This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Can't update antivirus , browser redirected

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

First of all, a big THANK YOU in advance. The black hat guys that create this stuff are paid professionals and without the community assistance of boards like this the average user (i.e. Me!) would really be up the creek. THANKS!!!

Here's the behavior I'm noticing:

I can't update any of my anti-virus/anti-malware programs. I can't run malwarebytes or spyware doctor, and I can only run McAfee with the old virus definitions. Needless to say, it doesn't find anything.
My browser gets redirected when I click on links. Oddly enough, it doesn't happen if I type the url in myself.
Computer is just generally running slow and seems to be using excessive CPU and memory during times of relative inactivity.

Here's the HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:14:56 AM, on 5/6/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\csrss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\Explorer.EXE
G:\Program Files\McAfee.com\Agent\mcagent.exe
G:\WINDOWS\SOUNDMAN.EXE
G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
G:\Program Files\Java\jre6\bin\jusched.exe
G:\Program Files\iTunes\iTunesHelper.exe
G:\Program Files\Spyware Doctor\pctsTray.exe
G:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\CASIO\Photo Loader\Plauto.exe
G:\Program Files\Locate\Locate32.exe
G:\Program Files\Secunia\PSI\psi.exe
G:\WINDOWS\system32\svchost.exe
G:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
G:\Program Files\Bonjour\mDNSResponder.exe
G:\Program Files\Java\jre6\bin\jqs.exe
G:\Program Files\McAfee\SiteAdvisor\McSACore.exe
G:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
g:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
g:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
G:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
G:\Program Files\McAfee\MPF\MPFSrv.exe
G:\Program Files\Spyware Doctor\pctsAuxs.exe
G:\Program Files\Spyware Doctor\pctsSvc.exe
G:\WINDOWS\system32\svchost.exe
G:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
G:\Program Files\Viewpoint\Common\ViewpointService.exe
G:\Program Files\iPod\bin\iPodService.exe
G:\WINDOWS\System32\alg.exe
G:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
G:\Program Files\Mozilla Firefox\firefox.exe
g:\PROGRA~1\mcafee\msc\mcuimgr.exe
g:\PROGRA~1\mcafee\msc\mcupdmgr.exe
G:\Program Files\Trend Micro\HijackThis\HijackThis.exe
g:\PROGRA~1\mcafee.com\agent\mcupdate.exe
G:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - G:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - G:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - G:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - G:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - G:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - G:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - G:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - g:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - G:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - G:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - G:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - G:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - g:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - G:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - G:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [mcagent_exe] G:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "G:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "G:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "G:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "G:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [swg] G:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Locate32 Autorun.lnk = ?
O4 - Startup: Secunia PSI.lnk = G:\Program Files\Secunia\PSI\psi.exe
O4 - Global Startup: Photo Loader supervisory.lnk = G:\Program Files\CASIO\Photo Loader\Plauto.exe
O8 - Extra context menu item: &AIM Toolbar Search - G:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://G:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - G:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - G:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{B195FBB7-F822-4F69-8E63-B4E9F35FF758}: NameServer = 85.255.112.114,85.255.112.115
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.114,85.255.112.115
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.114,85.255.112.115
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.112.114,85.255.112.115
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.112.114,85.255.112.115
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.114,85.255.112.115
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - G:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - g:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - G:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apple Mobile Device - Apple Inc. - G:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - G:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - G:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - G:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - G:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - G:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - G:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - g:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - G:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - g:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - G:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - G:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - G:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - G:\Program Files\WinPcap\rpcapd.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - G:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - G:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - G:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - G:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 10175 bytes


Cheers!
Travis
Hi,

please do the following:

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt back into this thread.
CatByte - Thanks millions for you help.

As a possible note…I couldn't rename ComboFix when I downloaded it with Firefox. It's probably just me not doing something right but I wanted to let you know….might help in the future. IE was no problem…"Save As" box popped right up.

Here's the CF Log:

ComboFix 09-05-05.05 - T-Ravis 05/06/2009 13:18.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.350.73 [GMT -5:00]
Running from: g:\documents and settings\[removed]\Desktop\Combo–Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *enabled*
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-9-2-58-100005480-100013945-100010883-9499.com
g:\recycler\S-9-2-58-100005480-100013945-100010883-9499.com
g:\windows\system32\drivers\gxvxclmivjgddohsahsvltpvgkukopgugaqll.sys
g:\windows\system32\gxvxccounter
g:\windows\system32\gxvxckdpgmavdefxejntjnlmnecsxphaejsht.dll
h:\recycler\S-9-2-58-100005480-100013945-100010883-9499.com

.
((((((((((((((((((((((((( Files Created from 2009-04-06 to 2009-05-06 )))))))))))))))))))))))))))))))
.

2009-05-06 17:54 . 2009-05-06 17:54 ——– d—–w G:\Combo-Fix
2009-05-06 14:56 . 2009-05-06 14:56 ——– d—–w g:\program files\Trend Micro
2009-05-06 14:50 . 2009-05-06 14:50 ——– d—–w g:\program files\ERUNT
2009-04-29 01:50 . 2009-04-29 01:50 ——– d—–w g:\documents and settings\T-Ravis\Local Settings\Application Data\AIM Toolbar
2009-04-28 12:36 . 2009-04-28 12:48 ——– d—–w g:\documents and settings\T-Ravis\Application Data\Juniper Networks
2009-04-28 12:34 . 2009-04-28 12:34 ——– d—–w g:\documents and settings\T-Ravis\Application Data\acccore
2009-04-28 12:33 . 2009-04-28 12:33 ——– d—–w g:\documents and settings\T-Ravis\Local Settings\Application Data\AOL OCP
2009-04-28 12:32 . 2009-04-28 12:32 ——– d—–w g:\documents and settings\T-Ravis\Local Settings\Application Data\AOL
2009-04-28 12:30 . 2009-04-28 12:30 ——– d—–w g:\program files\Common Files\Software Update Utility
2009-04-28 12:30 . 2009-04-28 12:30 ——– d—–w g:\documents and settings\All Users\Application Data\AIM Toolbar
2009-04-28 12:30 . 2009-04-28 12:30 ——– d—–w g:\program files\AIM Toolbar
2009-04-28 12:29 . 2009-04-28 12:29 ——– d—–w g:\documents and settings\All Users\Application Data\Viewpoint
2009-04-28 12:29 . 2009-04-28 12:29 ——– d—–w g:\program files\Viewpoint
2009-04-28 12:29 . 2009-04-28 12:29 ——– d—–w g:\documents and settings\All Users\Application Data\acccore
2009-04-28 12:29 . 2009-04-28 12:34 ——– d—–w g:\documents and settings\All Users\Application Data\AOL OCP
2009-04-28 12:29 . 2009-04-28 12:29 ——– d—–w g:\documents and settings\All Users\Application Data\AOL
2009-04-28 12:29 . 2009-04-28 12:29 ——– d—–w g:\program files\Common Files\AOL
2009-04-28 12:28 . 2009-04-28 12:32 ——– d—–w g:\program files\AIM6
2009-04-27 20:12 . 2009-04-27 20:12 ——– d—–w g:\documents and settings\LocalService\Application Data\SACore
2009-04-27 20:11 . 2009-04-27 20:11 ——– d—–w g:\windows\system32\config\systemprofile\Application Data\SACore
2009-04-27 19:08 . 2009-04-27 19:08 ——– d—–w g:\documents and settings\All Users\Application Data\SiteAdvisor
2009-04-27 19:00 . 2008-12-11 13:38 159600 —-a-w g:\windows\system32\drivers\pctgntdi.sys
2009-04-27 18:59 . 2009-04-03 16:18 130936 —-a-w g:\windows\system32\drivers\PCTCore.sys
2009-04-27 18:59 . 2008-12-18 17:16 73840 —-a-w g:\windows\system32\drivers\PCTAppEvent.sys
2009-04-27 18:59 . 2009-05-06 18:10 ——– d—a-w g:\documents and settings\All Users\Application Data\TEMP
2009-04-27 18:58 . 2009-04-27 19:00 ——– d—–w g:\program files\Common Files\PC Tools
2009-04-27 18:58 . 2008-12-10 16:36 64392 —-a-w g:\windows\system32\drivers\pctplsg.sys
2009-04-27 18:58 . 2009-04-27 18:58 ——– d—–w g:\documents and settings\All Users\Application Data\PC Tools
2009-04-27 18:58 . 2009-04-27 18:58 ——– d—–w g:\documents and settings\T-Ravis\Application Data\PC Tools
2009-04-27 18:58 . 2009-04-27 19:06 ——– d—–w g:\program files\Spyware Doctor
2009-04-26 16:19 . 2009-04-26 16:19 ——– d—–w g:\documents and settings\T-Ravis\Application Data\IObit
2009-04-26 16:18 . 2009-04-26 16:19 ——– d—–w g:\program files\IObit SmartDefrag
2009-04-26 16:17 . 2009-04-06 20:32 15504 —-a-w g:\windows\system32\drivers\mbam.sys
2009-04-26 16:17 . 2009-04-06 20:32 38496 —-a-w g:\windows\system32\drivers\mbamswissarmy.sys
2009-04-26 16:17 . 2009-04-26 16:17 ——– d—–w g:\program files\Malwarebytes' Anti-Malware
2009-04-22 15:34 . 2009-04-22 15:34 ——– d—–w g:\program files\VS Revo Group
2009-04-21 07:04 . 2009-04-21 07:04 ——– d—–w g:\documents and settings\T-Ravis\Local Settings\Application Data\My Games
2009-04-21 06:18 . 2009-04-21 06:18 ——– d—–w g:\documents and settings\T-Ravis\Application Data\ImgBurn
2009-04-21 06:17 . 2009-04-21 06:17 ——– d—–w g:\program files\ImgBurn
2009-04-17 22:46 . 2009-04-17 22:46 ——– d—–w g:\program files\iPod
2009-04-17 22:46 . 2009-04-17 22:47 ——– d—–w g:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-17 22:46 . 2009-04-17 22:47 ——– d—–w g:\program files\iTunes
2009-04-17 07:02 . 2008-05-30 19:11 1491992 —-a-w g:\windows\system32\D3DCompiler_38.dll
2009-04-17 07:01 . 2005-05-26 20:34 2297552 —-a-w g:\windows\system32\d3dx9_26.dll
2009-04-17 07:00 . 2009-04-17 07:00 ——– d—–w g:\windows\Logs
2009-04-17 07:00 . 2009-04-17 07:00 ——– d—–w G:\DirectX
2009-04-17 06:30 . 2009-04-17 06:30 ——– d—–w g:\program files\Activision
2009-04-17 06:25 . 2009-04-17 06:27 ——– d—–w g:\documents and settings\T-Ravis\Application Data\DAEMON Tools
2009-04-17 06:25 . 2009-04-17 06:25 ——– d—–w g:\documents and settings\T-Ravis\Application Data\DAEMON Tools Pro
2009-04-17 06:24 . 2009-04-17 06:24 ——– d—–w g:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-04-17 06:23 . 2009-04-17 06:23 ——– d—–w g:\program files\DAEMON Tools Lite
2009-04-17 06:16 . 2009-04-17 06:16 717296 —-a-w g:\windows\system32\drivers\sptd.sys
2009-04-17 06:16 . 2009-04-17 06:28 ——– d—–w g:\documents and settings\T-Ravis\Application Data\DAEMON Tools Lite
2009-04-17 05:05 . 2009-04-21 06:40 ——– d—–w g:\program files\Downloads
2009-04-16 23:04 . 2008-05-03 11:55 2560 ——w g:\windows\system32\xpsp4res.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-05 15:45 . 2009-02-12 06:31 664 —-a-w g:\windows\system32\d3d9caps.dat
2009-04-29 01:52 . 2009-02-11 20:30 ——– d—–w g:\program files\AskBarDis
2009-04-27 19:27 . 2009-02-10 07:03 ——– d—–w g:\program files\McAfee
2009-04-22 15:48 . 2009-02-10 06:25 ——– d–h–w g:\program files\InstallShield Installation Information
2009-04-17 22:46 . 2009-02-11 20:11 ——– d—–w g:\program files\Common Files\Apple
2009-04-17 06:29 . 2009-02-10 06:25 ——– d—–w g:\program files\Common Files\InstallShield
2009-04-12 05:01 . 2009-02-27 05:57 ——– d—–w g:\program files\PokerStars
2009-04-09 06:01 . 2009-02-12 06:17 ——– d—–w g:\program files\Java
2009-03-19 21:32 . 2009-02-11 20:15 23400 —-a-w g:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-17 14:38 . 2009-02-10 05:53 ——– d—–w g:\program files\Google
2009-03-16 19:18 . 2009-04-17 07:03 69448 —-a-w g:\windows\system32\XAPOFX1_3.dll
2009-03-16 19:18 . 2009-04-17 07:03 517448 —-a-w g:\windows\system32\XAudio2_4.dll
2009-03-16 19:18 . 2009-04-17 07:03 235352 —-a-w g:\windows\system32\xactengine3_4.dll
2009-03-16 19:18 . 2009-04-17 07:03 22360 —-a-w g:\windows\system32\X3DAudio1_6.dll
2009-03-13 16:10 . 2009-03-13 16:10 552 —-a-w g:\windows\system32\d3d8caps.dat
2009-03-09 20:27 . 2009-04-17 07:03 453456 —-a-w g:\windows\system32\d3dx10_41.dll
2009-03-09 20:27 . 2009-04-17 07:03 1846632 —-a-w g:\windows\system32\D3DCompiler_41.dll
2009-03-09 20:27 . 2009-04-17 07:03 4178264 —-a-w g:\windows\system32\D3DX9_41.dll
2009-03-09 10:19 . 2009-02-12 06:17 410984 —-a-w g:\windows\system32\deploytk.dll
2009-03-06 14:22 . 2008-04-14 04:42 284160 —-a-w g:\windows\system32\pdh.dll
2009-03-06 04:59 . 2009-03-24 19:26 1900544 —-a-w g:\windows\system32\usbaaplrc.dll
2009-03-06 04:59 . 2009-02-11 20:12 36864 —-a-w g:\windows\system32\drivers\usbaapl.sys
2009-03-03 00:18 . 2008-04-14 04:42 826368 —-a-w g:\windows\system32\wininet.dll
2009-02-20 18:09 . 2008-04-14 04:41 78336 —-a-w g:\windows\system32\ieencode.dll
2009-02-10 06:36 . 2009-02-10 06:36 0 —-a-w g:\windows\nsreg.dat
2009-02-10 06:04 . 2009-02-10 05:31 86327 —-a-w g:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-02-10 05:32 . 2001-08-23 11:00 67 –sha-w g:\windows\Fonts\desktop.ini
2009-02-10 05:28 . 2009-02-10 05:28 21640 —-a-w g:\windows\system32\emptyregdb.dat
2009-02-09 12:10 . 2008-04-14 04:41 729088 —-a-w g:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2008-04-14 04:42 401408 —-a-w g:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2008-04-14 04:41 617472 —-a-w g:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2008-04-14 04:41 714752 —-a-w g:\windows\system32\ntdll.dll
2009-02-09 11:13 . 2008-04-14 00:00 1846784 —-a-w g:\windows\system32\win32k.sys
2009-02-08 00:02 . 2008-04-14 00:01 2066048 —-a-w g:\windows\system32\ntkrnlpa.exe
2009-02-06 11:11 . 2008-04-14 04:42 110592 —-a-w g:\windows\system32\services.exe
2009-02-06 11:08 . 2008-04-13 23:57 2189056 —-a-w g:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2001-08-23 11:00 35328 —-a-w g:\windows\system32\sc.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-11-18 18:58 333192 —-a-w g:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "g:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "g:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="g:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-21 68856]
"ctfmon.exe"="g:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="g:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992]
"GrooveMonitor"="g:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"QuickTime Task"="g:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"SunJavaUpdateSched"="g:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"iTunesHelper"="g:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"ISTray"="g:\program files\Spyware Doctor\pctsTray.exe" [2008-12-08 1173384]
"SoundMan"="SOUNDMAN.EXE" - g:\windows\soundman.exe [2005-07-22 81920]

g:\documents and settings\T-Ravis\Start Menu\Programs\Startup\
Locate32 Autorun.lnk - g:\program files\Locate\Locate32.exe [2007-7-1 970752]
Secunia PSI.lnk - g:\program files\Secunia\PSI\psi.exe [2008-12-17 748840]

g:\documents and settings\All Users\Start Menu\Programs\Startup\
Photo Loader supervisory.lnk - g:\program files\CASIO\Photo Loader\Plauto.exe [2009-2-11 229376]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"g:\\Program Files\\uTorrent\\uTorrent.exe"=
"g:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"g:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"g:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"g:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"g:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"g:\\Program Files\\iTunes\\iTunes.exe"=
"g:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"g:\\Program Files\\AIM6\\aim6.exe"=

R0 PCTCore;PCTools KDS;g:\windows\system32\drivers\PCTCore.sys [4/27/2009 1:59 PM 130936]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;g:\program files\McAfee\SiteAdvisor\McSACore.exe [4/27/2009 2:00 PM 210216]
R2 sdAuxService;PC Tools Auxiliary Service;g:\program files\Spyware Doctor\pctsAuxs.exe [4/27/2009 1:58 PM 348752]
R2 Viewpoint Manager Service;Viewpoint Manager Service;g:\program files\Viewpoint\Common\ViewpointService.exe [4/28/2009 7:29 AM 24652]
R3 PSI;PSI;g:\windows\system32\drivers\psi_mf.sys [12/10/2008 9:17 AM 7808]
S3 FUTUREX;FUTUREX;g:\documents and settings\T-Ravis\Desktop\Aida32\aida32.sys [2/10/2009 1:13 AM 3907]
S3 NPF;NetGroup Packet Filter Driver;g:\windows\system32\drivers\npf.sys [12/23/2008 10:35 AM 50704]

— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f0ce7a6-33b3-11de-8078-00142a0c5c9c}]
\Shell\AutoRun\command - D:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder

2009-04-24 g:\windows\Tasks\AppleSoftwareUpdate.job
- g:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]

2009-04-15 g:\windows\Tasks\McDefragTask.job
- g:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-10 19:32]

2009-04-01 g:\windows\Tasks\McQcTask.job
- g:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-10 19:32]

2009-05-06 g:\windows\Tasks\RegCure Program Check.job
- g:\program files\RegCure\RegCure.exe [2008-04-21 20:40]

2009-04-23 g:\windows\Tasks\RegCure.job
- g:\program files\RegCure\RegCure.exe [2008-04-21 20:40]

2009-04-26 g:\windows\Tasks\SmartDefrag.job
- g:\program files\IObit SmartDefrag\IObit SmartDefrag.exe [2009-04-26 23:15]

2009-05-06 g:\windows\Tasks\WGASetup.job
- g:\windows\system32\KB905474\wgasetup.exe [2009-04-01 03:18]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Aim6 - (no file)


.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AIM Toolbar Search - g:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - g:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - g:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
FF - ProfilePath - g:\documents and settings\T-Ravis\Application Data\Mozilla\Firefox\Profiles\l437934z.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=&query=
FF - component: g:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: g:\documents and settings\T-Ravis\Application Data\Mozilla\Firefox\Profiles\l437934z.default\extensions\[removed]\plugins\npTVUAx.dll
FF - plugin: g:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: g:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: g:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-06 13:24
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-05-06 13:27
ComboFix-quarantined-files.txt 2009-05-06 18:27

Pre-Run: 5,558,009,856 bytes free
Post-Run: 5,691,392,000 bytes free

Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
232 — E O F — 2009-04-18 08:02
Hi

please run the following program, also please describe in detail how your computer is running now and what ,if any, issues remain.


Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
Hey yo,

Here's the GMER log…so much info it makes my head spin.

The 'puter seems to be running just fine….everything has been updated and all my anti- programs are scanning.

Thanks again.


GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-06 15:06:07
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateKey [0xF72AF514]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xF729E282]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xF729E474]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteKey [0xF72AFD00]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteValueKey [0xF72AFFB8]
SSDT spyq.sys ZwEnumerateKey [0xF73BFCA2]
SSDT spyq.sys ZwEnumerateValueKey [0xF73C0030]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwOpenKey [0xF72AE3FA]
SSDT spyq.sys ZwQueryKey [0xF73C0108]
SSDT spyq.sys ZwQueryValueKey [0xF73BFF88]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xF72B0422]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwSetValueKey [0xF72AF7D8]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xF729DF32]

INT 0x62 ? 8278ABF8
INT 0x63 ? 82223F00
INT 0x63 ? 82223F00
INT 0x63 ? 82223F00
INT 0x63 ? 82223F00
INT 0x63 ? 82223F00
INT 0x63 ? 82223F00
INT 0x82 ? 8278ABF8
INT 0x83 ? 8278ABF8

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF69389D8]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xF6938AF4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xF6938930]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xF6938944]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xF69389AC]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xF6938A9C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xF6938B1C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xF6938B08]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xF6938998]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xF6938984]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xF6938ADE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF69389EE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xF69389C2]
Code \??\G:\DOCUME~1\T-Ravis\LOCALS~1\Temp\catchme.sys pIofCallDriver
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

—- Kernel code sections - GMER 1.0.15 —-

? spyq.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F70EE8AC 5 Bytes JMP 822234E0
.text alnxt06l.SYS F6D02386 35 Bytes [00, 00, 00, 00, 00, 00, 20, …]
.text alnxt06l.SYS F6D023AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, …]
.text alnxt06l.SYS F6D023C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text alnxt06l.SYS F6D023C9 1 Byte [2E]
.text alnxt06l.SYS F6D023C9 11 Bytes [2E, 00, 00, 00, 5C, 02, 00, …] {ADD CS:[EAX], AL; ADD [EDX+EAX+0x0], BL; ADD [EAX], AL; ADD [EAX], AL}
.text …
? G:\WINDOWS\system32\Drivers\mchInjDrv.sys The system cannot find the file specified. !
? G:\DOCUME~1\T-Ravis\LOCALS~1\Temp\catchme.sys The system cannot find the file specified. !
? G:\WINDOWS\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text g:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[136] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 02DB0001
.text g:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[136] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C340 g:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text g:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[136] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0041C3C0 g:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text G:\Program Files\Java\jre6\bin\jqs.exe[204] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01300001
.text G:\Program Files\McAfee\SiteAdvisor\McSACore.exe[332] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 028A0001
.text G:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[396] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 02B40001
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001A0000
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001A0F66
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001A0065
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001A0F81
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001A0F9E
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001A0FAF
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001A0F38
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001A0080
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001A00B6
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001A0F1D
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!FreeLibrary + 15 7C80AC93 4 Bytes CALL 7170003D
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 001A0F02
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 001A0040
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 001A0FE5
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 001A0F55
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 001A001B
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 001A0FCA
.text G:\WINDOWS\explorer.exe[452] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 001A009B
.text G:\WINDOWS\explorer.exe[452] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00290FD4
.text G:\WINDOWS\explorer.exe[452] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00290040
.text G:\WINDOWS\explorer.exe[452] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00290FEF
.text G:\WINDOWS\explorer.exe[452] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00290025
.text G:\WINDOWS\explorer.exe[452] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00290F8D
.text G:\WINDOWS\explorer.exe[452] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00290000
.text G:\WINDOWS\explorer.exe[452] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00290F9E
.text G:\WINDOWS\explorer.exe[452] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [49, 88]
.text G:\WINDOWS\explorer.exe[452] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00290FC3
.text G:\WINDOWS\explorer.exe[452] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 002A0FA6
.text G:\WINDOWS\explorer.exe[452] msvcrt.dll!system 77C293C7 5 Bytes JMP 002A0FB7
.text G:\WINDOWS\explorer.exe[452] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 002A0FE3
.text G:\WINDOWS\explorer.exe[452] msvcrt.dll!_open 77C2F566 5 Bytes JMP 002A0000
.text G:\WINDOWS\explorer.exe[452] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 002A0FC8
.text G:\WINDOWS\explorer.exe[452] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 002A0011
.text G:\WINDOWS\explorer.exe[452] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 002C0FEF
.text G:\WINDOWS\explorer.exe[452] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 002C000A
.text G:\WINDOWS\explorer.exe[452] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 002C001B
.text G:\WINDOWS\explorer.exe[452] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 002C0036
.text G:\WINDOWS\explorer.exe[452] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01CF0FEF
.text G:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[524] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 009D0001
.text G:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[524] kernel32.dll!FreeLibrary + 15 7C80AC93 4 Bytes CALL 7170003D
.text g:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[536] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01150001
.text G:\WINDOWS\system32\csrss.exe[580] KERNEL32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01580001
.text G:\WINDOWS\system32\winlogon.exe[604] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01130001
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01070000
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01070F8F
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01070084
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01070073
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00CD0001
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01070058
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01070FC7
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01070F7E
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 010700BA
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 010700F2
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 010700E1
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01070F48
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01070FB6
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0107001B
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 010700A9
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0107003D
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0107002C
.text G:\WINDOWS\system32\services.exe[648] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01070F63
.text G:\WINDOWS\system32\services.exe[648] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01060FDB
.text G:\WINDOWS\system32\services.exe[648] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01060FAF
.text G:\WINDOWS\system32\services.exe[648] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0106002C
.text G:\WINDOWS\system32\services.exe[648] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01060011
.text G:\WINDOWS\system32\services.exe[648] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01060FC0
.text G:\WINDOWS\system32\services.exe[648] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01060000
.text G:\WINDOWS\system32\services.exe[648] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 01060058
.text G:\WINDOWS\system32\services.exe[648] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01060047
.text G:\WINDOWS\system32\services.exe[648] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00FF0031
.text G:\WINDOWS\system32\services.exe[648] msvcrt.dll!system 77C293C7 5 Bytes JMP 00FF0FA6
.text G:\WINDOWS\system32\services.exe[648] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00FF000C
.text G:\WINDOWS\system32\services.exe[648] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00FF0FE3
.text G:\WINDOWS\system32\services.exe[648] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00FF0FC1
.text G:\WINDOWS\system32\services.exe[648] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00FF0FD2
.text G:\WINDOWS\system32\services.exe[648] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FE0FE5
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F70FE5
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F70084
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F70073
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F70062
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00B90001
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F70051
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F7001B
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F700B5
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F70F6D
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F70F41
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F700DA
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F700F5
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F70036
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F70FCA
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F70F7E
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F7000A
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F70FB9
.text G:\WINDOWS\system32\lsass.exe[660] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F70F52
.text G:\WINDOWS\system32\lsass.exe[660] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00F60FE5
.text G:\WINDOWS\system32\lsass.exe[660] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00F60FA8
.text G:\WINDOWS\system32\lsass.exe[660] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00F60036
.text G:\WINDOWS\system32\lsass.exe[660] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00F6001B
.text G:\WINDOWS\system32\lsass.exe[660] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00F6005B
.text G:\WINDOWS\system32\lsass.exe[660] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00F60000
.text G:\WINDOWS\system32\lsass.exe[660] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00F60FB9
.text G:\WINDOWS\system32\lsass.exe[660] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [16, 89]
.text G:\WINDOWS\system32\lsass.exe[660] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00F60FCA
.text G:\WINDOWS\system32\lsass.exe[660] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BE0FA3
.text G:\WINDOWS\system32\lsass.exe[660] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BE0FB4
.text G:\WINDOWS\system32\lsass.exe[660] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BE001D
.text G:\WINDOWS\system32\lsass.exe[660] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BE000C
.text G:\WINDOWS\system32\lsass.exe[660] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BE002E
.text G:\WINDOWS\system32\lsass.exe[660] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BE0FEF
.text G:\WINDOWS\system32\lsass.exe[660] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00BA0000
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BD0FEF
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BD0093
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BD0078
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BD0067
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00EA0001
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BD0040
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BD0FAF
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BD0F79
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BD00C1
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BD0F57
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BD00E6
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BD0F46
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BD0F9E
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BD000A
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BD00A4
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BD001B
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BD0FCA
.text G:\WINDOWS\system32\svchost.exe[820] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BD0F68
.text G:\WINDOWS\system32\svchost.exe[820] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00BC0022
.text G:\WINDOWS\system32\svchost.exe[820] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00BC005F
.text G:\WINDOWS\system32\svchost.exe[820] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00BC0FDB
.text G:\WINDOWS\system32\svchost.exe[820] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00BC0011
.text G:\WINDOWS\system32\svchost.exe[820] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00BC004E
.text G:\WINDOWS\system32\svchost.exe[820] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00BC0000
.text G:\WINDOWS\system32\svchost.exe[820] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00BC0FAC
.text G:\WINDOWS\system32\svchost.exe[820] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [DC, 88]
.text G:\WINDOWS\system32\svchost.exe[820] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00BC0033
.text G:\WINDOWS\system32\svchost.exe[820] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BB0F90
.text G:\WINDOWS\system32\svchost.exe[820] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BB0FAB
.text G:\WINDOWS\system32\svchost.exe[820] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BB0000
.text G:\WINDOWS\system32\svchost.exe[820] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BB0FEF
.text G:\WINDOWS\system32\svchost.exe[820] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BB001B
.text G:\WINDOWS\system32\svchost.exe[820] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BB0FD2
.text G:\WINDOWS\system32\svchost.exe[820] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00BA0FEF
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00DC0000
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00DC0F8B
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00DC0F9C
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00DC0076
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00FA0001
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00DC005B
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00DC0FC3
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00DC00AC
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00DC0F70
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00DC0F38
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00DC0F53
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00DC00EC
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00DC004A
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00DC0FE5
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00DC009B
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00DC0FD4
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00DC0025
.text G:\WINDOWS\system32\svchost.exe[912] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00DC00C7
.text G:\WINDOWS\system32\svchost.exe[912] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00DB0FE5
.text G:\WINDOWS\system32\svchost.exe[912] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00DB007D
.text G:\WINDOWS\system32\svchost.exe[912] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00DB0040
.text G:\WINDOWS\system32\svchost.exe[912] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00DB001B
.text G:\WINDOWS\system32\svchost.exe[912] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00DB0FC0
.text G:\WINDOWS\system32\svchost.exe[912] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00DB000A
.text G:\WINDOWS\system32\svchost.exe[912] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00DB0062
.text G:\WINDOWS\system32\svchost.exe[912] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00DB0051
.text G:\WINDOWS\system32\svchost.exe[912] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00DA0FAD
.text G:\WINDOWS\system32\svchost.exe[912] msvcrt.dll!system 77C293C7 5 Bytes JMP 00DA0FC8
.text G:\WINDOWS\system32\svchost.exe[912] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00DA002E
.text G:\WINDOWS\system32\svchost.exe[912] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00DA000C
.text G:\WINDOWS\system32\svchost.exe[912] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00DA0FD9
.text G:\WINDOWS\system32\svchost.exe[912] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00DA001D
.text G:\WINDOWS\system32\svchost.exe[912] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00D90000
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02B40000
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02B4008E
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02B4007D
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02B40FAF
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 02140001
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02B4006C
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02B40040
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02B400C1
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02B400B0
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02B40F43
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02B40F54
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02B400F7
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02B40051
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02B4001B
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02B4009F
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02B40FD4
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02B40FE5
.text G:\WINDOWS\System32\svchost.exe[980] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02B400D2
.text G:\WINDOWS\System32\svchost.exe[980] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02B20036
.text G:\WINDOWS\System32\svchost.exe[980] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 02B20FAC
.text G:\WINDOWS\System32\svchost.exe[980] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 02B20025
.text G:\WINDOWS\System32\svchost.exe[980] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 02B20014
.text G:\WINDOWS\System32\svchost.exe[980] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02B20073
.text G:\WINDOWS\System32\svchost.exe[980] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 02B20FEF
.text G:\WINDOWS\System32\svchost.exe[980] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 02B20062
.text G:\WINDOWS\System32\svchost.exe[980] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02B20051
.text G:\WINDOWS\System32\svchost.exe[980] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02B10F84
.text G:\WINDOWS\System32\svchost.exe[980] msvcrt.dll!system 77C293C7 5 Bytes JMP 02B10F95
.text G:\WINDOWS\System32\svchost.exe[980] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02B10FC1
.text G:\WINDOWS\System32\svchost.exe[980] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02B10FEF
.text G:\WINDOWS\System32\svchost.exe[980] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02B10FB0
.text G:\WINDOWS\System32\svchost.exe[980] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02B10FD2
.text G:\WINDOWS\System32\svchost.exe[980] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02440000
.text G:\WINDOWS\System32\svchost.exe[980] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 02B30FEF
.text G:\WINDOWS\System32\svchost.exe[980] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 02B30000
.text G:\WINDOWS\System32\svchost.exe[980] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 02B30FCA
.text G:\WINDOWS\System32\svchost.exe[980] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 02B3001B
.text G:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[1000] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 066C0001
.text G:\Program Files\McAfee\MPF\MPFSrv.exe[1108] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 02CF0001
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 008C0FEF
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 008C0040
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 008C0F4B
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 008C0F5C
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00BA0001
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 008C0025
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 008C0F9E
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 008C0F04
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 008C0F15
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 008C0082
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 008C005D
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 008C0EC4
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 008C0F83
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 008C0FD4
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 008C0F30
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 008C000A
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 008C0FC3
.text G:\WINDOWS\system32\svchost.exe[1116] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 008C0EDF
.text G:\WINDOWS\system32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 008B0040
.text G:\WINDOWS\system32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 008B0098
.text G:\WINDOWS\system32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 008B0FEF
.text G:\WINDOWS\system32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 008B0025
.text G:\WINDOWS\system32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 008B007D
.text G:\WINDOWS\system32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 008B0000
.text G:\WINDOWS\system32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 008B0062
.text G:\WINDOWS\system32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 008B0051
.text G:\WINDOWS\system32\svchost.exe[1116] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 008A0050
.text G:\WINDOWS\system32\svchost.exe[1116] msvcrt.dll!system 77C293C7 5 Bytes JMP 008A003F
.text G:\WINDOWS\system32\svchost.exe[1116] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 008A0FE3
.text G:\WINDOWS\system32\svchost.exe[1116] msvcrt.dll!_open 77C2F566 5 Bytes JMP 008A000C
.text G:\WINDOWS\system32\svchost.exe[1116] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 008A002E
.text G:\WINDOWS\system32\svchost.exe[1116] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 008A001D
.text G:\WINDOWS\system32\svchost.exe[1116] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00890FEF
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00A3000A
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00A30F94
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00A30FAF
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00A30089
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 009B0001
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00A30062
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00A30FD1
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00A30F5C
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00A300A4
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A30F1F
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A30F30
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00A300D3
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00A30FC0
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00A30025
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00A30F83
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00A30047
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00A30036
.text G:\WINDOWS\system32\svchost.exe[1240] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00A30F4B
.text G:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00A20036
.text G:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00A20FA8
.text G:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00A20025
.text G:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00A20FE5
.text G:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00A20FC3
.text G:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00A20000
.text G:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00A20FD4
.text G:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [C2, 88]
.text G:\WINDOWS\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00A20051
.text G:\WINDOWS\system32\svchost.exe[1240] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00A10FA8
.text G:\WINDOWS\system32\svchost.exe[1240] msvcrt.dll!system 77C293C7 5 Bytes JMP 00A10FB9
.text G:\WINDOWS\system32\svchost.exe[1240] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00A10FDE
.text G:\WINDOWS\system32\svchost.exe[1240] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00A1000C
.text G:\WINDOWS\system32\svchost.exe[1240] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00A10033
.text G:\WINDOWS\system32\svchost.exe[1240] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00A10FEF
.text G:\WINDOWS\system32\svchost.exe[1240] WS2_32.dll!socket 71AB4211 5 Bytes JMP 009C0FEF
.text G:\WINDOWS\system32\spoolsv.exe[1488] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00A60001
.text G:\Program Files\McAfee.com\Agent\mcagent.exe[1696] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01BF0001
.text G:\Program Files\McAfee.com\Agent\mcagent.exe[1696] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F140F5A
.text G:\Program Files\McAfee.com\Agent\mcagent.exe[1696] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F0D0F5A
.text G:\Program Files\McAfee.com\Agent\mcagent.exe[1696] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text G:\Program Files\McAfee.com\Agent\mcagent.exe[1696] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [12, 5F]
.text G:\Program Files\McAfee.com\Agent\mcagent.exe[1696] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F170F5A
.text G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1716] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01040001
.text G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1716] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F140F5A
.text G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1716] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F0D0F5A
.text G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1716] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1716] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [12, 5F]
.text G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1716] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F170F5A
.text G:\Program Files\Java\jre6\bin\jusched.exe[1732] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00E60001
.text G:\Program Files\Java\jre6\bin\jusched.exe[1732] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F140F5A
.text G:\Program Files\Java\jre6\bin\jusched.exe[1732] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F0D0F5A
.text G:\Program Files\Java\jre6\bin\jusched.exe[1732] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text G:\Program Files\Java\jre6\bin\jusched.exe[1732] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [12, 5F]
.text G:\Program Files\Java\jre6\bin\jusched.exe[1732] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F170F5A
.text G:\Program Files\iTunes\iTunesHelper.exe[1740] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 022F0001
.text G:\Program Files\iTunes\iTunesHelper.exe[1740] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F140F5A
.text G:\Program Files\iTunes\iTunesHelper.exe[1740] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F0D0F5A
.text G:\Program Files\iTunes\iTunesHelper.exe[1740] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text G:\Program Files\iTunes\iTunesHelper.exe[1740] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [12, 5F]
.text G:\Program Files\iTunes\iTunesHelper.exe[1740] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F170F5A
.text G:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[1764] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 013F0001
.text G:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[1764] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F140F5A
.text G:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[1764] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F0D0F5A
.text G:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[1764] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text G:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[1764] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [12, 5F]
.text G:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[1764] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F170F5A
.text G:\WINDOWS\system32\ctfmon.exe[1784] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00D10001
.text G:\WINDOWS\system32\ctfmon.exe[1784] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F140F5A
.text G:\WINDOWS\system32\ctfmon.exe[1784] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F0D0F5A
.text G:\WINDOWS\system32\ctfmon.exe[1784] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text G:\WINDOWS\system32\ctfmon.exe[1784] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [12, 5F]
.text G:\WINDOWS\system32\ctfmon.exe[1784] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F170F5A
.text G:\Program Files\CASIO\Photo Loader\Plauto.exe[1812] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00D30001
.text G:\Program Files\CASIO\Photo Loader\Plauto.exe[1812] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F140F5A
.text G:\Program Files\CASIO\Photo Loader\Plauto.exe[1812] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F0D0F5A
.text G:\Program Files\CASIO\Photo Loader\Plauto.exe[1812] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text G:\Program Files\CASIO\Photo Loader\Plauto.exe[1812] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [12, 5F]
.text G:\Program Files\CASIO\Photo Loader\Plauto.exe[1812] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F170F5A
.text G:\Program Files\Locate\Locate32.exe[1852] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01160001
.text G:\Program Files\Locate\Locate32.exe[1852] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F140F5A
.text G:\Program Files\Locate\Locate32.exe[1852] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F0D0F5A
.text G:\Program Files\Locate\Locate32.exe[1852] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text G:\Program Files\Locate\Locate32.exe[1852] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [12, 5F]
.text G:\Program Files\Locate\Locate32.exe[1852] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F170F5A
.text G:\Program Files\Secunia\PSI\psi.exe[1860] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 02650001
.text G:\Program Files\Secunia\PSI\psi.exe[1860] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F140F5A
.text G:\Program Files\Secunia\PSI\psi.exe[1860] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F0D0F5A
.text G:\Program Files\Secunia\PSI\psi.exe[1860] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text G:\Program Files\Secunia\PSI\psi.exe[1860] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [12, 5F]
.text G:\Program Files\Secunia\PSI\psi.exe[1860] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F170F5A
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C00FEF
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C00F35
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C00F5A
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C00F6B
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00920001
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C00F7C
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C00FB2
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C00EF6
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C00F07
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C00ECA
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C00EE5
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00C00088
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00C00F97
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00C00014
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00C00F24
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00C00FC3
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00C00FD4
.text G:\WINDOWS\system32\svchost.exe[1972] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00C00063
.text G:\WINDOWS\system32\svchost.exe[1972] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00BE0025
.text G:\WINDOWS\system32\svchost.exe[1972] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00BE0F83
.text G:\WINDOWS\system32\svchost.exe[1972] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00BE0FCA
.text G:\WINDOWS\system32\svchost.exe[1972] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00BE0FE5
.text G:\WINDOWS\system32\svchost.exe[1972] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00BE0F9E
.text G:\WINDOWS\system32\svchost.exe[1972] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00BE0000
.text G:\WINDOWS\system32\svchost.exe[1972] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00BE0040
.text G:\WINDOWS\system32\svchost.exe[1972] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00BE0FB9
.text G:\WINDOWS\system32\svchost.exe[1972] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BD0F9E
.text G:\WINDOWS\system32\svchost.exe[1972] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BD0033
.text G:\WINDOWS\system32\svchost.exe[1972] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BD0FD4
.text G:\WINDOWS\system32\svchost.exe[1972] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BD0FEF
.text G:\WINDOWS\system32\svchost.exe[1972] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BD0FC3
.text G:\WINDOWS\system32\svchost.exe[1972] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BD0018
.text G:\WINDOWS\system32\svchost.exe[1972] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00BF0FEF
.text G:\WINDOWS\system32\svchost.exe[1972] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00BF0000
.text G:\WINDOWS\system32\svchost.exe[1972] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00BF0FD4
.text G:\WINDOWS\system32\svchost.exe[1972] WININET.dll!InternetOpenUrlW 780BAF69 5 Bytes JMP 00BF002F
.text G:\WINDOWS\system32\svchost.exe[1972] WS2_32.dll!socket 71AB4211 5 Bytes JMP 0093000A
.text G:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[2016] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00C30001
.text G:\Program Files\Bonjour\mDNSResponder.exe[2032] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 007A0001
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BC0000
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BC00AE
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BC0093
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BC0082
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00E70001
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BC0FB9
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BC0FD4
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BC0F7C
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BC0F8D
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BC0F3F
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BC0F5A
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BC0F24
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BC005B
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BC001B
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BC0F9E
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BC004A
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BC0FEF
.text G:\WINDOWS\system32\svchost.exe[2284] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BC0F6B
.text G:\WINDOWS\system32\svchost.exe[2284] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00BB001B
.text G:\WINDOWS\system32\svchost.exe[2284] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00BB0058
.text G:\WINDOWS\system32\svchost.exe[2284] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00BB0FCA
.text G:\WINDOWS\system32\svchost.exe[2284] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00BB000A
.text G:\WINDOWS\system32\svchost.exe[2284] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00BB0FA5
.text G:\WINDOWS\system32\svchost.exe[2284] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00BB0FEF
.text G:\WINDOWS\system32\svchost.exe[2284] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00BB003D
.text G:\WINDOWS\system32\svchost.exe[2284] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00BB002C
.text G:\WINDOWS\system32\svchost.exe[2284] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BA0F92
.text G:\WINDOWS\system32\svchost.exe[2284] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BA0FAD
.text G:\WINDOWS\system32\svchost.exe[2284] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BA0016
.text G:\WINDOWS\system32\svchost.exe[2284] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BA0FEF
.text G:\WINDOWS\system32\svchost.exe[2284] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BA0027
.text G:\WINDOWS\system32\svchost.exe[2284] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BA0FDE
.text G:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[2308] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00A00001
.text G:\Program Files\Viewpoint\Common\ViewpointService.exe[2320] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00900001
.text G:\WINDOWS\system32\notepad.exe[2732] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00AF0001
.text G:\WINDOWS\system32\notepad.exe[2732] kernel32.dll!FreeLibrary + 15 7C80AC93 4 Bytes CALL 7170003D
.text G:\WINDOWS\system32\notepad.exe[2732] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F140F5A
.text G:\WINDOWS\system32\notepad.exe[2732] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F0D0F5A
.text G:\WINDOWS\system32\notepad.exe[2732] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text G:\WINDOWS\system32\notepad.exe[2732] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [12, 5F]
.text G:\WINDOWS\system32\notepad.exe[2732] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F170F5A
.text G:\Program Files\iPod\bin\iPodService.exe[3568] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 008D0001
.text G:\Program Files\iPod\bin\iPodService.exe[3568] kernel32.dll!FreeLibrary + 15 7C80AC93 4 Bytes CALL 7170003D
.text G:\Documents and Settings\T-Ravis\Desktop\gmer.exe[3976] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003F0001
.text G:\Documents and Settings\T-Ravis\Desktop\gmer.exe[3976] kernel32.dll!FreeLibrary + 15 7C80AC93 4 Bytes CALL 7170003D
.text G:\Documents and Settings\T-Ravis\Desktop\gmer.exe[3976] USER32.dll!ChangeDisplaySettingsExA 7E42384E 6 Bytes JMP 5F0D0F5A
.text G:\Documents and Settings\T-Ravis\Desktop\gmer.exe[3976] USER32.dll!SetForegroundWindow 7E4242ED 6 Bytes JMP 5F040F5A
.text G:\Documents and Settings\T-Ravis\Desktop\gmer.exe[3976] USER32.dll!SetWindowPos 7E4299F3 3 Bytes [FF, 25, 1E]
.text G:\Documents and Settings\T-Ravis\Desktop\gmer.exe[3976] USER32.dll!SetWindowPos + 4 7E4299F7 2 Bytes [0B, 5F]
.text G:\Documents and Settings\T-Ravis\Desktop\gmer.exe[3976] USER32.dll!ChangeDisplaySettingsExW 7E4595BD 6 Bytes JMP 5F100F5A
.text G:\WINDOWS\System32\alg.exe[4076] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00870001
.text G:\WINDOWS\System32\alg.exe[4076] kernel32.dll!FreeLibrary + 15 7C80AC93 4 Bytes CALL 7170003D

—- Kernel IAT/EAT - GMER 1.0.15 —-

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F73A2040] spyq.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F73A213C] spyq.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F73A20BE] spyq.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F73A27FC] spyq.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F73A26D2] spyq.sys
IAT \SystemRoot\System32\Drivers\alnxt06l.SYS[HAL.dll!KfAcquireSpinLock] 4B8BDF8B
IAT \SystemRoot\System32\Drivers\alnxt06l.SYS[HAL.dll!READ_PORT_UCHAR] 8D3F0304
IAT \SystemRoot\System32\Drivers\alnxt06l.SYS[HAL.dll!KeGetCurrentIrql] CB033043
IAT \SystemRoot\System32\Drivers\alnxt06l.SYS[HAL.dll!KfRaiseIrql] 0673C13B
IAT \SystemRoot\System32\Drivers\alnxt06l.SYS[HAL.dll!KfLowerIrql] C13B0003
IAT \SystemRoot\System32\Drivers\alnxt06l.SYS[HAL.dll!HalGetInterruptVector] 8366FA72
IAT \SystemRoot\System32\Drivers\alnxt06l.SYS[HAL.dll!HalTranslateBusAddress] 75000E7B
IAT \SystemRoot\System32\Drivers\alnxt06l.SYS[HAL.dll!KeStallExecutionProcessor] 0B7D80E3
IAT \SystemRoot\System32\Drivers\alnxt06l.SYS[HAL.dll!KfReleaseSpinLock] 307B8D00
IAT \SystemRoot\System32\Drivers\alnxt06l.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 00AA840F
IAT \SystemRoot\System32\Drivers\alnxt06l.SYS[HAL.dll!READ_PORT_USHORT] 83660000
IAT \SystemRoot\System32\Drivers\alnxt06l.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 6A000E7A
IAT \SystemRoot\System32\Drivers\alnxt06l.SYS[HAL.dll!WRITE_PORT_UCHAR] C6647400
IAT \SystemRoot\System32\Drivers\alnxt06l.SYS[WMILIB.SYS!WmiSystemControl] 4F8B0200
IAT \SystemRoot\System32\Drivers\alnxt06l.SYS[WMILIB.SYS!WmiCompleteRequest] 968D5140
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F73B2048] spyq.sys

—- User IAT/EAT - GMER 1.0.15 —-

IAT G:\WINDOWS\explorer.exe[452] @ G:\WINDOWS\explorer.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT G:\WINDOWS\explorer.exe[452] @ G:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT G:\WINDOWS\explorer.exe[452] @ G:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT G:\WINDOWS\explorer.exe[452] @ G:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT G:\WINDOWS\explorer.exe[452] @ G:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT G:\WINDOWS\explorer.exe[452] @ G:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT G:\WINDOWS\explorer.exe[452] @ G:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT G:\WINDOWS\explorer.exe[452] @ G:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT G:\WINDOWS\explorer.exe[452] @ G:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 827881F8

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

Device \FileSystem\Fastfat \FatCdrom 822B3500

AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

Device \Driver\usbuhci \Device\USBPDO-0 82379500
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8278B1F8
Device \Driver\dmio \Device\DmControl\DmConfig 8278B1F8
Device \Driver\dmio \Device\DmControl\DmPnP 8278B1F8
Device \Driver\dmio \Device\DmControl\DmInfo 8278B1F8
Device \Driver\usbuhci \Device\USBPDO-1 82379500
Device \Driver\usbuhci \Device\USBPDO-2 82379500
Device \Driver\usbuhci \Device\USBPDO-3 82379500
Device \Driver\usbehci \Device\USBPDO-4 8250C500

AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

Device \Driver\usbstor \Device\00000070 822B1500
Device \Driver\Ftdisk \Device\HarddiskVolume1 8278C1F8
Device \Driver\usbstor \Device\00000071 822B1500
Device \Driver\Cdrom \Device\CdRom0 8235D1F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8278C1F8
Device \Driver\Ftdisk \Device\HarddiskVolume3 8278C1F8
Device \Driver\Cdrom \Device\CdRom1 8235D1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8250D500
Device \Driver\PCI_PNP3470 \Device\0000004b spyq.sys
Device \Driver\NetBT \Device\NetbiosSmb 8250D500

AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

Device \Driver\usbuhci \Device\USBFDO-0 82379500
Device \Driver\NetBT \Device\NetBT_Tcpip_{B195FBB7-F822-4F69-8E63-B4E9F35FF758} 8250D500
Device \Driver\usbuhci \Device\USBFDO-1 82379500
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 822AA500
Device \Driver\usbuhci \Device\USBFDO-2 82379500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 822AA500
Device \Driver\usbuhci \Device\USBFDO-3 82379500
Device \Driver\usbehci \Device\USBFDO-4 8250C500
Device \Driver\sptd \Device\2499234720 spyq.sys
Device \Driver\Ftdisk \Device\FtControl 8278C1F8
Device \Driver\alnxt06l \Device\Scsi\alnxt06l1Port4Path0Target0Lun0 8235B500
Device \Driver\alnxt06l \Device\Scsi\alnxt06l1 8235B500
Device \FileSystem\Fastfat \Fat 822B3500

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

Device \FileSystem\Cdfs \Cdfs 822B0500

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet001\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxclmivjgddohsahsvltpvgkukopgugaqll.sys
Reg HKLM\SYSTEM\ControlSet001\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\ControlSet001\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxclmivjgddohsahsvltpvgkukopgugaqll.sys
Reg HKLM\SYSTEM\ControlSet001\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxckdpgmavdefxejntjnlmnecsxphaejsht.dll
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 G:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x64 0xC1 0x1B 0xD7 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x23 0xF7 0x8D 0x39 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCB 0xC0 0x11 0xD7 …
Reg HKLM\SYSTEM\ControlSet002\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxclmivjgddohsahsvltpvgkukopgugaqll.sys
Reg HKLM\SYSTEM\ControlSet002\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\ControlSet002\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxclmivjgddohsahsvltpvgkukopgugaqll.sys
Reg HKLM\SYSTEM\ControlSet002\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxckdpgmavdefxejntjnlmnecsxphaejsht.dll
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 G:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x64 0xC1 0x1B 0xD7 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x23 0xF7 0x8D 0x39 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCB 0xC0 0x11 0xD7 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 G:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x64 0xC1 0x1B 0xD7 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x23 0xF7 0x8D 0x39 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCB 0xC0 0x11 0xD7 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 G:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x64 0xC1 0x1B 0xD7 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x23 0xF7 0x8D 0x39 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCB 0xC0 0x11 0xD7 …

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

In your next reply please include
  • MBAM Log
  • Kaspersky report
Hi For some reason I can't get Kaspersky to run the scan….it keeps stalling out about 7 minutes in. Here is my MBAM report. Malwarebytes' Anti-Malware 1.36 Database version: 1945 Windows 5.1.2600 Service Pack 3 5/7/2009 3:24:17 PM mbam-log-2009-05-07 (15-24-17).txt Scan type: Quick Scan Objects scanned: 66435 Time elapsed: 11 minute(s), 40 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 7 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.114,85.255.112.115 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{b195fbb7-f822-4f69-8e63-b4e9f35ff758}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.114,85.255.112.115 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.114,85.255.112.115 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{b195fbb7-f822-4f69-8e63-b4e9f35ff758}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.114,85.255.112.115 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.114,85.255.112.115 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\Interfaces\{b195fbb7-f822-4f69-8e63-b4e9f35ff758}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.114,85.255.112.115 -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi,

Please try this online scan instead:

Use IE for this scan:

Please run the following online scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start.  The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button.  The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Here is my ESET report: # version=4 # OnlineScanner.ocx=1.0.0.635 # OnlineScannerDLLA.dll=1, 0, 0, 79 # OnlineScannerDLLW.dll=1, 0, 0, 78 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=4065 (20090511) # vers_arch_module=1.064 (20080214) # vers_adv_heur_module=1.066 (20070917) # EOSSerial=04edfd567aad8e479b5a8eec421f98ef # end=finished # remove_checked=false # unwanted_checked=true # utc_time=2009-05-11 10:52:26 # local_time=2009-05-11 05:52:26 (-0600, Central Daylight Time) # country="United States" # osver=5.1.2600 NT Service Pack 3 # scanned=501418 # found=7 # scan_time=26742 E:\RECYCLER\S-9-2-58-100005480-100013945-100010883-9499.com Win32/AutoRun.Agent.NF worm 3E2940B6E979487EC484E9704F4A6937 G:\Program Files\Cain\Cain.exe probably a variant of Win32/Genetik trojan 43140EA84D4F0BF933B9044C7A1455D9 G:\Qoobox\Quarantine\C\RECYCLER\S-9-2-58-100005480-100013945-100010883-9499.com.vir Win32/AutoRun.Agent.NF worm 3E2940B6E979487EC484E9704F4A6937 G:\Qoobox\Quarantine\G\RECYCLER\S-9-2-58-100005480-100013945-100010883-9499.com.vir Win32/AutoRun.Agent.NF worm 3E2940B6E979487EC484E9704F4A6937 G:\Qoobox\Quarantine\G\WINDOWS\system32\drivers\gxvxclmivjgddohsahsvltpvgkukopgugaqll.sys.vir Win32/TrojanClicker.Agent.NGF trojan CAC71D16A1AE7EE30352212F52974986 G:\Qoobox\Quarantine\H\RECYCLER\S-9-2-58-100005480-100013945-100010883-9499.com.vir Win32/AutoRun.Agent.NF worm 3E2940B6E979487EC484E9704F4A6937 H:\Downloads\Sunny Day\LiveInSeattle.avi a variant of WMA/TrojanDownloader.GetCodec.gen trojan 89ABC43C4CDAAC27227D8600D9E968C7
Hi,

Please do the following:

Please download OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please click OTMoveIt3 and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Files
E:\RECYCLER\S-9-2-58-100005480-100013945-100010883-9499.com
H:\Downloads\Sunny Day\LiveInSeattle.avi

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



NEXT

Please post a fresh HJT log along with the OTMoveIt log and describe in detail how your computer is running now.
HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:44:00 PM, on 5/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\Explorer.EXE
G:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
G:\Program Files\Bonjour\mDNSResponder.exe
G:\Program Files\Java\jre6\bin\jqs.exe
G:\Program Files\McAfee\SiteAdvisor\McSACore.exe
G:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
g:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
g:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
G:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
G:\Program Files\McAfee\MPF\MPFSrv.exe
G:\WINDOWS\system32\svchost.exe
G:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
G:\Program Files\Viewpoint\Common\ViewpointService.exe
g:\PROGRA~1\mcafee.com\agent\mcagent.exe
G:\WINDOWS\notepad.exe
G:\WINDOWS\SOUNDMAN.EXE
G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
G:\WINDOWS\system32\wuauclt.exe
G:\Program Files\Java\jre6\bin\jusched.exe
G:\Program Files\iTunes\iTunesHelper.exe
G:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\CASIO\Photo Loader\Plauto.exe
G:\Program Files\Locate\Locate32.exe
G:\Program Files\Secunia\PSI\psi.exe
G:\Program Files\iPod\bin\iPodService.exe
G:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
G:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - G:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - G:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - G:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - G:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - G:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - G:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - G:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - g:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - G:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - G:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - G:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - G:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - g:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - G:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - G:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [mcagent_exe] G:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "G:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "G:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "G:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [swg] G:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Locate32 Autorun.lnk = ?
O4 - Startup: Secunia PSI.lnk = G:\Program Files\Secunia\PSI\psi.exe
O4 - Global Startup: Photo Loader supervisory.lnk = G:\Program Files\CASIO\Photo Loader\Plauto.exe
O8 - Extra context menu item: &AIM Toolbar Search - G:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://G:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - G:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - G:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - G:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - g:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - G:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apple Mobile Device - Apple Inc. - G:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - G:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - G:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - G:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - G:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - G:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - G:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - g:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - G:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - g:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - G:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - G:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - G:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - G:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - G:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - G:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 8927 bytes

OTMoveIt Log:
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
E:\RECYCLER\S-9-2-58-100005480-100013945-100010883-9499.com moved successfully.
H:\Downloads\Sunny Day\LiveInSeattle.avi moved successfully.
========== COMMANDS ==========
File delete failed. G:\DOCUME~1\T-Ravis\LOCALS~1\Temp\etilqs_vsrMZax1pYNU5OHp7GMz scheduled to be deleted on reboot.
File delete failed. G:\DOCUME~1\T-Ravis\LOCALS~1\Temp\Perflib_Perfdata_1d8.dat scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. G:\Documents and Settings\T-Ravis\Local Settings\Temporary Internet Files\Content.IE5\YF6MQWS8\index[4].htm scheduled to be deleted on reboot.
File delete failed. G:\Documents and Settings\T-Ravis\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. G:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. G:\WINDOWS\temp\mcafee_K0NxvkxV0FaF8zC scheduled to be deleted on reboot.
File delete failed. G:\WINDOWS\temp\mcmsc_f4ra1ZIxyCIjMrE scheduled to be deleted on reboot.
File delete failed. G:\WINDOWS\temp\mcmsc_HECEZ2nhHYm3OcL scheduled to be deleted on reboot.
File delete failed. G:\WINDOWS\temp\mcmsc_lPbvOSpMahcb6Bp scheduled to be deleted on reboot.
File delete failed. G:\WINDOWS\temp\mcmsc_uBdXxGP7FZxWTa5 scheduled to be deleted on reboot.
File delete failed. G:\WINDOWS\temp\mcmsc_zUGSjeLwukbGfwu scheduled to be deleted on reboot.
File delete failed. G:\WINDOWS\temp\Perflib_Perfdata_fc.dat scheduled to be deleted on reboot.
File delete failed. G:\WINDOWS\temp\sqlite_bJgDGXAjC4EqGTz scheduled to be deleted on reboot.
File delete failed. G:\WINDOWS\temp\sqlite_WuYsNR6ab4FzbdD scheduled to be deleted on reboot.
File delete failed. G:\WINDOWS\temp\sqlite_y4mNIMNjJbY1scC scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. G:\Documents and Settings\T-Ravis\Local Settings\Application Data\Mozilla\Firefox\Profiles\l437934z.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. G:\Documents and Settings\T-Ravis\Local Settings\Application Data\Mozilla\Firefox\Profiles\l437934z.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. G:\Documents and Settings\T-Ravis\Local Settings\Application Data\Mozilla\Firefox\Profiles\l437934z.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. G:\Documents and Settings\T-Ravis\Local Settings\Application Data\Mozilla\Firefox\Profiles\l437934z.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. G:\Documents and Settings\T-Ravis\Local Settings\Application Data\Mozilla\Firefox\Profiles\l437934z.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05132009_173013

Files moved on Reboot…
File G:\DOCUME~1\T-Ravis\LOCALS~1\Temp\etilqs_vsrMZax1pYNU5OHp7GMz not found!
File G:\DOCUME~1\T-Ravis\LOCALS~1\Temp\Perflib_Perfdata_1d8.dat not found!
G:\Documents and Settings\T-Ravis\Local Settings\Temporary Internet Files\Content.IE5\YF6MQWS8\index[4].htm moved successfully.
File G:\WINDOWS\temp\mcafee_K0NxvkxV0FaF8zC not found!
File G:\WINDOWS\temp\mcmsc_f4ra1ZIxyCIjMrE not found!
File G:\WINDOWS\temp\mcmsc_HECEZ2nhHYm3OcL not found!
File G:\WINDOWS\temp\mcmsc_lPbvOSpMahcb6Bp not found!
File G:\WINDOWS\temp\mcmsc_uBdXxGP7FZxWTa5 not found!
File G:\WINDOWS\temp\mcmsc_zUGSjeLwukbGfwu not found!
File G:\WINDOWS\temp\Perflib_Perfdata_fc.dat not found!
G:\WINDOWS\temp\sqlite_bJgDGXAjC4EqGTz moved successfully.
G:\WINDOWS\temp\sqlite_WuYsNR6ab4FzbdD moved successfully.
G:\WINDOWS\temp\sqlite_y4mNIMNjJbY1scC moved successfully.
G:\Documents and Settings\T-Ravis\Local Settings\Application Data\Mozilla\Firefox\Profiles\l437934z.default\Cache\_CACHE_001_ moved successfully.
G:\Documents and Settings\T-Ravis\Local Settings\Application Data\Mozilla\Firefox\Profiles\l437934z.default\Cache\_CACHE_002_ moved successfully.
G:\Documents and Settings\T-Ravis\Local Settings\Application Data\Mozilla\Firefox\Profiles\l437934z.default\Cache\_CACHE_003_ moved successfully.
G:\Documents and Settings\T-Ravis\Local Settings\Application Data\Mozilla\Firefox\Profiles\l437934z.default\Cache\_CACHE_MAP_ moved successfully.
G:\Documents and Settings\T-Ravis\Local Settings\Application Data\Mozilla\Firefox\Profiles\l437934z.default\urlclassifier3.sqlite moved successfully.
Hi,

Your logs are clean :thumbup:

Now we have some housekeeping to do,

Please do the following:


Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
  • Click the Pt. Restauration button and press OK to the prompts.
  • Click the Corbeille button and press OK to the prompt.
  • Click the Fichiers temp button and press OK to the prompt.
  • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
  • Once it is done click the Suppression button and let it remove anything it finds.
  • Close the program


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

  • For Firefox I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

  • Please read the guide by Rorschach112 on how to prevent malware and about safe computing here
Thank you for your patience, and performing all of the procedures requested.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI