Could you please help me - got the BankerA.Fox and Win32/Nuqel.E - here is the log after running my Spyware Doctor program. - Scott
date/time : 2009-02-21, 20:05:46, 625ms
computer name : D2Y60F21
user name : Scott Smyth
operating system : Windows XP Service Pack 2 build 2600
system language : English
system up time : 2 hours 22 minutes
program up time : 12 minutes 11 seconds
processor : Intel(R) Pentium(R) 4 CPU 2.40GHz
physical memory : 83/511 MB (free/total)
free disk space : (C 42.48 GB
display mode : 1024x768, 32 bit
process id : $808
allocated memory : 161.77 MB
executable : swdoctor.exe
exec. date/time : 2006-12-11 15:35
version : 4.0.0.2621
madExcept version : 2.7g
exception class : Exception
exception message : Error load log from "C:\Documents and Settings\Scott Smyth\Local Settings\Tempfirstlog.xml".
main thread ($1094):
0055ea05 +0a9 swdoctor.exe uXMLLog 555 +6 TXMLLog.LoadFromFile
0052bd7a +02a swdoctor.exe uGetSupport 323 +3 TfrmGetSupport.hlViewFirstLogClick
0042c28a +04e swdoctor.exe HotLabel 104 +3 THotLabel.Click
0042c165 +021 swdoctor.exe HotLabel 74 +3 THotLabel.WMLButtonDown
01bd1340 +188 vcl70.bpl Controls TControl.WndProc
01bd445d +089 vcl70.bpl Controls TWinControl.WndProc
01bd1340 +188 vcl70.bpl Controls TControl.WndProc
01bd1110 +024 vcl70.bpl Controls TControl.Perform
01bd43c2 +082 vcl70.bpl Controls TWinControl.IsControlMouseMsg
01bd44ae +0da vcl70.bpl Controls TWinControl.WndProc
01bd41a8 +02c vcl70.bpl Controls TWinControl.MainWndProc
0052ae87 +027 swdoctor.exe uGetSupport 77 +2 ShowGetSupportDialog
0055be3f +007 swdoctor.exe uGuiController 24 +1 TGUIController.ShowSupport
06e3a0c6 +076 maldetective.dll RunTool
005698f2 +026 swdoctor.exe Database 685 +2 TLibrary.Simple_RunTool
005303c3 +0bf swdoctor.exe Unit_tools 149 +13 TFormTools.ButtonRunToolClick
01bd14d8 +064 vcl70.bpl Controls TControl.Click
01bc16d0 +01c vcl70.bpl Stdctrls TButton.Click
01bc17c4 +00c vcl70.bpl Stdctrls TButton.CNCommand
01bd1340 +188 vcl70.bpl Controls TControl.WndProc
01bd452b +157 vcl70.bpl Controls TWinControl.WndProc
01bc1594 +06c vcl70.bpl Stdctrls TButtonControl.WndProc
01bd1110 +024 vcl70.bpl Controls TControl.Perform
01bd4d1b +00b vcl70.bpl Controls TWinControl.WMCommand
01bd1340 +188 vcl70.bpl Controls TControl.WndProc
01bd452b +157 vcl70.bpl Controls TWinControl.WndProc
01bd41a8 +02c vcl70.bpl Controls TWinControl.MainWndProc
7e41b8fe +044 USER32.dll SendMessageW
01bd1340 +188 vcl70.bpl Controls TControl.WndProc
7e41f658 +016 USER32.dll CallWindowProcA
01bd460f +0d7 vcl70.bpl Controls TWinControl.DefaultHandler
01bd18e0 +010 vcl70.bpl Controls TControl.WMLButtonUp
01bd1340 +188 vcl70.bpl Controls TControl.WndProc
01bd452b +157 vcl70.bpl Controls TWinControl.WndProc
01bc1594 +06c vcl70.bpl Stdctrls TButtonControl.WndProc
01bd41a8 +02c vcl70.bpl Controls TWinControl.MainWndProc
01b6e9bb +00f vcl70.bpl Extctrls TTimer.Timer
01b6e89f +02b vcl70.bpl Extctrls TTimer.WndProc
06952921 +01d iesdpb.dll DllRegisterServer
069975c6 +042 iesdpb.dll PUB_Start
0703c6eb +033 popupblocker.dll StartOnGuard
00569a05 +025 swdoctor.exe Database 720 +2 TLibrary.OnGuard_Start
00531333 +027 swdoctor.exe uOnGuard 325 +3 TfrmOnGuard.ActivateDLL
005311ab +0bf swdoctor.exe uOnGuard 285 +9 TfrmOnGuard.ActivateOnGuard
00531375 +02d swdoctor.exe uOnGuard 331 +1 TfrmOnGuard.WMOnGuard
01bd1340 +188 vcl70.bpl Controls TControl.WndProc
01bd452b +157 vcl70.bpl Controls TWinControl.WndProc
01bee005 +421 vcl70.bpl Forms TCustomForm.WndProc
01bd41a8 +02c vcl70.bpl Controls TWinControl.MainWndProc
01bf4de2 +00a vcl70.bpl Forms TApplication.HandleMessage
01bf5002 +096 vcl70.bpl Forms TApplication.Run
00582882 +2ee swdoctor.exe swdoctor 148 +63 initialization
7c91312f +069 ntdll.dll RtlUnicodeStringToAnsiString
7c812b94 +0b6 kernel32.dll GetVersionExA
thread $1294:
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7e42e03d +3b USER32.dll GetMessageA
77c3a3ad +a6 msvcrt.dll _endthreadex
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
6b989a08 +00 msscript.ocx
thread $10d0 (TSubscriptionThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9be +0a ntdll.dll NtWaitForSingleObject
7c8025c5 +85 kernel32.dll WaitForSingleObjectEx
7c80252d +0d kernel32.dll WaitForSingleObject
4003d801 +09 rtl70.bpl Syncobjs TEvent.WaitFor
005672b7 +1b swdoctor.exe uSubscription 445 +2 TSubscriptionThread.Execute
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
0056720f +1f swdoctor.exe uSubscription 430 +1 TSubscriptionThread.Create
thread $1180:
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90d85a +0a ntdll.dll NtDelayExecution
7c8023e7 +4b kernel32.dll SleepEx
7c80244c +0a kernel32.dll Sleep
thread $1280:
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e397 +0a ntdll.dll NtReplyWaitReceivePortEx
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by thread $1250 at:
77e875c7 +00 RPCRT4.dll
thread $1548 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $154c (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $10ec (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $1558 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $1568 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $1390 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $14c0 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $145c (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $13f8 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $1414 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $137c (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $13a8 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $1018 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $147c (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $15a8:
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e286 +0a ntdll.dll NtReadFile
7c80186f +61 kernel32.dll ReadFile
thread $15b0 (TRegMonitorThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
06d31a11 +00 Immunizer.dll
thread $1554:
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e286 +0a ntdll.dll NtReadFile
7c80186f +61 kernel32.dll ReadFile
thread $1274:
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e286 +0a ntdll.dll NtReadFile
7c80186f +61 kernel32.dll ReadFile
thread $166c (TNotiThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90d85a +0a ntdll.dll NtDelayExecution
7c8023e7 +4b kernel32.dll SleepEx
7c80244c +0a kernel32.dll Sleep
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
071ef4b2 +96 sdn.dll InitTool
thread $1580:
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e286 +0a ntdll.dll NtReadFile
7c80186f +61 kernel32.dll ReadFile
thread $15dc (TWorkerThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9be +0a ntdll.dll NtWaitForSingleObject
7c8025c5 +85 kernel32.dll WaitForSingleObjectEx
7c80252d +0d kernel32.dll WaitForSingleObject
004d2496 +16 swdoctor.exe VirtualTrees 5064 +3 TWorkerThread.Execute
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
004d239f +23 swdoctor.exe VirtualTrees 5027 +1 TWorkerThread.Create
thread $af0 (TRegMonitorThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
068ca6b0 +00 iemonitor.dll
thread $15e0 (TRegMonitorThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
068ca6b0 +00 iemonitor.dll
thread $1204 (TRegMonitorThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
068ca6b0 +00 iemonitor.dll
thread $1678 (TRegMonitorThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
06fdba7d +00 networkguard.dll
thread $167c (TRegMonitorThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
06fdba7d +00 networkguard.dll
thread $1598 (TRegMonitorThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
06fdba7d +00 networkguard.dll
thread $15c0 (TRegMonitorThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
06fdba7d +00 networkguard.dll
date/time : 2009-02-21, 20:05:46, 625ms
computer name : D2Y60F21
user name : Scott Smyth
operating system : Windows XP Service Pack 2 build 2600
system language : English
system up time : 2 hours 22 minutes
program up time : 12 minutes 11 seconds
processor : Intel(R) Pentium(R) 4 CPU 2.40GHz
physical memory : 83/511 MB (free/total)
free disk space : (C 42.48 GB
display mode : 1024x768, 32 bit
process id : $808
allocated memory : 161.77 MB
executable : swdoctor.exe
exec. date/time : 2006-12-11 15:35
version : 4.0.0.2621
madExcept version : 2.7g
exception class : Exception
exception message : Error load log from "C:\Documents and Settings\Scott Smyth\Local Settings\Tempfirstlog.xml".
main thread ($1094):
0055ea05 +0a9 swdoctor.exe uXMLLog 555 +6 TXMLLog.LoadFromFile
0052bd7a +02a swdoctor.exe uGetSupport 323 +3 TfrmGetSupport.hlViewFirstLogClick
0042c28a +04e swdoctor.exe HotLabel 104 +3 THotLabel.Click
0042c165 +021 swdoctor.exe HotLabel 74 +3 THotLabel.WMLButtonDown
01bd1340 +188 vcl70.bpl Controls TControl.WndProc
01bd445d +089 vcl70.bpl Controls TWinControl.WndProc
01bd1340 +188 vcl70.bpl Controls TControl.WndProc
01bd1110 +024 vcl70.bpl Controls TControl.Perform
01bd43c2 +082 vcl70.bpl Controls TWinControl.IsControlMouseMsg
01bd44ae +0da vcl70.bpl Controls TWinControl.WndProc
01bd41a8 +02c vcl70.bpl Controls TWinControl.MainWndProc
0052ae87 +027 swdoctor.exe uGetSupport 77 +2 ShowGetSupportDialog
0055be3f +007 swdoctor.exe uGuiController 24 +1 TGUIController.ShowSupport
06e3a0c6 +076 maldetective.dll RunTool
005698f2 +026 swdoctor.exe Database 685 +2 TLibrary.Simple_RunTool
005303c3 +0bf swdoctor.exe Unit_tools 149 +13 TFormTools.ButtonRunToolClick
01bd14d8 +064 vcl70.bpl Controls TControl.Click
01bc16d0 +01c vcl70.bpl Stdctrls TButton.Click
01bc17c4 +00c vcl70.bpl Stdctrls TButton.CNCommand
01bd1340 +188 vcl70.bpl Controls TControl.WndProc
01bd452b +157 vcl70.bpl Controls TWinControl.WndProc
01bc1594 +06c vcl70.bpl Stdctrls TButtonControl.WndProc
01bd1110 +024 vcl70.bpl Controls TControl.Perform
01bd4d1b +00b vcl70.bpl Controls TWinControl.WMCommand
01bd1340 +188 vcl70.bpl Controls TControl.WndProc
01bd452b +157 vcl70.bpl Controls TWinControl.WndProc
01bd41a8 +02c vcl70.bpl Controls TWinControl.MainWndProc
7e41b8fe +044 USER32.dll SendMessageW
01bd1340 +188 vcl70.bpl Controls TControl.WndProc
7e41f658 +016 USER32.dll CallWindowProcA
01bd460f +0d7 vcl70.bpl Controls TWinControl.DefaultHandler
01bd18e0 +010 vcl70.bpl Controls TControl.WMLButtonUp
01bd1340 +188 vcl70.bpl Controls TControl.WndProc
01bd452b +157 vcl70.bpl Controls TWinControl.WndProc
01bc1594 +06c vcl70.bpl Stdctrls TButtonControl.WndProc
01bd41a8 +02c vcl70.bpl Controls TWinControl.MainWndProc
01b6e9bb +00f vcl70.bpl Extctrls TTimer.Timer
01b6e89f +02b vcl70.bpl Extctrls TTimer.WndProc
06952921 +01d iesdpb.dll DllRegisterServer
069975c6 +042 iesdpb.dll PUB_Start
0703c6eb +033 popupblocker.dll StartOnGuard
00569a05 +025 swdoctor.exe Database 720 +2 TLibrary.OnGuard_Start
00531333 +027 swdoctor.exe uOnGuard 325 +3 TfrmOnGuard.ActivateDLL
005311ab +0bf swdoctor.exe uOnGuard 285 +9 TfrmOnGuard.ActivateOnGuard
00531375 +02d swdoctor.exe uOnGuard 331 +1 TfrmOnGuard.WMOnGuard
01bd1340 +188 vcl70.bpl Controls TControl.WndProc
01bd452b +157 vcl70.bpl Controls TWinControl.WndProc
01bee005 +421 vcl70.bpl Forms TCustomForm.WndProc
01bd41a8 +02c vcl70.bpl Controls TWinControl.MainWndProc
01bf4de2 +00a vcl70.bpl Forms TApplication.HandleMessage
01bf5002 +096 vcl70.bpl Forms TApplication.Run
00582882 +2ee swdoctor.exe swdoctor 148 +63 initialization
7c91312f +069 ntdll.dll RtlUnicodeStringToAnsiString
7c812b94 +0b6 kernel32.dll GetVersionExA
thread $1294:
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7e42e03d +3b USER32.dll GetMessageA
77c3a3ad +a6 msvcrt.dll _endthreadex
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
6b989a08 +00 msscript.ocx
thread $10d0 (TSubscriptionThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9be +0a ntdll.dll NtWaitForSingleObject
7c8025c5 +85 kernel32.dll WaitForSingleObjectEx
7c80252d +0d kernel32.dll WaitForSingleObject
4003d801 +09 rtl70.bpl Syncobjs TEvent.WaitFor
005672b7 +1b swdoctor.exe uSubscription 445 +2 TSubscriptionThread.Execute
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
0056720f +1f swdoctor.exe uSubscription 430 +1 TSubscriptionThread.Create
thread $1180:
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90d85a +0a ntdll.dll NtDelayExecution
7c8023e7 +4b kernel32.dll SleepEx
7c80244c +0a kernel32.dll Sleep
thread $1280:
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e397 +0a ntdll.dll NtReplyWaitReceivePortEx
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by thread $1250 at:
77e875c7 +00 RPCRT4.dll
thread $1548 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $154c (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $10ec (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $1558 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $1568 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $1390 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $14c0 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $145c (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $13f8 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $1414 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $137c (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $13a8 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $1018 (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $147c (TRegistryHook):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
02db3bb0 +00 actstartup.dll
thread $15a8:
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e286 +0a ntdll.dll NtReadFile
7c80186f +61 kernel32.dll ReadFile
thread $15b0 (TRegMonitorThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
06d31a11 +00 Immunizer.dll
thread $1554:
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e286 +0a ntdll.dll NtReadFile
7c80186f +61 kernel32.dll ReadFile
thread $1274:
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e286 +0a ntdll.dll NtReadFile
7c80186f +61 kernel32.dll ReadFile
thread $166c (TNotiThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90d85a +0a ntdll.dll NtDelayExecution
7c8023e7 +4b kernel32.dll SleepEx
7c80244c +0a kernel32.dll Sleep
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
071ef4b2 +96 sdn.dll InitTool
thread $1580:
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e286 +0a ntdll.dll NtReadFile
7c80186f +61 kernel32.dll ReadFile
thread $15dc (TWorkerThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9be +0a ntdll.dll NtWaitForSingleObject
7c8025c5 +85 kernel32.dll WaitForSingleObjectEx
7c80252d +0d kernel32.dll WaitForSingleObject
004d2496 +16 swdoctor.exe VirtualTrees 5064 +3 TWorkerThread.Execute
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
004d239f +23 swdoctor.exe VirtualTrees 5027 +1 TWorkerThread.Create
thread $af0 (TRegMonitorThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
068ca6b0 +00 iemonitor.dll
thread $15e0 (TRegMonitorThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
068ca6b0 +00 iemonitor.dll
thread $1204 (TRegMonitorThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
068ca6b0 +00 iemonitor.dll
thread $1678 (TRegMonitorThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
06fdba7d +00 networkguard.dll
thread $167c (TRegMonitorThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
06fdba7d +00 networkguard.dll
thread $1598 (TRegMonitorThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
06fdba7d +00 networkguard.dll
thread $15c0 (TRegMonitorThread):
7c90eb94 +00 ntdll.dll KiFastSystemCallRet
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094dc +00 kernel32.dll WaitForMultipleObjectsEx
7c80a070 +13 kernel32.dll WaitForMultipleObjects
00425bee +16 swdoctor.exe madExcept HookedTThreadExecute
00425b83 +27 swdoctor.exe madExcept ThreadExceptFrame
>> created by main thread ($1094) at:
06fdba7d +00 networkguard.dll