DDS (Ver_09-07-30.01) - NTFSx86
Run by JeRrY at 9:06:59.80 on Wed 09/09/2009
Internet Explorer: 8.0.6001.18813 BrowserJavaVersion: 1.6.0_15
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.61.1033.18.3069.1106 [GMT 8:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
SP: AntiVir Desktop *enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\USBScan\USBScan.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Users\JeRrY\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com.au/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: FCToolbarURLSearchHook Class: {b800be35-8e12-422f-9967-8176bbb4e828} - c:\program files\mousehunt toolbar\Helper.dll
uURLSearchHooks: H - No File
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.3.1.15.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Freecause Toolbar BHO: {91b53b55-36ce-4abe-a248-f97d6d9f0cff} - c:\program files\mousehunt toolbar\Toolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: MouseHunt Toolbar: {89f74ae6-cc04-4740-9a19-eee1dcd2861b} - c:\program files\mousehunt toolbar\Toolbar.dll
TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [DELL Webcam Manager] "c:\program files\dell\dell webcam manager\DellWMgr.exe" /s
uRun: [Google Update] "c:\users\jerry\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
uRun: [UIWatcher] c:\program files\ashampoo\ashampoo uninstaller 3\UIWatcher.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\sttray.exe
mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
mRun: [USBScan.exe] c:\program files\usbscan\USBScan.exe -Hide
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
StartupFolder: c:\users\jerry\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\windows\installer\{7f0c4457-8e64-491b-8d7b-991504365d1e}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{4c271126-c295-4828-a901-5910ae0c258b}\Icon3E5562ED7.ico
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm
IE: Download with IDM - c:\program files\internet download manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.3.1.15.dll/206
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: c:\windows\system32\idmmbc.dll
DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/mjss/MJSS.cab109791.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\users\jerry\appdata\roaming\mozilla\firefox\profiles\hcovt8to.default\
FF - prefs.js: browser.search.selectedEngine - Search the Web
FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=58819&p=
FF - component: c:\users\jerry\appdata\roaming\idm\idmmzcc2\components\idmmzcc.dll
FF - component: c:\users\jerry\appdata\roaming\mozilla\firefox\profiles\hcovt8to.default\extensions\{916ab64c-bc3e-471b-8e60-29551922a7ba}\components\Engine.dll
FF - component: c:\users\jerry\appdata\roaming\mozilla\firefox\profiles\hcovt8to.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\users\jerry\appdata\local\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\users\jerry\appdata\roaming\mozilla\firefox\profiles\hcovt8to.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-8-8 108289]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\common files\nero\nero backitup 4\NBService.exe [2008-12-5 935208]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\drivers\OEM02Dev.sys [2007-10-10 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\drivers\OEM02Vfx.sys [2009-8-8 7424]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2009-3-19 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2009-3-19 8320]
=============== Created Last 30 ================
2009-09-07 18:48 4,240,384 a------- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-07 18:48 28,672 a------- c:\windows\system32\Apphlpdm.dll
2009-09-07 17:34 <DIR> --dsh--- C:\$RECYCLE.BIN
2009-09-07 09:07 <DIR> --d----- c:\program files\Trend Micro
2009-09-07 07:39 <DIR> --d----- c:\programdata\TEMP
2009-09-07 07:39 77,312 a------- c:\windows\system32\ztvunace26.dll
2009-09-05 12:13 376 a------- c:\windows\ODBC.INI
2009-09-05 11:15 0 a---h--t c:\windows\wusa.lock
2009-09-05 11:15 <DIR> --d----- C:\a5e188cfc3beabe756a173d5a27f
2009-09-05 11:12 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-09-05 10:31 <DIR> --d----- c:\programdata\HP Product Assistant
2009-09-03 16:10 <DIR> --d----- c:\program files\common files\HP
2009-09-03 16:00 148,925 a------- c:\windows\hpoins19.dat
2009-09-03 15:53 26,952 a------- c:\windows\hpomdl19.dat
2009-09-03 15:33 258,048 a------- c:\windows\system32\hpzids01.dll
2009-09-03 15:33 675,840 a------- c:\windows\system32\hpowiav1.dll
2009-09-03 15:33 573,440 a------- c:\windows\system32\hpotscl1.dll
2009-09-03 15:33 303,104 a------- c:\windows\system32\hpovst01.dll
2009-09-03 15:25 <DIR> --d----- c:\users\jerry\appdata\roaming\Blitware
2009-09-03 11:06 0 a------- c:\windows\system32\ÄRÄR
2009-09-03 07:03 <DIR> --d----- c:\program files\LucasArts
2009-09-03 07:02 299,520 a------- c:\windows\uninst.exe
2009-09-03 07:01 116,736 a------- c:\windows\system32\drivers\mcdbus.sys
2009-09-03 07:01 <DIR> --d----- c:\program files\MagicDisc
2009-09-02 22:52 4,767 a------- c:\windows\Irremote.ini
2009-09-02 22:38 <DIR> --d----- c:\program files\Nero
2009-09-02 22:37 <DIR> --d----- c:\programdata\Nero
2009-09-02 22:37 <DIR> --d----- c:\progra~2\Nero
2009-09-02 21:14 0 a------- c:\windows\system32\ÄLÄL
2009-09-02 20:50 <DIR> --d----- c:\programdata\InstallShield
2009-09-02 20:49 <DIR> --d----- c:\programdata\Sonic
2009-09-02 20:46 <DIR> --d----- c:\program files\common files\SureThing Shared
2009-09-02 20:46 118 a------- c:\windows\wininit.ini
2009-09-02 20:46 <DIR> --d----- c:\program files\Roxio
2009-09-02 12:57 <DIR> --d----- c:\programdata\Nokia
2009-09-02 12:57 <DIR> --d----- c:\progra~2\Nokia
2009-09-02 11:10 0 a---h--- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2009-09-01 19:55 <DIR> --d----- c:\windows\system32\Adobe
2009-09-01 17:19 <DIR> --d----- c:\users\jerry\appdata\roaming\HpUpdate
2009-09-01 17:19 <DIR> --d----- c:\windows\Hewlett-Packard
2009-09-01 11:03 <DIR> --d----- c:\users\jerry\appdata\roaming\LimeWire
2009-09-01 11:03 <DIR> --d----- c:\program files\LimeWire
2009-09-01 00:22 <DIR> --d----- c:\programdata\PC Suite
2009-09-01 00:19 <DIR> --d----- c:\program files\common files\PCSuite
2009-09-01 00:19 <DIR> --d----- c:\program files\common files\Nokia
2009-09-01 00:19 18,816 a------- c:\windows\system32\drivers\pccsmcfd.sys
2009-09-01 00:18 <DIR> --d----- c:\program files\PC Connectivity Solution
2009-09-01 00:15 91,136 a------- c:\windows\system32\nmwcdcls.dll
2009-09-01 00:15 <DIR> --d----- c:\program files\Nokia
2009-09-01 00:15 <DIR> --d----- c:\programdata\Installations
2009-08-26 18:19 2,048 a------- c:\windows\system32\tzres.dll
2009-08-23 20:13 <DIR> --d----- c:\program files\SpeedFan
2009-08-23 20:13 45 a------- c:\windows\system32\initdebug.nfo
2009-08-22 20:10 27,136 a------- c:\windows\system32\PCWizard.cpl
2009-08-22 20:10 <DIR> --d----- c:\windows\Java
2009-08-22 20:10 <DIR> --d----- c:\program files\PC Wizard 2008
2009-08-21 23:40 411,368 a------- c:\windows\system32\deploytk.dll
2009-08-19 15:18 6,200 a------- c:\windows\system32\INT13EXT.VXD
2009-08-19 15:18 <DIR> --d----- c:\program files\PC Inspector File Recovery
2009-08-19 12:39 657,106 a------- c:\windows\Condition Zero Uninstaller.exe
2009-08-19 12:16 <DIR> --d----- C:\Valve
2009-08-19 01:56 0 a---h--- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-08-17 21:44 171,760 a---h--- c:\windows\system32\mlfcache.dat
2009-08-17 19:54 18,704 a------- c:\windows\system32\drivers\se45nd5.sys
2009-08-17 19:53 90,800 a------- c:\windows\system32\drivers\se45unic.sys
2009-08-17 19:53 4,128 a------- c:\windows\system32\drivers\se45cr.sys
2009-08-17 19:49 88,624 a------- c:\windows\system32\drivers\se45mgmt.sys
2009-08-17 19:49 6,240 a------- c:\windows\system32\drivers\se45cmnt.sys
2009-08-17 19:49 6,240 a------- c:\windows\system32\drivers\se45cm.sys
2009-08-17 19:47 61,536 a------- c:\windows\system32\drivers\se45bus.sys
2009-08-17 19:47 5,872 a------- c:\windows\system32\drivers\se45whnt.sys
2009-08-17 19:47 5,872 a------- c:\windows\system32\drivers\se45wh.sys
2009-08-17 17:35 <DIR> --d----- c:\program files\MSXML 4.0
2009-08-17 01:35 <DIR> --d----- c:\programdata\WEBREG
2009-08-17 01:35 <DIR> --d----- c:\progra~2\WEBREG
2009-08-17 01:34 <DIR> --d----- c:\programdata\Hewlett-Packard
2009-08-17 01:24 <DIR> --d----- c:\program files\common files\Hewlett-Packard
2009-08-17 01:22 117,760 a------- c:\windows\system32\hpzll5mu.dll
2009-08-17 01:21 <DIR> --d----- c:\program files\HP
2009-08-17 01:20 <DIR> --d----- c:\programdata\HP
2009-08-15 23:05 <DIR> --d----- c:\program files\USBScan
2009-08-15 09:06 4,096 a------- c:\windows\d3dx.dat
2009-08-14 22:16 107,368 a------- c:\windows\system32\GEARAspi.dll
2009-08-14 22:16 23,400 a------- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-08-14 22:15 <DIR> --d----- c:\program files\iPod
2009-08-14 22:15 <DIR> --d----- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-14 22:15 <DIR> --d----- c:\program files\iTunes
2009-08-14 22:15 <DIR> --d----- c:\progra~2\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-14 22:13 <DIR> --d----- c:\program files\Bonjour
2009-08-14 11:06 <DIR> --d----- c:\users\jerry\appdata\roaming\Disney Interactive Studios
2009-08-14 01:32 <DIR> --d----- c:\program files\Veoh Networks
2009-08-13 02:09 160,256 a------- c:\windows\system32\wkssvc.dll
2009-08-13 02:09 1,256,448 a------- c:\windows\system32\lsasrv.dll
2009-08-13 02:09 499,712 a------- c:\windows\system32\kerberos.dll
2009-08-13 02:09 213,504 a------- c:\windows\system32\msv1_0.dll
2009-08-13 02:09 175,104 a------- c:\windows\system32\wdigest.dll
2009-08-13 02:09 439,896 a------- c:\windows\system32\drivers\ksecdd.sys
2009-08-13 02:09 270,848 a------- c:\windows\system32\schannel.dll
2009-08-13 02:09 72,704 a------- c:\windows\system32\secur32.dll
2009-08-13 02:09 9,728 a------- c:\windows\system32\lsass.exe
2009-08-13 02:09 71,680 a------- c:\windows\system32\atl.dll
2009-08-13 02:09 91,136 a------- c:\windows\system32\avifil32.dll
2009-08-13 02:09 2,066,432 a------- c:\windows\system32\mstscax.dll
2009-08-13 02:08 313,344 a------- c:\windows\system32\wmpdxm.dll
2009-08-13 02:08 7,680 a------- c:\windows\system32\spwmp.dll
2009-08-13 02:08 4,096 a------- c:\windows\system32\msdxm.ocx
2009-08-13 02:08 4,096 a------- c:\windows\system32\dxmasf.dll
2009-08-13 02:08 8,147,456 a------- c:\windows\system32\wmploc.DLL
2009-08-13 02:08 43,520 a------- c:\windows\system32\msdxm.tlb
2009-08-13 02:08 18,432 a------- c:\windows\system32\amcompat.tlb
2009-08-12 22:35 <DIR> --d--r-- c:\program files\Skype
2009-08-11 22:27 <DIR> --d----- c:\program files\Ashampoo
2009-08-11 22:16 <DIR> --d----- C:\Temp
2009-08-11 22:16 <DIR> --d----- c:\programdata\Ashampoo
2009-08-11 22:16 <DIR> --d----- c:\progra~2\Ashampoo
2009-08-11 22:14 <DIR> --d----- c:\users\jerry\appdata\roaming\Thinking Minds Budiling Bytes
2009-08-11 22:13 <DIR> --d----- c:\program files\CubeDesktop
2009-08-11 17:31 <DIR> --d----- c:\users\jerry\appdata\roaming\tmp
2009-08-11 17:31 <DIR> --d----- c:\users\jerry\appdata\roaming\Reallusion
2009-08-11 15:50 147,456 a------- c:\windows\system32\Faultrep.dll
2009-08-11 15:50 125,952 a------- c:\windows\system32\wersvc.dll
2009-08-10 14:07 0 a---h--- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-08-10 13:47 137,480 a------- c:\windows\system32\drivers\PnkBstrK.sys
2009-08-10 13:47 183,120 a------- c:\windows\system32\PnkBstrB.exe
2009-08-10 13:47 66,872 a------- c:\windows\system32\PnkBstrA.exe
2009-08-10 13:44 <DIR> --d----- c:\windows\system32\directx
2009-08-10 13:42 <DIR> --dsh--- c:\windows\ftpcache
==================== Find3M ====================
2009-09-09 04:00 48,271 a------- c:\users\jerry\appdata\roaming\nvModes.dat
2009-09-05 11:40 143,360 a------- c:\windows\inf\infstrng.dat
2009-09-05 11:40 51,200 a------- c:\windows\inf\infpub.dat
2009-09-03 16:06 86,016 a------- c:\windows\inf\infstor.dat
2009-08-28 20:39 173,056 a------- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 20:38 2,153,984 a------- c:\windows\apppatch\AcGenral.dll
2009-08-28 20:38 541,696 a------- c:\windows\apppatch\AcLayers.dll
2009-08-28 20:38 459,776 a------- c:\windows\apppatch\AcSpecfc.dll
2009-08-10 07:46 174 a--sh--- c:\program files\desktop.ini
2009-08-10 07:35 665,600 a------- c:\windows\inf\drvindex.dat
2009-08-10 07:19 101,888 a------- c:\windows\system32\ifxcardm.dll
2009-08-10 07:19 82,432 a------- c:\windows\system32\axaltocm.dll
2009-08-09 02:14 241,152 a------- c:\windows\system32\PortableDeviceApi.dll
2009-08-09 02:14 160,768 a------- c:\windows\system32\PortableDeviceTypes.dll
2009-08-09 02:14 94,720 a------- c:\windows\system32\PortableDeviceClassExtension.dll
2009-08-09 02:13 428,544 a------- c:\windows\system32\EncDec.dll
2009-08-09 02:13 293,376 a------- c:\windows\system32\psisdecd.dll
2009-08-09 02:06 269,312 a------- c:\windows\system32\es.dll
2009-08-09 02:00 712,704 a------- c:\windows\system32\WindowsCodecs.dll
2009-08-09 02:00 425,472 a------- c:\windows\system32\PhotoMetadataHandler.dll
2009-08-09 02:00 347,136 a------- c:\windows\system32\WindowsCodecsExt.dll
2009-08-09 01:49 1,645,568 a------- c:\windows\system32\connect.dll
2009-08-08 23:35 55,656 a------- c:\windows\system32\drivers\avgntflt.sys
2009-08-08 20:14 61,440 a------- c:\windows\system32\winipsec.dll
2009-08-08 20:14 28,672 a------- c:\windows\system32\FwRemoteSvr.dll
2009-08-08 20:14 361,984 a------- c:\windows\system32\IPSECSVC.DLL
2009-08-08 20:14 272,896 a------- c:\windows\system32\polstore.dll
2009-08-08 20:09 2,033,152 a------- c:\windows\system32\win32k.sys
2009-08-08 20:07 289,792 a------- c:\windows\system32\atmfd.dll
2009-08-08 20:07 156,672 a------- c:\windows\system32\t2embed.dll
2009-08-08 20:07 72,704 a------- c:\windows\system32\fontsub.dll
2009-08-08 20:07 34,304 a------- c:\windows\system32\atmlib.dll
2009-08-08 20:07 23,552 a------- c:\windows\system32\lpk.dll
2009-08-08 20:07 10,240 a------- c:\windows\system32\dciman32.dll
2009-08-08 20:02 376,832 a------- c:\windows\system32\winhttp.dll
2009-08-08 20:00 296,960 a------- c:\windows\system32\gdi32.dll
2009-08-08 19:59 212,480 a------- c:\windows\system32\drivers\mrxsmb10.sys
2009-08-08 19:56 562,176 a------- c:\windows\system32\msdtcprx.dll
2009-08-08 19:56 38,912 a------- c:\windows\system32\xolehlp.dll
2009-08-08 19:53 2,560 a------- c:\windows\apppatch\AcRes.dll
2009-08-08 19:53 52,736 a------- c:\windows\apppatch\iebrshim.dll
2009-08-08 19:53 1,695,744 a------- c:\windows\system32\gameux.dll
2009-08-08 19:52 303,616 a------- c:\windows\system32\wmpeffects.dll
2009-08-08 19:51 1,191,936 a------- c:\windows\system32\msxml3.dll
2009-08-08 19:51 2,048 a------- c:\windows\system32\msxml3r.dll
2009-08-08 19:37 636,928 a------- c:\windows\system32\localspl.dll
2009-08-08 19:34 2,927,104 a------- c:\windows\explorer.exe
2009-08-08 19:26 9,892,864 a------- c:\windows\system32\NlsLexicons000a.dll
2009-08-08 19:25 220,160 a------- c:\windows\system32\drivers\bthport.sys
2009-08-08 19:25 181,760 a------- c:\windows\system32\fsquirt.exe
2009-08-08 19:25 29,184 a------- c:\windows\system32\drivers\BTHUSB.SYS
2009-08-08 19:25 19,456 a------- c:\windows\system32\drivers\bthenum.sys
2009-08-08 19:22 6,656 a------- c:\windows\system32\kbd106n.dll
2009-08-08 19:22 988,216 a------- c:\windows\system32\winload.exe
2009-08-08 19:22 927,288 a------- c:\windows\system32\winresume.exe
2009-08-08 19:22 378,368 a------- c:\windows\system32\srcore.dll
2009-08-08 19:22 318,464 a------- c:\windows\system32\rstrui.exe
2009-08-08 19:22 40,960 a------- c:\windows\system32\srclient.dll
2009-08-08 19:22 14,848 a------- c:\windows\system32\srdelayed.exe
2009-08-08 19:22 19,000 a------- c:\windows\system32\kd1394.dll
2009-08-08 19:22 46,592 a------- c:\windows\system32\setbcdlocale.dll
2009-08-08 19:22 615,992 a------- c:\windows\system32\ci.dll
2009-08-08 19:13 40,960 a------- c:\windows\apppatch\apihex86.dll
2009-08-08 19:13 24,064 a------- c:\windows\system32\amxread.dll
2009-08-08 19:13 13,824 a------- c:\windows\system32\apilogen.dll
2009-08-08 19:08 443,392 a------- c:\windows\system32\win32spl.dll
2009-08-08 19:08 37,888 a------- c:\windows\system32\printcom.dll
2009-08-08 19:08 113,664 a------- c:\windows\system32\drivers\rmcast.sys
2009-08-08 19:08 14,848 a------- c:\windows\system32\wshrm.dll
2009-08-08 19:04 288,768 a------- c:\windows\system32\drivers\srv.sys
2009-08-08 18:57 622,080 a------- c:\windows\system32\icardagt.exe
2009-08-08 18:57 11,264 a------- c:\windows\system32\icardres.dll
2009-08-08 18:57 97,800 a------- c:\windows\system32\infocardapi.dll
2009-08-08 18:57 105,016 a------- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-08-08 18:57 781,344 a------- c:\windows\system32\PresentationNative_v0300.dll
2009-08-08 18:57 326,160 a------- c:\windows\system32\PresentationHost.exe
2009-08-08 18:57 43,544 a------- c:\windows\system32\PresentationHostProxy.dll
2009-08-08 18:41 96,760 a------- c:\windows\system32\dfshim.dll
2009-08-08 18:41 41,984 a------- c:\windows\system32\netfxperf.dll
2009-08-08 18:41 282,112 a------- c:\windows\system32\mscoree.dll
2009-08-08 18:41 158,720 a------- c:\windows\system32\mscorier.dll
2009-08-08 18:41 83,968 a------- c:\windows\system32\mscories.dll
2009-08-08 18:19 2,868,736 a------- c:\windows\system32\mf.dll
2009-08-08 18:19 98,816 a------- c:\windows\system32\mfps.dll
2009-08-08 18:19 53,248 a------- c:\windows\system32\rrinstaller.exe
2009-08-08 18:19 24,576 a------- c:\windows\system32\mfpmp.exe
2009-08-08 18:19 2,048 a------- c:\windows\system32\mferror.dll
2009-08-08 18:19 94,720 a------- c:\windows\system32\logagent.exe
2009-08-08 18:19 996,352 a------- c:\windows\system32\WMNetMgr.dll
2009-08-08 18:18 738,304 a------- c:\windows\system32\inetcomm.dll
2009-08-08 18:18 84,480 a------- c:\windows\system32\INETRES.dll
2009-08-08 18:16 784,896 a------- c:\windows\system32\rpcrt4.dll
2009-08-08 18:16 1,314,816 a------- c:\windows\system32\quartz.dll
2009-08-08 18:15 1,334,272 a------- c:\windows\system32\msxml6.dll
2009-08-08 18:14 2,048 a------- c:\windows\system32\msxml6r.dll
2009-08-08 16:53 1,524,736 a------- c:\windows\system32\wucltux.dll
2009-08-08 16:49 83,456 a------- c:\windows\system32\wudriver.dll
2009-08-08 16:47 162,064 a------- c:\windows\system32\wuwebv.dll
2009-08-08 16:47 31,232 a------- c:\windows\system32\wuapp.exe
2009-08-08 15:57:58 A---H--- 0 c:\windows\system32\drivers\Msft_Kernel_Apfiltr_01005.Wdf
2007-02-22 03:49 8,192 a--sh--- c:\windows\users\default\NTUSER.DAT
============= FINISH: 9:07:50.46 ===============
GMER 1.0.15.15077 [odzu3qjn.exe] -
http://www.gmer.net
Rootkit scan 2009-09-09 09:04:45
Windows 6.0.6001 Service Pack 1
---- System - GMER 1.0.15 ----
SSDT 9D7C0A44 ZwCreateThread
SSDT 9D7C0A30 ZwOpenProcess
SSDT 9D7C0A35 ZwOpenThread
SSDT 9D7C0A3F ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetTimerEx + 454 820C6A18 4 Bytes [44, 0A, 7C, 9D]
.text ntkrnlpa.exe!KeSetTimerEx + 624 820C6BE8 4 Bytes [30, 0A, 7C, 9D] {XOR [EDX], CL; JL 0xffffffffffffffa1}
.text ntkrnlpa.exe!KeSetTimerEx + 640 820C6C04 4 Bytes [35, 0A, 7C, 9D]
.text ntkrnlpa.exe!KeSetTimerEx + 854 820C6E18 4 Bytes [3F, 0A, 7C, 9D]
---- User code sections - GMER 1.0.15 ----
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtCreateFile + 6 7781800E 4 Bytes [28, 00, 06, 00]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtCreateFile + B 77818013 1 Byte [E2]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtMapViewOfSection + 6 7781875E 1 Byte [28]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtMapViewOfSection + 6 7781875E 4 Bytes [28, 03, 06, 00]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtMapViewOfSection + B 77818763 1 Byte [E2]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtOpenFile + 6 778187EE 4 Bytes [68, 00, 06, 00]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtOpenFile + B 778187F3 1 Byte [E2]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtOpenProcess + 6 7781886E 4 Bytes [A8, 01, 06, 00]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtOpenProcess + B 77818873 1 Byte [E2]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtOpenProcessToken + 6 7781887E 4 Bytes CALL 76818E84
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtOpenProcessToken + B 77818883 1 Byte [E2]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtOpenProcessTokenEx + 6 7781888E 4 Bytes [A8, 02, 06, 00]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtOpenProcessTokenEx + B 77818893 1 Byte [E2]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtOpenThread + 6 778188DE 4 Bytes [68, 01, 06, 00]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtOpenThread + B 778188E3 1 Byte [E2]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtOpenThreadToken + 6 778188EE 4 Bytes [68, 02, 06, 00]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtOpenThreadToken + B 778188F3 1 Byte [E2]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtOpenThreadTokenEx + 6 778188FE 4 Bytes CALL 76818F05
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtOpenThreadTokenEx + B 77818903 1 Byte [E2]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtQueryAttributesFile + 6 7781898E 4 Bytes [A8, 00, 06, 00]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtQueryAttributesFile + B 77818993 1 Byte [E2]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtQueryFullAttributesFile + 6 77818A3E 4 Bytes CALL 76819043
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtQueryFullAttributesFile + B 77818A43 1 Byte [E2]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtSetInformationFile + 6 77818F1E 4 Bytes [28, 01, 06, 00]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtSetInformationFile + B 77818F23 1 Byte [E2]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtSetInformationThread + 6 77818F6E 4 Bytes [28, 02, 06, 00]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtSetInformationThread + B 77818F73 1 Byte [E2]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtUnmapViewOfSection + 6 7781920E 1 Byte [68]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtUnmapViewOfSection + 6 7781920E 4 Bytes [68, 03, 06, 00]
.text C:\Users\JeRrY\AppData\Local\Google\Chrome\Application\chrome.exe[5520] ntdll.dll!NtUnmapViewOfSection + B 77819213 1 Byte [E2]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] kernel32.dll!FindResourceExA 761E08DD 7 Bytes JMP 28001D80 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] kernel32.dll!FindResourceA 761E09A5 5 Bytes JMP 28001CF0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] kernel32.dll!CreateEventA 761F4AD8 5 Bytes JMP 28001840 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] kernel32.dll!LockResource 761F7F1F 5 Bytes JMP 28001F50 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] kernel32.dll!FindResourceExW 761F813B 1 Byte [E9]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] kernel32.dll!FindResourceExW 761F813B 7 Bytes JMP 28001C60 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] kernel32.dll!LoadResource 761F8213 7 Bytes JMP 28001E20 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] kernel32.dll!FindResourceW 761F97C7 5 Bytes JMP 28001BE0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] kernel32.dll!SizeofResource 761F97E5 7 Bytes JMP 28001EE0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] ADVAPI32.dll!CryptDeriveKey 763AE6F6 7 Bytes JMP 28001000 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] ADVAPI32.dll!CryptDecrypt 763AE8D9 7 Bytes JMP 28001060 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] USER32.dll!SetWindowPlacement 75F779BB 5 Bytes JMP 28005EA0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] USER32.dll!SetWindowRgn 75F795E2 7 Bytes JMP 28005FE0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] USER32.dll!LoadImageW 75F7D61D 5 Bytes JMP 28006770 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] USER32.dll!LoadIconW 75F7EC94 5 Bytes JMP 28006960 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] USER32.dll!CreateWindowExW 75F83D67 5 Bytes JMP 28003CF0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] USER32.dll!GetWindowLongW 75F8F67F 7 Bytes JMP 28006B00 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] USER32.dll!PeekMessageW 75F8FD9F 5 Bytes JMP 280046C0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] USER32.dll!TrackPopupMenuEx 75FA0F4D 5 Bytes JMP 28004FA0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] USER32.dll!CreateDialogParamW 75FA1C58 5 Bytes JMP 28006120 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] USER32.dll!MessageBoxIndirectW 75FCD56B 5 Bytes JMP 28006310 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] WS2_32.dll!closesocket 765C330C 5 Bytes JMP 2800BB90 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] WS2_32.dll!recv 765C343A 5 Bytes JMP 2800B3B0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] WS2_32.dll!WSASend 765C4496 5 Bytes JMP 2800B950 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] WS2_32.dll!send 765C659B 5 Bytes JMP 2800B770 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] WS2_32.dll!WSARecv 765C8400 5 Bytes JMP 2800B550 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] SHELL32.dll!Shell_NotifyIconW 7696C808 5 Bytes JMP 28003440 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] ole32.dll!CoRegisterClassObject 764845AC 5 Bytes JMP 28002360 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] ole32.dll!CoInitializeEx 764BB89A 5 Bytes JMP 28002260 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] ole32.dll!CoCreateInstance 764BE188 5 Bytes JMP 28002600 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] WININET.dll!InternetReadFile 7755654B 5 Bytes JMP 2800A3B0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] WININET.dll!InternetCloseHandle 77559088 5 Bytes JMP 2800A560 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] WININET.dll!HttpOpenRequestA 7755D508 5 Bytes JMP 2800A220 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5960] WININET.dll!HttpSendRequestA 7756EE81 5 Bytes JMP 2800A490 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73D67BA4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73DA98C5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73D6D3C8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73D5F527] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73D67599] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73D5E43D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [73D9B33D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [73D6D68A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73D6012E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73D60095] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73D571F3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [73DED802] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [73D875E1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73D5DAE1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73D5668F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73D566BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1848] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73D61E45] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001f3ae18c25
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001f3ae18c25@0024049ae5d9 0x41 0xF4 0x22 0x4F ...
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\001f3ae18c25 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\001f3ae18c25@0024049ae5d9 0x41 0xF4 0x22 0x4F ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7A23B884-38E2-6CEE-27D5-168DEC48173B}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7A23B884-38E2-6CEE-27D5-168DEC48173B}@jaalkpejgbpppnjhfmoo 0x66 0x61 0x64 0x6C ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7A23B884-38E2-6CEE-27D5-168DEC48173B}@paimddgdidddgkbakangemoblabldaid 0x65 0x61 0x64 0x6C ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7A23B884-38E2-6CEE-27D5-168DEC48173B}@haalkpejgbpppnjh 0x6E 0x62 0x64 0x6C ...
---- Files - GMER 1.0.15 ----
File C:\Users\JeRrY\AppData\Local\temp\foxtab\thumbs\3_8 0 bytes
File C:\Users\JeRrY\AppData\Local\temp\foxtab\thumbs\3_8_S 0 bytes
---- EOF - GMER 1.0.15 ----