This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Vundo, Redirect, Trojans suspected on my PC

37 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTListIt logfile created on: 3/29/2009 1:02:32 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.7.2 Folder = C:\Documents and Settings\Helene Lesueur\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.30 Mb Total Physical Memory | 274.61 Mb Available Physical Memory | 53.71% Memory free
1.22 Gb Paging File | 1.01 Gb Available in Paging File | 82.71% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 38.51 Gb Free Space | 68.90% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: GUESTROOM
Current User Name: Helene Lesueur
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINNT\GWMDMMSG.exe (GTW)
PRC - C:\WINNT\system32\SK9910DM.EXE (Silitek Corporation)
PRC - C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe (Roxio)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - C:\WINNT\system32\devldr32.exe (Creative Technology Ltd.)
PRC - C:\WINNT\explorer.exe (Microsoft Corporation)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\McShield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - C:\Documents and Settings\Helene Lesueur\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINNT\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (CCALib8 [Auto | Running]) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINNT\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPodService [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Computer, Inc.)
SRV - (lxdb_device [On_Demand | Stopped]) – C:\WINNT\system32\lxdbcoms.exe ( )
SRV - (mcmscsvc [Auto | Running]) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McNASvc [Auto | Running]) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (McODS [On_Demand | Stopped]) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy [Auto | Running]) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McShield [Unknown | Running]) – C:\Program Files\McAfee\VirusScan\McShield.exe (McAfee, Inc.)
SRV - (McSysmon [On_Demand | Running]) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MpfService [Auto | Running]) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PictureTaker [On_Demand | Stopped]) – File not found
SRV - (WinDefend [Auto | Stopped]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ac97intc [On_Demand | Running]) – C:\WINNT\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (aeaudio [On_Demand | Stopped]) – C:\WINNT\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (AN983 [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\AN983.sys (ADMtek Incorporated.)
DRV - (ASPI32 [Auto | Running]) – C:\WINNT\System32\drivers\aspi32.sys (Adaptec)
DRV - (ati2mpaa [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\ati2mpaa.sys (ATI Technologies Inc.)
DRV - (ati2mtaa [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\ati2mtaa.sys (ATI Technologies Inc.)
DRV - (BCMModem [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\BCMDM.sys (BCM)
DRV - (Cdr4_xp [System | Running]) – C:\WINNT\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (Cdralw2k [System | Running]) – C:\WINNT\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (cdrbsvsd [System | Running]) – C:\WINNT\System32\drivers\cdrbsvsd.sys (B.H.A Corporation)
DRV - (cdudf_xp [System | Running]) – C:\WINNT\System32\drivers\cdudf_xp.sys (Roxio)
DRV - (ctac32k [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (ctaud2k [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctljystk [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ctljystk.sys (Creative Technology Ltd.)
DRV - (ctprxy2k [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (DCamUSBSQTECH [On_Demand | Stopped]) – C:\WINNT\System32\Drivers\SQcaptur.sys (Service & Quality Technology.)
DRV - (dvd_2K [On_Demand | Stopped]) – C:\WINNT\System32\drivers\Dvd_2k.sys (Roxio)
DRV - (E100B [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (EL90XBC [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\el90xbc5.sys (3Com Corporation)
DRV - (emu10k [On_Demand | Running]) – C:\WINNT\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (emu10k1 [On_Demand | Running]) – C:\WINNT\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emupia [On_Demand | Stopped]) – C:\WINNT\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (Eplpdx02 [On_Demand | Running]) – C:\WINNT\System32\Drivers\EPLPDX02.SYS (MK Systems CO., LTD.)
DRV - (gameenum [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINNT\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (GTWModem [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\GWMDM.sys (GTW)
DRV - (ha10kx2k [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (ialm [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (L8042pr2 [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\L8042pr2.Sys (Logitech, Inc.)
DRV - (LHidFlt2 [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\LHidFlt2.Sys (Logitech, Inc.)
DRV - (LHidUsb [On_Demand | Running]) – C:\WINNT\System32\Drivers\LHidUsb.Sys (Logitech, Inc.)
DRV - (LMouFlt2 [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\LMouFlt2.Sys (Logitech, Inc.)
DRV - (mfeavfk [On_Demand | Running]) – C:\WINNT\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) – C:\WINNT\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [System | Running]) – C:\WINNT\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [On_Demand | Stopped]) – C:\WINNT\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (mfesmfk [On_Demand | Running]) – C:\WINNT\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mmc_2K [On_Demand | Running]) – C:\WINNT\System32\drivers\Mmc_2k.sys (Roxio)
DRV - (MODEMCSA [On_Demand | Running]) – C:\WINNT\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (MPFP [System | Running]) – C:\WINNT\System32\Drivers\Mpfp.sys (McAfee, Inc.)
DRV - (MR97310_VGA_DUAL_CAMERA [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\mr97310v.sys (Mars Semiconductor Corp.)
DRV - (ms_mpu401 [On_Demand | Stopped]) – C:\WINNT\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (nv [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (NwlnkIpx [Auto | Running]) – C:\WINNT\System32\DRIVERS\nwlnkipx.sys (Microsoft Corporation)
DRV - (NwlnkNb [Auto | Running]) – C:\WINNT\System32\DRIVERS\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx [Auto | Running]) – C:\WINNT\System32\DRIVERS\nwlnkspx.sys (Microsoft Corporation)
DRV - (ossrv [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (pwd_2k [System | Running]) – C:\WINNT\System32\drivers\pwd_2K.sys (Roxio)
DRV - (PxHelp20 [Boot | Running]) – C:\WINNT\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfman [On_Demand | Running]) – C:\WINNT\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (Sk99202k [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\Sk99202k.sys (Silitek Corp.)
DRV - (Sk9920nt [System | Running]) – C:\WINNT\System32\DRIVERS\Sk9920nt.sys (Silitek Corp.)
DRV - (smwdm [On_Demand | Stopped]) – C:\WINNT\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (sonypvs1 [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\sonypvs1.sys (Sony Corporation)
DRV - (UdfReadr_xp [System | Running]) – C:\WINNT\System32\drivers\udfreadr_xp.sys (Roxio)
DRV - (ultra [Disabled | Stopped]) – C:\WINNT\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINNT\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (wandrv [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\wandrv.sys (America Online, Inc.)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [System | Stopped]) – C:\WINNT\system32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adb…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.comcast.net/comcast.html"
[2006/07/17 20:02:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Helene Lesueur\Application Data\mozilla\Firefox\Profiles\5mmw5ggf.default\extensions
[2006/07/17 20:02:34 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2006/07/17 20:02:46 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}

O1 HOSTS File: (734 bytes) - C:\WINNT\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" (Roxio)
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [FlipViewer Library] C:\Program Files\E-Book Systems\FlipViewer\\FlipViewerLibrary.exe /showmode=hide File not found
O4 - HKLM..\Run: [GWMDMMSG] GWMDMMSG.exe (GTW)
O4 - HKLM..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE (Silitek Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Computer, Inc.)
O4 - HKLM..\Run: [Logitech Utility] Logi_MwX.Exe (Logitech Inc.)
O4 - HKLM..\Run: [LXDBCATS] rundll32 C:\WINNT\System32\spool\DRIVERS\W32X86\3\LXDBtime.dll,_RunDLLEntry@16 ()
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey (McAfee, Inc.)
O4 - HKLM..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server (Support.com, Inc.)
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe (Yahoo! Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINNT\System32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Sites: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Sites: mcafee.com ([]https in Trusted sites)
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsupport.com/OneClickFix/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/0/f…tualEarth3D.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} http://www.rockyou.com/RockYouImageUploader.cab (RockYou Image Uploader Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINNT\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ic32pp {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - C:\WINNT\wc98pp.dll ()
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINNT\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINNT\system32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( msansspc.dll) - File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
Ok I was able to post the entire extras.txt in message 29. I was able to post a couple pages of the otList.txt before being directed to the post by Admin Blair stating that I need a newer version hijackthis to post my hjtlog results. Going to try to download the gmer that you asked me too although there was not a link in the message that I could see.
Actually there is a gmer link. Was reading message from my cell phone first so couldn't see the link. Downloading that zip file now & will try to post the results when finished.
sweetiehlm5, I'm thinking that the problem with posting information here is a board error instead of a problem with your computer. It is somehow thinking that you're posting a HijackThis log and you aren't. Haven't seen that before. :wacko:
Hi Tomk, I think that must be the problem too. I wish it had of worked because I am trying to do the gmer.zip but when I right click I don't get an extract option & I have to select from extract to, extract to here, extract to C:folder/desktop which I picked but it didn't come up with options you gave. With erunt I just clicked open with Winzip & was able to follow your instructions for that from there. I have the free version on winzip so it might be an older version or something. Which option should I pick with gmer.zip? Should I pick open with winzip or which one of the extraction options that I have (extract here, extract to folder c:folder/desktop)?
Here are the gmer scan results

GMER 1.0.15.14966 - http://www.gmer.net
Rootkit scan 2009-03-29 09:10:01
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xF6C209AA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xF6C20A41]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xF6C20958]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xF6C2096C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xF6C20A55]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xF6C20A81]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xF6C20AEF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xF6C20AD9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF6C209EA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xF6C20B1B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xF6C20A2D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xF6C20930]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xF6C20944]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xF6C209BE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xF6C20B57]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xF6C20AC3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xF6C20AAD]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xF6C20A6B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xF6C20B43]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xF6C20B2F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xF6C20996]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xF6C20982]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xF6C20A97]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xF6C20A19]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xF6C20B05]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF6C20A00]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xF6C209D4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!ZwYieldExecution 804F0EA6 7 Bytes JMP F6C209D8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwOpenKey 80568D59 5 Bytes JMP F6C20A31 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryValueKey 8056A1F2 2 Bytes JMP F6C20AB1 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryValueKey + 3 8056A1F5 4 Bytes [6B, 76, 90, 90] {IMUL ESI, [ESI-0x70], 0x90}
PAGE ntoskrnl.exe!NtCreateFile 8056CDC0 5 Bytes JMP F6C209AE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtSetInformationProcess 8056DC01 5 Bytes JMP F6C20986 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateKey 8057065D 5 Bytes JMP F6C20A45 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryKey 80570A6D 7 Bytes JMP F6C20B5B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwEnumerateKey 80570D64 7 Bytes JMP F6C20AF3 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenProcess 805717C7 5 Bytes JMP F6C20934 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 80571CB1 7 Bytes JMP F6C209C2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetValueKey 80572889 7 Bytes JMP F6C20A9B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 805736E6 5 Bytes JMP F6C20A04 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtMapViewOfSection 80573B61 7 Bytes JMP F6C209EE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcessEx 8057FC6C 7 Bytes JMP F6C20970 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwTerminateProcess 805822EC 5 Bytes JMP F6C20A1D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenThread 8058A1C9 5 Bytes JMP F6C20948 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwNotifyChangeKey 8058A699 5 Bytes JMP F6C20B1F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwEnumerateValueKey 80590677 7 Bytes JMP F6C20ADD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteValueKey 80592D5C 7 Bytes JMP F6C20A85 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteKey 805952CA 7 Bytes JMP F6C20A59 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcess 805B136A 5 Bytes JMP F6C2095C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetContextThread 8062DCF7 5 Bytes JMP F6C2099A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnloadKey 8064DA12 7 Bytes JMP F6C20B09 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryMultipleValueKey 8064E338 7 Bytes JMP F6C20AC7 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRenameKey 8064E7B6 7 Bytes JMP F6C20A6F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRestoreKey 8064ECA9 5 Bytes JMP F6C20B33 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwReplaceKey 8064F112 5 Bytes JMP F6C20B47 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

—- User code sections - GMER 1.0.15 —-

.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D90FEF
.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D90087
.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D90F9C
.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D90076
.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D90065
.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D90FD4
.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D90F52
.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D90F6D
.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D900EB
.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D900C6
.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00D900FC
.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00D90FC3
.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00D9000A
.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00D90098
.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00D90036
.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00D90025
.text C:\WINNT\System32\svchost.exe[312] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00D900B5
.text C:\WINNT\System32\svchost.exe[312] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00D70F9E
.text C:\WINNT\System32\svchost.exe[312] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00D70F68
.text C:\WINNT\System32\svchost.exe[312] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00D70FB9
.text C:\WINNT\System32\svchost.exe[312] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00D70FCA
.text C:\WINNT\System32\svchost.exe[312] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00D70F83
.text C:\WINNT\System32\svchost.exe[312] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00D70FE5
.text C:\WINNT\System32\svchost.exe[312] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00D7001B
.text C:\WINNT\System32\svchost.exe[312] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00D7000A
.text C:\WINNT\System32\svchost.exe[312] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D6003D
.text C:\WINNT\System32\svchost.exe[312] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D6002C
.text C:\WINNT\System32\svchost.exe[312] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D60011
.text C:\WINNT\System32\svchost.exe[312] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D60000
.text C:\WINNT\System32\svchost.exe[312] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D60FBC
.text C:\WINNT\System32\svchost.exe[312] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D60FD7
.text C:\WINNT\System32\svchost.exe[312] ws2_32.dll!socket 71AB4211 5 Bytes JMP 00D5000A
.text C:\WINNT\System32\svchost.exe[312] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003384
.text C:\WINNT\System32\svchost.exe[312] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINNT\System32\svchost.exe[312] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINNT\System32\svchost.exe[312] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINNT\System32\svchost.exe[312] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003338
.text C:\WINNT\System32\svchost.exe[312] wininet.dll!InternetOpenA 7806C865 5 Bytes JMP 00D80FE5
.text C:\WINNT\System32\svchost.exe[312] wininet.dll!InternetOpenW 7806CE99 5 Bytes JMP 00D80FD4
.text C:\WINNT\System32\svchost.exe[312] wininet.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00D8000A
.text C:\WINNT\System32\svchost.exe[312] wininet.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00D80025
.text C:\WINNT\system32\winlogon.exe[456] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 1000343C
.text C:\WINNT\system32\winlogon.exe[456] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003384
.text C:\WINNT\system32\winlogon.exe[456] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINNT\system32\winlogon.exe[456] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINNT\system32\winlogon.exe[456] WS2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINNT\system32\winlogon.exe[456] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003338
.text C:\WINNT\system32\services.exe[500] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00070FEF
.text C:\WINNT\system32\services.exe[500] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00070096
.text C:\WINNT\system32\services.exe[500] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00070F97
.text C:\WINNT\system32\services.exe[500] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00070FA8
.text C:\WINNT\system32\services.exe[500] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00070065
.text C:\WINNT\system32\services.exe[500] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0007002F
.text C:\WINNT\system32\services.exe[500] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00070F72
.text C:\WINNT\system32\services.exe[500] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 000700B8
.text C:\WINNT\system32\services.exe[500] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00070F32
.text C:\WINNT\system32\services.exe[500] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 000700D5
.text C:\WINNT\system32\services.exe[500] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00070F17
.text C:\WINNT\system32\services.exe[500] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 0007004A
.text C:\WINNT\system32\services.exe[500] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00070FDE
.text C:\WINNT\system32\services.exe[500] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 000700A7
.text C:\WINNT\system32\services.exe[500] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 0007001E
.text C:\WINNT\system32\services.exe[500] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00070FCD
.text C:\WINNT\system32\services.exe[500] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00070F61
.text C:\WINNT\system32\services.exe[500] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 0006002C
.text C:\WINNT\system32\services.exe[500] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 000600A2
.text C:\WINNT\system32\services.exe[500] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 0006001B
.text C:\WINNT\system32\services.exe[500] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00060000
.text C:\WINNT\system32\services.exe[500] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 0006007D
.text C:\WINNT\system32\services.exe[500] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00060FEF
.text C:\WINNT\system32\services.exe[500] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 0006006C
.text C:\WINNT\system32\services.exe[500] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00060051
.text C:\WINNT\system32\services.exe[500] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00050FA3
.text C:\WINNT\system32\services.exe[500] msvcrt.dll!system 77C293C7 5 Bytes JMP 00050038
.text C:\WINNT\system32\services.exe[500] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00050FC8
.text C:\WINNT\system32\services.exe[500] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00050FE3
.text C:\WINNT\system32\services.exe[500] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0005001D
.text C:\WINNT\system32\services.exe[500] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0005000C
.text C:\WINNT\system32\services.exe[500] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00040000
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C6000A
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C60F5C
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C6005B
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C60F77
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C60040
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C60FB9
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C60093
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C60F41
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C600C9
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C600AE
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00C60F15
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00C60F9E
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00C60FE5
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00C6006C
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00C60FD4
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00C6001B
.text C:\WINNT\system32\lsass.exe[512] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00C60F30
.text C:\WINNT\system32\lsass.exe[512] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00C10047
.text C:\WINNT\system32\lsass.exe[512] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00C10FA5
.text C:\WINNT\system32\lsass.exe[512] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00C1002C
.text C:\WINNT\system32\lsass.exe[512] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00C10011
.text C:\WINNT\system32\lsass.exe[512] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00C10FB6
.text C:\WINNT\system32\lsass.exe[512] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00C10000
.text C:\WINNT\system32\lsass.exe[512] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00C10058
.text C:\WINNT\system32\lsass.exe[512] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00C10FD1
.text C:\WINNT\system32\lsass.exe[512] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00C00F92
.text C:\WINNT\system32\lsass.exe[512] msvcrt.dll!system 77C293C7 5 Bytes JMP 00C00FAD
.text C:\WINNT\system32\lsass.exe[512] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00C00027
.text C:\WINNT\system32\lsass.exe[512] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00C00000
.text C:\WINNT\system32\lsass.exe[512] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00C00FD2
.text C:\WINNT\system32\lsass.exe[512] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00C00FE3
.text C:\WINNT\system32\lsass.exe[512] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00BF0FE5
.text C:\WINNT\system32\lsass.exe[512] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003384
.text C:\WINNT\system32\lsass.exe[512] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINNT\system32\lsass.exe[512] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINNT\system32\lsass.exe[512] WS2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINNT\system32\lsass.exe[512] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003338
.text C:\WINNT\system32\lsass.exe[512] wininet.dll!InternetOpenA 7806C865 5 Bytes JMP 00C20000
.text C:\WINNT\system32\lsass.exe[512] wininet.dll!InternetOpenW 7806CE99 5 Bytes JMP 00C2001B
.text C:\WINNT\system32\lsass.exe[512] wininet.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00C2002C
.text C:\WINNT\system32\lsass.exe[512] wininet.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00C20FDB
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C8000A
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C80F88
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C8007D
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C8006C
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C8005B
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C8002F
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C80F61
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C800A9
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C80F21
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C80F32
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00C800D5
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00C8004A
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00C80FEF
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00C80098
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00C80FC3
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00C80FDE
.text C:\WINNT\system32\svchost.exe[672] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00C800BA
.text C:\WINNT\system32\svchost.exe[672] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00C60047
.text C:\WINNT\system32\svchost.exe[672] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00C60087
.text C:\WINNT\system32\svchost.exe[672] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00C6002C
.text C:\WINNT\system32\svchost.exe[672] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00C60011
.text C:\WINNT\system32\svchost.exe[672] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00C60FCA
.text C:\WINNT\system32\svchost.exe[672] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00C60000
.text C:\WINNT\system32\svchost.exe[672] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00C60FDB
.text C:\WINNT\system32\svchost.exe[672] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [E6, 88] {OUT 0x88, AL}
.text C:\WINNT\system32\svchost.exe[672] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00C60062
.text C:\WINNT\system32\svchost.exe[672] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00C50FCA
.text C:\WINNT\system32\svchost.exe[672] msvcrt.dll!system 77C293C7 5 Bytes JMP 00C50FDB
.text C:\WINNT\system32\svchost.exe[672] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00C5003A
.text C:\WINNT\system32\svchost.exe[672] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00C50000
.text C:\WINNT\system32\svchost.exe[672] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00C5004B
.text C:\WINNT\system32\svchost.exe[672] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00C5001D
.text C:\WINNT\system32\svchost.exe[672] ws2_32.dll!socket 71AB4211 5 Bytes JMP 006E0000
.text C:\WINNT\system32\svchost.exe[672] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003384
.text C:\WINNT\system32\svchost.exe[672] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINNT\system32\svchost.exe[672] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINNT\system32\svchost.exe[672] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINNT\system32\svchost.exe[672] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003338
.text C:\WINNT\system32\svchost.exe[672] wininet.dll!InternetOpenA 7806C865 5 Bytes JMP 00C70FEF
.text C:\WINNT\system32\svchost.exe[672] wininet.dll!InternetOpenW 7806CE99 5 Bytes JMP 00C7000A
.text C:\WINNT\system32\svchost.exe[672] wininet.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00C70FD4
.text C:\WINNT\system32\svchost.exe[672] wininet.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00C7002F
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D60FEF
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D600AE
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D60093
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D60076
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D60FB9
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D60FD4
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D600DC
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D60F94
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D60F57
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D60F72
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00D60115
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00D6005B
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00D60014
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00D600BF
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00D60036
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00D60025
.text C:\WINNT\system32\svchost.exe[724] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00D60F83
.text C:\WINNT\system32\svchost.exe[724] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00D4001E
.text C:\WINNT\system32\svchost.exe[724] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00D4005E
.text C:\WINNT\system32\svchost.exe[724] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00D40FCD
.text C:\WINNT\system32\svchost.exe[724] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00D40FDE
.text C:\WINNT\system32\svchost.exe[724] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00D40FA1
.text C:\WINNT\system32\svchost.exe[724] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00D40FEF
.text C:\WINNT\system32\svchost.exe[724] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00D40FB2
.text C:\WINNT\system32\svchost.exe[724] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [F4, 88]
.text C:\WINNT\system32\svchost.exe[724] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00D4002F
.text C:\WINNT\system32\svchost.exe[724] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D30F92
.text C:\WINNT\system32\svchost.exe[724] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D30FAD
.text C:\WINNT\system32\svchost.exe[724] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D30FD9
.text C:\WINNT\system32\svchost.exe[724] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D30000
.text C:\WINNT\system32\svchost.exe[724] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D30FC8
.text C:\WINNT\system32\svchost.exe[724] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D30011
.text C:\WINNT\system32\svchost.exe[724] ws2_32.dll!socket 71AB4211 5 Bytes JMP 00D20000
.text C:\WINNT\system32\svchost.exe[724] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003384
.text C:\WINNT\system32\svchost.exe[724] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINNT\system32\svchost.exe[724] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINNT\system32\svchost.exe[724] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINNT\system32\svchost.exe[724] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003338
.text C:\WINNT\system32\svchost.exe[724] wininet.dll!InternetOpenA 7806C865 5 Bytes JMP 00D50FE5
.text C:\WINNT\system32\svchost.exe[724] wininet.dll!InternetOpenW 7806CE99 5 Bytes JMP 00D50000
.text C:\WINNT\system32\svchost.exe[724] wininet.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00D50FCA
.text C:\WINNT\system32\svchost.exe[724] wininet.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00D50FAF
.text C:\WINNT\system32\ctfmon.exe[812] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 1002343C
.text C:\WINNT\system32\ctfmon.exe[812] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10023384
.text C:\WINNT\system32\ctfmon.exe[812] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10022BF8
.text C:\WINNT\system32\ctfmon.exe[812] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10022440
.text C:\WINNT\system32\ctfmon.exe[812] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100223C4
.text C:\WINNT\system32\ctfmon.exe[812] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10023338
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02A6000A
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02A60F83
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02A60F94
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02A6006C
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02A60051
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02A60FCA
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02A60F55
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02A6009D
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02A600D3
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02A60F3A
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 02A600E4
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 02A60FB9
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 02A6001B
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 02A60F72
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 02A60036
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 02A60FE5
.text C:\WINNT\System32\svchost.exe[840] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 02A600B8
.text C:\WINNT\System32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 029F0FC3
.text C:\WINNT\System32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 029F0F79
.text C:\WINNT\System32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 029F0014
.text C:\WINNT\System32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 029F0FDE
.text C:\WINNT\System32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 029F0F94
.text C:\WINNT\System32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 029F0FEF
.text C:\WINNT\System32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 029F0036
.text C:\WINNT\System32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 029F0025
.text C:\WINNT\System32\svchost.exe[840] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02920FB4
.text C:\WINNT\System32\svchost.exe[840] msvcrt.dll!system 77C293C7 5 Bytes JMP 02920049
.text C:\WINNT\System32\svchost.exe[840] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0292001D
.text C:\WINNT\System32\svchost.exe[840] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02920FEF
.text C:\WINNT\System32\svchost.exe[840] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0292002E
.text C:\WINNT\System32\svchost.exe[840] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02920000
.text C:\WINNT\System32\svchost.exe[840] ws2_32.dll!socket 71AB4211 5 Bytes JMP 02910FEF
.text C:\WINNT\System32\svchost.exe[840] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003384
.text C:\WINNT\System32\svchost.exe[840] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINNT\System32\svchost.exe[840] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINNT\System32\svchost.exe[840] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINNT\System32\svchost.exe[840] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003338
.text C:\WINNT\System32\svchost.exe[840] wininet.dll!InternetOpenA 7806C865 5 Bytes JMP 02A50FEF
.text C:\WINNT\System32\svchost.exe[840] wininet.dll!InternetOpenW 7806CE99 5 Bytes JMP 02A50FD4
.text C:\WINNT\System32\svchost.exe[840] wininet.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 02A5000A
.text C:\WINNT\System32\svchost.exe[840] wininet.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 02A5001B
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 006E0FEF
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 006E0F57
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 006E0F68
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 006E0F79
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 006E0F94
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 006E0036
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 006E0F10
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 006E0F21
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 006E0EF5
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 006E008E
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 006E0EE4
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 006E0FAF
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 006E000A
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 006E0F32
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 006E0FCA
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 006E001B
.text C:\WINNT\System32\svchost.exe[900] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 006E007D
.text C:\WINNT\System32\svchost.exe[900] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 006A001B
.text C:\WINNT\System32\svchost.exe[900] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 006A0F80
.text C:\WINNT\System32\svchost.exe[900] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 006A000A
.text C:\WINNT\System32\svchost.exe[900] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 006A0FD4
.text C:\WINNT\System32\svchost.exe[900] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 006A003D
.text C:\WINNT\System32\svchost.exe[900] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 006A0FEF
.text C:\WINNT\System32\svchost.exe[900] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 006A0FA5
.text C:\WINNT\System32\svchost.exe[900] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [8A, 88]
.text C:\WINNT\System32\svchost.exe[900] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 006A002C
.text C:\WINNT\System32\svchost.exe[900] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0069000A
.text C:\WINNT\System32\svchost.exe[900] msvcrt.dll!system 77C293C7 5 Bytes JMP 00690F89
.text C:\WINNT\System32\svchost.exe[900] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00690FAB
.text C:\WINNT\System32\svchost.exe[900] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00690FEF
.text C:\WINNT\System32\svchost.exe[900] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00690F9A
.text C:\WINNT\System32\svchost.exe[900] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00690FD2
.text C:\WINNT\System32\svchost.exe[900] ws2_32.dll!socket 71AB4211 5 Bytes JMP 00680000
.text C:\WINNT\System32\svchost.exe[900] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003384
.text C:\WINNT\System32\svchost.exe[900] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINNT\System32\svchost.exe[900] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINNT\System32\svchost.exe[900] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINNT\System32\svchost.exe[900] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003338
.text C:\WINNT\System32\svchost.exe[900] wininet.dll!InternetOpenA 7806C865 5 Bytes JMP 006B0000
.text C:\WINNT\System32\svchost.exe[900] wininet.dll!InternetOpenW 7806CE99 5 Bytes JMP 006B0011
.text C:\WINNT\System32\svchost.exe[900] wininet.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 006B0FD1
.text C:\WINNT\System32\svchost.exe[900] wininet.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 006B0FC0
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E90FEF
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E90095
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E90FA0
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E90084
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E90073
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E90047
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E900D7
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E900B0
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E9010D
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E90F74
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00E90128
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00E90058
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00E90000
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00E90F8F
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00E9002C
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00E90011
.text C:\WINNT\System32\svchost.exe[1048] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00E900F2
.text C:\WINNT\System32\svchost.exe[1048] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00E70FB2
.text C:\WINNT\System32\svchost.exe[1048] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00E70F75
.text C:\WINNT\System32\svchost.exe[1048] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00E70FCD
.text C:\WINNT\System32\svchost.exe[1048] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00E70FDE
.text C:\WINNT\System32\svchost.exe[1048] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00E70F86
.text C:\WINNT\System32\svchost.exe[1048] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00E70FEF
.text C:\WINNT\System32\svchost.exe[1048] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00E70032
.text C:\WINNT\System32\svchost.exe[1048] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00E70FA1
.text C:\WINNT\System32\svchost.exe[1048] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E60FC8
.text C:\WINNT\System32\svchost.exe[1048] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E60053
.text C:\WINNT\System32\svchost.exe[1048] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E60FE3
.text C:\WINNT\System32\svchost.exe[1048] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E6000C
.text C:\WINNT\System32\svchost.exe[1048] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E60042
.text C:\WINNT\System32\svchost.exe[1048] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E6001D
.text C:\WINNT\System32\svchost.exe[1048] ws2_32.dll!socket 71AB4211 5 Bytes JMP 00E40000
.text C:\WINNT\System32\svchost.exe[1048] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003384
.text C:\WINNT\System32\svchost.exe[1048] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINNT\System32\svchost.exe[1048] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINNT\System32\svchost.exe[1048] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINNT\System32\svchost.exe[1048] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003338
.text C:\WINNT\System32\svchost.exe[1048] wininet.dll!InternetOpenA 7806C865 5 Bytes JMP 00E80FEF
.text C:\WINNT\System32\svchost.exe[1048] wininet.dll!InternetOpenW 7806CE99 5 Bytes JMP 00E8000A
.text C:\WINNT\System32\svchost.exe[1048] wininet.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00E80025
.text C:\WINNT\System32\svchost.exe[1048] wininet.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00E80036
.text C:\WINNT\system32\spoolsv.exe[1260] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 1000343C
.text C:\WINNT\system32\spoolsv.exe[1260] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003384
.text C:\WINNT\system32\spoolsv.exe[1260] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINNT\system32\spoolsv.exe[1260] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINNT\system32\spoolsv.exe[1260] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINNT\system32\spoolsv.exe[1260] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003338
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00260FEF
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00260F70
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00260065
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0026004A
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00260F8D
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00260F9E
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00260F3A
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0026008C
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00260F04
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 002600A7
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 002600B8
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 0026002F
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00260FDE
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00260F5F
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00260FB9
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00260014
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00260F29
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00350036
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00350FB2
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00350FE5
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00350025
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00350FC3
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00350000
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00350065
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00350FD4
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0036004E
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] msvcrt.dll!system 77C293C7 5 Bytes JMP 00360FC3
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00360018
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00360FEF
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00360033
.text C:\PROGRA~1\WINZIP\winzip32.exe[1528] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00360FDE
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1764] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 1000343C
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1764] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003384
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1764] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1764] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1764] WS2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1764] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003338
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1884] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C340 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1884] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 0041C3C0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\McAfee\VirusScan\McShield.exe[1936] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 1000343C
.text C:\Program Files\McAfee\VirusScan\McShield.exe[1936] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003384
.text C:\Program Files\McAfee\VirusScan\McShield.exe[1936] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\Program Files\McAfee\VirusScan\McShield.exe[1936] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\Program Files\McAfee\VirusScan\McShield.exe[1936] WS2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\Program Files\McAfee\VirusScan\McShield.exe[1936] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003338
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1984] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 1000343C
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1984] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003384
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1984] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1984] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1984] WS2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1984] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003338
.text C:\WINNT\System32\alg.exe[2080] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 1000343C
.text C:\WINNT\System32\alg.exe[2080] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003384
.text C:\WINNT\System32\alg.exe[2080] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINNT\System32\alg.exe[2080] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINNT\System32\alg.exe[2080] WS2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINNT\System32\alg.exe[2080] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003338
.text C:\WINNT\explorer.exe[2768] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001A0000
.text C:\WINNT\explorer.exe[2768] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001A009A
.text C:\WINNT\explorer.exe[2768] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001A007F
.text C:\WINNT\explorer.exe[2768] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001A006E
.text C:\WINNT\explorer.exe[2768] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001A0051
.text C:\WINNT\explorer.exe[2768] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001A0040
.text C:\WINNT\explorer.exe[2768] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001A00D0
.text C:\WINNT\explorer.exe[2768] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001A0F88
.text C:\WINNT\explorer.exe[2768] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001A0F2D
.text C:\WINNT\explorer.exe[2768] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001A0F48
.text C:\WINNT\explorer.exe[2768] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 001A00EB
.text C:\WINNT\explorer.exe[2768] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 001A0FAF
.text C:\WINNT\explorer.exe[2768] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 001A0FE5
.text C:\WINNT\explorer.exe[2768] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 001A00B5
.text C:\WINNT\explorer.exe[2768] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 001A0FCA
.text C:\WINNT\explorer.exe[2768] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 001A001B
.text C:\WINNT\explorer.exe[2768] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 001A0F6D
.text C:\WINNT\explorer.exe[2768] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 0029001B
.text C:\WINNT\explorer.exe[2768] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00290F7C
.text C:\WINNT\explorer.exe[2768] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00290FC0
.text C:\WINNT\explorer.exe[2768] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00290000
.text C:\WINNT\explorer.exe[2768] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00290F8D
.text C:\WINNT\explorer.exe[2768] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00290FEF
.text C:\WINNT\explorer.exe[2768] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00290F9E
.text C:\WINNT\explorer.exe[2768] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [49, 88]
.text C:\WINNT\explorer.exe[2768] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00290FAF
.text C:\WINNT\explorer.exe[2768] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 002A0FB2
.text C:\WINNT\explorer.exe[2768] msvcrt.dll!system 77C293C7 5 Bytes JMP 002A0FC3
.text C:\WINNT\explorer.exe[2768] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 002A0018
.text C:\WINNT\explorer.exe[2768] msvcrt.dll!_open 77C2F566 5 Bytes JMP 002A0FEF
.text C:\WINNT\explorer.exe[2768] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 002A0033
.text C:\WINNT\explorer.exe[2768] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 002A0FDE
.text C:\WINNT\explorer.exe[2768] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 002C0FEF
.text C:\WINNT\explorer.exe[2768] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 002C0FDE
.text C:\WINNT\explorer.exe[2768] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 002C0014
.text C:\WINNT\explorer.exe[2768] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 002C0025
.text C:\WINNT\explorer.exe[2768] WS2_32.dll!socket 71AB4211 5 Bytes JMP 03070000
.text C:\WINNT\GWMDMMSG.exe[3768] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 1002343C
.text C:\WINNT\GWMDMMSG.exe[3768] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10023384
.text C:\WINNT\GWMDMMSG.exe[3768] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10022BF8
.text C:\WINNT\GWMDMMSG.exe[3768] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10022440
.text C:\WINNT\GWMDMMSG.exe[3768] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100223C4
.text C:\WINNT\GWMDMMSG.exe[3768] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10023338
.text C:\WINNT\system32\SK9910DM.EXE[3776] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 1003343C
.text C:\WINNT\system32\SK9910DM.EXE[3776] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10033384
.text C:\WINNT\system32\SK9910DM.EXE[3776] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10032BF8
.text C:\WINNT\system32\SK9910DM.EXE[3776] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10032440
.text C:\WINNT\system32\SK9910DM.EXE[3776] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100323C4
.text C:\WINNT\system32\SK9910DM.EXE[3776] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10033338
.text C:\WINNT\system32\devldr32.exe[3852] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 1002343C
.text C:\WINNT\system32\devldr32.exe[3852] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10023384
.text C:\WINNT\system32\devldr32.exe[3852] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10022BF8
.text C:\WINNT\system32\devldr32.exe[3852] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10022440
.text C:\WINNT\system32\devldr32.exe[3852] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100223C4
.text C:\WINNT\system32\devldr32.exe[3852] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10023338

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\explorer.exe [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\explorer.exe[2768] @ C:\WINNT\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

—- EOF - GMER 1.0.15 —-
OTlistit and gmer logs look good. Let's try running Combofix again. Please delete your current copy. You can do this by dragging the icon on your desktop to your recycle bin.


A. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

B. Now we must disable some of your security programs so that they do not interfere with the running of our tools:

http://forums.whatthetech.com/How_to_Disab…ams_t89859.html



C.Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • DO NOT USE your computer for any other purpose while ComboFix is running.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Here are results form Combofix.txt. The system did indicate windows recovery console was not installed but when clicked yes to install I got message that I was not connected to internet. It appears it went ahead & ran the combofix.txt. I also notice my Mcafee symbol has returned like normal.

ComboFix 09-03-28.06 - Helene Lesueur 2009-03-29 11:07:41.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.304 [GMT -4:00]
Running from: c:\documents and settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *disabled*
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\desktop.exe
c:\winnt\system32\open.ico
c:\winnt\wiaserviv.log

.
((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-29 )))))))))))))))))))))))))))))))
.

2009-03-29 00:25 . 2009-03-26 04:33 d——– C:\32788R22FWJFW.0.tmp
2009-03-28 19:05 . 2009-03-28 19:05 d——– C:\_OTMoveIt
2009-03-28 10:45 . 2009-03-28 10:45 d——– c:\program files\Trend Micro
2009-03-27 21:42 . 2009-03-27 21:42 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-27 21:42 . 2009-03-26 16:49 38,496 –a—— c:\winnt\system32\drivers\mbamswissarmy.sys
2009-03-27 21:42 . 2009-03-26 16:49 15,504 –a—— c:\winnt\system32\drivers\mbam.sys
2009-03-27 19:19 . 2009-03-27 19:19 d——– c:\program files\Windows Defender
2009-03-27 09:27 . 2009-03-29 11:12 4,223 –a—— c:\winnt\system32\Config.MPF
2009-03-27 09:21 . 2009-03-27 09:21 d——– c:\program files\McAfee.com
2009-03-27 09:21 . 2007-11-22 06:44 201,320 –a—— c:\winnt\system32\drivers\mfehidk.sys
2009-03-27 09:21 . 2007-07-13 06:20 113,952 –a—— c:\winnt\system32\drivers\Mpfp.sys
2009-03-27 09:21 . 2007-11-22 06:44 79,304 –a—— c:\winnt\system32\drivers\mfeavfk.sys
2009-03-27 09:21 . 2007-12-02 12:51 40,488 –a—— c:\winnt\system32\drivers\mfesmfk.sys
2009-03-27 09:21 . 2007-11-22 06:44 35,240 –a—— c:\winnt\system32\drivers\mfebopk.sys
2009-03-27 09:21 . 2007-11-22 06:44 33,832 –a—— c:\winnt\system32\drivers\mferkdk.sys
2009-03-27 09:20 . 2009-03-27 09:20 d——– c:\program files\McAfee
2009-03-27 09:20 . 2009-03-27 09:20 d——– c:\program files\Common Files\McAfee
2009-03-27 09:14 . 2009-03-27 09:14 d——– c:\documents and settings\All Users\Application Data\McAfee
2009-03-21 23:48 . 2009-03-21 23:48 d——– c:\documents and settings\Ella Lesueur\Application Data\Malwarebytes
2009-03-21 23:12 . 2009-03-21 23:12 d——– c:\documents and settings\Helene Lesueur\Application Data\Malwarebytes
2009-03-21 23:12 . 2009-03-21 23:12 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-21 20:00 . 2009-03-21 23:30 11,168 –ah—– c:\winnt\system32\jubisoha

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-14 01:50 0 —ha-w c:\winnt\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-02-14 01:50 0 —ha-w c:\winnt\system32\drivers\Msft_Kernel_zumbus_01007.Wdf
2009-02-09 11:13 1,846,784 —-a-w c:\winnt\system32\win32k.sys
2009-02-09 11:13 1,846,784 ——w c:\winnt\system32\dllcache\win32k.sys
2009-01-17 01:35 3,594,752 —-a-w c:\winnt\system32\dllcache\mshtml.dll
2008-08-11 21:23 99,648 —-a-w c:\documents and settings\Helene Lesueur\Application Data\GDIPFONTCACHEV1.DAT
2007-01-21 19:37 102,776 —-a-w c:\documents and settings\Ella Lesueur\Application Data\GDIPFONTCACHEV1.DAT
2006-03-29 22:48 21,254,280 —-a-w c:\program files\AdbeRdr707_en_US.exe
2006-03-29 22:47 762,512 —-a-w c:\program files\ytb612_efgsip.exe
2006-03-29 22:47 7,050,552 —-a-w c:\program files\psa30se_en_us.exe
2003-10-14 20:46 96 —-a-w c:\program files\NoArb.bat
2008-09-12 22:54 32,768 –sha-w c:\winnt\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008091220080913\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2006-11-30 4662776]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-06-19 684032]
"IgfxTray"="c:\winnt\System32\igfxtray.exe" [2002-05-14 155648]
"HotKeysCmds"="c:\winnt\System32\hkcmd.exe" [2002-05-14 114688]
"tgcmd"="c:\program files\support.com\bin\tgcmd.exe" [2002-04-24 1544192]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-06-14 278528]
"LXDBCATS"="c:\winnt\System32\spool\DRIVERS\W32X86\3\LXDBtime.dll" [2006-03-02 73728]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"GWMDMMSG"="GWMDMMSG.exe" [2001-12-04 c:\winnt\GWMDMMSG.exe]
"Hot Key Kbd 9910 Daemon"="SK9910DM.EXE" [2001-01-03 c:\winnt\system32\SK9910DM.EXE]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\winnt\LOGI_MWX.EXE]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2005-11-03 169472]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-02-05 54512]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"= ctwdm32.dll
"aux2"= ctwdm32.dll
"VIDC.JPEG"= jpegCode.dll
"VIDC.MJPG"= jpegCode.dll
"mixer"= APTRRNTm.dll
"wave"= APTRRNTm.dll
"aux4"= c:\winnt\system32\..\fwre.dyh

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Windows Media Player\\WMPLAYER.EXE"=
"c:\\Program Files\\Replay Radio 5\\ReplayRadio.exe"=
"c:\\Program Files\\Replay Player\\Replay Player.exe"=
"c:\\Program Files\\Radio Wizard\\RadioWizard.exe"=
"c:\\Program Files\\MP3 Magic\\MP3Magic.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\SUPPORT.COM\\BIN\\TGCMD.EXE"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\Source Engine\\OSE.EXE"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

S2 CoachCap;Concord EyeQ Duo 1300 USB Video Capture V1.01;c:\winnt\system32\drivers\CoachCap.sys –> c:\winnt\system32\drivers\CoachCap.sys [?]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 ati2mpaa;ati2mpaa;c:\winnt\system32\drivers\ati2mpaa.sys [2001-09-08 281856]
S3 iscFlash;iscFlash;\??\c:\winnt\SYSTEM32\DRIVERS\iscflash.sys –> c:\winnt\SYSTEM32\DRIVERS\iscflash.sys [?]
S3 lxdb_device;lxdb_device;c:\winnt\system32\lxdbcoms.exe -service –> c:\winnt\system32\lxdbcoms.exe -service [?]
S3 MR97310_VGA_DUAL_CAMERA;MR97310 VGA Dual Mode Camera;c:\winnt\system32\drivers\MR97310v.sys [2004-08-06 115790]
.
Contents of the 'Scheduled Tasks' folder

2009-03-16 c:\winnt\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]

2009-03-27 c:\winnt\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2009-03-27 c:\winnt\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-FlipViewer Library - c:\program files\E-Book Systems\FlipViewer\\FlipViewerLibrary.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.comcast.net/comcast.html
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
mWindow Title = Microsoft Internet Explorer provided by Comcast
Trusted Zone: internet
Trusted Zone: mcafee.com
Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - c:\winnt\wc98pp.dll
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-29 11:12:07
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
tgcmd = "c:\program files\support.com\bin\tgcmd.exe" /server?cmd.exe" /server
LXDBCATS = rundll32 c:\winnt\System32\spool\DRIVERS\W32X86\3\LXDBtime.dll,_RunDLLEntry@16?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\MCAFEE\MSC\MCMSCSVC.EXE
c:\program files\COMMON FILES\MCAFEE\MNA\MCNASVC.EXE
c:\program files\COMMON FILES\MCAFEE\MCPROXY\MCPROXY.EXE
c:\program files\MCAFEE\VIRUSSCAN\MCSHIELD.EXE
c:\program files\MCAFEE\MPF\MPFSRV.EXE
c:\winnt\system32\devldr32.exe
c:\program files\Logitech\MouseWare\system\em_exec.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\iPod\bin\iPodService.exe
c:\winnt\system32\wscntfy.exe
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
c:\progra~1\mcafee\msc\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2009-03-29 11:15:14 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-29 15:15:12

Pre-Run: 41,177,939,968 bytes free
Post-Run: 41,512,239,104 bytes free

177 — E O F — 2009-03-13 17:34:53
sweetiehlm5,

Success. :woot:

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    c:\winnt\system32\jubisoha
    c:\program files\NoArb.bat
    
    Folder::
    
    Registry::
    
    Driver::
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Here is the latest combofixlog after dragging the CFScrit.text into ComboFix.exe. I will do the kaspersky website scan next.

ComboFix 09-03-28.06 - Helene Lesueur 2009-03-29 11:46:28.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.254 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Helene Lesueur\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *disabled*
* Created a new restore point

FILE ::
c:\program files\NoArb.bat
c:\winnt\system32\jubisoha
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\NoArb.bat
c:\winnt\system32\jubisoha

.
((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-29 )))))))))))))))))))))))))))))))
.

2009-03-29 00:25 . 2009-03-26 04:33 d——– C:\32788R22FWJFW.0.tmp
2009-03-28 19:05 . 2009-03-28 19:05 d——– C:\_OTMoveIt
2009-03-28 10:45 . 2009-03-28 10:45 d——– c:\program files\Trend Micro
2009-03-27 21:42 . 2009-03-27 21:42 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-27 21:42 . 2009-03-26 16:49 38,496 –a—— c:\winnt\system32\drivers\mbamswissarmy.sys
2009-03-27 21:42 . 2009-03-26 16:49 15,504 –a—— c:\winnt\system32\drivers\mbam.sys
2009-03-27 19:19 . 2009-03-27 19:19 d——– c:\program files\Windows Defender
2009-03-27 09:27 . 2009-03-29 11:43 4,379 –a—— c:\winnt\system32\Config.MPF
2009-03-27 09:21 . 2009-03-27 09:21 d——– c:\program files\McAfee.com
2009-03-27 09:21 . 2007-11-22 06:44 201,320 –a—— c:\winnt\system32\drivers\mfehidk.sys
2009-03-27 09:21 . 2007-07-13 06:20 113,952 –a—— c:\winnt\system32\drivers\Mpfp.sys
2009-03-27 09:21 . 2007-11-22 06:44 79,304 –a—— c:\winnt\system32\drivers\mfeavfk.sys
2009-03-27 09:21 . 2007-12-02 12:51 40,488 –a—— c:\winnt\system32\drivers\mfesmfk.sys
2009-03-27 09:21 . 2007-11-22 06:44 35,240 –a—— c:\winnt\system32\drivers\mfebopk.sys
2009-03-27 09:21 . 2007-11-22 06:44 33,832 –a—— c:\winnt\system32\drivers\mferkdk.sys
2009-03-27 09:20 . 2009-03-27 09:20 d——– c:\program files\McAfee
2009-03-27 09:20 . 2009-03-27 09:20 d——– c:\program files\Common Files\McAfee
2009-03-27 09:14 . 2009-03-27 09:14 d——– c:\documents and settings\All Users\Application Data\McAfee
2009-03-21 23:48 . 2009-03-21 23:48 d——– c:\documents and settings\Ella Lesueur\Application Data\Malwarebytes
2009-03-21 23:12 . 2009-03-21 23:12 d——– c:\documents and settings\Helene Lesueur\Application Data\Malwarebytes
2009-03-21 23:12 . 2009-03-21 23:12 d——– c:\documents and settings\All Users\Application Data\Malwarebytes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-14 01:50 0 —ha-w c:\winnt\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-02-14 01:50 0 —ha-w c:\winnt\system32\drivers\Msft_Kernel_zumbus_01007.Wdf
2009-02-09 11:13 1,846,784 —-a-w c:\winnt\system32\win32k.sys
2009-02-09 11:13 1,846,784 ——w c:\winnt\system32\dllcache\win32k.sys
2009-01-17 01:35 3,594,752 —-a-w c:\winnt\system32\dllcache\mshtml.dll
2008-08-11 21:23 99,648 —-a-w c:\documents and settings\Helene Lesueur\Application Data\GDIPFONTCACHEV1.DAT
2007-01-21 19:37 102,776 —-a-w c:\documents and settings\Ella Lesueur\Application Data\GDIPFONTCACHEV1.DAT
2006-03-29 22:48 21,254,280 —-a-w c:\program files\AdbeRdr707_en_US.exe
2006-03-29 22:47 762,512 —-a-w c:\program files\ytb612_efgsip.exe
2006-03-29 22:47 7,050,552 —-a-w c:\program files\psa30se_en_us.exe
2008-09-12 22:54 32,768 –sha-w c:\winnt\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008091220080913\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2006-11-30 4662776]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-06-19 684032]
"IgfxTray"="c:\winnt\System32\igfxtray.exe" [2002-05-14 155648]
"HotKeysCmds"="c:\winnt\System32\hkcmd.exe" [2002-05-14 114688]
"tgcmd"="c:\program files\support.com\bin\tgcmd.exe" [2002-04-24 1544192]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-06-14 278528]
"LXDBCATS"="c:\winnt\System32\spool\DRIVERS\W32X86\3\LXDBtime.dll" [2006-03-02 73728]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"GWMDMMSG"="GWMDMMSG.exe" [2001-12-04 c:\winnt\GWMDMMSG.exe]
"Hot Key Kbd 9910 Daemon"="SK9910DM.EXE" [2001-01-03 c:\winnt\system32\SK9910DM.EXE]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\winnt\LOGI_MWX.EXE]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2005-11-03 169472]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-02-05 54512]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"= ctwdm32.dll
"aux2"= ctwdm32.dll
"VIDC.JPEG"= jpegCode.dll
"VIDC.MJPG"= jpegCode.dll
"mixer"= APTRRNTm.dll
"wave"= APTRRNTm.dll
"aux4"= c:\winnt\system32\..\fwre.dyh

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Windows Media Player\\WMPLAYER.EXE"=
"c:\\Program Files\\Replay Radio 5\\ReplayRadio.exe"=
"c:\\Program Files\\Replay Player\\Replay Player.exe"=
"c:\\Program Files\\Radio Wizard\\RadioWizard.exe"=
"c:\\Program Files\\MP3 Magic\\MP3Magic.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\SUPPORT.COM\\BIN\\TGCMD.EXE"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\Source Engine\\OSE.EXE"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R3 lxdb_device;lxdb_device;c:\winnt\system32\lxdbcoms.exe -service –> c:\winnt\system32\lxdbcoms.exe -service [?]
S2 CoachCap;Concord EyeQ Duo 1300 USB Video Capture V1.01;c:\winnt\system32\drivers\CoachCap.sys –> c:\winnt\system32\drivers\CoachCap.sys [?]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 ati2mpaa;ati2mpaa;c:\winnt\system32\drivers\ati2mpaa.sys [2001-09-08 281856]
S3 iscFlash;iscFlash;\??\c:\winnt\SYSTEM32\DRIVERS\iscflash.sys –> c:\winnt\SYSTEM32\DRIVERS\iscflash.sys [?]
S3 MR97310_VGA_DUAL_CAMERA;MR97310 VGA Dual Mode Camera;c:\winnt\system32\drivers\MR97310v.sys [2004-08-06 115790]
.
Contents of the 'Scheduled Tasks' folder

2009-03-16 c:\winnt\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]

2009-03-27 c:\winnt\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2009-03-27 c:\winnt\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.comcast.net/comcast.html
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
mWindow Title = Microsoft Internet Explorer provided by Comcast
Trusted Zone: internet
Trusted Zone: mcafee.com
Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - c:\winnt\wc98pp.dll
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-29 11:48:03
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
tgcmd = "c:\program files\support.com\bin\tgcmd.exe" /server?cmd.exe" /server
LXDBCATS = rundll32 c:\winnt\System32\spool\DRIVERS\W32X86\3\LXDBtime.dll,_RunDLLEntry@16?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-29 11:49:27
ComboFix-quarantined-files.txt 2009-03-29 15:49:26
ComboFix2.txt 2009-03-29 15:15:18

Pre-Run: 41,434,120,192 bytes free
Post-Run: 41,430,417,408 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINNT
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINNT="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

165 — E O F — 2009-03-13 17:34:53
Here are the latest results from the Combofix log after dragging the CFScript.txt in to ComboFix

ComboFix 09-03-28.06 - Helene Lesueur 2009-03-29 11:46:28.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.254 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Helene Lesueur\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *disabled*
* Created a new restore point

FILE ::
c:\program files\NoArb.bat
c:\winnt\system32\jubisoha
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\NoArb.bat
c:\winnt\system32\jubisoha

.
((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-29 )))))))))))))))))))))))))))))))
.

2009-03-29 00:25 . 2009-03-26 04:33 d——– C:\32788R22FWJFW.0.tmp
2009-03-28 19:05 . 2009-03-28 19:05 d——– C:\_OTMoveIt
2009-03-28 10:45 . 2009-03-28 10:45 d——– c:\program files\Trend Micro
2009-03-27 21:42 . 2009-03-27 21:42 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-27 21:42 . 2009-03-26 16:49 38,496 –a—— c:\winnt\system32\drivers\mbamswissarmy.sys
2009-03-27 21:42 . 2009-03-26 16:49 15,504 –a—— c:\winnt\system32\drivers\mbam.sys
2009-03-27 19:19 . 2009-03-27 19:19 d——– c:\program files\Windows Defender
2009-03-27 09:27 . 2009-03-29 11:43 4,379 –a—— c:\winnt\system32\Config.MPF
2009-03-27 09:21 . 2009-03-27 09:21 d——– c:\program files\McAfee.com
2009-03-27 09:21 . 2007-11-22 06:44 201,320 –a—— c:\winnt\system32\drivers\mfehidk.sys
2009-03-27 09:21 . 2007-07-13 06:20 113,952 –a—— c:\winnt\system32\drivers\Mpfp.sys
2009-03-27 09:21 . 2007-11-22 06:44 79,304 –a—— c:\winnt\system32\drivers\mfeavfk.sys
2009-03-27 09:21 . 2007-12-02 12:51 40,488 –a—— c:\winnt\system32\drivers\mfesmfk.sys
2009-03-27 09:21 . 2007-11-22 06:44 35,240 –a—— c:\winnt\system32\drivers\mfebopk.sys
2009-03-27 09:21 . 2007-11-22 06:44 33,832 –a—— c:\winnt\system32\drivers\mferkdk.sys
2009-03-27 09:20 . 2009-03-27 09:20 d——– c:\program files\McAfee
2009-03-27 09:20 . 2009-03-27 09:20 d——– c:\program files\Common Files\McAfee
2009-03-27 09:14 . 2009-03-27 09:14 d——– c:\documents and settings\All Users\Application Data\McAfee
2009-03-21 23:48 . 2009-03-21 23:48 d——– c:\documents and settings\Ella Lesueur\Application Data\Malwarebytes
2009-03-21 23:12 . 2009-03-21 23:12 d——– c:\documents and settings\Helene Lesueur\Application Data\Malwarebytes
2009-03-21 23:12 . 2009-03-21 23:12 d——– c:\documents and settings\All Users\Application Data\Malwarebytes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-14 01:50 0 —ha-w c:\winnt\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-02-14 01:50 0 —ha-w c:\winnt\system32\drivers\Msft_Kernel_zumbus_01007.Wdf
2009-02-09 11:13 1,846,784 —-a-w c:\winnt\system32\win32k.sys
2009-02-09 11:13 1,846,784 ——w c:\winnt\system32\dllcache\win32k.sys
2009-01-17 01:35 3,594,752 —-a-w c:\winnt\system32\dllcache\mshtml.dll
2008-08-11 21:23 99,648 —-a-w c:\documents and settings\Helene Lesueur\Application Data\GDIPFONTCACHEV1.DAT
2007-01-21 19:37 102,776 —-a-w c:\documents and settings\Ella Lesueur\Application Data\GDIPFONTCACHEV1.DAT
2006-03-29 22:48 21,254,280 —-a-w c:\program files\AdbeRdr707_en_US.exe
2006-03-29 22:47 762,512 —-a-w c:\program files\ytb612_efgsip.exe
2006-03-29 22:47 7,050,552 —-a-w c:\program files\psa30se_en_us.exe
2008-09-12 22:54 32,768 –sha-w c:\winnt\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008091220080913\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2006-11-30 4662776]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-06-19 684032]
"IgfxTray"="c:\winnt\System32\igfxtray.exe" [2002-05-14 155648]
"HotKeysCmds"="c:\winnt\System32\hkcmd.exe" [2002-05-14 114688]
"tgcmd"="c:\program files\support.com\bin\tgcmd.exe" [2002-04-24 1544192]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-06-14 278528]
"LXDBCATS"="c:\winnt\System32\spool\DRIVERS\W32X86\3\LXDBtime.dll" [2006-03-02 73728]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"GWMDMMSG"="GWMDMMSG.exe" [2001-12-04 c:\winnt\GWMDMMSG.exe]
"Hot Key Kbd 9910 Daemon"="SK9910DM.EXE" [2001-01-03 c:\winnt\system32\SK9910DM.EXE]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\winnt\LOGI_MWX.EXE]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2005-11-03 169472]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-02-05 54512]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"= ctwdm32.dll
"aux2"= ctwdm32.dll
"VIDC.JPEG"= jpegCode.dll
"VIDC.MJPG"= jpegCode.dll
"mixer"= APTRRNTm.dll
"wave"= APTRRNTm.dll
"aux4"= c:\winnt\system32\..\fwre.dyh

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Windows Media Player\\WMPLAYER.EXE"=
"c:\\Program Files\\Replay Radio 5\\ReplayRadio.exe"=
"c:\\Program Files\\Replay Player\\Replay Player.exe"=
"c:\\Program Files\\Radio Wizard\\RadioWizard.exe"=
"c:\\Program Files\\MP3 Magic\\MP3Magic.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\SUPPORT.COM\\BIN\\TGCMD.EXE"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\Source Engine\\OSE.EXE"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R3 lxdb_device;lxdb_device;c:\winnt\system32\lxdbcoms.exe -service –> c:\winnt\system32\lxdbcoms.exe -service [?]
S2 CoachCap;Concord EyeQ Duo 1300 USB Video Capture V1.01;c:\winnt\system32\drivers\CoachCap.sys –> c:\winnt\system32\drivers\CoachCap.sys [?]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 ati2mpaa;ati2mpaa;c:\winnt\system32\drivers\ati2mpaa.sys [2001-09-08 281856]
S3 iscFlash;iscFlash;\??\c:\winnt\SYSTEM32\DRIVERS\iscflash.sys –> c:\winnt\SYSTEM32\DRIVERS\iscflash.sys [?]
S3 MR97310_VGA_DUAL_CAMERA;MR97310 VGA Dual Mode Camera;c:\winnt\system32\drivers\MR97310v.sys [2004-08-06 115790]
.
Contents of the 'Scheduled Tasks' folder

2009-03-16 c:\winnt\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]

2009-03-27 c:\winnt\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2009-03-27 c:\winnt\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.comcast.net/comcast.html
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
mWindow Title = Microsoft Internet Explorer provided by Comcast
Trusted Zone: internet
Trusted Zone: mcafee.com
Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - c:\winnt\wc98pp.dll
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-29 11:48:03
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
tgcmd = "c:\program files\support.com\bin\tgcmd.exe" /server?cmd.exe" /server
LXDBCATS = rundll32 c:\winnt\System32\spool\DRIVERS\W32X86\3\LXDBtime.dll,_RunDLLEntry@16?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-29 11:49:27
ComboFix-quarantined-files.txt 2009-03-29 15:49:26
ComboFix2.txt 2009-03-29 15:15:18

Pre-Run: 41,434,120,192 bytes free
Post-Run: 41,430,417,408 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINNT
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINNT="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

165 — E O F — 2009-03-13 17:34:53
I clicked on download Kaspersky website link. The website opened up but the Accept button was not highlighted & I read that I needed an updated version of Java to run the download so I clicked on the updated version of Java which installed. After I installed the updated version of Java I then went back to the Kaspersky website where the Accept button was now highligted & I clicked it. I first got a window indicating there was some type of application error & noticed after that downloading & installing the program is hanging at 0% so it appears to not be working properly. Can you tell me how to get it download correct?
I tried again & got same error message that the Applications digital signature failed & then got another error that starting java applet failed & I must go online to use the program. What do I try next?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI