1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Vista working slowly recently

Discussion in 'Malware and Virus Removal Archive' started by JohnDy, 2009/11/30.

  1. 2009/11/30
    JohnDy

    JohnDy Inactive Thread Starter

    Joined:
    2009/11/29
    Messages:
    7
    Likes Received:
    0
    [Inactive] Vista working slowly recently

    Hello,
    I've had my computer since February 2009. It's a Dell Inspiron 519 with Vista Home Basic SP2. The computer had been fine until about a month ago. I made a huge mistake and updated Kaspersky Internet Security and Vista Updates the same day. The first problem I found was Internet Explorer (8.0.6001.18828) was opening Tabs or Windows very slowly.
    I did some research and disabled most of the add ons and this helped a bit.

    Then I noticed the computer itself was running slowly. The Anti-Virus scan used to take 2 hours, now it is taking 4 - 5 hours. In the Task Manager I notice svchost frequently uses about 50% of the CPU. The two services running at that time are dcomlaunch and plug n play.
    I did some more research on this and downloaded from Dell a new Realtek audio driver. The driver fails to install.

    Then finally, when using folders, I noticed that when I close a window, it takes 1 - 2 seconds for the window to actually close.

    These are annoying little issues, but fortunately everything I want to do on the computer is still possible.

    I posted on the Windows BBS blog and it was suggested to post on the Malware Thread. I ran the DDS tool and here are the results:

    DDS (Ver_09-11-29.01) - NTFSx86
    Run by John at 6:24:26.00 on Mon 11/30/2009
    Internet Explorer: 8.0.6001.18828
    Microsoft® Windows Vistaâ„¢ Home Basic 6.0.6002.2.1252.1.1033.18.3326.1553 [GMT -5:00]

    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\system32\Ati2evxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\Ati2evxx.exe
    C:\Program Files\Dell\DellDock\DockLogin.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Dell\MediaDirect\PCMService.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
    c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Genie-Soft\GBMHome8\GBMAgent.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
    C:\Program Files\Dell Remote Access\ezi_ra.exe
    C:\Program Files\PolderbitS\Recorder\Driver\PBDriverMonitor_uk.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Program Files\SecureSafe Pro\SecureSafe.exe
    C:\Program Files\Windows Mail\WinMail.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Users\John\Desktop\dds.scr
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uWindow Title = Internet Explorer provided by Dell
    uInternet Settings,ProxyOverride = *.local
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
    BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
    TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
    uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
    uRun: [GBMHome8Agent] "c:\program files\genie-soft\gbmhome8\GBMAgent.exe "
    uRun: [Genie Backup]
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [RtHDVCpl] RtHDVCpl.exe
    mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe "
    mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe "
    mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
    mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
    mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe "
    mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe "
    mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\programdata\scansoft\paperport\11\config\ereg\Ereg.ini
    mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
    mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
    mRun: [FileZilla Server Interface] "c:\program files\filezilla server\FileZilla Server Interface.exe "
    mRun: [GBMHome8Agent] "c:\program files\genie-soft\gbmhome8\GBMAgent.exe "
    mRun: [Genie Backup]
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe "
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe "
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe "
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe "
    mRun: [avp] "c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe "
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\dellre~1.lnk - c:\windows\installer\{f66a31d9-7831-4fba-ba02-c411c0047cc5}\NewShortcut10_F66A31D978314FBABA02C411C0047CC5.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\polder~1.lnk - c:\program files\polderbits\recorder\driver\PBDriverMonitor_uk.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2010\ie_banner_deny.htm
    IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi1933~1\office12\ONBttnIE.dll
    IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL
    IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxp://support.dell.com/systemprofiler/SysProExe.CAB
    DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
    AppInit_DLLs: c:\progra~1\kasper~1\kasper~2\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~2\kloehk.dll

    ============= SERVICES / DRIVERS ===============

    R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-14 36880]
    R1 FAMv4;FAMv4;c:\windows\system32\drivers\FAMv4.sys [2008-4-9 97816]
    R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2008-7-9 21520]
    R2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\drivers\RtNdPt60.sys [2009-2-20 27648]
    R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-10-2 19472]
    R3 PbsAuDrv;PolderbitS Audio Driver;c:\windows\system32\drivers\pbsaudrv.sys [2009-2-25 110752]

    =============== Created Last 30 ================

    2009-11-25 02:46:35 2048 ------w- c:\windows\system32\tzres.dll
    2009-11-25 02:44:01 1401856 ------w- c:\windows\system32\msxml6.dll
    2009-11-25 02:44:01 1248768 ------w- c:\windows\system32\msxml3.dll
    2009-11-23 12:48:11 319456 ------w- c:\windows\DIFxAPI.dll
    2009-11-23 12:48:04 315392 ------w- c:\windows\HideWin.exe
    2009-11-23 12:25:26 0 d-----w- c:\windows\system32\Dell
    2009-11-11 11:45:21 0 d-----w- c:\program files\Windows Portable Devices
    2009-11-11 11:44:43 0 ---h--w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
    2009-11-11 11:42:51 92672 ------w- c:\windows\system32\UIAnimation.dll
    2009-11-11 11:42:47 3023360 ------w- c:\windows\system32\UIRibbon.dll
    2009-11-11 11:42:47 1164800 ------w- c:\windows\system32\UIRibbonRes.dll
    2009-11-11 11:40:09 30208 ------w- c:\windows\system32\WPDShextAutoplay.exe
    2009-11-11 11:40:08 81920 ------w- c:\windows\system32\wpdbusenum.dll
    2009-11-11 11:40:08 31232 ------w- c:\windows\system32\BthMtpContextHandler.dll
    2009-11-11 11:37:08 4096 ------w- c:\windows\system32\oleaccrc.dll
    2009-11-11 11:37:06 555520 ------w- c:\windows\system32\UIAutomationCore.dll
    2009-11-11 11:37:06 234496 ------w- c:\windows\system32\oleacc.dll
    2009-11-11 11:34:05 28672 ------w- c:\windows\system32\Apphlpdm.dll
    2009-11-11 11:34:02 4240384 ------w- c:\windows\system32\GameUXLegacyGDFs.dll
    2009-11-11 11:32:04 310784 ------w- c:\windows\system32\unregmp2.exe
    2009-11-11 11:31:59 8147456 ------w- c:\windows\system32\wmploc.DLL
    2009-11-11 11:12:50 2036736 ------w- c:\windows\system32\win32k.sys
    2009-11-11 11:12:31 355328 ------w- c:\windows\system32\WSDApi.dll
    2009-11-07 13:13:07 0 d-----w- c:\programdata\WindowsSearch
    2009-11-07 13:12:47 95259 ------w- c:\windows\system32\drivers\klick.dat
    2009-11-07 13:12:47 108059 ------w- c:\windows\system32\drivers\klin.dat
    2009-11-07 13:11:46 0 d-----w- c:\program files\Kaspersky Lab
    2009-11-03 01:26:44 1638912 ------w- c:\windows\system32\mshtml.tlb
    2009-11-03 01:25:30 0 d-----w- c:\program files\iPod
    2009-11-03 01:25:28 0 d-----w- c:\program files\iTunes

    ==================== Find3M ====================

    2009-11-24 00:12:11 51200 ------w- c:\windows\inf\infpub.dat
    2009-11-24 00:12:11 143360 ------w- c:\windows\inf\infstrng.dat
    2009-11-23 12:49:07 86016 ------w- c:\windows\inf\infstor.dat
    2009-11-11 11:45:10 665600 ------w- c:\windows\inf\drvindex.dat
    2009-11-08 14:23:11 6218272 --sh--w- c:\windows\system32\drivers\fidbox.dat
    2009-11-08 14:23:11 5600 --sh--w- c:\windows\system32\drivers\fidbox2.idx
    2009-11-08 14:23:11 50708 --sh--w- c:\windows\system32\drivers\fidbox.idx
    2009-11-08 14:23:11 1015840 --sh--w- c:\windows\system32\drivers\fidbox2.dat
    2009-11-03 01:42:06 195456 ------w- c:\windows\system32\MpSigStub.exe
    2009-10-21 01:34:56 219664 ------w- c:\windows\system32\klogon.dll
    2009-10-15 02:18:34 36880 ------w- c:\windows\system32\drivers\klbg.sys
    2009-10-11 09:17:27 411368 ------w- c:\windows\system32\deploytk.dll
    2009-10-03 00:39:36 19472 ------w- c:\windows\system32\drivers\klmouflt.sys
    2009-10-01 01:02:17 2537472 ------w- c:\windows\system32\wpdshext.dll
    2009-10-01 01:02:04 334848 ------w- c:\windows\system32\PortableDeviceApi.dll
    2009-10-01 01:02:02 87552 ------w- c:\windows\system32\WPDShServiceObj.dll
    2009-10-01 01:01:59 546816 ------w- c:\windows\system32\wpd_ci.dll
    2009-10-01 01:01:59 160256 ------w- c:\windows\system32\PortableDeviceTypes.dll
    2009-10-01 01:01:56 60928 ------w- c:\windows\system32\PortableDeviceConnectApi.dll
    2009-10-01 01:01:56 350208 ------w- c:\windows\system32\WPDSp.dll
    2009-10-01 01:01:56 196608 ------w- c:\windows\system32\PortableDeviceWMDRM.dll
    2009-10-01 01:01:56 100864 ------w- c:\windows\system32\PortableDeviceClassExtension.dll
    2009-09-25 02:10:10 974848 ------w- c:\windows\system32\WindowsCodecs.dll
    2009-09-25 02:07:08 189440 ------w- c:\windows\system32\WindowsCodecsExt.dll
    2009-09-25 02:04:32 321024 ------w- c:\windows\system32\PhotoMetadataHandler.dll
    2009-09-25 01:49:22 1554432 ------w- c:\windows\system32\xpsservices.dll
    2009-09-25 01:48:08 351232 ------w- c:\windows\system32\XpsPrint.dll
    2009-09-25 01:38:29 847360 ------w- c:\windows\system32\OpcServices.dll
    2009-09-25 01:36:13 280064 ------w- c:\windows\system32\XpsGdiConverter.dll
    2009-09-25 01:35:31 135680 ------w- c:\windows\system32\XpsRasterService.dll
    2009-09-25 01:33:25 195584 ------w- c:\windows\system32\dxdiagn.dll
    2009-09-25 01:33:15 829440 ------w- c:\windows\system32\d3d10warp.dll
    2009-09-25 01:33:01 369664 ------w- c:\windows\system32\WMPhoto.dll
    2009-09-25 01:32:59 252928 ------w- c:\windows\system32\dxdiag.exe
    2009-09-25 01:31:53 519680 ------w- c:\windows\system32\d3d11.dll
    2009-09-25 01:31:26 486912 ------w- c:\windows\system32\d3d10level9.dll
    2009-09-25 01:31:21 161280 ------w- c:\windows\system32\d3d10_1.dll
    2009-09-25 01:31:19 218112 ------w- c:\windows\system32\d3d10_1core.dll
    2009-09-25 01:31:16 1030144 ------w- c:\windows\system32\d3d10.dll
    2009-09-25 01:31:15 828928 ------w- c:\windows\system32\d2d1.dll
    2009-09-25 01:30:23 481792 ------w- c:\windows\system32\dxgi.dll
    2009-09-25 01:30:23 190464 ------w- c:\windows\system32\d3d10core.dll
    2009-09-25 01:27:04 793088 ------w- c:\windows\system32\FntCache.dll
    2009-09-25 01:27:04 37888 ------w- c:\windows\system32\cdd.dll
    2009-09-25 01:27:04 1064448 ------w- c:\windows\system32\DWrite.dll
    2009-09-24 22:54:55 258048 ------w- c:\windows\system32\winspool.drv
    2009-09-24 22:54:53 667648 ------w- c:\windows\system32\printfilterpipelinesvc.exe
    2009-09-24 22:54:52 26112 ------w- c:\windows\system32\printfilterpipelineprxy.dll
    2009-09-10 16:48:01 218624 ------w- c:\windows\system32\msv1_0.dll
    2009-09-04 11:41:59 60928 ------w- c:\windows\system32\msasn1.dll
    2008-01-21 02:57:01 174 --sh--w- c:\program files\desktop.ini
    2006-11-02 12:39:34 30674 ------w- c:\windows\inf\perflib\0409\perfd.dat
    2006-11-02 12:39:34 30674 ------w- c:\windows\inf\perflib\0409\perfc.dat
    2006-11-02 12:39:34 287440 ------w- c:\windows\inf\perflib\0409\perfi.dat
    2006-11-02 12:39:34 287440 ------w- c:\windows\inf\perflib\0409\perfh.dat
    2006-11-02 09:20:21 287440 ------w- c:\windows\inf\perflib\0000\perfi.dat
    2006-11-02 09:20:21 287440 ------w- c:\windows\inf\perflib\0000\perfh.dat
    2006-11-02 09:20:19 30674 ------w- c:\windows\inf\perflib\0000\perfd.dat
    2006-11-02 09:20:19 30674 ------w- c:\windows\inf\perflib\0000\perfc.dat
    2009-02-27 12:12:15 16384 --sh--w- c:\windows\temp\cookies\index.dat
    2009-02-27 12:12:15 16384 --sh--w- c:\windows\temp\history\history.ie5\index.dat
    2009-02-27 12:12:15 32768 --sh--w- c:\windows\temp\temporary internet files\content.ie5\index.dat
    2009-02-20 09:03:32 8192 --sh--w- c:\windows\users\default\NTUSER.DAT

    ============= FINISH: 6:25:27.48 ===============

    .......... And the attachment:

    NLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-11-29.01)

    Microsoft® Windows Vistaâ„¢ Home Basic
    Boot Device: \Device\HarddiskVolume3
    Install Date: 2/20/2009 1:29:33 AM
    System Uptime: 11/24/2009 10:11:16 PM (128 hours ago)

    Motherboard: Dell Inc. | | 0K071D
    Processor: AMD Athlon(tm) Dual Core Processor 4450e | AM2 | 2300/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 451 GiB total, 340.524 GiB free.
    D: is FIXED (NTFS) - 15 GiB total, 7.629 GiB free.
    E: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP378: 11/8/2009 9:17:38 AM - Installed Kaspersky Internet Security 2010.
    RP379: 11/9/2009 12:00:09 AM - Scheduled Checkpoint
    RP380: 11/10/2009 12:00:09 AM - Scheduled Checkpoint
    RP381: 11/11/2009 12:10:13 AM - Scheduled Checkpoint
    RP382: 11/11/2009 6:13:17 AM - Windows Update
    RP383: 11/11/2009 6:34:22 AM - Windows Update
    RP384: 11/12/2009 12:00:04 AM - Scheduled Checkpoint
    RP385: 11/13/2009 12:00:09 AM - Scheduled Checkpoint
    RP386: 11/14/2009 1:32:26 AM - Scheduled Checkpoint
    RP387: 11/15/2009 12:00:10 AM - Scheduled Checkpoint
    RP388: 11/16/2009 12:07:19 AM - Scheduled Checkpoint
    RP389: 11/17/2009 12:00:05 AM - Scheduled Checkpoint
    RP390: 11/18/2009 12:00:10 AM - Scheduled Checkpoint
    RP391: 11/19/2009 12:00:10 AM - Scheduled Checkpoint
    RP392: 11/20/2009 12:00:10 AM - Scheduled Checkpoint
    RP393: 11/21/2009 12:00:11 AM - Scheduled Checkpoint
    RP394: 11/22/2009 12:00:12 AM - Scheduled Checkpoint
    RP395: 11/23/2009 12:00:06 AM - Scheduled Checkpoint
    RP396: 11/23/2009 7:05:38 AM - Windows Update
    RP397: 11/23/2009 7:48:26 AM - Device Driver Package Install: Realtek Semiconductor Corp. Sound, video and game controllers
    RP398: 11/24/2009 12:00:10 AM - Scheduled Checkpoint
    RP399: 11/24/2009 9:44:12 PM - Windows Update
    RP400: 11/26/2009 12:00:11 AM - Scheduled Checkpoint
    RP401: 11/27/2009 12:07:25 AM - Scheduled Checkpoint
    RP402: 11/28/2009 1:12:20 AM - Scheduled Checkpoint
    RP403: 11/29/2009 1:33:00 AM - Scheduled Checkpoint
    RP404: 11/30/2009 12:00:18 AM - Scheduled Checkpoint

    ==== Installed Programs ======================

    Acrobat.com
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Reader 9.2
    AnswerWorks 5.0 English Runtime
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    ATI Catalyst Control Center
    Bonjour
    Brother MFL-Pro Suite
    Catalyst Control Center - Branding
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center Graphics Previews Vista
    Catalyst Control Center Localization Chinese Standard
    Catalyst Control Center Localization Chinese Traditional
    Catalyst Control Center Localization French
    Catalyst Control Center Localization German
    Catalyst Control Center Localization Italian
    Catalyst Control Center Localization Japanese
    Catalyst Control Center Localization Korean
    Catalyst Control Center Localization Portuguese
    Catalyst Control Center Localization Spanish
    ccc-core-static
    ccc-utility
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help English
    CCC Help French
    CCC Help German
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Portuguese
    CCC Help Spanish
    Choice Guard
    Consumer In-Home Service Agreement
    Dell-eBay
    Dell Dock
    Dell Driver Download Manager
    Dell Getting Started Guide
    Dell Remote Access
    Dell Support Center (Support Software)
    DELL0604
    EDocs
    File Access Manager (remove only)
    FileZilla Server (remove only)
    Genie Backup Manager Home 8.0
    GoToAssist 8.0.0.514
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    iPhone Configuration Utility
    iTunes
    Java(TM) 6 Update 17
    Junk Mail filter update
    Kaspersky Internet Security 2010
    MediaDirect
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Home and Student 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Search Enhancement Pack
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Sync Framework Runtime Native v1.0 (x86)
    Microsoft Sync Framework Services Native v1.0 (x86)
    MSVCRT
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    OGA Notifier 2.0.0048.0
    Open File Backup Agent
    PaperPort Image Printer
    PolderbitS Sound Recorder and Editor
    Quicken 2009
    QuickTime
    Realtek Ethernet Network Card Diagnostic tool for Windows Vista
    Realtek High Definition Audio Driver
    Roxio Creator Audio
    Roxio Creator Copy
    Roxio Creator Data
    Roxio Creator DE
    Roxio Creator Tools
    Roxio Express Labeler 3
    Roxio Update Manager
    Safari
    ScanSoft PaperPort 11
    SecureSafe Pro (remove only)
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB973704)
    Security Update for Microsoft Office Excel 2007 (KB973593)
    Security Update for Microsoft Office PowerPoint 2007 (KB957789)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB969613)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Skins
    TaxCut Business 2008 (Remove Only)
    TaxCut New York 2008
    TaxCut Premium + State + Efile 2008
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 (KB974561)
    Update for Microsoft Office Word 2007 Help (KB963665)
    WildTangent Games
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Mail
    Windows Live Messenger
    Windows Live Photo Gallery
    Windows Live Sign-in Assistant
    Windows Live Sync
    Windows Live Toolbar
    Windows Live Upload Tool
    Windows Live Writer

    ==== Event Viewer Messages From Past Week ========

    11/24/2009 6:25:32 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Reboot the machine) after the unexpected termination of the DCOM Server Process Launcher service, but this action failed with the following error: A system shutdown has already been scheduled.
    11/24/2009 6:25:32 AM, Error: Service Control Manager [7031] - The Plug and Play service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
    11/24/2009 6:25:32 AM, Error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.

    ==== End Of File ===========================

    If you have any ideas, can you please send them along.
    Thank you,
    John
     
  2. 2009/11/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    How much RAM do you have?

    Print these instructions out.

    NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe

    ***VERY IMPORTANT! Make sure, you update Superantispyware, and Malwarebytes before running the scans.***

    STEP 1. Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes ". If not, update the definitions before scanning by selecting "Check for Updates ". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

    PHYSICALLY DISCONNECT FROM THE INTERNET

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Click Scan your Computer... button.
    * Click Scanning Preferences/Control Center... button.
    * Under General and Startup tab, make sure, Start SUPERAntiSpyware when Windows starts option is UN-checked.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Terminate memory threats before quarantining.
    * Click the Close button to leave the control center screen.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, choose Perform Complete Scan.
    * Click Next to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click OK.
    * Make sure everything has a checkmark next to it and click Next.
    * A notification will appear that Quarantine and Removal is Complete. Click OK and then click the Finish button to return to the main menu.
    * If asked if you want to reboot, click Yes.
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
    * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    RECONNECT TO THE INTERNET

    RESTART COMPUTER!

    STEP 2. Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    ******************************************************************************************
    Due to a bug in Malwarebytes, you may see in MBAM's log following entries:
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\atapi (Rootkit)
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\atapi (Rootkit)
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\atapi (Rootkit)

    DO NOT remove those entries!
    If you do, your computer will become UN-bootable.
    The issue has been fixed in the latest MBAM update, so, it's EXTREMELY important, you update MBAM before you run it.
    ****************************************************************************************

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!

    STEP 3. Download GMER: http://www.gmer.net/files.php, by clicking on Download EXE button.
    Alternative downloads:
    - http://majorgeeks.com/GMER_d5198.html
    - http://www.softpedia.com/get/Interne...ers/GMER.shtml
    Double click on downloaded .exe file, select Rootkit tab and click the Scan button.
    When scan is completed, click Save button, and save the results as gmer.log
    Warning ! Please, do not select the "Show all" checkbox during the scan.
    Post the log to your next reply.

    RESTART COMPUTER

    STEP 4. Download HijackThis:
    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
    by clicking on Download HijackThis Installer
    Install, and run it.
    Post HijackThis log.
    NOTE. If you're using Vista, right click on HijackThis, and click Run as Administrator
    Do NOT attempt to "fix" anything!


    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     

  3. to hide this advert.

  4. 2009/12/01
    JohnDy

    JohnDy Inactive Thread Starter

    Joined:
    2009/11/29
    Messages:
    7
    Likes Received:
    0
    Hello Broni,
    I've got 4gb RAM.
    The log for SUPERAntiSpyware is:
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 11/30/2009 at 07:31 PM

    Application Version : 4.31.1000

    Core Rules Database Version : 4321
    Trace Rules Database Version: 2178

    Scan type : Complete Scan
    Total Scan Time : 01:15:36

    Memory items scanned : 258
    Memory threats detected : 0
    Registry items scanned : 6628
    Registry threats detected : 0
    File items scanned : 202876
    File threats detected : 0

    The log for Malwarebyte:
    Malwarebytes' Anti-Malware 1.41
    Database version: 3264
    Windows 6.0.6002 Service Pack 2

    12/1/2009 2:40:40 AM
    mbam-log-2009-12-01 (02-40-40).txt

    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 317596
    Time elapsed: 2 hour(s), 37 minute(s), 43 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    I ran into an issue with GMER. I went to bed while the scan was in progress. When I got back to the computer there was a window saying the program could not continue with choice of quitting or checking online for a solution. I quit the program and tried to run GMER again. Horrifyingly I got the Blue Screen of Death. Windows has come along way over the years and when I rebooted I was able to view the log of the Blue Screen. That information is:
    Problem signature:
    Problem Event Name: BlueScreen
    OS Version: 6.0.6002.2.2.0.768.2
    Locale ID: 1033

    Additional information about the problem:
    BCCode: 1000008e
    BCP1: C0000005
    BCP2: 8365BD45
    BCP3: 8D064A54
    BCP4: 00000000
    OS Version: 6_0_6002
    Service Pack: 2_0
    Product: 768_1

    Files that help describe the problem:
    C:\Windows\Minidump\Mini120109-01.dmp
    C:\Users\John\AppData\Local\Temp\WER-650180-0.sysdata.xml
    C:\Users\John\AppData\Local\Temp\WER9A8A.tmp.version.txt

    Read our privacy statement:
    http://go.microsoft.com/fwlink/?linkid=50163&clcid=0x0409

    I rebooted and ran GMER again, and this time the scan worked. It's log is:
    GMER 1.0.15.15252 - http://www.gmer.net
    Rootkit scan 2009-12-01 07:15:54
    Windows 6.0.6002 Service Pack 2
    Running: gmer.exe; Driver: C:\Users\John\AppData\Local\Temp\kflyruod.sys


    ---- System - GMER 1.0.15 ----

    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0x92E1FBD0]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcConnectPort [0x92E2152C]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcCreatePort [0x92E21782]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcSendWaitReceivePort [0x92E219FC]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwClose [0x92E20450]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwConnectPort [0x92E20B32]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateEvent [0x92E20F3C]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateFile [0x92E205F8]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateMutant [0x92E20E14]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0x92E1F7D6]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreatePort [0x92E20CD0]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSection [0x92E1F992]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSemaphore [0x92E2106E]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0x92E22CB0]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateThread [0x92E200EE]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateWaitablePort [0x92E20D72]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDebugActiveProcess [0x92E226A2]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDuplicateObject [0x92E23672]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwFsControlFile [0x92E20752]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwLoadDriver [0x92E22734]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwMapViewOfSection [0x92E22D64]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenEvent [0x92E20FDE]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenFile [0x92E204D2]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenMutant [0x92E20EAC]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenProcess [0x92E1FDD6]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenSection [0x92E22CDA]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenSemaphore [0x92E21110]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenThread [0x92E1FCFA]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueryDirectoryObject [0x92E21C3E]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQuerySection [0x92E2307C]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueueApcThread [0x92E229CA]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwReplyPort [0x92E2149A]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0x92E21360]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0x92E22442]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwResumeThread [0x92E23554]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSecureConnectPort [0x92E2086C]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetContextThread [0x92E2030C]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetInformationToken [0x92E21CF2]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetSecurityObject [0x92E2282E]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetSystemInformation [0x92E231BC]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSuspendProcess [0x92E232A0]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSuspendThread [0x92E233C8]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSystemDebugControl [0x92E225CE]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwTerminateProcess [0x92E1FF4E]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwTerminateThread [0x92E1FEA4]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0x92E22F32]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0x92E2002E]
    SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateThreadEx [0x92E201EE]

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntkrnlpa.exe!KeSetEvent + 119 836E985C 4 Bytes [D0, FB, E1, 92] {SAR BL, 0x1; LOOPZ 0xffffffffffffff96}
    .text ntkrnlpa.exe!KeSetEvent + 13D 836E9880 8 Bytes [2C, 15, E2, 92, 82, 17, E2, ...] {SUB AL, 0x15; LOOP 0xffffffffffffff96; ADC BYTE [EDI], -0x1e; XCHG EDX, EAX}
    .text ntkrnlpa.exe!KeSetEvent + 181 836E98C4 4 Bytes [FC, 19, E2, 92] {CLD ; SBB EDX, ESP; XCHG EDX, EAX}
    .text ntkrnlpa.exe!KeSetEvent + 1A9 836E98EC 4 Bytes [50, 04, E2, 92] {PUSH EAX; ADD AL, 0xe2; XCHG EDX, EAX}
    .text ntkrnlpa.exe!KeSetEvent + 1C1 836E9904 4 Bytes [32, 0B, E2, 92] {XOR CL, [EBX]; LOOP 0xffffffffffffff96}
    .text ...
    .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x92004000, 0x1F7AC4, 0xE8000020]

    ---- User code sections - GMER 1.0.15 ----

    ? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] C:\Windows\system32\ntdll.dll time/date stamp mismatch;
    ? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] C:\Windows\system32\kernel32.dll time/date stamp mismatch;
    .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] USER32.dll!SetScrollInfo + 7A8 76EB7980 4 Bytes JMP 33117076
    ? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] C:\Windows\system32\ntdll.dll time/date stamp mismatch;
    ? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] C:\Windows\system32\kernel32.dll time/date stamp mismatch;
    .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] USER32.dll!SetScrollInfo + 7A8 76EB7980 4 Bytes JMP 33117076

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcessHeap] 0115E660
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] 0115E140
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DuplicateHandle] 0115D2A0
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!IsDebuggerPresent] 0115EBE0
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateThread] 0115C260
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 0115BBD0
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetEnvironmentStringsW] 0115BF90
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SetFilePointer] 0115D100
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFileEx] 0115D7C0
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileMappingW] 0115D550
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFile] 0115D740
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!OpenFileMappingW] 0115DC20
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!UnmapViewOfFile] 0115D930
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileType] 0115D450
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FlushViewOfFile] 0115D690
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileSize] 0115D240
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!WriteFile] 0115D0C0
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetACP] 0115E680
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!TerminateProcess] 0115C110
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalAlloc] 0115E3A0
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalLock] 0115E2C0
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalUnlock] 0115E280
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW] 0115C940
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] 0115BA30
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CloseHandle] 0115D340
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] 0115B9A0
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FreeLibrary] 0115BC80
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress] 0115A730
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!ReadFile] 0115CC90
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetVersion] 0115E650
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadIconW] 0115E920
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadCursorW] 0115E8C0
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [USER32.dll!CreateDialogParamW] 0115EB10
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [USER32.dll!DialogBoxParamW] 0115EBB0
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadStringW] 0115E9E0
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA] 0115E5D0
    IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1120] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] 0115E580
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlAllocateHeap] 00270240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlFreeHeap] 002702B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlSizeHeap] 00270320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlReAllocateHeap] 00270390
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlFreeHeap] 00270550
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlAllocateHeap] 002705C0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D10860
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!GetModuleFileNameA] 00D108D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] 00D10940
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] 00D109B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] 00D10A20
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] 00D10A90
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!VirtualFree] 002706A0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!VirtualAlloc] 00270710
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!HeapFree] 002707F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!CreateThread] 00270860
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlFreeHeap] 002708D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlAllocateHeap] 00270940
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] 00D10B00
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] 00D10B70
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!HeapFree] 002709B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] 00D10BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 00D10C50
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetModuleFileNameW] 00D10CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!SetErrorMode] 00D10D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!VirtualFree] 00270B00
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!CreateThread] 00270BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D10DA0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] 00D10E10
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlSizeHeap] 00270C50
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlReAllocateHeap] 00270CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlAllocateHeap] 00270D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlFreeHeap] 00270DA0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 00D10E80
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateThread] 00270E10
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateProcessW] 00D10EF0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetModuleFileNameA] 00D10F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] 75C50550
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 75C505C0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetModuleFileNameW] 75C50630
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] 75C506A0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] 75C50710
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FreeLibrary] 75C50780
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlAllocateHeap] 00270E80
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlFreeHeap] 00270EF0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 75C507F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 75C50860
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] 75C508D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] 75C50940
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] 75C509B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] 75C50A20
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetErrorMode] 75C50F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] 00D20010
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] 00D20080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] 00D200F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] 00D20160
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] 00D201D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!HeapDestroy] 77240780
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!VirtualFree] 772407F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!HeapFree] 77240860
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!VirtualAlloc] 77240940
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetModuleFileNameA] 00D20240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetModuleFileNameW] 00D202B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D20320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW] 00D20390
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateThread] 77240A20
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!VirtualFree] 77240BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!VirtualAlloc] 77240C50
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D204E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 00D20550
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!HeapDestroy] 77240CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateThread] 77240D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] 00D205C0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetModuleFileNameA] 00D20630
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetErrorMode] 00D206A0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] 00D20710
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetModuleFileNameW] 00D20780

    I have to break up the post to three entries. The continuation follows.
     
    Last edited: 2009/12/01
  5. 2009/12/01
    JohnDy

    JohnDy Inactive Thread Starter

    Joined:
    2009/11/29
    Messages:
    7
    Likes Received:
    0
    Part 2:
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] 00D207F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] 00D20860
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!HeapFree] 77240DA0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] 00D208D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!RtlFreeHeap] 77240EF0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] 00D20940
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleFileNameW] 00D209B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!HeapFree] 77240F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] 00280080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleFileNameA] 00D20A20
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D20A90
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 00D20B00
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetErrorMode] 00D20B70
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] 00D20BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] 00D20C50
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] 00D20CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!HeapFree] 00280160
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateThread] 002802B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 00D20D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!HeapDestroy] 00280320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateProcessW] 00D20DA0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!VirtualAlloc] 00280390
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D20E10
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] 00D20E80
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetModuleFileNameW] 00D20EF0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] 00D20F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FreeLibrary] 00D30010
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress] 00D30080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetModuleFileNameA] 00D300F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlFreeHeap] 00280400
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlAllocateHeap] 00280470
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlReAllocateHeap] 002804E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\Secur32.dll [ntdll.dll!RtlAllocateHeap] 77240010
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\Secur32.dll [ntdll.dll!RtlFreeHeap] 77240080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D402B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] 00D40320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] 00D40390
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetModuleFileNameW] 00D40400
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] 00D40470
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] 00D404E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\PSAPI.DLL [KERNEL32.dll!SetUnhandledExceptionFilter] 00D407F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\userenv.dll [ntdll.dll!RtlFreeHeap] 77240080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\userenv.dll [KERNEL32.dll!HeapFree] 772402B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\userenv.dll [KERNEL32.dll!CreateThread] 772401D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\userenv.dll [KERNEL32.dll!SetErrorMode] 00D40BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\userenv.dll [KERNEL32.dll!GetProcAddress] 00D40C50
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\userenv.dll [KERNEL32.dll!FreeLibrary] 00D40CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\userenv.dll [KERNEL32.dll!LoadLibraryA] 00D40D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\userenv.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D40DA0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\userenv.dll [KERNEL32.dll!GetModuleFileNameW] 00D40E10
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\iphlpapi.dll [ntdll.dll!RtlFreeHeap] 77240080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\iphlpapi.dll [ntdll.dll!RtlAllocateHeap] 77240010
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\iphlpapi.dll [KERNEL32.dll!HeapFree] 772402B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\iphlpapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 75C504E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] 75C502B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\iphlpapi.dll [KERNEL32.dll!FreeLibrary] 75C500F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] 75C50240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!GetModuleFileNameA] 75C50160
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 75C504E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!FreeLibrary] 75C500F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!CreateThread] 772401D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] 75C50240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] 75C502B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 75C50390
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!HeapDestroy] 77240240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!GetModuleFileNameW] 75C501D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryW] 75C50400
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!HeapFree] 772402B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 75C504E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!VirtualAlloc] 77240320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!FreeLibrary] 75C500F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] 75C50240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] 75C502B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!CreateThread] 772401D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 75C50390
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetModuleFileNameW] 75C501D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\CRYPT32.dll [ntdll.dll!RtlFreeHeap] 77240080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\CRYPT32.dll [ntdll.dll!RtlAllocateHeap] 77240010
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SAMLIB.dll [ntdll.dll!RtlFreeHeap] 77240080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SAMLIB.dll [KERNEL32.dll!LoadLibraryA] 75C502B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SAMLIB.dll [KERNEL32.dll!FreeLibrary] 75C500F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SAMLIB.dll [KERNEL32.dll!GetProcAddress] 75C50240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\SAMLIB.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 75C504E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\NETAPI32.dll [ntdll.dll!RtlAllocateHeap] 77240010
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\NETAPI32.dll [ntdll.dll!RtlFreeHeap] 77240080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] 75C50400
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] 75C502B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!FreeLibrary] 75C500F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] 75C50240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 75C504E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!GetModuleFileNameA] 75C50160
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!HeapFree] 772402B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!CreateThread] 772401D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\wininet.dll [KERNEL32.dll!LoadLibraryW] 75C50400
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\wininet.dll [KERNEL32.dll!CreateThread] 772401D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\wininet.dll [KERNEL32.dll!SetErrorMode] 75C50470
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\wininet.dll [KERNEL32.dll!GetModuleFileNameA] 75C50160
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\wininet.dll [KERNEL32.dll!HeapFree] 772402B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\wininet.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 75C504E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\wininet.dll [KERNEL32.dll!LoadLibraryExW] 75C50390
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\wininet.dll [KERNEL32.dll!GetProcAddress] 75C50240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\wininet.dll [KERNEL32.dll!LoadLibraryA] 75C502B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\wininet.dll [KERNEL32.dll!FreeLibrary] 75C500F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[1180] @ C:\Windows\system32\wininet.dll [KERNEL32.dll!GetModuleFileNameW] 75C501D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlAllocateHeap] 00170240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlFreeHeap] 001702B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlSizeHeap] 00170320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlReAllocateHeap] 00170390
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlFreeHeap] 00170550
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlAllocateHeap] 001705C0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 004A0860
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!GetModuleFileNameA] 004A08D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] 004A0940
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] 004A09B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] 004A0A20
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] 004A0A90
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!VirtualFree] 001706A0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!VirtualAlloc] 00170710
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!HeapFree] 001707F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!CreateThread] 00170860
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlFreeHeap] 001708D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlAllocateHeap] 00170940
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] 004A0B00
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] 004A0B70
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!HeapFree] 001709B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] 004A0BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 004A0C50
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetModuleFileNameW] 004A0CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!SetErrorMode] 004A0D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!VirtualFree] 00170B00
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!CreateThread] 00170BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 004A0DA0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] 004A0E10
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlSizeHeap] 00170C50
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlReAllocateHeap] 00170CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlAllocateHeap] 00170D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlFreeHeap] 00170DA0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 004A0E80
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateThread] 00170E10
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateProcessW] 004A0EF0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetModuleFileNameA] 004A0F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] 75C50550
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 75C505C0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetModuleFileNameW] 75C50630
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] 75C506A0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] 75C50710
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FreeLibrary] 75C50780
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlAllocateHeap] 00170E80
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlFreeHeap] 00170EF0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 75C507F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 75C50860
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] 75C508D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] 75C50940
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] 75C509B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] 75C50A20
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetErrorMode] 75C50F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] 004B0010
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] 004B0080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] 004B00F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] 004B0160
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] 004B01D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!HeapDestroy] 77240780
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!VirtualFree] 772407F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!HeapFree] 77240860
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!VirtualAlloc] 77240940
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetModuleFileNameA] 004B0240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetModuleFileNameW] 004B02B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 004B0320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW] 004B0390
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateThread] 77240A20
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!VirtualFree] 77240BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!VirtualAlloc] 77240C50
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 004B04E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 004B0550
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!HeapDestroy] 77240CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateThread] 77240D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] 004B05C0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetModuleFileNameA] 004B0630
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetErrorMode] 004B06A0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] 004B0710
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetModuleFileNameW] 004B0780
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] 004B07F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] 004B0860
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!HeapFree] 77240DA0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] 004B08D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!RtlFreeHeap] 77240EF0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] 004B0940
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleFileNameW] 004B09B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!HeapFree] 77240F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] 00180080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleFileNameA] 004B0A20
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 004B0A90
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 004B0B00
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetErrorMode] 004B0B70
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] 004B0BE0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] 004B0C50
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] 004B0CC0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!HeapFree] 00180160
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateThread] 001802B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 004B0D30
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!HeapDestroy] 00180320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateProcessW] 004B0DA0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!VirtualAlloc] 00180390
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 004B0E10
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] 004B0E80
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetModuleFileNameW] 004B0EF0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] 004B0F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FreeLibrary] 004C0010
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress] 004C0080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetModuleFileNameA] 004C00F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlFreeHeap] 00180400
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlAllocateHeap] 00180470
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlReAllocateHeap] 001804E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\Secur32.dll [ntdll.dll!RtlAllocateHeap] 77240010
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\Secur32.dll [ntdll.dll!RtlFreeHeap] 77240080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 005E02B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] 005E0320
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] 005E0390
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetModuleFileNameW] 005E0400
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] 005E0470
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] 005E04E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\PSAPI.DLL [KERNEL32.dll!SetUnhandledExceptionFilter] 005E0B00
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\userenv.dll [ntdll.dll!RtlFreeHeap] 77240080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\userenv.dll [KERNEL32.dll!HeapFree] 772402B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\userenv.dll [KERNEL32.dll!CreateThread] 772401D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\userenv.dll [KERNEL32.dll!SetErrorMode] 005E0EF0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\userenv.dll [KERNEL32.dll!GetProcAddress] 005E0F60
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\userenv.dll [KERNEL32.dll!FreeLibrary] 005F0010
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\userenv.dll [KERNEL32.dll!LoadLibraryA] 005F0080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\userenv.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 005F00F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\userenv.dll [KERNEL32.dll!GetModuleFileNameW] 005F0160
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\NETAPI32.dll [ntdll.dll!RtlAllocateHeap] 77240010
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\NETAPI32.dll [ntdll.dll!RtlFreeHeap] 77240080
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] 75C50400
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] 75C502B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!FreeLibrary] 75C500F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] 75C50240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 75C504E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!GetModuleFileNameA] 75C50160
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!HeapFree] 772402B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!CreateThread] 772401D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!GetModuleFileNameA] 75C50160
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 75C504E0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!FreeLibrary] 75C500F0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!CreateThread] 772401D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] 75C50240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] 75C502B0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 75C50390
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!HeapDestroy] 77240240
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!GetModuleFileNameW] 75C501D0
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryW] 75C50400
    IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2800] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!HeapFree] 772402B0
     
  6. 2009/12/01
    JohnDy

    JohnDy Inactive Thread Starter

    Joined:
    2009/11/29
    Messages:
    7
    Likes Received:
    0
    Part 3:
    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \Driver\tdx \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
    AttachedDevice \Driver\tdx \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
    AttachedDevice \Driver\tdx \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
    AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    ---- EOF - GMER 1.0.15 ----

    I can make a couple of guesses why the scan would fail. Kaspersky does a scan of the computer overnight and I'm not sure if the power settings would have shut the hard drives off.

    HijackThis ran smoothly. It's log is:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:23:23 AM, on 12/1/2009
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v8.00 (8.00.6001.18828)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Dell\MediaDirect\PCMService.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files\Genie-Soft\GBMHome8\GBMAgent.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Dell Remote Access\ezi_ra.exe
    C:\Program Files\PolderbitS\Recorder\Driver\PBDriverMonitor_uk.exe
    C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\SearchFilterHost.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe "
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe "
    O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe "
    O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe "
    O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
    O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
    O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
    O4 - HKLM\..\Run: [FileZilla Server Interface] "C:\Program Files\FileZilla Server\FileZilla Server Interface.exe "
    O4 - HKLM\..\Run: [GBMHome8Agent] "C:\Program Files\Genie-Soft\GBMHome8\GBMAgent.exe "
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe "
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe "
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe "
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe "
    O4 - HKLM\..\Run: [avp] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe "
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\windows sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [GBMHome8Agent] "C:\Program Files\Genie-Soft\GBMHome8\GBMAgent.exe "
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
    O4 - Global Startup: Dell Remote Access.lnk = ?
    O4 - Global Startup: PolderbitS Audio Driver Monitor.lnk = C:\Program Files\PolderbitS\Recorder\Driver\PBDriverMonitor_uk.exe
    O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
    O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
    O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
    O13 - Gopher Prefix:
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - http://support.dell.com/systemprofiler/SysProExe.CAB
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~2\kloehk.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
    O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe
    O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
    O23 - Service: Advanced Networking Service (hnmsvc) - Dell Inc. - c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

    --
    End of file - 9946 bytes


    Another issue I remembered was Acrobat and printing. When trying to print a PDF the system takes a good 20 - 30 seconds to send the information to the printer. After you get back to me, I'm thinking I might uninstall Acrobat and the Brother printer and try reinstalling them.
    Thank you for your help!
    John
     
  7. 2009/12/01
    JohnDy

    JohnDy Inactive Thread Starter

    Joined:
    2009/11/29
    Messages:
    7
    Likes Received:
    0
    duplicate
     
    Last edited: 2009/12/01
  8. 2009/12/01
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Please, never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    NOTE. If Combofix asks you to install Recovery Console, please allow it.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    • Double click on combofix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  9. 2009/12/04
    JohnDy

    JohnDy Inactive Thread Starter

    Joined:
    2009/11/29
    Messages:
    7
    Likes Received:
    0
    Broni,
    I ran into some major issues. I couldn't get the computer to boot back up, so I had to send it to Dell to see what's up. Thank you for your help.
    John
     
  10. 2009/12/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I see. Let us know, what the outcome is...
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.