This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Windows slow, crashes, locks up

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My PC was built by Alienware and its only a yr old. It is running slow, IE crashes, and locks up. I have defraged, ran Mcafee virus, along with Spybot Search and Destroy. Every once in a while, when going to a website, i get redirected, but not always. My system reboots sometimes on its own, but b4 it does, it shows the blue screen of death, but it doesnt stay there long enough to see what it says. Here is my HJT file.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:57:47 AM, on 6/18/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\windows\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\windows\system32\PnkBstrB.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\windows\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\windows\Explorer.EXE
C:\Program Files\2Wire\Gateway\2PortalMon.exe
C:\windows\system32\RUNDLL32.EXE
C:\windows\RTHDCPL.EXE
C:\windows\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {348FE907-249E-4C65-A838-F34A193FE1D1} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\Gateway\2PortalMon.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [19364214] C:\Documents and Settings\All Users\Application Data\19364214\19364214.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\dlm.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103472 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; YComp 5.0.0.0; GTB6; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET CLR 1.1.4322)" -"http://www.miniclip.com/games/rich-racer/en/"
O4 - Global Startup: OSCust.lnk = C:\WINDOWS\system32\oem\OSCust.exe
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.alienware.com
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.32.17/ttinst.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: karna.dat
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\windows\system32\PnkBstrB.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 11223 bytes
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous.
  • Most infections require more than one round to properly eradicate.
  • Absence of symptoms does not always mean the job is complete.
  • You can be certain that I will advise you when the computer is clean.
  • Kindly follow my instructions in the order posted.
  • Please resist the urge to run further scans or fix items on your own without my direction.



Please do the following:

STEP #1

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



STEP #2


Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.
here are the logs you requested.

DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 7:20:11.71 on Fri 06/19/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1493 [GMT -7:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\windows\system32\svchost -k DcomLaunch
svchost.exe
C:\windows\System32\svchost.exe -k netsvcs
svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\Explorer.EXE
C:\Program Files\2Wire\Gateway\2PortalMon.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\windows\system32\RUNDLL32.EXE
C:\windows\RTHDCPL.EXE
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\windows\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\windows\system32\PnkBstrB.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Documents and Settings\Mike\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchAssistant = hxxp://www.google.com
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearchAssistant = hxxp://www.google.com
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {348FE907-249E-4C65-A838-F34A193FE1D1} - No File
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SidebarAutoLaunch Class: {f2aa9440-6328-4933-b7c9-a6ccdf9cbf6d} - c:\program files\yahoo!\browser\YSidebarIEBHO.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\program files\yahoo!\messenger\yhexbmes.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
uRun: [igndlm.exe] c:\program files\download manager\dlm.exe /windowsstart /startifwork
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~2.EXE -Update -1103472 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; YComp 5.0.0.0; GTB6; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET CLR 1.1.4322)" -"http://www.miniclip.com/games/rich-racer/en/"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [2wSysTray] c:\program files\2wire\gateway\2PortalMon.exe
mRun: [YBrowser] c:\progra~1\yahoo!\browser\ybrwicon.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [mcagent_exe] c:\program files\mcafee.com\agent\mcagent.exe /runkey
mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\oscust.lnk - c:\windows\system32\oem\OSCust.exe
IE: Add to Windows &Live Favorites
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: roseonlinegame.com\www
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper20073151.dll
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} - hxxp://download.yahoo.com/dl/installs/ymail/ymmapi.dll
DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} - hxxp://a.download.toontown.com/sv1.0.32.17/ttinst.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: WB - c:\program files\alienguise\fastload.dll
AppInit_DLLs: karna.dat
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-4-24 201320]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-4-24 203280]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-4-24 359248]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-4-24 144704]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-4-24 695624]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-4-24 79304]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-4-24 35240]
R3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-4-24 33832]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-4-24 40488]
S3 XDva195;XDva195;\??\c:\windows\system32\xdva195.sys –> c:\windows\system32\XDva195.sys [?]

=============== Created Last 30 ================

2009-06-12 08:43 –d—– c:\docume~1\alluse~1\applic~1\PMB Files
2009-06-12 08:43 –d—– c:\program files\Pando Networks
2009-05-26 19:24 –d—– c:\program files\Sony Online Entertainment
2009-05-23 08:18 –d—– c:\docume~1\alluse~1\applic~1\99374206
2009-05-23 08:18 –d—– c:\docume~1\alluse~1\applic~1\19364214

==================== Find3M ====================


============= FINISH: 7:22:29.62 ===============


Here is the attach.txt

DDS (Ver_09-05-14.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 2/28/2008 1:34:35 PM
System Uptime: 6/19/2009 7:03:57 AM (0 hours ago)

Motherboard: alienware | | alienware
Processor: AMD Athlon™ 64 X2 Dual Core Processor 5200+ | Socket M2 | 2611/201mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 233 GiB total, 109.756 GiB free.
D: is CDROM (UDF)

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP394: 6/13/2009 6:01:11 PM - System Checkpoint
RP395: 6/13/2009 6:01:11 PM - System Checkpoint
RP396: 6/13/2009 6:01:11 PM - System Checkpoint
RP397: 6/13/2009 6:01:11 PM - System Checkpoint
RP398: 6/13/2009 6:01:11 PM - System Checkpoint
RP399: 6/13/2009 6:01:11 PM - System Checkpoint
RP400: 6/13/2009 6:01:11 PM - System Checkpoint
RP401: 6/13/2009 6:01:11 PM - System Checkpoint
RP402: 6/13/2009 6:01:11 PM - Software Distribution Service 3.0
RP403: 6/13/2009 6:01:11 PM - System Checkpoint
RP404: 6/13/2009 6:01:11 PM - System Checkpoint
RP405: 6/13/2009 6:01:12 PM - Installed Call of Duty® - World at War™ 1.4 Patch
RP406: 6/13/2009 6:01:12 PM - Performance
RP407: 6/13/2009 6:01:12 PM - Removed Call of Duty® - World at War™ 1.4 Patch
RP408: 6/13/2009 6:01:12 PM - Installed DirectX
RP409: 6/13/2009 6:01:12 PM - System Checkpoint
RP410: 6/13/2009 6:01:12 PM - System Checkpoint
RP411: 6/13/2009 6:01:12 PM - System Checkpoint
RP412: 6/13/2009 6:01:12 PM - System Checkpoint
RP413: 6/13/2009 6:01:12 PM - System Checkpoint
RP414: 6/13/2009 6:01:13 PM - System Checkpoint
RP415: 6/13/2009 6:01:13 PM - Software Distribution Service 3.0
RP416: 6/13/2009 6:01:13 PM - System Checkpoint
RP417: 6/13/2009 6:01:13 PM - System Checkpoint
RP418: 6/13/2009 6:01:13 PM - System Checkpoint
RP419: 6/13/2009 6:01:13 PM - System Checkpoint
RP420: 6/13/2009 6:01:13 PM - System Checkpoint
RP421: 6/13/2009 6:01:13 PM - System Checkpoint
RP422: 6/13/2009 6:01:13 PM - System Checkpoint
RP423: 6/13/2009 6:01:13 PM - System Checkpoint
RP424: 6/13/2009 6:01:14 PM - System Checkpoint
RP425: 6/13/2009 6:01:14 PM - System Checkpoint
RP426: 6/13/2009 6:01:14 PM - Software Distribution Service 3.0
RP427: 6/13/2009 6:01:14 PM - Restore Operation
RP428: 6/13/2009 6:01:14 PM - System Checkpoint
RP429: 6/13/2009 6:01:14 PM - Software Distribution Service 3.0
RP430: 6/13/2009 6:01:14 PM - System Checkpoint
RP431: 6/13/2009 6:01:14 PM - System Checkpoint
RP432: 6/13/2009 6:01:15 PM - System Checkpoint
RP433: 6/13/2009 6:01:15 PM - System Checkpoint
RP434: 6/13/2009 6:01:15 PM - System Checkpoint
RP435: 6/13/2009 6:01:15 PM - System Checkpoint
RP436: 6/13/2009 6:01:15 PM - System Checkpoint
RP437: 6/13/2009 6:01:15 PM - System Checkpoint
RP438: 6/13/2009 6:01:15 PM - System Checkpoint
RP439: 6/13/2009 6:01:15 PM - System Checkpoint
RP440: 6/13/2009 6:01:16 PM - System Checkpoint
RP441: 6/13/2009 6:01:16 PM - System Checkpoint
RP442: 6/13/2009 6:01:16 PM - System Checkpoint
RP443: 6/13/2009 6:01:16 PM - System Checkpoint
RP444: 6/13/2009 6:01:17 PM - System Checkpoint
RP445: 6/13/2009 6:01:17 PM - System Checkpoint
RP446: 6/13/2009 6:01:17 PM - Removed Battlefield 2142 Deluxe Edition
RP447: 6/13/2009 6:01:18 PM - Removed BattleForge™
RP448: 6/13/2009 6:01:18 PM - Removed LiveUpdate Notice (Symantec Corporation)
RP449: 6/13/2009 6:01:18 PM - Software Distribution Service 3.0
RP450: 6/13/2009 6:01:18 PM - Software Distribution Service 3.0
RP451: 6/13/2009 6:01:18 PM - System Checkpoint
RP452: 6/13/2009 6:01:19 PM - Removed MapleStory.
RP453: 6/13/2009 6:01:19 PM - Installed MapleStory.

==== Installed Programs ======================


==== Event Viewer Messages From Past Week ========


==== End Of File ===========================


Here is Gmer

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-19 19:33:14
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xACD8A9AA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xACD8AA41]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xACD8A958]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xACD8A96C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xACD8AA55]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xACD8AA81]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xACD8AAF4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xACD8AAD9]
Code 8A80BCC0 ZwFlushInstructionCache
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xACD8A9EA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xACD8AB1E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xACD8AA2D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xACD8A930]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xACD8A944]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xACD8A9BE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xACD8AB5A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xACD8AAC3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xACD8AAAD]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xACD8AA6B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xACD8AB46]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xACD8AB32]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xACD8A996]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xACD8A982]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xACD8AA97]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xACD8AA19]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xACD8AB08]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xACD8AA00]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xACD8A9D4]
Code 89FB6096 IofCallDriver
Code 8A865096 IofCompleteRequest
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!IofCallDriver 804EF1A6 5 Bytes JMP 89FB609B
.text ntkrnlpa.exe!IofCompleteRequest 804EF236 5 Bytes JMP 8A86509B
.text ntkrnlpa.exe!ZwYieldExecution 80504AE8 7 Bytes JMP ACD8A9D8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 80579084 5 Bytes JMP ACD8A9AE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805B2006 7 Bytes JMP ACD8A9EE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B2E14 5 Bytes JMP ACD8AA04 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805B6812 5 Bytes JMP 8A80BCC4
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805B83E6 7 Bytes JMP ACD8A9C2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805CB408 5 Bytes JMP ACD8A934 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805CB694 5 Bytes JMP ACD8A948 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 805CDE52 5 Bytes JMP ACD8A986 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1142 7 Bytes JMP ACD8A970 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805D11F8 5 Bytes JMP ACD8A95C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 805D1702 5 Bytes JMP ACD8A99A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D29AA 5 Bytes JMP ACD8AA1D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryValueKey 806219E8 7 Bytes JMP ACD8AAB1 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetValueKey 80621D36 7 Bytes JMP ACD8AA9B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnloadKey 80622060 7 Bytes JMP ACD8AB0C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryMultipleValueKey 806228FE 7 Bytes JMP ACD8AAC7 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 806231D2 7 Bytes JMP ACD8AA6F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateKey 806237B0 5 Bytes JMP ACD8AA45 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 80623C40 7 Bytes JMP ACD8AA59 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 80623E10 7 Bytes JMP ACD8AA85 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateKey 80623FF0 5 Bytes JMP ACD8AAF8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateValueKey 8062425A 2 Bytes JMP ACD8AADD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateValueKey + 3 8062425D 4 Bytes [76, 2C, 90, 90] {JBE 0x2e; NOP ; NOP }
PAGE ntkrnlpa.exe!ZwOpenKey 80624B82 5 Bytes JMP ACD8AA31 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryKey 80624EA8 7 Bytes JMP ACD8AB5E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRestoreKey 80625168 5 Bytes JMP ACD8AB36 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplaceKey 8062585C 5 Bytes JMP ACD8AB4A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 80625976 5 Bytes JMP ACD8AB22 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\msiexec.exe[356] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0066000A
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[360] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 008B000A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[444] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0085000A
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[588] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0085000A
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[588] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C340 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[588] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0041C3C0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[672] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0072000A
.text C:\windows\system32\nvsvc32.exe[836] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 006C000A
.text C:\WINDOWS\system32\winlogon.exe[908] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0068000A
.text C:\windows\system32\services.exe[956] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0065000A
.text C:\windows\system32\services.exe[956] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01290FEF
.text C:\windows\system32\services.exe[956] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01290067
.text C:\windows\system32\services.exe[956] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01290F72
.text C:\windows\system32\services.exe[956] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01290056
.text C:\windows\system32\services.exe[956] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01290F8D
.text C:\windows\system32\services.exe[956] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01290FB9
.text C:\windows\system32\services.exe[956] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01290084
.text C:\windows\system32\services.exe[956] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01290F3C
.text C:\windows\system32\services.exe[956] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01290F2B
.text C:\windows\system32\services.exe[956] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 012900C4
.text C:\windows\system32\services.exe[956] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01290F1A
.text C:\windows\system32\services.exe[956] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01290FA8
.text C:\windows\system32\services.exe[956] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0129000A
.text C:\windows\system32\services.exe[956] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01290F57
.text C:\windows\system32\services.exe[956] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01290FCA
.text C:\windows\system32\services.exe[956] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01290025
.text C:\windows\system32\services.exe[956] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 0129009F
.text C:\windows\system32\services.exe[956] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01280FD1
.text C:\windows\system32\services.exe[956] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 0128007A
.text C:\windows\system32\services.exe[956] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01280022
.text C:\windows\system32\services.exe[956] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01280011
.text C:\windows\system32\services.exe[956] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0128005F
.text C:\windows\system32\services.exe[956] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01280000
.text C:\windows\system32\services.exe[956] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0128004E
.text C:\windows\system32\services.exe[956] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0128003D
.text C:\windows\system32\services.exe[956] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01270FA8
.text C:\windows\system32\services.exe[956] msvcrt.dll!system 77C293C7 5 Bytes JMP 01270029
.text C:\windows\system32\services.exe[956] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01270FCD
.text C:\windows\system32\services.exe[956] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01270FEF
.text C:\windows\system32\services.exe[956] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01270018
.text C:\windows\system32\services.exe[956] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01270FDE
.text C:\windows\system32\services.exe[956] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00FF0FEF
.text C:\windows\system32\services.exe[956] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00FF0FDE
.text C:\windows\system32\services.exe[956] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00FF0FC3
.text C:\windows\system32\services.exe[956] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00FF000A
.text C:\windows\system32\services.exe[956] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01260FE5
.text C:\windows\system32\lsass.exe[968] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 011F000A
.text C:\windows\system32\lsass.exe[968] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 011F0F83
.text C:\windows\system32\lsass.exe[968] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 011F0078
.text C:\windows\system32\lsass.exe[968] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 011F005B
.text C:\windows\system32\lsass.exe[968] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 011F004A
.text C:\windows\system32\lsass.exe[968] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 011F0FC3
.text C:\windows\system32\lsass.exe[968] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 011F0F4B
.text C:\windows\system32\lsass.exe[968] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 011F0093
.text C:\windows\system32\lsass.exe[968] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 011F00C2
.text C:\windows\system32\lsass.exe[968] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 011F0F29
.text C:\windows\system32\lsass.exe[968] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 011F0F18
.text C:\windows\system32\lsass.exe[968] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 011F0FA8
.text C:\windows\system32\lsass.exe[968] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 011F0FEF
.text C:\windows\system32\lsass.exe[968] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 011F0F72
.text C:\windows\system32\lsass.exe[968] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 011F0025
.text C:\windows\system32\lsass.exe[968] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 011F0FD4
.text C:\windows\system32\lsass.exe[968] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 011F0F3A
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 011E0FCA
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 011E0047
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 011E0FE5
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 011E001B
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 011E0F94
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 011E0000
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 011E0FA5
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [3E, 89]
.text C:\windows\system32\lsass.exe[968] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 011E002C
.text C:\windows\system32\lsass.exe[968] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 011D0FD7
.text C:\windows\system32\lsass.exe[968] msvcrt.dll!system 77C293C7 5 Bytes JMP 011D0058
.text C:\windows\system32\lsass.exe[968] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 011D002C
.text C:\windows\system32\lsass.exe[968] msvcrt.dll!_open 77C2F566 5 Bytes JMP 011D0000
.text C:\windows\system32\lsass.exe[968] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 011D003D
.text C:\windows\system32\lsass.exe[968] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 011D0011
.text C:\windows\system32\lsass.exe[968] WS2_32.dll!socket 71AB4211 5 Bytes JMP 011C0FEF
.text C:\windows\system32\lsass.exe[968] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00D30000
.text C:\windows\system32\lsass.exe[968] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00D30011
.text C:\windows\system32\lsass.exe[968] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00D3002C
.text C:\windows\system32\lsass.exe[968] WININET.dll!InternetOpenUrlW 3D9A6DD7 1 Byte [E9]
.text C:\windows\system32\lsass.exe[968] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00D30FDB
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F00000
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F00F91
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F00086
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F0005F
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F0004E
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F00022
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F00F52
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F00F63
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F00F41
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F000D0
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F00F26
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F0003D
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F00011
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F00F80
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F00FC0
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F00FDB
.text C:\windows\system32\svchost.exe[1148] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F000BF
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00EF0FCA
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00EF0051
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00EF001B
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00EF0000
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00EF0040
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00EF0FEF
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00EF0F9E
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [0F, 89]
.text C:\windows\system32\svchost.exe[1148] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00EF0FAF
.text C:\windows\system32\svchost.exe[1148] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00EE0FA6
.text C:\windows\system32\svchost.exe[1148] msvcrt.dll!system 77C293C7 5 Bytes JMP 00EE0FC1
.text C:\windows\system32\svchost.exe[1148] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00EE0FE3
.text C:\windows\system32\svchost.exe[1148] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00EE0000
.text C:\windows\system32\svchost.exe[1148] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00EE0FD2
.text C:\windows\system32\svchost.exe[1148] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00EE001D
.text C:\windows\system32\svchost.exe[1148] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00EC0FE5
.text C:\windows\system32\svchost.exe[1148] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00EC0FD4
.text C:\windows\system32\svchost.exe[1148] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00EC0000
.text C:\windows\system32\svchost.exe[1148] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00EC0011
.text C:\windows\system32\svchost.exe[1148] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00ED000A
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FF0000
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FF0089
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FF0F9E
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FF0078
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FF0FAF
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FF003D
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FF00C1
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FF0F79
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FF0F57
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FF0F68
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FF0F46
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FF0FC0
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FF0FE5
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FF009A
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FF002C
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FF001B
.text C:\windows\system32\svchost.exe[1216] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FF00E6
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00FE0FD1
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00FE0FAF
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00FE002C
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00FE0011
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00FE0062
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00FE0000
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00FE0FC0
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [1E, 89]
.text C:\windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00FE0047
.text C:\windows\system32\svchost.exe[1216] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00FD0F9C
.text C:\windows\system32\svchost.exe[1216] msvcrt.dll!system 77C293C7 5 Bytes JMP 00FD0FAD
.text C:\windows\system32\svchost.exe[1216] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00FD0FC8
.text C:\windows\system32\svchost.exe[1216] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00FD0000
.text C:\windows\system32\svchost.exe[1216] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00FD001D
.text C:\windows\system32\svchost.exe[1216] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00FD0FEF
.text C:\windows\system32\svchost.exe[1216] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00FB0000
.text C:\windows\system32\svchost.exe[1216] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00FB0FE5
.text C:\windows\system32\svchost.exe[1216] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00FB001B
.text C:\windows\system32\svchost.exe[1216] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00FB002C
.text C:\windows\system32\svchost.exe[1216] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FC0000
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1344] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003E000A
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 05390000
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 05390082
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 05390067
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 05390F8D
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0539004A
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 05390025
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 05390F44
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 05390F61
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 053900D3
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 053900B8
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 053900EE
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 05390FA8
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 05390FEF
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 05390F72
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 05390FB9
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 05390FD4
.text C:\windows\System32\svchost.exe[1368] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 053900A7
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 05360039
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 05360F8D
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0536001E
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 05360FDE
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0536004A
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 05360FEF
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 05360FB2
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [56, 8D]
.text C:\windows\System32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 05360FCD
.text C:\windows\System32\svchost.exe[1368] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 05350FBC
.text C:\windows\System32\svchost.exe[1368] msvcrt.dll!system 77C293C7 5 Bytes JMP 05350051
.text C:\windows\System32\svchost.exe[1368] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 05350022
.text C:\windows\System32\svchost.exe[1368] msvcrt.dll!_open 77C2F566 5 Bytes JMP 05350000
.text C:\windows\System32\svchost.exe[1368] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 05350FD7
.text C:\windows\System32\svchost.exe[1368] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 05350011
.text C:\windows\System32\svchost.exe[1368] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 05380000
.text C:\windows\System32\svchost.exe[1368] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 05380025
.text C:\windows\System32\svchost.exe[1368] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 05380040
.text C:\windows\System32\svchost.exe[1368] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 0538005B
.text C:\windows\System32\svchost.exe[1368] WS2_32.dll!socket 71AB4211 5 Bytes JMP 05340000
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FE0FEF
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FE0F95
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FE008A
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FE006F
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FE0FB2
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FE0039
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FE0F84
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FE00CC
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FE0F62
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FE0F73
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FE010C
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FE0054
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FE0FDE
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FE00AF
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FE0FCD
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FE001E
.text C:\windows\system32\svchost.exe[1540] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FE00F1
.text C:\windows\system32\svchost.exe[1540] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00C30FAF
.text C:\windows\system32\svchost.exe[1540] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00C3005B
.text C:\windows\system32\svchost.exe[1540] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00C30FD4
.text C:\windows\system32\svchost.exe[1540] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00C30000
.text C:\windows\system32\svchost.exe[1540] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00C30F9E
.text C:\windows\system32\svchost.exe[1540] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00C30FE5
.text C:\windows\system32\svchost.exe[1540] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00C30036
.text C:\windows\system32\svchost.exe[1540] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00C3001B
.text C:\windows\system32\svchost.exe[1540] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00C2006E
.text C:\windows\system32\svchost.exe[1540] msvcrt.dll!system 77C293C7 5 Bytes JMP 00C2005D
.text C:\windows\system32\svchost.exe[1540] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00C2002E
.text C:\windows\system32\svchost.exe[1540] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00C20000
.text C:\windows\system32\svchost.exe[1540] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00C20FE3
.text C:\windows\system32\svchost.exe[1540] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00C20011
.text C:\windows\system32\svchost.exe[1540] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00660000
.text C:\windows\system32\svchost.exe[1540] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00660FE5
.text C:\windows\system32\svchost.exe[1540] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 0066001B
.text C:\windows\system32\svchost.exe[1540] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00660FCA
.text C:\windows\system32\svchost.exe[1540] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00C10000
.text C:\windows\system32\svchost.exe[1616] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0066000A
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D70000
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D70F54
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D70F6F
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D70F8A
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D70F9B
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D7003D
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D7006E
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D70F28
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D70EF0
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D70089
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00D70ED5
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00D70FB6
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00D70FE5
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!CreatePipe 7C81D83F 1 Byte [E9]
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00D70F43
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00D70022
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00D70011
.text C:\windows\system32\svchost.exe[1616] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00D70F0B
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00D60022
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00D60F94
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00D60011
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00D60FE5
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00D60047
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00D60000
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00D60FA5
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [F6, 88]
.text C:\windows\system32\svchost.exe[1616] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00D60FB6
.text C:\windows\system32\svchost.exe[1616] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D5004E
.text C:\windows\system32\svchost.exe[1616] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D50FCD
.text C:\windows\system32\svchost.exe[1616] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D50FDE
.text C:\windows\system32\svchost.exe[1616] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D50FEF
.text C:\windows\system32\svchost.exe[1616] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D5003D
.text C:\windows\system32\svchost.exe[1616] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D5000C
.text C:\windows\system32\svchost.exe[1616] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00D40FE5
.text C:\windows\system32\svchost.exe[1616] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00D40000
.text C:\windows\system32\svchost.exe[1616] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00D40011
.text C:\windows\system32\svchost.exe[1616] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00D40FC0
.text C:\windows\system32\svchost.exe[1864] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0066000A
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00A90FEF
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00A90076
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00A9005B
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00A90F8D
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00A90F9E
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00A90036
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00A90F49
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00A90091
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A900B6
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A90F27
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00A900C7
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00A90FAF
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00A90FD4
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00A90F66
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00A9001B
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00A9000A
.text C:\windows\system32\svchost.exe[1864] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00A90F38
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00950025
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00950F8D
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00950FD4
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00950FE5
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00950040
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00950000
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00950FA8
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [B5, 88] {MOV CH, 0x88}
.text C:\windows\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00950FB9
.text C:\windows\system32\svchost.exe[1864] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00940042
.text C:\windows\system32\svchost.exe[1864] msvcrt.dll!system 77C293C7 5 Bytes JMP 00940FB7
.text C:\windows\system32\svchost.exe[1864] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00940FD2
.text C:\windows\system32\svchost.exe[1864] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00940FEF
.text C:\windows\system32\svchost.exe[1864] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00940027
.text C:\windows\system32\svchost.exe[1864] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0094000C
.text C:\windows\system32\svchost.exe[1864] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00920FE5
.text C:\windows\system32\svchost.exe[1864] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00920000
.text C:\windows\system32\svchost.exe[1864] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00920025
.text C:\windows\system32\svchost.exe[1864] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00920040
.text C:\windows\system32\svchost.exe[1864] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00930000
.text C:\Program Files\McAfee\SiteAdvisor\McSACore.exe[1964] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00AF000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2800] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003C000A
.text c:\PROGRA~1\mcafee.com\agent\mcagent.exe[3024] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00D2000A
.text C:\windows\Explorer.EXE[3292] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00BC000A
.text C:\windows\Explorer.EXE[3292] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001B0FEF
.text C:\windows\Explorer.EXE[3292] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001B0F66
.text C:\windows\Explorer.EXE[3292] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001B0F77
.text C:\windows\Explorer.EXE[3292] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001B0051
.text C:\windows\Explorer.EXE[3292] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001B0F9E
.text C:\windows\Explorer.EXE[3292] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001B0040
.text C:\windows\Explorer.EXE[3292] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001B00A2
.text C:\windows\Explorer.EXE[3292] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001B0091
.text C:\windows\Explorer.EXE[3292] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001B0F09
.text C:\windows\Explorer.EXE[3292] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001B0F1A
.text C:\windows\Explorer.EXE[3292] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 001B00C7
.text C:\windows\Explorer.EXE[3292] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 001B0FB9
.text C:\windows\Explorer.EXE[3292] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 001B0FDE
.text C:\windows\Explorer.EXE[3292] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 001B0080
.text C:\windows\Explorer.EXE[3292] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 001B002F
.text C:\windows\Explorer.EXE[3292] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 001B001E
.text C:\windows\Explorer.EXE[3292] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 001B0F35
.text C:\windows\Explorer.EXE[3292] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 002A0025
.text C:\windows\Explorer.EXE[3292] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 002A007D
.text C:\windows\Explorer.EXE[3292] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 002A0FDE
.text C:\windows\Explorer.EXE[3292] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 002A0FEF
.text C:\windows\Explorer.EXE[3292] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 002A006C
.text C:\windows\Explorer.EXE[3292] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 002A000A
.text C:\windows\Explorer.EXE[3292] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 002A0047
.text C:\windows\Explorer.EXE[3292] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 002A0036
.text C:\windows\Explorer.EXE[3292] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 002B003A
.text C:\windows\Explorer.EXE[3292] msvcrt.dll!system 77C293C7 5 Bytes JMP 002B0FAF
.text C:\windows\Explorer.EXE[3292] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 002B0FDE
.text C:\windows\Explorer.EXE[3292] msvcrt.dll!_open 77C2F566 5 Bytes JMP 002B0FEF
.text C:\windows\Explorer.EXE[3292] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 002B0029
.text C:\windows\Explorer.EXE[3292] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 002B0018
.text C:\windows\Explorer.EXE[3292] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 002D000A
.text C:\windows\Explorer.EXE[3292] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 002D0FEF
.text C:\windows\Explorer.EXE[3292] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 002D0FD4
.text C:\windows\Explorer.EXE[3292] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 002D0FB9
.text C:\windows\Explorer.EXE[3292] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01B60000
.text C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe[3548] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003E000A
.text C:\windows\system32\RUNDLL32.EXE[3632] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 009D000A
.text C:\windows\RTHDCPL.EXE[3640] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003E000A
.text C:\windows\system32\ctfmon.exe[3764] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00C0000A
.text C:\PROGRA~1\Yahoo!\browser\ycommon.exe[3812] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0096000A
.text …

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

—- Services - GMER 1.0.15 —-

Service C:\windows\system32\drivers\SKYNETsthkyveu.sys (*** hidden *** ) [SYSTEM] SKYNETovyxjlno <– ROOTKIT !!!
Service system32\drivers\TDSSmxjt.sys (*** hidden *** ) [SYSTEM] TDSSserv <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv@imagepath \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@TDSSserv \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@TDSSl \systemroot\system32\TDSSoitt.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@tdssservers \systemroot\system32\TDSSmtve.dat
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@tdssmain \systemroot\system32\TDSSarxx.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@tdsslog \systemroot\system32\TDSSvoql.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@tdssadw \systemroot\system32\TDSSnvuo.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@tdssinit \systemroot\system32\TDSSdxcp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@tdsspanels \systemroot\system32\TDSSsahc.dll
Reg HKLM\SYSTEM\ControlSet003\Services\TDSSserv\modules@tdssserf \systemroot\system32\TDSSxhyf.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv@start 1
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv@type 1
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv@imagepath \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@TDSSserv \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@TDSSl \systemroot\system32\TDSSoitt.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@tdssservers \systemroot\system32\TDSSmtve.dat
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@tdssmain \systemroot\system32\TDSSarxx.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@tdsslog \systemroot\system32\TDSSvoql.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@tdssadw \systemroot\system32\TDSSnvuo.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@tdssinit \systemroot\system32\TDSSdxcp.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@tdsspanels \systemroot\system32\TDSSsahc.dll
Reg HKLM\SYSTEM\ControlSet004\Services\TDSSserv\modules@tdssserf \systemroot\system32\TDSSxhyf.dll
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv@start 1
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv@type 1
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv@imagepath \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@TDSSserv \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@TDSSl \systemroot\system32\TDSSoitt.dll
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@tdssservers \systemroot\system32\TDSSmtve.dat
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@tdssmain \systemroot\system32\TDSSarxx.dll
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@tdsslog \systemroot\system32\TDSSvoql.dll
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@tdssadw \systemroot\system32\TDSSnvuo.dll
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@tdssinit \systemroot\system32\TDSSdxcp.dll
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@tdsspanels \systemroot\system32\TDSSsahc.dll
Reg HKLM\SYSTEM\ControlSet005\Services\TDSSserv\modules@tdssserf \systemroot\system32\TDSSxhyf.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno@imagepath \systemroot\system32\drivers\SKYNETsthkyveu.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\main@aid 10096
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\main@cmddelay 7200
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\[removed] \systemroot\system32\drivers\SKYNETsthkyveu.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\[removed] \systemroot\system32\SKYNETwmencbvm.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\[removed] \systemroot\system32\SKYNETehqobyqx.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\[removed] \systemroot\system32\SKYNETtivkpsru.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETovyxjlno\[removed] \systemroot\system32\SKYNETwpiewxnm.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv@imagepath \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@TDSSserv \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@TDSSl \systemroot\system32\TDSSoitt.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@tdssservers \systemroot\system32\TDSSmtve.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@tdssmain \systemroot\system32\TDSSarxx.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@tdsslog \systemroot\system32\TDSSvoql.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@tdssadw \systemroot\system32\TDSSnvuo.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@tdssinit \systemroot\system32\TDSSdxcp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@tdsspanels \systemroot\system32\TDSSsahc.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv\modules@tdssserf \systemroot\system32\TDSSxhyf.dll
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno@start 1
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno@type 1
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno@group file system
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno@imagepath \systemroot\system32\drivers\SKYNETsthkyveu.sys
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\main
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\main@aid 10096
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\main@sid 0
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\main@cmddelay 7200
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\main\delete
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\main\injector
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\main\tasks
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\modules
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\[removed] \systemroot\system32\drivers\SKYNETsthkyveu.sys
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\[removed] \systemroot\system32\SKYNETwmencbvm.dll
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\[removed] \systemroot\system32\SKYNETehqobyqx.dat
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\[removed] \systemroot\system32\SKYNETtivkpsru.dll
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETovyxjlno\[removed] \systemroot\system32\SKYNETwpiewxnm.dat
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv@start 1
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv@type 1
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv@imagepath \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@TDSSserv \systemroot\system32\drivers\TDSSmxjt.sys
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@TDSSl \systemroot\system32\TDSSoitt.dll
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@tdssservers \systemroot\system32\TDSSmtve.dat
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@tdssmain \systemroot\system32\TDSSarxx.dll
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@tdsslog \systemroot\system32\TDSSvoql.dll
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@tdssadw \systemroot\system32\TDSSnvuo.dll
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@tdssinit \systemroot\system32\TDSSdxcp.dll
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@tdsspanels \systemroot\system32\TDSSsahc.dll
Reg HKLM\SYSTEM\ControlSet007\Services\TDSSserv\modules@tdssserf \systemroot\system32\TDSSxhyf.dll

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\SKYNETsthkyveu.sys 69632 bytes executable <– ROOTKIT !!!
File C:\WINDOWS\system32\SKYNETehqobyqx.dat 42489 bytes
File C:\WINDOWS\system32\SKYNETtivkpsru.dll 20992 bytes executable
File C:\WINDOWS\system32\SKYNETwmencbvm.dll 44544 bytes executable
File C:\WINDOWS\Temp\SKYNETbopiuvcxbd.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETbqxpvqvvit.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETncwkbdeiyc.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETnwbbmciqsg.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETvirpfktusp.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETvxrtcegqxd.tmp 20992 bytes executable

—- EOF - GMER 1.0.15 —-

that last one took forever!!
Hi,

Please do the following:

Please download ComboFix from Here or Here to your Desktop.
**Note:  In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    [external image: Posted Image]

    [external image: Posted Image]
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.  
  • Please post the "C:\Combo-Fix.txt" for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
here is Combo-fix


ComboFix 09-06-19.01 - Mike 06/20/2009 7:04.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1705 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Mike\Local Settings\Temporary Internet Files\guvykose._dl
c:\documents and settings\Mike\Local Settings\Temporary Internet Files\ijjistarter_verinfo.dat
c:\windows\system32\_000111_.tmp.dll
c:\windows\system32\drivers\SKYNETsthkyveu.sys
c:\windows\system32\drivers\TDSSmxjt.sys
c:\windows\system32\SKYNETehqobyqx.dat
c:\windows\system32\SKYNETtivkpsru.dll
c:\windows\system32\SKYNETwmencbvm.dll
c:\windows\system32\TDSSarxx.dll
c:\windows\system32\TDSSdxcp.dll
c:\windows\system32\TDSSmtve.dat
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSnvuo.dll
c:\windows\system32\TDSSoitt.dll
c:\windows\system32\TDSSsahc.dll
c:\windows\system32\TDSSvoql.dll
c:\windows\system32\TDSSxhyf.dll
c:\windows\wiaservv.log

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SKYNETovyxjlno
——-\Service_TDSSSERV
——-\Legacy_TDSSSERV


((((((((((((((((((((((((( Files Created from 2009-05-20 to 2009-06-20 )))))))))))))))))))))))))))))))
.

2009-06-19 03:56 . 2009-06-19 03:57 3561743 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-12 15:43 . 2009-06-12 23:33 ——– d—–w- c:\documents and settings\Mike\Local Settings\Application Data\PMB Files
2009-06-12 15:43 . 2009-06-12 15:44 ——– d—–w- c:\documents and settings\All Users\Application Data\PMB Files
2009-06-12 15:43 . 2009-06-12 15:43 ——– d—–w- c:\program files\Pando Networks
2009-06-11 22:29 . 2009-06-11 22:29 41808 —-a-w- c:\windows\system32\xfcodec.dll
2009-06-10 15:56 . 2009-06-10 15:56 ——– d-sh–w- C:\found.000
2009-06-10 00:03 . 2006-03-22 18:21 10240 —-a-w- c:\windows\system32\bdco1ins.dll
2009-06-10 00:03 . 2006-03-15 00:45 35840 —-a-w- c:\windows\system32\nvconrm.dll
2009-06-10 00:02 . 2006-03-22 18:24 18944 —-a-w- c:\windows\system32\drivers\nvnetbus.sys
2009-06-10 00:02 . 2006-03-22 18:23 1068800 —-a-w- c:\windows\system32\drivers\nvnrm.sys
2009-06-10 00:02 . 2006-03-22 17:21 10240 —-a-w- c:\windows\system32\bdco1.dll
2009-06-09 18:15 . 2009-04-30 21:22 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-06-09 18:15 . 2009-04-30 21:22 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-08 03:33 . 2009-06-08 03:33 ——– d—–w- c:\documents and settings\Mike\Local Settings\Application Data\Yahoo
2009-06-07 20:22 . 2009-06-07 20:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-06-07 20:21 . 2009-05-27 02:50 607472 —-a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-05-27 02:29 . 2009-05-27 02:29 ——– d—–w- c:\documents and settings\Mike\Local Settings\Application Data\SCE
2009-05-27 02:24 . 2009-06-20 02:54 ——– d—–w- c:\program files\Sony Online Entertainment
2009-05-23 15:18 . 2009-05-23 15:18 ——– d—–w- c:\documents and settings\All Users\Application Data\99374206
2009-05-23 15:18 . 2009-05-23 15:18 ——– d—–w- c:\documents and settings\All Users\Application Data\19364214

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-19 21:18 . 2008-12-24 18:22 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-19 05:13 . 2008-02-29 04:48 ——– d-s—w- c:\program files\Xfire
2009-06-19 05:11 . 2008-02-29 04:48 ——– d—–w- c:\docume~1\Mike\APPLIC~1\Xfire
2009-06-19 03:57 . 2008-10-18 21:54 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-19 01:58 . 2009-01-29 19:22 189496 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-06-18 19:12 . 2009-01-29 19:22 139984 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-06-17 18:27 . 2008-10-18 21:54 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 18:27 . 2008-10-18 21:54 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-13 17:58 . 2009-02-22 19:07 ——– d—–w- c:\docume~1\Mike\APPLIC~1\LimeWire
2009-06-13 17:52 . 2009-02-22 19:06 ——– d—–w- c:\program files\LimeWire
2009-06-07 21:29 . 2008-05-03 17:20 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2009-06-07 21:28 . 2008-02-29 05:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-07 21:28 . 2008-02-29 05:12 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-07 21:25 . 2009-01-10 18:47 ——– d—–w- c:\program files\Electronic Arts
2009-06-07 20:23 . 2008-02-29 05:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-06-07 20:23 . 2008-02-28 21:59 ——– d—–w- c:\program files\Yahoo!
2009-06-07 20:22 . 2008-02-29 05:21 ——– d—–w- c:\docume~1\Mike\APPLIC~1\Yahoo!
2009-05-13 05:15 . 2005-08-31 15:58 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2005-08-31 15:58 345600 —-a-w- c:\windows\system32\localspl.dll
2009-05-06 22:24 . 2009-04-25 02:47 ——– d—–w- c:\program files\McAfee
2009-04-25 02:52 . 2009-04-25 02:52 ——– d—–w- c:\documents and settings\LocalService\Application Data\SACore
2009-04-25 02:49 . 2009-04-25 02:31 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-04-25 02:49 . 2009-04-25 02:49 ——– d—–w- c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-04-25 02:47 . 2009-04-25 02:47 ——– d—–w- c:\program files\Common Files\McAfee
2009-04-25 02:47 . 2009-04-25 02:47 ——– d—–w- c:\program files\McAfee.com
2009-04-25 02:39 . 2008-02-29 05:13 ——– d—–w- c:\program files\Symantec
2009-04-17 12:26 . 2005-08-31 15:58 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2005-08-31 15:58 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2008-10-18 19:48 . 2008-10-18 19:48 15317 —-a-w- c:\program files\Common Files\ovegixomi.reg
2008-10-18 19:48 . 2008-10-18 19:48 11592 —-a-w- c:\program files\Common Files\azevi.lib
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"igndlm.exe"="c:\program files\Download Manager\dlm.exe" [2009-02-25 1103216]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"2wSysTray"="c:\program files\2Wire\Gateway\2PortalMon.exe" [2002-11-14 446464]
"YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-22 129536]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-17 136600]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2005-08-31 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2005-08-31 44032]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2005-08-31 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2005-08-31 455168]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-08 385024]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2007-11-30 1164576]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-18 1657376]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-02-27 16005120]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
OSCust.lnk - c:\windows\system32\oem\OSCust.exe [2007-8-17 67072]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 04:34 24576 —-a-w- c:\program files\AlienGUIse\fastload.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Sierra\\FEARCombat\\FEARMP.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Triggersoft\\ROSE Online Evolution\\ROSEonline.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Makena\\There\\ThereClient\\There.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58477:TCP"= 58477:TCP:Pando Media Booster
"58477:UDP"= 58477:UDP:Pando Media Booster

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [4/24/2009 7:49 PM 203280]
S3 XDva195;XDva195;\??\c:\windows\system32\XDva195.sys –> c:\windows\system32\XDva195.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-04-25 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-25 20:32]

2009-04-25 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-25 20:32]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
HKCU-RunOnce-Shockwave Updater - c:\windows\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103472 -Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; YComp 5.0.0.0; GTB6; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET
SafeBoot-TDSSmxjt.sys


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: Add to Windows &Live; Favorites
Trusted Zone: roseonlinegame.com\www
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-20 07:15
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3678683883-2346267703-745543312-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:1a,74,fb,b2,20,77,c5,26,ca,69,86,86,4b,e0,08,e6,d0,79,55,18,3c,c3,54,
0a,8f,f8,a1,c7,6d,b7,5a,a6,aa,0f,a6,8e,5e,bd,40,72,45,93,66,14,84,80,cb,df,\
"??"=hex:3f,eb,b2,a8,d5,51,4b,c2,1b,01,ec,08,0f,18,11,95

[HKEY_USERS\S-1-5-21-3678683883-2346267703-745543312-1005\Software\SecuROM\License information*]
"datasecu"=hex:f6,cf,b9,e3,1b,3b,8c,89,d5,4b,eb,29,29,61,e0,6f,b4,b9,05,95,6e,
e8,26,5a,50,07,65,d5,29,41,55,b3,40,b8,1d,87,5e,f7,80,4d,c2,27,14,66,1a,eb,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(908)
c:\program files\AlienGUIse\fastload.dll
.
Completion time: 2009-06-20 7:16
ComboFix-quarantined-files.txt 2009-06-20 14:16

Pre-Run: 126,006,050,816 bytes free
Post-Run: 128,881,815,552 bytes free

Current=6 Default=6 Failed=5 LastKnownGood=7 Sets=3,4,5,6,7
223 — E O F — 2009-01-14 15:29
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Windows_slow_crashes_locks_up_t104273.html&view=findpost&p=570156#entry570156

Collect::
c:\program files\Common Files\ovegixomi.reg
c:\program files\Common Files\azevi.lib

DirLook::
c:\documents and settings\All Users\Application Data\99374206
c:\documents and settings\All Users\Application Data\19364214

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
quick question before i drag the file over to ComboFix. Do i drag it to the desk icon that you had me save as Combo-Fix? or do i need to redownload it again, and not change the name this time as i save it?
drag to the one that's already there…if it asks to update itself - ALLOW it If it asks to install the Recovery Console - ALLOW it
OK, ran the one you said, and it told me it wouldnt run with the name change. So i renamed it from Combo-Fix to Combofix, and then it was able to run. Just thought i would let you know, incase this happens to someone else. Here is the new log:

ComboFix 09-06-19.01 - Mike 06/20/2009 8:33.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1442 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Mike\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

file zipped: c:\program files\Common Files\azevi.lib
file zipped: c:\program files\Common Files\ovegixomi.reg
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Common Files\azevi.lib
c:\program files\Common Files\ovegixomi.reg

.
((((((((((((((((((((((((( Files Created from 2009-05-20 to 2009-06-20 )))))))))))))))))))))))))))))))
.

2009-06-20 13:46 . 2009-06-20 14:16 ——– d-s—w- C:\Combo-Fix
2009-06-19 03:56 . 2009-06-19 03:57 3561743 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-12 15:43 . 2009-06-12 23:33 ——– d—–w- c:\documents and settings\Mike\Local Settings\Application Data\PMB Files
2009-06-12 15:43 . 2009-06-12 15:44 ——– d—–w- c:\documents and settings\All Users\Application Data\PMB Files
2009-06-12 15:43 . 2009-06-12 15:43 ——– d—–w- c:\program files\Pando Networks
2009-06-11 22:29 . 2009-06-11 22:29 41808 —-a-w- c:\windows\system32\xfcodec.dll
2009-06-10 15:56 . 2009-06-10 15:56 ——– d-sh–w- C:\found.000
2009-06-10 00:03 . 2006-03-22 18:21 10240 —-a-w- c:\windows\system32\bdco1ins.dll
2009-06-10 00:03 . 2006-03-15 00:45 35840 —-a-w- c:\windows\system32\nvconrm.dll
2009-06-10 00:02 . 2006-03-22 18:24 18944 —-a-w- c:\windows\system32\drivers\nvnetbus.sys
2009-06-10 00:02 . 2006-03-22 18:23 1068800 —-a-w- c:\windows\system32\drivers\nvnrm.sys
2009-06-10 00:02 . 2006-03-22 17:21 10240 —-a-w- c:\windows\system32\bdco1.dll
2009-06-09 18:15 . 2009-04-30 21:22 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-06-09 18:15 . 2009-04-30 21:22 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-08 03:33 . 2009-06-08 03:33 ——– d—–w- c:\documents and settings\Mike\Local Settings\Application Data\Yahoo
2009-06-07 20:22 . 2009-06-07 20:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-06-07 20:21 . 2009-05-27 02:50 607472 —-a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-05-27 02:29 . 2009-05-27 02:29 ——– d—–w- c:\documents and settings\Mike\Local Settings\Application Data\SCE
2009-05-27 02:24 . 2009-06-20 02:54 ——– d—–w- c:\program files\Sony Online Entertainment
2009-05-23 15:18 . 2009-05-23 15:18 ——– d—–w- c:\documents and settings\All Users\Application Data\99374206
2009-05-23 15:18 . 2009-05-23 15:18 ——– d—–w- c:\documents and settings\All Users\Application Data\19364214

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-20 15:20 . 2009-01-29 19:22 189496 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-06-20 15:12 . 2009-01-29 19:22 139984 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-06-19 21:18 . 2008-12-24 18:22 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-19 05:13 . 2008-02-29 04:48 ——– d-s—w- c:\program files\Xfire
2009-06-19 05:11 . 2008-02-29 04:48 ——– d—–w- c:\docume~1\Mike\APPLIC~1\Xfire
2009-06-19 03:57 . 2008-10-18 21:54 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-17 18:27 . 2008-10-18 21:54 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 18:27 . 2008-10-18 21:54 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-13 17:58 . 2009-02-22 19:07 ——– d—–w- c:\docume~1\Mike\APPLIC~1\LimeWire
2009-06-13 17:52 . 2009-02-22 19:06 ——– d—–w- c:\program files\LimeWire
2009-06-07 21:29 . 2008-05-03 17:20 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2009-06-07 21:28 . 2008-02-29 05:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-07 21:28 . 2008-02-29 05:12 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-07 21:25 . 2009-01-10 18:47 ——– d—–w- c:\program files\Electronic Arts
2009-06-07 20:23 . 2008-02-29 05:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-06-07 20:23 . 2008-02-28 21:59 ——– d—–w- c:\program files\Yahoo!
2009-06-07 20:22 . 2008-02-29 05:21 ——– d—–w- c:\docume~1\Mike\APPLIC~1\Yahoo!
2009-05-13 05:15 . 2005-08-31 15:58 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2005-08-31 15:58 345600 —-a-w- c:\windows\system32\localspl.dll
2009-05-06 22:24 . 2009-04-25 02:47 ——– d—–w- c:\program files\McAfee
2009-04-25 02:52 . 2009-04-25 02:52 ——– d—–w- c:\documents and settings\LocalService\Application Data\SACore
2009-04-25 02:49 . 2009-04-25 02:31 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-04-25 02:49 . 2009-04-25 02:49 ——– d—–w- c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-04-25 02:47 . 2009-04-25 02:47 ——– d—–w- c:\program files\Common Files\McAfee
2009-04-25 02:47 . 2009-04-25 02:47 ——– d—–w- c:\program files\McAfee.com
2009-04-25 02:39 . 2008-02-29 05:13 ——– d—–w- c:\program files\Symantec
2009-04-17 12:26 . 2005-08-31 15:58 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2005-08-31 15:58 585216 —-a-w- c:\windows\system32\rpcrt4.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\documents and settings\All Users\Application Data\19364214 —-

2009-05-23 15:18 . 2009-05-23 15:18 64784 —-a-w- c:\documents and settings\All Users\Application Data\19364214\19364214.glu

—- Directory of c:\documents and settings\All Users\Application Data\99374206 —-



((((((((((((((((((((((((((((( SnapShot@2009-06-20_14.15.05 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-20 14:20 . 2009-06-20 14:20 16384 c:\windows\Temp\Perflib_Perfdata_758.dat
- 2009-06-20 14:03 . 2009-06-20 14:03 16384 c:\windows\Temp\Perflib_Perfdata_758.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"igndlm.exe"="c:\program files\Download Manager\dlm.exe" [2009-02-25 1103216]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-09 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"2wSysTray"="c:\program files\2Wire\Gateway\2PortalMon.exe" [2002-11-14 446464]
"YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-22 129536]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-17 136600]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2005-08-31 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2005-08-31 44032]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2005-08-31 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2005-08-31 455168]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-08 385024]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2007-11-30 1164576]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-18 1657376]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-02-27 16005120]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
OSCust.lnk - c:\windows\system32\oem\OSCust.exe [2007-8-17 67072]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 04:34 24576 —-a-w- c:\program files\AlienGUIse\fastload.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSSmxjt.sys]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Sierra\\FEARCombat\\FEARMP.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Triggersoft\\ROSE Online Evolution\\ROSEonline.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Makena\\There\\ThereClient\\There.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58477:TCP"= 58477:TCP:Pando Media Booster
"58477:UDP"= 58477:UDP:Pando Media Booster

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [4/24/2009 7:49 PM 203280]
S3 XDva195;XDva195;\??\c:\windows\system32\XDva195.sys –> c:\windows\system32\XDva195.sys [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - PNKBSTRB

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-04-25 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-25 20:32]

2009-04-25 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-25 20:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: Add to Windows &Live; Favorites
Trusted Zone: roseonlinegame.com\www
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-20 08:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3678683883-2346267703-745543312-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:1a,74,fb,b2,20,77,c5,26,ca,69,86,86,4b,e0,08,e6,d0,79,55,18,3c,c3,54,
0a,8f,f8,a1,c7,6d,b7,5a,a6,aa,0f,a6,8e,5e,bd,40,72,45,93,66,14,84,80,cb,df,\
"??"=hex:3f,eb,b2,a8,d5,51,4b,c2,1b,01,ec,08,0f,18,11,95

[HKEY_USERS\S-1-5-21-3678683883-2346267703-745543312-1005\Software\SecuROM\License information*]
"datasecu"=hex:f6,cf,b9,e3,1b,3b,8c,89,d5,4b,eb,29,29,61,e0,6f,b4,b9,05,95,6e,
e8,26,5a,50,07,65,d5,29,41,55,b3,40,b8,1d,87,5e,f7,80,4d,c2,27,14,66,1a,eb,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(904)
c:\program files\AlienGUIse\fastload.dll
.
Completion time: 2009-06-20 8:38
ComboFix-quarantined-files.txt 2009-06-20 15:38
ComboFix2.txt 2009-06-20 14:16

Pre-Run: 128,887,259,136 bytes free
Post-Run: 128,877,457,408 bytes free

Current=6 Default=6 Failed=5 LastKnownGood=7 Sets=1,2,3,4,5,6,7
217 — E O F — 2009-01-14 15:29
Upload was successful
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Windows_slow_crashes_locks_up_t104273.html&view=findpost&p=570182#entry570182

Collect::
c:\documents and settings\All Users\Application Data\19364214\19364214.glu
c:\documents and settings\All Users\Application Data\19364214\19364214.exe

Folder::
c:\documents and settings\All Users\Application Data\99374206
c:\documents and settings\All Users\Application Data\19364214

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT

ran the one you said, and it told me it wouldnt run with the name change. So i renamed it from Combo-Fix to Combofix, and then it was able to run.



That's interesting - not supposed to matter, we'll have to do some testing - thanks for the info.


NEXT

If you can post the log from the initial run of malwareBytes Antimalware that you ran before you posted, I would like to see it:

Now update MalwareBytes and re-run it, make sure it's clean.
Post this log also.

NEXT

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner



1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
mooze, another thing I noticed was that the recovery console didn't install - did you get any error messages when it first initially ran regarding the recovery console?
still working on the last post. Yes i did get a message, saying that the recovery console wasnt installed on my pc, and it asked if i wanted to install it. i clicked on YES, then a few mins later it said something like, the boot.ini wasnt formated, and didnt give me an option to, only an OK to click. i thought it was taking care of it, but i guess, it was just informing me of the situationa nd began to do its scan.
here is the malware i ran before posting.

Malwarebytes' Anti-Malware 1.38
Database version: 2307
Windows 5.1.2600 Service Pack 3

6/18/2009 10:11:25 PM
mbam-log-2009-06-18 (22-11-24).txt

Scan type: Full Scan (C:\|)
Objects scanned: 386527
Time elapsed: 51 minute(s), 49 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 6
Folders Infected: 1
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\19364214 (Rogue.Multiple) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
c:\documents and settings\Mike\Application Data\GetModule (Trojan.Agent) -> Quarantined and deleted successfully.

Files Infected:
(No malicious items detected)


Here is Combofix the 2nd time

ComboFix 09-06-20.01 - Mike 06/20/2009 11:48.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1625 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Mike\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

file zipped: c:\documents and settings\All Users\Application Data\19364214\19364214.glu
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\19364214
c:\documents and settings\All Users\Application Data\99374206
c:\documents and settings\All Users\Application Data\19364214\19364214.glu

.
((((((((((((((((((((((((( Files Created from 2009-05-20 to 2009-06-20 )))))))))))))))))))))))))))))))
.

2009-06-20 13:46 . 2009-06-20 14:16 ——– d-s—w- C:\Combo-Fix
2009-06-19 03:56 . 2009-06-19 03:57 3561743 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-12 17:28 . 2009-06-12 17:28 45056 —-a-r- c:\documents and settings\Mike\Application Data\Microsoft\Installer\{48E16DC7-79EC-45F1-847A-F8D3C620515E}\MapleStory.exe1_801DA03C4E824858A615529E6AFB9A78.exe
2009-06-12 17:28 . 2009-06-12 17:28 45056 —-a-r- c:\documents and settings\Mike\Application Data\Microsoft\Installer\{48E16DC7-79EC-45F1-847A-F8D3C620515E}\MapleStory.exe_801DA03C4E824858A615529E6AFB9A78.exe
2009-06-12 17:28 . 2009-06-12 17:28 10134 —-a-r- c:\documents and settings\Mike\Application Data\Microsoft\Installer\{48E16DC7-79EC-45F1-847A-F8D3C620515E}\ARPPRODUCTICON.exe
2009-06-12 15:43 . 2009-06-12 23:33 ——– d—–w- c:\documents and settings\Mike\Local Settings\Application Data\PMB Files
2009-06-12 15:43 . 2009-06-12 15:44 ——– d—–w- c:\documents and settings\All Users\Application Data\PMB Files
2009-06-12 15:43 . 2009-06-12 15:43 ——– d—–w- c:\program files\Pando Networks
2009-06-11 22:29 . 2009-06-11 22:29 41808 —-a-w- c:\windows\system32\xfcodec.dll
2009-06-10 15:56 . 2009-06-10 15:56 ——– d-sh–w- C:\found.000
2009-06-10 00:03 . 2006-03-22 18:21 10240 —-a-w- c:\windows\system32\bdco1ins.dll
2009-06-10 00:03 . 2006-03-15 00:45 35840 —-a-w- c:\windows\system32\nvconrm.dll
2009-06-10 00:02 . 2006-03-22 18:24 18944 —-a-w- c:\windows\system32\drivers\nvnetbus.sys
2009-06-10 00:02 . 2006-03-22 18:23 1068800 —-a-w- c:\windows\system32\drivers\nvnrm.sys
2009-06-10 00:02 . 2006-03-22 17:21 10240 —-a-w- c:\windows\system32\bdco1.dll
2009-06-09 18:15 . 2009-04-30 21:22 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-06-09 18:15 . 2009-04-30 21:22 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-08 03:33 . 2009-06-08 03:33 ——– d—–w- c:\documents and settings\Mike\Local Settings\Application Data\Yahoo
2009-06-07 20:22 . 2009-06-07 20:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-06-07 20:21 . 2009-05-27 02:50 607472 —-a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-05-27 02:29 . 2009-05-27 02:29 ——– d—–w- c:\documents and settings\Mike\Local Settings\Application Data\SCE
2009-05-27 02:24 . 2009-06-20 02:54 ——– d—–w- c:\program files\Sony Online Entertainment

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-20 18:43 . 2008-02-29 04:48 ——– d—–w- c:\documents and settings\Mike\Application Data\Xfire
2009-06-20 15:20 . 2009-01-29 19:22 189496 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-06-20 15:12 . 2009-01-29 19:22 139984 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-06-19 21:18 . 2008-12-24 18:22 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-19 05:13 . 2008-02-29 04:48 ——– d-s—w- c:\program files\Xfire
2009-06-19 03:57 . 2008-10-18 21:54 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-17 18:27 . 2008-10-18 21:54 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 18:27 . 2008-10-18 21:54 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-13 17:58 . 2009-02-22 19:07 ——– d—–w- c:\documents and settings\Mike\Application Data\LimeWire
2009-06-13 17:52 . 2009-02-22 19:06 ——– d—–w- c:\program files\LimeWire
2009-06-07 21:29 . 2008-05-03 17:20 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2009-06-07 21:28 . 2008-02-29 05:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-07 21:28 . 2008-02-29 05:12 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-07 21:25 . 2009-01-10 18:47 ——– d—–w- c:\program files\Electronic Arts
2009-06-07 20:23 . 2008-02-29 05:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-06-07 20:23 . 2008-02-28 21:59 ——– d—–w- c:\program files\Yahoo!
2009-06-07 20:22 . 2008-02-29 05:21 ——– d—–w- c:\documents and settings\Mike\Application Data\Yahoo!
2009-05-13 05:15 . 2005-08-31 15:58 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2005-08-31 15:58 345600 —-a-w- c:\windows\system32\localspl.dll
2009-05-06 22:24 . 2009-04-25 02:47 ——– d—–w- c:\program files\McAfee
2009-04-25 02:52 . 2009-04-25 02:52 ——– d—–w- c:\documents and settings\LocalService\Application Data\SACore
2009-04-25 02:49 . 2009-04-25 02:31 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-04-25 02:49 . 2009-04-25 02:49 ——– d—–w- c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-04-25 02:47 . 2009-04-25 02:47 ——– d—–w- c:\program files\Common Files\McAfee
2009-04-25 02:47 . 2009-04-25 02:47 ——– d—–w- c:\program files\McAfee.com
2009-04-25 02:39 . 2008-02-29 05:13 ——– d—–w- c:\program files\Symantec
2009-04-17 12:26 . 2005-08-31 15:58 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2005-08-31 15:58 585216 —-a-w- c:\windows\system32\rpcrt4.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-06-20_14.15.05 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-20 17:43 . 2009-06-20 17:43 16384 c:\windows\Temp\Perflib_Perfdata_2b0.dat
+ 2006-05-18 23:04 . 2009-06-20 17:48 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-05-18 23:04 . 2009-06-20 13:34 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2006-05-18 23:04 . 2009-06-20 17:48 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2006-05-18 23:04 . 2009-06-20 13:34 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-04-29 19:18 . 2009-06-20 17:48 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2009-04-29 19:18 . 2009-06-20 13:34 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"igndlm.exe"="c:\program files\Download Manager\dlm.exe" [2009-02-25 1103216]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-09 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"2wSysTray"="c:\program files\2Wire\Gateway\2PortalMon.exe" [2002-11-14 446464]
"YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-22 129536]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-17 136600]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2005-08-31 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2005-08-31 44032]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2005-08-31 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2005-08-31 455168]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-08 385024]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2007-11-30 1164576]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-18 1657376]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-02-27 16005120]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
OSCust.lnk - c:\windows\system32\oem\OSCust.exe [2007-8-17 67072]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 04:34 24576 —-a-w- c:\program files\AlienGUIse\fastload.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSSmxjt.sys]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Sierra\\FEARCombat\\FEARMP.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Triggersoft\\ROSE Online Evolution\\ROSEonline.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Makena\\There\\ThereClient\\There.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58477:TCP"= 58477:TCP:Pando Media Booster
"58477:UDP"= 58477:UDP:Pando Media Booster

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [4/24/2009 7:49 PM 203280]
S3 XDva195;XDva195;\??\c:\windows\system32\XDva195.sys –> c:\windows\system32\XDva195.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-04-25 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-25 20:32]

2009-04-25 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-25 20:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: Add to Windows &Live; Favorites
Trusted Zone: roseonlinegame.com\www
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-20 11:51
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3678683883-2346267703-745543312-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:1a,74,fb,b2,20,77,c5,26,ca,69,86,86,4b,e0,08,e6,d0,79,55,18,3c,c3,54,
0a,8f,f8,a1,c7,6d,b7,5a,a6,aa,0f,a6,8e,5e,bd,40,72,45,93,66,14,84,80,cb,df,\
"??"=hex:3f,eb,b2,a8,d5,51,4b,c2,1b,01,ec,08,0f,18,11,95

[HKEY_USERS\S-1-5-21-3678683883-2346267703-745543312-1005\Software\SecuROM\License information*]
"datasecu"=hex:f6,cf,b9,e3,1b,3b,8c,89,d5,4b,eb,29,29,61,e0,6f,b4,b9,05,95,6e,
e8,26,5a,50,07,65,d5,29,41,55,b3,40,b8,1d,87,5e,f7,80,4d,c2,27,14,66,1a,eb,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(904)
c:\program files\AlienGUIse\fastload.dll
.
Completion time: 2009-06-20 11:52
ComboFix-quarantined-files.txt 2009-06-20 18:52
ComboFix2.txt 2009-06-20 17:00
ComboFix3.txt 2009-06-20 14:16

Pre-Run: 128,883,462,144 bytes free
Post-Run: 128,872,820,736 bytes free

Current=6 Default=6 Failed=5 LastKnownGood=7 Sets=1,2,3,4,5,6,7
217 — E O F — 2009-01-14 15:29
Upload was successful


Here is Kapersky

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Saturday, June 20, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Saturday, June 20, 2009 18:25:54
Records in database: 2371340
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 198269
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 03:13:34


File name / Threat name / Threats count
C:\Documents and Settings\Mike\My Documents\Gamez\Poker\pkrinstall.exe Infected: not-a-virus:Monitor.Win32.PKRPoker.e 1

The selected area was scanned.

I think that is everything you asked for.
Yes, thank-you, there's still some indicators of the presence of that rootkit, so I would like you to re-run GMER to make sure it's gone completely,

please do the following:

  • Please run GMER once again, using these instructions.
  • Double click GMER.exe.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then proceed as indicated below to set it up for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



NEXT


Please download BootCheck.exe to your desktop.
  • Double click BootCheck.exe to run the check
  • When complete, a Notepad window will open with some text in it
  • Save the Notepad file to your desktop as BootCheck.txt
  • Copy the contents of BootCheck.txt and post it in your next reply
Hey Catbyte, i ran Gmer again, and it froze when i was in the middle of saving the file. Took about 5 hrs to complete and now i have to do it all over again. Anyways, i wanted to let you know, since it takes so long, and its Fathers Day here in the States, that i most likely wont be posting it until tomorrow. Didnt want you waiting around for a reply from me. Thanks for all your help so far, and i will post the log tomorrow after i rerun the Gmer program.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI