This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Please help me remove win32trojan.tdss

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello! This is my first post here, so thank you in advance for trying to help me out. I'm running Windows XP SP3. It looks like I've caught a nasty by the name of win32trojan.tdss. I discovered it after getting several alerts from Mcaffee. Before finding your fine forum here I tried running Ad-Aware, but it wouldn't open. I uninstalled and reinstalled Ad-Aware, ran a full scan, but it doesn't seem to be able to get rid of it. Same for Mcaffee… Upon restarting my computer, I get an odd screen before Windows loads that says something like "boot cleaner initialized" and ":\\globalroot…" something or another. The screen goes away quickly, and I don't have time to read everything on the screen. I'm using Firefox, but every few minutes I get a message asking if I'd like to make IE my default browser. I haven't used IE in a long time, but I went to Microsoft.com and upgraded to IE 8. Shortly after that I discovered a shortcut to "Internet Explorer: No Addons" in Start>All Programs>Accessories>System Tools. I've never seen that before, and I deleted the shortcut. I'm not really sure if it's supposed to be there or not, but the shortcut is gone, nonetheless. I've downloaded HJT.exe and mbam-setup.exe to my desktop, but neither will run. After I double-click either and hit 'run', I get an hourglass for a few seconds, then nothing. I'm assuming it's got something to do with the virus… :pullhair: :pullhair: So, that's where I'm at. I'm hoping someone can help me to get HijackThis and mbam to run so I can get the ball rolling on getting this tricky booger removed. After reading through a few threads, I'm confident that I came to the right place seeking help. I'm glad guys like you are out there. On a funnier note, a Michael Jackson song started playing through my computer speakers a few minutes ago. "We Will Heal the World" I think… As far as I know, I don't have any Michael Jackson songs in this computer. There were no players or other browser windows open, and I have no idea where the music was coming from. Now, I was pretty peeved that I had no control over what was happening to my computer, but I had to laugh at that one. I think it actually started playing right after I found this website, so maybe it was playing from your site. I hope so, but I doubt it. Either way I gotta chuckle out of it.
Hi lucky_1_chris, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop


Next

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

Please post back with
  • GMER log
  • both DDS logs

Thanks
I can download gmer, unzipped it to my desktop, double-clicked gmer.exe, but gmer will not run. EDIT: I changed the name of gmer, now it will run. I will post the logs you need as soon as I get them. THANK YOU.
GMER LOG:

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-22 20:16:08
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xA8D5B4EA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xA8D5B581]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xA8D5B498]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xA8D5B4AC]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xA8D5B595]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xA8D5B5C1]
Code 8AC77250 ZwEnumerateKey
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xA8D5B619]
Code 8AC78808 ZwFlushInstructionCache
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xA8D5B52A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xA8D5B65E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xA8D5B56D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xA8D5B470]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xA8D5B484]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xA8D5B4FE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xA8D5B69A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xA8D5B603]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xA8D5B5ED]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xA8D5B5AB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xA8D5B686]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xA8D5B672]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xA8D5B4D6]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xA8D5B4C2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xA8D5B5D7]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xA8D5B559]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xA8D5B648]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xA8D5B540]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xA8D5B514]
Code 8AC1CE06 IofCallDriver
Code 8A9C25FE IofCompleteRequest
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
Code 8ACBC6B5 ZwSaveKey
Code 8AC78345 ZwSaveKeyEx

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!IofCallDriver 804EF1A6 5 Bytes JMP 8AC1CE0B
.text ntkrnlpa.exe!IofCompleteRequest 804EF236 5 Bytes JMP 8A9C2603
.text ntkrnlpa.exe!ZwSaveKey 80500D68 5 Bytes JMP 8ACBC6BA
.text ntkrnlpa.exe!ZwSaveKeyEx 80500D7C 5 Bytes JMP 8AC7834A
.text ntkrnlpa.exe!ZwYieldExecution 80504AE8 7 Bytes JMP A8D5B518 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 80579084 5 Bytes JMP A8D5B4EE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805B2006 7 Bytes JMP A8D5B52E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B2E14 5 Bytes JMP A8D5B544 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805B6812 5 Bytes JMP 8AC7880C
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805B83E6 7 Bytes JMP A8D5B502 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805CB408 2 Bytes JMP A8D5B474 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess + 3 805CB40B 2 Bytes [79, 28] {JNS 0x2a}
PAGE ntkrnlpa.exe!NtOpenThread 805CB694 5 Bytes JMP A8D5B488 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 805CDE52 5 Bytes JMP A8D5B4C6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1142 7 Bytes JMP A8D5B4B0 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805D11F8 5 Bytes JMP A8D5B49C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 805D1702 5 Bytes JMP A8D5B4DA \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D29AA 5 Bytes JMP A8D5B55D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryValueKey 806219E8 7 Bytes JMP A8D5B5F1 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetValueKey 80621D36 7 Bytes JMP A8D5B5DB \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnloadKey 80622060 7 Bytes JMP A8D5B64C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryMultipleValueKey 806228FE 7 Bytes JMP A8D5B607 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 806231D2 7 Bytes JMP A8D5B5AF \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateKey 806237B0 5 Bytes JMP A8D5B585 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 80623C40 7 Bytes JMP A8D5B599 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 80623E10 7 Bytes JMP A8D5B5C5 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateKey 80623FF0 4 Bytes JMP 8AC77254
PAGE ntkrnlpa.exe!ZwEnumerateValueKey 8062425A 7 Bytes JMP A8D5B61D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwOpenKey 80624B82 5 Bytes JMP A8D5B571 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryKey 80624EA8 7 Bytes JMP A8D5B69E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRestoreKey 80625168 5 Bytes JMP A8D5B676 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplaceKey 8062585C 5 Bytes JMP A8D5B68A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 80625976 5 Bytes JMP A8D5B662 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
.text ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00EA000A
.text ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00EB000A

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\Explorer.EXE[476] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00DE000A
.text C:\WINDOWS\Explorer.EXE[476] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00DF000A
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01D10FEF
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01D10FA5
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01D1009A
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01D10FB6
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01D10073
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01D10047
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01D100D0
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01D10F8A
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01D10F41
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01D10F52
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01D100EB
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01D10062
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01D10000
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01D100B5
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01D1002C
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01D1001B
.text C:\WINDOWS\Explorer.EXE[476] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01D10F6D
.text C:\WINDOWS\Explorer.EXE[476] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01D00025
.text C:\WINDOWS\Explorer.EXE[476] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01D00080
.text C:\WINDOWS\Explorer.EXE[476] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01D00FD4
.text C:\WINDOWS\Explorer.EXE[476] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01D00FEF
.text C:\WINDOWS\Explorer.EXE[476] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01D0006F
.text C:\WINDOWS\Explorer.EXE[476] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01D00000
.text C:\WINDOWS\Explorer.EXE[476] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01D00FC3
.text C:\WINDOWS\Explorer.EXE[476] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [F0, 89]
.text C:\WINDOWS\Explorer.EXE[476] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01D00040
.text C:\WINDOWS\Explorer.EXE[476] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01CF0FD1
.text C:\WINDOWS\Explorer.EXE[476] msvcrt.dll!system 77C293C7 5 Bytes JMP 01CF0066
.text C:\WINDOWS\Explorer.EXE[476] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01CF003A
.text C:\WINDOWS\Explorer.EXE[476] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01CF0000
.text C:\WINDOWS\Explorer.EXE[476] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01CF004B
.text C:\WINDOWS\Explorer.EXE[476] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01CF001D
.text C:\WINDOWS\Explorer.EXE[476] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 01CD0FEF
.text C:\WINDOWS\Explorer.EXE[476] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 01CD0000
.text C:\WINDOWS\Explorer.EXE[476] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 01CD0011
.text C:\WINDOWS\Explorer.EXE[476] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 01CD0022
.text C:\WINDOWS\Explorer.EXE[476] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01CE0FEF
.text C:\WINDOWS\system32\winlogon.exe[692] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0094000A
.text C:\WINDOWS\system32\winlogon.exe[692] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0095000A
.text C:\WINDOWS\system32\services.exe[740] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00A4000A
.text C:\WINDOWS\system32\services.exe[740] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00A5000A
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 012E0000
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 012E0FB4
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 012E00A9
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 012E0098
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 012E0087
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 012E0051
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 012E00D5
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 012E0F8D
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 012E00FA
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 012E0F61
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 012E0F46
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 012E0076
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 012E001B
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 012E00BA
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 012E0FE5
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 012E002C
.text C:\WINDOWS\system32\services.exe[740] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 012E0F72
.text C:\WINDOWS\system32\services.exe[740] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0007001B
.text C:\WINDOWS\system32\services.exe[740] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00070065
.text C:\WINDOWS\system32\services.exe[740] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0007000A
.text C:\WINDOWS\system32\services.exe[740] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00070FD4
.text C:\WINDOWS\system32\services.exe[740] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0007004A
.text C:\WINDOWS\system32\services.exe[740] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00070FEF
.text C:\WINDOWS\system32\services.exe[740] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00070F9E
.text C:\WINDOWS\system32\services.exe[740] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [27, 88]
.text C:\WINDOWS\system32\services.exe[740] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00070FAF
.text C:\WINDOWS\system32\services.exe[740] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0006005D
.text C:\WINDOWS\system32\services.exe[740] msvcrt.dll!system 77C293C7 5 Bytes JMP 00060FC8
.text C:\WINDOWS\system32\services.exe[740] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0006001D
.text C:\WINDOWS\system32\services.exe[740] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00060FEF
.text C:\WINDOWS\system32\services.exe[740] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00060038
.text C:\WINDOWS\system32\services.exe[740] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00060000
.text C:\WINDOWS\system32\services.exe[740] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00050FEF
.text C:\WINDOWS\system32\services.exe[740] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00040FEF
.text C:\WINDOWS\system32\services.exe[740] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 0004000A
.text C:\WINDOWS\system32\services.exe[740] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00040FD4
.text C:\WINDOWS\system32\services.exe[740] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 0004002F
.text C:\WINDOWS\system32\lsass.exe[752] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00AD000A
.text C:\WINDOWS\system32\lsass.exe[752] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00B0000A
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01370000
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01370F52
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01370F63
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0137003D
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01370F8A
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0137002C
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 0137007D
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0137006C
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01370F06
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 0137009F
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01370EF5
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01370FA5
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01370FE5
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01370F41
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0137001B
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01370FD4
.text C:\WINDOWS\system32\lsass.exe[752] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 0137008E
.text C:\WINDOWS\system32\lsass.exe[752] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0136001B
.text C:\WINDOWS\system32\lsass.exe[752] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 0136003D
.text C:\WINDOWS\system32\lsass.exe[752] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01360FCA
.text C:\WINDOWS\system32\lsass.exe[752] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01360000
.text C:\WINDOWS\system32\lsass.exe[752] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01360F80
.text C:\WINDOWS\system32\lsass.exe[752] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01360FEF
.text C:\WINDOWS\system32\lsass.exe[752] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0136002C
.text C:\WINDOWS\system32\lsass.exe[752] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01360FA5
.text C:\WINDOWS\system32\lsass.exe[752] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0135003F
.text C:\WINDOWS\system32\lsass.exe[752] msvcrt.dll!system 77C293C7 5 Bytes JMP 01350FBE
.text C:\WINDOWS\system32\lsass.exe[752] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0135002E
.text C:\WINDOWS\system32\lsass.exe[752] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01350000
.text C:\WINDOWS\system32\lsass.exe[752] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01350FD9
.text C:\WINDOWS\system32\lsass.exe[752] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0135001D
.text C:\WINDOWS\system32\lsass.exe[752] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01340000
.text C:\WINDOWS\system32\lsass.exe[752] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00FF0FEF
.text C:\WINDOWS\system32\lsass.exe[752] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00FF0FD4
.text C:\WINDOWS\system32\lsass.exe[752] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00FF0FC3
.text C:\WINDOWS\system32\lsass.exe[752] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00FF0F9E
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02AB0FEF
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02AB0FA3
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02AB0098
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02AB0087
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02AB0076
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02AB0040
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02AB00DA
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02AB00BD
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02AB0F66
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02AB00FF
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02AB0F55
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02AB005B
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02AB000A
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02AB0F92
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02AB0025
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02AB0FD4
.text C:\WINDOWS\system32\svchost.exe[916] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02AB0F81
.text C:\WINDOWS\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02AA0040
.text C:\WINDOWS\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 02AA0087
.text C:\WINDOWS\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 02AA0025
.text C:\WINDOWS\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 02AA0FEF
.text C:\WINDOWS\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02AA006C
.text C:\WINDOWS\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 02AA0000
.text C:\WINDOWS\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 02AA005B
.text C:\WINDOWS\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02AA0FD4
.text C:\WINDOWS\system32\svchost.exe[916] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02A90F82
.text C:\WINDOWS\system32\svchost.exe[916] msvcrt.dll!system 77C293C7 5 Bytes JMP 02A90F93
.text C:\WINDOWS\system32\svchost.exe[916] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02A90FB5
.text C:\WINDOWS\system32\svchost.exe[916] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02A90FE3
.text C:\WINDOWS\system32\svchost.exe[916] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02A90FA4
.text C:\WINDOWS\system32\svchost.exe[916] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02A90FC6
.text C:\WINDOWS\system32\svchost.exe[916] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02A80000
.text C:\WINDOWS\system32\svchost.exe[916] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 02A70FE5
.text C:\WINDOWS\system32\svchost.exe[916] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 02A70000
.text C:\WINDOWS\system32\svchost.exe[916] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 02A70011
.text C:\WINDOWS\system32\svchost.exe[916] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 02A70FC0
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01390000
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01390F99
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0139008E
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0139007D
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01390FC0
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01390051
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 013900A9
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01390F61
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01390F1A
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01390F2B
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 013900D8
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01390062
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01390025
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01390F88
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01390FE5
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01390036
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01390F46
.text C:\WINDOWS\system32\svchost.exe[1008] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01380FB2
.text C:\WINDOWS\system32\svchost.exe[1008] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01380F86
.text C:\WINDOWS\system32\svchost.exe[1008] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01380FCD
.text C:\WINDOWS\system32\svchost.exe[1008] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01380FDE
.text C:\WINDOWS\system32\svchost.exe[1008] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01380F97
.text C:\WINDOWS\system32\svchost.exe[1008] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01380FEF
.text C:\WINDOWS\system32\svchost.exe[1008] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 01380039
.text C:\WINDOWS\system32\svchost.exe[1008] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01380028
.text C:\WINDOWS\system32\svchost.exe[1008] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01370051
.text C:\WINDOWS\system32\svchost.exe[1008] msvcrt.dll!system 77C293C7 5 Bytes JMP 01370036
.text C:\WINDOWS\system32\svchost.exe[1008] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0137001B
.text C:\WINDOWS\system32\svchost.exe[1008] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01370000
.text C:\WINDOWS\system32\svchost.exe[1008] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01370FBC
.text C:\WINDOWS\system32\svchost.exe[1008] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01370FE3
.text C:\WINDOWS\system32\svchost.exe[1008] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01360FE5
.text C:\WINDOWS\system32\svchost.exe[1008] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00FF0000
.text C:\WINDOWS\system32\svchost.exe[1008] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00FF0FEF
.text C:\WINDOWS\system32\svchost.exe[1008] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00FF0FD4
.text C:\WINDOWS\system32\svchost.exe[1008] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00FF0FB9
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02D8000A
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02D80F8D
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02D80082
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02D80071
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02D80FA8
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02D8004A
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02D80F57
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02D80F72
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02D80F3C
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02D800D5
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02D80F2B
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02D80FC3
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02D80FEF
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02D8009D
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02D80039
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02D80FDE
.text C:\WINDOWS\System32\svchost.exe[1052] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02D800BA
.text C:\WINDOWS\System32\svchost.exe[1052] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02D70047
.text C:\WINDOWS\System32\svchost.exe[1052] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 02D70FCA
.text C:\WINDOWS\System32\svchost.exe[1052] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 02D7002C
.text C:\WINDOWS\System32\svchost.exe[1052] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 02D70011
.text C:\WINDOWS\System32\svchost.exe[1052] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02D70087
.text C:\WINDOWS\System32\svchost.exe[1052] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 02D70000
.text C:\WINDOWS\System32\svchost.exe[1052] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 02D7006C
.text C:\WINDOWS\System32\svchost.exe[1052] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02D70FDB
.text C:\WINDOWS\System32\svchost.exe[1052] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02D60FA1
.text C:\WINDOWS\System32\svchost.exe[1052] msvcrt.dll!system 77C293C7 5 Bytes JMP 02D60FB2
.text C:\WINDOWS\System32\svchost.exe[1052] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02D60FD7
.text C:\WINDOWS\System32\svchost.exe[1052] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02D60000
.text C:\WINDOWS\System32\svchost.exe[1052] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02D60022
.text C:\WINDOWS\System32\svchost.exe[1052] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02D60011
.text C:\WINDOWS\System32\svchost.exe[1052] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02D50000
.text C:\WINDOWS\System32\svchost.exe[1052] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 02D40FE5
.text C:\WINDOWS\System32\svchost.exe[1052] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 02D40000
.text C:\WINDOWS\System32\svchost.exe[1052] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 02D4001B
.text C:\WINDOWS\System32\svchost.exe[1052] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 02D40FCA
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00EF0000
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00EF00A9
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00EF008E
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00EF0FB6
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00EF0069
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00EF0FC7
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00EF0F72
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00EF0F83
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00EF0F57
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00EF00F0
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00EF0F3C
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00EF0058
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00EF0011
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00EF00BA
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00EF0033
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00EF0022
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00EF00D5
.text C:\WINDOWS\system32\svchost.exe[1096] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00DB0FDB
.text C:\WINDOWS\system32\svchost.exe[1096] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00DB0FA5
.text C:\WINDOWS\system32\svchost.exe[1096] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00DB002C
.text C:\WINDOWS\system32\svchost.exe[1096] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00DB001B
.text C:\WINDOWS\system32\svchost.exe[1096] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00DB0062
.text C:\WINDOWS\system32\svchost.exe[1096] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00DB000A
.text C:\WINDOWS\system32\svchost.exe[1096] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00DB0047
.text C:\WINDOWS\system32\svchost.exe[1096] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00DB0FB6
.text C:\WINDOWS\system32\svchost.exe[1096] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00DA0058
.text C:\WINDOWS\system32\svchost.exe[1096] msvcrt.dll!system 77C293C7 5 Bytes JMP 00DA0FC3
.text C:\WINDOWS\system32\svchost.exe[1096] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00DA0FEF
.text C:\WINDOWS\system32\svchost.exe[1096] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00DA0000
.text C:\WINDOWS\system32\svchost.exe[1096] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00DA0FD4
.text C:\WINDOWS\system32\svchost.exe[1096] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00DA0029
.text C:\WINDOWS\system32\svchost.exe[1096] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00D90FEF
.text C:\WINDOWS\system32\svchost.exe[1096] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00D80FE5
.text C:\WINDOWS\system32\svchost.exe[1096] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00D80FD4
.text C:\WINDOWS\system32\svchost.exe[1096] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00D80FAF
.text C:\WINDOWS\system32\svchost.exe[1096] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00D80000
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00EC0FEF
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00EC0082
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00EC0071
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00EC0F97
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00EC0054
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00EC0FA8
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00EC0F61
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00EC0F72
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00EC00CB
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00EC00BA
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00EC0F17
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00EC002F
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00EC0FDE
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00EC009D
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00EC0FB9
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00EC000A
.text C:\WINDOWS\system32\svchost.exe[1244] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00EC0F3C
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00EB0FC0
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00EB0F65
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00EB001B
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00EB0FE5
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00EB002C
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00EB0000
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00EB0F94
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [0B, 89]
.text C:\WINDOWS\system32\svchost.exe[1244] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00EB0FAF
.text C:\WINDOWS\system32\svchost.exe[1244] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00EA0FB7
.text C:\WINDOWS\system32\svchost.exe[1244] msvcrt.dll!system 77C293C7 5 Bytes JMP 00EA0042
.text C:\WINDOWS\system32\svchost.exe[1244] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00EA0FD2
.text C:\WINDOWS\system32\svchost.exe[1244] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00EA0000
.text C:\WINDOWS\system32\svchost.exe[1244] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00EA0031
.text C:\WINDOWS\system32\svchost.exe[1244] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00EA0FE3
.text C:\WINDOWS\system32\svchost.exe[1244] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00E90000
.text C:\WINDOWS\system32\svchost.exe[1244] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00E8000A
.text C:\WINDOWS\system32\svchost.exe[1244] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00E8001B
.text C:\WINDOWS\system32\svchost.exe[1244] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00E80036
.text C:\WINDOWS\system32\svchost.exe[1244] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00E80FE5
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E30000
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E30F99
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E30FB4
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E3008E
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E30FD1
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E30062
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E30F61
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E300A9
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E30F2B
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E300C4
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00E300D5
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00E30073
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00E3001B
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00E30F7E
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00E30047
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00E30036
.text C:\WINDOWS\system32\svchost.exe[1280] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00E30F46
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00E2002F
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00E20FB2
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00E20FD4
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00E20FE5
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00E2006F
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00E20000
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00E20FC3
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [02, 89]
.text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00E20040
.text C:\WINDOWS\system32\svchost.exe[1280] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E10FB9
.text C:\WINDOWS\system32\svchost.exe[1280] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E10044
.text C:\WINDOWS\system32\svchost.exe[1280] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E10FDE
.text C:\WINDOWS\system32\svchost.exe[1280] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E10000
.text C:\WINDOWS\system32\svchost.exe[1280] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E10033
.text C:\WINDOWS\system32\svchost.exe[1280] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E10FEF
.text C:\WINDOWS\system32\svchost.exe[1280] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00E0000A
.text C:\WINDOWS\system32\svchost.exe[1280] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00BD000A
.text C:\WINDOWS\system32\svchost.exe[1280] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00BD0FEF
.text C:\WINDOWS\system32\svchost.exe[1280] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00BD0FDE
.text C:\WINDOWS\system32\svchost.exe[1280] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00BD0FCD
.text C:\WINDOWS\system32\spoolsv.exe[1392] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00D6000A
.text C:\WINDOWS\system32\spoolsv.exe[1392] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00D7000A
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00EA0FE5
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00EA0F3C
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00EA0F57
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00EA0F68
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00EA0025
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00EA0F9E
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00EA0F06
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00EA0042
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00EA0EEB
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00EA0084
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00EA009F
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00EA0F8D
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00EA0FD4
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00EA0F21
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00EA0FB9
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00EA0014
.text C:\WINDOWS\system32\svchost.exe[1476] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00EA0069
.text C:\WINDOWS\system32\svchost.exe[1476] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00DB0051
.text C:\WINDOWS\system32\svchost.exe[1476] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00DB0FC7
.text C:\WINDOWS\system32\svchost.exe[1476] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00DB0036
.text C:\WINDOWS\system32\svchost.exe[1476] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00DB001B
.text C:\WINDOWS\system32\svchost.exe[1476] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00DB008E
.text C:\WINDOWS\system32\svchost.exe[1476] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00DB0000
.text C:\WINDOWS\system32\svchost.exe[1476] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00DB007D
.text C:\WINDOWS\system32\svchost.exe[1476] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00DB006C
.text C:\WINDOWS\system32\svchost.exe[1476] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00DA0FC3
.text C:\WINDOWS\system32\svchost.exe[1476] msvcrt.dll!system 77C293C7 5 Bytes JMP 00DA0FD4
.text C:\WINDOWS\system32\svchost.exe[1476] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00DA0029
.text C:\WINDOWS\system32\svchost.exe[1476] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00DA0FEF
.text C:\WINDOWS\system32\svchost.exe[1476] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00DA004E
.text C:\WINDOWS\system32\svchost.exe[1476] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00DA000C
.text C:\WINDOWS\system32\svchost.exe[1476] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00D9000A
.text C:\WINDOWS\system32\svchost.exe[1476] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00D80FEF
.text C:\WINDOWS\system32\svchost.exe[1476] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00D8000A
.text C:\WINDOWS\system32\svchost.exe[1476] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00D80025
.text C:\WINDOWS\system32\svchost.exe[1476] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00D80040
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1520] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00B9000A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1520] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00BA000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1536] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00BD000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1536] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00BE000A
.text C:\Program Files\McAfee\SiteAdvisor\McSACore.exe[1588] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00E5000A
.text C:\Program Files\McAfee\SiteAdvisor\McSACore.exe[1588] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00E6000A
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1652] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00C6000A
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1652] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00C7000A
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1692] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00E0000A
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1692] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00E1000A
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1768] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00BE000A
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1768] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00BF000A
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1768] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C130 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1768] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0041C1B0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[1808] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00B9000A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[1808] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00BA000A
.text c:\PROGRA~1\mcafee.com\agent\mcagent.exe[1884] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00EC000A
.text c:\PROGRA~1\mcafee.com\agent\mcagent.exe[1884] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00ED000A
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 015B0FEF
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 015B006C
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 015B0F77
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 015B0051
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 015B0040
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 015B0F9E
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 015B0F3F
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 015B0087
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 015B0F13
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 015B00AC
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 015B0F02
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 015B002F
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 015B000A
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 015B0F66
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 015B0FB9
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 015B0FD4
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 015B0F2E
.text C:\WINDOWS\system32\svchost.exe[1920] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 015A0FD4
.text C:\WINDOWS\system32\svchost.exe[1920] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 015A0FA8
.text C:\WINDOWS\system32\svchost.exe[1920] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 015A0FE5
.text C:\WINDOWS\system32\svchost.exe[1920] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 015A001B
.text C:\WINDOWS\system32\svchost.exe[1920] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 015A0FB9
.text C:\WINDOWS\system32\svchost.exe[1920] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 015A0000
.text C:\WINDOWS\system32\svchost.exe[1920] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 015A0051
.text C:\WINDOWS\system32\svchost.exe[1920] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 015A0040
.text C:\WINDOWS\system32\svchost.exe[1920] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01590FCD
.text C:\WINDOWS\system32\svchost.exe[1920] msvcrt.dll!system 77C293C7 5 Bytes JMP 01590FDE
.text C:\WINDOWS\system32\svchost.exe[1920] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01590FEF
.text C:\WINDOWS\system32\svchost.exe[1920] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01590000
.text C:\WINDOWS\system32\svchost.exe[1920] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01590044
.text C:\WINDOWS\system32\svchost.exe[1920] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0159001D
.text C:\WINDOWS\system32\svchost.exe[1920] WS2_32.dll!socket 71AB4211 5 Bytes JMP 0158000A
.text C:\WINDOWS\system32\svchost.exe[1920] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 01570000
.text C:\WINDOWS\system32\svchost.exe[1920] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 01570025
.text C:\WINDOWS\system32\svchost.exe[1920] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 01570FE5
.text C:\WINDOWS\system32\svchost.exe[1920] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 01570FD4
.text C:\Program Files\iTunes\iTunesHelper.exe[2116] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00E4000A
.text C:\Program Files\iTunes\iTunesHelper.exe[2116] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00E5000A
.text C:\WINDOWS\system32\hkcmd.exe[2144] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00E7000A
.text C:\WINDOWS\system32\hkcmd.exe[2144] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00E8000A
.text C:\WINDOWS\system32\igfxpers.exe[2168] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00E1000A
.text C:\WINDOWS\system32\igfxpers.exe[2168] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00E2000A
.text C:\WINDOWS\RTHDCPL.EXE[2184] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 01FB000A
.text C:\WINDOWS\RTHDCPL.EXE[2184] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 01FC000A
.text C:\WINDOWS\system32\igfxsrvc.exe[2252] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00E2000A
.text C:\WINDOWS\system32\igfxsrvc.exe[2252] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00E3000A
.text C:\WINDOWS\system32\ctfmon.exe[2264] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00D7000A
.text C:\WINDOWS\system32\ctfmon.exe[2264] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00D8000A
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2536] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00C5000A
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2536] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00C6000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0100000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0101000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00290FE5
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00290067
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00290F72
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00290F83
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00290F94
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00290FAF
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00290F1F
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00290F46
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00290EFD
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 0029008C
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 002900A7
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00290036
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00290000
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00290F57
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0029001B
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00290FD4
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00290F0E
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0038001B
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00380F83
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0038000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00380FDE
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00380036
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00380FEF
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00380F94
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [58, 88]
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00380FAF
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9261 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DC8A9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED2C4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254254 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E40B6CB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E40B5FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E40B668 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E40B4CE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E40B530 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E40B72E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E40B592 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00390FB7
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] msvcrt.dll!system 77C293C7 5 Bytes JMP 00390038
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0039001D
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0039000C
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00390FD2
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00390FE3
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2ED320 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 10011DE0
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00A50FEF
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10011C20
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011C00
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10011BE0
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] WININET.dll!HttpAddRequestHeadersA 3D94D02E 5 Bytes JMP 010C000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] WININET.dll!HttpAddRequestHeadersW 3D94FF29 5 Bytes JMP 011D000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00D50FEF
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00D5000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00D50FDE
.text C:\Program Files\Internet Explorer\Iexplore.exe[2584] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00D50FC3
.text C:\WINDOWS\System32\alg.exe[2636] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00B1000A
.text C:\WINDOWS\System32\alg.exe[2636] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00B2000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0100000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0103000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00290FE5
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00290F37
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0029002C
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0029001B
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00290F68
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00290F94
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00290EEE
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00290F09
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00290EB1
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00290EC2
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00290E96
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00290F83
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00290000
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00290F26
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00290FAF
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00290FC0
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00290EDD
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0038002F
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00380087
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00380FD4
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0038000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00380076
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00380FEF
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0038005B
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0038004A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED2C4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E40B6CB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E40B5FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E40B668 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E40B4CE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E40B530 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E40B72E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E40B592 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00390070
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] msvcrt.dll!system 77C293C7 5 Bytes JMP 00390FEF
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00390044
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0039000C
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0039005F
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00390029
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 10011DE0
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00A50FEF
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10011C20
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011C00
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10011BE0
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] WININET.dll!HttpAddRequestHeadersA 3D94D02E 5 Bytes JMP 010E000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] WININET.dll!HttpAddRequestHeadersW 3D94FF29 5 Bytes JMP 011F000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00D50000
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00D50FE5
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00D50FD4
.text C:\Program Files\Internet Explorer\Iexplore.exe[2824] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00D50025
.text C:\Program Files\iPod\bin\iPodService.exe[3012] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00C1000A
.text C:\Program Files\iPod\bin\iPodService.exe[3012] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00C2000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0100000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0101000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00290000
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00290F94
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00290FAF
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0029007D
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0029006C
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00290FCA
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 002900CB
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 002900AE
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00290F4D
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 002900E6
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00290F32
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00290051
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0029001B
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00290F83
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00290FDB
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0029002C
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00290F68
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00380FC3
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00380FB2
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0038000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00380FD4
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00380065
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00380FEF
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00380054
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00380039
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED2C4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E40B6CB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E40B5FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E40B668 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E40B4CE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E40B530 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E40B72E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E40B592 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0039003B
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] msvcrt.dll!system 77C293C7 5 Bytes JMP 00390FB0
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00390FC1
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00390FE3
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00390016
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00390FD2
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 10011DE0
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00A50000
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10011C20
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011C00
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10011BE0
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] WININET.dll!HttpAddRequestHeadersA 3D94D02E 5 Bytes JMP 010C000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] WININET.dll!HttpAddRequestHeadersW 3D94FF29 5 Bytes JMP 011D000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00D50FEF
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00D50FDE
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00D5000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3856] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00D50FC3
.text C:\Documents and Settings\Chris\Desktop\g-mer\g-mer.exe[3968] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00EA000A
.text C:\Documents and Settings\Chris\Desktop\g-mer\g-mer.exe[3968] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00EB000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0100000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0101000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00290000
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00290F48
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00290F6D
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00290F7E
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0029003D
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0029002C
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 0029007F
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00290058
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00290F12
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 002900AB
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 002900D0
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00290F9B
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00290011
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00290F2D
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00290FC0
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00290FD1
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00290090
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0038002C
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00380FA5
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00380011
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00380FE5
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00380FC0
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00380000
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00380058
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00380047
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9261 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DC8A9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED2C4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254254 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E40B6CB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E40B5FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E40B668 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E40B4CE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E40B530 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E40B72E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E40B592 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0039005D
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] msvcrt.dll!system 77C293C7 5 Bytes JMP 00390FD2
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00390FE3
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00390000
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00390042
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0039001D
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2ED320 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 10011DE0
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00A50FEF
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10011C20
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011C00
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10011BE0
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] WININET.dll!HttpAddRequestHeadersA 3D94D02E 5 Bytes JMP 010C000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] WININET.dll!HttpAddRequestHeadersW 3D94FF29 5 Bytes JMP 011D000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] WININET.dll!InternetOpenA 3D95D6C0 5 Bytes JMP 00D50FE5
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] WININET.dll!InternetOpenW 3D95DB39 5 Bytes JMP 00D50FD4
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] WININET.dll!InternetOpenUrlA 3D95F3D4 5 Bytes JMP 00D50000
.text C:\Program Files\Internet Explorer\Iexplore.exe[3992] WININET.dll!InternetOpenUrlW 3D9A6DD7 5 Bytes JMP 00D5001B

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Program Files\Internet Explorer\Iexplore.exe[2584] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1A7B] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\Iexplore.exe[3992] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1A7B] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
—- Processes - GMER 1.0.15 —-

Library \\?\globalroot\systemroot\system32\UAClnosytwdsi.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [916] 0x03060000

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR

—- EOF - GMER 1.0.15 —-

DDS.txt


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 20:19:35.25 on Wed 07/22/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3062.2466 [GMT -5:00]

AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Chris\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
TB: {6F4F95AF-1647-4B72-A632-055405455423} - No File
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [LXCYCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXCYtime.dll,_RunDLLEntry@16
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [net] "c:\windows\system32\net.net"
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\pokerstars.net\PokerStarsUpdate.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1242083466796
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\chris\applic~1\mozilla\firefox\profiles\dnkh6hm4.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - component: c:\documents and settings\chris\application data\mozilla\firefox\profiles\dnkh6hm4.default\extensions\[removed]\components\coolirisstub.dll
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\chris\application data\mozilla\firefox\profiles\dnkh6hm4.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\documents and settings\chris\application data\mozilla\firefox\profiles\dnkh6hm4.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-7-21 64160]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2009-5-11 13696]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-1-16 214024]
R2 CFSDrv;CFSDrv;c:\program files\protect folder plus\CFSDrv.sys [2008-1-2 10240]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-4-9 210216]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-4-9 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-4-9 144704]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-4-9 79880]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-4-9 35272]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456]
S3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;c:\windows\system32\drivers\l251x86.sys [2007-12-4 29696]
S3 CamdAudio;CamdAudio;c:\windows\system32\drivers\CamdAudio.sys [2009-4-7 23096]
S3 CamdVideo;CamdVideo;c:\windows\system32\drivers\CamdVideo.sys [2009-4-7 3768]
S3 DbusAudio;DbusAudio;c:\windows\system32\drivers\DbusAudio.sys [2009-4-7 23096]
S3 DbusVideo;DbusVideo;c:\windows\system32\drivers\DbusVideo.sys [2009-4-7 3768]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-4-9 34216]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-4-9 40552]
S3 rtl8180;Realtek RTL8180 Wireless LAN (Mini-)PCI NIC NT Driver;c:\windows\system32\drivers\RTL8180.sys [2004-3-18 185216]
S3 V90drv;v90drv;c:\windows\system32\drivers\v90drv.sys [2001-11-29 1432836]
S4 CFSService;CFSService;c:\program files\protect folder plus\CFSSvc.exe [2008-1-2 179712]
S4 lxcy_device;lxcy_device;c:\windows\system32\lxcycoms.exe -service –> c:\windows\system32\lxcycoms.exe -service [?]
S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-4-9 606736]

=============== Created Last 30 ================

2009-07-21 23:25 –dsh— c:\documents and settings\chris\PrivacIE
2009-07-21 23:24 –dsh— c:\documents and settings\chris\IETldCache
2009-07-21 23:23 –d—– c:\windows\ie8updates
2009-07-21 23:22 -cd-h— c:\windows\ie8
2009-07-21 23:20 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll
2009-07-21 23:20 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll
2009-07-21 23:20 1,985,024 -c—— c:\windows\system32\dllcache\iertutil.dll
2009-07-21 23:20 11,064,832 -c—— c:\windows\system32\dllcache\ieframe.dll
2009-07-21 22:37 15,688 a——- c:\windows\system32\lsdelete.exe
2009-07-21 22:30 64,160 a——- c:\windows\system32\drivers\Lbd.sys
2009-07-21 22:30 -cd-h— c:\docume~1\alluse~1\applic~1\{EF63305C-BAD7-4144-9208-D65528260864}
2009-07-21 22:30 –d—– c:\program files\Lavasoft
2009-07-21 22:05 –d—– c:\program files\Adware Professional
2009-07-21 21:50 40,960 a——- c:\windows\system32\geyekrqjiructk.dll
2009-07-21 21:49 –d—– c:\docume~1\chris\applic~1\Messenger
2009-07-09 19:27 1,700,352 a——- c:\windows\system32\GdiPlus.dll

==================== Find3M ====================

2009-06-16 09:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 09:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-03 14:09 1,291,264 a——- c:\windows\system32\quartz.dll
2009-05-13 00:15 915,456 a——- c:\windows\system32\wininet.dll
2009-05-11 17:54 319,488 a——- c:\windows\HideWin.exe
2009-05-11 17:33 22,748 a——- c:\windows\system32\emptyregdb.dat
2009-05-07 10:32 345,600 a——- c:\windows\system32\localspl.dll
2008-07-06 12:28 87,608 a——- c:\docume~1\chris\applic~1\inst.exe
2008-07-06 12:28 47,360 a——- c:\docume~1\chris\applic~1\pcouffin.sys
2008-07-06 12:28 81,920 a——- c:\docume~1\chris\applic~1\ezpinst.exe

============= FINISH: 20:20:45.12 ===============

Attach.txt

📎Attach.txt

I hope I did this correctly. Thanks again.

EDIT: After looking at the dates in the .txt files, I've discovered that my system clock is set to Wed. July 22 2009. I'm not sure if this is a symptom of my problem, or if it was an error on my part that I haven't noticed until now.
Hi lucky_1_chris,

You can reset your clock after we are done.

After you download this next tool, please disable McAffee with the following instructions:

How to disable McAfee:

  • Please open McAfee Security Centre
  • Under Common Tasks click on Home
  • Click Computer Files
  • Click Configure
  • Make sure the following are disabled by ticking the "Off" button.
    • Virus protection
    • Spyware protection
    • System Guards Protection
    • Script Scanning Protection (you may have to scroll down to see it)
  • Next, set it when it should resume (30 minutes should be sufficient) or you choose Never, and re-enable manually after ComboFix has completed it's tasks.
  • and click OK.
Firewall is disabled from the Internet and Network link on the left.



Please read through the instructions to familiarize yourself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]

[external image: Posted Image]

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.Close all other windows/browser first.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do Not run combofix more than once. If you have problems please post back for further instructions.
3.CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • combofix log
How's the computer?

Thanks
The computer is actin' a little weird. It took a few tries to get Windows to boot. I'm hearing mysterious noises that sound like the mouse has clicked on something when I haven't clicked anything. A few minutes ago I got some weird music playing that I have no idea where it's coming from. The music stopped when I disabled my internet connection. I still have an alert on my screen asking me if I want to make IE my default browser, even though I haven't tried to open it…. Other than that, it doesn't seem to be running slow. Thanks for the quick response, I'll post the log as soon as it's finished.
ComboFix log:

ComboFix 09-07-21.03 - Chris 07/22/2009 22:54.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3062.2581 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Chris\APPLIC~1\inst.exe
c:\program files\Adware Professional
c:\program files\Adware Professional\noadware4_072009.na
c:\windows\system32\drivers\UACpbabrsntit.sys
c:\windows\system32\geyekrqjiructk.dll
c:\windows\system32\UACekxwpdmikx.dll
c:\windows\system32\UAChwbrprrvky.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UAClnosytwdsi.dll
c:\windows\system32\UACmbcjpwticq.dat
c:\windows\system32\UACngxlmitliu.dll
c:\windows\system32\UACqukarmtteq.dll
c:\windows\system32\UACxufxwbpxdu.db

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-06-23 to 2009-07-23 )))))))))))))))))))))))))))))))
.

2009-07-22 04:25 . 2009-07-22 04:25 ——– d-sh–w- c:\documents and settings\Chris\PrivacIE
2009-07-22 04:24 . 2009-07-22 04:24 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-07-22 04:24 . 2009-07-22 04:24 ——– d-sh–w- c:\documents and settings\Chris\IETldCache
2009-07-22 04:23 . 2009-07-22 04:23 ——– d—–w- c:\windows\ie8updates
2009-07-22 04:22 . 2009-07-22 04:22 ——– dc-h–w- c:\windows\ie8
2009-07-22 04:20 . 2009-04-30 21:22 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-07-22 04:20 . 2009-04-30 21:22 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-07-22 04:20 . 2009-04-30 21:22 1985024 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2009-07-22 04:20 . 2009-04-30 21:22 11064832 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2009-07-22 03:37 . 2009-07-03 14:49 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-07-22 03:30 . 2009-07-03 14:49 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-07-22 03:30 . 2009-07-22 03:30 ——– dc-h–w- c:\docume~1\ALLUSE~1\APPLIC~1\{EF63305C-BAD7-4144-9208-D65528260864}
2009-07-22 03:30 . 2009-07-22 03:30 ——– d—–w- c:\program files\Lavasoft
2009-07-22 02:49 . 2009-07-22 02:49 ——– d—–w- c:\docume~1\Chris\APPLIC~1\Messenger
2009-07-10 00:27 . 2007-02-27 23:36 1700352 —-a-w- c:\windows\system32\GdiPlus.dll
2009-07-10 00:13 . 2009-07-10 00:13 ——– d—–w- c:\documents and settings\Chris\Local Settings\Application Data\WMTools Downloaded Files
2009-06-25 21:44 . 2009-06-25 21:44 ——– d—–w- c:\program files\QuickTime

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-22 04:15 . 2009-03-31 04:02 ——– d—–w- c:\docume~1\Chris\APPLIC~1\Orbit
2009-07-22 04:09 . 2009-03-31 04:46 ——– d—–w- c:\program files\Yahoo!
2009-07-22 04:09 . 2009-03-31 03:57 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Yahoo!
2009-07-22 03:44 . 2009-06-21 03:00 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2009-07-19 05:00 . 2009-03-31 04:43 ——– d—–w- c:\program files\PokerStars.NET
2009-07-12 01:40 . 2009-03-31 03:09 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\McAfee
2009-07-11 22:33 . 2009-04-09 05:33 ——– d—–w- c:\program files\McAfee
2009-07-10 00:28 . 2009-03-31 04:33 ——– d—–w- c:\program files\AVS4YOU
2009-07-10 00:28 . 2009-03-31 04:34 ——– d—–w- c:\program files\Common Files\AVSMedia
2009-07-01 01:18 . 2009-03-31 04:30 ——– d—–w- c:\documents and settings\LocalService\Application Data\SACore
2009-06-27 08:29 . 2009-05-12 23:40 ——– d—–w- c:\program files\SpeedFan
2009-06-21 03:36 . 2007-12-04 06:46 16056 —-a-w- c:\documents and settings\Chris\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-21 03:29 . 2009-06-21 03:29 ——– d—–w- c:\program files\Common Files\Windows Live
2009-06-21 03:00 . 2009-03-31 04:02 ——– d–h–w- c:\docume~1\Chris\APPLIC~1\yahoo!
2009-06-16 14:36 . 2006-02-28 12:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2006-02-28 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:09 . 2006-02-28 12:00 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-05-13 05:15 . 2006-02-28 12:00 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-11 22:54 . 2007-12-04 06:27 319488 —-a-w- c:\windows\HideWin.exe
2009-05-11 22:47 . 2008-12-17 11:42 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-05-11 22:33 . 2007-12-04 06:13 22748 —-a-w- c:\windows\system32\emptyregdb.dat
2009-05-07 15:32 . 2006-02-28 12:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-07-19 02:54 . 2008-11-11 08:13 134648 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-09-09 04:08 279944 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-09 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-09 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXCYCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll" [2006-11-21 106496]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-09 645328]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-10-09 17021440]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"SLService"=2 (0x2)
"NMIndexingService"=3 (0x3)
"NBService"=3 (0x3)
"lxcy_device"=2 (0x2)
"iPod Service"=3 (0x3)
"idsvc"=3 (0x3)
"CFSService"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"aawservice"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5339:TCP"= 5339:TCP:listening port
"6346:TCP"= 6346:TCP:lime

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/21/2009 10:30 PM 64160]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [5/11/2009 5:50 PM 13696]
R2 CFSDrv;CFSDrv;c:\program files\Protect Folder Plus\CFSDrv.sys [1/2/2008 3:49 AM 10240]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1029456]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [4/9/2009 12:36 AM 210216]
S3 CamdAudio;CamdAudio;c:\windows\system32\drivers\CamdAudio.sys [4/7/2009 9:17 PM 23096]
S3 CamdVideo;CamdVideo;c:\windows\system32\drivers\CamdVideo.sys [4/7/2009 9:17 PM 3768]
S3 DbusAudio;DbusAudio;c:\windows\system32\drivers\DbusAudio.sys [4/7/2009 9:49 PM 23096]
S3 DbusVideo;DbusVideo;c:\windows\system32\drivers\DbusVideo.sys [4/7/2009 9:49 PM 3768]
S3 rtl8180;Realtek RTL8180 Wireless LAN (Mini-)PCI NIC NT Driver;c:\windows\system32\drivers\RTL8180.sys [3/18/2004 2:26 PM 185216]
S3 V90drv;v90drv;c:\windows\system32\drivers\v90drv.sys [11/29/2001 6:10 PM 1432836]
S4 CFSService;CFSService;c:\program files\Protect Folder Plus\CFSSvc.exe [1/2/2008 3:49 AM 179712]
S4 lxcy_device;lxcy_device;c:\windows\system32\lxcycoms.exe -service –> c:\windows\system32\lxcycoms.exe -service [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-msnmsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe
HKLM-Run-net - c:\windows\system32\net.net


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe
Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - c:\docume~1\Chris\APPLIC~1\Mozilla\Firefox\Profiles\dnkh6hm4.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - component: c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\dnkh6hm4.default\extensions\[removed]\components\coolirisstub.dll
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\dnkh6hm4.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\dnkh6hm4.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

—- FIREFOX POLICIES —-
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-22 22:57
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCYCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-07-23 22:58
ComboFix-quarantined-files.txt 2009-07-23 03:58

Pre-Run: 272,028,143,616 bytes free
Post-Run: 272,008,777,728 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

185 — E O F — 2009-07-16 08:05
Hi

Please be advised that a rootkit has been removd from you computer. This infection may have allowed remote access to your computer.

I strongly suggest you do the following immediately:
  • From a know clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.

A few minutes ago I got some weird music playing that I have no idea where it's coming from. The music stopped when I disabled my internet connection

You posted this before the combofix log. Is this still happening?

I still have an alert on my screen asking me if I want to make IE my default browser

Do you still get these?

Internet Explorer: No Addons" in Start>All Programs>Accessories>System Tools

Normal.



Download: DelDomains and save it to the desktop.
  • Close all open windows and your browser
  • Right Click DelDomains.inf and select > Install
  • Reboot your computer
Internet Explorer is needed to run this program properly.



You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • answer to questions
  • MBAM log
  • new DDS log
Just the DDS.txt this time.

Thanks
To question 1. It hasn't happened since I ran ComboFix Question 2. Hasn't happened since I ran ComboFix Couple things of note before I post the log from Malware Bytes. I didn't disable Mcaffee before I ran Malware Bytes. After Malware Bytes completed its scan and I hit 'remove all', Mcaffee popped up with an alert that a Potentially Unwanted Program was running on the computer. I thought it might be Malware Bytes, so I ignored the alert. I honestly didn't remember to disable Mcaffee and Ad-Aware before I ran the scan, and I hope it's not an issue. I hope I haven't messed anything up… Also, when I ran ComboFix, it ran for a minute or so and gave me a list of files that it was removing and said it needed to reboot Windows to complete the process. It asked me to write down the file names because I might need them later. After running Malware Bytes, it needed to reboot windows to complete the removal process, as well. While Windows was restarting, I got a screen that said it was running chkdsk before Windows could start. Toward the end of that process I noticed that chkdsk said it was recovering orphaned files, and they were the same files that ComboFix asked me to write down for later use except each one had .vir on the end. I hope this hasn't been a setback. Here is the Malware Bytes log: Malwarebytes' Anti-Malware 1.39 Database version: 2477 Windows 5.1.2600 Service Pack 3 7/23/2009 12:33:31 AM mbam-log-2009-07-23 (00-33-31).txt Scan type: Quick Scan Objects scanned: 94012 Time elapsed: 2 minute(s), 30 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 3 Files Infected: 4 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\Chris\Application Data\Messenger\Drivers (Trojan.Agent.M) -> Quarantined and deleted successfully. c:\documents and settings\Chris\application data\messenger\Drivers\Aud32 (Trojan.Agent.M) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Application Data\Messenger\Sys (Trojan.Agent.M) -> Quarantined and deleted successfully. Files Infected: c:\documents and settings\Chris\application data\messenger\Drivers\conf.sys (Trojan.Agent.M) -> Quarantined and deleted successfully. c:\documents and settings\Chris\application data\messenger\Drivers\IgfxSys.dll (Trojan.Agent.M) -> Quarantined and deleted successfully. c:\documents and settings\Chris\application data\messenger\Drivers\pub.dll (Trojan.Agent.M) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Local Settings\Temp\db.exe (Trojan.Downloader) -> Delete on reboot. I really hope that when chkdsk ran it didn't set us back. Here are the file names that ComboFix had me write down: C:\WINDOWS\system32\drivers\UACpbqbrsntit.sys C:\WINDOWS\system32\drivers\UACekxwpdmikx.dll C:\WINDOWS\system32\drivers\UACmbcjpwticq.dat C:\WINDOWS\system32\drivers\UAChwbrprrvyk.dll C:\WINDOWS\system32\drivers\UACxufxwbpxdu.db C:\WINDOWS\system32\drivers\UAClnosytwdsi.dll C:\WINDOWS\system32\drivers\UACngxlmitliu.dll C:\WINDOWS\system32\drivers\UACqukarmtteq.dll When chkdsk ran, it said it was recovering orphaned files by the same names except with .vir at the end. Example: C:\WINDOWS\system32\drivers\UACqukarmtteq.dll.vir
Hi lucky_1_chris,

If they have a .vir on the end they are combofix's quaratine files so we should be ok. Let's see if we can find out why checkdisk would try to replace them.



Please download MBR.exe and save it to your desktop

Double click on the MBR.exe file to run it.

A log will be produced, MBR.log.
Please open this log in Notepad and post its contents in your next reply.

I need a new DDS log. If you don't still have DDS.scr on your desktop, you can get a copy from HERE


Please post back with the MBR log and the DDS.txt

Thanks
MBR log:

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.6 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK

DDS.txt


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 1:16:56.82 on Thu 07/23/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3062.2569 [GMT -5:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Documents and Settings\Chris\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [LXCYCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXCYtime.dll,_RunDLLEntry@16
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\pokerstars.net\PokerStarsUpdate.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1242083466796
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\chris\applic~1\mozilla\firefox\profiles\dnkh6hm4.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - component: c:\documents and settings\chris\application data\mozilla\firefox\profiles\dnkh6hm4.default\extensions\[removed]\components\coolirisstub.dll
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\chris\application data\mozilla\firefox\profiles\dnkh6hm4.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\documents and settings\chris\application data\mozilla\firefox\profiles\dnkh6hm4.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-7-21 64160]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2009-5-11 13696]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-1-16 214024]
R2 CFSDrv;CFSDrv;c:\program files\protect folder plus\CFSDrv.sys [2008-1-2 10240]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-4-9 210216]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-4-9 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-4-9 144704]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-4-9 79880]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-4-9 35272]
S0 kcdhimys;kcdhimys;c:\windows\system32\drivers\dcgozfm.sys –> c:\windows\system32\drivers\dcgozfm.sys [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456]
S3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;c:\windows\system32\drivers\l251x86.sys [2007-12-4 29696]
S3 CamdAudio;CamdAudio;c:\windows\system32\drivers\CamdAudio.sys [2009-4-7 23096]
S3 CamdVideo;CamdVideo;c:\windows\system32\drivers\CamdVideo.sys [2009-4-7 3768]
S3 DbusAudio;DbusAudio;c:\windows\system32\drivers\DbusAudio.sys [2009-4-7 23096]
S3 DbusVideo;DbusVideo;c:\windows\system32\drivers\DbusVideo.sys [2009-4-7 3768]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-4-9 34216]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-4-9 40552]
S3 rtl8180;Realtek RTL8180 Wireless LAN (Mini-)PCI NIC NT Driver;c:\windows\system32\drivers\RTL8180.sys [2004-3-18 185216]
S3 V90drv;v90drv;c:\windows\system32\drivers\v90drv.sys [2001-11-29 1432836]
S4 CFSService;CFSService;c:\program files\protect folder plus\CFSSvc.exe [2008-1-2 179712]
S4 lxcy_device;lxcy_device;c:\windows\system32\lxcycoms.exe -service –> c:\windows\system32\lxcycoms.exe -service [?]
S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-4-9 606736]

=============== Created Last 30 ================

2009-07-23 00:25 –d—– c:\docume~1\chris\applic~1\Malwarebytes
2009-07-23 00:25 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-23 00:25 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-07-23 00:25 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-07-23 00:25 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-22 22:58 -cd—– c:\windows\system32\dllcache\cache
2009-07-22 22:41 a-dshr– C:\cmdcons
2009-07-22 22:39 –ds—- C:\Combo-Fix
2009-07-22 22:35 219,648 a——- c:\windows\PEV.exe
2009-07-22 22:35 161,792 a——- c:\windows\SWREG.exe
2009-07-22 22:35 98,816 a——- c:\windows\sed.exe
2009-07-21 23:25 –dsh— c:\documents and settings\chris\PrivacIE
2009-07-21 23:24 –dsh— c:\documents and settings\chris\IETldCache
2009-07-21 23:23 –d—– c:\windows\ie8updates
2009-07-21 23:22 -cd-h— c:\windows\ie8
2009-07-21 23:20 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll
2009-07-21 23:20 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll
2009-07-21 23:20 1,985,024 -c—— c:\windows\system32\dllcache\iertutil.dll
2009-07-21 23:20 11,064,832 -c—— c:\windows\system32\dllcache\ieframe.dll
2009-07-21 22:37 15,688 a——- c:\windows\system32\lsdelete.exe
2009-07-21 22:30 64,160 a——- c:\windows\system32\drivers\Lbd.sys
2009-07-21 22:30 -cd-h— c:\docume~1\alluse~1\applic~1\{EF63305C-BAD7-4144-9208-D65528260864}
2009-07-21 22:30 –d—– c:\program files\Lavasoft
2009-07-21 21:49 –d—– c:\docume~1\chris\applic~1\Messenger
2009-07-09 19:27 1,700,352 a——- c:\windows\system32\GdiPlus.dll

==================== Find3M ====================

2009-06-16 09:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 09:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-03 14:09 1,291,264 a——- c:\windows\system32\quartz.dll
2009-05-13 00:15 915,456 a——- c:\windows\system32\wininet.dll
2009-05-11 17:54 319,488 a——- c:\windows\HideWin.exe
2009-05-11 17:33 22,748 a——- c:\windows\system32\emptyregdb.dat
2009-05-07 10:32 345,600 a——- c:\windows\system32\localspl.dll
2008-07-06 12:28 47,360 a——- c:\docume~1\chris\applic~1\pcouffin.sys
2008-07-06 12:28 81,920 a——- c:\docume~1\chris\applic~1\ezpinst.exe

============= FINISH: 1:17:09.82 ===============
Hi lucky_1_chris,

MBR is ok. I don't see those files in the log.

We will be using Combofix again but run it differently.

Please read through these instructions to familarize yourself with what to expect.

Please follow all previous instructions regarding security programs.

Use the previous instructions for disabling McAffee.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the all of the text in the code box below into the Notepad, (including the URL). Do Not copy the word CODE

http://forums.whatthetech.com/Please_help_me_remove_win32trojan_tdss_t105405.html&gopid=580598#entry580598

KillAll::

Collect::[4]
c:\windows\system32\drivers\dcgozfm.sys 

Rootkit::
c:\windows\system32\drivers\dcgozfm.sys

Driver::
kcdhimys

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


Please post back with the combofix log.

Thanks
New ComboFix Log:

ComboFix 09-07-21.03 - Chris 07/23/2009 1:43.2.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3062.2594 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Chris\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_kcdhimys


((((((((((((((((((((((((( Files Created from 2009-06-23 to 2009-07-23 )))))))))))))))))))))))))))))))
.

2009-07-23 05:25 . 2009-07-23 05:25 ——– d—–w- c:\docume~1\Chris\APPLIC~1\Malwarebytes
2009-07-23 05:25 . 2009-07-13 18:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-23 05:25 . 2009-07-23 05:25 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-23 05:25 . 2009-07-23 05:25 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Malwarebytes
2009-07-23 05:25 . 2009-07-13 18:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-22 04:25 . 2009-07-22 04:25 ——– d-sh–w- c:\documents and settings\Chris\PrivacIE
2009-07-22 04:24 . 2009-07-22 04:24 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-07-22 04:24 . 2009-07-22 04:24 ——– d-sh–w- c:\documents and settings\Chris\IETldCache
2009-07-22 04:23 . 2009-07-22 04:23 ——– d—–w- c:\windows\ie8updates
2009-07-22 04:22 . 2009-07-22 04:22 ——– dc-h–w- c:\windows\ie8
2009-07-22 04:20 . 2009-04-30 21:22 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-07-22 04:20 . 2009-04-30 21:22 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-07-22 04:20 . 2009-04-30 21:22 1985024 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2009-07-22 04:20 . 2009-04-30 21:22 11064832 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2009-07-22 03:37 . 2009-07-03 14:49 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-07-22 03:30 . 2009-07-03 14:49 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-07-22 03:30 . 2009-07-22 03:30 ——– dc-h–w- c:\docume~1\ALLUSE~1\APPLIC~1\{EF63305C-BAD7-4144-9208-D65528260864}
2009-07-22 03:30 . 2009-07-22 03:30 ——– d—–w- c:\program files\Lavasoft
2009-07-22 02:49 . 2009-07-23 05:33 ——– d—–w- c:\docume~1\Chris\APPLIC~1\Messenger
2009-07-10 00:27 . 2007-02-27 23:36 1700352 —-a-w- c:\windows\system32\GdiPlus.dll
2009-07-10 00:13 . 2009-07-10 00:13 ——– d—–w- c:\documents and settings\Chris\Local Settings\Application Data\WMTools Downloaded Files
2009-06-25 21:44 . 2009-06-25 21:44 ——– d—–w- c:\program files\QuickTime

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-22 04:15 . 2009-03-31 04:02 ——– d—–w- c:\docume~1\Chris\APPLIC~1\Orbit
2009-07-22 04:09 . 2009-03-31 04:46 ——– d—–w- c:\program files\Yahoo!
2009-07-22 04:09 . 2009-03-31 03:57 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Yahoo!
2009-07-22 03:44 . 2009-06-21 03:00 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2009-07-19 05:00 . 2009-03-31 04:43 ——– d—–w- c:\program files\PokerStars.NET
2009-07-12 01:40 . 2009-03-31 03:09 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\McAfee
2009-07-11 22:33 . 2009-04-09 05:33 ——– d—–w- c:\program files\McAfee
2009-07-10 00:28 . 2009-03-31 04:33 ——– d—–w- c:\program files\AVS4YOU
2009-07-10 00:28 . 2009-03-31 04:34 ——– d—–w- c:\program files\Common Files\AVSMedia
2009-07-01 01:18 . 2009-03-31 04:30 ——– d—–w- c:\documents and settings\LocalService\Application Data\SACore
2009-06-27 08:29 . 2009-05-12 23:40 ——– d—–w- c:\program files\SpeedFan
2009-06-21 03:36 . 2007-12-04 06:46 16056 —-a-w- c:\documents and settings\Chris\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-21 03:29 . 2009-06-21 03:29 ——– d—–w- c:\program files\Common Files\Windows Live
2009-06-21 03:00 . 2009-03-31 04:02 ——– d–h–w- c:\docume~1\Chris\APPLIC~1\yahoo!
2009-06-16 14:36 . 2006-02-28 12:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2006-02-28 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:09 . 2006-02-28 12:00 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-05-13 05:15 . 2006-02-28 12:00 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-11 22:54 . 2007-12-04 06:27 319488 —-a-w- c:\windows\HideWin.exe
2009-05-11 22:47 . 2008-12-17 11:42 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-05-11 22:33 . 2007-12-04 06:13 22748 —-a-w- c:\windows\system32\emptyregdb.dat
2009-05-07 15:32 . 2006-02-28 12:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-07-19 02:54 . 2008-11-11 08:13 134648 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-09-09 04:08 279944 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-09 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-09 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXCYCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll" [2006-11-21 106496]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-09 645328]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-10-09 17021440]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"SLService"=2 (0x2)
"NMIndexingService"=3 (0x3)
"NBService"=3 (0x3)
"lxcy_device"=2 (0x2)
"iPod Service"=3 (0x3)
"idsvc"=3 (0x3)
"CFSService"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"aawservice"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5339:TCP"= 5339:TCP:listening port
"6346:TCP"= 6346:TCP:lime

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/21/2009 10:30 PM 64160]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [5/11/2009 5:50 PM 13696]
R2 CFSDrv;CFSDrv;c:\program files\Protect Folder Plus\CFSDrv.sys [1/2/2008 3:49 AM 10240]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1029456]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [4/9/2009 12:36 AM 210216]
S3 CamdAudio;CamdAudio;c:\windows\system32\drivers\CamdAudio.sys [4/7/2009 9:17 PM 23096]
S3 CamdVideo;CamdVideo;c:\windows\system32\drivers\CamdVideo.sys [4/7/2009 9:17 PM 3768]
S3 DbusAudio;DbusAudio;c:\windows\system32\drivers\DbusAudio.sys [4/7/2009 9:49 PM 23096]
S3 DbusVideo;DbusVideo;c:\windows\system32\drivers\DbusVideo.sys [4/7/2009 9:49 PM 3768]
S3 rtl8180;Realtek RTL8180 Wireless LAN (Mini-)PCI NIC NT Driver;c:\windows\system32\drivers\RTL8180.sys [3/18/2004 2:26 PM 185216]
S3 V90drv;v90drv;c:\windows\system32\drivers\v90drv.sys [11/29/2001 6:10 PM 1432836]
S4 CFSService;CFSService;c:\program files\Protect Folder Plus\CFSSvc.exe [1/2/2008 3:49 AM 179712]
S4 lxcy_device;lxcy_device;c:\windows\system32\lxcycoms.exe -service –> c:\windows\system32\lxcycoms.exe -service [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe
FF - ProfilePath - c:\docume~1\Chris\APPLIC~1\Mozilla\Firefox\Profiles\dnkh6hm4.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - component: c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\dnkh6hm4.default\extensions\[removed]\components\coolirisstub.dll
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\dnkh6hm4.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\dnkh6hm4.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

—- FIREFOX POLICIES —-
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-23 01:48
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCYCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3216)
c:\windows\system32\WININET.dll
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\program files\Common Files\Ahead\Lib\NeroSearchBar.dll
c:\program files\Common Files\Ahead\Lib\MFC71U.DLL
c:\program files\Common Files\Ahead\Lib\BCGCBPRO860un71.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\McAfee\MPF\MpfSrv.exe
.
**************************************************************************
.
Completion time: 2009-07-23 1:51 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-23 06:51
ComboFix2.txt 2009-07-23 03:58

Pre-Run: 272,003,665,920 bytes free
Post-Run: 271,901,081,600 bytes free

196 — E O F — 2009-07-16 08:05

NOTE: On step 6a during the scan, Mcaffee's opening screen popped up after explorer restarted, and after reboot Ad-Aware reloaded. Just letting you know in case they affected the scan.
Hi lucky_1_chris,

Thanks for letting me know about your security programs, it should be ok.

You have some old vulnerable java to update.

  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java Runtime Environment (JRE) 6 Update 14"
  • Click the download button on the right.
If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.
  • Select the platform (Windows, in your case), mutli language.
  • Accept the license agreement, click continue.
You do not have to install the Java Web Start ActiveX Control
  • Scroll down and click on Windows Offline Installation,
  • Save the file jre-6u14-windows-i586-p.exe to your desktop;
Do not select Run . Do not install it yet.

When the download is complete, close your browser.

Open Control Panel > Add/Remove Programs and unininstall:

Java™ 6 Update 2
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7


Do not uninstall Java TM 6 Update 14 if found! :yeah:

Reboot your computer.

  • Double-click on the saved file ( jre-6u14-windows-i586-p.exe) to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.

Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all 3 boxes
  • Click OK

One more scan to be sure we didn't miss something.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.

Please post back with
  • Kaspersky log
  • new DDS log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI