This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Computer freezing up

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Your log is clean.

You issue doesn't appear to be malware related.
You could try switching to FireFox (link is in my closings) that may help.

Try doing a defrag of your system:

Download and run Auslogics Disc Defragmenter

That may help somewhat. If it doesn't, post a new topic in our Browsers section and see if the expert techs can assist with that.

Link back to this topic so they can see you are clean of Malware.

Right now I will clean up the tools we used and leave you with my usual closing recommendations.

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.


  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.
Hi,

When did you first experience the fake paypal page?

Is this a new symptom.

Lets have another deeper look at your system.

Please do the following:

STEP #1

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries




STEP #3

Download RootRepeal and save it to your desktop.
  • Extract RootRepeal.exe from the zip archive.
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check all six boxes: [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, click the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.

If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead.
To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
DDS (Ver_09-06-26.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 3/1/2009 6:21:54 PM
System Uptime: 7/28/2009 9:12:30 PM (1 hours ago)

Motherboard: ASUSTeK Computer INC. | | 901
Processor: Intel® Atom™ CPU N270 @ 1.60GHz | Socket 478M | 1600/133mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 4 GiB total, 0.552 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {95C7A0A0-3094-11D7-A202-00508B9D7D5A}
Description: BT-253
Device ID: USB\VID_0B05&PID_B700\0015AFF4FED1
Manufacturer: Broadcom
Name: BT-253
PNP Device ID: USB\VID_0B05&PID_B700\0015AFF4FED1
Service: BTWUSB

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================


7-Zip 4.65
Adabas D 13.01.00
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Shockwave Player 11.5
AIM 6
Asus ACPI Driver
ASUSUpdate for Eee PC
Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
avast! Antivirus
Azurewave Wireless LAN
Build Your Own Net Dream (remove only)
CCleaner (remove only)
Choice Guard
Eee Instant Key
Eusing Free Registry Cleaner
flupScript 1.5
Intel® Graphics Media Accelerator Driver
InterVideo Register Manager
InterVideo WinDVD
Java™ 6 Update 14
JGoodies JDiskReport 1.3.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 1.1 Hotfix (KB929729)
Microsoft .NET Framework 2.0
Microsoft Application Error Reporting
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4048
mIRC
MSVCRT
Realtek High Definition Audio Driver
RegCure 1.5.2.7
Security Task Manager 1.7h
Segoe UI
ShellExView
Super Hybrid Engine
WebFldrs XP
Where'd My Space Go version 1.0
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Yugioh Virtual Dueling

==== Event Viewer Messages From Past Week ========

7/28/2009 5:51:53 PM, error: Service Control Manager [7034] - The avast! Web Scanner service terminated unexpectedly. It has done this 1 time(s).
7/28/2009 5:04:19 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
7/28/2009 2:38:59 PM, error: Service Control Manager [7034] - The TCP/IP NetBIOS Helper service terminated unexpectedly. It has done this 1 time(s).
7/28/2009 2:38:59 PM, error: Service Control Manager [7034] - The SSDP Discovery Service service terminated unexpectedly. It has done this 1 time(s).
7/28/2009 2:38:59 PM, error: Service Control Manager [7034] - The Alerter service terminated unexpectedly. It has done this 1 time(s).
7/28/2009 2:38:56 PM, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/28/2009 2:28:45 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
7/27/2009 1:26:45 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.

==== End Of File ===========================


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 22:02:04.37 on Tue 07/28/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.514 [GMT -8:00]

AV: avast! antivirus 4.8.1335 [VPS 090727-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\flupScript\mirc.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Nigel Adamson\Local Settings\Temporary Internet Files\Content.IE5\H2BM4I9S\dds[1].pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://google.com/
uURLSearchHooks: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aim search\AOLSearch.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search
BHO: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aim search\AOLSearch.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [AlcWzrd] ALCWZRD.EXE
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [AsusTray] c:\program files\eeepc\acpi\AsTray.exe
mRun: [AsusACPIServer] c:\program files\eeepc\acpi\AsAcpiSvr.exe
mRun: [AsusEPCMonitor] c:\program files\eeepc\acpi\AsEPCMon.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\superh~1.lnk - c:\program files\asus\eeepc\super hybrid engine\SuperHybridEngine.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-7-28 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-7-28 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-7-28 138680]
R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [2008-5-22 11264]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-7-28 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-7-28 352920]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [2008-5-18 36864]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [2008-5-22 625024]

=============== Created Last 30 ================

2009-07-28 18:23 –d—– c:\program files\Where'd My Space Go
2009-07-28 17:19 1,060,864 a——- c:\windows\system32\MFC71.dll
2009-07-28 16:41 –d—– c:\docume~1\alluse~1\applic~1\SecTaskMan
2009-07-28 16:41 –d—– c:\program files\Security Task Manager
2009-07-28 16:34 73,728 a——- c:\windows\system32\javacpl.cpl
2009-07-28 14:59 1,033,728 a——- c:\windows\name.exe
2009-07-27 13:20 161,792 a——- c:\windows\SWREG.exe
2009-07-27 13:20 98,816 a——- c:\windows\sed.exe
2009-07-24 15:21 -cd—– c:\windows\system32\dllcache\cache
2009-07-24 15:13 a-dshr– C:\cmdcons
2009-07-24 15:11 219,648 a——- c:\windows\PEV.exe
2009-07-23 16:23 –d—– c:\program files\Trend Micro
2009-07-22 18:48 –d—– c:\docume~1\nigela~1\applic~1\SUPERAntiSpyware.com
2009-07-22 12:58 118 a——- c:\windows\system32\MRT.INI
2009-07-22 00:26 –ds—- c:\documents and settings\nigel adamson\UserData
2009-07-21 14:50 –d—– c:\docume~1\nigela~1\applic~1\Malwarebytes
2009-07-21 14:30 1,100 a——- c:\windows\system32\d3d8caps.dat
2009-07-21 14:22 272,128 -c—— c:\windows\system32\dllcache\bthport.sys
2009-07-21 14:22 272,128 ——– c:\windows\system32\drivers\bthport.sys
2009-07-21 11:37 203,136 -c—— c:\windows\system32\dllcache\rmcast.sys
2009-07-21 11:37 455,296 -c—— c:\windows\system32\dllcache\mrxsmb.sys
2009-07-21 11:36 333,952 -c—— c:\windows\system32\dllcache\srv.sys
2009-07-21 11:36 331,776 -c—— c:\windows\system32\dllcache\msadce.dll
2009-07-21 11:36 691,712 -c—— c:\windows\system32\dllcache\inetcomm.dll
2009-07-21 11:33 247,326 -c—— c:\windows\system32\dllcache\strmdll.dll
2009-07-21 11:33 337,408 -c—— c:\windows\system32\dllcache\netapi32.dll
2009-07-21 11:32 1,106,944 -c—— c:\windows\system32\dllcache\msxml3.dll
2009-07-21 11:29 2,560 ——– c:\windows\system32\xpsp4res.dll
2009-07-21 11:29 1,203,922 -c—— c:\windows\system32\dllcache\sysmain.sdb
2009-07-21 11:29 215,552 -c—— c:\windows\system32\dllcache\wordpad.exe
2009-07-21 11:27 –d—– c:\windows\system32\PreInstall
2009-07-21 11:27 26,488 a——- c:\windows\system32\spupdsvc.exe
2009-07-21 11:26 –d-h— c:\windows\$hf_mig$
2009-07-20 19:42 345,600 -c—— c:\windows\system32\dllcache\localspl.dll
2009-07-20 19:42 8,461,312 -c—— c:\windows\system32\dllcache\shell32.dll
2009-07-20 19:42 138,496 -c—— c:\windows\system32\dllcache\afd.sys
2009-07-20 19:16 –d—– c:\program files\Spybot - Search & Destroy
2009-07-20 19:16 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-07-20 18:58 268,648 a——- c:\windows\system32\mucltui.dll
2009-07-20 18:58 208,744 a——- c:\windows\system32\muweb.dll
2009-07-20 18:58 27,496 a——- c:\windows\system32\mucltui.dll.mui
2009-07-20 18:50 39,424 a——- c:\windows\zipinst.exe
2009-07-20 18:50 –d—– c:\program files\ShellExView
2009-07-20 18:10 –d—– c:\program files\Taskbar Hide
2009-07-20 14:39 –d—– c:\docume~1\nigela~1\applic~1\LimeWire
2009-07-20 12:43 –d—– c:\documents and settings\Nigel Adamson
2009-07-20 08:57 –d—– c:\windows\system32\LogFiles

==================== Find3M ====================

2009-07-28 16:32 410,984 a——- c:\windows\system32\deploytk.dll
2009-06-18 04:08 2,098 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-06-16 06:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 06:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-03 11:09 1,291,264 a——- c:\windows\system32\quartz.dll
2009-05-07 07:32 345,600 a——- c:\windows\system32\localspl.dll
2009-05-02 14:53 33,968 a—h— c:\windows\system32\mlfcache.dat
2009-03-01 16:12 32 a——- c:\docume~1\alluse~1\applic~1\ezsid.dat
2005-04-16 12:43 244,224 a–shr– c:\windows\plugin.dat

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-28 22:16:46
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xA9A5F6B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xA9A5F574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xA9A5FA52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xA9A5F14C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xA9A5F64E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xA9A5F08C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xA9A5F0F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xA9A5F76E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xA9A5F72E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xA9A5F8AE]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[336] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00BC2B80
.text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[336] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00BC2B3D
.text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[336] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00BC2B01
.text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[336] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00BC2AE6
.text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[336] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00BC2972
.text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[336] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00BC2A64
.text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[336] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00BC29AA
.text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[336] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00BC29E2
.text C:\Program Files\Java\jre6\bin\jqs.exe[376] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 02182AE6
.text C:\Program Files\Java\jre6\bin\jqs.exe[376] WS2_32.dll!send 71AB4C27 5 Bytes JMP 02182972
.text C:\Program Files\Java\jre6\bin\jqs.exe[376] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 02182A64
.text C:\Program Files\Java\jre6\bin\jqs.exe[376] WS2_32.dll!recv 71AB676F 5 Bytes JMP 021829AA
.text C:\Program Files\Java\jre6\bin\jqs.exe[376] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 021829E2
.text C:\Program Files\Java\jre6\bin\jqs.exe[376] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 02182B80
.text C:\Program Files\Java\jre6\bin\jqs.exe[376] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 02182B3D
.text C:\Program Files\Java\jre6\bin\jqs.exe[376] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 02182B01
.text C:\WINDOWS\system32\igfxtray.exe[1048] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00DB2B80
.text C:\WINDOWS\system32\igfxtray.exe[1048] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00DB2B3D
.text C:\WINDOWS\system32\igfxtray.exe[1048] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00DB2B01
.text C:\WINDOWS\system32\igfxtray.exe[1048] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00DB2AE6
.text C:\WINDOWS\system32\igfxtray.exe[1048] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00DB2972
.text C:\WINDOWS\system32\igfxtray.exe[1048] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00DB2A64
.text C:\WINDOWS\system32\igfxtray.exe[1048] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00DB29AA
.text C:\WINDOWS\system32\igfxtray.exe[1048] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00DB29E2
.text C:\WINDOWS\system32\hkcmd.exe[1068] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00DB2B80
.text C:\WINDOWS\system32\hkcmd.exe[1068] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00DB2B3D
.text C:\WINDOWS\system32\hkcmd.exe[1068] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00DB2B01
.text C:\WINDOWS\system32\hkcmd.exe[1068] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00DB2AE6
.text C:\WINDOWS\system32\hkcmd.exe[1068] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00DB2972
.text C:\WINDOWS\system32\hkcmd.exe[1068] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00DB2A64
.text C:\WINDOWS\system32\hkcmd.exe[1068] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00DB29AA
.text C:\WINDOWS\system32\hkcmd.exe[1068] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00DB29E2
.text C:\Program Files\EeePC\ACPI\AsTray.exe[1152] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 009B2B80
.text C:\Program Files\EeePC\ACPI\AsTray.exe[1152] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 009B2B3D
.text C:\Program Files\EeePC\ACPI\AsTray.exe[1152] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 009B2B01
.text C:\Program Files\EeePC\ACPI\AsTray.exe[1152] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 009B2AE6
.text C:\Program Files\EeePC\ACPI\AsTray.exe[1152] WS2_32.dll!send 71AB4C27 5 Bytes JMP 009B2972
.text C:\Program Files\EeePC\ACPI\AsTray.exe[1152] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 009B2A64
.text C:\Program Files\EeePC\ACPI\AsTray.exe[1152] WS2_32.dll!recv 71AB676F 5 Bytes JMP 009B29AA
.text C:\Program Files\EeePC\ACPI\AsTray.exe[1152] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 009B29E2
.text C:\WINDOWS\Explorer.EXE[1172] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 016C2B80
.text C:\WINDOWS\Explorer.EXE[1172] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 016C2B3D
.text C:\WINDOWS\Explorer.EXE[1172] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 016C2B01
.text C:\WINDOWS\Explorer.EXE[1172] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 016C2AE6
.text C:\WINDOWS\Explorer.EXE[1172] WS2_32.dll!send 71AB4C27 5 Bytes JMP 016C2972
.text C:\WINDOWS\Explorer.EXE[1172] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 016C2A64
.text C:\WINDOWS\Explorer.EXE[1172] WS2_32.dll!recv 71AB676F 5 Bytes JMP 016C29AA
.text C:\WINDOWS\Explorer.EXE[1172] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 016C29E2
.text C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe[1236] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00C72B80
.text C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe[1236] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00C72B3D
.text C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe[1236] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00C72B01
.text C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe[1236] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00C72AE6
.text C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe[1236] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00C72972
.text C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe[1236] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00C72A64
.text C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe[1236] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00C729AA
.text C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe[1236] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00C729E2
.text C:\WINDOWS\system32\igfxsrvc.exe[1276] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00E42B80
.text C:\WINDOWS\system32\igfxsrvc.exe[1276] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00E42B3D
.text C:\WINDOWS\system32\igfxsrvc.exe[1276] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00E42B01
.text C:\WINDOWS\system32\igfxsrvc.exe[1276] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00E42AE6
.text C:\WINDOWS\system32\igfxsrvc.exe[1276] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00E42972
.text C:\WINDOWS\system32\igfxsrvc.exe[1276] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00E42A64
.text C:\WINDOWS\system32\igfxsrvc.exe[1276] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00E429AA
.text C:\WINDOWS\system32\igfxsrvc.exe[1276] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00E429E2
.text C:\WINDOWS\system32\igfxext.exe[1364] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00E62B80
.text C:\WINDOWS\system32\igfxext.exe[1364] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00E62B3D
.text C:\WINDOWS\system32\igfxext.exe[1364] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00E62B01
.text C:\WINDOWS\system32\igfxext.exe[1364] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00E62AE6
.text C:\WINDOWS\system32\igfxext.exe[1364] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00E62972
.text C:\WINDOWS\system32\igfxext.exe[1364] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00E62A64
.text C:\WINDOWS\system32\igfxext.exe[1364] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00E629AA
.text C:\WINDOWS\system32\igfxext.exe[1364] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00E629E2
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1420] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 02442B80
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1420] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 02442B3D
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1420] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 02442B01
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1420] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 02442AE6
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1420] WS2_32.dll!send 71AB4C27 5 Bytes JMP 02442972
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1420] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 02442A64
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1420] WS2_32.dll!recv 71AB676F 5 Bytes JMP 024429AA
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1420] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 024429E2
.text C:\WINDOWS\system32\wuauclt.exe[1556] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00DE2B80
.text C:\WINDOWS\system32\wuauclt.exe[1556] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00DE2B3D
.text C:\WINDOWS\system32\wuauclt.exe[1556] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00DE2B01
.text C:\WINDOWS\system32\wuauclt.exe[1556] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00DE2AE6
.text C:\WINDOWS\system32\wuauclt.exe[1556] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00DE2972
.text C:\WINDOWS\system32\wuauclt.exe[1556] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00DE2A64
.text C:\WINDOWS\system32\wuauclt.exe[1556] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00DE29AA
.text C:\WINDOWS\system32\wuauclt.exe[1556] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00DE29E2
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1612] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 012D2B80
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1612] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 012D2B3D
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1612] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 012D2B01
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1612] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 012D2AE6
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1612] WS2_32.dll!send 71AB4C27 5 Bytes JMP 012D2972
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1612] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 012D2A64
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1612] WS2_32.dll!recv 71AB676F 5 Bytes JMP 012D29AA
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1612] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 012D29E2
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2152] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01972AE6
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2152] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01972972
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2152] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01972A64
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2152] WS2_32.dll!recv 71AB676F 5 Bytes JMP 019729AA
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2152] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 019729E2
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2152] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01972B80
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2152] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01972B3D
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2152] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01972B01
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2200] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 06892AE6
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2200] WS2_32.dll!send 71AB4C27 5 Bytes JMP 06892972
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2200] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 06892A64
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2200] WS2_32.dll!recv 71AB676F 5 Bytes JMP 068929AA
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2200] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 068929E2
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2200] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 06892B80
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2200] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 06892B3D
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2200] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 06892B01
.text C:\WINDOWS\System32\alg.exe[2656] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00B52B80
.text C:\WINDOWS\System32\alg.exe[2656] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00B52B3D
.text C:\WINDOWS\System32\alg.exe[2656] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00B52B01
.text C:\WINDOWS\System32\alg.exe[2656] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00B52AE6
.text C:\WINDOWS\System32\alg.exe[2656] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00B52972
.text C:\WINDOWS\System32\alg.exe[2656] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00B52A64
.text C:\WINDOWS\System32\alg.exe[2656] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00B529AA
.text C:\WINDOWS\System32\alg.exe[2656] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00B529E2
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3112] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00CC2B80
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3112] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00CC2B3D
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3112] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00CC2B01
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3112] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00CC2AE6
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3112] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00CC2972
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3112] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00CC2A64
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3112] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00CC29AA
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3112] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00CC29E2
.text C:\Program Files\flupScript\mirc.exe[3412] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01322B80
.text C:\Program Files\flupScript\mirc.exe[3412] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01322B3D
.text C:\Program Files\flupScript\mirc.exe[3412] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01322B01
.text C:\Program Files\flupScript\mirc.exe[3412] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01322AE6
.text C:\Program Files\flupScript\mirc.exe[3412] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01322972
.text C:\Program Files\flupScript\mirc.exe[3412] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01322A64
.text C:\Program Files\flupScript\mirc.exe[3412] WS2_32.dll!recv 71AB676F 5 Bytes JMP 013229AA
.text C:\Program Files\flupScript\mirc.exe[3412] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 013229E2
.text C:\Program Files\internet explorer\iexplore.exe[3592] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01972B80
.text C:\Program Files\internet explorer\iexplore.exe[3592] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01972B3D
.text C:\Program Files\internet explorer\iexplore.exe[3592] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01972B01
.text C:\Program Files\internet explorer\iexplore.exe[3592] CRYPT32.dll!CertGetCertificateChain 77A92F67 5 Bytes JMP 019735D4
.text C:\Program Files\internet explorer\iexplore.exe[3592] CRYPT32.dll!CertVerifyCertificateChainPolicy 77A9B76F 5 Bytes JMP 019735DD
.text C:\Program Files\internet explorer\iexplore.exe[3592] WININET.dll!HttpOpenRequestA 771C2B01 5 Bytes JMP 01972DD5
.text C:\Program Files\internet explorer\iexplore.exe[3592] WININET.dll!InternetConnectA 771C345A 5 Bytes JMP 01972B9B
.text C:\Program Files\internet explorer\iexplore.exe[3592] WININET.dll!InternetCloseHandle 771C4D94 5 Bytes JMP 019730DD
.text C:\Program Files\internet explorer\iexplore.exe[3592] WININET.dll!HttpSendRequestA 771C60A9 5 Bytes JMP 01972F41
.text C:\Program Files\internet explorer\iexplore.exe[3592] WININET.dll!InternetReadFile 771C82F2 5 Bytes JMP 01973088
.text C:\Program Files\internet explorer\iexplore.exe[3592] WININET.dll!HttpSendRequestW 7721303C 5 Bytes JMP 01973A57

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\WINDOWS\system32\services.exe[756] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[756] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\ACPI \Device\00000040 8580C1C0
Device \Driver\ACPI \Device\00000041 8580C1C0
Device \Driver\ACPI \Device\00000050 8580C1C0
Device \Driver\ACPI \Device\00000044 8580C1C0
Device \Driver\ACPI \Device\00000051 8580C1C0
Device \Driver\ACPI \Device\00000045 8580C1C0
Device \Driver\ACPI \Device\00000060 8580C1C0
Device \Driver\ACPI \Device\00000047 8580C1C0
Device \Driver\ACPI \Device\00000061 8580C1C0

AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\ACPI \Device\00000063 8580C1C0
Device \Driver\ACPI \Device\00000057 8580C1C0
Device \Driver\ACPI \Device\00000058 8580C1C0
Device \Driver\ACPI \Device\00000064 8580C1C0
Device \Driver\ACPI \Device\00000059 8580C1C0
Device \Driver\ACPI \Device\0000003b 8580C1C0
Device \Driver\ACPI \Device\0000003c 8580C1C0
Device \Driver\ACPI \Device\0000003d 8580C1C0
Device \Driver\ACPI \Device\0000003f 8580C1C0
Device \Driver\ACPI \Device\0000004c 8580C1C0
Device \Driver\ACPI \Device\0000004d 8580C1C0
Device \Driver\ACPI \Device\0000004e 8580C1C0
Device \Driver\ACPI \Device\0000005c 8580C1C0
Device \Driver\ACPI \Device\0000004f 8580C1C0

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

—- Threads - GMER 1.0.15 —-

Thread System [4:124] 858421A0
Thread System [4:144] 8582CF9F
Thread System [4:136] 85860517
Thread System [4:148] 8582FC11
Thread System [4:3904] 858421A0
Thread System [4:1780] 8582CF9F
Thread System [4:2280] 85860517
Thread System [4:2328] 8582FC11

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\@P_9}\2ó7}\x90\x203aó\0\4ï\xb8\0Nô7}\x90\x203aó\0\24ï\xb8\0v`,}X_9}L\t ?j??????????h?H??j????G???Wj?j?h I???U???}?P???C???Ph?a??h?;?

—- EOF - GMER 1.0.15 —-

============= FINISH: 22:02:37.14 ===============
Hey, thanks for taking the time to help me again. I don't know how long my computer has been infected with the paypal redirecting, but I tried to log-in not so long after this was resolved. After I logged in, it would redirect me to an obvious fraud site asking for my details due to "security reasons". For some reason the other scanner won't operate correctly, it pops up with various errors.
Hi,

Please run this scanner instead:

Please download Sysprot Antirootkit from here

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.

  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select all items.
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to.
  • Open the text file and copy/paste the log here.
SysProt AntiRootkit v1.0.1.0 by swatkat ******************************************************************************** ********** ******************************************************************************** ********** Process: Name: [System Idle Process] PID: 0 Hidden: No Window Visible: No Name: System PID: 4 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\smss.exe PID: 636 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\csrss.exe PID: 684 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\winlogon.exe PID: 712 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\services.exe PID: 756 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\lsass.exe PID: 768 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 940 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 984 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1076 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1184 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1216 Hidden: No Window Visible: No Name: C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe PID: 1320 Hidden: No Window Visible: No Name: C:\Program Files\Alwil Software\Avast4\ashServ.exe PID: 1420 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\spoolsv.exe PID: 208 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1752 Hidden: No Window Visible: No Name: C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe PID: 336 Hidden: No Window Visible: No Name: C:\Program Files\Java\jre6\bin\jqs.exe PID: 376 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 484 Hidden: No Window Visible: No Name: C:\WINDOWS\RTHDCPL.exe PID: 556 Hidden: No Window Visible: No Name: C:\WINDOWS\SoundMan.exe PID: 948 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\igfxtray.exe PID: 1048 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\hkcmd.exe PID: 1068 Hidden: No Window Visible: No Name: C:\Program Files\EeePC\ACPI\AsTray.exe PID: 1152 Hidden: No Window Visible: No Name: C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe PID: 1236 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\igfxsrvc.exe PID: 1276 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\igfxext.exe PID: 1364 Hidden: No Window Visible: No Name: C:\Program Files\EeePC\ACPI\AsEPCMon.exe PID: 1352 Hidden: No Window Visible: No Name: C:\Program Files\Java\jre6\bin\jusched.exe PID: 1456 Hidden: No Window Visible: No Name: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe PID: 1612 Hidden: No Window Visible: No Name: C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe PID: 2108 Hidden: No Window Visible: No Name: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe PID: 2152 Hidden: No Window Visible: No Name: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe PID: 2200 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\alg.exe PID: 2656 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\wbem\wmiapsrv.exe PID: 3112 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 3476 Hidden: No Window Visible: No Name: C:\Program Files\Internet Explorer\IEXPLORE.EXE PID: 3592 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\wuauclt.exe PID: 1556 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\wscntfy.exe PID: 2972 Hidden: No Window Visible: No Name: C:\WINDOWS\explorer.exe PID: 1620 Hidden: No Window Visible: No Name: C:\Documents and Settings\Nigel Adamson\Desktop\SysProt\SysProt\SysProt.exe PID: 2780 Hidden: No Window Visible: Yes Name: C:\WINDOWS\system32\services.exe PID: 4 Hidden: Yes Window Visible: No Name: C:\WINDOWS\system32\services.exe PID: 4 Hidden: Yes Window Visible: No Name: C:\WINDOWS\system32\services.exe PID: 4 Hidden: Yes Window Visible: No Name: C:\WINDOWS\system32\services.exe PID: 4 Hidden: Yes Window Visible: No Name: C:\WINDOWS\system32\services.exe PID: 4 Hidden: Yes Window Visible: No Name: C:\WINDOWS\system32\services.exe PID: 4 Hidden: Yes Window Visible: No Name: C:\WINDOWS\system32\services.exe PID: 4 Hidden: Yes Window Visible: No Name: C:\WINDOWS\system32\services.exe PID: 4 Hidden: Yes Window Visible: No Name: C:\WINDOWS\system32\services.exe PID: 4 Hidden: Yes Window Visible: No Name: C:\WINDOWS\system32\services.exe PID: 4 Hidden: Yes Window Visible: No Name: C:\WINDOWS\system32\services.exe PID: 4 Hidden: Yes Window Visible: No Name: C:\WINDOWS\system32\services.exe PID: 4 Hidden: Yes Window Visible: No ******************************************************************************** ********** ******************************************************************************** ********** Kernel Modules: Module Name: \??\C:\Documents and Settings\Nigel Adamson\Desktop\SysProt\SysProt\SysProtDrv.sys Service Name: SysProtDrv.sys Module Base: A871B000 Module End: A8726000 Hidden: No Module Name: \WINDOWS\system32\ntkrnlpa.exe Service Name: — Module Base: 804D7000 Module End: 806E4000 Hidden: No Module Name: \WINDOWS\system32\hal.dll Service Name: — Module Base: 806E4000 Module End: 80704D00 Hidden: No Module Name: \WINDOWS\system32\KDCOM.DLL Service Name: — Module Base: F7A88000 Module End: F7A8A000 Hidden: No Module Name: \WINDOWS\system32\BOOTVID.dll Service Name: — Module Base: F7998000 Module End: F799B000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ACPI.sys Service Name: ACPI Module Base: F7459000 Module End: F7487000 Hidden: No Module Name: \WINDOWS\system32\DRIVERS\WMILIB.SYS Service Name: — Module Base: F7A8A000 Module End: F7A8C000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\pci.sys Service Name: PCI Module Base: F7448000 Module End: F7459000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\isapnp.sys Service Name: isapnp Module Base: F7588000 Module End: F7592000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\compbatt.sys Service Name: Compbatt Module Base: F799C000 Module End: F799F000 Hidden: No Module Name: \WINDOWS\system32\DRIVERS\BATTC.SYS Service Name: BattC Module Base: F79A0000 Module End: F79A4000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\pciide.sys Service Name: PCIIde Module Base: F7B50000 Module End: F7B51000 Hidden: No Module Name: \WINDOWS\system32\DRIVERS\PCIIDEX.SYS Service Name: — Module Base: F7808000 Module End: F780F000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\MountMgr.sys Service Name: MountMgr Module Base: F7598000 Module End: F75A3000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ftdisk.sys Service Name: Disk Module Base: F7429000 Module End: F7448000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ACPIEC.sys Service Name: ACPIEC Module Base: F79A4000 Module End: F79A7000 Hidden: No Module Name: \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS Service Name: — Module Base: F7B51000 Module End: F7B52000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\PartMgr.sys Service Name: PartMgr Module Base: F7810000 Module End: F7815000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\VolSnap.sys Service Name: VolSnap Module Base: F75A8000 Module End: F75B5000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\atapi.sys Service Name: atapi Module Base: F7411000 Module End: F7429000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\disk.sys Service Name: — Module Base: F75B8000 Module End: F75C1000 Hidden: No Module Name: \WINDOWS\system32\DRIVERS\CLASSPNP.SYS Service Name: — Module Base: F75C8000 Module End: F75D5000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\fltMgr.sys Service Name: FltMgr Module Base: F73F1000 Module End: F7411000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\KSecDD.sys Service Name: KSecDD Module Base: F73DA000 Module End: F73F1000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\Ntfs.sys Service Name: Ntfs Module Base: F734D000 Module End: F73DA000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\NDIS.sys Service Name: NDIS Module Base: F7320000 Module End: F734D000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\Mup.sys Service Name: Mup Module Base: F7306000 Module End: F7320000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\intelppm.sys Service Name: intelppm Module Base: F7698000 Module End: F76A1000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\igxpmp32.sys Service Name: ialm Module Base: F6D28000 Module End: F72BE000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS Service Name: — Module Base: F6D14000 Module End: F6D28000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\HDAudBus.sys Service Name: HDAudBus Module Base: F6CEC000 Module End: F6D14000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\l1e51x86.sys Service Name: L1e Module Base: F76A8000 Module End: F76B5000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\RT2860.sys Service Name: RT80x86 Module Base: F6C53000 Module End: F6CEC000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\usbuhci.sys Service Name: usbuhci Module Base: F7870000 Module End: F7876000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS Service Name: — Module Base: F6C2F000 Module End: F6C53000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\usbehci.sys Service Name: usbehci Module Base: F7878000 Module End: F7880000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\i8042prt.sys Service Name: i8042prt Module Base: F76B8000 Module End: F76C5000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\kbdclass.sys Service Name: Kbdclass Module Base: F7880000 Module End: F7886000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\mouclass.sys Service Name: Mouclass Module Base: F7888000 Module End: F788E000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\CmBatt.sys Service Name: CmBatt Module Base: F7A38000 Module End: F7A3C000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ASUSACPI.sys Service Name: AsusACPI Module Base: F7A3C000 Module End: F7A3F000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\audstub.sys Service Name: audstub Module Base: F7CAA000 Module End: F7CAB000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys Service Name: Rasl2tp Module Base: F76C8000 Module End: F76D5000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ndistapi.sys Service Name: NdisTapi Module Base: F7A40000 Module End: F7A43000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ndiswan.sys Service Name: NdisWan Module Base: F6C18000 Module End: F6C2F000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\raspppoe.sys Service Name: RasPppoe Module Base: F76D8000 Module End: F76E3000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\raspptp.sys Service Name: PptpMiniport Module Base: F76E8000 Module End: F76F4000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\TDI.SYS Service Name: — Module Base: F7890000 Module End: F7895000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\psched.sys Service Name: PSched Module Base: F6C07000 Module End: F6C18000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\msgpc.sys Service Name: Gpc Module Base: F76F8000 Module End: F7701000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ptilink.sys Service Name: Ptilink Module Base: F7898000 Module End: F789D000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\raspti.sys Service Name: Raspti Module Base: F78A0000 Module End: F78A5000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\termdd.sys Service Name: TermDD Module Base: F7708000 Module End: F7712000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\swenum.sys Service Name: swenum Module Base: F7AA0000 Module End: F7AA2000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ks.sys Service Name: — Module Base: F6BE4000 Module End: F6C07000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\update.sys Service Name: Update Module Base: F6B46000 Module End: F6BA4000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\mssmbios.sys Service Name: mssmbios Module Base: F7A54000 Module End: F7A58000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\NDProxy.SYS Service Name: NDProxy Module Base: F7718000 Module End: F7722000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\usbhub.sys Service Name: usbhub Module Base: F7768000 Module End: F7777000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\USBD.SYS Service Name: — Module Base: F7AA6000 Module End: F7AA8000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\RtkHDAud.sys Service Name: IntcAzAudAddService Module Base: AA083000 Module End: AA530000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\portcls.sys Service Name: — Module Base: AA05F000 Module End: AA083000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\drmk.sys Service Name: — Module Base: F7778000 Module End: F7787000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS Service Name: Fs_Rec Module Base: F7AB0000 Module End: F7AB2000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Null.SYS Service Name: Null Module Base: F7C49000 Module End: F7C4A000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Beep.SYS Service Name: Beep Module Base: F7AB2000 Module End: F7AB4000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\vga.sys Service Name: VgaSave Module Base: F78E8000 Module End: F78EE000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\mnmdd.SYS Service Name: mnmdd Module Base: F7AB4000 Module End: F7AB6000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys Service Name: RDPCDD Module Base: F7AB6000 Module End: F7AB8000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Msfs.SYS Service Name: Msfs Module Base: F78F0000 Module End: F78F5000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Npfs.SYS Service Name: Npfs Module Base: F78F8000 Module End: F7900000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\rasacd.sys Service Name: RasAcd Module Base: F7A2C000 Module End: F7A2F000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ipsec.sys Service Name: IPSec Module Base: A9C88000 Module End: A9C9B000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\tcpip.sys Service Name: Tcpip Module Base: A9C2F000 Module End: A9C88000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\aswTdi.SYS Service Name: aswTdi Module Base: F77A8000 Module End: F77B3000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ipnat.sys Service Name: IpNat Module Base: A9C09000 Module End: A9C2F000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\netbt.sys Service Name: NetBT Module Base: A9BE1000 Module End: A9C09000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\afd.sys Service Name: AFD Module Base: A9BBF000 Module End: A9BE1000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\netbios.sys Service Name: NetBIOS Module Base: F77B8000 Module End: F77C1000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\rdbss.sys Service Name: Rdbss Module Base: A9B94000 Module End: A9BBF000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys Service Name: MRxSmb Module Base: A9AFC000 Module End: A9B6C000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Fips.SYS Service Name: Fips Module Base: F77E8000 Module End: F77F3000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\aswSP.SYS Service Name: aswSP Module Base: A9A57000 Module End: A9A78000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Aavmker4.SYS Service Name: Aavmker4 Module Base: F7900000 Module End: F7905000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\wanarp.sys Service Name: Wanarp Module Base: F7618000 Module End: F7621000 Hidden: No Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys Service Name: — Module Base: A9A3F000 Module End: A9A57000 Hidden: Yes Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS Service Name: — Module Base: F7ABC000 Module End: F7ABE000 Hidden: Yes Module Name: C:\WINDOWS\System32\drivers\Dxapi.sys Service Name: — Module Base: AA043000 Module End: AA046000 Hidden: No Module Name: C:\WINDOWS\System32\watchdog.sys Service Name: — Module Base: F7920000 Module End: F7925000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\dxgthk.sys Service Name: — Module Base: F7C75000 Module End: F7C76000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys Service Name: aswFsBlk Module Base: F7938000 Module End: F7940000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ndisuio.sys Service Name: Ndisuio Module Base: A9943000 Module End: A9947000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\aswMon2.SYS Service Name: aswMon2 Module Base: A97A9000 Module End: A97BF000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\wdmaud.sys Service Name: wdmaud Module Base: A944C000 Module End: A9461000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\sysaudio.sys Service Name: sysaudio Module Base: A9A2F000 Module End: A9A3E000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\mrxdav.sys Service Name: MRxDAV Module Base: A9199000 Module End: A91C6000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\srv.sys Service Name: Srv Module Base: A911F000 Module End: A9171000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\HTTP.sys Service Name: HTTP Module Base: A8C7E000 Module End: A8CBF000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\aswRdr.SYS Service Name: aswRdr Module Base: A8C46000 Module End: A8C4A000 Hidden: No Module Name: \??\C:\DOCUME~1\NIGELA~1\LOCALS~1\Temp\aujasnkj.sys Service Name: aujasnkj Module Base: A8587000 Module End: A859B000 Hidden: Yes Module Name: C:\WINDOWS\system32\drivers\kmixer.sys Service Name: kmixer Module Base: A855C000 Module End: A8587000 Hidden: No ******************************************************************************** ********** ******************************************************************************** ********** SSDT: Function Name: ZwClose Address: A9A5F6B8 Driver Base: A9A57000 Driver End: A9A78000 Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS Function Name: ZwCreateKey Address: A9A5F574 Driver Base: A9A57000 Driver End: A9A78000 Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS Function Name: ZwDeleteValueKey Address: A9A5FA52 Driver Base: A9A57000 Driver End: A9A78000 Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS Function Name: ZwDuplicateObject Address: A9A5F14C Driver Base: A9A57000 Driver End: A9A78000 Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS Function Name: ZwOpenKey Address: A9A5F64E Driver Base: A9A57000 Driver End: A9A78000 Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS Function Name: ZwOpenProcess Address: A9A5F08C Driver Base: A9A57000 Driver End: A9A78000 Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS Function Name: ZwOpenThread Address: A9A5F0F0 Driver Base: A9A57000 Driver End: A9A78000 Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS Function Name: ZwQueryValueKey Address: A9A5F76E Driver Base: A9A57000 Driver End: A9A78000 Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS Function Name: ZwRestoreKey Address: A9A5F72E Driver Base: A9A57000 Driver End: A9A78000 Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS Function Name: ZwSetValueKey Address: A9A5F8AE Driver Base: A9A57000 Driver End: A9A78000 Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS ******************************************************************************** ********** ******************************************************************************** ********** No Kernel Hooks found ******************************************************************************** ********** ******************************************************************************** ********** IRP Hooks: Hooked Module: C:\WINDOWS\system32\drivers\ACPI.sys Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL Jump To: 8580C1C0 Hooking Module: _unknown_ ******************************************************************************** ********** ******************************************************************************** ********** Ports: Local Address: YOUR-AHPMBZIK7E:2869 Remote Address: 192.168.0.1:4436 Type: TCP Process: C:\WINDOWS\system32\svchost.exe State: CLOSE_WAIT Local Address: YOUR-AHPMBZIK7E:2818 Remote Address: WY-IN-F164.GOOGLE.COM:HTTP Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: YOUR-AHPMBZIK7E:2814 Remote Address: WY-IN-F157.GOOGLE.COM:HTTP Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: YOUR-AHPMBZIK7E:2812 Remote Address: WY-IN-F157.GOOGLE.COM:HTTP Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: YOUR-AHPMBZIK7E:2806 Remote Address: WY-IN-F102.GOOGLE.COM:HTTP Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: YOUR-AHPMBZIK7E:2804 Remote Address: WY-IN-F103.GOOGLE.COM:HTTP Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: YOUR-AHPMBZIK7E:2802 Remote Address: WY-IN-F103.GOOGLE.COM:HTTP Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: YOUR-AHPMBZIK7E:2800 Remote Address: WY-IN-F101.GOOGLE.COM:HTTP Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: YOUR-AHPMBZIK7E:2771 Remote Address: WY-IN-F100.GOOGLE.COM:HTTP Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: YOUR-AHPMBZIK7E:1169 Remote Address: A92-122-209-201.DEPLOY.AKAMAITECHNOLOGIES.COM:HTTP Type: TCP Process: C:\Program Files\Java\jre6\bin\jusched.exe State: CLOSE_WAIT Local Address: YOUR-AHPMBZIK7E:NETBIOS-SSN Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: YOUR-AHPMBZIK7E:12143 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe State: LISTENING Local Address: YOUR-AHPMBZIK7E:12119 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe State: LISTENING Local Address: YOUR-AHPMBZIK7E:12110 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe State: LISTENING Local Address: YOUR-AHPMBZIK7E:12080 Remote Address: LOCALHOST:2839 Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: YOUR-AHPMBZIK7E:12080 Remote Address: LOCALHOST:2837 Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: YOUR-AHPMBZIK7E:12080 Remote Address: LOCALHOST:2835 Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: YOUR-AHPMBZIK7E:12080 Remote Address: LOCALHOST:2831 Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: YOUR-AHPMBZIK7E:12080 Remote Address: LOCALHOST:2829 Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: YOUR-AHPMBZIK7E:12080 Remote Address: LOCALHOST:2827 Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: YOUR-AHPMBZIK7E:12080 Remote Address: LOCALHOST:2821 Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: YOUR-AHPMBZIK7E:12080 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe State: LISTENING Local Address: YOUR-AHPMBZIK7E:12025 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe State: LISTENING Local Address: YOUR-AHPMBZIK7E:5152 Remote Address: LOCALHOST:2843 Type: TCP Process: C:\Program Files\Java\jre6\bin\jqs.exe State: CLOSE_WAIT Local Address: YOUR-AHPMBZIK7E:5152 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Java\jre6\bin\jqs.exe State: LISTENING Local Address: YOUR-AHPMBZIK7E:2843 Remote Address: LOCALHOST:5152 Type: TCP Process: C:\Program Files\Internet Explorer\IEXPLORE.EXE State: FIN_WAIT2 Local Address: YOUR-AHPMBZIK7E:2798 Remote Address: LOCALHOST:5152 Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: YOUR-AHPMBZIK7E:1029 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\system32\alg.exe State: LISTENING Local Address: YOUR-AHPMBZIK7E:3246 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\system32\services.exe State: LISTENING Local Address: YOUR-AHPMBZIK7E:2869 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\system32\svchost.exe State: LISTENING Local Address: YOUR-AHPMBZIK7E:2479 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\system32\services.exe State: LISTENING Local Address: YOUR-AHPMBZIK7E:MICROSOFT-DS Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: YOUR-AHPMBZIK7E:EPMAP Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\system32\svchost.exe State: LISTENING Local Address: YOUR-AHPMBZIK7E:1900 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: YOUR-AHPMBZIK7E:138 Remote Address: NA Type: UDP Process: System State: NA Local Address: YOUR-AHPMBZIK7E:NETBIOS-NS Remote Address: NA Type: UDP Process: System State: NA Local Address: YOUR-AHPMBZIK7E:123 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: YOUR-AHPMBZIK7E:1900 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: YOUR-AHPMBZIK7E:1048 Remote Address: NA Type: UDP Process: C:\Program Files\Internet Explorer\IEXPLORE.EXE State: NA Local Address: YOUR-AHPMBZIK7E:1036 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: YOUR-AHPMBZIK7E:123 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: YOUR-AHPMBZIK7E:4500 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\lsass.exe State: NA Local Address: YOUR-AHPMBZIK7E:500 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\lsass.exe State: NA Local Address: YOUR-AHPMBZIK7E:MICROSOFT-DS Remote Address: NA Type: UDP Process: System State: NA ******************************************************************************** ********** ******************************************************************************** ********** Hidden files/folders: Object: C:\System Volume Information\MountPointManagerRemoteDatabase Status: Access denied Object: C:\System Volume Information\tracking.log Status: Access denied
Hi,

Yes there appears there could be a new infection on board

Please do the following:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    c:\windows\name.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


where did this come from?

Security Task Manager
OK,

That clears that up then.

Let's flush your DNS first:

  • Now go to Start > Run > type: cmd
  • Press OK or Hit Enter.
  • At the command prompt, type or copy/paste: ipconfig /flushdns (note the space between “..g /f…” it needs to be there)
  • Hit Enter.
  • You will get a confirmation that the flush was successful.
  • Close the command box.

Then do an online scan:

Please do a scan with F-secure

  • Go to http://support.f-secure.com/enu/home/ols.shtml
  • Scroll to the bottom of the page and click the Start scanning button. A window will pop up.
  • Allow the Active X control to be installed on your computer, then click the Accept button
  • Click Full System Scan and allow the components to download and the scan to complete.
  • If malware is found, check Submit samples to F-Secure then select Automatic cleaning

When cleaning has finished, click Show report (this will open an Internet Explorer window containing the report)

  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post
  • If Automatic cleaning with Submit samples hangs, click Cancel, then New Scan
  • When the cleaning option is presented, Uncheck Submit samples to F-Secure
  • Click Automatic cleaning
  • When cleaning has finished, click Show report (this will open an Internet Explorer window containing the report)
  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post

Notes:
  • This scan will only work with Internet Explorer
  • You must have administrator rights to run this scan
  • This scan can take a while, so please be patient
Scanning Report Wednesday, July 29, 2009 01:36:30 - 01:53:25 Computer name: YOUR-AHPMBZIK7E Scanning type: Scan system for malware, spyware and rootkits Target: C:\ ——————————————————————————– 15 malware found TrackingCookie.Questionmarket (spyware) System (Disinfected) TrackingCookie.2o7 (spyware) System (Disinfected) TrackingCookie.Advertising (spyware) System (Disinfected) TrackingCookie.Atdmt (spyware) System (Disinfected) TrackingCookie.Adtech (spyware) System (Disinfected) TrackingCookie.Revsci (spyware) System (Disinfected) TrackingCookie.Zanox (spyware) System (Disinfected) TrackingCookie.Xiti (spyware) System (Disinfected) TrackingCookie.Webtrends (spyware) System (Disinfected) TrackingCookie.Mediaplex (spyware) System (Disinfected) TrackingCookie.Tradedoubler (spyware) System (Disinfected) TrackingCookie.Statcounter (spyware) System (Disinfected) TrackingCookie.Atwola (spyware) System (Disinfected) TrackingCookie.Yieldmanager (spyware) System (Disinfected) TrackingCookie.Imrworldwide (spyware) System (Disinfected) ——————————————————————————– Statistics Scanned: Files: 19191 System: 2474 Not scanned: 7 Actions: Disinfected: 15 Renamed: 0 Deleted: 0 Not cleaned: 0 Submitted: 0 Files not scanned: C:\PAGEFILE.SYS C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT C:\WINDOWS\SYSTEM32\CONFIG\SAM C:\WINDOWS\SYSTEM32\CONFIG\SECURITY C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBARNOTIFIER\SWG-5.1.1309.15642\SEARCHWITHGOOGLEUPDATE.EXE ——————————————————————————– Options Scanning engines: Scanning options: Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML XXX ANI AVB BAT CMD JOB LSP MAP MHT MIF PHP POT SWF WMF NWS TAR Use advanced heuristics ——————————————————————————–
Hi,

There doesn't appear to be any malware on your system

The tracking cookies are of no concern - anytime you go on the internet, you will get tracking cookies.



Please run this program, if it comes back clean, then you can go back to paws and have him check for hardware issues.

although I would be interested in the paypal site you were redirected to:

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI