here are the logs you requested.
DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 7:20:11.71 on Fri 06/19/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1493 [GMT -7:00]
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:\windows\system32\svchost -k DcomLaunch
svchost.exe
C:\windows\System32\svchost.exe -k netsvcs
svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\Explorer.EXE
C:\Program Files\2Wire\Gateway\2PortalMon.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\windows\system32\RUNDLL32.EXE
C:\windows\RTHDCPL.EXE
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\windows\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\windows\system32\PnkBstrB.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Documents and Settings\Mike\Desktop\dds.pif
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchAssistant = hxxp://www.google.com
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearchAssistant = hxxp://www.google.com
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {348FE907-249E-4C65-A838-F34A193FE1D1} - No File
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SidebarAutoLaunch Class: {f2aa9440-6328-4933-b7c9-a6ccdf9cbf6d} - c:\program files\yahoo!\browser\YSidebarIEBHO.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\program files\yahoo!\messenger\yhexbmes.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
uRun: [igndlm.exe] c:\program files\download manager\dlm.exe /windowsstart /startifwork
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~2.EXE -Update -1103472 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; YComp 5.0.0.0; GTB6; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET CLR 1.1.4322)" -"
http://www.miniclip.com/games/rich-racer/en/"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [2wSysTray] c:\program files\2wire\gateway\2PortalMon.exe
mRun: [YBrowser] c:\progra~1\yahoo!\browser\ybrwicon.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [mcagent_exe] c:\program files\mcafee.com\agent\mcagent.exe /runkey
mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\oscust.lnk - c:\windows\system32\oem\OSCust.exe
IE: Add to Windows &Live Favorites
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: roseonlinegame.com\www
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper20073151.dll
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} - hxxp://download.yahoo.com/dl/installs/ymail/ymmapi.dll
DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} - hxxp://a.download.toontown.com/sv1.0.32.17/ttinst.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: WB - c:\program files\alienguise\fastload.dll
AppInit_DLLs: karna.dat
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-4-24 201320]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-4-24 203280]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-4-24 359248]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-4-24 144704]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-4-24 695624]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-4-24 79304]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-4-24 35240]
R3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-4-24 33832]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-4-24 40488]
S3 XDva195;XDva195;\??\c:\windows\system32\xdva195.sys –> c:\windows\system32\XDva195.sys [?]
=============== Created Last 30 ================
2009-06-12 08:43 –d—– c:\docume~1\alluse~1\applic~1\PMB Files
2009-06-12 08:43 –d—– c:\program files\Pando Networks
2009-05-26 19:24 –d—– c:\program files\Sony Online Entertainment
2009-05-23 08:18 –d—– c:\docume~1\alluse~1\applic~1\99374206
2009-05-23 08:18 –d—– c:\docume~1\alluse~1\applic~1\19364214
==================== Find3M ====================
============= FINISH: 7:22:29.62 ===============
Here is the attach.txt
DDS (Ver_09-05-14.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 2/28/2008 1:34:35 PM
System Uptime: 6/19/2009 7:03:57 AM (0 hours ago)
Motherboard: alienware | | alienware
Processor: AMD Athlon™ 64 X2 Dual Core Processor 5200+ | Socket M2 | 2611/201mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 233 GiB total, 109.756 GiB free.
D: is CDROM (UDF)
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP394: 6/13/2009 6:01:11 PM - System Checkpoint
RP395: 6/13/2009 6:01:11 PM - System Checkpoint
RP396: 6/13/2009 6:01:11 PM - System Checkpoint
RP397: 6/13/2009 6:01:11 PM - System Checkpoint
RP398: 6/13/2009 6:01:11 PM - System Checkpoint
RP399: 6/13/2009 6:01:11 PM - System Checkpoint
RP400: 6/13/2009 6:01:11 PM - System Checkpoint
RP401: 6/13/2009 6:01:11 PM - System Checkpoint
RP402: 6/13/2009 6:01:11 PM - Software Distribution Service 3.0
RP403: 6/13/2009 6:01:11 PM - System Checkpoint
RP404: 6/13/2009 6:01:11 PM - System Checkpoint
RP405: 6/13/2009 6:01:12 PM - Installed Call of Duty® - World at War™ 1.4 Patch
RP406: 6/13/2009 6:01:12 PM - Performance
RP407: 6/13/2009 6:01:12 PM - Removed Call of Duty® - World at War™ 1.4 Patch
RP408: 6/13/2009 6:01:12 PM - Installed DirectX
RP409: 6/13/2009 6:01:12 PM - System Checkpoint
RP410: 6/13/2009 6:01:12 PM - System Checkpoint
RP411: 6/13/2009 6:01:12 PM - System Checkpoint
RP412: 6/13/2009 6:01:12 PM - System Checkpoint
RP413: 6/13/2009 6:01:12 PM - System Checkpoint
RP414: 6/13/2009 6:01:13 PM - System Checkpoint
RP415: 6/13/2009 6:01:13 PM - Software Distribution Service 3.0
RP416: 6/13/2009 6:01:13 PM - System Checkpoint
RP417: 6/13/2009 6:01:13 PM - System Checkpoint
RP418: 6/13/2009 6:01:13 PM - System Checkpoint
RP419: 6/13/2009 6:01:13 PM - System Checkpoint
RP420: 6/13/2009 6:01:13 PM - System Checkpoint
RP421: 6/13/2009 6:01:13 PM - System Checkpoint
RP422: 6/13/2009 6:01:13 PM - System Checkpoint
RP423: 6/13/2009 6:01:13 PM - System Checkpoint
RP424: 6/13/2009 6:01:14 PM - System Checkpoint
RP425: 6/13/2009 6:01:14 PM - System Checkpoint
RP426: 6/13/2009 6:01:14 PM - Software Distribution Service 3.0
RP427: 6/13/2009 6:01:14 PM - Restore Operation
RP428: 6/13/2009 6:01:14 PM - System Checkpoint
RP429: 6/13/2009 6:01:14 PM - Software Distribution Service 3.0
RP430: 6/13/2009 6:01:14 PM - System Checkpoint
RP431: 6/13/2009 6:01:14 PM - System Checkpoint
RP432: 6/13/2009 6:01:15 PM - System Checkpoint
RP433: 6/13/2009 6:01:15 PM - System Checkpoint
RP434: 6/13/2009 6:01:15 PM - System Checkpoint
RP435: 6/13/2009 6:01:15 PM - System Checkpoint
RP436: 6/13/2009 6:01:15 PM - System Checkpoint
RP437: 6/13/2009 6:01:15 PM - System Checkpoint
RP438: 6/13/2009 6:01:15 PM - System Checkpoint
RP439: 6/13/2009 6:01:15 PM - System Checkpoint
RP440: 6/13/2009 6:01:16 PM - System Checkpoint
RP441: 6/13/2009 6:01:16 PM - System Checkpoint
RP442: 6/13/2009 6:01:16 PM - System Checkpoint
RP443: 6/13/2009 6:01:16 PM - System Checkpoint
RP444: 6/13/2009 6:01:17 PM - System Checkpoint
RP445: 6/13/2009 6:01:17 PM - System Checkpoint
RP446: 6/13/2009 6:01:17 PM - Removed Battlefield 2142 Deluxe Edition
RP447: 6/13/2009 6:01:18 PM - Removed BattleForge™
RP448: 6/13/2009 6:01:18 PM - Removed LiveUpdate Notice (Symantec Corporation)
RP449: 6/13/2009 6:01:18 PM - Software Distribution Service 3.0
RP450: 6/13/2009 6:01:18 PM - Software Distribution Service 3.0
RP451: 6/13/2009 6:01:18 PM - System Checkpoint
RP452: 6/13/2009 6:01:19 PM - Removed MapleStory.
RP453: 6/13/2009 6:01:19 PM - Installed MapleStory.
==== Installed Programs ======================
==== Event Viewer Messages From Past Week ========
==== End Of File ===========================
Here is Gmer
GMER 1.0.15.14972 -
http://www.gmer.net
Rootkit scan 2009-06-19 19:33:14
Windows 5.1.2600 Service Pack 3
—- System - GMER 1.0.15 —-
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xACD8A9AA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xACD8AA41]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xACD8A958]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xACD8A96C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xACD8AA55]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xACD8AA81]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xACD8AAF4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xACD8AAD9]
Code 8A80BCC0 ZwFlushInstructionCache
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xACD8A9EA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xACD8AB1E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xACD8AA2D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xACD8A930]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xACD8A944]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xACD8A9BE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xACD8AB5A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xACD8AAC3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xACD8AAAD]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xACD8AA6B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xACD8AB46]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xACD8AB32]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xACD8A996]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xACD8A982]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xACD8AA97]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xACD8AA19]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xACD8AB08]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xACD8AA00]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xACD8A9D4]
Code 89FB6096 IofCallDriver
Code 8A865096 IofCompleteRequest
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!IofCallDriver 804EF1A6 5 Bytes JMP 89FB609B
.text ntkrnlpa.exe!IofCompleteRequest 804EF236 5 Bytes JMP 8A86509B
.text ntkrnlpa.exe!ZwYieldExecution 80504AE8 7 Bytes JMP ACD8A9D8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 80579084 5 Bytes JMP ACD8A9AE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805B2006 7 Bytes JMP ACD8A9EE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B2E14 5 Bytes JMP ACD8AA04 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805B6812 5 Bytes JMP 8A80BCC4
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805B83E6 7 Bytes JMP ACD8A9C2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805CB408 5 Bytes JMP ACD8A934 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805CB694 5 Bytes JMP ACD8A948 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 805CDE52 5 Bytes JMP ACD8A986 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1142 7 Bytes JMP ACD8A970 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805D11F8 5 Bytes JMP ACD8A95C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 805D1702 5 Bytes JMP ACD8A99A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D29AA 5 Bytes JMP ACD8AA1D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryValueKey 806219E8 7 Bytes JMP ACD8AAB1 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetValueKey 80621D36 7 Bytes JMP ACD8AA9B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnloadKey 80622060 7 Bytes JMP ACD8AB0C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryMultipleValueKey 806228FE 7 Bytes JMP ACD8AAC7 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 806231D2 7 Bytes JMP ACD8AA6F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateKey 806237B0 5 Bytes JMP ACD8AA45 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 80623C40 7 Bytes JMP ACD8AA59 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 80623E10 7 Bytes JMP ACD8AA85 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateKey 80623FF0 5 Bytes JMP ACD8AAF8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateValueKey 8062425A 2 Bytes JMP ACD8AADD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateValueKey + 3 8062425D 4 Bytes [76, 2C, 90, 90] {JBE 0x2e; NOP ; NOP }
PAGE ntkrnlpa.exe!ZwOpenKey 80624B82 5 Bytes JMP ACD8AA31 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryKey 80624EA8 7 Bytes JMP ACD8AB5E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRestoreKey 80625168 5 Bytes JMP ACD8AB36 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplaceKey 8062585C 5 Bytes JMP ACD8AB4A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 80625976 5 Bytes JMP ACD8AB22 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\system32\msiexec.exe[356] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0066000A
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[360] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 008B000A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[444] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0085000A
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[588] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0085000A
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[588] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C340 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[588] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0041C3C0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[672] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0072000A
.text C:\windows\system32\nvsvc32.exe[836] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 006C000A
.text C:\WINDOWS\system32\winlogon.exe[908] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0068000A
.text C:\windows\system32\services.exe[956] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0065000A
.text C:\windows\system32\services.exe[956] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01290FEF
.text C:\windows\system32\services.exe[956] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01290067
.text C:\windows\system32\services.exe[956] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01290F72
.text C:\windows\system32\services.exe[956] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01290056
.text C:\windows\system32\services.exe[956] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01290F8D
.text C:\windows\system32\services.exe[956] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01290FB9
.text C:\windows\system32\services.exe[956] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01290084
.text C:\windows\system32\services.exe[956] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01290F3C
.text C:\windows\system32\services.exe[956] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01290F2B
.text C:\windows\system32\services.exe[956] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 012900C4
.text C:\windows\system32\services.exe[956] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01290F1A
.text C:\windows\system32\services.exe[956] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01290FA8
.text C:\windows\system32\services.exe[956] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0129000A
.text C:\windows\system32\services.exe[956] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01290F57
.text C:\windows\system32\services.exe[956] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01290FCA
.text C:\windows\system32\services.exe[956] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01290025
.text C:\windows\system32\services.exe[956] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 0129009F
.text C:\windows\system32\services.exe[956] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01280FD1
.text C:\windows\system32\services.exe[956] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 0128007A
.text C:\windows\system32\services.exe[956] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01280022
.text C:\windows\system32\services.exe[956] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01280011
.text C:\windows\system32\services.exe[956] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0128005F
.text C:\windows\system32\services.exe[956] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01280000
.text C:\windows\system32\services.exe[956] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0128004E
.text C:\windows\system32\services.exe[956] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0128003D
.text C:\windows\system32\services.exe[956] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01270FA8
.text C:\windows\system32\services.exe[956] msvcrt.dll!system 77C293C7 5 Bytes JMP 01270029
.text C:\windows\system32\services.exe[956] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01270FCD
.text C:\windows\system32\services.exe[956] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01270FEF
.text C:\windows\system32\services.exe[956] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01270018
.text C:\windows\system32\services.exe[956] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01270FDE
.text C:\windows\system32\services.exe[956] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00FF0FEF
.text C:\windows\system32\services.exe[956] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00FF0FDE
.text C:\windows\system32\services.exe[956] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00FF0FC3
.text C:\windows\system32\services.exe[956] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00FF000A
.text C:\windows\system32\services.exe[956] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01260FE5
.text C:\windows\system32\lsass.exe[968] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 011F000A
.text C:\windows\system32\lsass.exe[968] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 011F0F83
.text C:\windows\system32\lsass.exe[968] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 011F0078
.text C:\windows\system32\lsass.exe[968] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 011F005B
.text C:\windows\system32\lsass.exe[968] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 011F004A
.text C:\windows\system32\lsass.exe[968] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 011F0FC3
.text C:\windows\system32\lsass.exe[968] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 011F0F4B
.text C:\windows\system32\lsass.exe[968] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 011F0093
.text C:\windows\system32\lsass.exe[968] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 011F00C2
.text C:\windows\system32\lsass.exe[968] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 011F0F29
.text C:\windows\system32\lsass.exe[968] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 011F0F18
.text C:\windows\system32\lsass.exe[968] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 011F0FA8
.text C:\windows\system32\lsass.exe[968] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 011F0FEF
.text C:\windows\system32\lsass.exe[968] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 011F0F72
.text C:\windows\system32\lsass.exe[968] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 011F0025
.text C:\windows\system32\lsass.exe[968] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 011F0FD4
.text C:\windows\system32\lsass.exe[968] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 011F0F3A
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 011E0FCA
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 011E0047
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 011E0FE5
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 011E001B
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 011E0F94
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 011E0000
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 011E0FA5
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [3E, 89]
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 011E002C
.text C:\windows\system32\lsass.exe[968] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 011D0FD7
.text C:\windows\system32\lsass.exe[968] msvcrt.dll!system 77C293C7 5 Bytes JMP 011D0058
.text C:\windows\system32\lsass.exe[968] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 011D002C
.text C:\windows\system32\lsass.exe[968] msvcrt.dll!_open 77C2F566 5 Bytes JMP 011D0000
.text C:\windows\system32\lsass.exe[968] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 011D003D
.text C:\windows\system32\lsass.exe[968] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 011D0011
.text C:\windows\system32\lsass.exe[968] WS2_32.dll!socket 71AB4211 5 Bytes JMP 011C0FEF
.text C:\windows\system32\lsass.exe[968] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00D30000
.text C:\windows\system32\lsass.exe[968] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00D30011
.text C:\windows\system32\lsass.exe[968] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00D3002C
.text C:\windows\system32\lsass.exe[968] WININET.dll!InternetOpenUrlW 3D9A6DD7 1 Byte [E9]
.text C:\windows\system32\lsass.exe[968] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00D30FDB
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F00000
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F00F91
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F00086
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F0005F
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F0004E
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F00022
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F00F52
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F00F63
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F00F41
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F000D0
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F00F26
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F0003D
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F00011
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F00F80
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F00FC0
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F00FDB
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F000BF
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00EF0FCA
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00EF0051
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00EF001B
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00EF0000
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00EF0040
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00EF0FEF
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00EF0F9E
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [0F, 89]
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00EF0FAF
.text C:\windows\system32\svchost.exe[1148] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00EE0FA6
.text C:\windows\system32\svchost.exe[1148] msvcrt.dll!system 77C293C7 5 Bytes JMP 00EE0FC1
.text C:\windows\system32\svchost.exe[1148] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00EE0FE3
.text C:\windows\system32\svchost.exe[1148] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00EE0000
.text C:\windows\system32\svchost.exe[1148] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00EE0FD2
.text C:\windows\system32\svchost.exe[1148] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00EE001D
.text C:\windows\system32\svchost.exe[1148] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00EC0FE5
.text C:\windows\system32\svchost.exe[1148] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00EC0FD4
.text C:\windows\system32\svchost.exe[1148] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00EC0000
.text C:\windows\system32\svchost.exe[1148] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00EC0011
.text C:\windows\system32\svchost.exe[1148] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00ED000A
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FF0000
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FF0089
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FF0F9E
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FF0078
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FF0FAF
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FF003D
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FF00C1
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FF0F79
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FF0F57
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FF0F68
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FF0F46
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FF0FC0
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FF0FE5
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FF009A
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FF002C
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FF001B
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FF00E6
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00FE0FD1
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00FE0FAF
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00FE002C
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00FE0011
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00FE0062
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00FE0000
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00FE0FC0
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [1E, 89]
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00FE0047
.text C:\windows\system32\svchost.exe[1216] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00FD0F9C
.text C:\windows\system32\svchost.exe[1216] msvcrt.dll!system 77C293C7 5 Bytes JMP 00FD0FAD
.text C:\windows\system32\svchost.exe[1216] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00FD0FC8
.text C:\windows\system32\svchost.exe[1216] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00FD0000
.text C:\windows\system32\svchost.exe[1216] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00FD001D
.text C:\windows\system32\svchost.exe[1216] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00FD0FEF
.text C:\windows\system32\svchost.exe[1216] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00FB0000
.text C:\windows\system32\svchost.exe[1216] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00FB0FE5
.text C:\windows\system32\svchost.exe[1216] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00FB001B
.text C:\windows\system32\svchost.exe[1216] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00FB002C
.text C:\windows\system32\svchost.exe[1216] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FC0000
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1344] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003E000A
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 05390000
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 05390082
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 05390067
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 05390F8D
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0539004A
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 05390025
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 05390F44
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 05390F61
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 053900D3
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 053900B8
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 053900EE
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 05390FA8
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 05390FEF
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 05390F72
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 05390FB9
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 05390FD4
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 053900A7
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 05360039
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 05360F8D
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0536001E
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 05360FDE
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0536004A
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 05360FEF
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 05360FB2
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [56, 8D]
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 05360FCD
.text C:\windows\System32\svchost.exe[1368] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 05350FBC
.text C:\windows\System32\svchost.exe[1368] msvcrt.dll!system 77C293C7 5 Bytes JMP 05350051
.text C:\windows\System32\svchost.exe[1368] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 05350022
.text C:\windows\System32\svchost.exe[1368] msvcrt.dll!_open 77C2F566 5 Bytes JMP 05350000
.text C:\windows\System32\svchost.exe[1368] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 05350FD7
.text C:\windows\System32\svchost.exe[1368] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 05350011
.text C:\windows\System32\svchost.exe[1368] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 05380000
.text C:\windows\System32\svchost.exe[1368] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 05380025
.text C:\windows\System32\svchost.exe[1368] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 05380040
.text C:\windows\System32\svchost.exe[1368] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 0538005B
.text C:\windows\System32\svchost.exe[1368] WS2_32.dll!socket 71AB4211 5 Bytes JMP 05340000
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FE0FEF
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FE0F95
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FE008A
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FE006F
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FE0FB2
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FE0039
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FE0F84
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FE00CC
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FE0F62
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FE0F73
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FE010C
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FE0054
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FE0FDE
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FE00AF
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FE0FCD
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FE001E
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FE00F1
.text C:\windows\system32\svchost.exe[1540] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00C30FAF
.text C:\windows\system32\svchost.exe[1540] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00C3005B
.text C:\windows\system32\svchost.exe[1540] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00C30FD4
.text C:\windows\system32\svchost.exe[1540] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00C30000
.text C:\windows\system32\svchost.exe[1540] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00C30F9E
.text C:\windows\system32\svchost.exe[1540] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00C30FE5
.text C:\windows\system32\svchost.exe[1540] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00C30036
.text C:\windows\system32\svchost.exe[1540] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00C3001B
.text C:\windows\system32\svchost.exe[1540] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00C2006E
.text C:\windows\system32\svchost.exe[1540] msvcrt.dll!system 77C293C7 5 Bytes JMP 00C2005D
.text C:\windows\system32\svchost.exe[1540] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00C2002E
.text C:\windows\system32\svchost.exe[1540] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00C20000
.text C:\windows\system32\svchost.exe[1540] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00C20FE3
.text C:\windows\system32\svchost.exe[1540] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00C20011
.text C:\windows\system32\svchost.exe[1540] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00660000
.text C:\windows\system32\svchost.exe[1540] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00660FE5
.text C:\windows\system32\svchost.exe[1540] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 0066001B
.text C:\windows\system32\svchost.exe[1540] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00660FCA
.text C:\windows\system32\svchost.exe[1540] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00C10000
.text C:\windows\system32\svchost.exe[1616] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0066000A
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D70000
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D70F54
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D70F6F
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D70F8A
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D70F9B
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D7003D
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D7006E
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D70F28
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D70EF0
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D70089
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00D70ED5
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00D70FB6
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00D70FE5
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!CreatePipe 7C81D83F 1 Byte [E9]
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00D70F43
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00D70022
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00D70011
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00D70F0B
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00D60022
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00D60F94
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00D60011
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00D60FE5
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00D60047
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00D60000
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00D60FA5
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [F6, 88]
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00D60FB6
.text C:\windows\system32\svchost.exe[1616] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D5004E
.text C:\windows\system32\svchost.exe[1616] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D50FCD
.text C:\windows\system32\svchost.exe[1616] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D50FDE
.text C:\windows\system32\svchost.exe[1616] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D50FEF
.text C:\windows\system32\svchost.exe[1616] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D5003D
.text C:\windows\system32\svchost.exe[1616] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D5000C
.text C:\windows\system32\svchost.exe[1616] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00D40FE5
.text C:\windows\system32\svchost.exe[1616] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00D40000
.text C:\windows\system32\svchost.exe[1616] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00D40011
.text C:\windows\system32\svchost.exe[1616] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00D40FC0
.text C:\windows\system32\svchost.exe[1864] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0066000A
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00A90FEF
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00A90076
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00A9005B
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00A90F8D
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00A90F9E
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00A90036
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00A90F49
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00A90091
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A900B6
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A90F27
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00A900C7
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00A90FAF
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00A90FD4
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00A90F66
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00A9001B
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00A9000A
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00A90F38
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00950025
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00950F8D
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00950FD4
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00950FE5
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00950040
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00950000
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00950FA8
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [B5, 88] {MOV CH, 0x88}
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00950FB9
.text C:\windows\system32\svchost.exe[1864] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00940042
.text C:\windows\system32\svchost.exe[1864] msvcrt.dll!system 77C293C7 5 Bytes JMP 00940FB7
.text C:\windows\system32\svchost.exe[1864] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00940FD2
.text C:\windows\system32\svchost.exe[1864] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00940FEF
.text C:\windows\system32\svchost.exe[1864] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00940027
.text C:\windows\system32\svchost.exe[1864] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0094000C
.text C:\windows\system32\svchost.exe[1864] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00920FE5
.text C:\windows\system32\svchost.exe[1864] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00920000
.text C:\windows\system32\svchost.exe[1864] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00920025
.text C:\windows\system32\svchost.exe[1864] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00920040
.text C:\windows\system32\svchost.exe[1864] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00930000
.text C:\Program Files\McAfee\SiteAdvisor\McSACore.exe[1964] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00AF000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2800] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003C000A
.text c:\PROGRA~1\mcafee.com\agent\mcagent.exe[3024] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00D2000A
.text C:\windows\Explorer.EXE[3292] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00BC000A
.text C:\windows\Explorer.EXE[3292] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001B0FEF
.text C:\windows\Explorer.EXE[3292] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001B0F66
.text C:\windows\Explorer.EXE[3292] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001B0F77
.text C:\windows\Explorer.EXE[3292] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001B0051
.text C:\windows\Explorer.EXE[3292] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001B0F9E
.text C:\windows\Explorer.EXE[3292] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001B0040
.text C:\windows\Explorer.EXE[3292] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001B00A2
.text C:\windows\Explorer.EXE[3292] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001B0091
.text C:\windows\Explorer.EXE[3292] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001B0F09
.text C:\windows\Explorer.EXE[3292] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001B0F1A
.text C:\windows\Explorer.EXE[3292] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 001B00C7
.text C:\windows\Explorer.EXE[3292] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 001B0FB9
.text C:\windows\Explorer.EXE[3292] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 001B0FDE
.text C:\windows\Explorer.EXE[3292] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 001B0080
.text C:\windows\Explorer.EXE[3292] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 001B002F
.text C:\windows\Explorer.EXE[3292] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 001B001E
.text C:\windows\Explorer.EXE[3292] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 001B0F35
.text C:\windows\Explorer.EXE[3292] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 002A0025
.text C:\windows\Explorer.EXE[3292] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 002A007D
.text C:\windows\Explorer.EXE[3292] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 002A0FDE
.text C:\windows\Explorer.EXE[3292] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 002A0FEF
.text C:\windows\Explorer.EXE[3292] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 002A006C
.text C:\windows\Explorer.EXE[3292] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 002A000A
.text C:\windows\Explorer.EXE[3292] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 002A0047
.text C:\windows\Explorer.EXE[3292] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 002A0036
.text C:\windows\Explorer.EXE[3292] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 002B003A
.text C:\windows\Explorer.EXE[3292] msvcrt.dll!system 77C293C7 5 Bytes JMP 002B0FAF
.text C:\windows\Explorer.EXE[3292] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 002B0FDE
.text C:\windows\Explorer.EXE[3292] msvcrt.dll!_open 77C2F566 5 Bytes JMP 002B0FEF
.text C:\windows\Explorer.EXE[3292] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 002B0029
.text C:\windows\Explorer.EXE[3292] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 002B0018
.text C:\windows\Explorer.EXE[3292] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 002D000A
.text C:\windows\Explorer.EXE[3292] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 002D0FEF
.text C:\windows\Explorer.EXE[3292] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 002D0FD4
.text C:\windows\Explorer.EXE[3292] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 002D0FB9
.text C:\windows\Explorer.EXE[3292] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01B60000
.text C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe[3548] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003E000A
.text C:\windows\system32\RUNDLL32.EXE[3632] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 009D000A
.text C:\windows\RTHDCPL.EXE[3640] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003E000A
.text C:\windows\system32\ctfmon.exe[3764] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00C0000A
.text C:\PROGRA~1\Yahoo!\browser\ycommon.exe[3812] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0096000A
.text …
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
—- Services - GMER 1.0.15 —-
Service C:\windows\system32\drivers\SKYNETsthkyveu.sys (*** hidden *** ) [SYSTEM] SKYNETovyxjlno <– ROOTKIT !!!
Service system32\drivers\TDSSmxjt.sys (*** hidden *** ) [SYSTEM] TDSSserv <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv@imagepath \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@TDSSserv \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@TDSSl \systemroot\system32\TDSSoitt.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@tdssservers \systemroot\system32\TDSSmtve.dat
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@tdssmain \systemroot\system32\TDSSarxx.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@tdsslog \systemroot\system32\TDSSvoql.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@tdssadw \systemroot\system32\TDSSnvuo.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@tdssinit \systemroot\system32\TDSSdxcp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@tdsspanels \systemroot\system32\TDSSsahc.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@tdssserf \systemroot\system32\TDSSxhyf.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv@start 1
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv@type 1
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv@imagepath \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@TDSSserv \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@TDSSl \systemroot\system32\TDSSoitt.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@tdssservers \systemroot\system32\TDSSmtve.dat
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@tdssmain \systemroot\system32\TDSSarxx.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@tdsslog \systemroot\system32\TDSSvoql.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@tdssadw \systemroot\system32\TDSSnvuo.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@tdssinit \systemroot\system32\TDSSdxcp.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@tdsspanels \systemroot\system32\TDSSsahc.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@tdssserf \systemroot\system32\TDSSxhyf.dll
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv@start 1
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv@type 1
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv@imagepath \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@TDSSserv \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@TDSSl \systemroot\system32\TDSSoitt.dll
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@tdssservers \systemroot\system32\TDSSmtve.dat
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@tdssmain \systemroot\system32\TDSSarxx.dll
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@tdsslog \systemroot\system32\TDSSvoql.dll
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@tdssadw \systemroot\system32\TDSSnvuo.dll
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@tdssinit \systemroot\system32\TDSSdxcp.dll
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@tdsspanels \systemroot\system32\TDSSsahc.dll
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@tdssserf \systemroot\system32\TDSSxhyf.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno@imagepath \systemroot\system32\drivers\SKYNETsthkyveu.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\main@aid 10096
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\main@cmddelay 7200
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\[removed] \systemroot\system32\drivers\SKYNETsthkyveu.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\[removed] \systemroot\system32\SKYNETwmencbvm.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\[removed] \systemroot\system32\SKYNETehqobyqx.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\[removed] \systemroot\system32\SKYNETtivkpsru.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\[removed] \systemroot\system32\SKYNETwpiewxnm.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv@imagepath \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@TDSSserv \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@TDSSl \systemroot\system32\TDSSoitt.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@tdssservers \systemroot\system32\TDSSmtve.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@tdssmain \systemroot\system32\TDSSarxx.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@tdsslog \systemroot\system32\TDSSvoql.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@tdssadw \systemroot\system32\TDSSnvuo.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@tdssinit \systemroot\system32\TDSSdxcp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@tdsspanels \systemroot\system32\TDSSsahc.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@tdssserf \systemroot\system32\TDSSxhyf.dll
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno@start 1
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno@type 1
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno@group file system
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno@imagepath \systemroot\system32\drivers\SKYNETsthkyveu.sys
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\main
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\main@aid 10096
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\main@sid 0
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\main@cmddelay 7200
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\main\delete
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\main\injector
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\main\tasks
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\modules
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\[removed] \systemroot\system32\drivers\SKYNETsthkyveu.sys
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\[removed] \systemroot\system32\SKYNETwmencbvm.dll
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\[removed] \systemroot\system32\SKYNETehqobyqx.dat
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\[removed] \systemroot\system32\SKYNETtivkpsru.dll
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\[removed] \systemroot\system32\SKYNETwpiewxnm.dat
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv@start 1
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv@type 1
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv@imagepath \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@TDSSserv \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@TDSSl \systemroot\system32\TDSSoitt.dll
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@tdssservers \systemroot\system32\TDSSmtve.dat
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@tdssmain \systemroot\system32\TDSSarxx.dll
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@tdsslog \systemroot\system32\TDSSvoql.dll
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@tdssadw \systemroot\system32\TDSSnvuo.dll
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@tdssinit \systemroot\system32\TDSSdxcp.dll
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@tdsspanels \systemroot\system32\TDSSsahc.dll
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@tdssserf \systemroot\system32\TDSSxhyf.dll
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\system32\drivers\SKYNETsthkyveu.sys 69632 bytes executable <– ROOTKIT !!!
File C:\WINDOWS\system32\SKYNETehqobyqx.dat 42489 bytes
File C:\WINDOWS\system32\SKYNETtivkpsru.dll 20992 bytes executable
File C:\WINDOWS\system32\SKYNETwmencbvm.dll 44544 bytes executable
File C:\WINDOWS\Temp\SKYNETbopiuvcxbd.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETbqxpvqvvit.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETncwkbdeiyc.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETnwbbmciqsg.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETvirpfktusp.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETvxrtcegqxd.tmp 20992 bytes executable
—- EOF - GMER 1.0.15 —-
that last one took forever!!