This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Hungapp Errors

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

mgw7625,

Hopefully you can get back online.

Please download gmer.zip from Gmer and save it to your desktop.

  • Right click on gmer.zip and select Extract All….
  • Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  • Click on the Browse button. Click on Desktop. Then click OK.
  • Click Next. It will start extracting.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Double click on gmer.exe to run it.
  • Select the Rootkit tab.
  • On the right hand side, check all the items to be scanned, but leave Show All box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click on the Scan button.
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard.
  • Open Notepad or a similar text editor.
  • Paste the clipboard contents into the text editor.
  • Save the Gmer scan log and post it in your next reply.
  • Close Gmer.
  • Open Command Prompt by going to Start > Run and type in cmd. Press Enter.
  • In Command Prompt, type in net stop gmer. Press Enter.
  • Type in exit to close Command Prompt.

Note: Do not run any programs while Gmer is running.
I got my connection back…somehow my wireless connection dropped and I had to manually reconfigure it back onto the network . Pleae let me know wht you wish for me to do next. Thank you for your time and patience!
Tomk. I wrote my last e-mail befoe I saw your post to run the GMER. I ran it but it stopped. I got an error that said, "gmer.exe has encounterd a problem and needs to close." I closed the file and then restarted it again and got the same error. I ahve no aother apps open.
The GMER.exe seems to keep geting stopped at some "Device". I unchecked the "Device" option and restarted the scan. It has been going on now for the last 3 mins without stopping. I need to take visiting family to the airport and should be back within an hour. I'll check back here when I return.
GMER 1.0.15.14966 - http://www.gmer.net
Rootkit scan 2009-04-13 21:21:57
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xEE92B44A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xEE92B4E1]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xEE92B3F8]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xEE92B40C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xEE92B4F5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xEE92B521]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xEE92B58F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xEE92B579]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xEE92B48A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xEE92B5BB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xEE92B4CD]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xEE92B3D0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xEE92B3E4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xEE92B45E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xEE92B5F7]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xEE92B563]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xEE92B54D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xEE92B50B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xEE92B5E3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xEE92B5CF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xEE92B436]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xEE92B422]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xEE92B537]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xEE92B4B9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xEE92B5A5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xEE92B4A0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xEE92B474]
Code 85E512CE IoReportHalResourceUsage
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwYieldExecution 8050223C 7 Bytes JMP EE92B478 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 8056E2FC 5 Bytes JMP EE92B44E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805A7500 7 Bytes JMP EE92B48E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805A8316 5 Bytes JMP EE92B4A4 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805ADA94 7 Bytes JMP EE92B462 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805C1322 5 Bytes JMP EE92B3D4 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805C15AE 5 Bytes JMP EE92B3E8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 805C3DE0 5 Bytes JMP EE92B426 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805C73F6 7 Bytes JMP EE92B410 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805C74AC 5 Bytes JMP EE92B3FC \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 805C79B6 5 Bytes JMP EE92B43A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805C8CB6 5 Bytes JMP EE92B4BD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryValueKey 8061854A 7 Bytes JMP EE92B551 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetValueKey 80618898 7 Bytes JMP EE92B53B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnloadKey 80618BC2 7 Bytes JMP EE92B5A9 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryMultipleValueKey 80619460 7 Bytes JMP EE92B567 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 80619D34 7 Bytes JMP EE92B50F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateKey 8061A312 5 Bytes JMP EE92B4E5 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 8061A7A2 7 Bytes JMP EE92B4F9 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 8061A972 7 Bytes JMP EE92B525 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateKey 8061AB52 7 Bytes JMP EE92B593 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateValueKey 8061ADBC 7 Bytes JMP EE92B57D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwOpenKey 8061B6E4 5 Bytes JMP EE92B4D1 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryKey 8061BA0A 7 Bytes JMP EE92B5FB \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRestoreKey 8061BCCA 5 Bytes JMP EE92B5D3 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplaceKey 8061C3BE 5 Bytes JMP EE92B5E7 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 8061C4D8 5 Bytes JMP EE92B5BF \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E00FEF
.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E00F2B
.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E00F46
.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E00F61
.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E0001E
.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E00F8D
.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E00067
.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E00056
.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E00EE9
.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E00078
.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00E0009D
.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00E00F7C
.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00E00FDE
.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00E0003B
.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00E00F9E
.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00E00FB9
.text C:\WINDOWS\system32\services.exe[928] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00E00EFA
.text C:\WINDOWS\system32\services.exe[928] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00DF0036
.text C:\WINDOWS\system32\services.exe[928] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00DF0FCA
.text C:\WINDOWS\system32\services.exe[928] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00DF0025
.text C:\WINDOWS\system32\services.exe[928] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00DF000A
.text C:\WINDOWS\system32\services.exe[928] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00DF007D
.text C:\WINDOWS\system32\services.exe[928] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00DF0FEF
.text C:\WINDOWS\system32\services.exe[928] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00DF0062
.text C:\WINDOWS\system32\services.exe[928] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00DF0051
.text C:\WINDOWS\system32\services.exe[928] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00DE0036
.text C:\WINDOWS\system32\services.exe[928] msvcrt.dll!system 77C293C7 5 Bytes JMP 00DE0FAB
.text C:\WINDOWS\system32\services.exe[928] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00DE0FC6
.text C:\WINDOWS\system32\services.exe[928] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00DE0FEF
.text C:\WINDOWS\system32\services.exe[928] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00DE0011
.text C:\WINDOWS\system32\services.exe[928] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00DE0000
.text C:\WINDOWS\system32\services.exe[928] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00DD0FE5
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F00FEF
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F00051
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F00F5C
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F00F6D
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F00036
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F00F9E
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F00F2B
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F00073
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F00EE4
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F00EFF
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00F00ED3
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00F00025
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00F00FD4
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00F00062
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00F0000A
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00F00FB9
.text C:\WINDOWS\system32\lsass.exe[940] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00F00F10
.text C:\WINDOWS\system32\lsass.exe[940] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00EF0014
.text C:\WINDOWS\system32\lsass.exe[940] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00EF0F83
.text C:\WINDOWS\system32\lsass.exe[940] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00EF0FC3
.text C:\WINDOWS\system32\lsass.exe[940] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00EF0FDE
.text C:\WINDOWS\system32\lsass.exe[940] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00EF004A
.text C:\WINDOWS\system32\lsass.exe[940] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00EF0FEF
.text C:\WINDOWS\system32\lsass.exe[940] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00EF0FA8
.text C:\WINDOWS\system32\lsass.exe[940] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [0F, 89]
.text C:\WINDOWS\system32\lsass.exe[940] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00EF002F
.text C:\WINDOWS\system32\lsass.exe[940] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00EE0038
.text C:\WINDOWS\system32\lsass.exe[940] msvcrt.dll!system 77C293C7 5 Bytes JMP 00EE0FAD
.text C:\WINDOWS\system32\lsass.exe[940] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00EE000C
.text C:\WINDOWS\system32\lsass.exe[940] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00EE0FE3
.text C:\WINDOWS\system32\lsass.exe[940] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00EE001D
.text C:\WINDOWS\system32\lsass.exe[940] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00EE0FD2
.text C:\WINDOWS\system32\lsass.exe[940] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00ED000A
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B40000
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B40F5F
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B40F70
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B40F8D
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B40F9E
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B4002C
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B40096
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B40F4E
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B40F22
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B400B1
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00B400D6
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00B40FAF
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00B40FDB
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00B40079
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00B40011
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00B40FC0
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00B40F33
.text C:\WINDOWS\system32\svchost.exe[1132] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00B30036
.text C:\WINDOWS\system32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00B30084
.text C:\WINDOWS\system32\svchost.exe[1132] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00B30FE5
.text C:\WINDOWS\system32\svchost.exe[1132] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00B3001B
.text C:\WINDOWS\system32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00B30073
.text C:\WINDOWS\system32\svchost.exe[1132] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00B30000
.text C:\WINDOWS\system32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00B30062
.text C:\WINDOWS\system32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00B30047
.text C:\WINDOWS\system32\svchost.exe[1132] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B20F97
.text C:\WINDOWS\system32\svchost.exe[1132] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B2002C
.text C:\WINDOWS\system32\svchost.exe[1132] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B20FD7
.text C:\WINDOWS\system32\svchost.exe[1132] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B20000
.text C:\WINDOWS\system32\svchost.exe[1132] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B20FB2
.text C:\WINDOWS\system32\svchost.exe[1132] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B20011
.text C:\WINDOWS\system32\svchost.exe[1132] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00AB0FEF
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C30000
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C30FAF
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C300A4
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C30FC0
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C3007D
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C3003D
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C30F94
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C300D0
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C30F65
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C30108
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00C30F54
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00C30058
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00C30011
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00C300BF
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00C3002C
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00C30FDB
.text C:\WINDOWS\system32\svchost.exe[1212] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00C300ED
.text C:\WINDOWS\system32\svchost.exe[1212] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00C20F9E
.text C:\WINDOWS\system32\svchost.exe[1212] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00C20F79
.text C:\WINDOWS\system32\svchost.exe[1212] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00C20FC3
.text C:\WINDOWS\system32\svchost.exe[1212] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00C20FD4
.text C:\WINDOWS\system32\svchost.exe[1212] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00C20040
.text C:\WINDOWS\system32\svchost.exe[1212] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00C20FEF
.text C:\WINDOWS\system32\svchost.exe[1212] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00C20025
.text C:\WINDOWS\system32\svchost.exe[1212] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00C2000A
.text C:\WINDOWS\system32\svchost.exe[1212] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00C10053
.text C:\WINDOWS\system32\svchost.exe[1212] msvcrt.dll!system 77C293C7 5 Bytes JMP 00C10038
.text C:\WINDOWS\system32\svchost.exe[1212] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00C10FD2
.text C:\WINDOWS\system32\svchost.exe[1212] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00C10000
.text C:\WINDOWS\system32\svchost.exe[1212] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00C1001D
.text C:\WINDOWS\system32\svchost.exe[1212] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00C10FE3
.text C:\WINDOWS\system32\svchost.exe[1212] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00C00000
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 020E0000
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 020E00A2
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 020E0FAD
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 020E0091
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 020E0076
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 020E005B
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 020E00DA
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 020E0F88
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 020E0F66
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 020E00FF
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 020E0F4B
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 020E0FD4
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 020E0FEF
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 020E00B3
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!CreateNamedPipeW 7C82F0C5 3 Bytes JMP 020E0040
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!CreateNamedPipeW + 4 7C82F0C9 1 Byte [85]
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 020E002F
.text C:\WINDOWS\System32\svchost.exe[1252] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 020E0F77
.text C:\WINDOWS\System32\svchost.exe[1252] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 01F30FC3
.text C:\WINDOWS\System32\svchost.exe[1252] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 01F30065
.text C:\WINDOWS\System32\svchost.exe[1252] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 01F30FDE
.text C:\WINDOWS\System32\svchost.exe[1252] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 01F30FEF
.text C:\WINDOWS\System32\svchost.exe[1252] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 01F30054
.text C:\WINDOWS\System32\svchost.exe[1252] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 01F30000
.text C:\WINDOWS\System32\svchost.exe[1252] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 01F30039
.text C:\WINDOWS\System32\svchost.exe[1252] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 01F30FA8
.text C:\WINDOWS\System32\svchost.exe[1252] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01590049
.text C:\WINDOWS\System32\svchost.exe[1252] msvcrt.dll!system 77C293C7 5 Bytes JMP 01590FC8
.text C:\WINDOWS\System32\svchost.exe[1252] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0159001D
.text C:\WINDOWS\System32\svchost.exe[1252] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01590FE3
.text C:\WINDOWS\System32\svchost.exe[1252] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01590038
.text C:\WINDOWS\System32\svchost.exe[1252] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01590000
.text C:\WINDOWS\System32\svchost.exe[1252] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01580FEF
.text C:\WINDOWS\System32\svchost.exe[1252] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 020D0000
.text C:\WINDOWS\System32\svchost.exe[1252] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 020D001B
.text C:\WINDOWS\System32\svchost.exe[1252] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 020D002C
.text C:\WINDOWS\System32\svchost.exe[1252] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 020D0047
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00770000
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00770F92
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00770FA3
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0077007D
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00770FC0
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00770047
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 007700B3
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00770F77
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00770F3F
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00770F50
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00770F2E
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00770058
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00770011
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 007700A2
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00770FDB
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00770022
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 007700CE
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00760025
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00760FAF
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00760FD4
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00760FEF
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 0076006C
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00760000
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 0076005B
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00760040
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00750069
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!system 77C293C7 5 Bytes JMP 00750058
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00750022
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00750000
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0075003D
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00750011
.text C:\WINDOWS\System32\svchost.exe[1312] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00740FE5
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01810FE5
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01810F83
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01810082
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01810F9E
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0181005B
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01810FB9
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01810F4B
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01810093
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 018100B8
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01810F1F
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 018100DD
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 01810036
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 01810FD4
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 01810F68
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 0181001B
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 01810000
.text C:\WINDOWS\Explorer.EXE[1520] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 01810F30
.text C:\WINDOWS\Explorer.EXE[1520] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 016B0025
.text C:\WINDOWS\Explorer.EXE[1520] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 016B0F83
.text C:\WINDOWS\Explorer.EXE[1520] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 016B0FD4
.text C:\WINDOWS\Explorer.EXE[1520] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 016B0000
.text C:\WINDOWS\Explorer.EXE[1520] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 016B0040
.text C:\WINDOWS\Explorer.EXE[1520] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 016B0FE5
.text C:\WINDOWS\Explorer.EXE[1520] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 016B0F9E
.text C:\WINDOWS\Explorer.EXE[1520] ADVAPI32.dll!RegCreateKeyW + 4 77DFBA29 1 Byte [89]
.text C:\WINDOWS\Explorer.EXE[1520] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 3 Bytes JMP 016B0FAF
.text C:\WINDOWS\Explorer.EXE[1520] ADVAPI32.dll!RegCreateKeyA + 4 77DFBCC7 1 Byte [89]
.text C:\WINDOWS\Explorer.EXE[1520] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 016A0039
.text C:\WINDOWS\Explorer.EXE[1520] msvcrt.dll!system 77C293C7 5 Bytes JMP 016A0FA4
.text C:\WINDOWS\Explorer.EXE[1520] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 016A0FC6
.text C:\WINDOWS\Explorer.EXE[1520] msvcrt.dll!_open 77C2F566 5 Bytes JMP 016A0000
.text C:\WINDOWS\Explorer.EXE[1520] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 016A0FB5
.text C:\WINDOWS\Explorer.EXE[1520] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 016A0FD7
.text C:\WINDOWS\Explorer.EXE[1520] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 01800FEF
.text C:\WINDOWS\Explorer.EXE[1520] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 01800000
.text C:\WINDOWS\Explorer.EXE[1520] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 01800025
.text C:\WINDOWS\Explorer.EXE[1520] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 01800FD4
.text C:\WINDOWS\Explorer.EXE[1520] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02530FEF
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C20FEF
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C20093
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C20082
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C20065
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C2004A
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C20FC3
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C200BF
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C20F83
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C20F2D
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C20F48
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00C20F1C
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00C20FB2
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00C2000A
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00C200A4
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00C20FD4
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00C2001B
.text C:\WINDOWS\system32\svchost.exe[1528] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00C200D0
.text C:\WINDOWS\system32\svchost.exe[1528] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 009B0FA8
.text C:\WINDOWS\system32\svchost.exe[1528] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 009B0F7C
.text C:\WINDOWS\system32\svchost.exe[1528] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 009B0FC3
.text C:\WINDOWS\system32\svchost.exe[1528] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 009B0FDE
.text C:\WINDOWS\system32\svchost.exe[1528] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 009B0039
.text C:\WINDOWS\system32\svchost.exe[1528] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 009B0FEF
.text C:\WINDOWS\system32\svchost.exe[1528] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 009B0F8D
.text C:\WINDOWS\system32\svchost.exe[1528] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [BB, 88]
.text C:\WINDOWS\system32\svchost.exe[1528] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 009B0014
.text C:\WINDOWS\system32\svchost.exe[1528] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 009A0055
.text C:\WINDOWS\system32\svchost.exe[1528] msvcrt.dll!system 77C293C7 5 Bytes JMP 009A0044
.text C:\WINDOWS\system32\svchost.exe[1528] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 009A0FD4
.text C:\WINDOWS\system32\svchost.exe[1528] msvcrt.dll!_open 77C2F566 5 Bytes JMP 009A0FEF
.text C:\WINDOWS\system32\svchost.exe[1528] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 009A0029
.text C:\WINDOWS\system32\svchost.exe[1528] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 009A000C
.text C:\WINDOWS\system32\svchost.exe[1528] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00990000
.text C:\WINDOWS\system32\svchost.exe[1528] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 009C0000
.text C:\WINDOWS\system32\svchost.exe[1528] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 009C0FE5
.text C:\WINDOWS\system32\svchost.exe[1528] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 009C0FCA
.text C:\WINDOWS\system32\svchost.exe[1528] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 009C0FB9
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2008] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C130 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2008] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 0041C1B0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001A0000
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001A0093
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001A0078
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001A0F9E
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001A005B
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001A0036
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001A0F79
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001A00B5
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001A0F46
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001A0F57
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 001A00FA
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 001A0FB9
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 001A0FE5
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 001A00A4
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 001A0FCA
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 001A001B
.text C:\Program Files\Messenger\msmsgs.exe[2980] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 001A0F68
.text C:\Program Files\Messenger\msmsgs.exe[2980] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0029002E
.text C:\Program Files\Messenger\msmsgs.exe[2980] msvcrt.dll!system 77C293C7 5 Bytes JMP 00290FA3
.text C:\Program Files\Messenger\msmsgs.exe[2980] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00290FD2
.text C:\Program Files\Messenger\msmsgs.exe[2980] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00290FEF
.text C:\Program Files\Messenger\msmsgs.exe[2980] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0029001D
.text C:\Program Files\Messenger\msmsgs.exe[2980] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0029000C
.text C:\Program Files\Messenger\msmsgs.exe[2980] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 002A0FC3
.text C:\Program Files\Messenger\msmsgs.exe[2980] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 002A0F90
.text C:\Program Files\Messenger\msmsgs.exe[2980] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 002A0FDE
.text C:\Program Files\Messenger\msmsgs.exe[2980] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 002A000A
.text C:\Program Files\Messenger\msmsgs.exe[2980] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 002A004D
.text C:\Program Files\Messenger\msmsgs.exe[2980] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 002A0FEF
.text C:\Program Files\Messenger\msmsgs.exe[2980] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 002A0FA1
.text C:\Program Files\Messenger\msmsgs.exe[2980] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [4A, 88]
.text C:\Program Files\Messenger\msmsgs.exe[2980] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 002A0FB2
.text C:\Program Files\Messenger\msmsgs.exe[2980] WS2_32.dll!socket 71AB4211 5 Bytes JMP 002B0FE5
.text C:\Program Files\Messenger\msmsgs.exe[2980] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 002C0FEF
.text C:\Program Files\Messenger\msmsgs.exe[2980] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 002C0FD4
.text C:\Program Files\Messenger\msmsgs.exe[2980] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 002C0FC3
.text C:\Program Files\Messenger\msmsgs.exe[2980] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 002C0FA8
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001A0000
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001A008E
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001A0073
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001A0062
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001A0051
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001A0FC0
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001A00B3
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001A0F6D
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001A0F10
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001A0F2B
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 001A0EF5
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 001A0FAF
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 001A0011
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 001A0F7E
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 001A0036
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 001A0FDB
.text C:\WINDOWS\System32\svchost.exe[3040] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 001A0F46
.text C:\WINDOWS\System32\svchost.exe[3040] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 0029001E
.text C:\WINDOWS\System32\svchost.exe[3040] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 0029005E
.text C:\WINDOWS\System32\svchost.exe[3040] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00290FCD
.text C:\WINDOWS\System32\svchost.exe[3040] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00290FDE
.text C:\WINDOWS\System32\svchost.exe[3040] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00290FA1
.text C:\WINDOWS\System32\svchost.exe[3040] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00290FEF
.text C:\WINDOWS\System32\svchost.exe[3040] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00290FBC
.text C:\WINDOWS\System32\svchost.exe[3040] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [49, 88]
.text C:\WINDOWS\System32\svchost.exe[3040] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00290043
.text C:\WINDOWS\System32\svchost.exe[3040] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 003E006C
.text C:\WINDOWS\System32\svchost.exe[3040] msvcrt.dll!system 77C293C7 5 Bytes JMP 003E0047
.text C:\WINDOWS\System32\svchost.exe[3040] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 003E002C
.text C:\WINDOWS\System32\svchost.exe[3040] msvcrt.dll!_open 77C2F566 5 Bytes JMP 003E0000
.text C:\WINDOWS\System32\svchost.exe[3040] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 003E0FD7
.text C:\WINDOWS\System32\svchost.exe[3040] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 003E0011
.text C:\WINDOWS\System32\svchost.exe[3040] WS2_32.dll!socket 71AB4211 5 Bytes JMP 009B0FEF

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-436374069-1935655697-839522115-1003@RefCount 206

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\config\software.LOG (size mismatch) 1024/12288 bytes

—- EOF - GMER 1.0.15 —-
mgw7625,

I'm not finding a good reason for your problems. :wacko:


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Tuesday, April 14, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Tuesday, April 14, 2009 00:44:00 Records in database: 2041721 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Files scanned: 53502 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 01:41:10 File name / Threat name / Threats count C:\Documents and Settings\All Users\Application Data\AOL Downloads\lpaolcom_setupSTUS\comps\toolbar\toolbr.exe Infected: not-a-virus:AdWare.Win32.SearchIt.t 1 The selected area was scanned.
mgw7625,

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\Documents and Settings\All Users\Application Data\AOL Downloads\lpaolcom_setupSTUS\comps\toolbar\toolbr.exe
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Then please let me have a new HijackThis log and tell me how things are running.
I logged on to te laptop today and again had no wireless network connetion. After doing a repair again and rebooting I finally got int. I downloaded the app as you instructed and it gave me the reboot message. Now it is just frozen and has an hourglass for the last 3 minutes. Is this normal?
It finally rebooted and now again I have no wireless internet access. The repair process is not working this time…do you know what I can do now to get it back?
I want to throw this thing out of the window but I'm going to hang in there. I did 3 more repairs and finally got back on line. Here is the last log you asked for. If I can I'll post the HiJackthis is a few. Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\Documents and Settings\All Users\Application Data\AOL Downloads\lpaolcom_setupSTUS\comps\toolbar\toolbr.exe moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Michel\LOCALS~1\Temp\Perflib_Perfdata_90c.dat scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Michel\LOCALS~1\Temp\Perflib_Perfdata_cac.dat scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Michel\LOCALS~1\Temp\~DF426E.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\Michel\Local Settings\Temporary Internet Files\Content.IE5\G90R547Y\iframe[3].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Michel\Local Settings\Temporary Internet Files\Content.IE5\28U63GMD\Hungapp_Errors_t101740[2].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Michel\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Michel\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot. User's Temporary Internet Files folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Network Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\mcafee_zvVwNc4y1DxtrUn scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\mcmsc_1banlsWzHgDuhot scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\mcmsc_36mQOysFUW7z7wJ scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_758.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_2JCJbwxwb4K9eck scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_EsauQIxQ9yoJR9T scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_gfcWKOudv3ScAva scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_h1AZKaY99voL0Pp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_hck4V8tNMhe3X0H scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_t85XeYcucHDkADX scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_wew5wc10dIEPuJZ scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 04152009_170143 Files moved on Reboot… File C:\DOCUME~1\Michel\LOCALS~1\Temp\Perflib_Perfdata_90c.dat not found! File C:\DOCUME~1\Michel\LOCALS~1\Temp\Perflib_Perfdata_cac.dat not found! C:\DOCUME~1\Michel\LOCALS~1\Temp\~DF426E.tmp moved successfully. File C:\Documents and Settings\Michel\Local Settings\Temporary Internet Files\Content.IE5\G90R547Y\iframe[3].htm not found! File C:\Documents and Settings\Michel\Local Settings\Temporary Internet Files\Content.IE5\28U63GMD\Hungapp_Errors_t101740[2].htm not found! C:\Documents and Settings\Michel\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat moved successfully. File C:\WINDOWS\temp\mcafee_zvVwNc4y1DxtrUn not found! File C:\WINDOWS\temp\mcmsc_1banlsWzHgDuhot not found! File C:\WINDOWS\temp\mcmsc_36mQOysFUW7z7wJ not found! File move failed. C:\WINDOWS\temp\Perflib_Perfdata_758.dat scheduled to be moved on reboot. C:\WINDOWS\temp\sqlite_2JCJbwxwb4K9eck moved successfully. File C:\WINDOWS\temp\sqlite_EsauQIxQ9yoJR9T not found! C:\WINDOWS\temp\sqlite_gfcWKOudv3ScAva moved successfully. File C:\WINDOWS\temp\sqlite_h1AZKaY99voL0Pp not found! File C:\WINDOWS\temp\sqlite_hck4V8tNMhe3X0H not found! File C:\WINDOWS\temp\sqlite_t85XeYcucHDkADX not found! C:\WINDOWS\temp\sqlite_wew5wc10dIEPuJZ moved successfully.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:36:08 PM, on 4/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\WLTRAY.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Palo Alto Software\9.0\PAS9_UD.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Michel\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\System32\WLTRAY.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Palo Alto Software Update Manager 9.0.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: Acronis Remote Agent (AcronisAgent) - Acronis - C:\Program Files\Common Files\Acronis\Agent\agent.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 9967 bytes
mgw7625,

I'm not finding a good reason for all your troubles. Let's give this a try:


Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click Yes to all if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found:[external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    [external image: Posted Image]
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI