GMER Part 1
GMER 1.0.15.15570 -
http://www.gmer.net
Rootkit scan 2011-04-06 00:03:44
Windows 6.1.7600 Harddisk1\DR1 -> \Device\0000008e OCZ-VERT rev.1.4_
Running: v3t1cn3e.exe; Driver: K:\Temp\fgtyqpob.sys
.text ...
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
---- Kernel code sections - GMER 1.0.15 ----
.text KernelBase.dll!LoadLibraryExW + 11C 7525B8A0 4 Bytes [0A, 00, 64, 00]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] SHELL32.dll!Shell_NotifyIconW 755CFBE1 5 Bytes JMP 280A8AF0 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] ole32.dll!CoRegisterClassObject 763111F5 5 Bytes JMP 280A8290 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] ole32.dll!CoInitializeEx 76340804 5 Bytes JMP 280A8190 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Windows\system32\svchost.exe[1208] ole32.dll!CoCreateInstance 763557FC 5 Bytes JMP 005B000A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] ADVAPI32.dll!CryptDecrypt 76862140 5 Bytes JMP 280A6F90 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] ADVAPI32.dll!CryptDeriveKey 76862150 5 Bytes JMP 280A6F30 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] USER32.dll!SetWindowPlacement 768C8169 5 Bytes JMP 280ABB80 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] USER32.dll!CreateDialogParamW 768C9BFF 5 Bytes JMP 280ABCD0 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] USER32.dll!SetWindowRgn 768CB29A 7 Bytes JMP 280ABC20 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
---- Kernel code sections - GMER 1.0.15 ----
.text user32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
---- User code sections - GMER 1.0.15 ----
.text C:\Users\Nader\Local Settings\Apps\F.lux\flux.exe[1476] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text C:\Windows\system32\taskhost.exe[2260] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text E:\Program Files\No-IP 2.2.1\DUC20.exe[2432] user32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text C:\Windows\system32\taskeng.exe[2688] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text D:\Program Files\EVGA Precision\EVGAPrecision.exe[3044] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3092] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text C:\Program Files\Core Temp.exe[3116] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text C:\Program Files\Everything\Everything.exe[3232] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text D:\Program Files\Astaro\Astaro SSL VPN Client\bin\openvpn-gui.exe[3416] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text C:\Windows\System32\Ctxfihlp.exe[3476] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text D:\Program Files\SugarSync\SugarSyncManager.exe[3548] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text C:\Users\Nader\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe[3616] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text C:\Users\Nader\Desktop\v3t1cn3e.exe[3708] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text D:\Program Files\NetWorx\networx.exe[3872] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text D:\Program Files\iTunes\iTunesHelper.exe[3992] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text D:\Program Files\Spyware Doctor\BDT\FGuard.exe[4052] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text C:\Windows\system32\wuauclt.exe[5008] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[5304] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[5804] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 717B0F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] USER32.dll!SetForegroundWindow 768CD3AE 6 Bytes JMP 71840F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] USER32.dll!CreateWindowExW 768D0E51 5 Bytes JMP 280A9380 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] USER32.dll!LoadIconW 768D1431 5 Bytes JMP 280AC4A0 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] USER32.dll!LoadImageW 768D2323 5 Bytes JMP 280AC320 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
---- Kernel code sections - GMER 1.0.15 ----
.text user32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
---- User code sections - GMER 1.0.15 ----
.text C:\Users\Nader\Local Settings\Apps\F.lux\flux.exe[1476] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[2260] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text E:\Program Files\No-IP 2.2.1\DUC20.exe[2432] user32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2688] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text D:\Program Files\EVGA Precision\EVGAPrecision.exe[3044] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3092] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Core Temp.exe[3116] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Everything\Everything.exe[3232] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Astaro\Astaro SSL VPN Client\bin\openvpn-gui.exe[3416] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[3476] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text D:\Program Files\SugarSync\SugarSyncManager.exe[3548] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text C:\Users\Nader\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe[3616] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text C:\Users\Nader\Desktop\v3t1cn3e.exe[3708] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text D:\Program Files\NetWorx\networx.exe[3872] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text D:\Program Files\iTunes\iTunesHelper.exe[3992] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Spyware Doctor\BDT\FGuard.exe[4052] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[5008] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[5304] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[5804] USER32.dll!SetWindowPos 768D3581 3 Bytes [FF, 25, 1E]
---- Kernel code sections - GMER 1.0.15 ----
.text user32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
---- User code sections - GMER 1.0.15 ----
.text C:\Users\Nader\Local Settings\Apps\F.lux\flux.exe[1476] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text C:\Windows\system32\taskhost.exe[2260] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text E:\Program Files\No-IP 2.2.1\DUC20.exe[2432] user32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text C:\Windows\system32\taskeng.exe[2688] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text D:\Program Files\EVGA Precision\EVGAPrecision.exe[3044] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text C:\Program Files\Mozilla Firefox\firefox.exe[3092] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text C:\Program Files\Core Temp.exe[3116] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text C:\Program Files\Everything\Everything.exe[3232] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text D:\Program Files\Astaro\Astaro SSL VPN Client\bin\openvpn-gui.exe[3416] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text C:\Windows\System32\Ctxfihlp.exe[3476] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text D:\Program Files\SugarSync\SugarSyncManager.exe[3548] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text C:\Users\Nader\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe[3616] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text C:\Users\Nader\Desktop\v3t1cn3e.exe[3708] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text D:\Program Files\NetWorx\networx.exe[3872] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text D:\Program Files\iTunes\iTunesHelper.exe[3992] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text D:\Program Files\Spyware Doctor\BDT\FGuard.exe[4052] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text C:\Windows\system32\wuauclt.exe[5008] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text C:\Program Files\Mozilla Firefox\firefox.exe[5304] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[5804] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [76, 71] {JBE 0x73}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] USER32.dll!SetWindowPos + 4 768D3585 2 Bytes [7F, 71] {JG 0x73}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] USER32.dll!GetWindowLongW 768D83A9 7 Bytes JMP 280AC5D0 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] USER32.dll!PeekMessageW 768D91B5 5 Bytes JMP 280AA060 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
---- Kernel code sections - GMER 1.0.15 ----
.text user32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
---- User code sections - GMER 1.0.15 ----
.text C:\Users\Nader\Local Settings\Apps\F.lux\flux.exe[1476] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text C:\Windows\system32\taskhost.exe[2260] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text E:\Program Files\No-IP 2.2.1\DUC20.exe[2432] user32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text C:\Windows\system32\taskeng.exe[2688] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text D:\Program Files\EVGA Precision\EVGAPrecision.exe[3044] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3092] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text C:\Program Files\Core Temp.exe[3116] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text C:\Program Files\Everything\Everything.exe[3232] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text D:\Program Files\Astaro\Astaro SSL VPN Client\bin\openvpn-gui.exe[3416] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text C:\Windows\System32\Ctxfihlp.exe[3476] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text D:\Program Files\SugarSync\SugarSyncManager.exe[3548] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text C:\Users\Nader\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe[3616] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text C:\Users\Nader\Desktop\v3t1cn3e.exe[3708] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text D:\Program Files\NetWorx\networx.exe[3872] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text D:\Program Files\iTunes\iTunesHelper.exe[3992] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text D:\Program Files\Spyware Doctor\BDT\FGuard.exe[4052] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text C:\Windows\system32\wuauclt.exe[5008] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[5304] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[5804] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 71740F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] USER32.dll!ChangeDisplaySettingsExA 768E81B7 6 Bytes JMP 717D0F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] USER32.dll!TrackPopupMenuEx 768F5F72 5 Bytes JMP 280AA760 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
---- Kernel code sections - GMER 1.0.15 ----
.text user32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
---- User code sections - GMER 1.0.15 ----
.text C:\Users\Nader\Local Settings\Apps\F.lux\flux.exe[1476] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text C:\Windows\system32\taskhost.exe[2260] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text E:\Program Files\No-IP 2.2.1\DUC20.exe[2432] user32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text C:\Windows\system32\taskeng.exe[2688] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text D:\Program Files\EVGA Precision\EVGAPrecision.exe[3044] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3092] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text C:\Program Files\Core Temp.exe[3116] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text C:\Program Files\Everything\Everything.exe[3232] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text D:\Program Files\Astaro\Astaro SSL VPN Client\bin\openvpn-gui.exe[3416] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text C:\Windows\System32\Ctxfihlp.exe[3476] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text D:\Program Files\SugarSync\SugarSyncManager.exe[3548] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text C:\Users\Nader\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe[3616] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text C:\Users\Nader\Desktop\v3t1cn3e.exe[3708] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text D:\Program Files\NetWorx\networx.exe[3872] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text D:\Program Files\iTunes\iTunesHelper.exe[3992] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text D:\Program Files\Spyware Doctor\BDT\FGuard.exe[4052] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text C:\Windows\system32\wuauclt.exe[5008] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[5304] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[5804] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 71710F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] USER32.dll!ChangeDisplaySettingsExW 7690FA61 6 Bytes JMP 717A0F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] USER32.dll!MessageBoxIndirectW 7691E9C3 5 Bytes JMP 280ABF00 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] WININET.dll!InternetCloseHandle 76C1C83E 5 Bytes JMP 280B0120 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] WININET.dll!InternetReadFile 76C1E264 5 Bytes JMP 280AFFE0 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] WININET.dll!HttpOpenRequestA 76C203FA 5 Bytes JMP 280AFE80 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] WININET.dll!HttpSendRequestA 76C90574 5 Bytes JMP 280B0080 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] WS2_32.dll!closesocket 76EF3BED 5 Bytes JMP 280B13F0 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] WS2_32.dll!recv 76EF47DF 5 Bytes JMP 280B0DD0 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] WS2_32.dll!WSASend 76EF68A7 5 Bytes JMP 280B1220 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] WS2_32.dll!WSARecv 76EFC29F 5 Bytes JMP 280B0F00 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] WS2_32.dll!send 76EFC4C8 5 Bytes JMP 280B10B0 D:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Bonjour\mDNSResponder.exe[276] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[436] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[496] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[504] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[544] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[568] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[576] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[660] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[720] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\conhost.exe[828] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[972] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1004] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[1020] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1176] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\explorer.exe[1200] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1392] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1440] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Users\Nader\Local Settings\Apps\F.lux\flux.exe[1476] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1504] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1528] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1564] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1668] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1676] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1852] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1920] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[2012] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Digidesign\Digidesign\Drivers\MMERefresh.exe[2232] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[2260] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2304] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Avid\Mbox\AudioDevMon.exe[2372] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text E:\Program Files\No-IP 2.2.1\DUC20.exe[2432] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2476] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Avid\Mbox Mini\AudioDevMon.exe[2516] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Avid\Mbox Pro\AudioDevMon.exe[2604] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2688] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[2712] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Spyware Doctor\pctsAuxs.exe[2840] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\vmnetdhcp.exe[2936] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Spyware Doctor\pctsSvc.exe[2996] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text D:\Program Files\EVGA Precision\EVGAPrecision.exe[3044] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3092] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Core Temp.exe[3116] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3160] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Everything\Everything.exe[3232] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[3324] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3360] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text c:\program files\subversion\bin\svnserve.exe[3384] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Astaro\Astaro SSL VPN Client\bin\openvpn-gui.exe[3416] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\Ctxfihlp.exe[3476] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text D:\Program Files\SugarSync\SugarSyncManager.exe[3548] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Users\Nader\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe[3616] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\vmnat.exe[3696] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Users\Nader\Desktop\v3t1cn3e.exe[3708] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3792] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\RealVNC\VNC4\WinVNC4.exe[3848] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text D:\Program Files\NetWorx\networx.exe[3872] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\RealVNC\VNC4\winvnc4.exe[3972] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text D:\Program Files\iTunes\iTunesHelper.exe[3992] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text E:\Program Files\VMware\VMware Workstation\vmware-authd.exe[4000] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text D:\Program Files\Spyware Doctor\BDT\FGuard.exe[4052] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4560] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[4744] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[4816] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wuauclt.exe[5008] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[5304] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\alg.exe[5336] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Program Files\iPod\bin\iPodService.exe[5772] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\SYSTEM32\CTXFISPI.EXE[5804] ntdll.dll!NtClose 76F74770 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1676] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7B, 71] {JNP 0x73}
.text C:\Program Files\Bonjour\mDNSResponder.exe[276] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\csrss.exe[436] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\wininit.exe[496] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\csrss.exe[504] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\services.exe[544] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\lsass.exe[568] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\lsm.exe[576] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\winlogon.exe[660] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\svchost.exe[720] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\conhost.exe[828] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\nvvsvc.exe[972] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\svchost.exe[1004] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\System32\svchost.exe[1176] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\explorer.exe[1200] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Creative\Shared Files\CTAudSvc.exe[1392] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\svchost.exe[1440] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Users\Nader\Local Settings\Apps\F.lux\flux.exe[1476] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe[1504] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\nvvsvc.exe[1528] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\svchost.exe[1564] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1668] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\System32\spoolsv.exe[1852] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\svchost.exe[1920] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text D:\Program Files\Digidesign\Digidesign\Drivers\MMERefresh.exe[2232] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\taskhost.exe[2260] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\svchost.exe[2304] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Avid\Mbox\AudioDevMon.exe[2372] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text E:\Program Files\No-IP 2.2.1\DUC20.exe[2432] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\Dwm.exe[2476] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Avid\Mbox Mini\AudioDevMon.exe[2516] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Avid\Mbox Pro\AudioDevMon.exe[2604] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\taskeng.exe[2688] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[2712] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text D:\Program Files\Spyware Doctor\pctsAuxs.exe[2840] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\vmnetdhcp.exe[2936] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text D:\Program Files\Spyware Doctor\pctsSvc.exe[2996] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text D:\Program Files\EVGA Precision\EVGAPrecision.exe[3044] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Mozilla Firefox\firefox.exe[3092] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Core Temp.exe[3116] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Everything\Everything.exe[3232] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[3324] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\svchost.exe[3360] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text c:\program files\subversion\bin\svnserve.exe[3384] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text D:\Program Files\Astaro\Astaro SSL VPN Client\bin\openvpn-gui.exe[3416] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\System32\Ctxfihlp.exe[3476] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text D:\Program Files\SugarSync\SugarSyncManager.exe[3548] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Users\Nader\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe[3616] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\vmnat.exe[3696] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Users\Nader\Desktop\v3t1cn3e.exe[3708] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\svchost.exe[3792] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\RealVNC\VNC4\WinVNC4.exe[3848] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}
.text D:\Program Files\NetWorx\networx.exe[3872] ntdll.dll!NtClose + 4 76F74774 2 Bytes [7D, 71] {JGE 0x73}