WiredWX Hobby Weather ToolsLog in

 


Troj/Rustok-N HJT log and symptoms

3 posters

descriptionSolvedTroj/Rustok-N HJT log and symptoms

more_horiz
Hi. I was experiencing random redirects, and an adult streaming video site returned this:

"Your computer (IP: xxx.xxx.xxx.xxx) generates an attacking DOS requests at our servers caused by the spyware/virus named 'Troj/Rustok-N'

We cannot provide you with an access to our content for browsing purposes as it will lead to the inevitable crush of our website.

We strongly recommend you to run your antivirus edition and, if necessary, check it for the latest updates available."

I've been at this for a couple of days now, so I've scanned/cleaned with everything under the sun.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:05:14 PM, on 1/1/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netflix.com/MemberHome
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 6666 bytes

descriptionSolvedUninstall List

more_horiz
7-Zip 4.62
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Apple Mobile Device Support
Apple Software Update
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
Belarc Advisor 7.2
BitComet 1.07
Bonjour
Catalyst Control Center - Branding
Compatibility Pack for the 2007 Office system
Driver Sweeper 1.5.5
ESET NOD32 Antivirus
GlassFish V2 UR2
GlassFish v3 Prelude
GrabIt 1.7.2 Beta 3 (build 996)
Guitar Pro 5.0
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
HP Deskjet 3900 series
HP Imaging Device Functions 5.0
HP Software Update
HP Solution Center & Imaging Support Tools 5.0
ImgBurn
iTunes
Java DB 10.4.1.3
Java(TM) 6 Update 11
Java(TM) SE Development Kit 6 Update 11
Logitech GamePanel Software 2.02
Malwarebytes' Anti-Malware
Marvell Miniport Driver
Medieval II Total War
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Mozilla Firefox (3.0.5)
MSXML 4.0 SP2 (KB954430)
NetBeans IDE 6.5
Netflix Movie Viewer
QuickTime
Radeon Omega Drivers v4.8.442 Setup Files and Tools
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB960714)
SoundMAX
Sumatra PDF reader
Sun Java System Application Server
TeamSpeak 2 RC2
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Winamp
WindowBlinds
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Search 4.0
Windows XP Service Pack 3
WinRAR archiver
World of Warcraft

descriptionSolvedRe: Troj/Rustok-N HJT log and symptoms

more_horiz
Since MBAM is already on the system, we'll use that.


  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.

descriptionSolvedMBAM log

more_horiz
Thanks so much for your help. MBAM didn't detect any problems:

Malwarebytes' Anti-Malware 1.31
Database version: 1456
Windows 5.1.2600 Service Pack 3

1/1/2009 12:41:33 PM
mbam-log-2009-01-01 (12-41-33).txt

Scan type: Quick Scan
Objects scanned: 50874
Time elapsed: 1 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

descriptionSolvedRe: Troj/Rustok-N HJT log and symptoms

more_horiz
Okay, lets see what's being created recently.


  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    Link 1
    Link 2
    Link 3
  • Double click DDS.scr to run
  • When complete, DDS.txt will open.
  • Click No for Optional Scan.
  • Save the report to your Desktop.
  • Copy and paste the report back here.

descriptionSolvedDDS Log 1

more_horiz
DDS (Version 1.1.0) - NTFSx86
Run by Scott Fontenot at 13:07:55.57 on Thu 01/01/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1098 [GMT -8:00]

AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\javaw.exe
C:\Program Files\NetBeans 6.5\bin\netbeans.exe
C:\Program Files\NetBeans 6.5\platform9\lib\nbexec.exe
C:\Program Files\NetBeans 6.5\platform9\lib\nbexec.exe
C:\Program Files\Java\jdk1.6.0_11\jre\bin\java.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\iTunes\iTunes.exe
C:\Documents and Settings\Scott Fontenot\Desktop\dds.com

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.netflix.com/MemberHome
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
mRun: [SoundMAX] "c:\program files\analog devices\soundmax\Smax4.exe" /tray
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [Launch LCDMon] "c:\program files\logitech\gamepanel software\lcd manager\LCDMon.exe"
mRun: [Launch LGDCore] "c:\program files\logitech\gamepanel software\g-series software\LGDCore.exe" /SHOWHIDE
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll/206
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: WBSrv - c:\program files\stardock\object desktop\windowblinds\WBSrv.dll
AppInit_DLLs: wbsys.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\scottf~1\applic~1\mozilla\firefox\profiles\bt2qn7h0.default\
FF - component: c:\documents and settings\scott fontenot\application data\mozilla\firefox\profiles\bt2qn7h0.default\extensions\{b042753d-f57e-4e8e-a01b-7379a6d4cefb}\components\IBitCometExtension.dll

============= SERVICES / DRIVERS ===============

R1 atitray;atitray;\??\c:\program files\radeon omega drivers\v4.8.442\ati tray tools\atitray.sys [2008-12-21 17952]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-7-1 34312]
R2 ekrn;Eset Service;"c:\program files\eset\eset nod32 antivirus\ekrn.exe" [2008-7-1 468224]
R3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys [2009-1-1 38496]

=============== Created Last 30 ================

2009-01-01 11:54 --d----- c:\program files\Trend Micro
2009-01-01 03:14 --d----- c:\docume~1\scottf~1\applic~1\Malwarebytes
2009-01-01 03:14 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-01-01 03:14 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-01 03:14 --d----- c:\program files\Malwarebytes' Anti-Malware
2009-01-01 03:14 --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-01-01 03:07 2,560 a------- c:\windows\_MSRSTRT.EXE
2008-12-31 20:52 --d----- c:\program files\common files\Stardock
2008-12-30 23:05 --d----- c:\windows\pss
2008-12-30 22:31 --d----- c:\program files\HP
2008-12-30 22:30 78,816 a------- c:\windows\hpfins05.dat
2008-12-30 22:30 1,395 -------- c:\windows\hpfmdl05.dat
2008-12-30 22:29 372,736 a------- c:\windows\system32\hpzidi01.dll
2008-12-30 22:29 77,824 a------- c:\windows\system32\hpzids01.dll
2008-12-28 18:27 42,672 a------- c:\windows\system32\wbsys.dll
2008-12-28 18:27 --d----- c:\program files\Stardock
2008-12-28 18:15 0 a------- c:\windows\system32\4ever
2008-12-28 18:00 --d----- c:\program files\Guitar Pro 5
2008-12-28 16:15 12,392 a------- c:\windows\system32\productregistry
2008-12-28 16:15 --d----- C:\Sun
2008-12-28 15:56 --d----- c:\documents and settings\scott fontenot\.SunDownloadManager
2008-12-28 14:43 107,368 a------- c:\windows\system32\GEARAspi.dll
2008-12-28 14:43 15,464 a------- c:\windows\system32\drivers\GEARAspiWDM.sys
2008-12-28 14:42 --d----- c:\program files\iPod
2008-12-28 14:42 --d----- c:\program files\iTunes
2008-12-28 14:42 --d----- c:\docume~1\alluse~1\applic~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-28 14:42 --d----- c:\program files\Bonjour
2008-12-28 14:42 32,000 a------- c:\windows\system32\drivers\usbaapl.sys
2008-12-28 09:08 --d----- c:\program files\SEGA
2008-12-26 23:35 593,920 -------- c:\windows\system32\ati2sgag.exe
2008-12-26 23:34 --d----- C:\ATI
2008-12-22 10:04 26,368 ac------ c:\windows\system32\dllcache\usbstor.sys
2008-12-22 09:38 53,248 a------- c:\windows\system32\CSVer.dll
2008-12-22 09:38 --d----- C:\Intel=

descriptionSolvedDDS Log 1 cont.

more_horiz
2008-12-22 09:35 --d----- c:\program files\MSXML 4.0
2008-12-22 09:00 2,297,552 a------- c:\windows\system32\d3dx9_26.dll
2008-12-22 08:56 --d----- c:\program files\Microsoft Games
2008-12-22 07:29 --d----- c:\program files\MSECache
2008-12-22 07:27 376 a------- c:\windows\ODBC.INI
2008-12-22 07:27 17,920 a------- c:\windows\system32\mdimon.dll
2008-12-22 07:27 --d----- c:\program files\Microsoft ActiveSync
2008-12-22 07:26 --d----- c:\windows\SHELLNEW
2008-12-22 07:24 --d----- c:\docume~1\scottf~1\applic~1\DAEMON Tools Pro
2008-12-22 07:23 --d----- c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite
2008-12-22 07:23 --d----- c:\program files\DAEMON Tools Lite
2008-12-22 07:21 717,296 a------- c:\windows\system32\drivers\sptd.sys
2008-12-22 07:21 --d----- c:\docume~1\scottf~1\applic~1\DAEMON Tools Lite
2008-12-22 07:19 5,632 a------- c:\windows\system32\ptpusb.dll
2008-12-22 07:19 15,104 ac------ c:\windows\system32\dllcache\usbscan.sys
2008-12-22 07:19 159,232 a------- c:\windows\system32\ptpusd.dll
2008-12-22 07:19 15,104 a------- c:\windows\system32\drivers\usbscan.sys
2008-12-21 22:54 --d----- c:\program files\Netflix
2008-12-21 20:35 --d----- C:\Downloads
2008-12-21 20:34 --d----- c:\program files\BitComet
2008-12-21 19:47 --d----- c:\docume~1\scottf~1\applic~1\SumatraPDF
2008-12-21 16:34 136,272 a------- c:\windows\system32\atmenuxx.hlp
2008-12-21 16:34 40,651 a------- c:\windows\system32\attenuxx.hlp
2008-12-21 16:34 23,224 a------- c:\windows\system32\atfenuxx.hlp
2008-12-21 15:49 --d----- c:\docume~1\scottf~1\applic~1\atitray
2008-12-21 15:22 --d----- c:\docume~1\scottf~1\applic~1\Windows Search
2008-12-21 15:16 472,576 a------- c:\windows\Radeon Omega Drivers v4.8.442 Uninstall.exe
2008-12-21 15:16 --d----- c:\program files\Radeon Omega Drivers
2008-12-21 13:27 --d----- c:\program files\Driver Sweeper
2008-12-21 13:06 --d----- c:\docume~1\scottf~1\applic~1\Windows Desktop Search
2008-12-21 13:05 --d----- c:\windows\system32\GroupPolicy
2008-12-21 13:05 --d----- c:\program files\Windows Desktop Search
2008-12-21 13:05 192,000 -c------ c:\windows\system32\dllcache\offfilt.dll
2008-12-21 13:05 98,304 -c------ c:\windows\system32\dllcache\nlhtml.dll
2008-12-21 13:05 29,696 -c------ c:\windows\system32\dllcache\mimefilt.dll
2008-12-21 13:05 221,184 a------- c:\windows\system32\wmpns.dll
2008-12-21 13:04 --d----- c:\program files\Windows Media Connect 2
2008-12-21 13:03 --d----- c:\windows\system32\LogFiles
2008-12-21 13:00 --d----- c:\windows\system32\URTTemp
2008-12-21 12:56 --d----- c:\program files\ATI Technologies
2008-12-21 12:36 --d----- c:\documents and settings\scott fontenot\.netbeans-derby
2008-12-21 12:33 --d----- c:\documents and settings\scott fontenot\.netbeans-registration
2008-12-21 12:33 --d----- c:\documents and settings\scott fontenot\.netbeans
2008-12-21 12:32 --d----- c:\program files\glassfish-v3-prelude
2008-12-21 12:31 --d----- c:\program files\glassfish-v2ur2
2008-12-21 12:27 --d----- c:\program files\NetBeans 6.5
2008-12-21 12:26 --d----- c:\documents and settings\scott fontenot\.nbi
2008-12-21 12:19 --d----- c:\program files\Sun
2008-12-21 12:19 410,984 a------- c:\windows\system32\deploytk.dll
2008-12-21 12:19 73,728 a------- c:\windows\system32\javacpl.cpl
2008-12-21 12:10 --d----- c:\program files\SumatraPDF
2008-12-21 08:55 --d----- C:\Logs
2008-12-21 07:49 10 a------- c:\windows\WININIT.INI
2008-12-21 07:28 --d----- c:\program files\World of Warcraft
2008-12-20 16:21 --d----- c:\docume~1\scottf~1\applic~1\GrabIt
2008-12-20 16:20 --d----- c:\program files\GrabIt
2008-12-20 15:53 --d----- c:\windows\system32\scripting
2008-12-20 15:53 --d----- c:\windows\system32\en
2008-12-20 15:53 --d----- c:\windows\l2schemas
2008-12-20 15:53 --d----- c:\windows\system32\bits
2008-12-20 15:48 --d----- c:\windows\ServicePackFiles
2008-12-20 15:37 --d----- c:\windows\EHome
2008-12-20 15:24 --d----- c:\docume~1\alluse~1\applic~1\Blizzard
2008-12-20 15:23 --d----- c:\program files\common files\Blizzard Entertainment
2008-12-20 15:13 64,756 a------- c:\windows\system32\DVCState-{00000002-00000000-00000009-00001102-00000005-00311102}.rfx
2008-12-20 15:13 53,800 a------- c:\windows\system32\BMXStateBkp-{00000002-00000000-00000009-00001102-00000005-00311102}.rfx
2008-12-20 15:13 53,800 a------- c:\windows\system32\BMXState-{00000002-00000000-00000009-00001102-00000005-00311102}.rfx
2008-12-20 15:13 1,080 a------- c:\windows\system32\settingsbkup.sfm
2008-12-20 15:13 1,080 a------- c:\windows\system32\settings.sfm
2008-12-20 15:11 --d----- c:\program files\Teamspeak2_RC2
2008-12-20 15:09 --d----- c:\windows\network diagnostic
2008-12-20 15:04 --d----- c:\program files\Belarc
2008-12-20 15:03 409,600 a------- c:\windows\system32\wrap_oal.dll
2008-12-20 15:03 114,688 a------- c:\windows\system32\OpenAL32.dll
2008-12-20 15:03 --d----- c:\windows\system32\data
2008-12-20 14:57 272,128 -c------ c:\windows\system32\dllcache\bthport.sys
2008-12-20 14:57 272,128 -------- c:\windows\system32\drivers\bthport.sys
2008-12-20 14:57 138,496 -c------ c:\windows\system32\dllcache\afd.sys
2008-12-20 14:57 333,824 -c------ c:\windows\system32\dllcache\srv.sys
2008-12-20 14:56 1,846,400 -c------ c:\windows\system32\dllcache\win32k.sys
2008-12-20 14:56 2,189,184 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-20 14:56 2,145,280 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-20 14:56 2,066,048 -c------ c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-20 14:56 2,023,936 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-20 14:55 203,136 -c------ c:\windows\system32\dllcache\rmcast.sys
2008-12-20 14:55 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2008-12-20 14:55 691,712 -c------ c:\windows\system32\dllcache\inetcomm.dll
2008-12-20 14:55 337,408 -c------ c:\windows\system32\dllcache\netapi32.dll
2008-12-20 14:54 --d----- c:\program files\ESET
2008-12-20 14:53 0 a------- c:\windows\ativpsrm.bin
2008-12-20 14:51 26,488 a------- c:\windows\system32\spupdsvc.exe
2008-12-20 14:51 --d----- c:\windows\system32\PreInstall
2008-12-20 14:51 --d-h--- c:\windows\$hf_mig$
2008-12-20 14:45 253,952 -c------ c:\windows\system32\dllcache\es.dll
2008-12-20 14:42 --d----- c:\windows\system32\ReinstallBackups
2008-12-20 14:41 --d----- c:\program files\Analog Devices
2008-12-20 14:40 13,646 a------- c:\windows\system32\wpa.bak
2008-12-20 14:40 --d----- c:\windows\system32\SoftwareDistribution
2008-12-20 14:40 --d----- c:\program files\Marvell
2008-12-20 14:38 10,352 a------- c:\windows\Ascd_tmp.ini
2008-12-20 14:38 5,824 a------- c:\windows\system32\drivers\ASUSHWIO.SYS
2008-12-20 14:38 --d----- c:\documents and settings\Scott Fontenot
2008-12-20 14:36 --ds---- c:\windows\system32\Microsoft
2008-12-20 14:35 8,192 a------- c:\windows\REGLOCS.OLD
2008-12-20 14:33 1,875,968 ac------ c:\windows\system32\dllcache\msir3jp.lex
2008-12-20 14:32 316,640 a------- c:\windows\WMSysPr9.prx
2008-12-20 14:32 --dsh--- c:\documents and settings\all users\DRM
2008-12-20 14:32 --d-h--- c:\program files\WindowsUpdate
2008-12-20 14:31 --d----- c:\program files\common files\MSSoap
2008-12-20 14:30 --d----- c:\program files\Online Services
2008-12-20 14:30 --d----- c:\program files\Messenger
2008-12-20 14:30 --d----- c:\program files\MSN Gaming Zone
2008-12-20 14:30 --d----- c:\program files\Windows NT
2008-12-20 06:23 --d----- c:\program files\common files\ODBC
2008-12-20 06:23 --d----- c:\program files\common files\SpeechEngines
2008-12-20 06:23 --d--r-- c:\documents and settings\all users\Documents

==================== Find3M ====================

2008-12-20 15:59 76,487 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2008-12-20 14:31 21,640 a------- c:\windows\system32\emptyregdb.dat
2008-12-01 14:13 3,452,928 a------- c:\windows\system32\drivers\ati2mtag.sys
2008-12-01 12:52 425,984 a------- c:\windows\system32\ATIDEMGX.dll
2008-12-01 12:51 318,464 a------- c:\windows\system32\ati2dvag.dll
2008-12-01 12:46 11,304,960 a------- c:\windows\system32\atioglxx.dll
2008-12-01 12:41 188,416 a------- c:\windows\system32\atipdlxx.dll
2008-12-01 12:40 147,456 a------- c:\windows\system32\Oemdspif.dll
2008-12-01 12:40 26,112 a------- c:\windows\system32\Ati2mdxx.exe
2008-12-01 12:40 43,520 a------- c:\windows\system32\ati2edxx.dll
2008-12-01 12:40 143,360 a------- c:\windows\system32\ati2evxx.dll
2008-12-01 12:38 598,016 a------- c:\windows\system32\ati2evxx.exe
2008-12-01 12:37 53,248 a------- c:\windows\system32\ATIDDC.DLL
2008-12-01 12:27 4,120,384 a------- c:\windows\system32\ati3duag.dll
2008-12-01 12:19 307,200 a------- c:\windows\system32\atiiiexx.dll
2008-12-01 12:11 2,495,360 a------- c:\windows\system32\ativvaxx.dll
2008-12-01 12:11 3,107,788 a------- c:\windows\system32\ativvaxx.dat
2008-12-01 12:11 3,107,788 a------- c:\windows\system32\ativva5x.dat
2008-12-01 12:11 887,724 a------- c:\windows\system32\ativva6x.dat
2008-12-01 11:57 48,640 a------- c:\windows\system32\amdpcom32.dll
2008-12-01 11:53 401,408 a------- c:\windows\system32\atikvmag.dll
2008-12-01 11:53 45,056 a------- c:\windows\system32\amdcalrt.dll
2008-12-01 11:53 45,056 a------- c:\windows\system32\amdcalcl.dll
2008-12-01 11:52 86,016 a------- c:\windows\system32\atiadlxx.dll
2008-12-01 11:52 17,408 a------- c:\windows\system32\atitvo32.dll
2008-12-01 11:51 53,248 a------- c:\windows\system32\drivers\ati2erec.dll
2008-12-01 11:50 286,720 a------- c:\windows\system32\atiok3x2.dll
2008-12-01 11:50 3,252,224 a------- c:\windows\system32\Amdcaldd.dll
2008-12-01 11:45 577,536 a------- c:\windows\system32\ati2cqag.dll
2008-10-30 06:45 180,720 a------- c:\windows\system32\atiicdxx.dat
2008-10-23 04:36 286,720 a------- c:\windows\system32\gdi32.dll
2008-10-21 10:51 118,784 a------- c:\windows\system32\atibrtmon.exe
2008-10-16 12:38 826,368 a------- c:\windows\system32\wininet.dll

============= FINISH: 13:08:18.84 ==============

descriptionSolvedRe: Troj/Rustok-N HJT log and symptoms

more_horiz
Log looks clean.

Please run a GMER Rootkit scan:

Download GMER's application from here:
http://www.gmer.net/gmer.zip

Unzip it and start the GMER.exe
Click the Rootkit tab and click the Scan button.

Once done, click the Copy button.
This will copy the results to your clipboard.
Paste the results in your next reply.

Warning ! Please, do not select the "Show all" checkbox during the scan.

If you're having problems with running GMER.exe, try it in safe mode.
This tools works in safe mode. Other rootkitrevealers don't.

descriptionSolvedGMER log

more_horiz
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-01-01 15:04:18
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.14 ----

SSDT spda.sys ZwCreateKey [0xF74D70E0]
SSDT spda.sys ZwEnumerateKey [0xF74F5CA2]
SSDT spda.sys ZwEnumerateValueKey [0xF74F6030]
SSDT spda.sys ZwOpenKey [0xF74D70C0]
SSDT spda.sys ZwQueryKey [0xF74F6108]
SSDT spda.sys ZwQueryValueKey [0xF74F5F88]
SSDT spda.sys ZwSetValueKey [0xF74F619A]

INT 0x62 ? 89BA1BF8
INT 0x73 ? 89A10F00
INT 0x73 ? 89A10F00
INT 0x82 ? 89BA1BF8
INT 0x83 ? 89BA1BF8
INT 0x83 ? 89BA1BF8
INT 0x83 ? 89A10F00
INT 0x83 ? 89BA1BF8
INT 0xA4 ? 89A10F00
INT 0xB4 ? 89A10F00

Code 8975F218 ZwFlushInstructionCache
Code A4383E99 pIofCallDriver

---- Kernel code sections - GMER 1.0.14 ----

PAGE ntoskrnl.exe!ZwFlushInstructionCache 80587BFB 5 Bytes JMP 8975F21C
? spda.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload B99448AC 5 Bytes JMP 89A104E0

---- User code sections - GMER 1.0.14 ----

.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1924] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 4 Bytes [ C2, 04, 00, 00 ]
.text C:\WINDOWS\system32\SearchIndexer.exe[2640] kernel32.dll!WriteFile 7C810E17 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)

---- Kernel IAT/EAT - GMER 1.0.14 ----

IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 89BA32D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F7508C4C] spda.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7508CA0] spda.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74D8040] spda.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74D813C] spda.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74D80BE] spda.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74D87FC] spda.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74D86D2] spda.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint]

descriptionSolvedcont.

more_horiz
---- User IAT/EAT - GMER 1.0.14 ----

IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6603DB56] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!GetPixel] [6603E33F] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!SetPixel] [6603E3A4] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6603DB56] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [6603DC79] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowPlacement] [66603F30] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [6603DC30] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6603DB56] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [6603DC30] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [6603DC79] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongA] [66603E7C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[160] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!GetPixel] [6603E33F] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!SetPixel] [6603E3A4] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6603DB56] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [6603DC79] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)

descriptionSolvedRe: Troj/Rustok-N HJT log and symptoms

more_horiz
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowPlacement] [66603F30] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [6603DC30] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6603DB56] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [6603DC30] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [6603DC79] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongA] [66603E7C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6603DB56] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe[176] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6603DB56] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [6603DC30] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [6603DC79] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongA] [66603E7C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6603DB56] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [6603DC79] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [6603DC30] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6603DB56] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[184] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)

descriptionSolvedRe: Troj/Rustok-N HJT log and symptoms

more_horiz
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6603DB56] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [6603DC30] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [6603DC79] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongA] [66603E7C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!GetPixel] [6603E33F] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!SetPixel] [6603E3A4] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6603DB56] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [6603DC79] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowPlacement] [66603F30] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [6603DC30] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6603DB56] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe[200] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6603DB56] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)

descriptionSolvedRe: Troj/Rustok-N HJT log and symptoms

more_horiz
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [6603DC30] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [6603DC79] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongA] [66603E7C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6603DB56] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!GetPixel] [6603E33F] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!SetPixel] [6603E3A4] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6603DB56] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [6603DC79] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowPos] [66603F82] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DeferWindowPos] [66603E28] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetWindowPlacement] [66603F30] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!MoveWindow] [66603F52] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [6603DC30] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe[228] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\WINDOWS\system32\CTHELPER.EXE[256] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\WINDOWS\system32\CTHELPER.EXE[256] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\WINDOWS\system32\CTHELPER.EXE[256] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\WINDOWS\system32\CTHELPER.EXE[256] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\WINDOWS\system32\CTHELPER.EXE[256] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\WINDOWS\system32\CTHELPER.EXE[256] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\WINDOWS\system32\CTHELPER.EXE[256] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6603DB5C] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\WINDOWS\system32\CTHELPER.EXE[256] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6603DBB3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\WINDOWS\system32\CTHELPER.EXE[256] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6603DB56] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (WindowBlinds (32 bit XP)/Stardock Corporation)
IAT C:\WINDOWS\system32\CTHELPER.EXE[256] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CallWindowProcW] [66604121] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\WINDOWS\system32\CTHELPER.EXE[256] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetWindowLongW] [66603EA3] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\WINDOWS\system32\CTHELPER.EXE[256] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetWindowRect] [66603FB5] C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)

descriptionSolvedRe: Troj/Rustok-N HJT log and symptoms

more_horiz
http://www.mediafire.com/?sharekey=da0bf26139d6843bd2db6fb9a8902bda

Last edited by scottf on 1st January 2009, 11:25 pm; edited 1 time in total (Reason for editing : http://www.mediafire.com/?sharekey=da0bf26139d6843bd2db6fb9a8902bda)

descriptionSolvedRe: Troj/Rustok-N HJT log and symptoms

more_horiz
log available at http://www.mediafire.com/?sharekey=da0bf26139d6843bd2db6fb9a8902bda

Last edited by scottf on 1st January 2009, 11:25 pm; edited 1 time in total (Reason for editing : excessive length)

descriptionSolvedRe: Troj/Rustok-N HJT log and symptoms

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum