problem luder i jos neki

1

problem luder i jos neki

offline
  • Pridružio: 07 Avg 2006
  • Poruke: 1182
  • Gde živiš: Fili Davydkovo, Moscow, Russia

Logfile of HijackThis v1.99.1
Scan saved at 15:02:41, on 03.02.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAP.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\dumprep.exe
C:\Documents and Settings\User\Рабочий стол\Hujack\HijackThis.exe
C:\WINDOWS\system32\dwwin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Ссылки
O2 - BHO: Helper Class - {00D13CE9-1879-41bd-B8A3-EA3CB1BD01BC} - C:\WINDOWS\system32\helper.dll
O2 - BHO: XY33 Popup Blocker - {4B5A7560-16C6-4063-86D3-000000000002} - C:\Program Files\system102\system102.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [EPSON Stylus C67 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAP.EXE /P23 "EPSON Stylus C67 Series" /O6 "USB001" /M "Stylus C67"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [System64] C:\WINDOWS\system32\inet.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE
O8 - Extra context menu item: &Экспорт в Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {4B5A7560-16C6-4063-86D3-000000000003} - C:\Program Files\system102\system102.dll (file missing)
O9 - Extra 'Tools' menuitem: Блокировка всплывающих окон - {4B5A7560-16C6-4063-86D3-000000000003} - C:\Program Files\system102\system102.dll (file missing)
O9 - Extra button: Справочные материалы - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{E32440CC-00DE-47AD-A0E1-57A3CCD59F82}: NameServer = 217.26.0.2,217.26.1.2
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 194.67.57.104
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 194.67.57.104
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 194.67.57.104
O20 - Winlogon Notify: xmm13g - C:\WINDOWS\SYSTEM32\xmm13g.dll
O21 - SSODL: VStorage - {5FBF9BF0-4191-4CBF-844D-89BC2B8A7E89} - swmclip.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Журнал событий (Eventlog) - Корпорация Майкрософт - C:\WINDOWS\system32\services.exe
O23 - Service: Служба COM записи компакт-дисков IMAPI (ImapiService) - Корпорация Майкрософт - C:\WINDOWS\system32\imapi.exe
O23 - Service: Plug and Play (PlugPlay) - Корпорация Майкрософт - C:\WINDOWS\system32\services.exe
O23 - Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) - Корпорация Майкрософт - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Адаптер производительности WMI (WmiApSrv) - Корпорация Майкрософт - C:\WINDOWS\system32\wbem\wmiapsrv.exe

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Uploaduj mi na http://www.mycity.rs/ambulanta-upload.php sledece:
C:\WINDOWS\system32\inet.exe
C:\WINDOWS\SYSTEM32\xmm13g.dll


Cemu ti sluzi sledeci program:
C:\Program Files\system102
Pise da je neki pop-up stoper. Jesi li ga ti instalirao ili ne?

Opisi simptome koji se javljaju.

offline
  • Pridružio: 07 Avg 2006
  • Poruke: 1182
  • Gde živiš: Fili Davydkovo, Moscow, Russia

sad sam stigao ovde jer su me zvali...avast prijavljuje generic.backdoor.trojan i jos nesto...ne moze nista da se uradi ovako...sav sam konfuzan...nema system propertis, ne moze da se udje u administrative tools/upravljanje kompjuterom(kad pokusam da udjem avast izbaci mmc.exe infected win32:Luder-F), znaci kompjuter se raspada....spybot isto...naso je ovde par hiljada infekcija(luder i backdoor.nesto)....za ovo ne znam sta je(system 102) nisam ovde nista radio...

Dopuna: 03 Feb 2007 13:30

ova dva fajla ne mogu da nadjem...ponovo cu staviti log...mozda je spybots&d nesto odradio, ali isto je stanje....

Dopuna: 03 Feb 2007 13:32

Logfile of HijackThis v1.99.1
Scan saved at 15:33:21, on 03.02.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAP.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\User\Рабочий стол\Hujack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Ссылки
O2 - BHO: XY33 Popup Blocker - {4B5A7560-16C6-4063-86D3-000000000002} - C:\Program Files\system102\system102.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [EPSON Stylus C67 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAP.EXE /P23 "EPSON Stylus C67 Series" /O6 "USB001" /M "Stylus C67"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [System64] C:\WINDOWS\system32\inet.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE
O8 - Extra context menu item: &Экспорт в Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {4B5A7560-16C6-4063-86D3-000000000003} - C:\Program Files\system102\system102.dll (file missing)
O9 - Extra 'Tools' menuitem: Блокировка всплывающих окон - {4B5A7560-16C6-4063-86D3-000000000003} - C:\Program Files\system102\system102.dll (file missing)
O9 - Extra button: Справочные материалы - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{E32440CC-00DE-47AD-A0E1-57A3CCD59F82}: NameServer = 217.26.0.2,217.26.1.2
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 194.67.57.104
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 194.67.57.104
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 194.67.57.104
O20 - Winlogon Notify: xmm13g - C:\WINDOWS\SYSTEM32\xmm13g.dll
O21 - SSODL: VStorage - {5FBF9BF0-4191-4CBF-844D-89BC2B8A7E89} - swmclip.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Журнал событий (Eventlog) - Корпорация Майкрософт - C:\WINDOWS\system32\services.exe
O23 - Service: Служба COM записи компакт-дисков IMAPI (ImapiService) - Корпорация Майкрософт - C:\WINDOWS\system32\imapi.exe
O23 - Service: Plug and Play (PlugPlay) - Корпорация Майкрософт - C:\WINDOWS\system32\services.exe
O23 - Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) - Корпорация Майкрософт - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Адаптер производительности WMI (WmiApSrv) - Корпорация Майкрософт - C:\WINDOWS\system32\wbem\wmiapsrv.exe






ukljucio sam prikazivanje hidden files, na desktopu je ludnica....ne mogu screen shot da uradim iz istih razloga...

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Da te ne uplasim, ali je teska infekcija. Imas li dosta vremena da ovo resavas?
Imamo posla sa rootkitom pod broj 1.

Preuzmi fajl gmer.zip sa ovog linka i sačuvaj na Desktop-u.
Raspakuj ga u neki folder.
Dupli klik na gmer.exe za početak: Izaberi Rootkit Tab na vrhu.
Klikni na Scan.
Kada je skeniranje završeno, klik na Copy dugme ispod - ovo će sačuvati to u Clipboard.
Iskoristi opciju Paste u Notepad-u da bi to prebacio u tekst i sačuvaj. (npr file 1)
Ponovi ovo isto sa Autostart Tab-om. Sačuvaj kao npr file 2


Iskopiraj nam ovde sadrzaj oba tekst fajla.

offline
  • Pridružio: 07 Avg 2006
  • Poruke: 1182
  • Gde živiš: Fili Davydkovo, Moscow, Russia

sad ponovo nisam tamo jer sam razapet na dve strane, bicu tamo ovih dana pa cu se javiti...interesuje me nesto, posto gomila win fajlova fali, da li je uopste moguce resiti ovo antibioticima ili mi ne gine reinstalacija posle toga(jos jednom da ti napomenem, kad hocu u sys propertis kaze da run32.dll is mising, hocu paint, takodje missing, tako za gomilu stvari)....

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Probacemo da sredimo bez reinstalacije ukoliko je moguce, preko SystemFileProtection.

offline
  • Pridružio: 07 Avg 2006
  • Poruke: 1182
  • Gde živiš: Fili Davydkovo, Moscow, Russia

ok, thx, javljam se cim budem tamo i ako ti budes ovde....

offline
  • Pridružio: 07 Avg 2006
  • Poruke: 1182
  • Gde živiš: Fili Davydkovo, Moscow, Russia

GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2007-02-06 11:33:39
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.12 ----

SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \??\C:\WINDOWS\system32\mmx19g.sys ZwQueryDirectoryFile
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess

---- User code sections - GMER 1.0.12 ----

.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE[148] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE[148] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE[148] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE[148] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE[148] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE[148] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, 7F, E2 ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE[148] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE[148] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE[148] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE[180] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE[180] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE[180] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE[180] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE[180] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE[180] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, 7F, E2 ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE[180] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE[180] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE[180] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[552] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[552] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[552] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[552] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[552] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[552] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, 7F, E2 ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[552] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[552] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[552] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\WINDOWS\SYSTEM32\CSRSS.EXE[572] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\SYSTEM32\CSRSS.EXE[572] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\SYSTEM32\CSRSS.EXE[572] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\WINDOWS\SYSTEM32\CSRSS.EXE[572] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\SYSTEM32\CSRSS.EXE[572] KERNEL32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\SYSTEM32\CSRSS.EXE[572] KERNEL32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\SYSTEM32\CSRSS.EXE[572] KERNEL32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\SYSTEM32\CSRSS.EXE[572] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\WINDOWS\SYSTEM32\WINLOGON.EXE[596] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\SYSTEM32\WINLOGON.EXE[596] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\SYSTEM32\WINLOGON.EXE[596] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\SYSTEM32\WINLOGON.EXE[596] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\SYSTEM32\WINLOGON.EXE[596] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\SYSTEM32\WINLOGON.EXE[596] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\WINDOWS\SYSTEM32\WINLOGON.EXE[596] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\SYSTEM32\WINLOGON.EXE[596] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\WINDOWS\SYSTEM32\SERVICES.EXE[640] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\SYSTEM32\SERVICES.EXE[640] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\SYSTEM32\SERVICES.EXE[640] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\SYSTEM32\SERVICES.EXE[640] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\SYSTEM32\SERVICES.EXE[640] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\SYSTEM32\SERVICES.EXE[640] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\WINDOWS\SYSTEM32\SERVICES.EXE[640] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\SYSTEM32\SERVICES.EXE[640] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\WINDOWS\SYSTEM32\LSASS.EXE[652] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\SYSTEM32\LSASS.EXE[652] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\SYSTEM32\LSASS.EXE[652] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\SYSTEM32\LSASS.EXE[652] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\SYSTEM32\LSASS.EXE[652] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\SYSTEM32\LSASS.EXE[652] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\WINDOWS\SYSTEM32\LSASS.EXE[652] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\SYSTEM32\LSASS.EXE[652] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[796] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[796] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[796] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[796] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[796] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[796] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[796] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE[796] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[812] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[812] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[812] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[812] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[812] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[812] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[812] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[812] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[872] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[872] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[872] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[872] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[872] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[872] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[872] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[872] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[932] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[932] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[932] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[932] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[932] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[932] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[932] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[932] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[980] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[980] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[980] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[980] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[980] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[980] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[980] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[980] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[1120] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[1120] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[1120] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[1120] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[1120] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[1120] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[1120] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\SYSTEM32\SVCHOST.EXE[1120] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\WINDOWS\SYSTEM32\SPOOLSV.EXE[1252] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\SYSTEM32\SPOOLSV.EXE[1252] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\SYSTEM32\SPOOLSV.EXE[1252] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\SYSTEM32\SPOOLSV.EXE[1252] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\SYSTEM32\SPOOLSV.EXE[1252] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\SYSTEM32\SPOOLSV.EXE[1252] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\WINDOWS\SYSTEM32\SPOOLSV.EXE[1252] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\WINDOWS\SYSTEM32\SPOOLSV.EXE[1252] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\EXPLORER.EXE[1328] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\EXPLORER.EXE[1328] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\EXPLORER.EXE[1328] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\EXPLORER.EXE[1328] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\EXPLORER.EXE[1328] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\EXPLORER.EXE[1328] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, 7F, E2 ]
.text C:\WINDOWS\EXPLORER.EXE[1328] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\WINDOWS\EXPLORER.EXE[1328] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\WINDOWS\EXPLORER.EXE[1328] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE[1404] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE[1404] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE[1404] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE[1404] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE[1404] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE[1404] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE[1404] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE[1404] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE[1416] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE[1416] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE[1416] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE[1416] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE[1416] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE[1416] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE[1416] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE[1416] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE[1464] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE[1464] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE[1464] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE[1464] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE[1464] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE[1464] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE[1464] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE[1464] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGUPSVC.EXE[1480] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGUPSVC.EXE[1480] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGUPSVC.EXE[1480] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGUPSVC.EXE[1480] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGUPSVC.EXE[1480] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGUPSVC.EXE[1480] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGUPSVC.EXE[1480] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGUPSVC.EXE[1480] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE[1492] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE[1492] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE[1492] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE[1492] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE[1492] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE[1492] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE[1492] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE[1492] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\PROGRAM FILES\SPYWARE DOCTOR\SDHELP.EXE[1636] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRAM FILES\SPYWARE DOCTOR\SDHELP.EXE[1636] user32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\PROGRAM FILES\SPYWARE DOCTOR\SDHELP.EXE[1636] user32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRAM FILES\SPYWARE DOCTOR\SDHELP.EXE[1636] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMAGENT.EXE[1784] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMAGENT.EXE[1784] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMAGENT.EXE[1784] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMAGENT.EXE[1784] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMAGENT.EXE[1784] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMAGENT.EXE[1784] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMAGENT.EXE[1784] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMAGENT.EXE[1784] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE[1856] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE[1856] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE[1856] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE[1856] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE[1856] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE[1856] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, 7F, E2 ]
.text C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE[1856] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE[1856] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE[1856] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMTRAY.EXE[1984] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMTRAY.EXE[1984] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMTRAY.EXE[1984] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMTRAY.EXE[1984] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMTRAY.EXE[1984] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMTRAY.EXE[1984] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, 7F, E2 ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMTRAY.EXE[1984] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMTRAY.EXE[1984] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMTRAY.EXE[1984] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_FATIAAP.EXE[1992] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_FATIAAP.EXE[1992] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_FATIAAP.EXE[1992] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_FATIAAP.EXE[1992] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_FATIAAP.EXE[1992] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_FATIAAP.EXE[1992] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, 7F, E2 ]
.text C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_FATIAAP.EXE[1992] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_FATIAAP.EXE[1992] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_FATIAAP.EXE[1992] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHDISP.EXE[2004] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHDISP.EXE[2004] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHDISP.EXE[2004] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHDISP.EXE[2004] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHDISP.EXE[2004] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHDISP.EXE[2004] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, 7F, E2 ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHDISP.EXE[2004] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHDISP.EXE[2004] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHDISP.EXE[2004] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE[2212] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE[2212] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE[2212] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE[2212] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE[2212] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE[2212] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, 7F, E2 ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE[2212] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE[2212] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE[2212] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE[2220] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE[2220] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE[2220] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE[2220] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE[2220] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE[2220] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, 7F, E2 ]
.text C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE[2220] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE[2220] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE[2220] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\SYSTEM32\CTFMON.EXE[2248] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\SYSTEM32\CTFMON.EXE[2248] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\SYSTEM32\CTFMON.EXE[2248] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\SYSTEM32\CTFMON.EXE[2248] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\SYSTEM32\CTFMON.EXE[2248] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\SYSTEM32\CTFMON.EXE[2248] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, 7F, E2 ]
.text C:\WINDOWS\SYSTEM32\CTFMON.EXE[2248] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\WINDOWS\SYSTEM32\CTFMON.EXE[2248] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\WINDOWS\SYSTEM32\CTFMON.EXE[2248] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE[2260] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE[2260] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 0E, 5F ]
.text C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE[2260] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE[2260] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE[2260] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE[2260] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, 7F, E2 ]
.text C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE[2260] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 11, 5F ]
.text C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE[2260] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 19, 5F ]
.text C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE[2260] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 15, 5F ]
.text C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE[2416] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE[2416] kernel32.dll!FreeLibrary + 15 7C80AA7B 4 Bytes [ BD, 55, 7F, E2 ]
.text C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE[2416] USER32.dll!SetWindowsHookExW 77D5E621 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE[2416] USER32.dll!SetWindowsHookExA 77D602B2 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE[2416] GDI32.dll!Escape 77F27FBB 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!NlsMbOemCodePageTag + FFF84FE8 7C901000 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlEnterCriticalSection + 7 7C90100C 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlEnterCriticalSection + F 7C901014 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlEnterCriticalSection + 24 7C901029 4 Bytes [ 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlEnterCriticalSection + 29 7C90102E 3 Bytes [ 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlEnterCriticalSection + 30 7C901035 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlLeaveCriticalSection + 17 7C901104 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlLeaveCriticalSection + 1D 7C90110A 4 Bytes [ 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlLeaveCriticalSection + 22 7C90110F 4 Bytes [ 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlLeaveCriticalSection + 2A 7C901117 3 Bytes [ 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlLeaveCriticalSection + 31 7C90111E 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlTryEnterCriticalSection + E 7C901139 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlTryEnterCriticalSection + 1B 7C901146 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlTryEnterCriticalSection + 25 7C901150 2 Bytes [ 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlTryEnterCriticalSection + 2A 7C901155 2 Bytes [ 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlTryEnterCriticalSection + 2D 7C901158 3 Bytes [ 00, 00, 00 ]
.text ...
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!LdrInitializeThunk + F 7C90118D 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!LdrInitializeThunk + 32 7C9011B0 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlActivateActivationContextUnsafeFast + D 7C9011C2 4 Bytes [ 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlActivateActivationContextUnsafeFast + 13 7C9011C8 9 Bytes [ 5C, 41, 32, 40, 5C, 41, 32, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlActivateActivationContextUnsafeFast + 1E 7C9011D3 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlActivateActivationContextUnsafeFast + 26 7C9011DB 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlActivateActivationContextUnsafeFast + 2D 7C9011E2 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlDeactivateActivationContextUnsafeFast + 2 7C9011FC 40 Bytes [ D1, 93, 6D, FF, D1, 93, 6D, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlDeactivateActivationContextUnsafeFast + 2C 7C901226 4 Bytes [ 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlDeactivateActivationContextUnsafeFast + 31 7C90122B 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!DbgUserBreakPoint + 12 7C90124B 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!NtCurrentTeb + 6 7C901256 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlInitString + 14 7C901270 16 Bytes [ 8B, 75, 69, FF, 8B, 75, 69, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlInitString + 25 7C901281 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlInitString + 2C 7C901288 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlInitString + 38 7C901294 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlInitAnsiString + F 7C9012A8 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlInitAnsiString + 25 7C9012BE 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlInitAnsiString + 2C 7C9012C5 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlInitAnsiString + 38 7C9012D1 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlInitUnicodeString + F 7C9012E5 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlInitUnicodeString + 28 7C9012FE 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlInitUnicodeString + 2F 7C901305 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!RtlInitUnicodeString + 3C 7C901312 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_CIcos + B 7C901322 2 Bytes [ 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_CIcos + 10 7C901327 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!cos + 9 7C901334 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!cos + 2D 7C901358 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!cos + 33 7C90135E 2 Bytes [ 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!cos + 38 7C901363 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!cos + 43 7C90136E 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_CIlog + 41 7C901414 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_CIlog + 51 7C901424 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_CIlog + 57 7C90142A 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_CIlog + 62 7C901435 4 Bytes [ 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_CIlog + 67 7C90143A 1 Byte [ 00 ]
.text ...
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_CIpow + 15 7C9014CC 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_CIpow + 22 7C9014D9 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_CIpow + 36 7C9014ED 2 Bytes [ 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_CIpow + 39 7C9014F0 60 Bytes [ EE, AF, 7A, FF, D1, 93, 6D, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_CIpow + 76 7C90152D 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!sin + 2D 7C90170C 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!sin + 33 7C901712 2 Bytes [ 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!sin + 38 7C901717 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!sin + 43 7C901722 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!sin + 5E 7C90173D 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_CIsqrt + B 7C901789 2 Bytes [ 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_CIsqrt + 10 7C90178E 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!sqrt + 9 7C90179B 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!sqrt + 21 7C9017B3 1 Byte [ 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!sqrt + 25 7C9017B7 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!sqrt + 31 7C9017C3 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!sqrt + 37 7C9017C9 2 Bytes [ 00, 00 ]
.text ...
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_alldiv + 19 7C901856 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_alldiv + 35 7C901872 110 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_alldiv + A4 7C9018E1 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_alldiv + AA 7C9018E7 32 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_alldvrm + 1C 7C901908 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_alldvrm + 38 7C901924 140 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_alldvrm + C5 7C9019B1 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_alldvrm + D9 7C9019C5 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_alldvrm + DF 7C9019CB 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_allmul + 19 7C9019E9 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_allmul + 34 7C901A04 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_alloca_probe + 2 7C901A0B 1 Byte [ 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_alloca_probe + 5 7C901A0E 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_alloca_probe + 10 7C901A19 2 Bytes [ 00, 00 ]
.text C:\Program Files\Alwil Software\Avast4\setup\avast.setup[2668] ntdll.dll!_alloca_probe + 13 7C901A1C 9 Byt

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Skini sledeci program i instaliraj ga:
http://users.telenet.be/marcvn/tools/haxfix.exe

Startuj i odaberi opciju:
2. Run auto-fix

Zatrazice ti restart.

Postavi nam ovde log fajl c:\haxfix.log koji bi trebao da se automatski pojavi na ekranu posle restarta.

Nakon toga, skeniraj ponovo HJT-om, selektuj polje ispred linije
O4 - HKLM\..\Run: [System64] C:\WINDOWS\system32\inet.exe
I klikni na Fix Checked.

Na disku je potrebno naci fajl C:\WINDOWS\system32\inet.exe, koji ces za sada samo da premestis na neko drugo mesto (ZIP-uj ga, i stavi na sigurno mesto, a original obrisi).

Skeniraj ponovo HJT-om i postavi svez log.

offline
  • Pridružio: 07 Avg 2006
  • Poruke: 1182
  • Gde živiš: Fili Davydkovo, Moscow, Russia

HAXFIX logfile - by Marckie

version 4.37
06.02.2007 12:05:29,79

--- Auto Haxdoorfix ---


searching for files:


searching for services....
service xmm13g found
[SWSC] DeleteService SUCCESS
service mmx19g found
[SWSC] DeleteService SUCCESS


--- Goldunfix ---


searching for files:


checking iexplore.exe
iexplore.exe is not infected

searching for SSODLkeys:
no SSODLkeys found

searching for notifykeys:
no notifykeys found

searching for services:
no services found


.....rebooting the computer.....


searching for ssodlkeys

not needed


searching for notifykeys

notifykey xmm13g not found


searching for services

service xmm13g not found
service mmx19g not found


searching for safeboot services

safeboot service xmm13g.sys not found
safeboot service mmx19g.sys not found


searching for files

xmm13g.dll exists
deleting xmm13g.dll
xmm13g.dll has been deleted

mmx19g.sys exists
deleting mmx19g.sys
mmx19g.sys has been deleted


checking for other files

qz.dll exists
deleting qz.dll
qz.dll has been deleted

qz.sys exists
deleting qz.sys
qz.sys has been deleted

aszzxewaqo.vb exists
deleting aszzxewaqo.vb
aszzxewaqo.vb has been deleted

wa114.ini exists
deleting wa114.ini
wa114.ini has been deleted


checking for a3d files

ps.a3d
deleting a3d files
a3d files are deleted


Finished

Dopuna: 06 Feb 2007 10:17

da li prvo da selektujem i fix, ili prvo da nadjem fajl da ga sklonim pa onda fix...

26 Feb 2007 23:25 bobby Zaključavanje topica Razlog: Javiti se na PP ukoliko je potrebno otkljucavanje teme  
Ko je trenutno na forumu
 

Ukupno su 977 korisnika na forumu :: 43 registrovanih, 8 sakrivenih i 926 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., amaterSRB, antonije64, bigfoot, CikaKURE, Dimitrise93, Djokislav, DonRumataEstorski, dushan, Excalibur13, FOX, Georgius, goxin, hyla, Ivica1102, Karla, kjkszpj, krkalon, Krvava Devetka, kunktator, Lošmi, Matija, mercedesamg, MilosKop, miodrag, naki011, nebojsag, opt1, Panonsky, procesor, rasok, Sokic, Srle993, Stanlio, Steeeefan, stegonosa, Trpe Grozni, vobo, wizzardone, x9, zeo, zillbg, 79693