Help - Search - Members - Calendar
Full Version: hijackthis log
Lavasoft Support Forums > Archived Topics > Archives: Resolved/Inactive Topics > Resolved/Inactive HijackThis Logs
nickhamer
I don't seem to be able to shift this worm, whihc redirects me when i search from google.

Adaware picked it up as: Win32.Toolbar.MegaSearch

...and supposedly removed it, but I'm still having the same problem.

I'd really appreciate any help



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:12:23, on 05/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16915)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.skybroadband.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided By Sky Broadband
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [] C:\Program Files\Mozilla Firefox\firefox.exe http://www.symantec.com/techsupp/servlet/P...00001e.00000079
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} (HidInputMonitorX Control) - file://D:\components\hidinputmonitorx.ocx
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} (A9Helper.A9) - file://D:\components\A9.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1128346550328
O16 - DPF: {7030CC6C-1A88-4591-BB5A-651B9F7F0C30} (WMVHDRatingCtrl Class) - file://D:\components\wmvhdrating.ocx
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://8.10.120.42/activex/AMC.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 10708 bytes
Blade81
Hi there,

Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    1. DDS.txt
    2. Attach.txt
  • Save both reports to your desktop. Post them back to your topic.

  • Download GMER here by clicking download exe -button and then saving it your desktop:
    • Double-click .exe that you downloaded
    • Click rootkit-tab and then scan.
    • Don't check
      Show All
      box while scanning in progress!
    • When scanning is ready, click Copy.
    • This copies log to clipboard
    • Post log in your reply.
    nickhamer
    Hi,

    Thanks very much for your help on this.

    I actually think I might have shifted this, I did all of this:

    http://vnboards.ign.com/pc_generalhardware...22497/111485628

    ...and although I now get a "rundll" error message on startup, at least I don't get redirected everytime I search google.

    I would like to be sure that I have a clean system, and remove anything that would cause me problems though, so I'd appreciate the help... My DDS logs as requested are attached, and the GMER log is here:

    GMER 1.0.15.15220 - http://www.gmer.net
    Rootkit scan 2009-11-11 10:05:51
    Windows 5.1.2600 Service Pack 3
    Running: w831eee9.exe; Driver: C:\DOCUME~1\PCPMED~1\LOCALS~1\Temp\kxtdqpoc.sys


    ---- User code sections - GMER 1.0.15 ----

    .text C:\WINDOWS\system32\SearchIndexer.exe[1008] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\System32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!GetPixel] [660337F1] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!SetPixel] [66033856] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [6603311B] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowPlacement] [66603F30] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [660330E6] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!CallWindowProcW] [66604121] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [660330E6] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [6603311B] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongA] [66603E7C] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CallWindowProcW] [66604121] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CallWindowProcA] [666040F4] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CallWindowProcW] [66604121] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\System32\DSentry.exe[304] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!GetPixel] [660337F1] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!SetPixel] [66033856] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [6603311B] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowPlacement] [66603F30] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [660330E6] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [660330E6] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [6603311B] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongA] [66603E7C] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\PROGRA~1\AVG\AVG9\avgtray.exe[308] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [660330E6] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [6603311B] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongA] [66603E7C] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\shell32.dll [GDI32.dll!GetPixel] [660337F1] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\shell32.dll [GDI32.dll!SetPixel] [66033856] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\shell32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\shell32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\shell32.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TrackPopupMenuEx] [6603311B] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetWindowPlacement] [66603F30] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TrackPopupMenu] [660330E6] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\wininet.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\wininet.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!SetWindowLongA] [66603E7C] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\netapi32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\netapi32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2332] @ C:\WINDOWS\system32\psapi.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!GetPixel] [660337F1] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!SetPixel] [66033856] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [6603311B] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowPlacement] [66603F30] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [660330E6] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [660330E6] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [6603311B] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongA] [66603E7C] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[2380] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!GetPixel] [660337F1] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!SetPixel] [66033856] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [6603311B] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SendMessageW] [66033153] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowPlacement] [66603F30] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [660330E6] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [660330E6] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [6603311B] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongA] [66603E7C] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SendMessageW] [66033153] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SendMessageW] [66033153] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!SendMessageW] [66033153] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!SetWindowLongA] [66603E7C] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Program Files\Mozilla Firefox\firefox.exe[3316] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!GetPixel] [660337F1] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!SetPixel] [66033856] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [6603311B] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowPlacement] [66603F30] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [660330E6] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [660330E6] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [6603311B] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongA] [66603E7C] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\Documents and Settings\PCP Media\My Documents\Downloads\w831eee9.exe[3568] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\Explorer.EXE [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\Explorer.EXE [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\Explorer.EXE [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\Explorer.EXE [USER32.dll!SetWindowPlacement] [66603F0E] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\Explorer.EXE [USER32.dll!MoveWindow] [66603F52] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\Explorer.EXE [USER32.dll!GetWindowPlacement] [66603F30] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\Explorer.EXE [USER32.dll!LoadImageW] [66032861] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\Explorer.EXE [USER32.dll!CallWindowProcW] [66604121] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\Explorer.EXE [USER32.dll!SendMessageW] [66033153] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\Explorer.EXE [USER32.dll!TrackPopupMenuEx] [6603311B] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\Explorer.EXE [USER32.dll!TrackPopupMenu] [660330E6] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\Explorer.EXE [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\Explorer.EXE [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\Explorer.EXE [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CallWindowProcW] [66604121] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SendMessageW] [66033153] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [660330E6] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [6603311B] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!LoadImageW] [66032861] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SendMessageW] [66033153] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CallWindowProcW] [66604121] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CallWindowProcA] [666040F4] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!SendMessageW] [66033153] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SizeofResource] [660306AF] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FindResourceW] [6603278D] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadResource] [66030772] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [660301DB] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [6603311B] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!LoadStringW] [66030777] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!LoadImageW] [66032861] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SendMessageW] [66033153] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowPlacement] [66603F30] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [660330E6] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!CallWindowProcW] [66604121] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [660330CD] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [66033070] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\ws2_32.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)
    IAT C:\WINDOWS\Explorer.EXE[3668] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [66033076] C:\Program Files\AlienGUIse\wblind.dll (WindowBlinds/Stardock Corporation)

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

    Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
    Device rdpdr.sys (Microsoft RDP Device redirector/Microsoft Corporation)
    Device B3DEED20
    Device B3E06631

    AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    ---- Registry - GMER 1.0.15 ----

    Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{86FE59E1-7380-2D72-FFF9-BEB7213926FB}

    ---- EOF - GMER 1.0.15 ----


    Thanks again in advance

    NH
    Blade81
    Hi,

    ComboFix is not a removal tool for general use. It should be used under supervision of trained advisor only.

    Look for c:\ComboFix.txt file and post back its contents, please.
    nickhamer
    Hi,

    Thank you, combofix log:

    ComboFix 09-11-05.01 - PCP Media 06/11/2009 9:40.1.2 - NTFSx86
    Running from: c:\documents and settings\PCP Media\My Documents\Downloads\ComboFix.exe
    * Created a new restore point

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\PCP Media\Application Data\EurekaLog
    c:\documents and settings\PCP Media\My Documents\REG backup.reg
    c:\documents and settings\PCP Media\My Documents\regbackup.reg
    c:\windows\patch.exe
    c:\windows\run.log
    c:\windows\system32\_000006_.tmp.dll
    c:\windows\system32\_000008_.tmp.dll
    c:\windows\system32\installer.exe
    c:\windows\system32\nfr.assembly
    c:\windows\system32\nfr.gpref

    Infected copy of c:\windows\System32\DRIVERS\atapi.sys was found and disinfected
    Restored copy from - Kitty ate it tongue.gif
    .
    ((((((((((((((((((((((((( Files Created from 2009-10-06 to 2009-11-06 )))))))))))))))))))))))))))))))
    .

    2009-11-05 14:03 . 2009-11-05 14:03 -------- d-----w- c:\documents and settings\PCP Media\Application Data\Malwarebytes
    2009-11-05 14:03 . 2009-09-10 14:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-11-05 14:03 . 2009-11-05 14:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-11-05 14:03 . 2009-09-10 14:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-11-05 14:03 . 2009-11-05 15:44 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-11-05 10:08 . 2009-11-05 10:08 -------- d-----w- c:\program files\ERUNT
    2009-11-04 20:10 . 2009-11-04 16:24 15880 ----a-w- c:\windows\system32\lsdelete.exe
    2009-11-04 15:58 . 2009-11-04 15:58 17632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\WSCUpdate.dll
    2009-11-04 12:07 . 2009-09-15 11:54 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2009-11-04 12:07 . 2009-09-15 11:54 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2009-11-04 12:07 . 2009-09-15 11:53 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
    2009-11-04 12:07 . 2009-09-15 11:53 97480 ----a-w- c:\windows\system32\AvastSS.scr
    2009-11-04 12:07 . 2009-09-15 11:56 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
    2009-11-04 12:07 . 2009-09-15 11:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
    2009-11-04 12:07 . 2009-09-15 11:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2009-11-04 12:07 . 2009-09-15 11:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2009-11-04 12:07 . 2009-09-15 11:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe
    2009-11-04 12:07 . 2009-11-04 12:07 -------- d-----w- c:\program files\Alwil Software
    2009-11-03 13:59 . 2009-11-03 13:59 -------- d-----w- c:\documents and settings\PCP Media\Application Data\AVG9
    2009-11-03 13:35 . 2009-11-03 13:35 -------- dc----w- C:\$AVG
    2009-11-03 13:34 . 2009-11-03 13:34 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2009-11-03 13:34 . 2009-11-06 08:36 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
    2009-11-03 10:13 . 2009-11-03 10:13 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-11-04 16:23 . 2009-11-04 16:23 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
    2009-11-04 15:58 . 2009-11-04 15:58 68640 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\lbd.sys
    2009-11-04 15:58 . 2009-11-04 15:58 303976 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\AAWDriverTool.exe
    2009-11-04 15:58 . 2009-11-04 15:58 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
    2009-11-04 15:58 . 2009-11-04 15:58 85352 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\AAWDriverTool.exe
    2009-11-04 15:58 . 2009-11-04 15:58 640760 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
    2009-11-04 15:32 . 2009-03-24 11:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2009-11-04 15:32 . 2004-04-30 08:01 -------- d-----w- c:\program files\Lavasoft
    2009-11-04 09:51 . 2004-03-30 16:59 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
    2009-11-03 13:35 . 2009-01-22 18:35 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-11-03 13:35 . 2009-01-22 18:35 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2009-11-03 13:34 . 2009-01-31 14:32 12464 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-11-03 13:34 . 2009-01-22 18:35 -------- d-----w- c:\program files\AVG
    2009-11-02 21:04 . 2008-10-03 10:32 -------- d-----w- c:\documents and settings\PCP Media\Application Data\uTorrent
    2009-10-30 16:45 . 2003-12-11 11:03 224064 -c--a-w- c:\documents and settings\PCP Media\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-10-23 09:26 . 2008-12-22 08:27 -------- d-----w- c:\documents and settings\PCP Media\Application Data\dvdcss
    2009-10-21 04:08 . 2004-07-07 17:37 3598336 ----a-w- c:\windows\system32\mshtml.dll
    2009-10-15 10:48 . 2009-01-23 11:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
    2009-10-03 08:15 . 2009-11-04 16:23 2924848 -c--a-w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
    2009-10-02 18:01 . 2005-05-13 13:57 25198016 ----a-w- c:\windows\system32\MRT.exe
    2009-10-01 09:29 . 2009-10-04 13:44 195440 ------w- c:\windows\system32\MpSigStub.exe
    2009-09-23 12:55 . 2009-11-04 15:58 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2009-09-16 20:37 . 2009-03-24 15:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-09-11 14:18 . 2002-08-29 05:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
    2009-09-10 14:15 . 2009-09-10 14:15 -------- d-----w- c:\documents and settings\PCP Media\Application Data\Office Genuine Advantage
    2009-09-10 10:09 . 2003-11-25 14:10 -------- d-----w- c:\program files\Microsoft Picture It! PhotoPub
    2009-09-10 09:25 . 2009-01-05 09:54 -------- d-----w- c:\program files\Microsoft Silverlight
    2009-09-09 21:39 . 2008-10-21 18:36 256 ----a-w- c:\documents and settings\PCP Media\pool.bin
    2009-09-08 07:41 . 2006-09-13 14:39 -------- d-----w- c:\documents and settings\PCP Media\Application Data\Vso
    2009-09-04 21:03 . 2002-08-29 05:00 58880 ----a-w- c:\windows\system32\msasn1.dll
    2009-08-29 07:36 . 2004-02-06 17:05 832512 ----a-w- c:\windows\system32\wininet.dll
    2009-08-29 07:36 . 2002-08-29 05:00 671232 ----a-w- c:\windows\system32\mstime.dll
    2009-08-29 07:36 . 2002-08-29 05:00 477696 ----a-w- c:\windows\system32\mshtmled.dll
    2009-08-29 07:36 . 2002-08-29 05:00 44544 ----a-w- c:\windows\system32\pngfilt.dll
    2009-08-29 07:36 . 2002-08-29 05:00 193024 ----a-w- c:\windows\system32\msrating.dll
    2009-08-29 07:36 . 2009-07-07 08:33 78336 ----a-w- c:\windows\system32\ieencode.dll
    2009-08-29 07:36 . 2002-08-29 05:00 17408 ----a-w- c:\windows\system32\corpol.dll
    2009-08-26 08:00 . 2002-08-29 05:00 247326 ----a-w- c:\windows\system32\strmdll.dll
    2009-08-17 22:33 . 2009-08-17 22:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
    .

    ------- Sigcheck -------

    [7] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\eventlog.dll
    [7] 2004-08-04 . 82B24CB70E5944E6E34662205A2A5B78 . 55808 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\eventlog.dll

    c:\windows\system32\eventlog.dll ... is missing !!
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "<NO NAME>"="c:\program files\Mozilla Firefox\firefox.exe" [2009-10-28 908280]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
    2005-12-20 21:57 176128 ----a-w- c:\progra~1\ALIENG~1\WbSrv.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-11-03 13:34 12464 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\windows\SYSTEM32\wbsys.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
    backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
    backup=c:\windows\pss\Windows Search.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^PCP Media^Start Menu^Programs^Startup^Adobe Gamma.lnk]
    backup=c:\windows\pss\Adobe Gamma.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^PCP Media^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "gusvc"=3 (0x3)
    "Apple Mobile Device"=2 (0x2)
    "Adobe LM Service"=3 (0x3)
    "CCALib8"=2 (0x2)
    "WMPNetworkSvc"=3 (0x3)
    "TVersityMediaServer"=3 (0x3)
    "RoxWatch9"=2 (0x2)
    "RoxMediaDB9"=3 (0x3)
    "RoxLiveShare9"=2 (0x2)
    "Roxio Upnp Server 9"=2 (0x2)
    "Roxio UPnP Renderer 9"=3 (0x3)
    "WSearch"=2 (0x2)
    "FLEXnet Licensing Service"=3 (0x3)
    "CiSvc"=3 (0x3)
    "Browser"=2 (0x2)
    "iPod Service"=3 (0x3)
    "xmlprov"=3 (0x3)
    "WZCSVC"=2 (0x2)
    "WudfSvc"=2 (0x2)
    "wuauserv"=2 (0x2)
    "wscsvc"=2 (0x2)
    "WmiApSrv"=3 (0x3)
    "Wmi"=3 (0x3)
    "WmdmPmSN"=3 (0x3)
    "winmgmt"=2 (0x2)
    "WinDefend"=2 (0x2)
    "WebClient"=2 (0x2)
    "w32time"=2 (0x2)
    "VSS"=3 (0x3)
    "UPS"=3 (0x3)
    "upnphost"=3 (0x3)
    "TrkWks"=2 (0x2)
    "Themes"=2 (0x2)
    "TermService"=3 (0x3)
    "TapiSrv"=3 (0x3)
    "SysmonLog"=3 (0x3)
    "SwPrv"=3 (0x3)
    "stisvc"=2 (0x2)
    "SSDPSRV"=3 (0x3)
    "srservice"=2 (0x2)
    "Spooler"=2 (0x2)
    "ShellHWDetection"=2 (0x2)
    "SharedAccess"=2 (0x2)
    "ServiceLayer"=3 (0x3)
    "SENS"=2 (0x2)
    "seclogon"=2 (0x2)
    "Schedule"=2 (0x2)
    "SCardSvr"=3 (0x3)
    "SamSs"=2 (0x2)
    "RSVP"=3 (0x3)
    "RemoteRegistry"=2 (0x2)
    "RDSessMgr"=3 (0x3)
    "RasMan"=3 (0x3)
    "RasAuto"=3 (0x3)
    "ProtectedStorage"=2 (0x2)
    "PolicyAgent"=2 (0x2)
    "Pml Driver HPZ12"=2 (0x2)
    "PlugPlay"=2 (0x2)
    "ose"=3 (0x3)
    "odserv"=3 (0x3)
    "NVSvc"=2 (0x2)
    "NtmsSvc"=3 (0x3)
    "NtLmSsp"=3 (0x3)
    "Nla"=3 (0x3)
    "NetSvc"=3 (0x3)
    "Netman"=3 (0x3)
    "Netlogon"=3 (0x3)
    "napagent"=3 (0x3)
    "MSIServer"=3 (0x3)
    "MSDTC"=3 (0x3)
    "mnmsrvc"=3 (0x3)
    "Macromedia Licensing Service"=3 (0x3)
    "LmHosts"=2 (0x2)
    "Lavasoft Ad-Aware Service"=2 (0x2)
    "lanmanworkstation"=2 (0x2)
    "lanmanserver"=2 (0x2)
    "ImapiService"=3 (0x3)
    "idsvc"=3 (0x3)
    "IDriverT"=3 (0x3)
    "HTTPFilter"=3 (0x3)
    "hkmsvc"=3 (0x3)
    "helpsvc"=2 (0x2)
    "FontCache3.0.0.0"=3 (0x3)
    "Fax"=2 (0x2)
    "FastUserSwitchingCompatibility"=3 (0x3)
    "EventSystem"=3 (0x3)
    "Eventlog"=2 (0x2)
    "ERSvc"=2 (0x2)
    "EapHost"=3 (0x3)
    "Dot3svc"=3 (0x3)
    "Dnscache"=2 (0x2)
    "dmserver"=2 (0x2)
    "dmadmin"=3 (0x3)
    "Dhcp"=2 (0x2)
    "CryptSvc"=2 (0x2)
    "COMSysApp"=3 (0x3)
    "clr_optimization_v2.0.50727_32"=3 (0x3)
    "Bonjour Service"=2 (0x2)
    "BITS"=3 (0x3)
    "avg9wd"=2 (0x2)
    "avast! Web Scanner"=3 (0x3)
    "avast! Mail Scanner"=3 (0x3)
    "avast! Antivirus"=2 (0x2)
    "AudioSrv"=2 (0x2)
    "aswUpdSv"=2 (0x2)
    "aspnet_state"=3 (0x3)
    "AppMgmt"=3 (0x3)
    "ALG"=3 (0x3)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\eMule\\emule.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    "c:\\Program Files\\PPLive\\PPLive.exe"=
    "c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
    "c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
    "5353:TCP"= 5353:TCP:Adobe CSI CS4

    R4 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2009-11-03 285392]
    R4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-11-04 1179232]
    R4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
    S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-09-23 64288]
    S1 aswSP;avast! Self Protection; [x]
    S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-11-03 333192]
    S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-11-03 360584]
    S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-09-15 20560]


    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - MBR
    *Deregistered* - mbr
    *Deregistered* - PROCEXP113
    .
    Contents of the 'Scheduled Tasks' folder

    2009-11-04 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:24]

    2009-11-06 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.co.uk/
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uDefault_Search_URL = hxxp://www.google.com/ie
    mStart Page = hxxp://www.euro.dell.com/countries/uk/enu/gen/default.htm
    mSearch Bar = hxxp://www.google.com/ie
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = <local>
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
    DPF: ppctlcab - hxxp://www.pestscan.com/scanner/ppctlcab.cab
    FF - ProfilePath - c:\documents and settings\PCP Media\Application Data\Mozilla\Firefox\Profiles\v3lrhxyh.default\
    FF - prefs.js: browser.startup.homepage - hxxp://en-GB.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-GB:official
    FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
    FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava11.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava12.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava13.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava14.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava32.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJPI150_10.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPOJI610.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npwbe.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    .
    - - - - ORPHANS REMOVED - - - -

    AddRemove-Adobe_1710d324011afc3e7658e969025f4ba - c:\program files\Common Files\Adobe\Installers\1710d324011afc3e7658e969025f4ba\Setup.exe
    AddRemove-Adobe_2a31ae7a5c43ff52d8577782dd34e04 - c:\program files\Common Files\Adobe\Installers\2a31ae7a5c43ff52d8577782dd34e04\Setup.exe
    AddRemove-AlienGUIse Theme Manager - c:\progra~1\ALIENG~1\thememgr.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-11-06 09:54
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-1390736524-3946099755-67225680-1005\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)

    [HKEY_USERS\S-1-5-21-1390736524-3946099755-67225680-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
    @Denied: (Full) (LocalSystem)

    [HKEY_USERS\S-1-5-21-1390736524-3946099755-67225680-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{86FE59E1-7380-2D72-FFF9-BEB7213926FB}*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(780)
    c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
    c:\progra~1\ALIENG~1\wbsrv.dll
    c:\windows\system32\DivXa32.acm
    c:\windows\system32\ff_acm.acm
    c:\program files\Theorica Divx ;-) Codecs\ffdshow.ax
    c:\windows\system32\imc32.acm
    .
    Completion time: 2009-11-06 9:59
    ComboFix-quarantined-files.txt 2009-11-06 09:59

    Pre-Run: 9,121,361,920 bytes free
    Post-Run: 9,137,061,888 bytes free

    - - End Of File - - 512B16EEB10145CC8D97F3CCA102930F
    Blade81
    Hi again,

    utorrent
    emule


    Both above listed are P2P file sharing programs. P2P downloads are nowadays one of those things that most likely bring infection into the system. My recommendation is to uninstall these (and other if present) P2P file sharing programs.

    Are you using Adobe Acrobat for other things than just viewing pdfs and converting files to those?


    Disable Spybot's TeaTimer to make sure it won't interfere with fixes. You can re-enable it when you're clean again:
    • Run Spybot-S&D in Advanced Mode
    • If it is not already set to do this, go to the Mode menu
      select
      Advanced Mode
    • On the left hand side, click on Tools
    • Then click on the Resident icon in the list
    • Uncheck
      Resident TeaTimer
      and OK any prompts.
    • Restart your computer


    Open notepad and copy/paste the text in the quotebox below into it:

    CODE
    FCopy::
    c:\windows\ServicePackFiles\i386\eventlog.dll|c:\windows\system32\eventlog.dll
    c:\windows\ServicePackFiles\i386\eventlog.dll|c:\windows\system32\dllcache\eventlog.dll
    DDS::
    BHO: {AA58ED58-01DD-4d91-8333-CF10577473F7} - No File
    BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
    TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
    TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    uRun: [dll] rundll32 dll32,sm
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000000
    Regnull::
    [HKEY_USERS\S-1-5-21-1390736524-3946099755-67225680-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{86FE59E1-7380-2D72-FFF9-BEB7213926FB}*]



    Save this as
    CFScript

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.



    Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe. Make sure you have internet connection open and let ComboFix update itself if asked for a permission. Also let ComboFix install recovery console.
    Then post the resultant log.



    Uninstall vulnerable Flash versions by following instructions here. Fresh version can be obtained here.


    Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

    Updating Java:
    • Download the latest version of Java Runtime Environment (JRE) 6 Update 17.
    • Click the
      Download
      button to the right.
    • Select Windows on platform combobox and check the box that says:
      Accept License Agreement. Click continue.
    • The page will refresh.
    • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each Java versions.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-6u17-windows-i586-p.exe to install the newest version. Uncheck Carbonite online backup trial if it's offered there.



    Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

    Double-click ATF Cleaner.exe to open it

    Under Main choose:
    Windows Temp
    Current User Temp
    All Users Temp
    Cookies
    Temporary Internet Files
    Prefetch
    Java Cache

    *The other boxes are optional*
    Then click the Empty Selected button.

    If you use Firefox:
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    If you use Opera:
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    Click Exit on the Main menu to close the program.


    Please run an online scan with Kaspersky Online Scanner as instructed in the screenshot here.


    Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.
    nickhamer
    Hi, thanks again, done all that.

    The redirect symptoms appear to be gone, and are not reocccurring - would you say from the logs below that my pc's all sorted?

    To answer your queries I use Acrobat Pro to convert files to PDF. I do this from several different programs (Word, outlook, photoshop, also bundling individual pictures/graphics). I also convert from PDF to import to photoshop, and also use it to read the resulting files.

    Thank you for your pointers regarding emule and utorrent's dangers, I am aware of these, so I use them very carefully, and infrequently.

    Here are my logs as requested

    KOS report:
    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7.0: scan report
    Thursday, November 12, 2009
    Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Last database update: Thursday, November 12, 2009 06:50:24
    Records in database: 3194318
    --------------------------------------------------------------------------------

    Scan settings:
    scan using the following database: extended
    Scan archives: yes
    Scan e-mail databases: yes

    Scan area - My Computer:
    A:\
    C:\
    D:\
    E:\
    F:\
    G:\

    Scan statistics:
    Objects scanned: 155153
    Threats found: 0
    Infected objects found: 0
    Suspicious objects found: 0
    Scan duration: 04:10:41

    No threats found. Scanned area is clean.

    Selected area has been scanned.


    New dds log:


    DDS (Ver_09-10-26.01) - NTFSx86
    Run by PCP Media at 13:19:54.04 on 12/11/2009
    Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_17
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2559.1625 [GMT 0:00]

    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    AV: avast! antivirus 4.8.1356 [VPS 091105-2] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    svchost.exe
    svchost.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    svchost.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe -k imgsvc
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\DSentry.exe
    C:\PROGRA~1\AVG\AVG9\avgtray.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Java\jre6\bin\java.exe
    C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\DllHost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Documents and Settings\PCP Media\My Documents\Downloads\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.co.uk/
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = <local>
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
    BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
    uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRunOnce: [<NO NAME>] c:\program files\mozilla firefox\firefox.exe http://www.symantec.com/techsupp/servlet/P...00001e.00000079
    mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [DVDSentry] c:\windows\system32\DSentry.exe
    mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
    dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
    IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: ppctlcab - hxxp://www.pestscan.com/scanner/ppctlcab.cab
    DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} - hxxp://housecall60.trendmicro.com/housecall/xscan60.cab
    DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab
    DPF: {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} - file://d:\components\hidinputmonitorx.ocx
    DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} - hxxp://www.cult3d.com/download/cult.cab
    DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab
    DPF: {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} - file://d:\components\A9.ocx
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1128346550328
    DPF: {7030CC6C-1A88-4591-BB5A-651B9F7F0C30} - file://d:\components\wmvhdrating.ocx
    DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - hxxp://8.10.120.42/activex/AMC.cab
    DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - hxxp://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
    DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
    Notify: avgrsstarter - avgrsstx.dll
    Notify: WBSrv - c:\progra~1\alieng~1\wbsrv.dll
    AppInit_DLLs: c:\windows\system32\wbsys.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
    SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\pcpmed~1\applic~1\mozilla\firefox\profiles\v3lrhxyh.default\
    FF - prefs.js: browser.startup.homepage - hxxp://en-GB.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-GB:official
    FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
    FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npwbe.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

    ============= SERVICES / DRIVERS ===============

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-1-22 333192]
    R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-11-3 360584]
    R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-11-3 285392]
    S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys --> c:\windows\system32\drivers\Lbd.sys [?]
    S3 getPlusHelper;getPlus® Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2002-8-29 14336]

    =============== Created Last 30 ================

    2009-11-11 19:26:30 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2009-11-11 19:26:30 411368 ----a-w- c:\windows\system32\deploytk.dll
    2009-11-11 18:21:23 56320 ----a-w- c:\windows\system32\dllcache\eventlog.dll
    2009-11-11 18:21:23 56320 ------w- c:\windows\system32\eventlog.dll
    2009-11-11 18:10:03 0 dcsha-r- C:\cmdcons
    2009-11-06 09:37:59 5504 -c--a-w- c:\windows\system32\drivers\imagedrv.sys
    2009-11-06 09:31:10 98816 ----a-w- c:\windows\sed.exe
    2009-11-06 09:31:10 77312 ----a-w- c:\windows\MBR.exe
    2009-11-06 09:31:10 267264 ----a-w- c:\windows\PEV.exe
    2009-11-06 09:31:10 161792 ----a-w- c:\windows\SWREG.exe
    2009-11-05 14:03:21 0 d-----w- c:\docume~1\pcpmed~1\applic~1\Malwarebytes
    2009-11-05 14:03:10 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2009-11-05 14:03:09 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-11-04 16:24:55 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2009-11-04 16:23:03 0 dc-h--w- c:\docume~1\alluse~1\applic~1\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
    2009-11-03 13:59:48 0 d-----w- c:\docume~1\pcpmed~1\applic~1\AVG9
    2009-11-03 13:35:34 0 dc----w- C:\$AVG
    2009-11-03 13:34:53 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2009-11-03 13:34:34 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
    2009-11-03 10:13:53 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys

    ==================== Find3M ====================

    2009-11-03 13:35:14 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-11-03 13:34:53 12464 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-11-02 20:42:06 195456 ------w- c:\windows\system32\MpSigStub.exe
    2009-10-26 12:07:07 95808 ----a-w- c:\windows\fonts\ITC Zapf Chancery Italic.ttf
    2009-10-21 04:08:54 3598336 ----a-w- c:\windows\system32\dllcache\mshtml.dll
    2009-09-30 08:37:52 79308 ----a-w- c:\windows\fonts\MyriadPro-Light.ttf
    2009-09-23 16:44:42 49564 ----a-w- c:\windows\fonts\accoh.ttf
    2009-09-23 16:44:39 63908 ----a-w- c:\windows\fonts\acco.ttf
    2009-09-23 16:38:25 49808 ----a-w- c:\windows\fonts\ACCOLi.TTF
    2009-09-23 16:38:19 54000 ----a-w- c:\windows\fonts\ACCOi.TTf
    2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
    2009-09-11 14:18:39 136192 ------w- c:\windows\system32\dllcache\msv1_0.dll
    2009-09-09 21:39:31 256 ----a-w- c:\documents and settings\pcp media\pool.bin
    2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll
    2009-09-04 21:03:36 58880 ------w- c:\windows\system32\dllcache\msasn1.dll
    2009-08-28 10:28:59 70656 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe
    2009-08-28 10:28:59 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
    2009-08-27 05:18:44 634648 ----a-w- c:\windows\system32\dllcache\iexplore.exe
    2009-08-27 05:18:41 161792 ----a-w- c:\windows\system32\dllcache\ieakui.dll
    2009-08-26 08:00:21 247326 ----a-w- c:\windows\system32\strmdll.dll
    2009-08-26 08:00:21 247326 ------w- c:\windows\system32\dllcache\strmdll.dll
    2009-08-17 22:33:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
    2009-08-14 13:21:25 1850624 ----a-w- c:\windows\system32\win32k.sys
    2009-08-14 13:21:25 1850624 ------w- c:\windows\system32\dllcache\win32k.sys
    2008-08-19 08:08:31 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008081920080820\index.dat

    ============= FINISH: 13:21:08.70 ===============


    ComboFix resultant log:

    ComboFix 09-11-11.01 - PCP Media 11/11/2009 18:21.2.2 - FAT32x86
    Running from: c:\documents and settings\PCP Media\My Documents\Downloads\ComboFix.exe
    Command switches used :: c:\documents and settings\PCP Media\Desktop\CFScript.txt
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\tmp.reg

    .
    --------------- FCopy ---------------

    c:\windows\ServicePackFiles\i386\eventlog.dll --> c:\windows\system32\eventlog.dll
    c:\windows\ServicePackFiles\i386\eventlog.dll --> c:\windows\system32\dllcache\eventlog.dll
    .
    ((((((((((((((((((((((((( Files Created from 2009-10-11 to 2009-11-11 )))))))))))))))))))))))))))))))
    .

    2009-11-11 18:21 . 2008-04-14 00:11 56320 ----a-w- c:\windows\system32\eventlog.dll
    2009-11-11 18:21 . 2008-04-14 00:11 56320 ----a-w- c:\windows\system32\dllcache\eventlog.dll
    2009-11-06 09:37 . 2004-03-02 16:37 5504 -c--a-w- c:\windows\system32\drivers\imagedrv.sys
    2009-11-05 14:03 . 2009-11-05 14:03 -------- d-----w- c:\documents and settings\PCP Media\Application Data\Malwarebytes
    2009-11-05 14:03 . 2009-11-05 14:03 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Malwarebytes
    2009-11-05 14:03 . 2009-11-07 16:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-11-04 16:24 . 2009-11-04 16:24 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2009-11-04 16:23 . 2009-11-07 16:08 -------- dc-h--w- c:\docume~1\ALLUSE~1\APPLIC~1\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
    2009-11-04 12:07 . 2009-11-04 12:07 -------- d-----w- c:\program files\Alwil Software
    2009-11-03 13:59 . 2009-11-03 13:59 -------- d-----w- c:\documents and settings\PCP Media\Application Data\AVG9
    2009-11-03 13:35 . 2009-11-03 13:35 -------- dc----w- C:\$AVG
    2009-11-03 13:34 . 2009-11-11 11:33 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2009-11-03 13:34 . 2009-11-06 08:36 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\avg9
    2009-11-03 10:13 . 2009-11-03 10:13 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-11-11 17:53 . 2008-10-03 10:32 -------- d-----w- c:\documents and settings\PCP Media\Application Data\uTorrent
    2009-11-11 09:08 . 2009-01-23 11:05 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Microsoft Help
    2009-11-07 16:09 . 2005-08-24 16:19 -------- d-----w- c:\program files\Google
    2009-11-07 16:08 . 2004-04-30 08:01 -------- d-----w- c:\program files\Lavasoft
    2009-11-04 15:32 . 2009-03-24 11:57 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Lavasoft
    2009-11-04 09:51 . 2004-03-30 16:59 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\nView_Profiles
    2009-11-03 13:35 . 2009-01-22 18:35 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-11-03 13:35 . 2009-01-22 18:35 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2009-11-03 13:34 . 2009-01-31 14:32 12464 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-11-03 13:34 . 2009-01-22 18:35 -------- d-----w- c:\program files\AVG
    2009-11-02 20:42 . 2009-10-04 13:44 195456 ------w- c:\windows\system32\MpSigStub.exe
    2009-10-30 16:45 . 2003-12-11 11:03 224064 -c--a-w- c:\documents and settings\PCP Media\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-10-23 09:26 . 2008-12-22 08:27 -------- d-----w- c:\documents and settings\PCP Media\Application Data\dvdcss
    2009-09-16 20:37 . 2009-03-24 15:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-09-11 14:18 . 2002-08-29 05:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
    2009-09-09 21:39 . 2008-10-21 18:36 256 ----a-w- c:\documents and settings\PCP Media\pool.bin
    2009-09-04 21:03 . 2002-08-29 05:00 58880 ----a-w- c:\windows\system32\msasn1.dll
    2009-08-29 07:36 . 2004-02-06 17:05 832512 ------w- c:\windows\system32\wininet.dll
    2009-08-29 07:36 . 2009-07-07 08:33 78336 ----a-w- c:\windows\system32\ieencode.dll
    2009-08-29 07:36 . 2002-08-29 05:00 17408 ----a-w- c:\windows\system32\corpol.dll
    2009-08-26 08:00 . 2002-08-29 05:00 247326 ----a-w- c:\windows\system32\strmdll.dll
    2009-08-17 22:33 . 2009-08-17 22:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
    2009-08-14 13:21 . 2002-08-29 05:00 1850624 ----a-w- c:\windows\system32\win32k.sys
    .

    ((((((((((((((((((((((((((((( SnapShot@2009-11-06_09.54.49 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-01-23 11:13 . 2009-11-11 09:08 35088 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
    - 2009-01-23 11:13 . 2009-10-15 10:48 35088 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
    + 2009-01-23 11:13 . 2009-11-11 09:08 18704 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
    - 2009-01-23 11:13 . 2009-10-15 10:48 18704 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
    - 2009-01-23 11:13 . 2009-10-15 10:48 20240 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
    + 2009-01-23 11:13 . 2009-11-11 09:08 20240 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
    + 2009-01-23 11:13 . 2009-11-11 09:08 888080 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
    - 2009-01-23 11:13 . 2009-10-15 10:48 888080 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
    - 2009-01-23 11:13 . 2009-10-15 10:48 272648 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\pubs.exe
    + 2009-01-23 11:13 . 2009-11-11 09:08 272648 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\pubs.exe
    + 2009-01-23 11:13 . 2009-11-11 09:08 922384 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\pptico.exe
    - 2009-01-23 11:13 . 2009-10-15 10:48 922384 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\pptico.exe
    + 2009-01-23 11:13 . 2009-11-11 09:08 845584 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\outicon.exe
    - 2009-01-23 11:13 . 2009-10-15 10:48 845584 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\outicon.exe
    - 2009-01-23 11:13 . 2009-10-15 10:48 217864 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\misc.exe
    + 2009-01-23 11:13 . 2009-11-11 09:08 217864 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\misc.exe
    + 2002-09-03 13:42 . 2009-11-11 09:21 4753440 c:\windows\SYSTEM32\FNTCACHE.DAT
    - 2002-09-03 13:42 . 2009-10-31 09:18 4753440 c:\windows\SYSTEM32\FNTCACHE.DAT
    + 2008-10-16 08:19 . 2009-08-14 13:21 1850624 c:\windows\SYSTEM32\DLLCACHE\win32k.sys
    + 2009-10-16 07:03 . 2009-10-16 07:03 5003776 c:\windows\Installer\115e1982.msp
    + 2009-08-18 12:58 . 2009-08-18 12:58 8301056 c:\windows\Installer\115e196f.msp
    + 2009-08-18 12:57 . 2009-08-18 12:57 9122304 c:\windows\Installer\115e195c.msp
    - 2009-01-23 11:13 . 2009-10-15 10:48 1172240 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
    + 2009-01-23 11:13 . 2009-11-11 09:08 1172240 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
    - 2009-01-23 11:13 . 2009-10-15 10:48 1165584 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\accicons.exe
    + 2009-01-23 11:13 . 2009-11-11 09:08 1165584 c:\windows\Installer\{90120000-0014-0000-0000-0000000FF1CE}\accicons.exe
    + 2005-05-13 13:57 . 2009-11-05 17:36 26768832 c:\windows\SYSTEM32\MRT.exe
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "<NO NAME>"="c:\program files\Mozilla Firefox\firefox.exe" [2009-11-09 908248]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
    "NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-10-06 5058560]
    "DVDSentry"="c:\windows\System32\DSentry.exe" [2003-08-13 28672]
    "AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-11 2016536]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
    2005-12-20 21:57 176128 ----a-w- c:\progra~1\ALIENG~1\WbSrv.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-11-03 13:34 12464 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\windows\SYSTEM32\wbsys.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
    backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
    backup=c:\windows\pss\Windows Search.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^PCP Media^Start Menu^Programs^Startup^Adobe Gamma.lnk]
    backup=c:\windows\pss\Adobe Gamma.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^PCP Media^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "gusvc"=3 (0x3)
    "Apple Mobile Device"=2 (0x2)
    "Adobe LM Service"=3 (0x3)
    "CCALib8"=2 (0x2)
    "WMPNetworkSvc"=3 (0x3)
    "TVersityMediaServer"=3 (0x3)
    "RoxWatch9"=2 (0x2)
    "RoxMediaDB9"=3 (0x3)
    "RoxLiveShare9"=2 (0x2)
    "Roxio Upnp Server 9"=2 (0x2)
    "Roxio UPnP Renderer 9"=3 (0x3)
    "iPod Service"=3 (0x3)
    "Macromedia Licensing Service"=3 (0x3)
    "Lavasoft Ad-Aware Service"=2 (0x2)
    "Bonjour Service"=2 (0x2)
    "avast! Web Scanner"=3 (0x3)
    "avast! Mail Scanner"=3 (0x3)
    "avast! Antivirus"=2 (0x2)
    "aswUpdSv"=2 (0x2)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\eMule\\emule.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    "c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
    "c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
    "5353:TCP"= 5353:TCP:Adobe CSI CS4

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [22/01/2009 18:35 333192]
    R1 AvgTdiX;AVG Free Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [03/11/2009 13:34 360584]
    R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [03/11/2009 13:34 285392]
    R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 18:19 13592]
    S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]

    --- Other Services/Drivers In Memory ---

    *Deregistered* - mbr
    *Deregistered* - PROCEXP113
    .
    .
    ------- Supplementary Scan -------
    .
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = <local>
    IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
    DPF: ppctlcab - hxxp://www.pestscan.com/scanner/ppctlcab.cab
    FF - ProfilePath - c:\documents and settings\PCP Media\Application Data\Mozilla\Firefox\Profiles\v3lrhxyh.default\
    FF - prefs.js: browser.startup.homepage - hxxp://en-GB.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-GB:official
    FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
    FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava11.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava12.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava13.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava14.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava32.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJPI150_10.dll
    FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPOJI610.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npwbe.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    .
    - - - - ORPHANS REMOVED - - - -

    HKCU-Run-RocketDock - c:\program files\RocketDock\RocketDock.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-11-11 18:28
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...


    c:\docume~1\PCPMED~1\LOCALS~1\Temp\catchme.dll 53248 bytes executable

    scan completed successfully
    hidden files: 1

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-1390736524-3946099755-67225680-1005\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)

    [HKEY_USERS\S-1-5-21-1390736524-3946099755-67225680-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
    @Denied: (Full) (LocalSystem)
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(764)
    c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
    c:\progra~1\ALIENG~1\wbsrv.dll
    .
    Completion time: 2009-11-11 18:33
    ComboFix-quarantined-files.txt 2009-11-11 18:33
    ComboFix2.txt 2009-11-06 09:59

    Pre-Run: 12,358,492,160 bytes free
    Post-Run: 12,379,488,256 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

    - - End Of File - - EDFED3BE0C58071C332F0B3CD5AF9550
    Blade81
    Hi,

    Since vulnerabilities in Adobe's product are used pretty often nowadays I recommend to try alternative PDF writer. List of those can be found here.

    Now it's time for the final steps smile.gif


    THESE STEPS ARE VERY IMPORTANT

    Let's reset system restore
    Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

    1. Turn off System Restore.
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    Check Turn off System Restore.
    Click Apply, and then click OK.

    2. Reboot.

    3. Turn ON System Restore.
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    UN-Check *Turn off System Restore*.
    Click Apply, and then click OK.
    NOTE: only do this ONCE,NOT on a regular basis



    Now lets uninstall ComboFix:
    • Click START then RUN
    • Now copy-paste Combofix /uninstall in the runbox and click OK


    Please download OTC and save it to desktop.
    • Double-click OTC.exe.
    • Click the CleanUp! button.
    • Select Yes when the
      Begin cleanup Process?
      prompt appears.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes, if not delete it by yourself.

    Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.



    UPDATING WINDOWS AND INTERNET EXPLORER

    IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates.

    If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.


    Make your Internet Explorer more secure

    This can be done by following these simple instructions:
    From within Internet Explorer click on the Tools menu and then click on Options.
    Click once on the Security tab
    Click once on the Internet icon so it becomes highlighted.
    Click once on the Custom Level button.
    Change the Download signed ActiveX controls to Prompt
    Change the Download unsigned ActiveX controls to Disable
    Change the Initialize and script ActiveX controls not marked as safe to Disable
    Change the Installation of desktop items to Prompt
    Change the Launching programs and files in an IFRAME to Prompt
    Change the Navigate sub-frames across different domains to Prompt
    When all these settings have been made, click on the OK button.
    If it prompts you as to whether or not you want to save the settings, press the Yes button.
    Next press the Apply button and then the OK to exit the Internet Properties page.



    The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.
    • hosts file:
      • Every version of windows has a hosts file as part of them.
      • In a very basic sense, they are used to locate webpages.
      • We can customize a hosts file so that it blocks certain webpages.
      • However, it can slow down certain computers.
      • This is why using a hosts file is optional!!
      Download it here. Make sure you read the instructions on how to install the hosts file. There is a good tutorial here
      If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
      1. Click the start button (at the lower left hand corner of your screen)
      2. Click run
      3. In the dialog box, type services.msc
      4. hit enter, then locate dns client
      5. Highlight it, then double-click it.
      6. On the dropdown box, change the setting from automatic to manual.
      7. Click ok
  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this webpage out.
    If you don't have a 3rd party firewall or a router behind NAT then I recommend getting one. I recommend either Online Armor Free or Comodo Firewall Pro (If you choose Comodo: Uncheck during installation Install Comodo HopSurf.., Make Comodo my default search provider and Make Comodo Search my homepage and install firewall ONLY!). Both providers have support forums that help with configuration related questions.


  • Just a final reminder for you. I am trying to stress these two points.
    UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
    Make sure all of your security programs are up to date.
    Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.



    Once again, please post and tell me how things are going with your system... problems etc.

    Have a great day,
    Blade cool.gif
    nickhamer
    Hi Blade,

    Thanks very much for all your help on this, my pc seems to be virus free at last.

    I'll make sure I stay ontop of windows updates, again thanks for all your advice, I really appreciate it

    Nick
    Blade81
    Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. smile.gif

    If you're the topic starter, and need this topic reopened, please contact the staff member who was helping you with your issue.

    Everyone else please begin a New Topic.

    Thank you !
    This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
    Invision Power Board © 2001-2009 Invision Power Services, Inc.