lenovo
[2009/03/13 22:34:25 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/10/15 23:16:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2007/08/31 14:36:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2008/01/10 20:12:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Quark
[2007/06/26 09:51:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBSI
[2008/09/05 22:32:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype
[2008/10/28 13:25:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sony Ericsson
[2007/08/07 13:42:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sophos
[2009/04/09 20:20:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2007/10/15 23:30:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Symantec
[2008/07/16 09:02:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Thunder Network
[2007/06/26 10:07:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/05/02 22:38:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WLInstaller
[2008/08/07 17:44:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\yahoo!
[2009/02/09 15:34:37 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Hong Zhu\Application Data
[2007/08/08 17:09:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\5400 Series
[2008/03/02 21:51:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Adobe
[2007/08/07 14:02:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\AdobeAUM
[2007/08/08 18:01:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\AdobeUM
[2008/07/06 09:45:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Apple Computer
[2007/06/26 10:19:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\ATI
[2009/02/09 15:34:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\DAEMON Tools
[2007/08/06 15:27:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Design Science
[2007/10/24 17:57:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Google
[2007/08/06 15:27:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Help
[2007/06/26 09:51:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Identities
[2007/10/23 23:52:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Kontiki
[2008/01/13 20:51:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Leadertech
[2007/08/06 15:50:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Lenovo
[2007/08/06 14:44:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Macromedia
[2009/03/28 17:57:41 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Microsoft
[2009/03/28 17:56:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Mozilla
[2007/08/31 14:48:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\OfficeUpdate12
[2007/09/26 23:26:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\QQ
[2008/01/10 20:37:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Quark
[2008/03/02 21:53:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Real
[2007/08/07 14:02:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Sun
[2007/06/26 10:28:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Symantec
[2007/09/26 22:53:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\Tencent
[2007/06/26 10:44:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\ThinkVantage
[2007/08/07 14:02:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\WinEdt
[2007/08/03 20:17:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Hong Zhu\Application Data\WinRAR
[2009/04/09 18:57:04 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 13:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/04/10 13:26:13 | 00,000,934 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-765243075-2163651610-3221528316-1017.job
[2009/04/10 11:14:27 | 00,000,300 | ---- | M] () -- C:\WINDOWS\Tasks\PMTask.job
[2009/04/10 11:12:45 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >
  • 0

#4
Jon7

Jon7

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Extras.txt

OTListIt Extras logfile created on: 4/10/2009 1:37:18 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.12.2 Folder = C:\Documents and Settings\Hong Zhu\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.06 Gb Available Physical Memory | 53.15% Memory free
2.60 Gb Paging File | 1.71 Gb Available in Paging File | 65.77% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.79 Gb Total Space | 16.70 Gb Free Space | 11.61% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NOTEBOOKT60
Current User Name: Hong Zhu
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.txt [@ = txtfile] -- C:\WINDOWS\notepad.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
"EnableFirewall" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"24930:TCP" = 24930:TCP:*:Enabled:BitComet 24930 TCP
"24930:UDP" = 24930:UDP:*:Enabled:BitComet 24930 UDP
"135:TCP" = 135:TCP:*:Enabled:TCP Port 135
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"26898:TCP" = 26898:TCP:*:Enabled:BitComet 26898 TCP
"26898:UDP" = 26898:UDP:*:Enabled:BitComet 26898 UDP
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"5000:TCP" = 5000:TCP:*:Enabled:TCP Port 5000
"5001:TCP" = 5001:TCP:*:Enabled:TCP Port 5001
"5002:TCP" = 5002:TCP:*:Enabled:TCP Port 5002
"5003:TCP" = 5003:TCP:*:Enabled:TCP Port 5003
"5004:TCP" = 5004:TCP:*:Enabled:TCP Port 5004
"5005:TCP" = 5005:TCP:*:Enabled:TCP Port 5005
"5006:TCP" = 5006:TCP:*:Enabled:TCP Port 5006
"5007:TCP" = 5007:TCP:*:Enabled:TCP Port 5007
"5008:TCP" = 5008:TCP:*:Enabled:TCP Port 5008
"5009:TCP" = 5009:TCP:*:Enabled:TCP Port 5009
"5010:TCP" = 5010:TCP:*:Enabled:TCP Port 5010
"5011:TCP" = 5011:TCP:*:Enabled:TCP Port 5011
"5012:TCP" = 5012:TCP:*:Enabled:TCP Port 5012
"5013:TCP" = 5013:TCP:*:Enabled:TCP Port 5013
"5014:TCP" = 5014:TCP:*:Enabled:TCP Port 5014
"5015:TCP" = 5015:TCP:*:Enabled:TCP Port 5015
"5016:TCP" = 5016:TCP:*:Enabled:TCP Port 5016
"5017:TCP" = 5017:TCP:*:Enabled:TCP Port 5017
"5018:TCP" = 5018:TCP:*:Enabled:TCP Port 5018
"5019:TCP" = 5019:TCP:*:Enabled:TCP Port 5019
"5020:TCP" = 5020:TCP:*:Enabled:TCP Port 5020
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 (Microsoft Corporation)
C:\Program Files\IBM\Updater\jre\bin\java.exe:*:Enabled:IBM Update Connector File not found
C:\Program Files\IBM\Updater\jre\bin\javaw.exe:*:Enabled:IBM Update Connector File not found
C:\Program Files\IBM\Updater\ucsmb.exe:*:Enabled:IBM Update Connector File not found
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 (Microsoft Corporation)
C:\Documents and Settings\Hong Zhu\Local Settings\Temp\java_app_platform_sdk-5_02-windows.exe2\package\jre\bin\javaw.exe:*:Enabled:Java™ Platform SE binary File not found
C:\Documents and Settings\Hong Zhu\Local Settings\Temp\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard File not found
C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client (www.BitComet.com)
C:\Program Files\BitTorrent\btdownloadgui.exe:*:Enabled:BitTorrent File not found
C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk File not found
C:\Program Files\IBM\Updater\jre\bin\java.exe:*:Enabled:IBM Update Connector File not found
C:\Program Files\IBM\Updater\jre\bin\javaw.exe:*:Enabled:IBM Update Connector File not found
C:\Program Files\IBM\Updater\ucsmb.exe:*:Enabled:IBM Update Connector File not found
C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer (Microsoft Corporation)
C:\Program Files\Java\jdk\bin\java.exe:*:Enabled:Java™ Platform SE binary File not found
C:\Program Files\Java\jre1.5.0_11\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary File not found
C:\Program Files\Palm\HOTSYNC.EXE:*:Enabled:HotSync® Manager Application File not found
C:\Program Files\Parasoft\SOAtest\4.5\JRE\1.4.2\bin\javaw.exe:*:Enabled:javaw File not found
C:\Program Files\Yahoo!\Messenger\ypager.exe:*:Enabled:Yahoo! Messenger File not found
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server (Yahoo! Inc.)
C:\WINDOWS\system32\java.exe:*:Enabled:Java launcher (Sun Microsystems, Inc.)
C:\WINDOWS\system32\LEXPPS.EXE:*:Enabled:LEXPPS.EXE File not found
C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard (Microsoft Corporation)
C:\WINDOWS\system32\lxctcoms.exe:*:Enabled:Lexmark Communications System ( )
C:\Documents and Settings\Hong Zhu\Desktop\qqonlineinstall.exe:*:Enabled:QQ???? File not found
C:\Program Files\Tencent\QQ\QQ.exe:*:Enabled:QQ File not found
C:\Program Files\Tencent\QQDownload\QDAutoUpdate.exe:*:Disabled:AutoUpdate Module File not found
C:\Program Files\Tencent\QQDownload\QQDownload.exe:*:Disabled:???? File not found
C:\WINDOWS\kdx\KHost.exe:*:Enabled:Delivery Manager (Kontiki Inc.)
C:\Program Files\KService\KService.exe:*:Enabled:Delivery Manager Service File not found
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client File not found
C:\ijji\ENGLISH\u_goonzu.exe:*:Enabled:<ijji Downloader> File not found
C:\Program Files\Codemasters\RF Online\RF.exe:*:Enabled:RFLauncher File not found
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\Kontiki\KService.exe:*:Enabled:Delivery Manager Service (Kontiki Inc.)
C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\SightSpeed\SightSpeed.exe:*:Enabled:SightSpeed (SightSpeed Inc.)
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)
C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype (Skype Technologies S.A.)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire (Lime Wire, LLC)
C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper (Microsoft Corporation)
C:\Program Files\Microsoft Games\Age of Empires II\EMPIRES2.ICD:*:Enabled:Age of Empires II (Microsoft Corporation)
C:\Program Files\Microsoft Games\Age of Empires II\EMPIRES2.EXE:*:Enabled:Age of Empires II (Microsoft Corporation)
C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\age2_x1.icd:*:Enabled:Age of Empires II Expansion (Microsoft Corporation)
C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC (mIRC Co. Ltd.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
C:\Program Files\Microsoft Games\Age of Empires\EMPIRESX.EXE:*:Enabled:Age of Empires, the Rise of Rome (Microsoft Corporation)
C:\Program Files\Microsoft Games\Age of Empires\EMPIRES.EXE:*:Enabled:Age of Empires (Microsoft Corporation)
C:\Program Files\Participatory Culture Foundation\Miro\xulrunner\python\Miro_Downloader.exe:*:Enabled:Miro_Downloader ()
C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary (Sun Microsystems, Inc.)
C:\Program Files\aMSN\bin\wish.exe:*:Enabled:Wish Application (ActiveState Corporation)
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:*:Disabled:Football Manager 2008 File not found
C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify (Spotify AB)
\??\C:\WINDOWS\system32\winlogon.exe:*:enabled:@shell32.dll,-1 (Microsoft Corporation)
C:\Program Files\Sports Interactive\Football Manager 2009\fm.exe:*:Disabled:Football Manager 2009 File not found

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{034759DA-E21A-4795-BFB3-C66D17FAD183}" = Sophos Anti-Virus
"{0405E51E-9582-4207-8F38-AC44201D3808}" = VeohTV BETA
"{075473F5-846A-448B-BCB3-104AA1760205}" = RecordNow Data
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0B69C194-49D3-4A47-A0F9-BBEEAC28E886}" = 2moons
"{1007F41F-7D69-468E-8017-3849A5A973C2}" = ThinkVantage Technologies Welcome Message
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Toolbar
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1297C681-92D7-40EF-93BF-03F66EC5105C}" = ThinkPad EasyEject Utility
"{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2111B23F-7FDA-4A41-8309-E5A1663CA296}" = ThinkPad Keyboard Customizer Utility
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 11
"{2FFE93F0-BB72-4E52-8761-354D1AAA9387}" = Sony Ericsson PC Suite 4.010.00
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HYDRAVISION
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = ThinkPad Bluetooth with Enhanced Data Rate Software
"{4526E521-18BC-4C01-8563-5CCE47AAC01C}" = ThinkVantage Fingerprint Software 5.5
"{48227AEB-DC8E-4A90-A274-0B4A39D699B1}" = Client Security Solution
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6DA9102E-199F-43A0-A36B-6EF48081A658}" = MobileMe Control Panel
"{72806716-7088-41B2-8FA6-717A2A164DAB}" = ThinkVantage Active Protection System
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{7726CF62-7B45-4E6D-9266-615346816BCA}" = Rescue and Recovery
"{796E076A-82F7-4D49-98C8-DEC0C3BC733A}" = Diskeeper Lite
"{7EB114D8-207F-45AE-BABD-1669715F2630}" = ThinkVantage Access Connections
"{7FC3BBEC-5A91-41B0-9CB8-960EC4421411}" = InterVideo WinDVD Creator 3
"{82512BC9-BD5D-4C50-BE4D-B98E7DF78687}" = ThinkPad UltraNav Wizard
"{8675339C-128C-44DD-83BF-0A5D6ABD8297}" = System Update
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{986F64DC-FF15-449D-998F-EE3BCEC6666A}" = Help Center
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9EA84FDD-CCC0-47FD-A993-923165BEA47A}" = System Migration Assistant
"{A0E64EBA-8BF0-49FB-90C0-BB3D781A2016}" = ThinkPad Power Manager
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A654A805-41D9-40C7-AA46-4AF04F044D61}" = Adobe® Photoshop® Album Starter Edition 3.2
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = RecordNow Audio
"{AC76BA86-1033-0000-7760-000000000003}" = Adobe Acrobat 8 Professional
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{B0862276-5257-11D4-8153-0050041DB5FE}" = SafeSign
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = RecordNow Copy
"{B334D9AE-1393-423E-97C0-3BDC3360E692}" = Sonic Icons for Lenovo
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C031CD16-1112-4133-B8C6-68F9582B3476}" = ATI Catalyst Control Center
"{C54ED2B6-1AF2-416F-BBA8-5E2B8CDCB5C4}" = XP Themes
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C6FA39A7-26B1-480A-BC74-6D17531AC222}" = Access Help
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CF5737AF-8550-4546-A69B-0EA9EF5A9B55}" = ThinkVantage Productivity Center
"{D466F3D9-510C-4729-B7D4-2E70490E4CDF}" = BBC iPlayer Download Manager
"{D728E945-256D-4477-B377-6BBA693714AC}" = Productivity Center Supplement for ThinkPad
"{DA320635-F48C-4613-8325-D75A933C549E}" = ThinkVantage System Update Toolbar Button for IE
"{DB71210F-8314-4AE3-B7A7-EBAF85BD30E9}" = Wallpapers
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E7E836B8-4BDD-454F-82E6-5FEA17C83AD4}" = Message Center
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{EA664480-3844-11D5-8C25-444553540000}" = TrackPoint Accessibility Features
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F958CA02-BB40-4007-894B-258729456EE4}" = QuickTime
"{FC081D4D-DF1B-4CF1-B530-027E4118D846}" = ThinkPad Configuration
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"7-Zip" = 7-Zip 4.42
"AC3Filter" = AC3Filter (remove only)
"Adobe Acrobat 8 Professional" = Adobe Acrobat 8.1.3 Professional
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player
"Adobe® Photoshop® Album Starter Edition 3.2" = Adobe® Photoshop® Album Starter Edition 3.2
"Advanced Video FX Utility" = Advanced Video FX Utility
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires Gold 1.0" = Microsoft Age of Empires Gold
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"All ATI Software" = ATI - Software Uninstall Utility
"aMSN" = aMSN 0.97.2
"ATI Display Driver" = ATI Display Driver
"AVG8Uninstall" = AVG Free 8.0
"AwayTask" = ThinkVantage Away Manager
"BBC iPlayer Download Manager" = BBC iPlayer Download Manager
"BitComet" = BitComet 1.03
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_10140588" = ThinkPad Modem
"Creative Live! Cam Notebook Pro User's Guide English" = Creative Live! Cam Notebook Pro User's Guide (English)
"Creative VF0250" = Creative Live! Cam Notebook Pro Driver (1.01.03.0405)
"Creative WebCam Center" = Creative WebCam Center
"DSMT5" = MathType 5
"Get Yahoo! Messenger" = Get Yahoo! Messenger
"GPL Ghostscript 8.60" = GPL Ghostscript 8.60
"GPL Ghostscript Fonts" = GPL Ghostscript Fonts
"GSview 4.8" = GSview 4.8
"Hamachi" = Hamachi 1.0.3.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Lexmark 5400 Series" = Lexmark 5400 Series
"LimeWire" = LimeWire 4.18.8
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"mIRC" = mIRC
"Miro" = Miro
"Mozilla Firefox (3.0.8)" = Mozilla Firefox (3.0.8)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PC-Doctor 5 for Windows" = PC-Doctor 5 for Windows
"PCMCIAPW" = ThinkPad PC Card Power Policy
"Picasa2" = Picasa 2
"Power Management Driver" = ThinkPad Power Management Driver
"Presentation Director" = ThinkPad Presentation Director
"ProInst" = Intel® PROSet/Wireless Software
"PROSet" = Intel® PRO Network Connections Drivers
"RealPlayer 6.0" = RealPlayer
"Remove Multimedia Center" = Remove Multimedia Center
"SightSpeed" = SightSpeed (remove only)
"SmartCard2000" = SmartCard2000
"Spotify" = Spotify
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"SysInfo" = Creative System Information
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger
"ZHCIELangPack" = Chinese (Simplified) Language Support

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/9/2009 4:59:34 PM | Computer Name = NOTEBOOKT60 | Source = Application Hang | ID = 1002
Description = Hanging application Ad-Aware.exe, version 7.1.0.12, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 4/9/2009 6:41:42 PM | Computer Name = NOTEBOOKT60 | Source = Sophos Anti-Virus | ID = 131078
Description = E_FAILURE. CManager::Unregister in the ComponentManager component encountered
a catastrophic error that it could not recover from.

Error - 4/9/2009 6:41:44 PM | Computer Name = NOTEBOOKT60 | Source = Sophos Anti-Virus | ID = 131078
Description = E_FAILURE. CManager::TriggerShutdown in the ComponentManager component
encountered a catastrophic error that it could not recover from.

Error - 4/9/2009 6:44:45 PM | Computer Name = NOTEBOOKT60 | Source = Application Error | ID = 1000
Description = Faulting application ALUpdate.exe, version 5.7.22.180, faulting module
ALUpdate.exe, version 5.7.22.180, fault address 0x000a23fe.

Error - 4/9/2009 6:46:59 PM | Computer Name = NOTEBOOKT60 | Source = Application Error | ID = 1000
Description = Faulting application f8d21.exe.exe, version 1.0.0.0, faulting module
f8d21.exe.exe, version 1.0.0.0, fault address 0x00018ac4.

Error - 4/9/2009 7:04:37 PM | Computer Name = NOTEBOOKT60 | Source = Application Error | ID = 1000
Description = Faulting application ALUpdate.exe, version 5.7.22.180, faulting module
ALUpdate.exe, version 5.7.22.180, fault address 0x000a23fe.

Error - 4/10/2009 5:58:48 AM | Computer Name = NOTEBOOKT60 | Source = Application Error | ID = 1000
Description = Faulting application ALUpdate.exe, version 5.7.22.180, faulting module
ALUpdate.exe, version 5.7.22.180, fault address 0x000a2401.

Error - 4/10/2009 6:01:10 AM | Computer Name = NOTEBOOKT60 | Source = Application Error | ID = 1000
Description = Faulting application f8d21.exe.exe, version 1.0.0.0, faulting module
f8d21.exe.exe, version 1.0.0.0, fault address 0x00018ac4.

Error - 4/10/2009 6:08:33 AM | Computer Name = NOTEBOOKT60 | Source = Google Update | ID = 20
Description =

Error - 4/10/2009 6:13:20 AM | Computer Name = NOTEBOOKT60 | Source = Application Error | ID = 1000
Description = Faulting application ALUpdate.exe, version 5.7.22.180, faulting module
ALUpdate.exe, version 5.7.22.180, fault address 0x000a2401.

[ System Events ]
Error - 4/10/2009 4:49:20 AM | Computer Name = NOTEBOOKT60 | Source = Srv | ID = 2019
Description = The server was unable to allocate from the system nonpaged pool because
the pool was empty.

Error - 4/10/2009 5:01:20 AM | Computer Name = NOTEBOOKT60 | Source = Srv | ID = 2019
Description = The server was unable to allocate from the system nonpaged pool because
the pool was empty.

Error - 4/10/2009 5:13:20 AM | Computer Name = NOTEBOOKT60 | Source = Srv | ID = 2019
Description = The server was unable to allocate from the system nonpaged pool because
the pool was empty.

Error - 4/10/2009 5:25:20 AM | Computer Name = NOTEBOOKT60 | Source = Srv | ID = 2019
Description = The server was unable to allocate from the system nonpaged pool because
the pool was empty.

Error - 4/10/2009 5:37:20 AM | Computer Name = NOTEBOOKT60 | Source = Srv | ID = 2019
Description = The server was unable to allocate from the system nonpaged pool because
the pool was empty.

Error - 4/10/2009 5:49:20 AM | Computer Name = NOTEBOOKT60 | Source = Srv | ID = 2019
Description = The server was unable to allocate from the system nonpaged pool because
the pool was empty.

Error - 4/10/2009 5:59:33 AM | Computer Name = NOTEBOOKT60 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the afisicx Service service
to connect.

Error - 4/10/2009 5:59:33 AM | Computer Name = NOTEBOOKT60 | Source = Service Control Manager | ID = 7000
Description = The afisicx Service service failed to start due to the following
error: %%1053

Error - 4/10/2009 6:14:21 AM | Computer Name = NOTEBOOKT60 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the afisicx Service service
to connect.

Error - 4/10/2009 6:14:22 AM | Computer Name = NOTEBOOKT60 | Source = Service Control Manager | ID = 7000
Description = The afisicx Service service failed to start due to the following
error: %%1053


< End of report >
  • 0

#5
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Download this program:

submit files packer

Highlight the files listed below in bold and right-click and selecting copy.

C:\jacgl.exe
C:\frlnrr.exe
C:\WINDOWS\System32\w.exe
C:\WINDOWS\instsSD.exe
C:\WINDOWS\61175.exe



Then start the file packer program and right click in the white box and select paste to paste the copied file names in the field.

Then press the Continue button.

I will create an archive with these files and a small log on your Desktop that starts with a name like requested-file[date].cab.

Rename this file to samples.

Click Here to upload the files please.
================================
Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

Posted Image


Posted Image
--------------------------------------------------------------------

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.

  • 0

#6
Jon7

Jon7

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
I have done the first stage.

In the second stage, I followed the instructions, but when I open the Combo-Fix, I get:

Error - Win32 Only, "only works for workstations with Windows 2000 and XP", which is confusing because this is an XP computer.

What do I do? :)

Edited by Jon7, 10 April 2009 - 07:25 AM.

  • 0

#7
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hit ok.
  • 0

#8
Jon7

Jon7

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Gotcha.

Have it OK, and nothing seems to be happening.

:)
  • 0

#9
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Ok Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<--- ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
  • 0

#10
Jon7

Jon7

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
I'm sorry this took a while - the first scan crashed somehow, and I had to leave and scan another time overnight. But here it is, I hope I've done it right! :)

GMER 1.0.15.14966 - http://www.gmer.net
Rootkit scan 2009-04-11 10:53:21
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.15 ----

INT 0x62 ? 8A8DFBF8
INT 0x74 ? 89E22F00
INT 0x83 ? 8A94FBF8
INT 0x83 ? 89E22F00
INT 0x84 ? 89E22F00
INT 0x94 ? 89E22F00

---- Kernel code sections - GMER 1.0.15 ----

? spoz.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload B8E2C8AC 5 Bytes JMP 89E224E0
.text akdevjii.SYS B8D8E386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text akdevjii.SYS B8D8E3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text akdevjii.SYS B8D8E3C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text akdevjii.SYS B8D8E3C9 1 Byte [2E]
.text akdevjii.SYS B8D8E3C9 11 Bytes [2E, 00, 00, 00, 5A, 02, 00, ...]
.text ...

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe[196] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe[196] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe[196] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe[196] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe[196] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe[200] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe[200] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe[200] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe[200] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe[200] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\svchost.exe[212] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\svchost.exe[212] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\svchost.exe[212] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\svchost.exe[212] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\svchost.exe[212] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Picasa2\PicasaMediaDetector.exe[324] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Picasa2\PicasaMediaDetector.exe[324] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Picasa2\PicasaMediaDetector.exe[324] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Picasa2\PicasaMediaDetector.exe[324] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Picasa2\PicasaMediaDetector.exe[324] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[340] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[340] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[340] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[340] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[340] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\System32\svchost.exe[380] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FF94625
.text C:\WINDOWS\System32\svchost.exe[380] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FF946B4
.text C:\WINDOWS\System32\svchost.exe[380] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FF946C1
.text C:\WINDOWS\System32\svchost.exe[380] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FF946AA
.text C:\WINDOWS\System32\svchost.exe[380] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FF94702
.text C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe[444] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FF84625
.text C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe[444] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FF846B4
.text C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe[444] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FF846C1
.text C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe[444] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FF846AA
.text C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe[444] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FF84702
.text C:\WINDOWS\system32\Ati2evxx.exe[468] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\Ati2evxx.exe[468] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\Ati2evxx.exe[468] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\Ati2evxx.exe[468] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\Ati2evxx.exe[468] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Digital Line Detect\DLG.exe[644] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Digital Line Detect\DLG.exe[644] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Digital Line Detect\DLG.exe[644] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Digital Line Detect\DLG.exe[644] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Digital Line Detect\DLG.exe[644] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe[860] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe[860] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe[860] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe[860] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe[860] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[880] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[880] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[880] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[880] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[880] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Lenovo\Client Security Solution\cssauth.exe[1032] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Lenovo\Client Security Solution\cssauth.exe[1032] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Lenovo\Client Security Solution\cssauth.exe[1032] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Lenovo\Client Security Solution\cssauth.exe[1032] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Lenovo\Client Security Solution\cssauth.exe[1032] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1072] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1072] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1072] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1072] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1072] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\spoolsv.exe[1080] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\spoolsv.exe[1080] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\spoolsv.exe[1080] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\spoolsv.exe[1080] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\spoolsv.exe[1080] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1132] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1132] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1132] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1132] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1132] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe[1192] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe[1192] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe[1192] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe[1192] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe[1192] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\System32\SCardSvr.exe[1208] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\System32\SCardSvr.exe[1208] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\System32\SCardSvr.exe[1208] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\System32\SCardSvr.exe[1208] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\System32\SCardSvr.exe[1208] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\svchost.exe[1280] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\svchost.exe[1280] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\svchost.exe[1280] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\svchost.exe[1280] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\svchost.exe[1280] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\ctfmon.exe[1312] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\ctfmon.exe[1312] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\ctfmon.exe[1312] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\ctfmon.exe[1312] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\ctfmon.exe[1312] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\winlogon.exe[1472] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FF84625
.text C:\WINDOWS\system32\winlogon.exe[1472] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FF846B4
.text C:\WINDOWS\system32\winlogon.exe[1472] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FF846C1
.text C:\WINDOWS\system32\winlogon.exe[1472] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FF846AA
.text C:\WINDOWS\system32\winlogon.exe[1472] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FF84702
.text C:\Program Files\Messenger\msmsgs.exe[1492] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Messenger\msmsgs.exe[1492] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Messenger\msmsgs.exe[1492] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Messenger\msmsgs.exe[1492] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Messenger\msmsgs.exe[1492] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\services.exe[1516] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FF94625
.text C:\WINDOWS\system32\services.exe[1516] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FF946B4
.text C:\WINDOWS\system32\services.exe[1516] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FF946C1
.text C:\WINDOWS\system32\services.exe[1516] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FF946AA
.text C:\WINDOWS\system32\services.exe[1516] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FF94702
.text C:\WINDOWS\system32\lsass.exe[1528] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FF94625
.text C:\WINDOWS\system32\lsass.exe[1528] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FF946B4
.text C:\WINDOWS\system32\lsass.exe[1528] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FF946C1
.text C:\WINDOWS\system32\lsass.exe[1528] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FF946AA
.text C:\WINDOWS\system32\lsass.exe[1528] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FF94702
.text C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe[1644] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe[1644] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe[1644] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe[1644] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe[1644] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\ibmpmsvc.exe[1724] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\ibmpmsvc.exe[1724] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\ibmpmsvc.exe[1724] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\ibmpmsvc.exe[1724] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\ibmpmsvc.exe[1724] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\Ati2evxx.exe[1752] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\Ati2evxx.exe[1752] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\Ati2evxx.exe[1752] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\Ati2evxx.exe[1752] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\Ati2evxx.exe[1752] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\svchost.exe[1788] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FF94625
.text C:\WINDOWS\system32\svchost.exe[1788] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FF946B4
.text C:\WINDOWS\system32\svchost.exe[1788] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FF946C1
.text C:\WINDOWS\system32\svchost.exe[1788] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FF946AA
.text C:\WINDOWS\system32\svchost.exe[1788] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FF94702
.text C:\WINDOWS\Explorer.EXE[1828] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FF94625
.text C:\WINDOWS\Explorer.EXE[1828] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FF946B4
.text C:\WINDOWS\Explorer.EXE[1828] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FF946C1
.text C:\WINDOWS\Explorer.EXE[1828] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FF946AA
.text C:\WINDOWS\Explorer.EXE[1828] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FF94702
.text C:\WINDOWS\system32\svchost.exe[1836] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\svchost.exe[1836] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\svchost.exe[1836] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\svchost.exe[1836] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\svchost.exe[1836] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe[1868] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe[1868] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe[1868] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe[1868] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe[1868] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\svchost.exe[1988] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\IPSSVC.EXE[2024] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\IPSSVC.EXE[2024] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\IPSSVC.EXE[2024] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\IPSSVC.EXE[2024] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\IPSSVC.EXE[2024] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\System32\svchost.exe[2064] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\System32\svchost.exe[2064] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\System32\svchost.exe[2064] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\System32\svchost.exe[2064] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\System32\svchost.exe[2064] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Lexmark 5400 Series\lxctmon.exe[2072] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Lexmark 5400 Series\lxctmon.exe[2072] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Lexmark 5400 Series\lxctmon.exe[2072] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Lexmark 5400 Series\lxctmon.exe[2072] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Lexmark 5400 Series\lxctmon.exe[2072] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Documents and Settings\Hong Zhu\Desktop\gmer.exe[2092] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Documents and Settings\Hong Zhu\Desktop\gmer.exe[2092] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Documents and Settings\Hong Zhu\Desktop\gmer.exe[2092] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Documents and Settings\Hong Zhu\Desktop\gmer.exe[2092] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Documents and Settings\Hong Zhu\Desktop\gmer.exe[2092] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe[2120] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe[2120] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe[2120] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe[2120] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe[2120] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2132] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2132] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2132] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2132] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2132] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\System32\TPHDEXLG.EXE[2136] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\System32\TPHDEXLG.EXE[2136] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\System32\TPHDEXLG.EXE[2136] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\System32\TPHDEXLG.EXE[2136] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\System32\TPHDEXLG.EXE[2136] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\rundll32.exe[2176] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\rundll32.exe[2176] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\rundll32.exe[2176] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\rundll32.exe[2176] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\rundll32.exe[2176] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[2212] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[2212] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[2212] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[2212] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[2212] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[2236] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[2236] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[2236] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[2236] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe[2236] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[2312] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[2312] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[2312] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[2312] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[2312] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[2320] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[2320] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[2320] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[2320] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[2320] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2328] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2328] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2328] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2328] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2328] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\kdx\KHost.exe[2336] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\kdx\KHost.exe[2336] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\kdx\KHost.exe[2336] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\kdx\KHost.exe[2336] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\kdx\KHost.exe[2336] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe[2384] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe[2384] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe[2384] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe[2384] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe[2384] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2444] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2444] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2444] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2444] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2444] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[2528] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[2528] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[2528] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[2528] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[2528] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\TpShocks.exe[2540] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\TpShocks.exe[2540] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\TpShocks.exe[2540] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\TpShocks.exe[2540] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\TpShocks.exe[2540] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\lxctcoms.exe[2544] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\lxctcoms.exe[2544] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\lxctcoms.exe[2544] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\lxctcoms.exe[2544] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\lxctcoms.exe[2544] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Kontiki\KService.exe[2560] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Kontiki\KService.exe[2560] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Kontiki\KService.exe[2560] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Kontiki\KService.exe[2560] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Kontiki\KService.exe[2560] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\wuauclt.exe[2592] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\wuauclt.exe[2592] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\wuauclt.exe[2592] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\wuauclt.exe[2592] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\wuauclt.exe[2592] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe[2620] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe[2620] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe[2620] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe[2620] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe[2620] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\iTunes\iTunesHelper.exe[2640] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\iTunes\iTunesHelper.exe[2640] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\iTunes\iTunesHelper.exe[2640] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\iTunes\iTunesHelper.exe[2640] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\iTunes\iTunesHelper.exe[2640] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2688] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2688] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2688] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2688] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2688] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\TpKmpSVC.exe[2692] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\TpKmpSVC.exe[2692] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\TpKmpSVC.exe[2692] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\TpKmpSVC.exe[2692] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\TpKmpSVC.exe[2692] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe[2736] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe[2736] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe[2736] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe[2736] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe[2736] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe[2756] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe[2756] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe[2756] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe[2756] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe[2756] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[2792] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[2792] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[2792] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[2792] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[2792] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe[2820] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe[2820] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe[2820] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe[2820] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe[2820] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe[2900] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe[2900] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe[2900] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe[2900] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe[2900] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[2908] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[2908] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[2908] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[2908] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[2908] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[2924] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[2924] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[2924] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[2924] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\System32\DLA\DLACTRLW.EXE[2924] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe[2948] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe[2948] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe[2948] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe[2948] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe[2948] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[2988] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[2988] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[2988] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[2988] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe[2988] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe[3020] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe[3020] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe[3020] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe[3020] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe[3020] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[3088] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[3088] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[3088] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[3088] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[3088] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Java\jre6\bin\jqs.exe[3100] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Java\jre6\bin\jqs.exe[3100] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Java\jre6\bin\jqs.exe[3100] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Java\jre6\bin\jqs.exe[3100] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Java\jre6\bin\jqs.exe[3100] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[3116] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[3116] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[3116] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[3116] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[3116] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe[3132] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe[3132] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe[3132] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe[3132] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe[3132] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Lenovo\AwayTask\AwaySch.EXE[3136] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Lenovo\AwayTask\AwaySch.EXE[3136] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Lenovo\AwayTask\AwaySch.EXE[3136] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Lenovo\AwayTask\AwaySch.EXE[3136] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Lenovo\AwayTask\AwaySch.EXE[3136] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Java\jre6\bin\jusched.exe[3156] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Java\jre6\bin\jusched.exe[3156] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Java\jre6\bin\jusched.exe[3156] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Java\jre6\bin\jusched.exe[3156] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Java\jre6\bin\jusched.exe[3156] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[3168] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[3168] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[3168] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[3168] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe[3168] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Bonjour\mDNSResponder.exe[3260] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Bonjour\mDNSResponder.exe[3260] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Bonjour\mDNSResponder.exe[3260] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Bonjour\mDNSResponder.exe[3260] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Bonjour\mDNSResponder.exe[3260] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Sophos\AutoUpdate\ALMon.exe[3384] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Sophos\AutoUpdate\ALMon.exe[3384] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Sophos\AutoUpdate\ALMon.exe[3384] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Sophos\AutoUpdate\ALMon.exe[3384] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Sophos\AutoUpdate\ALMon.exe[3384] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Common Files\Lenovo\Logger\logmon.exe[3412] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Common Files\Lenovo\Logger\logmon.exe[3412] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Common Files\Lenovo\Logger\logmon.exe[3412] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Common Files\Lenovo\Logger\logmon.exe[3412] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Common Files\Lenovo\Logger\logmon.exe[3412] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3516] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3516] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3516] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3516] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3516] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe[3716] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe[3716] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe[3716] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe[3716] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe[3716] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Lexmark 5400 Series\ezprint.exe[3724] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Lexmark 5400 Series\ezprint.exe[3724] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Lexmark 5400 Series\ezprint.exe[3724] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Lexmark 5400 Series\ezprint.exe[3724] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Lexmark 5400 Series\ezprint.exe[3724] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe[3740] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe[3740] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe[3740] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe[3740] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe[3740] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[3756] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[3756] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[3756] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[3756] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[3756] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\WINDOWS\system32\SafeSignCertReg.exe[3784] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\WINDOWS\system32\SafeSignCertReg.exe[3784] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\WINDOWS\system32\SafeSignCertReg.exe[3784] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\WINDOWS\system32\SafeSignCertReg.exe[3784] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\WINDOWS\system32\SafeSignCertReg.exe[3784] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[3804] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[3804] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[3804] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[3804] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[3804] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[3816] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[3816] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[3816] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[3816] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[3816] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[3904] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[3904] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[3904] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[3904] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[3904] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Sophos\AutoUpdate\ALsvc.exe[3924] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Sophos\AutoUpdate\ALsvc.exe[3924] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Sophos\AutoUpdate\ALsvc.exe[3924] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Sophos\AutoUpdate\ALsvc.exe[3924] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Sophos\AutoUpdate\ALsvc.exe[3924] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3952] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3952] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3952] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3952] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[3952] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702
.text C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe[4500] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA4625
.text C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe[4500] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA46B4
.text C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe[4500] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA46C1
.text C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe[4500] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA46AA
.text C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe[4500] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA4702

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [BA6A9040] spoz.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [BA6A913C] spoz.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [BA6A90BE] spoz.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [BA6A97FC] spoz.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [BA6A96D2] spoz.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [BA6B9048] spoz.sys
IAT \SystemRoot\System32\Drivers\akdevjii.SYS[HAL.dll!KfAcquireSpinLock] C0840CEC
IAT \SystemRoot\System32\Drivers\akdevjii.SYS[HAL.dll!READ_PORT_UCHAR] 053C0D74
IAT \SystemRoot\System32\Drivers\akdevjii.SYS[HAL.dll!KeGetCurrentIrql] 57B80974
IAT \SystemRoot\System32\Drivers\akdevjii.SYS[HAL.dll!KfRaiseIrql] 8B000000
IAT \SystemRoot\System32\Drivers\akdevjii.SYS[HAL.dll!KfLowerIrql] 56C35DE5
IAT \SystemRoot\System32\Drivers\akdevjii.SYS[HAL.dll!HalGetInterruptVector] 8D08758B
IAT \SystemRoot\System32\Drivers\akdevjii.SYS[HAL.dll!HalTranslateBusAddress] 8D51FC4D
IAT \SystemRoot\System32\Drivers\akdevjii.SYS[HAL.dll!KeStallExecutionProcessor] 8D52FD55
IAT \SystemRoot\System32\Drivers\akdevjii.SYS[HAL.dll!KfReleaseSpinLock] 8D51FE4D
IAT \SystemRoot\System32\Drivers\akdevjii.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 8D52FF55
IAT \SystemRoot\System32\Drivers\akdevjii.SYS[HAL.dll!READ_PORT_USHORT] 8D51F84D
IAT \SystemRoot\System32\Drivers\akdevjii.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 5052F455
IAT \SystemRoot\System32\Drivers\akdevjii.SYS[HAL.dll!WRITE_PORT_UCHAR] EACAE856
IAT \SystemRoot\System32\Drivers\akdevjii.SYS[WMILIB.SYS!WmiSystemControl] 0FC08520
IAT \SystemRoot\System32\Drivers\akdevjii.SYS[WMILIB.SYS!WmiCompleteRequest] 0001B185

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [10001D50] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [10001D50] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [10001D50] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [10001D50] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [10001D20] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AdjustWindowRectEx] [1002DE60] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AdjustWindowRect] [1002DED0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [10001D20] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [10001D50] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongA] [1002DEF0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [10001D50] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [10001D20] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [10001D00] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [10001D50] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!SetWindowLongA] [1002DEF0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [10001050] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [10001CE0] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [10001D20] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
IAT C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[2232] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [10001D50] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 8A94E1F8

AttachedDevice \FileSystem\Ntfs \Ntfs savonaccessfilter.sys (SAV On-access and HIPS for Windows XP (x86)/Sophos Plc)
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Ip ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 mouclass.sys (Mouse Class Driver/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device \Driver\usbuhci \Device\USBPDO-0 8A806500
Device \Driver\NetBT \Device\NetBT_Tcpip_{26554BC7-4702-45B5-8FB1-C6AC76AF5E39} 89B2E500
Device \Driver\usbuhci \Device\USBPDO-1 8A806500
Device \Driver\usbuhci \Device\USBPDO-2 8A806500
Device \Driver\usbuhci \Device\USBPDO-3 8A806500
Device \Driver\usbehci \Device\USBPDO-4 89E65368

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)

Device \Driver\Ftdisk \Device\HarddiskVolume1 8A9501F8
Device \Driver\Cdrom \Device\CdRom0 89E741F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8A9501F8
Device \Driver\PCI_PNP4962 \Device\00000065 spoz.sys
Device \Driver\Cdrom \Device\CdRom1 89E741F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 89B2E500
Device \Driver\NetBT \Device\NetBT_Tcpip_{D808A5C1-0A8F-4880-B19C-C3CEA0458176} 89B2E500
Device \Driver\NetBT \Device\NetbiosSmb 89B2E500

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)

Device \Driver\sptd \Device\599337462 spoz.sys
Device \Driver\usbuhci \Device\USBFDO-0 8A806500
Device \Driver\usbuhci \Device\USBFDO-1 8A806500
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 88DE71F8
Device \Driver\usbuhci \Device\USBFDO-2 8A806500
Device \Driver\NetBT \Device\NetBT_Tcpip_{1B00D1D6-6AAB-41C1-9C68-16D316AAE874} 89B2E500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 88DE71F8
Device \Driver\usbuhci \Device\USBFDO-3 8A806500
Device \Driver\usbehci \Device\USBFDO-4 89E65368
Device \Driver\Ftdisk \Device\FtControl 8A9501F8
Device \Driver\akdevjii \Device\Scsi\akdevjii1Port2Path0Target0Lun0 89E43500
Device \Driver\akdevjii \Device\Scsi\akdevjii1 89E43500
Device \FileSystem\Fastfat \Fat 89AEA1F8
Device \FileSystem\Fastfat \Fat 9D334297

AttachedDevice \FileSystem\Fastfat \Fat savonaccessfilter.sys (SAV On-access and HIPS for Windows XP (x86)/Sophos Plc)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs 89B861F8
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x92 0x8F 0x71 0xE5 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xDB 0x9B 0xFF 0x3C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x4F 0x00 0x7D 0x77 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x92 0x8F 0x71 0xE5 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xDB 0x9B 0xFF 0x3C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x4F 0x00 0x7D 0x77 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-765243075-2163651610-3221528316-1010@RefCount 32
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Í\x2039í\x2039T\x20acó` 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Í\x2039í\x2039\x201c\x008feQ 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\20\x90\20nĐc:y 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\26Y\1xĐc:y 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@̉czz<h 0
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@IQ\ahß\x8d\x8f\x2013 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\26\1xågâ\x2039 -535951356
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\26\1xågâ\x2039\1x\x2022 12

---- Files - GMER 1.0.15 ----

File C:\RRbackups\common 0 bytes
File C:\RRbackups\common\hints.dat 8192 bytes
File C:\RRbackups\common\mnd.dat 8192 bytes
File C:\RRbackups\common\regcerts.dat 8192 bytes
File C:\RRbackups\common\restore.log 110 bytes
File C:\RRbackups\common\rr.log 355 bytes
File C:\RRbackups\common\SAM 262144 bytes
File C:\RRbackups\common\seccache.dat 8192 bytes
File C:\RRbackups\common\secpolicy.dat 53248 bytes
File C:\RRbackups\common\settings.dat 28672 bytes
File C:\RRbackups\common\system.dat 12288 bytes
File C:\RRbackups\common\tvtns.bin 23 bytes
File C:\RRbackups\common\usersids.dat 18720 bytes
File C:\RRbackups\Documents and Settings 0 bytes
File C:\RRbackups\Documents and Settings\All Users 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc1e3851f429ea606d6ff1e01a5229f1_1c493ada-df8e-472f-9602-d2afefc19152 52 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\42e7e898003fbdeb9585806ee1664b51_1c493ada-df8e-472f-9602-d2afefc19152 57 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\6d14e4b1d8ca773bab785d1be032546e_1c493ada-df8e-472f-9602-d2afefc19152 47 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\b973ec0ff915c48a18fe09064ce3a22d_1c493ada-df8e-472f-9602-d2afefc19152 56 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\d42cc0c3858a58db2db37658219e6400_1c493ada-df8e-472f-9602-d2afefc19152 893 bytes
File C:\RRbackups\Documents and Settings\Default User 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1352397986-2504758007-3842333180-1003 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1352397986-2504758007-3842333180-1003\0cd4ba10-6c6f-489d-9716-806217450cc8 388 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1352397986-2504758007-3842333180-1003\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1785498888-968475537-2660010255-1003 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1785498888-968475537-2660010255-1003\c3133d03-57dd-4b2d-b735-0c304d575a4a 388 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1785498888-968475537-2660010255-1003\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-335589547-484362620-2224364317-1003 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-335589547-484362620-2224364317-1003\3b7e68ac-fe96-46ea-89f3-ba72d7bc3eae 388 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-335589547-484362620-2224364317-1003\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Lenovo\Client Security Solution\hibernation.dat 4 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1010 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1010\6b29ae44e85efac3c72ff4d1865d73f1_1c493ada-df8e-472f-9602-d2afefc19152 53 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1010\8f71098770f72c7a67cd8f1151619865_1c493ada-df8e-472f-9602-d2afefc19152 54 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1010\d9118c8d2ec2ea2b0d32144d9c51f0d8_1c493ada-df8e-472f-9602-d2afefc19152 49 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\CREDHIST 296 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-1352397986-2504758007-3842333180-1003 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-1352397986-2504758007-3842333180-1003\0cd4ba10-6c6f-489d-9716-806217450cc8 388 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-1352397986-2504758007-3842333180-1003\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-1785498888-968475537-2660010255-1003 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-1785498888-968475537-2660010255-1003\c3133d03-57dd-4b2d-b735-0c304d575a4a 388 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-1785498888-968475537-2660010255-1003\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-335589547-484362620-2224364317-1003 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-335589547-484362620-2224364317-1003\3b7e68ac-fe96-46ea-89f3-ba72d7bc3eae 388 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-335589547-484362620-2224364317-1003\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1010 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1010\0ad0c0f2-34e4-4248-8b6b-d120122aaaa6 388 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1010\105dff2c-a030-499e-9bb1-3339d7c68b46 388 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1010\1ff4dfc5-dd4c-4395-be52-3634e8402b1a 388 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1010\34b2004a-2b32-41c2-bee6-bde5d81f8789 388 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1010\4866045a-44f2-448b-8036-88663302485d 388 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1010\656e2aac-cc90-4686-a2ec-57dcf8d28a88 388 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1010\9b9b3926-6757-4e9e-a7c4-cb01327d2430 388 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1010\dde12493-8023-44b4-90f5-9199ab1003f5 388 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1010\EE840471-00F5-4991-94EA-A699F8F2F007 388 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1010\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\SystemCertificates\My\Certificates\5EC7262B3CB87CD09D07C86AD38AD9B84BE5A319 1317 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\SystemCertificates\My\Keys 0 bytes
File C:\RRbackups\Documents and Settings\Hong Zhu\Application Data\Microsoft\SystemCertificates\My\Keys\4B935FE9811F3D7E5ADB62ED3297356D796DE760 216 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Lenovo\Client Security Solution\hibernation.dat 4 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1017 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1017\49197ecad3882e48267ecafebdff90ed_1c493ada-df8e-472f-9602-d2afefc19152 1305 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1017\5bbde90d674d9a105bbf0c46bfe7cfe5_1c493ada-df8e-472f-9602-d2afefc19152 79 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1017\6b29ae44e85efac3c72ff4d1865d73f1_1c493ada-df8e-472f-9602-d2afefc19152 53 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1017\7c70392f33a82aa0947126dc6dbb2bb9_1c493ada-df8e-472f-9602-d2afefc19152 1305 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1017\83aa4cc77f591dfc2374580bbd95f6ba_1c493ada-df8e-472f-9602-d2afefc19152 45 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1017\8c65c782aa0a093c2c9ee73afe59d718_1c493ada-df8e-472f-9602-d2afefc19152 1305 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1017\8f71098770f72c7a67cd8f1151619865_1c493ada-df8e-472f-9602-d2afefc19152 54 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1017\90a0aaf28013f2610db3c07d88411413_1c493ada-df8e-472f-9602-d2afefc19152 1305 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1017\d95386211c4e76be364bbc23f22b9926_1c493ada-df8e-472f-9602-d2afefc19152 1305 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1017\de54f4a191269ce0998e78eaef9cf5d6_1c493ada-df8e-472f-9602-d2afefc19152 48 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-1352397986-2504758007-3842333180-1003 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-1352397986-2504758007-3842333180-1003\0cd4ba10-6c6f-489d-9716-806217450cc8 388 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-1352397986-2504758007-3842333180-1003\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-1785498888-968475537-2660010255-1003 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-1785498888-968475537-2660010255-1003\c3133d03-57dd-4b2d-b735-0c304d575a4a 388 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-1785498888-968475537-2660010255-1003\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-335589547-484362620-2224364317-1003 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-335589547-484362620-2224364317-1003\3b7e68ac-fe96-46ea-89f3-ba72d7bc3eae 388 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-335589547-484362620-2224364317-1003\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1017 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1017\0c0d8ceb-e5ab-4bae-b407-369dc6191ab8 388 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1017\15735528-523f-4d58-ad3e-d6b7f2cf039f 388 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1017\4c902485-d1e0-43de-b3d8-786d2baff2db 388 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1017\6a04d555-8b20-4e89-897b-2548f9eb2fde 388 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1017\95d9ae6c-e63d-4369-8c50-256787483421 388 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1017\fca8e6fd-1b9b-4b67-a605-26f5d149ce3b 388 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1017\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Jon Zhu\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\LocalService 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Crypto\RSA\S-1-5-20 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Crypto\RSA\S-1-5-20\94498385663a229a93d423c6d144ae0b_1c493ada-df8e-472f-9602-d2afefc19152 2519 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\7dd5d439-60f8-46c1-82db-1a4bd5906e88 388 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\ee840471-00f5-4991-94ea-a699f8f2f007 388 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\Owner 0 bytes
File C:\RRbackups\Documents and Settings\Owner\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Owner\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Owner\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Owner\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Lenovo\Client Security Solution\hibernation.dat 4 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\Protect\S-1-5-21-1352397986-2504758007-3842333180-1003 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\Protect\S-1-5-21-1352397986-2504758007-3842333180-1003\0cd4ba10-6c6f-489d-9716-806217450cc8 388 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\Protect\S-1-5-21-1352397986-2504758007-3842333180-1003\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\Protect\S-1-5-21-1785498888-968475537-2660010255-1003 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\Protect\S-1-5-21-1785498888-968475537-2660010255-1003\c3133d03-57dd-4b2d-b735-0c304d575a4a 388 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\Protect\S-1-5-21-1785498888-968475537-2660010255-1003\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\Protect\S-1-5-21-335589547-484362620-2224364317-1003 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\Protect\S-1-5-21-335589547-484362620-2224364317-1003\3b7e68ac-fe96-46ea-89f3-ba72d7bc3eae 388 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\Protect\S-1-5-21-335589547-484362620-2224364317-1003\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1018 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1018\63414d13-327b-43d9-b575-45d45b1d21f4 388 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1018\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\QSIC2008\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Lenovo\Client Security Solution\hibernation.dat 4 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1009 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Crypto\RSA\S-1-5-21-765243075-2163651610-3221528316-1009\8f71098770f72c7a67cd8f1151619865_1c493ada-df8e-472f-9602-d2afefc19152 54 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Protect\S-1-5-21-1352397986-2504758007-3842333180-1003 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Protect\S-1-5-21-1352397986-2504758007-3842333180-1003\0cd4ba10-6c6f-489d-9716-806217450cc8 388 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Protect\S-1-5-21-1352397986-2504758007-3842333180-1003\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Protect\S-1-5-21-1785498888-968475537-2660010255-1003 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Protect\S-1-5-21-1785498888-968475537-2660010255-1003\c3133d03-57dd-4b2d-b735-0c304d575a4a 388 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Protect\S-1-5-21-1785498888-968475537-2660010255-1003\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Protect\S-1-5-21-335589547-484362620-2224364317-1003 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Protect\S-1-5-21-335589547-484362620-2224364317-1003\3b7e68ac-fe96-46ea-89f3-ba72d7bc3eae 388 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Protect\S-1-5-21-335589547-484362620-2224364317-1003\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1009 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1009\aaccec90-a6da-4603-8d28-a4a5af571e18 388 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\Protect\S-1-5-21-765243075-2163651610-3221528316-1009\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Userdanny\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\WINDOWS\system32\TPHDLOG0.LOG (size mismatch) 504576/504448 bytes

---- EOF - GMER 1.0.15 ----
  • 0

Advertisements


#11
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    O2 - BHO: (C:\WINDOWS\system32\ds43g4nfjkn93.dll) - {D5BF49A0-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\ds43g4nfjkn93.dll ()
    O22 - SharedTaskScheduler: {D5BF49A0-94F3-42BD-F434-3604812C8955} - lkjf9873jhifjnsfi8w3fe - C:\WINDOWS\system32\ds43g4nfjkn93.dll ()
    O32 - Autorun File - C:\autorun.inf.tmp () - [ NTFS ]
    O33 - MountPoints2\{6c9ef72d-4404-11dc-b1d1-001a6b68e736}\Shell\1\Command - "" = .\recycled\info.exe
    
    :Files
    C:\jacgl.exe
    C:\frlnrr.exe
    C:\WINDOWS\System32\drivers\ovfsthurepocbcxvsiwtxvkswtpebrppavramu.sys
    C:\WINDOWS\System32\w.exe
    C:\WINDOWS\System32\comsa32.sys
    C:\WINDOWS\System32\ds43g4nfjkn93.dll
    C:\WINDOWS\instsSD.exe
    C:\WINDOWS\61175.exe
    
    :Commands
    [emptytemp]
    [resethosts]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • It will produce a log for you on reboot, please post that log in your next reply.
================Next===========================
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatley.
============Then===============
Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Post that log in your next reply.

(Note if you cannot open the log it produces then right click on it and choose rename.
Rename it to .txt and you will be able to open it)

  • 0

#12
Jon7

Jon7

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
========== OTLISTIT ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5BF49A0-94F3-42BD-F434-3604812C8955}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D5BF49A0-94F3-42BD-F434-3604812C8955}\ deleted successfully.
C:\WINDOWS\system32\ds43g4nfjkn93.dll NOT unregistered.
C:\WINDOWS\system32\ds43g4nfjkn93.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{D5BF49A0-94F3-42BD-F434-3604812C8955} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D5BF49A0-94F3-42BD-F434-3604812C8955}\ not found.
File C:\WINDOWS\system32\ds43g4nfjkn93.dll not found.
File not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6c9ef72d-4404-11dc-b1d1-001a6b68e736}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6c9ef72d-4404-11dc-b1d1-001a6b68e736}\ not found.
File not found.
========== FILES ==========
C:\jacgl.exe moved successfully.
C:\frlnrr.exe moved successfully.
C:\WINDOWS\System32\drivers\ovfsthurepocbcxvsiwtxvkswtpebrppavramu.sys moved successfully.
C:\WINDOWS\System32\w.exe moved successfully.
C:\WINDOWS\System32\comsa32.sys moved successfully.
File/Folder C:\WINDOWS\System32\ds43g4nfjkn93.dll not found.
C:\WINDOWS\instsSD.exe moved successfully.
C:\WINDOWS\61175.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\Hong Zhu\Local Settings\Temp\etilqs_MThXl00NGpAoYCSppBAu scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Hong Zhu\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\mpj97782.dll scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_35c.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_a00.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_c1c.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\x1c85752.dll scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTListIt2 by OldTimer - Version 2.0.12.2 log created on 04122009_144107

Files moved on Reboot...
File C:\Documents and Settings\Hong Zhu\Local Settings\Temp\etilqs_MThXl00NGpAoYCSppBAu not found!
C:\WINDOWS\temp\mpj97782.dll unregistered successfully.
C:\WINDOWS\temp\mpj97782.dll moved successfully.
C:\WINDOWS\temp\Perflib_Perfdata_35c.dat moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_a00.dat not found!
File C:\WINDOWS\temp\Perflib_Perfdata_c1c.dat not found!
C:\WINDOWS\temp\x1c85752.dll unregistered successfully.
C:\WINDOWS\temp\x1c85752.dll moved successfully.

Registry entries deleted on Reboot...
  • 0

#13
Jon7

Jon7

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Deep apologies for the delay - Easter sunday and lots of families around :)

Tried downloading Malwarebytes' Anti-Malware, but I cannot because the sign says "Under current Security Zone Policy" I could not download it.

How would I get around that? :)
  • 0

#14
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Try this please:

  • Open Internet Explorer 7.
  • Click Tools, and then click Internet Options.
  • Click the Advanced tab.
  • Under Reset Internet Explorer Settings, click Reset.
  • Restart IE7 then try it again.

  • 0

#15
Jon7

Jon7

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Dear K,

Doesn't seem to work, now even the download window doesn't seem to pop up.

Every time I go on the internet, Sophos and AVG still seems to pick up a lot more new mals/trojs/etcs, so could it be a problem from that?

Secondly, can I later the settings on Firefox instead to download it? At least if I click on download on Firefox the window still pops up.

Thank you for your help :)
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP