DDS (Ver_09-06-26.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 3/1/2009 6:21:54 PM
System Uptime: 7/28/2009 9:12:30 PM (1 hours ago)
Motherboard: ASUSTeK Computer INC. | | 901
Processor: Intel® Atom™ CPU N270 @ 1.60GHz | Socket 478M | 1600/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 4 GiB total, 0.552 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {95C7A0A0-3094-11D7-A202-00508B9D7D5A}
Description: BT-253
Device ID: USB\VID_0B05&PID_B700\0015AFF4FED1
Manufacturer: Broadcom
Name: BT-253
PNP Device ID: USB\VID_0B05&PID_B700\0015AFF4FED1
Service: BTWUSB
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
7-Zip 4.65
Adabas D 13.01.00
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Shockwave Player 11.5
AIM 6
Asus ACPI Driver
ASUSUpdate for Eee PC
Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
avast! Antivirus
Azurewave Wireless LAN
Build Your Own Net Dream (remove only)
CCleaner (remove only)
Choice Guard
Eee Instant Key
Eusing Free Registry Cleaner
flupScript 1.5
Intel® Graphics Media Accelerator Driver
InterVideo Register Manager
InterVideo WinDVD
Java™ 6 Update 14
JGoodies JDiskReport 1.3.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 1.1 Hotfix (KB929729)
Microsoft .NET Framework 2.0
Microsoft Application Error Reporting
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4048
mIRC
MSVCRT
Realtek High Definition Audio Driver
RegCure 1.5.2.7
Security Task Manager 1.7h
Segoe UI
ShellExView
Super Hybrid Engine
WebFldrs XP
Where'd My Space Go version 1.0
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Yugioh Virtual Dueling
==== Event Viewer Messages From Past Week ========
7/28/2009 5:51:53 PM, error: Service Control Manager [7034] - The avast! Web Scanner service terminated unexpectedly. It has done this 1 time(s).
7/28/2009 5:04:19 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
7/28/2009 2:38:59 PM, error: Service Control Manager [7034] - The TCP/IP NetBIOS Helper service terminated unexpectedly. It has done this 1 time(s).
7/28/2009 2:38:59 PM, error: Service Control Manager [7034] - The SSDP Discovery Service service terminated unexpectedly. It has done this 1 time(s).
7/28/2009 2:38:59 PM, error: Service Control Manager [7034] - The Alerter service terminated unexpectedly. It has done this 1 time(s).
7/28/2009 2:38:56 PM, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/28/2009 2:28:45 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
7/27/2009 1:26:45 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
==== End Of File ===========================
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 22:02:04.37 on Tue 07/28/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.514 [GMT -8:00]
AV: avast! antivirus 4.8.1335 [VPS 090727-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\flupScript\mirc.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Nigel Adamson\Local Settings\Temporary Internet Files\Content.IE5\H2BM4I9S\dds[1].pif
============== Pseudo HJT Report ===============
uStart Page = hxxp://google.com/
uURLSearchHooks: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aim search\AOLSearch.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search
BHO: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aim search\AOLSearch.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [AlcWzrd] ALCWZRD.EXE
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [AsusTray] c:\program files\eeepc\acpi\AsTray.exe
mRun: [AsusACPIServer] c:\program files\eeepc\acpi\AsAcpiSvr.exe
mRun: [AsusEPCMonitor] c:\program files\eeepc\acpi\AsEPCMon.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\superh~1.lnk - c:\program files\asus\eeepc\super hybrid engine\SuperHybridEngine.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-7-28 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-7-28 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-7-28 138680]
R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [2008-5-22 11264]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-7-28 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-7-28 352920]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [2008-5-18 36864]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [2008-5-22 625024]
=============== Created Last 30 ================
2009-07-28 18:23 –d—– c:\program files\Where'd My Space Go
2009-07-28 17:19 1,060,864 a——- c:\windows\system32\MFC71.dll
2009-07-28 16:41 –d—– c:\docume~1\alluse~1\applic~1\SecTaskMan
2009-07-28 16:41 –d—– c:\program files\Security Task Manager
2009-07-28 16:34 73,728 a——- c:\windows\system32\javacpl.cpl
2009-07-28 14:59 1,033,728 a——- c:\windows\name.exe
2009-07-27 13:20 161,792 a——- c:\windows\SWREG.exe
2009-07-27 13:20 98,816 a——- c:\windows\sed.exe
2009-07-24 15:21 -cd—– c:\windows\system32\dllcache\cache
2009-07-24 15:13 a-dshr– C:\cmdcons
2009-07-24 15:11 219,648 a——- c:\windows\PEV.exe
2009-07-23 16:23 –d—– c:\program files\Trend Micro
2009-07-22 18:48 –d—– c:\docume~1\nigela~1\applic~1\SUPERAntiSpyware.com
2009-07-22 12:58 118 a——- c:\windows\system32\MRT.INI
2009-07-22 00:26 –ds—- c:\documents and settings\nigel adamson\UserData
2009-07-21 14:50 –d—– c:\docume~1\nigela~1\applic~1\Malwarebytes
2009-07-21 14:30 1,100 a——- c:\windows\system32\d3d8caps.dat
2009-07-21 14:22 272,128 -c—— c:\windows\system32\dllcache\bthport.sys
2009-07-21 14:22 272,128 ——– c:\windows\system32\drivers\bthport.sys
2009-07-21 11:37 203,136 -c—— c:\windows\system32\dllcache\rmcast.sys
2009-07-21 11:37 455,296 -c—— c:\windows\system32\dllcache\mrxsmb.sys
2009-07-21 11:36 333,952 -c—— c:\windows\system32\dllcache\srv.sys
2009-07-21 11:36 331,776 -c—— c:\windows\system32\dllcache\msadce.dll
2009-07-21 11:36 691,712 -c—— c:\windows\system32\dllcache\inetcomm.dll
2009-07-21 11:33 247,326 -c—— c:\windows\system32\dllcache\strmdll.dll
2009-07-21 11:33 337,408 -c—— c:\windows\system32\dllcache\netapi32.dll
2009-07-21 11:32 1,106,944 -c—— c:\windows\system32\dllcache\msxml3.dll
2009-07-21 11:29 2,560 ——– c:\windows\system32\xpsp4res.dll
2009-07-21 11:29 1,203,922 -c—— c:\windows\system32\dllcache\sysmain.sdb
2009-07-21 11:29 215,552 -c—— c:\windows\system32\dllcache\wordpad.exe
2009-07-21 11:27 –d—– c:\windows\system32\PreInstall
2009-07-21 11:27 26,488 a——- c:\windows\system32\spupdsvc.exe
2009-07-21 11:26 –d-h— c:\windows\$hf_mig$
2009-07-20 19:42 345,600 -c—— c:\windows\system32\dllcache\localspl.dll
2009-07-20 19:42 8,461,312 -c—— c:\windows\system32\dllcache\shell32.dll
2009-07-20 19:42 138,496 -c—— c:\windows\system32\dllcache\afd.sys
2009-07-20 19:16 –d—– c:\program files\Spybot - Search & Destroy
2009-07-20 19:16 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-07-20 18:58 268,648 a——- c:\windows\system32\mucltui.dll
2009-07-20 18:58 208,744 a——- c:\windows\system32\muweb.dll
2009-07-20 18:58 27,496 a——- c:\windows\system32\mucltui.dll.mui
2009-07-20 18:50 39,424 a——- c:\windows\zipinst.exe
2009-07-20 18:50 –d—– c:\program files\ShellExView
2009-07-20 18:10 –d—– c:\program files\Taskbar Hide
2009-07-20 14:39 –d—– c:\docume~1\nigela~1\applic~1\LimeWire
2009-07-20 12:43 –d—– c:\documents and settings\Nigel Adamson
2009-07-20 08:57 –d—– c:\windows\system32\LogFiles
==================== Find3M ====================
2009-07-28 16:32 410,984 a——- c:\windows\system32\deploytk.dll
2009-06-18 04:08 2,098 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-06-16 06:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 06:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-03 11:09 1,291,264 a——- c:\windows\system32\quartz.dll
2009-05-07 07:32 345,600 a——- c:\windows\system32\localspl.dll
2009-05-02 14:53 33,968 a—h— c:\windows\system32\mlfcache.dat
2009-03-01 16:12 32 a——- c:\docume~1\alluse~1\applic~1\ezsid.dat
2005-04-16 12:43 244,224 a–shr– c:\windows\plugin.dat
GMER 1.0.15.14972 -
http://www.gmer.net
Rootkit scan 2009-07-28 22:16:46
Windows 5.1.2600 Service Pack 3
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xA9A5F6B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xA9A5F574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xA9A5FA52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xA9A5F14C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xA9A5F64E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xA9A5F08C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xA9A5F0F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xA9A5F76E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xA9A5F72E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xA9A5F8AE]
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[336] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00BC2B80
.text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[336] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00BC2B3D
.text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[336] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00BC2B01
.text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[336] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00BC2AE6
.text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[336] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00BC2972
.text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[336] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00BC2A64
.text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[336] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00BC29AA
.text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[336] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00BC29E2
.text C:\Program Files\Java\jre6\bin\jqs.exe[376] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 02182AE6
.text C:\Program Files\Java\jre6\bin\jqs.exe[376] WS2_32.dll!send 71AB4C27 5 Bytes JMP 02182972
.text C:\Program Files\Java\jre6\bin\jqs.exe[376] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 02182A64
.text C:\Program Files\Java\jre6\bin\jqs.exe[376] WS2_32.dll!recv 71AB676F 5 Bytes JMP 021829AA
.text C:\Program Files\Java\jre6\bin\jqs.exe[376] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 021829E2
.text C:\Program Files\Java\jre6\bin\jqs.exe[376] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 02182B80
.text C:\Program Files\Java\jre6\bin\jqs.exe[376] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 02182B3D
.text C:\Program Files\Java\jre6\bin\jqs.exe[376] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 02182B01
.text C:\WINDOWS\system32\igfxtray.exe[1048] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00DB2B80
.text C:\WINDOWS\system32\igfxtray.exe[1048] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00DB2B3D
.text C:\WINDOWS\system32\igfxtray.exe[1048] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00DB2B01
.text C:\WINDOWS\system32\igfxtray.exe[1048] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00DB2AE6
.text C:\WINDOWS\system32\igfxtray.exe[1048] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00DB2972
.text C:\WINDOWS\system32\igfxtray.exe[1048] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00DB2A64
.text C:\WINDOWS\system32\igfxtray.exe[1048] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00DB29AA
.text C:\WINDOWS\system32\igfxtray.exe[1048] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00DB29E2
.text C:\WINDOWS\system32\hkcmd.exe[1068] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00DB2B80
.text C:\WINDOWS\system32\hkcmd.exe[1068] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00DB2B3D
.text C:\WINDOWS\system32\hkcmd.exe[1068] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00DB2B01
.text C:\WINDOWS\system32\hkcmd.exe[1068] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00DB2AE6
.text C:\WINDOWS\system32\hkcmd.exe[1068] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00DB2972
.text C:\WINDOWS\system32\hkcmd.exe[1068] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00DB2A64
.text C:\WINDOWS\system32\hkcmd.exe[1068] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00DB29AA
.text C:\WINDOWS\system32\hkcmd.exe[1068] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00DB29E2
.text C:\Program Files\EeePC\ACPI\AsTray.exe[1152] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 009B2B80
.text C:\Program Files\EeePC\ACPI\AsTray.exe[1152] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 009B2B3D
.text C:\Program Files\EeePC\ACPI\AsTray.exe[1152] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 009B2B01
.text C:\Program Files\EeePC\ACPI\AsTray.exe[1152] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 009B2AE6
.text C:\Program Files\EeePC\ACPI\AsTray.exe[1152] WS2_32.dll!send 71AB4C27 5 Bytes JMP 009B2972
.text C:\Program Files\EeePC\ACPI\AsTray.exe[1152] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 009B2A64
.text C:\Program Files\EeePC\ACPI\AsTray.exe[1152] WS2_32.dll!recv 71AB676F 5 Bytes JMP 009B29AA
.text C:\Program Files\EeePC\ACPI\AsTray.exe[1152] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 009B29E2
.text C:\WINDOWS\Explorer.EXE[1172] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 016C2B80
.text C:\WINDOWS\Explorer.EXE[1172] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 016C2B3D
.text C:\WINDOWS\Explorer.EXE[1172] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 016C2B01
.text C:\WINDOWS\Explorer.EXE[1172] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 016C2AE6
.text C:\WINDOWS\Explorer.EXE[1172] WS2_32.dll!send 71AB4C27 5 Bytes JMP 016C2972
.text C:\WINDOWS\Explorer.EXE[1172] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 016C2A64
.text C:\WINDOWS\Explorer.EXE[1172] WS2_32.dll!recv 71AB676F 5 Bytes JMP 016C29AA
.text C:\WINDOWS\Explorer.EXE[1172] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 016C29E2
.text C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe[1236] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00C72B80
.text C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe[1236] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00C72B3D
.text C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe[1236] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00C72B01
.text C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe[1236] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00C72AE6
.text C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe[1236] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00C72972
.text C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe[1236] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00C72A64
.text C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe[1236] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00C729AA
.text C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe[1236] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00C729E2
.text C:\WINDOWS\system32\igfxsrvc.exe[1276] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00E42B80
.text C:\WINDOWS\system32\igfxsrvc.exe[1276] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00E42B3D
.text C:\WINDOWS\system32\igfxsrvc.exe[1276] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00E42B01
.text C:\WINDOWS\system32\igfxsrvc.exe[1276] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00E42AE6
.text C:\WINDOWS\system32\igfxsrvc.exe[1276] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00E42972
.text C:\WINDOWS\system32\igfxsrvc.exe[1276] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00E42A64
.text C:\WINDOWS\system32\igfxsrvc.exe[1276] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00E429AA
.text C:\WINDOWS\system32\igfxsrvc.exe[1276] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00E429E2
.text C:\WINDOWS\system32\igfxext.exe[1364] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00E62B80
.text C:\WINDOWS\system32\igfxext.exe[1364] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00E62B3D
.text C:\WINDOWS\system32\igfxext.exe[1364] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00E62B01
.text C:\WINDOWS\system32\igfxext.exe[1364] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00E62AE6
.text C:\WINDOWS\system32\igfxext.exe[1364] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00E62972
.text C:\WINDOWS\system32\igfxext.exe[1364] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00E62A64
.text C:\WINDOWS\system32\igfxext.exe[1364] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00E629AA
.text C:\WINDOWS\system32\igfxext.exe[1364] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00E629E2
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1420] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 02442B80
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1420] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 02442B3D
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1420] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 02442B01
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1420] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 02442AE6
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1420] WS2_32.dll!send 71AB4C27 5 Bytes JMP 02442972
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1420] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 02442A64
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1420] WS2_32.dll!recv 71AB676F 5 Bytes JMP 024429AA
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1420] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 024429E2
.text C:\WINDOWS\system32\wuauclt.exe[1556] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00DE2B80
.text C:\WINDOWS\system32\wuauclt.exe[1556] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00DE2B3D
.text C:\WINDOWS\system32\wuauclt.exe[1556] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00DE2B01
.text C:\WINDOWS\system32\wuauclt.exe[1556] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00DE2AE6
.text C:\WINDOWS\system32\wuauclt.exe[1556] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00DE2972
.text C:\WINDOWS\system32\wuauclt.exe[1556] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00DE2A64
.text C:\WINDOWS\system32\wuauclt.exe[1556] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00DE29AA
.text C:\WINDOWS\system32\wuauclt.exe[1556] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00DE29E2
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1612] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 012D2B80
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1612] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 012D2B3D
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1612] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 012D2B01
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1612] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 012D2AE6
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1612] WS2_32.dll!send 71AB4C27 5 Bytes JMP 012D2972
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1612] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 012D2A64
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1612] WS2_32.dll!recv 71AB676F 5 Bytes JMP 012D29AA
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1612] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 012D29E2
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2152] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01972AE6
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2152] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01972972
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2152] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01972A64
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2152] WS2_32.dll!recv 71AB676F 5 Bytes JMP 019729AA
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2152] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 019729E2
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2152] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01972B80
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2152] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01972B3D
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2152] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01972B01
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2200] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 06892AE6
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2200] WS2_32.dll!send 71AB4C27 5 Bytes JMP 06892972
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2200] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 06892A64
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2200] WS2_32.dll!recv 71AB676F 5 Bytes JMP 068929AA
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2200] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 068929E2
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2200] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 06892B80
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2200] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 06892B3D
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2200] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 06892B01
.text C:\WINDOWS\System32\alg.exe[2656] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00B52B80
.text C:\WINDOWS\System32\alg.exe[2656] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00B52B3D
.text C:\WINDOWS\System32\alg.exe[2656] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00B52B01
.text C:\WINDOWS\System32\alg.exe[2656] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00B52AE6
.text C:\WINDOWS\System32\alg.exe[2656] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00B52972
.text C:\WINDOWS\System32\alg.exe[2656] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00B52A64
.text C:\WINDOWS\System32\alg.exe[2656] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00B529AA
.text C:\WINDOWS\System32\alg.exe[2656] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00B529E2
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3112] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00CC2B80
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3112] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00CC2B3D
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3112] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00CC2B01
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3112] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00CC2AE6
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3112] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00CC2972
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3112] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00CC2A64
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3112] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00CC29AA
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[3112] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00CC29E2
.text C:\Program Files\flupScript\mirc.exe[3412] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01322B80
.text C:\Program Files\flupScript\mirc.exe[3412] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01322B3D
.text C:\Program Files\flupScript\mirc.exe[3412] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01322B01
.text C:\Program Files\flupScript\mirc.exe[3412] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01322AE6
.text C:\Program Files\flupScript\mirc.exe[3412] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01322972
.text C:\Program Files\flupScript\mirc.exe[3412] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01322A64
.text C:\Program Files\flupScript\mirc.exe[3412] WS2_32.dll!recv 71AB676F 5 Bytes JMP 013229AA
.text C:\Program Files\flupScript\mirc.exe[3412] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 013229E2
.text C:\Program Files\internet explorer\iexplore.exe[3592] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01972B80
.text C:\Program Files\internet explorer\iexplore.exe[3592] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01972B3D
.text C:\Program Files\internet explorer\iexplore.exe[3592] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01972B01
.text C:\Program Files\internet explorer\iexplore.exe[3592] CRYPT32.dll!CertGetCertificateChain 77A92F67 5 Bytes JMP 019735D4
.text C:\Program Files\internet explorer\iexplore.exe[3592] CRYPT32.dll!CertVerifyCertificateChainPolicy 77A9B76F 5 Bytes JMP 019735DD
.text C:\Program Files\internet explorer\iexplore.exe[3592] WININET.dll!HttpOpenRequestA 771C2B01 5 Bytes JMP 01972DD5
.text C:\Program Files\internet explorer\iexplore.exe[3592] WININET.dll!InternetConnectA 771C345A 5 Bytes JMP 01972B9B
.text C:\Program Files\internet explorer\iexplore.exe[3592] WININET.dll!InternetCloseHandle 771C4D94 5 Bytes JMP 019730DD
.text C:\Program Files\internet explorer\iexplore.exe[3592] WININET.dll!HttpSendRequestA 771C60A9 5 Bytes JMP 01972F41
.text C:\Program Files\internet explorer\iexplore.exe[3592] WININET.dll!InternetReadFile 771C82F2 5 Bytes JMP 01973088
.text C:\Program Files\internet explorer\iexplore.exe[3592] WININET.dll!HttpSendRequestW 7721303C 5 Bytes JMP 01973A57
—- User IAT/EAT - GMER 1.0.15 —-
IAT C:\WINDOWS\system32\services.exe[756] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[756] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\ACPI \Device\00000040 8580C1C0
Device \Driver\ACPI \Device\00000041 8580C1C0
Device \Driver\ACPI \Device\00000050 8580C1C0
Device \Driver\ACPI \Device\00000044 8580C1C0
Device \Driver\ACPI \Device\00000051 8580C1C0
Device \Driver\ACPI \Device\00000045 8580C1C0
Device \Driver\ACPI \Device\00000060 8580C1C0
Device \Driver\ACPI \Device\00000047 8580C1C0
Device \Driver\ACPI \Device\00000061 8580C1C0
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\ACPI \Device\00000063 8580C1C0
Device \Driver\ACPI \Device\00000057 8580C1C0
Device \Driver\ACPI \Device\00000058 8580C1C0
Device \Driver\ACPI \Device\00000064 8580C1C0
Device \Driver\ACPI \Device\00000059 8580C1C0
Device \Driver\ACPI \Device\0000003b 8580C1C0
Device \Driver\ACPI \Device\0000003c 8580C1C0
Device \Driver\ACPI \Device\0000003d 8580C1C0
Device \Driver\ACPI \Device\0000003f 8580C1C0
Device \Driver\ACPI \Device\0000004c 8580C1C0
Device \Driver\ACPI \Device\0000004d 8580C1C0
Device \Driver\ACPI \Device\0000004e 8580C1C0
Device \Driver\ACPI \Device\0000005c 8580C1C0
Device \Driver\ACPI \Device\0000004f 8580C1C0
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
—- Threads - GMER 1.0.15 —-
Thread System [4:124] 858421A0
Thread System [4:144] 8582CF9F
Thread System [4:136] 85860517
Thread System [4:148] 8582FC11
Thread System [4:3904] 858421A0
Thread System [4:1780] 8582CF9F
Thread System [4:2280] 85860517
Thread System [4:2328] 8582FC11
—- Registry - GMER 1.0.15 —-
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\@P_9}\2ó7}\x90\x203aó\0\4ï\xb8\0Nô7}\x90\x203aó\0\24ï\xb8\0v`,}X_9}L\t ?j??????????h?H??j????G???Wj?j?h I???U???}?P???C???Ph?a??h?;?
—- EOF - GMER 1.0.15 —-
============= FINISH: 22:02:37.14 ===============