This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] firefox and pc freezing found a virus days ago

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

heelo guys im at my moms pc…

i noticed like 3 weeks ago, that her firefox browser was freezing everytime we tried to look for something on google or any search engine in the web… firefox freezes, then the pc sends a message of error sometimes… when i discovered that, i used malwares to look for a virus and found some adware or virus… im gonna add the log of malwaresbytes as well


im sorry, but the pc or the virus, i dont know which one is noit letting me run the rootrepeal program and cuz of that, i didnt post the log of it… i even tried to use it in safe mode as well and it didnt work….even running the program as administrator

here are my dds logs and malwarebytes that i did days ago before come to this site for help






DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 17:51:05.56 on 03/12/2009
Internet Explorer: 8.0.6001.18828 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1918.868 [GMT -6:00]

AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Norton Internet Security *enabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\System32\mobsync.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Users\Owner\AppData\Local\Sony Corporation\VirtualExpander\VirtualExpander.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\PROGRA~1\McAfee\MSM\McSmtFwk.exe
C:\PROGRA~1\COMMON~1\McAfee\MSC\McUICnt.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Owner\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uDefault_Page_URL = hxxp://www.msn.com
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mStart Page = hxxp://www.yahoo.com/
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn3\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [YSearchProtection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRun: [Google Update] "c:\users\owner\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [KBD] c:\hp\kbd\KbdStub.EXE
mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: []
mRun: [RoxioDragToDisc] "c:\program files\roxio\drag-to-disc\DrgToDsc.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
dRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\virtua~1.lnk - c:\users\owner\appdata\local\sony corporation\virtualexpander\VirtualExpander.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\ymetray.lnk - c:\program files\yahoo!\yahoo! music jukebox\ymetray.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: c:\progra~1\google\google~1\goec62~1.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\mip2e4bu.default\
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\program files\google\google updater\2.4.1591.6512\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\owner\appdata\local\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\users\owner\appdata\local\yahoo!\browserplus\2.4.17\plugins\npybrowserplus_2.4.17.dll
FF - plugin: c:\users\owner\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-9-15 93320]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
R3 hcw18bda;Hauppauge WinTV 418 Driver;c:\windows\system32\drivers\hcw18bda.sys [2009-3-19 391168]
S2 gupdate1c9df196c3e980b;Servicio de actualización de Google (gupdate1c9df196c3e980b);c:\program files\google\update\GoogleUpdate.exe [2009-5-27 133104]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-20 21504]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-10-20 54632]
S3 fsssvc;Servicio de Windows Live Protección infantil;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-12-3 29744]

=============== Created Last 30 ================

2009-11-30 14:52 –d—– c:\programdata\Office Genuine Advantage
2009-11-30 11:58 499,712 a——- c:\windows\system32\kerberos.dll
2009-11-30 11:58 270,848 a——- c:\windows\system32\schannel.dll
2009-11-30 11:39 –d—– c:\programdata\Spybot - Search & Destroy
2009-11-30 11:39 –d—– c:\program files\Spybot - Search & Destroy
2009-11-30 11:39 –d—– c:\progra~2\Spybot - Search & Destroy
2009-11-30 11:08 a-d—– c:\programdata\TEMP
2009-11-30 11:08 –d—– c:\program files\SpywareBlaster
2009-11-30 11:01 –d—– c:\users\owner\appdata\roaming\Malwarebytes
2009-11-30 11:01 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-30 11:01 19,160 a——- c:\windows\system32\drivers\mbam.sys
2009-11-30 11:01 –d—– c:\programdata\Malwarebytes
2009-11-30 11:01 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-11-30 11:01 –d—– c:\progra~2\Malwarebytes
2009-11-25 18:28 2,048 a——- c:\windows\system32\tzres.dll
2009-11-25 10:14 1,401,856 a——- c:\windows\system32\msxml6.dll
2009-11-25 10:14 1,248,768 a——- c:\windows\system32\msxml3.dll
2009-11-25 10:14 714,240 a——- c:\windows\system32\timedate.cpl
2009-11-18 09:52 –d—– c:\program files\Windows Portable Devices
2009-11-18 09:51 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-17 19:11 30,208 a——- c:\windows\system32\WPDShextAutoplay.exe
2009-11-17 19:10 4,096 a——- c:\windows\system32\oleaccrc.dll
2009-11-17 19:10 555,520 a——- c:\windows\system32\UIAutomationCore.dll
2009-11-17 19:10 234,496 a——- c:\windows\system32\oleacc.dll
2009-11-11 17:01 2,036,736 a——- c:\windows\system32\win32k.sys
2009-11-11 17:01 355,328 a——- c:\windows\system32\WSDApi.dll
2009-11-04 10:21 1,638,912 a——- c:\windows\system32\mshtml.tlb

==================== Find3M ====================

2009-11-30 12:11 143,360 a——- c:\windows\inf\infstrng.dat
2009-11-30 12:11 51,200 a——- c:\windows\inf\infpub.dat
2009-11-30 12:11 86,016 a——- c:\windows\inf\infstor.dat
2009-11-19 17:18 1,410 a——- c:\users\owner\appdata\roaming\wklnhst.dat
2009-11-18 09:51 665,600 a——- c:\windows\inf\drvindex.dat
2009-10-11 04:17 411,368 a——- c:\windows\system32\deploytk.dll
2009-09-30 19:02 2,537,472 a——- c:\windows\system32\wpdshext.dll
2009-09-30 19:02 334,848 a——- c:\windows\system32\PortableDeviceApi.dll
2009-09-30 19:02 87,552 a——- c:\windows\system32\WPDShServiceObj.dll
2009-09-30 19:02 31,232 a——- c:\windows\system32\BthMtpContextHandler.dll
2009-09-30 19:01 546,816 a——- c:\windows\system32\wpd_ci.dll
2009-09-30 19:01 160,256 a——- c:\windows\system32\PortableDeviceTypes.dll
2009-09-30 19:01 350,208 a——- c:\windows\system32\WPDSp.dll
2009-09-30 19:01 196,608 a——- c:\windows\system32\PortableDeviceWMDRM.dll
2009-09-30 19:01 100,864 a——- c:\windows\system32\PortableDeviceClassExtension.dll
2009-09-30 19:01 60,928 a——- c:\windows\system32\PortableDeviceConnectApi.dll
2009-09-30 19:01 81,920 a——- c:\windows\system32\wpdbusenum.dll
2009-09-24 20:10 974,848 a——- c:\windows\system32\WindowsCodecs.dll
2009-09-24 20:07 189,440 a——- c:\windows\system32\WindowsCodecsExt.dll
2009-09-24 20:04 321,024 a——- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-24 19:49 1,554,432 a——- c:\windows\system32\xpsservices.dll
2009-09-24 19:48 351,232 a——- c:\windows\system32\XpsPrint.dll
2009-09-24 19:38 847,360 a——- c:\windows\system32\OpcServices.dll
2009-09-24 19:36 280,064 a——- c:\windows\system32\XpsGdiConverter.dll
2009-09-24 19:35 135,680 a——- c:\windows\system32\XpsRasterService.dll
2009-09-24 19:33 195,584 a——- c:\windows\system32\dxdiagn.dll
2009-09-24 19:33 829,440 a——- c:\windows\system32\d3d10warp.dll
2009-09-24 19:33 369,664 a——- c:\windows\system32\WMPhoto.dll
2009-09-24 19:32 252,928 a——- c:\windows\system32\dxdiag.exe
2009-09-24 19:31 519,680 a——- c:\windows\system32\d3d11.dll
2009-09-24 19:31 486,912 a——- c:\windows\system32\d3d10level9.dll
2009-09-24 19:31 161,280 a——- c:\windows\system32\d3d10_1.dll
2009-09-24 19:31 218,112 a——- c:\windows\system32\d3d10_1core.dll
2009-09-24 19:31 1,030,144 a——- c:\windows\system32\d3d10.dll
2009-09-24 19:31 828,928 a——- c:\windows\system32\d2d1.dll
2009-09-24 19:30 481,792 a——- c:\windows\system32\dxgi.dll
2009-09-24 19:30 190,464 a——- c:\windows\system32\d3d10core.dll
2009-09-24 19:27 1,064,448 a——- c:\windows\system32\DWrite.dll
2009-09-24 19:27 793,088 a——- c:\windows\system32\FntCache.dll
2009-09-24 19:27 37,888 a——- c:\windows\system32\cdd.dll
2009-09-24 16:54 258,048 a——- c:\windows\system32\winspool.drv
2009-09-24 16:54 667,648 a——- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 16:54 26,112 a——- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-10 10:48 218,624 a——- c:\windows\system32\msv1_0.dll
2009-09-10 08:59 8,147,456 a——- c:\windows\system32\wmploc.DLL
2009-09-10 08:58 310,784 a——- c:\windows\system32\unregmp2.exe
2009-09-09 20:01 3,023,360 a——- c:\windows\system32\UIRibbon.dll
2009-09-09 20:00 1,164,800 a——- c:\windows\system32\UIRibbonRes.dll
2009-09-09 20:00 92,672 a——- c:\windows\system32\UIAnimation.dll
2009-01-02 13:17 56 a—h— c:\programdata\ezsidmv.dat
2009-01-02 13:17 56 a—h— c:\progra~2\ezsidmv.dat
2008-06-21 10:35 174 a–sh— c:\program files\desktop.ini
2007-07-31 15:34 262,144 a——- c:\progra~2\ntuser.dat
2006-11-02 06:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 06:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 06:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 06:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 03:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 03:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 03:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 03:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 17:51:47.60 ===============




Malwarebytes' Anti-Malware 1.41
Database version: 3261
Windows 6.0.6002 Service Pack 2

30/11/2009 01:09:52 p.m.
mbam-log-2009-11-30 (13-09-52).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|)
Objects scanned: 284090
Time elapsed: 1 hour(s), 58 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hi lamar,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Let's try a different ARK scanner.

Please download gmer.zip from Gmer and save it to your desktop.

  • Right click on gmer.zip and select Extract All….
  • Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  • Click on the Browse button. Click on Desktop. Then click OK.
  • Click Next. It will start extracting.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Double click on gmer.exe to run it.
  • Select the Rootkit tab.
  • On the right hand side, check all the items to be scanned, but leave Show All box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click on the Scan button.
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard.
  • Open Notepad or a similar text editor.
  • Paste the clipboard contents into the text editor.
  • Save the Gmer scan log and post it in your next reply.

Note: Do not run any programs while Gmer is running.
Hi tOMK thenx for offering ur help.. :D

the program gmer.exe was stopped from working as well… something is not letting the programs to run appropiately… ( i also run the program as an administrator)



EDIT: i run it for a second time and i dunno if it did the whole log or not ill paste it here so u can have a better look thnx




GMER 1.0.15.15252 - http://www.gmer.net
Rootkit scan 2009-12-07 16:57:05
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\Owner\AppData\Local\Temp\kwlcapow.sys


—- System - GMER 1.0.15 —-

INT 0x62 ? 90C20A50

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0x9179C79E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0x9179C738]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0x9179C74C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x9179C7DC]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0x9179C81F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0x9179C710]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0x9179C724]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0x9179C7B2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0x9179C847]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0x9179C833]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0x9179C78A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0x9179C776]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0x9179C80B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x9179C7F2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0x9179C7C8]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateUserProcess [0x9179C762]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwYieldExecution 82049982 5 Bytes JMP 9179C7CC \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 821DD5B5 5 Bytes JMP 9179C823 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateUserProcess 821E7B82 5 Bytes JMP 9179C766 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 8220ED5D 5 Bytes JMP 9179C80F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 8222E446 7 Bytes JMP 9179C7E0 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 8222E709 5 Bytes JMP 9179C7F6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 82232474 5 Bytes JMP 9179C77A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 82237E7D 7 Bytes JMP 9179C7B6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 8223A09A 5 Bytes JMP 9179C728 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 8223EB48 5 Bytes JMP 9179C714 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 8225FD59 5 Bytes JMP 9179C7A2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRestoreKey 822707B2 5 Bytes JMP 9179C837 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplaceKey 822719B6 5 Bytes JMP 9179C84B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 822AF74B 5 Bytes JMP 9179C73C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 822AF796 7 Bytes JMP 9179C750 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 822B0253 5 Bytes JMP 9179C78E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8C002340, 0x3DA8C7, 0xE8000020]

—- User code sections - GMER 1.0.15 —-

.text C:\Windows\Explorer.EXE[356] kernel32.dll!GetStartupInfoW 75EF1929 5 Bytes JMP 02D800BD
.text C:\Windows\Explorer.EXE[356] kernel32.dll!GetStartupInfoA 75EF19C9 5 Bytes JMP 02D80F77
.text C:\Windows\Explorer.EXE[356] kernel32.dll!CreateProcessW 75EF1BF3 5 Bytes JMP 02D800E9
.text C:\Windows\Explorer.EXE[356] kernel32.dll!CreateProcessA 75EF1C28 5 Bytes JMP 02D800D8
.text C:\Windows\Explorer.EXE[356] kernel32.dll!VirtualProtect 75EF1DC3 5 Bytes JMP 02D80F99
.text C:\Windows\Explorer.EXE[356] kernel32.dll!CreateNamedPipeA 75EF2EF5 5 Bytes JMP 02D8001B
.text C:\Windows\Explorer.EXE[356] kernel32.dll!CreateNamedPipeW 75EF5C0C 5 Bytes JMP 02D80036
.text C:\Windows\Explorer.EXE[356] kernel32.dll!CreatePipe 75F18E6E 5 Bytes JMP 02D80F88
.text C:\Windows\Explorer.EXE[356] kernel32.dll!LoadLibraryExW 75F19109 5 Bytes JMP 02D80FAA
.text C:\Windows\Explorer.EXE[356] kernel32.dll!LoadLibraryW 75F19362 5 Bytes JMP 02D80062
.text C:\Windows\Explorer.EXE[356] kernel32.dll!LoadLibraryExA 75F194B4 5 Bytes JMP 02D80073
.text C:\Windows\Explorer.EXE[356] kernel32.dll!LoadLibraryA 75F194DC 5 Bytes JMP 02D80051
.text C:\Windows\Explorer.EXE[356] kernel32.dll!VirtualProtectEx 75F1DBDA 5 Bytes JMP 02D80098
.text C:\Windows\Explorer.EXE[356] kernel32.dll!GetProcAddress 75F3903B 5 Bytes JMP 02D80F37
.text C:\Windows\Explorer.EXE[356] kernel32.dll!CreateFileW 75F3AECB 5 Bytes JMP 02D80FE5
.text C:\Windows\Explorer.EXE[356] kernel32.dll!CreateFileA 75F3CE5F 5 Bytes JMP 02D8000A
.text C:\Windows\Explorer.EXE[356] kernel32.dll!WinExec 75F85CF7 5 Bytes JMP 02D80F66
.text C:\Windows\Explorer.EXE[356] ADVAPI32.dll!RegCreateKeyExA 760F39AB 5 Bytes JMP 03560036
.text C:\Windows\Explorer.EXE[356] ADVAPI32.dll!RegCreateKeyA 760F3BA9 5 Bytes JMP 03560025
.text C:\Windows\Explorer.EXE[356] ADVAPI32.dll!RegOpenKeyA 760F89C7 5 Bytes JMP 03560FE5
.text C:\Windows\Explorer.EXE[356] ADVAPI32.dll!RegCreateKeyW 7610391E 5 Bytes JMP 03560F94
.text C:\Windows\Explorer.EXE[356] ADVAPI32.dll!RegCreateKeyExW 761041F1 5 Bytes JMP 03560F79
.text C:\Windows\Explorer.EXE[356] ADVAPI32.dll!RegOpenKeyExA 76107C42 5 Bytes JMP 03560FC3
.text C:\Windows\Explorer.EXE[356] ADVAPI32.dll!RegOpenKeyW 7610E2B5 5 Bytes JMP 03560FD4
.text C:\Windows\Explorer.EXE[356] ADVAPI32.dll!RegOpenKeyExW 76117BA1 5 Bytes JMP 03560014
.text C:\Windows\Explorer.EXE[356] msvcrt.dll!_wsystem 76037F2F 5 Bytes JMP 02D90049
.text C:\Windows\Explorer.EXE[356] msvcrt.dll!system 7603804B 5 Bytes JMP 02D90038
.text C:\Windows\Explorer.EXE[356] msvcrt.dll!_creat 7603BBE1 5 Bytes JMP 02D9001D
.text C:\Windows\Explorer.EXE[356] msvcrt.dll!_open 7603D106 5 Bytes JMP 02D90000
.text C:\Windows\Explorer.EXE[356] msvcrt.dll!_wcreat 7603D326 5 Bytes JMP 02D90FC8
.text C:\Windows\Explorer.EXE[356] msvcrt.dll!_wopen 7603D501 5 Bytes JMP 02D90FE3
.text C:\Windows\Explorer.EXE[356] WS2_32.dll!socket 760A36D1 5 Bytes JMP 02F20FEF
.text C:\Windows\Explorer.EXE[356] WININET.dll!InternetOpenA 761CD690 5 Bytes JMP 036E000A
.text C:\Windows\Explorer.EXE[356] WININET.dll!InternetOpenW 761CDB09 5 Bytes JMP 036E001B
.text C:\Windows\Explorer.EXE[356] WININET.dll!InternetOpenUrlA 761CF3A4 5 Bytes JMP 036E002C
.text C:\Windows\Explorer.EXE[356] WININET.dll!InternetOpenUrlW 76216DDF 5 Bytes JMP 036E0047
.text C:\Windows\system32\services.exe[672] kernel32.dll!GetStartupInfoW 75EF1929 5 Bytes JMP 007C0F61
.text C:\Windows\system32\services.exe[672] kernel32.dll!GetStartupInfoA 75EF19C9 5 Bytes JMP 007C0F72
.text C:\Windows\system32\services.exe[672] kernel32.dll!CreateProcessW 75EF1BF3 5 Bytes JMP 007C00DD
.text C:\Windows\system32\services.exe[672] kernel32.dll!CreateProcessA 75EF1C28 5 Bytes JMP 007C00CC
.text C:\Windows\system32\services.exe[672] kernel32.dll!VirtualProtect 75EF1DC3 5 Bytes JMP 007C0082
.text C:\Windows\system32\services.exe[672] kernel32.dll!CreateNamedPipeA 75EF2EF5 5 Bytes JMP 007C0FD4
.text C:\Windows\system32\services.exe[672] kernel32.dll!CreateNamedPipeW 75EF5C0C 5 Bytes JMP 007C0025
.text C:\Windows\system32\services.exe[672] kernel32.dll!CreatePipe 75F18E6E 5 Bytes JMP 007C0F83
.text C:\Windows\system32\services.exe[672] kernel32.dll!LoadLibraryExW 75F19109 5 Bytes JMP 007C0065
.text C:\Windows\system32\services.exe[672] kernel32.dll!LoadLibraryW 75F19362 5 Bytes JMP 007C004A
.text C:\Windows\system32\services.exe[672] kernel32.dll!LoadLibraryExA 75F194B4 5 Bytes JMP 007C0FA8
.text C:\Windows\system32\services.exe[672] kernel32.dll!LoadLibraryA 75F194DC 5 Bytes JMP 007C0FC3
.text C:\Windows\system32\services.exe[672] kernel32.dll!VirtualProtectEx 75F1DBDA 5 Bytes JMP 007C0093
.text C:\Windows\system32\services.exe[672] kernel32.dll!GetProcAddress 75F3903B 5 Bytes JMP 007C00EE
.text C:\Windows\system32\services.exe[672] kernel32.dll!CreateFileW 75F3AECB 5 Bytes JMP 007C000A
.text C:\Windows\system32\services.exe[672] kernel32.dll!CreateFileA 75F3CE5F 5 Bytes JMP 007C0FEF
.text C:\Windows\system32\services.exe[672] kernel32.dll!WinExec 75F85CF7 5 Bytes JMP 007C0F50
.text C:\Windows\system32\services.exe[672] ADVAPI32.dll!RegCreateKeyExA 760F39AB 5 Bytes JMP 00800F83
.text C:\Windows\system32\services.exe[672] ADVAPI32.dll!RegCreateKeyA 760F3BA9 5 Bytes JMP 00800FAF
.text C:\Windows\system32\services.exe[672] ADVAPI32.dll!RegOpenKeyA 760F89C7 5 Bytes JMP 00800000
.text C:\Windows\system32\services.exe[672] ADVAPI32.dll!RegCreateKeyW 7610391E 5 Bytes JMP 00800F94
.text C:\Windows\system32\services.exe[672] ADVAPI32.dll!RegCreateKeyExW 761041F1 5 Bytes JMP 00800040
.text C:\Windows\system32\services.exe[672] ADVAPI32.dll!RegOpenKeyExA 76107C42 5 Bytes JMP 00800FC0
.text C:\Windows\system32\services.exe[672] ADVAPI32.dll!RegOpenKeyW 7610E2B5 5 Bytes JMP 00800FDB
.text C:\Windows\system32\services.exe[672] ADVAPI32.dll!RegOpenKeyExW 76117BA1 5 Bytes JMP 0080001B
.text C:\Windows\system32\services.exe[672] msvcrt.dll!_wsystem 76037F2F 5 Bytes JMP 007D0FA8
.text C:\Windows\system32\services.exe[672] msvcrt.dll!system 7603804B 5 Bytes JMP 007D0033
.text C:\Windows\system32\services.exe[672] msvcrt.dll!_creat 7603BBE1 5 Bytes JMP 007D0FCD
.text C:\Windows\system32\services.exe[672] msvcrt.dll!_open 7603D106 5 Bytes JMP 007D0000
.text C:\Windows\system32\services.exe[672] msvcrt.dll!_wcreat 7603D326 5 Bytes JMP 007D0022
.text C:\Windows\system32\services.exe[672] msvcrt.dll!_wopen 7603D501 5 Bytes JMP 007D0011
.text C:\Windows\system32\services.exe[672] WS2_32.dll!socket 760A36D1 5 Bytes JMP 007E0000
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!GetStartupInfoW 75EF1929 5 Bytes JMP 001C006F
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!GetStartupInfoA 75EF19C9 5 Bytes JMP 001C0054
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!CreateProcessW 75EF1BF3 5 Bytes JMP 001C008A
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!CreateProcessA 75EF1C28 5 Bytes JMP 001C0EFD
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!VirtualProtect 75EF1DC3 5 Bytes JMP 001C0F44
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!CreateNamedPipeA 75EF2EF5 5 Bytes JMP 001C0FC3
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!CreateNamedPipeW 75EF5C0C 5 Bytes JMP 001C0FA8
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!CreatePipe 75F18E6E 5 Bytes JMP 001C0F33
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!LoadLibraryExW 75F19109 5 Bytes JMP 001C0F61
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!LoadLibraryW 75F19362 5 Bytes JMP 001C0F97
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!LoadLibraryExA 75F194B4 5 Bytes JMP 001C0F7C
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!LoadLibraryA 75F194DC 5 Bytes JMP 001C0014
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!VirtualProtectEx 75F1DBDA 5 Bytes JMP 001C0043
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!GetProcAddress 75F3903B 5 Bytes JMP 001C009B
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!CreateFileW 75F3AECB 5 Bytes JMP 001C0FD4
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!CreateFileA 75F3CE5F 5 Bytes JMP 001C0FEF
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!WinExec 75F85CF7 5 Bytes JMP 001C0F0E
.text C:\Windows\system32\lsass.exe[688] ADVAPI32.dll!RegCreateKeyExA 760F39AB 5 Bytes JMP 002D0FDB
.text C:\Windows\system32\lsass.exe[688] ADVAPI32.dll!RegCreateKeyA 760F3BA9 5 Bytes JMP 002D0062
.text C:\Windows\system32\lsass.exe[688] ADVAPI32.dll!RegOpenKeyA 760F89C7 5 Bytes JMP 002D0000
.text C:\Windows\system32\lsass.exe[688] ADVAPI32.dll!RegCreateKeyW 7610391E 5 Bytes JMP 002D007D
.text C:\Windows\system32\lsass.exe[688] ADVAPI32.dll!RegCreateKeyExW 761041F1 5 Bytes JMP 002D00A2
.text C:\Windows\system32\lsass.exe[688] ADVAPI32.dll!RegOpenKeyExA 76107C42 5 Bytes JMP 002D0036
.text C:\Windows\system32\lsass.exe[688] ADVAPI32.dll!RegOpenKeyW 7610E2B5 5 Bytes JMP 002D001B
.text C:\Windows\system32\lsass.exe[688] ADVAPI32.dll!RegOpenKeyExW 76117BA1 5 Bytes JMP 002D0051
.text C:\Windows\system32\lsass.exe[688] msvcrt.dll!_wsystem 76037F2F 5 Bytes JMP 001D0F95
.text C:\Windows\system32\lsass.exe[688] msvcrt.dll!system 7603804B 5 Bytes JMP 001D0FA6
.text C:\Windows\system32\lsass.exe[688] msvcrt.dll!_creat 7603BBE1 5 Bytes JMP 001D0FC1
.text C:\Windows\system32\lsass.exe[688] msvcrt.dll!_open 7603D106 5 Bytes JMP 001D0FEF
.text C:\Windows\system32\lsass.exe[688] msvcrt.dll!_wcreat 7603D326 5 Bytes JMP 001D0016
.text C:\Windows\system32\lsass.exe[688] msvcrt.dll!_wopen 7603D501 5 Bytes JMP 001D0FD2
.text C:\Windows\system32\lsass.exe[688] WS2_32.dll!socket 760A36D1 5 Bytes JMP 001E000A
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!GetStartupInfoW 75EF1929 5 Bytes JMP 00680098
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!GetStartupInfoA 75EF19C9 5 Bytes JMP 00680F52
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!CreateProcessW 75EF1BF3 5 Bytes JMP 00680F26
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!CreateProcessA 75EF1C28 5 Bytes JMP 00680F37
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!VirtualProtect 75EF1DC3 5 Bytes JMP 00680F99
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!CreateNamedPipeA 75EF2EF5 5 Bytes JMP 00680011
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!CreateNamedPipeW 75EF5C0C 5 Bytes JMP 0068002C
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!CreatePipe 75F18E6E 5 Bytes JMP 00680F6D
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!LoadLibraryExW 75F19109 5 Bytes JMP 00680FAA
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!LoadLibraryW 75F19362 5 Bytes JMP 00680058
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!LoadLibraryExA 75F194B4 5 Bytes JMP 00680069
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!LoadLibraryA 75F194DC 5 Bytes JMP 0068003D
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!VirtualProtectEx 75F1DBDA 5 Bytes JMP 00680F88
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!GetProcAddress 75F3903B 5 Bytes JMP 00680F15
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!CreateFileW 75F3AECB 5 Bytes JMP 00680000
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!CreateFileA 75F3CE5F 5 Bytes JMP 00680FEF
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!WinExec 75F85CF7 5 Bytes JMP 006800B3
.text C:\Windows\system32\svchost.exe[896] msvcrt.dll!_wsystem 76037F2F 5 Bytes JMP 00690FC3
.text C:\Windows\system32\svchost.exe[896] msvcrt.dll!system 7603804B 5 Bytes JMP 00690044
.text C:\Windows\system32\svchost.exe[896] msvcrt.dll!_creat 7603BBE1 5 Bytes JMP 00690029
.text C:\Windows\system32\svchost.exe[896] msvcrt.dll!_open 7603D106 5 Bytes JMP 00690FEF
.text C:\Windows\system32\svchost.exe[896] msvcrt.dll!_wcreat 7603D326 5 Bytes JMP 00690FD4
.text C:\Windows\system32\svchost.exe[896] msvcrt.dll!_wopen 7603D501 5 Bytes JMP 00690018
.text C:\Windows\system32\svchost.exe[896] ADVAPI32.dll!RegCreateKeyExA 760F39AB 5 Bytes JMP 006F0FC3
.text C:\Windows\system32\svchost.exe[896] ADVAPI32.dll!RegCreateKeyA 760F3BA9 5 Bytes JMP 006F005B
.text C:\Windows\system32\svchost.exe[896] ADVAPI32.dll!RegOpenKeyA 760F89C7 5 Bytes JMP 006F0000
.text C:\Windows\system32\svchost.exe[896] ADVAPI32.dll!RegCreateKeyW 7610391E 5 Bytes JMP 006F0FD4
.text C:\Windows\system32\svchost.exe[896] ADVAPI32.dll!RegCreateKeyExW 761041F1 5 Bytes JMP 006F0FA8
.text C:\Windows\system32\svchost.exe[896] ADVAPI32.dll!RegOpenKeyExA 76107C42 5 Bytes JMP 006F0036
.text C:\Windows\system32\svchost.exe[896] ADVAPI32.dll!RegOpenKeyW 7610E2B5 5 Bytes JMP 006F001B
.text C:\Windows\system32\svchost.exe[896] ADVAPI32.dll!RegOpenKeyExW 76117BA1 5 Bytes JMP 006F0FEF
.text C:\Windows\system32\svchost.exe[896] WS2_32.dll!socket 760A36D1 5 Bytes JMP 006E0000
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!GetStartupInfoW 75EF1929 5 Bytes JMP 007000AB
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!GetStartupInfoA 75EF19C9 5 Bytes JMP 00700F65
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!CreateProcessW 75EF1BF3 5 Bytes JMP 007000D0
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!CreateProcessA 75EF1C28 5 Bytes JMP 00700F39
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!VirtualProtect 75EF1DC3 5 Bytes JMP 00700075
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!CreateNamedPipeA 75EF2EF5 5 Bytes JMP 0070002C
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!CreateNamedPipeW 75EF5C0C 5 Bytes JMP 0070003D
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!CreatePipe 75F18E6E 5 Bytes JMP 00700F80
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!LoadLibraryExW 75F19109 5 Bytes JMP 00700064
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!LoadLibraryW 75F19362 5 Bytes JMP 00700FB6
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!LoadLibraryExA 75F194B4 5 Bytes JMP 00700F9B
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!LoadLibraryA 75F194DC 5 Bytes JMP 00700FD1
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!VirtualProtectEx 75F1DBDA 5 Bytes JMP 00700090
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!GetProcAddress 75F3903B 5 Bytes JMP 00700F1E
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!CreateFileW 75F3AECB 5 Bytes JMP 00700011
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!CreateFileA 75F3CE5F 5 Bytes JMP 00700000
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!WinExec 75F85CF7 5 Bytes JMP 00700F4A
.text C:\Windows\system32\svchost.exe[1000] msvcrt.dll!_wsystem 76037F2F 5 Bytes JMP 00710042
.text C:\Windows\system32\svchost.exe[1000] msvcrt.dll!system 7603804B 5 Bytes JMP 00710FB7
.text C:\Windows\system32\svchost.exe[1000] msvcrt.dll!_creat 7603BBE1 5 Bytes JMP 00710FC8
.text C:\Windows\system32\svchost.exe[1000] msvcrt.dll!_open 7603D106 5 Bytes JMP 00710000
.text C:\Windows\system32\svchost.exe[1000] msvcrt.dll!_wcreat 7603D326 5 Bytes JMP 0071001D
.text C:\Windows\system32\svchost.exe[1000] msvcrt.dll!_wopen 7603D501 5 Bytes JMP 00710FE3
.text C:\Windows\system32\svchost.exe[1000] ADVAPI32.dll!RegCreateKeyExA 760F39AB 5 Bytes JMP 00770F9E
.text C:\Windows\system32\svchost.exe[1000] ADVAPI32.dll!RegCreateKeyA 760F3BA9 5 Bytes JMP 00770036
.text C:\Windows\system32\svchost.exe[1000] ADVAPI32.dll!RegOpenKeyA 760F89C7 5 Bytes JMP 00770000
.text C:\Windows\system32\svchost.exe[1000] ADVAPI32.dll!RegCreateKeyW 7610391E 5 Bytes JMP 00770FAF
.text C:\Windows\system32\svchost.exe[1000] ADVAPI32.dll!RegCreateKeyExW 761041F1 5 Bytes JMP 0077005B
.text C:\Windows\system32\svchost.exe[1000] ADVAPI32.dll!RegOpenKeyExA 76107C42 5 Bytes JMP 00770025
.text C:\Windows\system32\svchost.exe[1000] ADVAPI32.dll!RegOpenKeyW 7610E2B5 5 Bytes JMP 00770FEF
.text C:\Windows\system32\svchost.exe[1000] ADVAPI32.dll!RegOpenKeyExW 76117BA1 5 Bytes JMP 00770FCA
.text C:\Windows\system32\svchost.exe[1000] WS2_32.dll!socket 760A36D1 5 Bytes JMP 00760000
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!GetStartupInfoW 75EF1929 5 Bytes JMP 00930F43
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!GetStartupInfoA 75EF19C9 5 Bytes JMP 0093007F
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!CreateProcessW 75EF1BF3 5 Bytes JMP 00930F06
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!CreateProcessA 75EF1C28 5 Bytes JMP 00930F21
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!VirtualProtect 75EF1DC3 5 Bytes JMP 0093005D
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!CreateNamedPipeA 75EF2EF5 5 Bytes JMP 00930FD4
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!CreateNamedPipeW 75EF5C0C 5 Bytes JMP 00930FAF
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!CreatePipe 75F18E6E 5 Bytes JMP 00930F5E
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!LoadLibraryExW 75F19109 5 Bytes JMP 00930040
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!LoadLibraryW 75F19362 5 Bytes JMP 00930F8D
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!LoadLibraryExA 75F194B4 5 Bytes JMP 00930025
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!LoadLibraryA 75F194DC 5 Bytes JMP 00930F9E
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!VirtualProtectEx 75F1DBDA 5 Bytes JMP 0093006E
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!GetProcAddress 75F3903B 5 Bytes JMP 009300B8
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!CreateFileW 75F3AECB 5 Bytes JMP 0093000A
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!CreateFileA 75F3CE5F 5 Bytes JMP 00930FEF
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!WinExec 75F85CF7 5 Bytes JMP 00930F32
.text C:\Windows\System32\svchost.exe[1140] msvcrt.dll!_wsystem 76037F2F 5 Bytes JMP 00A20044
.text C:\Windows\System32\svchost.exe[1140] msvcrt.dll!system 7603804B 5 Bytes JMP 00A20033
.text C:\Windows\System32\svchost.exe[1140] msvcrt.dll!_creat 7603BBE1 5 Bytes JMP 00A20FC3
.text C:\Windows\System32\svchost.exe[1140] msvcrt.dll!_open 7603D106 5 Bytes JMP 00A20FEF
.text C:\Windows\System32\svchost.exe[1140] msvcrt.dll!_wcreat 7603D326 5 Bytes JMP 00A20022
.text C:\Windows\System32\svchost.exe[1140] msvcrt.dll!_wopen 7603D501 5 Bytes JMP 00A20FDE
.text C:\Windows\System32\svchost.exe[1140] ADVAPI32.dll!RegCreateKeyExA 760F39AB 5 Bytes JMP 01190F97
.text C:\Windows\System32\svchost.exe[1140] ADVAPI32.dll!RegCreateKeyA 760F3BA9 5 Bytes JMP 01190FC3
.text C:\Windows\System32\svchost.exe[1140] ADVAPI32.dll!RegOpenKeyA 760F89C7 5 Bytes JMP 01190000
.text C:\Windows\System32\svchost.exe[1140] ADVAPI32.dll!RegCreateKeyW 7610391E 5 Bytes JMP 01190FB2
.text C:\Windows\System32\svchost.exe[1140] ADVAPI32.dll!RegCreateKeyExW 761041F1 5 Bytes JMP 01190F7C
.text C:\Windows\System32\svchost.exe[1140] ADVAPI32.dll!RegOpenKeyExA 76107C42 5 Bytes JMP 01190025
.text C:\Windows\System32\svchost.exe[1140] ADVAPI32.dll!RegOpenKeyW 7610E2B5 5 Bytes JMP 01190FE5
.text C:\Windows\System32\svchost.exe[1140] ADVAPI32.dll!RegOpenKeyExW 76117BA1 5 Bytes JMP 01190FD4
.text C:\Windows\System32\svchost.exe[1140] WS2_32.dll!socket 760A36D1 5 Bytes JMP 01100000
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!GetStartupInfoW 75EF1929 5 Bytes JMP 00990F9C
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!GetStartupInfoA 75EF19C9 5 Bytes JMP 009900E2
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateProcessW 75EF1BF3 5 Bytes JMP 00990F7A
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateProcessA 75EF1C28 5 Bytes JMP 00990F8B
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!VirtualProtect 75EF1DC3 5 Bytes JMP 00990098
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateNamedPipeA 75EF2EF5 5 Bytes JMP 00990025
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateNamedPipeW 75EF5C0C 5 Bytes JMP 00990040
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreatePipe 75F18E6E 5 Bytes JMP 00990FAD
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!LoadLibraryExW 75F19109 5 Bytes JMP 00990087
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!LoadLibraryW 75F19362 5 Bytes JMP 0099006C
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!LoadLibraryExA 75F194B4 5 Bytes JMP 00990FCA
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!LoadLibraryA 75F194DC 5 Bytes JMP 00990051
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!VirtualProtectEx 75F1DBDA 5 Bytes JMP 009900B3
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!GetProcAddress 75F3903B 5 Bytes JMP 00990F69
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateFileW 75F3AECB 5 Bytes JMP 0099000A
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateFileA 75F3CE5F 5 Bytes JMP 00990FEF
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!WinExec 75F85CF7 5 Bytes JMP 00990107
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!_wsystem 76037F2F 5 Bytes JMP 00DD0FAF
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!system 7603804B 5 Bytes JMP 00DD003A
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!_creat 7603BBE1 5 Bytes JMP 00DD0029
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!_open 7603D106 5 Bytes JMP 00DD0FEF
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!_wcreat 7603D326 5 Bytes JMP 00DD0FD4
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!_wopen 7603D501 5 Bytes JMP 00DD0018
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegCreateKeyExA 760F39AB 5 Bytes JMP 00DF0FA8
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegCreateKeyA 760F3BA9 5 Bytes JMP 00DF004A
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegOpenKeyA 760F89C7 5 Bytes JMP 00DF0FE5
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegCreateKeyW 7610391E 5 Bytes JMP 00DF0FB9
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegCreateKeyExW 761041F1 5 Bytes JMP 00DF0065
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegOpenKeyExA 76107C42 5 Bytes JMP 00DF0FD4
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegOpenKeyW 7610E2B5 5 Bytes JMP 00DF0000
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegOpenKeyExW 76117BA1 5 Bytes JMP 00DF002F
.text C:\Windows\System32\svchost.exe[1172] WS2_32.dll!socket 760A36D1 5 Bytes JMP 00DE0000
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!GetStartupInfoW 75EF1929 5 Bytes JMP 009F007A
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!GetStartupInfoA 75EF19C9 5 Bytes JMP 009F0F34
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!CreateProcessW 75EF1BF3 5 Bytes JMP 009F00A9
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!CreateProcessA 75EF1C28 5 Bytes JMP 009F0F08
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!VirtualProtect 75EF1DC3 5 Bytes JMP 009F0F6A
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!CreateNamedPipeA 75EF2EF5 5 Bytes JMP 009F0FDB
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!CreateNamedPipeW 75EF5C0C 5 Bytes JMP 009F002C
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!CreatePipe 75F18E6E 5 Bytes JMP 009F005F
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!LoadLibraryExW 75F19109 5 Bytes JMP 009F004E
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!LoadLibraryW 75F19362 5 Bytes JMP 009F0FB6
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!LoadLibraryExA 75F194B4 5 Bytes JMP 009F0F91
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!LoadLibraryA 75F194DC 5 Bytes JMP 009F003D
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!VirtualProtectEx 75F1DBDA 5 Bytes JMP 009F0F59
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!GetProcAddress 75F3903B 5 Bytes JMP 009F0EF7
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!CreateFileW 75F3AECB 5 Bytes JMP 009F001B
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!CreateFileA 75F3CE5F 5 Bytes JMP 009F0000
.text C:\Windows\system32\svchost.exe[1204] kernel32.dll!WinExec 75F85CF7 5 Bytes JMP 009F0F19
.text C:\Windows\system32\svchost.exe[1204] msvcrt.dll!_wsystem 76037F2F 5 Bytes JMP 00A10042
.text C:\Windows\system32\svchost.exe[1204] msvcrt.dll!system 7603804B 5 Bytes JMP 00A10031
.text C:\Windows\system32\svchost.exe[1204] msvcrt.dll!_creat 7603BBE1 5 Bytes JMP 00A10FD2
.text C:\Windows\system32\svchost.exe[1204] msvcrt.dll!_open 7603D106 5 Bytes JMP 00A10FEF
.text C:\Windows\system32\svchost.exe[1204] msvcrt.dll!_wcreat 7603D326 5 Bytes JMP 00A10FB7
.text C:\Windows\system32\svchost.exe[1204] msvcrt.dll!_wopen 7603D501 5 Bytes JMP 00A1000C
.text C:\Windows\system32\svchost.exe[1204] ADVAPI32.dll!RegCreateKeyExA 760F39AB 5 Bytes JMP 01010F9E
.text C:\Windows\system32\svchost.exe[1204] ADVAPI32.dll!RegCreateKeyA 760F3BA9 5 Bytes JMP 01010FD4
.text C:\Windows\system32\svchost.exe[1204] ADVAPI32.dll!RegOpenKeyA 760F89C7 5 Bytes JMP 01010FEF
.text C:\Windows\system32\svchost.exe[1204] ADVAPI32.dll!RegCreateKeyW 7610391E 5 Bytes JMP 01010FB9
.text C:\Windows\system32\svchost.exe[1204] ADVAPI32.dll!RegCreateKeyExW 761041F1 5 Bytes JMP 01010065
.text C:\Windows\system32\svchost.exe[1204] ADVAPI32.dll!RegOpenKeyExA 76107C42 5 Bytes JMP 0101001B
.text C:\Windows\system32\svchost.exe[1204] ADVAPI32.dll!RegOpenKeyW 7610E2B5 5 Bytes JMP 0101000A
.text C:\Windows\system32\svchost.exe[1204] ADVAPI32.dll!RegOpenKeyExW 76117BA1 5 Bytes JMP 01010036
.text C:\Windows\system32\svchost.exe[1204] WS2_32.dll!socket 760A36D1 5 Bytes JMP 01000000
.text C:\Windows\system32\svchost.exe[1204] WININET.dll!InternetOpenA 761CD690 5 Bytes JMP 01A50FEF
.text C:\Windows\system32\svchost.exe[1204] WININET.dll!InternetOpenW 761CDB09 5 Bytes JMP 01A50014
.text C:\Windows\system32\svchost.exe[1204] WININET.dll!InternetOpenUrlA 761CF3A4 5 Bytes JMP 01A50025
.text C:\Windows\system32\svchost.exe[1204] WININET.dll!InternetOpenUrlW 76216DDF 5 Bytes JMP 01A50036
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!GetStartupInfoW 75EF1929 5 Bytes JMP 001D00D0
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!GetStartupInfoA 75EF19C9 5 Bytes JMP 001D00AB
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!CreateProcessW 75EF1BF3 5 Bytes JMP 001D0106
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!CreateProcessA 75EF1C28 5 Bytes JMP 001D0F6F
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!VirtualProtect 75EF1DC3 5 Bytes JMP 001D0089
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!CreateNamedPipeA 75EF2EF5 5 Bytes JMP 001D0011
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!CreateNamedPipeW 75EF5C0C 5 Bytes JMP 001D0022
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!CreatePipe 75F18E6E 5 Bytes JMP 001D0F80
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!LoadLibraryExW 75F19109 5 Bytes JMP 001D0FA5
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!LoadLibraryW 75F19362 5 Bytes JMP 001D0062
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!LoadLibraryExA 75F194B4 5 Bytes JMP 001D0FC0
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!LoadLibraryA 75F194DC 5 Bytes JMP 001D0047
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!VirtualProtectEx 75F1DBDA 5 Bytes JMP 001D009A
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!GetProcAddress 75F3903B 5 Bytes JMP 001D0117
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!CreateFileW 75F3AECB 5 Bytes JMP 001D0000
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!CreateFileA 75F3CE5F 5 Bytes JMP 001D0FEF
.text C:\Windows\system32\svchost.exe[1320] kernel32.dll!WinExec 75F85CF7 5 Bytes JMP 001D00EB
.text C:\Windows\system32\svchost.exe[1320] msvcrt.dll!_wsystem 76037F2F 5 Bytes JMP 001E0F90
.text C:\Windows\system32\svchost.exe[1320] msvcrt.dll!system 7603804B 5 Bytes JMP 001E0FAB
.text C:\Windows\system32\svchost.exe[1320] msvcrt.dll!_creat 7603BBE1 5 Bytes JMP 001E000A
.text C:\Windows\system32\svchost.exe[1320] msvcrt.dll!_open 7603D106 5 Bytes JMP 001E0FEF
.text C:\Windows\system32\svchost.exe[1320] msvcrt.dll!_wcreat 7603D326 5 Bytes JMP 001E001B
.text C:\Windows\system32\svchost.exe[1320] msvcrt.dll!_wopen 7603D501 5 Bytes JMP 001E0FD2
.text C:\Windows\system32\svchost.exe[1320] ADVAPI32.dll!RegCreateKeyExA 760F39AB 5 Bytes JMP 002A0062
.text C:\Windows\system32\svchost.exe[1320] ADVAPI32.dll!RegCreateKeyA 760F3BA9 5 Bytes JMP 002A0FC0
.text C:\Windows\system32\svchost.exe[1320] ADVAPI32.dll!RegOpenKeyA 760F89C7 5 Bytes JMP 002A0000
.text C:\Windows\system32\svchost.exe[1320] ADVAPI32.dll!RegCreateKeyW 7610391E 5 Bytes JMP 002A003D
.text C:\Windows\system32\svchost.exe[1320] ADVAPI32.dll!RegCreateKeyExW 761041F1 5 Bytes JMP 002A0F9B
.text C:\Windows\system32\svchost.exe[1320] ADVAPI32.dll!RegOpenKeyExA 76107C42 5 Bytes JMP 002A0011
.text C:\Windows\system32\svchost.exe[1320] ADVAPI32.dll!RegOpenKeyW 7610E2B5 5 Bytes JMP 002A0FDB
.text C:\Windows\system32\svchost.exe[1320] ADVAPI32.dll!RegOpenKeyExW 76117BA1 5 Bytes JMP 002A002C
.text C:\Windows\system32\svchost.exe[1320] WS2_32.dll!socket 760A36D1 5 Bytes JMP 00290FEF
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!GetStartupInfoW 75EF1929 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!GetStartupInfoW 75EF1929 5 Bytes JMP 001E0F2D
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!GetStartupInfoA 75EF19C9 5 Bytes JMP 001E0073
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!CreateProcessW 75EF1BF3 5 Bytes JMP 001E00B0
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!CreateProcessA 75EF1C28 5 Bytes JMP 001E009F
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!VirtualProtect 75EF1DC3 5 Bytes JMP 001E003D
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!CreateNamedPipeA 75EF2EF5 5 Bytes JMP 001E0FAF
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!CreateNamedPipeW 75EF5C0C 5 Bytes JMP 001E0F94
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!CreatePipe 75F18E6E 5 Bytes JMP 001E0058
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!LoadLibraryExW 75F19109 5 Bytes JMP 001E002C
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!LoadLibraryW 75F19362 5 Bytes JMP 001E0F6F
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!LoadLibraryExA 75F194B4 5 Bytes JMP 001E001B
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!LoadLibraryA 75F194DC 5 Bytes JMP 001E0000
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!VirtualProtectEx 75F1DBDA 5 Bytes JMP 001E0F48
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!GetProcAddress 75F3903B 5 Bytes JMP 001E0F08
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!CreateFileW 75F3AECB 5 Bytes JMP 001E0FD4
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!CreateFileA 75F3CE5F 5 Bytes JMP 001E0FEF
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!WinExec 75F85CF7 5 Bytes JMP 001E0084
.text C:\Windows\system32\svchost.exe[1376] msvcrt.dll!_wsystem 76037F2F 5 Bytes JMP 00DE0FC8
.text C:\Windows\system32\svchost.exe[1376] msvcrt.dll!system 7603804B 5 Bytes JMP 00DE0053
.text C:\Windows\system32\svchost.exe[1376] msvcrt.dll!_creat 7603BBE1 5 Bytes JMP 00DE002E
.text C:\Windows\system32\svchost.exe[1376] msvcrt.dll!_open 7603D106 5 Bytes JMP 00DE0000
.text C:\Windows\system32\svchost.exe[1376] msvcrt.dll!_wcreat 7603D326 5 Bytes JMP 00DE0FE3
.text C:\Windows\system32\svchost.exe[1376] msvcrt.dll!_wopen 7603D501 5 Bytes JMP 00DE001D
.text C:\Windows\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyExA 760F39AB 5 Bytes JMP 01090FBC
.text C:\Windows\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyA 760F3BA9 5 Bytes JMP 01090054
.text C:\Windows\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyA 760F89C7 5 Bytes JMP 01090FEF
.text C:\Windows\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyW 7610391E 5 Bytes JMP 01090FCD
.text C:\Windows\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyExW 761041F1 5 Bytes JMP 01090079
.text C:\Windows\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyExA 76107C42 5 Bytes JMP 0109001E
.text C:\Windows\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyW 7610E2B5 5 Bytes JMP 01090FDE
.text C:\Windows\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyExW 76117BA1 5 Bytes JMP 01090039
.text C:\Windows\system32\svchost.exe[1376] WS2_32.dll!socket 760A36D1 5 Bytes JMP 01000FE5
.text C:\Windows\system32\svchost.exe[1376] WinInet.dll!InternetOpenA 761CD690 5 Bytes JMP 010A0000
.text C:\Windows\system32\svchost.exe[1376] WinInet.dll!InternetOpenW 761CDB09 5 Bytes JMP 010A0011
.text C:\Windows\system32\svchost.exe[1376] WinInet.dll!InternetOpenUrlA 761CF3A4 5 Bytes JMP 010A0022
.text C:\Windows\system32\svchost.exe[1376] WinInet.dll!InternetOpenUrlW 76216DDF 5 Bytes JMP 010A0FDB
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!GetStartupInfoW 75EF1929 5 Bytes JMP 00820F46
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!GetStartupInfoA 75EF19C9 5 Bytes JMP 00820082
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!CreateProcessW 75EF1BF3 5 Bytes JMP 008200D3
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!CreateProcessA 75EF1C28 5 Bytes JMP 008200C2
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!VirtualProtect 75EF1DC3 5 Bytes JMP 0082003B
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!CreateNamedPipeA 75EF2EF5 5 Bytes JMP 0082000A
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!CreateNamedPipeW 75EF5C0C 5 Bytes JMP 00820FB9
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!CreatePipe 75F18E6E 5 Bytes JMP 00820067
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!LoadLibraryExW 75F19109 5 Bytes JMP 00820F57
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!LoadLibraryW 75F19362 5 Bytes JMP 00820F8D
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!LoadLibraryExA 75F194B4 5 Bytes JMP 00820F68
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!LoadLibraryA 75F194DC 5 Bytes JMP 00820F9E
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!VirtualProtectEx 75F1DBDA 5 Bytes JMP 0082004C
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!GetProcAddress 75F3903B 5 Bytes JMP 008200EE
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!CreateFileW 75F3AECB 5 Bytes JMP 00820FD4
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!CreateFileA 75F3CE5F 5 Bytes JMP 00820FEF
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!WinExec 75F85CF7 5 Bytes JMP 008200B1
.text C:\Windows\system32\svchost.exe[1592] msvcrt.dll!_wsystem 76037F2F 5 Bytes JMP 00830F89
.text C:\Windows\system32\svchost.exe[1592] msvcrt.dll!system 7603804B 5 Bytes JMP 00830F9A
.text C:\Windows\system32\svchost.exe[1592] msvcrt.dll!_creat 7603BBE1 5 Bytes JMP 00830FBC
.text C:\Windows\system32\svchost.exe[1592] msvcrt.dll!_open 7603D106 5 Bytes JMP 00830000
.text C:\Windows\system32\svchost.exe[1592] msvcrt.dll!_wcreat 7603D326 5 Bytes JMP 00830FAB
.text C:\Windows\system32\svchost.exe[1592] msvcrt.dll!_wopen 7603D501 5 Bytes JMP 00830FE3
.text C:\Windows\system32\svchost.exe[1592] ADVAPI32.dll!RegCreateKeyExA 760F39AB 5 Bytes JMP 00920069
.text C:\Windows\system32\svchost.exe[1592] ADVAPI32.dll!RegCreateKeyA 760F3BA9 5 Bytes JMP 00920058
.text C:\Windows\system32\svchost.exe[1592] ADVAPI32.dll!RegOpenKeyA 760F89C7 5 Bytes JMP 0092000A
.text C:\Windows\system32\svchost.exe[1592] ADVAPI32.dll!RegCreateKeyW 7610391E 5 Bytes JMP 00920FC7
.text C:\Windows\system32\svchost.exe[1592] ADVAPI32.dll!RegCreateKeyExW 761041F1 5 Bytes JMP 00920084
.text C:\Windows\system32\svchost.exe[1592] ADVAPI32.dll!RegOpenKeyExA 76107C42 5 Bytes JMP 00920036
.text C:\Windows\system32\svchost.exe[1592] ADVAPI32.dll!RegOpenKeyW 7610E2B5 5 Bytes JMP 0092001B
.text C:\Windows\system32\svchost.exe[1592] ADVAPI32.dll!RegOpenKeyExW 76117BA1 5 Bytes JMP 00920047
.text C:\Windows\system32\svchost.exe[1592] WS2_32.dll!socket 760A36D1 5 Bytes JMP 00880FE5
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!GetStartupInfoW 75EF1929 5 Bytes JMP 002B0F48
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!GetStartupInfoA 75EF19C9 5 Bytes JMP 002B0F63
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!CreateProcessW 75EF1BF3 5 Bytes JMP 002B0F12
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!CreateProcessA 75EF1C28 5 Bytes JMP 002B0F23
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!VirtualProtect 75EF1DC3 5 Bytes JMP 002B0F99
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!CreateNamedPipeA 75EF2EF5 5 Bytes JMP 002B001B
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!CreateNamedPipeW 75EF5C0C 5 Bytes JMP 002B002C
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!CreatePipe 75F18E6E 5 Bytes JMP 002B008E
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!LoadLibraryExW 75F19109 5 Bytes JMP 002B0073
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!LoadLibraryW 75F19362 5 Bytes JMP 002B0047
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!LoadLibraryExA 75F194B4 5 Bytes JMP 002B0058
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!LoadLibraryA 75F194DC 5 Bytes JMP 002B0FC0
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!VirtualProtectEx 75F1DBDA 5 Bytes JMP 002B0F7E
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!GetProcAddress 75F3903B 5 Bytes JMP 002B0EF7
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!CreateFileW 75F3AECB 5 Bytes JMP 002B0FE5
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!CreateFileA 75F3CE5F 5 Bytes JMP 002B0000
.text C:\Windows\system32\svchost.exe[1860] kernel32.dll!WinExec 75F85CF7 5 Bytes JMP 002B00A9
.text C:\Windows\system32\svchost.exe[1860] msvcrt.dll!_wsystem 76037F2F 5 Bytes JMP 009C003F
.text C:\Windows\system32\svchost.exe[1860] msvcrt.dll!system 7603804B 5 Bytes JMP 009C002E
.text C:\Windows\system32\svchost.exe[1860] msvcrt.dll!_creat 7603BBE1 5 Bytes JMP 009C001D
.text C:\Windows\system32\svchost.exe[1860] msvcrt.dll!_open 7603D106 5 Bytes JMP 009C0FEF
.text C:\Windows\system32\svchost.exe[1860] msvcrt.dll!_wcreat 7603D326 5 Bytes JMP 009C0FC8
.text C:\Windows\system32\svchost.exe[1860] msvcrt.dll!_wopen 7603D501 5 Bytes JMP 009C000C
.text C:\Windows\system32\svchost.exe[1860] ADVAPI32.dll!RegCreateKeyExA 760F39AB 5 Bytes JMP 00A2002F
.text C:\Windows\system32\svchost.exe[1860] ADVAPI32.dll!RegCreateKeyA 760F3BA9 5 Bytes JMP 00A20F9E
.text C:\Windows\system32\svchost.exe[1860] ADVAPI32.dll!RegOpenKeyA 760F89C7 5 Bytes JMP 00A20FEF
.text C:\Windows\system32\svchost.exe[1860] ADVAPI32.dll!RegCreateKeyW 7610391E 5 Bytes JMP 00A20F8D
.text C:\Windows\system32\svchost.exe[1860] ADVAPI32.dll!RegCreateKeyExW 761041F1 5 Bytes JMP 00A2004A
.text C:\Windows\system32\svchost.exe[1860] ADVAPI32.dll!RegOpenKeyExA 76107C42 5 Bytes JMP 00A20FCD
.text C:\Windows\system32\svchost.exe[1860] ADVAPI32.dll!RegOpenKeyW 7610E2B5 5 Bytes JMP 00A20FDE
.text C:\Windows\system32\svchost.exe[1860] ADVAPI32.dll!RegOpenKeyExW 76117BA1 5 Bytes JMP 00A20014
.text C:\Windows\system32\svchost.exe[1860] WS2_32.dll!socket 760A36D1 5 Bytes JMP 00A10FE5
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2232] kernel32.dll!LoadLibraryW 75F19362 5 Bytes JMP 0041C1B0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2232] kernel32.dll!LoadLibraryA 75F194DC 5 Bytes JMP 0041C130 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!GetStartupInfoW 75EF1929 5 Bytes JMP 006800DC
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!GetStartupInfoA 75EF19C9 5 Bytes JMP 00680F96
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!CreateProcessW 75EF1BF3 5 Bytes JMP 00680112
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!CreateProcessA 75EF1C28 5 Bytes JMP 006800F7
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!VirtualProtect 75EF1DC3 5 Bytes JMP 0068009F
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!CreateNamedPipeA 75EF2EF5 5 Bytes JMP 0068001B
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!CreateNamedPipeW 75EF5C0C 5 Bytes JMP 0068002C
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!CreatePipe 75F18E6E 5 Bytes JMP 006800CB
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!LoadLibraryExW 75F19109 5 Bytes JMP 0068008E
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!LoadLibraryW 75F19362 5 Bytes JMP 00680062
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!LoadLibraryExA 75F194B4 5 Bytes JMP 0068007D
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!LoadLibraryA 75F194DC 5 Bytes JMP 00680047
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!VirtualProtectEx 75F1DBDA 5 Bytes JMP 006800BA
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!GetProcAddress 75F3903B 5 Bytes JMP 00680123
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!CreateFileW 75F3AECB 5 Bytes JMP 00680FE5
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!CreateFileA 75F3CE5F 5 Bytes JMP 00680000
.text C:\Windows\system32\svchost.exe[2512] kernel32.dll!WinExec 75F85CF7 5 Bytes JMP 00680F85
.text C:\Windows\system32\svchost.exe[2512] msvcrt.dll!_wsystem 76037F2F 5 Bytes JMP 006F0FB7
.text C:\Windows\system32\svchost.exe[2512] msvcrt.dll!system 7603804B 5 Bytes JMP 006F0FC8
.text C:\Windows\system32\svchost.exe[2512] msvcrt.dll!_creat 7603BBE1 5 Bytes JMP 006F002E
.text C:\Windows\system32\svchost.exe[2512] msvcrt.dll!_open 7603D106 5 Bytes JMP 006F000C
.text C:\Windows\system32\svchost.exe[2512] msvcrt.dll!_wcreat 7603D326 5 Bytes JMP 006F0FD9
.text C:\Windows\system32\svchost.exe[2512] msvcrt.dll!_wopen 7603D501 5 Bytes JMP 006F001D
.text C:\Windows\system32\svchost.exe[2512] ADVAPI32.dll!RegCreateKeyExA 760F39AB 5 Bytes JMP 00870047
.text C:\Windows\system32\svchost.exe[2512] ADVAPI32.dll!RegCreateKeyA 760F3BA9 5 Bytes JMP 00870FAF
.text C:\Windows\system32\svchost.exe[2512] ADVAPI32.dll!RegOpenKeyA 760F89C7 5 Bytes JMP 0087000A
.text C:\Windows\system32\svchost.exe[2512] ADVAPI32.dll!RegCreateKeyW 7610391E 5 Bytes JMP 00870036
.text C:\Windows\system32\svchost.exe[2512] ADVAPI32.dll!RegCreateKeyExW 761041F1 5 Bytes JMP 00870058
.text C:\Windows\system32\svchost.exe[2512] ADVAPI32.dll!RegOpenKeyExA 76107C42 5 Bytes JMP 00870FE5
.text C:\Windows\system32\svchost.exe[2512] ADVAPI32.dll!RegOpenKeyW 7610E2B5 5 Bytes JMP 0087001B
.text C:\Windows\system32\svchost.exe[2512] ADVAPI32.dll!RegOpenKeyExW 76117BA1 5 Bytes JMP 00870FCA
.text C:\Windows\system32\svchost.exe[2512] WS2_32.dll!socket 760A36D1 5 Bytes JMP 00710000
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!GetStartupInfoW 75EF1929 5 Bytes JMP 003700DA
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!GetStartupInfoA 75EF19C9 5 Bytes JMP 00370F8A
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!CreateProcessW 75EF1BF3 5 Bytes JMP 00370F5E
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!CreateProcessA 75EF1C28 5 Bytes JMP 003700F5
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!VirtualProtect 75EF1DC3 5 Bytes JMP 00370FB6
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!CreateNamedPipeA 75EF2EF5 5 Bytes JMP 0037002C
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!CreateNamedPipeW 75EF5C0C 5 Bytes JMP 00370FE5
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!CreatePipe 75F18E6E 5 Bytes JMP 003700B5
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!LoadLibraryExW 75F19109 5 Bytes JMP 00370090
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!LoadLibraryW 75F19362 5 Bytes JMP 00370062
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!LoadLibraryExA 75F194B4 5 Bytes JMP 00370073
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!LoadLibraryA 75F194DC 5 Bytes JMP 00370051
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!VirtualProtectEx 75F1DBDA 5 Bytes JMP 00370FA5
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!GetProcAddress 75F3903B 5 Bytes JMP 00370110
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!CreateFileW 75F3AECB 5 Bytes JMP 0037001B
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!CreateFileA 75F3CE5F 5 Bytes JMP 00370000
.text C:\Windows\system32\svchost.exe[2652] kernel32.dll!WinExec 75F85CF7 5 Bytes JMP 00370F79
.text C:\Windows\system32\svchost.exe[2652] msvcrt.dll!_wsystem 76037F2F 5 Bytes JMP 00380F9A
.text C:\Windows\system32\svchost.exe[2652] msvcrt.dll!system 7603804B 5 Bytes JMP 00380FAB
.text C:\Windows\system32\svchost.exe[2652] msvcrt.dll!_creat 7603BBE1 5 Bytes JMP 00380FCD
.text C:\Windows\system32\svchost.exe[2652] msvcrt.dll!_open 7603D106 5 Bytes JMP 00380000
.text C:\Windows\system32\svchost.exe[2652] msvcrt.dll!_wcreat 7603D326 5 Bytes JMP 00380FBC
.text C:\Windows\system32\svchost.exe[2652] msvcrt.dll!_wopen 7603D501 5 Bytes JMP 00380011
.text C:\Windows\system32\svchost.exe[2652] ADVAPI32.dll!RegCreateKeyExA 760F39AB 3 Bytes JMP 009B0051
.text C:\Windows\system32\svchost.exe[2652] ADVAPI32.dll!RegCreateKeyExA + 4 760F39AF 1 Byte [8A]
.text C:\Windows\system32\svchost.exe[2652] ADVAPI32.dll!RegCreateKeyA 760F3BA9 3 Bytes JMP 009B0FCA
.text C:\Windows\system32\svchost.exe[2652] ADVAPI32.dll!RegCreateKeyA + 4 760F3BAD 1 Byte [8A]
.text C:\Windows\system32\svchost.exe[2652] ADVAPI32.dll!RegOpenKeyA 760F89C7 3 Bytes JMP 009B0000
.text C:\Windows\system32\svchost.exe[2652] ADVAPI32.dll!RegOpenKeyA + 4 760F89CB 1 Byte [8A]
.text C:\Windows\system32\svchost.exe[2652] ADVAPI32.dll!RegCreateKeyW 7610391E 5 Bytes JMP 009B0FAF
.text C:\Windows\system32\svchost.exe[2652] ADVAPI32.dll!RegCreateKeyExW 761041F1 5 Bytes JMP 009B0062
.text C:\Windows\system32\svchost.exe[2652] ADVAPI32.dll!RegOpenKeyExA 76107C42 5 Bytes JMP 009B002C
.text C:\Windows\system32\svchost.exe[2652] ADVAPI32.dll!RegOpenKeyW 7610E2B5 5 Bytes JMP 009B001B
.text C:\Windows\system32\svchost.exe[2652] ADVAPI32.dll!RegOpenKeyExW 76117BA1 5 Bytes JMP 009B0FDB
.text C:\Windows\system32\svchost.exe[2652] WS2_32.dll!socket 760A36D1 3 Bytes JMP 00960FEF
.text C:\Windows\system32\svchost.exe[2652] WS2_32.dll!socket + 4 760A36D5 1 Byte [8A]
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!GetStartupInfoW 75EF1929 5 Bytes JMP 00050F91
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!GetStartupInfoA 75EF19C9 5 Bytes JMP 000500D7
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!CreateProcessW 75EF1BF3 5 Bytes JMP 0005011E
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!CreateProcessA 75EF1C28 5 Bytes JMP 000500F9
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!VirtualProtect 75EF1DC3 5 Bytes JMP 00050090
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!CreateNamedPipeA 75EF2EF5 5 Bytes JMP 00050036
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!CreateNamedPipeW 75EF5C0C 5 Bytes JMP 00050FE5
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!CreatePipe 75F18E6E 5 Bytes JMP 000500B2
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!LoadLibraryExW 75F19109 5 Bytes JMP 00050073
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!LoadLibraryW 75F19362 5 Bytes JMP 00050FCA
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!LoadLibraryExA 75F194B4 5 Bytes JMP 00050062
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!LoadLibraryA 75F194DC 5 Bytes JMP 00050051
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!VirtualProtectEx 75F1DBDA 5 Bytes JMP 000500A1
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!GetProcAddress 75F3903B 5 Bytes JMP 00050F6C
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!CreateFileW 75F3AECB 5 Bytes JMP 00050011
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!CreateFileA 75F3CE5F 5 Bytes JMP 00050000
.text C:\Windows\System32\svchost.exe[2764] kernel32.dll!WinExec 75F85CF7 5 Bytes JMP 000500E8
.text C:\Windows\System32\svchost.exe[2764] msvcrt.dll!_wsystem 76037F2F 5 Bytes JMP 00060F90
.text C:\Windows\System32\svchost.exe[2764] msvcrt.dll!system 7603804B 5 Bytes JMP 00060FAB
.text C:\Windows\System32\svchost.exe[2764] msvcrt.dll!_creat 7603BBE1 5 Bytes JMP 00060FD7
.text C:\Windows\System32\svchost.exe[2764] msvcrt.dll!_open 7603D106 5 Bytes JMP 00060000
.text C:\Windows\System32\svchost.exe[2764] msvcrt.dll!_wcreat 7603D326 5 Bytes JMP 00060FC6
.text C:\Windows\System32\svchost.exe[2764] msvcrt.dll!_wopen 7603D501 5 Bytes JMP 00060011
.text C:\Windows\System32\svchost.exe[2764] ADVAPI32.dll!RegCreateKeyExA 760F39AB 5 Bytes JMP 00070039
.text C:\Windows\System32\svchost.exe[2764] ADVAPI32.dll!RegCreateKeyA 760F3BA9 5 Bytes JMP 00070F97
.text C:\Windows\System32\svchost.exe[2764] ADVAPI32.dll!RegOpenKeyA 760F89C7 5 Bytes JMP 00070FE5
.text C:\Windows\System32\svchost.exe[2764] ADVAPI32.dll!RegCreateKeyW 7610391E 5 Bytes JMP 00070028
.text C:\Windows\System32\svchost.exe[2764] ADVAPI32.dll!RegCreateKeyExW 761041F1 5 Bytes JMP 00070F86
.text C:\Windows\System32\svchost.exe[2764] ADVAPI32.dll!RegOpenKeyExA 76107C42 5 Bytes JMP 00070FC3
.text C:\Windows\System32\svchost.exe[2764] ADVAPI32.dll!RegOpenKeyW 7610E2B5 5 Bytes JMP 00070FD4
.text C:\Windows\System32\svchost.exe[2764] ADVAPI32.dll!RegOpenKeyExW 76117BA1 5 Bytes JMP 00070FB2
.text C:\Windows\System32\svchost.exe[2764] WS2_32.dll!socket 760A36D1 5 Bytes JMP 00160000

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

—- EOF - GMER 1.0.15 —-
lamar,

JavaRa …by: Paul McLain and Fred de Vries

Please download JavaRa (Copyright © 2008 RaProducts.org) and unzip it to your desktop.
***Please close any instances of Internet Explorer before continuing!***
Print these instructions…you won't have Internet access during this particular phase!
  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English or the appropriate language…and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.
  • Copy and paste the contents of the JavaRa log, in your next reply.

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
JavaRa took out some java updates i think but it didnt give me a log the only thing that appeared was a document with an unkown file that i cannot open


JavaRa.def so i cannot post the log


and heres is the combofix:

at the beggining it stated me that i had norton and t could gave me problems,… but i do have mcafee and i disable it , so i dont know why it syasy that i had norton virus protection active.. werd






ComboFix 09-12-07.04 - Owner 07/12/2009 19:20.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1918.1191 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
SP: Norton Internet Security *enabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-2638380620-1949518047-3134838997-500
c:\$recycle.bin\S-1-5-21-3195504165-2291815495-2145060001-500
c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
c:\programdata\ntuser.dat{cc861e8b-3f75-11dc-bce6-001a92c392e9}.TMContainer00000000000000000001.regtrans-ms
c:\programdata\ntuser.dat{cc861e9f-3f75-11dc-bce6-001a92c392e9}.TMContainer00000000000000000001.regtrans-ms

.
((((((((((((((((((((((((( Files Created from 2009-11-08 to 2009-12-08 )))))))))))))))))))))))))))))))
.

2009-12-08 01:30 . 2009-12-08 01:31 ——– d—–w- c:\users\Owner\AppData\Local\temp
2009-12-08 01:30 . 2009-12-08 01:30 ——– d—–w- c:\users\Default\AppData\Local\temp
2009-12-03 23:44 . 2009-12-03 23:44 4096 d—–w- c:\program files\ERUNT
2009-12-03 00:14 . 2009-06-20 08:04 607472 —-a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2009-11-30 20:52 . 2009-11-30 20:52 ——– d—–w- c:\programdata\Office Genuine Advantage
2009-11-30 17:58 . 2009-06-15 14:52 499712 —-a-w- c:\windows\system32\kerberos.dll
2009-11-30 17:58 . 2009-06-15 14:53 270848 —-a-w- c:\windows\system32\schannel.dll
2009-11-30 17:39 . 2009-12-02 23:47 8192 d—–w- c:\program files\Spybot - Search & Destroy
2009-11-30 17:39 . 2009-12-02 23:46 4096 d—–w- c:\programdata\Spybot - Search & Destroy
2009-11-30 17:08 . 2009-11-30 17:11 4096 d—–w- c:\program files\SpywareBlaster
2009-11-30 17:01 . 2009-11-30 17:01 ——– d—–w- c:\users\Owner\AppData\Roaming\Malwarebytes
2009-11-30 17:01 . 2009-09-10 20:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-30 17:01 . 2009-11-30 17:01 4096 d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-11-30 17:01 . 2009-11-30 17:01 ——– d—–w- c:\programdata\Malwarebytes
2009-11-30 17:01 . 2009-09-10 20:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-26 00:28 . 2009-10-29 09:17 2048 —-a-w- c:\windows\system32\tzres.dll
2009-11-25 16:14 . 2009-08-11 16:44 1401856 —-a-w- c:\windows\system32\msxml6.dll
2009-11-25 16:14 . 2009-08-11 16:44 1248768 —-a-w- c:\windows\system32\msxml3.dll
2009-11-18 15:52 . 2009-11-18 15:52 ——– d—–w- c:\program files\Windows Portable Devices
2009-11-18 01:11 . 2009-10-01 01:02 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-11-18 01:11 . 2009-10-01 01:02 31232 —-a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-11-18 01:11 . 2009-10-01 01:01 81920 —-a-w- c:\windows\system32\wpdbusenum.dll
2009-11-18 01:11 . 2009-10-01 01:01 60928 —-a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-11-18 01:11 . 2009-10-01 01:02 2537472 —-a-w- c:\windows\system32\wpdshext.dll
2009-11-18 01:11 . 2009-10-01 01:02 334848 —-a-w- c:\windows\system32\PortableDeviceApi.dll
2009-11-18 01:11 . 2009-10-01 01:02 87552 —-a-w- c:\windows\system32\WPDShServiceObj.dll
2009-11-18 01:11 . 2009-10-01 01:01 546816 —-a-w- c:\windows\system32\wpd_ci.dll
2009-11-18 01:11 . 2009-10-01 01:01 160256 —-a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-11-18 01:11 . 2009-10-01 01:01 350208 —-a-w- c:\windows\system32\WPDSp.dll
2009-11-18 01:11 . 2009-10-01 01:01 196608 —-a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-11-18 01:11 . 2009-10-01 01:01 100864 —-a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-11-18 01:10 . 2009-10-08 21:07 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2009-11-18 01:10 . 2009-10-08 21:08 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-11-18 01:10 . 2009-10-08 21:08 234496 —-a-w- c:\windows\system32\oleacc.dll
2009-11-11 23:01 . 2009-08-14 13:27 2036736 —-a-w- c:\windows\system32\win32k.sys
2009-11-11 23:01 . 2009-08-10 12:35 355328 —-a-w- c:\windows\system32\WSDApi.dll
2009-11-11 06:28 . 2009-11-11 06:28 247280 —-a-w- c:\users\Owner\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-07 23:13 . 2009-12-07 23:13 658184 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-03 22:18 . 2007-08-16 19:54 4096 d—–w- c:\users\Owner\AppData\Roaming\Yahoo!
2009-12-03 22:18 . 2007-07-27 19:41 4096 d—–w- c:\programdata\Yahoo!
2009-12-03 00:14 . 2007-02-09 14:31 4096 d—–w- c:\program files\Yahoo!
2009-12-02 01:09 . 2009-01-02 19:14 4096 d—–w- c:\users\Owner\AppData\Roaming\Skype
2009-12-02 00:50 . 2008-09-15 20:08 4096 d—–w- c:\program files\McAfee
2009-12-02 00:40 . 2009-01-02 19:17 ——– d—–w- c:\users\Owner\AppData\Roaming\skypePM
2009-12-01 16:52 . 2008-09-15 20:02 4096 d—–w- c:\programdata\McAfee
2009-11-30 18:11 . 2007-02-09 14:15 8192 d—–w- c:\programdata\Microsoft Help
2009-11-30 18:04 . 2007-02-09 14:14 24576 d—–w- c:\program files\Microsoft Works
2009-11-30 17:22 . 2008-04-07 17:04 4096 d—–w- c:\program files\Java
2009-11-20 17:03 . 2007-08-03 17:43 40960 d—–w- c:\program files\PamperedPartnerSP
2009-11-19 23:18 . 2007-08-02 20:00 1410 —-a-w- c:\users\Owner\AppData\Roaming\wklnhst.dat
2009-11-18 15:51 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-11-18 15:51 . 2009-11-18 15:51 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-12 16:05 . 2006-11-02 11:18 4096 d—–w- c:\program files\Windows Mail
2009-10-28 17:20 . 2009-10-28 17:20 ——– d—–w- c:\program files\Common Files\SWF Studio
2009-10-20 23:04 . 2008-06-10 17:08 4096 d—–w- c:\program files\Windows Live
2009-10-16 22:45 . 2007-02-09 14:09 4096 d—–w- c:\programdata\Roxio
2009-10-13 20:34 . 2008-05-21 22:09 ——– d—–w- c:\program files\Common Files\Adobe
2009-10-11 10:17 . 2009-05-08 22:11 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-09-25 02:10 . 2009-11-18 01:12 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-11-18 01:12 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04 . 2009-11-18 01:12 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49 . 2009-11-18 01:12 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48 . 2009-11-18 01:12 351232 —-a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38 . 2009-11-18 01:12 847360 —-a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36 . 2009-11-18 01:12 280064 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35 . 2009-11-18 01:12 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33 . 2009-11-18 01:12 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33 . 2009-11-18 01:12 829440 —-a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33 . 2009-11-18 01:12 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32 . 2009-11-18 01:12 252928 —-a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31 . 2009-11-18 01:12 519680 —-a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31 . 2009-11-18 01:12 486912 —-a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31 . 2009-11-18 01:12 161280 —-a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31 . 2009-11-18 01:12 218112 —-a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31 . 2009-11-18 01:12 1030144 —-a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31 . 2009-11-18 01:12 828928 —-a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30 . 2009-11-18 01:12 481792 —-a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30 . 2009-11-18 01:12 190464 —-a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27 . 2009-11-18 01:12 634880 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27 . 2009-11-18 01:12 37888 —-a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27 . 2009-11-18 01:12 793088 —-a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27 . 2009-11-18 01:12 1064448 —-a-w- c:\windows\system32\DWrite.dll
2009-09-24 22:54 . 2009-11-18 01:12 258048 —-a-w- c:\windows\system32\winspool.drv
2009-09-24 22:54 . 2009-11-18 01:12 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54 . 2009-11-18 01:12 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-16 15:22 . 2008-09-15 20:09 79816 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 15:22 . 2008-09-15 20:09 40552 —-a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 15:22 . 2008-09-15 20:09 35272 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 15:22 . 2008-06-27 11:08 214664 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 15:22 . 2008-09-15 20:05 34248 —-a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-14 09:29 . 2009-10-15 15:29 144896 —-a-w- c:\windows\system32\drivers\srv2.sys
2009-09-10 16:48 . 2009-10-15 15:29 218624 —-a-w- c:\windows\system32\msv1_0.dll
2009-09-10 14:59 . 2009-10-28 15:29 8147456 —-a-w- c:\windows\system32\wmploc.DLL
2009-09-10 14:58 . 2009-10-28 15:30 310784 —-a-w- c:\windows\system32\unregmp2.exe
2009-09-10 02:01 . 2009-11-18 01:12 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2009-09-10 02:00 . 2009-11-18 01:12 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2009-09-10 02:00 . 2009-11-18 01:12 92672 —-a-w- c:\windows\system32\UIAnimation.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"Google Update"="c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-07-01 133104]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2006-11-20 155648]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 4874240]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-11-15 1121016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-07-31 271672]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-07-25 29744]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 92704]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-25 44136]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
VirtualExpander.lnk - c:\users\Owner\AppData\Local\Sony Corporation\VirtualExpander\VirtualExpander.exe [2007-11-23 474808]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-4-9 972064]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2006-10-3 54776]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Connections.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Connections.lnk
backup=c:\windows\pss\HP Connections.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
2006-11-24 00:53 1480296 —-a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):7c,18,01,12,24,e4,c9,01

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [15/09/2008 02:10 p.m. 93320]
R3 hcw18bda;Hauppauge WinTV 418 Driver;c:\windows\System32\drivers\hcw18bda.sys [19/03/2009 09:50 p.m. 391168]
S2 gupdate1c9df196c3e980b;Servicio de actualización de Google (gupdate1c9df196c3e980b);c:\program files\Google\Update\GoogleUpdate.exe [27/05/2009 04:21 p.m. 133104]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [20/06/2008 09:30 a.m. 21504]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [20/10/2009 05:04 p.m. 54632]
S3 fsssvc;Servicio de Windows Live Protección infantil;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 09:48 p.m. 704864]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [03/12/2007 01:27 p.m. 29744]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\mip2e4bu.default\
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1591.6512\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Owner\AppData\Local\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\users\Owner\AppData\Local\Yahoo!\BrowserPlus\2.4.17\Plugins\npybrowserplus_2.4.17.dll
FF - plugin: c:\users\Owner\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKCU-Run-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
AddRemove-{2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\Google\Google Toolbar\Component\GoogleToolbarManager_9DE96A29E721D90A.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-07 19:31
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-12-07 19:35
ComboFix-quarantined-files.txt 2009-12-08 01:35

Pre-Run: 398,828,765,184 bytes free
Post-Run: 398,775,529,472 bytes free

- - End Of File - - 09C7BD6DF49B3747DDCB08CA22FD5597
lamar,

Use the link below to see how to run the Norton Removal Tool
http://service1.symantec.com/SUPPORT/tsgen…005033108162039

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    SecCenter::
    {E10A9785-9598-4754-B552-92431C1C35F8}
    {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
    {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
I DID THE COMBofix script and the kalspersky detection, seems like my firefox still freezing when i make a search on any search engine :(, any idea??





ComboFix 09-12-08.07 - Owner 09/12/2009 10:31:20.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1918.809 [GMT -6:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2009-11-09 to 2009-12-09 )))))))))))))))))))))))))))))))
.

2009-12-09 16:37 . 2009-12-09 16:37 ——– d—–w- c:\users\Owner\AppData\Local\temp
2009-12-09 16:37 . 2009-12-09 16:37 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2009-12-09 16:37 . 2009-12-09 16:37 ——– d—–w- c:\users\ReleaseEngineer.MACROVISION\AppData\Local\temp
2009-12-09 16:37 . 2009-12-09 16:37 ——– d—–w- c:\users\Public\AppData\Local\temp
2009-12-09 16:37 . 2009-12-09 16:37 ——– d—–w- c:\users\Default\AppData\Local\temp
2009-12-09 16:28 . 2009-12-09 16:28 ——– d—–w- C:\32788R22FWJFW
2009-12-07 23:13 . 2009-12-07 23:13 658184 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-05 17:25 . 2009-12-05 17:25 ——– d—–w- c:\users\Owner\AppData\Local\Apple Computer
2009-12-04 00:33 . 2009-12-04 00:33 ——– d—–w- c:\users\Owner\AppData\Local\Adobe
2009-12-03 23:44 . 2009-12-03 23:44 ——– d—–w- c:\program files\ERUNT
2009-12-03 00:14 . 2009-06-20 08:04 607472 —-a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2009-11-30 20:52 . 2009-11-30 20:52 ——– d—–w- c:\programdata\Office Genuine Advantage
2009-11-30 17:58 . 2009-06-15 14:52 499712 —-a-w- c:\windows\system32\kerberos.dll
2009-11-30 17:58 . 2009-06-15 14:53 270848 —-a-w- c:\windows\system32\schannel.dll
2009-11-30 17:39 . 2009-12-02 23:47 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-11-30 17:39 . 2009-12-02 23:46 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2009-11-30 17:08 . 2009-11-30 17:11 ——– d—–w- c:\program files\SpywareBlaster
2009-11-30 17:01 . 2009-11-30 17:01 ——– d—–w- c:\users\Owner\AppData\Roaming\Malwarebytes
2009-11-30 17:01 . 2009-09-10 20:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-30 17:01 . 2009-11-30 17:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-11-30 17:01 . 2009-11-30 17:01 ——– d—–w- c:\programdata\Malwarebytes
2009-11-30 17:01 . 2009-09-10 20:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-26 00:28 . 2009-10-29 09:17 2048 —-a-w- c:\windows\system32\tzres.dll
2009-11-25 16:14 . 2009-08-11 16:44 1401856 —-a-w- c:\windows\system32\msxml6.dll
2009-11-25 16:14 . 2009-08-11 16:44 1248768 —-a-w- c:\windows\system32\msxml3.dll
2009-11-18 15:52 . 2009-11-18 15:52 ——– d—–w- c:\program files\Windows Portable Devices
2009-11-18 01:11 . 2009-10-01 01:02 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-11-18 01:11 . 2009-10-01 01:02 31232 —-a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-11-18 01:11 . 2009-10-01 01:01 81920 —-a-w- c:\windows\system32\wpdbusenum.dll
2009-11-18 01:11 . 2009-10-01 01:01 60928 —-a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-11-18 01:11 . 2009-10-01 01:02 2537472 —-a-w- c:\windows\system32\wpdshext.dll
2009-11-18 01:11 . 2009-10-01 01:02 334848 —-a-w- c:\windows\system32\PortableDeviceApi.dll
2009-11-18 01:11 . 2009-10-01 01:02 87552 —-a-w- c:\windows\system32\WPDShServiceObj.dll
2009-11-18 01:11 . 2009-10-01 01:01 546816 —-a-w- c:\windows\system32\wpd_ci.dll
2009-11-18 01:11 . 2009-10-01 01:01 160256 —-a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-11-18 01:11 . 2009-10-01 01:01 350208 —-a-w- c:\windows\system32\WPDSp.dll
2009-11-18 01:11 . 2009-10-01 01:01 196608 —-a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-11-18 01:11 . 2009-10-01 01:01 100864 —-a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-11-18 01:10 . 2009-10-08 21:07 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2009-11-18 01:10 . 2009-10-08 21:08 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-11-18 01:10 . 2009-10-08 21:08 234496 —-a-w- c:\windows\system32\oleacc.dll
2009-11-11 23:01 . 2009-08-14 13:27 2036736 —-a-w- c:\windows\system32\win32k.sys
2009-11-11 23:01 . 2009-08-10 12:35 355328 —-a-w- c:\windows\system32\WSDApi.dll
2009-11-11 06:28 . 2009-11-11 06:28 247280 —-a-w- c:\users\Owner\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-03 22:18 . 2007-08-16 19:54 ——– d—–w- c:\users\Owner\AppData\Roaming\Yahoo!
2009-12-03 22:18 . 2007-07-27 19:41 ——– d—–w- c:\programdata\Yahoo!
2009-12-03 00:14 . 2007-02-09 14:31 ——– d—–w- c:\program files\Yahoo!
2009-12-02 01:09 . 2009-01-02 19:14 ——– d—–w- c:\users\Owner\AppData\Roaming\Skype
2009-12-02 00:50 . 2008-09-15 20:08 ——– d—–w- c:\program files\McAfee
2009-12-02 00:40 . 2009-01-02 19:17 ——– d—–w- c:\users\Owner\AppData\Roaming\skypePM
2009-12-01 16:52 . 2008-09-15 20:02 ——– d—–w- c:\programdata\McAfee
2009-11-30 18:11 . 2007-02-09 14:15 ——– d—–w- c:\programdata\Microsoft Help
2009-11-30 18:04 . 2007-02-09 14:14 ——– d—–w- c:\program files\Microsoft Works
2009-11-30 17:22 . 2008-04-07 17:04 ——– d—–w- c:\program files\Java
2009-11-20 17:03 . 2007-08-03 17:43 ——– d—–w- c:\program files\PamperedPartnerSP
2009-11-19 23:18 . 2007-08-02 20:00 1410 —-a-w- c:\users\Owner\AppData\Roaming\wklnhst.dat
2009-11-18 15:51 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-11-18 15:51 . 2009-11-18 15:51 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-12 16:05 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-10-28 17:20 . 2009-10-28 17:20 ——– d—–w- c:\program files\Common Files\SWF Studio
2009-10-20 23:04 . 2008-06-10 17:08 ——– d—–w- c:\program files\Windows Live
2009-10-16 22:45 . 2007-02-09 14:09 ——– d—–w- c:\programdata\Roxio
2009-10-13 20:34 . 2008-05-21 22:09 ——– d—–w- c:\program files\Common Files\Adobe
2009-10-11 10:17 . 2009-05-08 22:11 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-09-25 02:10 . 2009-11-18 01:12 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-11-18 01:12 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04 . 2009-11-18 01:12 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49 . 2009-11-18 01:12 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48 . 2009-11-18 01:12 351232 —-a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38 . 2009-11-18 01:12 847360 —-a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36 . 2009-11-18 01:12 280064 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35 . 2009-11-18 01:12 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33 . 2009-11-18 01:12 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33 . 2009-11-18 01:12 829440 —-a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33 . 2009-11-18 01:12 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32 . 2009-11-18 01:12 252928 —-a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31 . 2009-11-18 01:12 519680 —-a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31 . 2009-11-18 01:12 486912 —-a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31 . 2009-11-18 01:12 161280 —-a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31 . 2009-11-18 01:12 218112 —-a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31 . 2009-11-18 01:12 1030144 —-a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31 . 2009-11-18 01:12 828928 —-a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30 . 2009-11-18 01:12 481792 —-a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30 . 2009-11-18 01:12 190464 —-a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27 . 2009-11-18 01:12 634880 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27 . 2009-11-18 01:12 37888 —-a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27 . 2009-11-18 01:12 793088 —-a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27 . 2009-11-18 01:12 1064448 —-a-w- c:\windows\system32\DWrite.dll
2009-09-24 22:54 . 2009-11-18 01:12 258048 —-a-w- c:\windows\system32\winspool.drv
2009-09-24 22:54 . 2009-11-18 01:12 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54 . 2009-11-18 01:12 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-16 15:22 . 2008-09-15 20:09 79816 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 15:22 . 2008-09-15 20:09 40552 —-a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 15:22 . 2008-09-15 20:09 35272 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 15:22 . 2008-06-27 11:08 214664 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 15:22 . 2008-09-15 20:05 34248 —-a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-14 09:29 . 2009-10-15 15:29 144896 —-a-w- c:\windows\system32\drivers\srv2.sys
2009-09-10 16:48 . 2009-10-15 15:29 218624 —-a-w- c:\windows\system32\msv1_0.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-12-08_01.31.39 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-02-09 14:44 . 2009-12-08 00:58 63758 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2007-02-09 14:44 . 2009-12-09 16:12 63758 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-12-09 16:12 63206 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2007-06-23 22:05 . 2009-12-09 16:12 10030 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3195504165-2291815495-2145060001-1000_UserData.bin
- 2007-06-23 22:05 . 2009-12-08 00:58 10030 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3195504165-2291815495-2145060001-1000_UserData.bin
+ 2007-06-23 22:02 . 2009-12-09 16:13 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2007-06-23 22:02 . 2009-12-08 00:59 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2007-06-23 22:02 . 2009-12-08 00:59 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-06-23 22:02 . 2009-12-09 16:13 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-06-23 22:02 . 2009-12-09 16:13 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-06-23 22:02 . 2009-12-08 00:59 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-04-24 23:14 . 2009-12-07 23:03 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-04-24 23:14 . 2009-12-09 16:11 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-04-24 23:14 . 2009-12-09 16:11 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-04-24 23:14 . 2009-12-07 23:03 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-04-24 23:14 . 2009-12-09 16:11 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-04-24 23:14 . 2009-12-07 23:03 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-08-07 22:38 . 2009-12-08 00:57 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-08-07 22:38 . 2009-12-09 16:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2007-08-07 22:38 . 2009-12-08 00:57 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-08-07 22:38 . 2009-12-09 16:11 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-08-07 22:38 . 2009-12-08 00:57 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-08-07 22:38 . 2009-12-09 16:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-09 16:19 . 2009-12-09 16:25 7318 c:\windows\SoftwareDistribution\EventCache\{A9F9850E-1D89-4307-AF30-9E2D00B848DB}.bin
- 2009-12-08 00:57 . 2009-12-08 00:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-12-09 16:11 . 2009-12-09 16:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-12-09 16:11 . 2009-12-09 16:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-12-08 00:57 . 2009-12-08 00:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-10-16 20:10 . 2009-12-09 16:16 245760 c:\windows\System32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat
- 2009-10-16 20:10 . 2009-12-07 21:53 245760 c:\windows\System32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat
- 2006-11-02 10:22 . 2009-11-30 20:49 7077888 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 10:22 . 2009-12-09 16:17 7077888 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-12-09 16:29 . 2009-12-09 16:29 6905856 c:\windows\ERDNT\Hiv-backup\schema.dat
+ 2009-05-30 15:18 . 2009-12-09 16:24 220754854 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"Google Update"="c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-07-01 133104]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2006-11-20 155648]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 4874240]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-11-15 1121016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-07-31 271672]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-07-25 29744]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 92704]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-25 44136]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
VirtualExpander.lnk - c:\users\Owner\AppData\Local\Sony Corporation\VirtualExpander\VirtualExpander.exe [2007-11-23 474808]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-4-9 972064]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2006-10-3 54776]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Connections.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Connections.lnk
backup=c:\windows\pss\HP Connections.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
2006-11-24 00:53 1480296 —-a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):7c,18,01,12,24,e4,c9,01

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [15/09/2008 02:10 p.m. 93320]
R3 hcw18bda;Hauppauge WinTV 418 Driver;c:\windows\System32\drivers\hcw18bda.sys [19/03/2009 09:50 p.m. 391168]
S2 gupdate1c9df196c3e980b;Servicio de actualización de Google (gupdate1c9df196c3e980b);c:\program files\Google\Update\GoogleUpdate.exe [27/05/2009 04:21 p.m. 133104]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [20/06/2008 09:30 a.m. 21504]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [20/10/2009 05:04 p.m. 54632]
S3 fsssvc;Servicio de Windows Live Protección infantil;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 09:48 p.m. 704864]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [03/12/2007 01:27 p.m. 29744]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\mip2e4bu.default\
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1591.6512\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Owner\AppData\Local\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\users\Owner\AppData\Local\Yahoo!\BrowserPlus\2.4.17\Plugins\npybrowserplus_2.4.17.dll
FF - plugin: c:\users\Owner\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-09 10:37
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(5560)
c:\progra~1\mcafee\SITEAD~1\saHook.dll
.
Completion time: 2009-12-09 10:40:19
ComboFix-quarantined-files.txt 2009-12-09 16:40
ComboFix2.txt 2009-12-08 01:35

Pre-Run: 398,642,614,272 bytes free
Post-Run: 398,601,388,032 bytes free

- - End Of File - - 564205B33851F25700BB0FD7080AD3DC







——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Wednesday, December 9, 2009
Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Wednesday, December 09, 2009 11:12:15
Records in database: 3346997
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan statistics:
Objects scanned: 159546
Threats found: 0
Infected objects found: 0
Suspicious objects found: 0
Scan duration: 02:09:31

No threats found. Scanned area is clean.
lamar,

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Folder::
    C:\32788R22FWJFW
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
EVERYTHING DONE TOMK, I really appreciate the help that u are providing… but still, my firefox freezes everytime i use any search engine like google, yahoo.etc…. i even tried to uninstall firefox and installing it again and still the same :(.. do i have a virus or its an error on a file or something?

thnx man



GooredFix by jpshortstuff (06.12.09.1)
Log created at 17:36 on 09/12/2009 (Owner)
Firefox version 3.5.5 (en-US)

========== GooredScan ==========


========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\
{635abd67-4fe9-1b23-4f01-e679fa7484c1} [23:27 08/05/2009]
{972ce4c6-7e08-4474-a285-3208198ce6fd} [23:21 03/12/2009]
{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [14:38 14/08/2009]
{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [17:22 30/11/2009]

C:\Users\Owner\Application Data\Mozilla\Firefox\Profiles\mip2e4bu.default\extensions\
{20a82645-c095-46ed-80e3-08825760534b} [23:27 03/12/2009]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{B7082FAA-CB62-4872-9106-E42DD88EDE45}"="C:\Program Files\McAfee\SiteAdvisor" [20:10 15/09/2008]
"{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [22:32 08/05/2009]

-=E.O.F=-








ComboFix 09-12-09.04 - Owner 09/12/2009 17:42:41.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1918.1120 [GMT -6:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\cfSCRIPT.TXT
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2009-11-09 to 2009-12-09 )))))))))))))))))))))))))))))))
.

2009-12-09 23:50 . 2009-12-09 23:50 ——– d—–w- c:\users\Owner\AppData\Local\temp
2009-12-09 23:50 . 2009-12-09 23:50 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2009-12-09 23:50 . 2009-12-09 23:50 ——– d—–w- c:\users\ReleaseEngineer.MACROVISION\AppData\Local\temp
2009-12-09 23:50 . 2009-12-09 23:50 ——– d—–w- c:\users\Public\AppData\Local\temp
2009-12-09 23:50 . 2009-12-09 23:50 ——– d—–w- c:\users\Default\AppData\Local\temp
2009-12-09 16:47 . 2009-12-09 16:47 ——– d—–w- c:\windows\Sun
2009-12-07 23:13 . 2009-12-07 23:13 658184 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-05 17:25 . 2009-12-05 17:25 ——– d—–w- c:\users\Owner\AppData\Local\Apple Computer
2009-12-04 00:33 . 2009-12-04 00:33 ——– d—–w- c:\users\Owner\AppData\Local\Adobe
2009-12-03 23:44 . 2009-12-03 23:44 ——– d—–w- c:\program files\ERUNT
2009-12-03 00:14 . 2009-06-20 08:04 607472 —-a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2009-11-30 20:52 . 2009-11-30 20:52 ——– d—–w- c:\programdata\Office Genuine Advantage
2009-11-30 17:58 . 2009-06-15 14:52 499712 —-a-w- c:\windows\system32\kerberos.dll
2009-11-30 17:58 . 2009-06-15 14:53 270848 —-a-w- c:\windows\system32\schannel.dll
2009-11-30 17:39 . 2009-12-02 23:47 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-11-30 17:39 . 2009-12-02 23:46 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2009-11-30 17:08 . 2009-11-30 17:11 ——– d—–w- c:\program files\SpywareBlaster
2009-11-30 17:01 . 2009-11-30 17:01 ——– d—–w- c:\users\Owner\AppData\Roaming\Malwarebytes
2009-11-30 17:01 . 2009-09-10 20:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-30 17:01 . 2009-11-30 17:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-11-30 17:01 . 2009-11-30 17:01 ——– d—–w- c:\programdata\Malwarebytes
2009-11-30 17:01 . 2009-09-10 20:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-26 00:28 . 2009-10-29 09:17 2048 —-a-w- c:\windows\system32\tzres.dll
2009-11-25 16:14 . 2009-08-11 16:44 1401856 —-a-w- c:\windows\system32\msxml6.dll
2009-11-25 16:14 . 2009-08-11 16:44 1248768 —-a-w- c:\windows\system32\msxml3.dll
2009-11-18 15:52 . 2009-11-18 15:52 ——– d—–w- c:\program files\Windows Portable Devices
2009-11-18 01:11 . 2009-10-01 01:02 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-11-18 01:11 . 2009-10-01 01:02 31232 —-a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-11-18 01:11 . 2009-10-01 01:01 81920 —-a-w- c:\windows\system32\wpdbusenum.dll
2009-11-18 01:11 . 2009-10-01 01:01 60928 —-a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-11-18 01:11 . 2009-10-01 01:02 2537472 —-a-w- c:\windows\system32\wpdshext.dll
2009-11-18 01:11 . 2009-10-01 01:02 334848 —-a-w- c:\windows\system32\PortableDeviceApi.dll
2009-11-18 01:11 . 2009-10-01 01:02 87552 —-a-w- c:\windows\system32\WPDShServiceObj.dll
2009-11-18 01:11 . 2009-10-01 01:01 546816 —-a-w- c:\windows\system32\wpd_ci.dll
2009-11-18 01:11 . 2009-10-01 01:01 160256 —-a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-11-18 01:11 . 2009-10-01 01:01 350208 —-a-w- c:\windows\system32\WPDSp.dll
2009-11-18 01:11 . 2009-10-01 01:01 196608 —-a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-11-18 01:11 . 2009-10-01 01:01 100864 —-a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-11-18 01:10 . 2009-10-08 21:07 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2009-11-18 01:10 . 2009-10-08 21:08 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-11-18 01:10 . 2009-10-08 21:08 234496 —-a-w- c:\windows\system32\oleacc.dll
2009-11-11 23:01 . 2009-08-14 13:27 2036736 —-a-w- c:\windows\system32\win32k.sys
2009-11-11 23:01 . 2009-08-10 12:35 355328 —-a-w- c:\windows\system32\WSDApi.dll
2009-11-11 06:28 . 2009-11-11 06:28 247280 —-a-w- c:\users\Owner\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-03 22:18 . 2007-08-16 19:54 ——– d—–w- c:\users\Owner\AppData\Roaming\Yahoo!
2009-12-03 22:18 . 2007-07-27 19:41 ——– d—–w- c:\programdata\Yahoo!
2009-12-03 00:14 . 2007-02-09 14:31 ——– d—–w- c:\program files\Yahoo!
2009-12-02 01:09 . 2009-01-02 19:14 ——– d—–w- c:\users\Owner\AppData\Roaming\Skype
2009-12-02 00:50 . 2008-09-15 20:08 ——– d—–w- c:\program files\McAfee
2009-12-02 00:40 . 2009-01-02 19:17 ——– d—–w- c:\users\Owner\AppData\Roaming\skypePM
2009-12-01 16:52 . 2008-09-15 20:02 ——– d—–w- c:\programdata\McAfee
2009-11-30 18:11 . 2007-02-09 14:15 ——– d—–w- c:\programdata\Microsoft Help
2009-11-30 18:04 . 2007-02-09 14:14 ——– d—–w- c:\program files\Microsoft Works
2009-11-30 17:22 . 2008-04-07 17:04 ——– d—–w- c:\program files\Java
2009-11-20 17:03 . 2007-08-03 17:43 ——– d—–w- c:\program files\PamperedPartnerSP
2009-11-19 23:18 . 2007-08-02 20:00 1410 —-a-w- c:\users\Owner\AppData\Roaming\wklnhst.dat
2009-11-18 15:51 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-11-18 15:51 . 2009-11-18 15:51 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-12 16:05 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-10-28 17:20 . 2009-10-28 17:20 ——– d—–w- c:\program files\Common Files\SWF Studio
2009-10-20 23:04 . 2008-06-10 17:08 ——– d—–w- c:\program files\Windows Live
2009-10-16 22:45 . 2007-02-09 14:09 ——– d—–w- c:\programdata\Roxio
2009-10-13 20:34 . 2008-05-21 22:09 ——– d—–w- c:\program files\Common Files\Adobe
2009-10-11 10:17 . 2009-05-08 22:11 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-09-25 02:10 . 2009-11-18 01:12 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-11-18 01:12 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04 . 2009-11-18 01:12 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49 . 2009-11-18 01:12 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48 . 2009-11-18 01:12 351232 —-a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38 . 2009-11-18 01:12 847360 —-a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36 . 2009-11-18 01:12 280064 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35 . 2009-11-18 01:12 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33 . 2009-11-18 01:12 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33 . 2009-11-18 01:12 829440 —-a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33 . 2009-11-18 01:12 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32 . 2009-11-18 01:12 252928 —-a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31 . 2009-11-18 01:12 519680 —-a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31 . 2009-11-18 01:12 486912 —-a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31 . 2009-11-18 01:12 161280 —-a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31 . 2009-11-18 01:12 218112 —-a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31 . 2009-11-18 01:12 1030144 —-a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31 . 2009-11-18 01:12 828928 —-a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30 . 2009-11-18 01:12 481792 —-a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30 . 2009-11-18 01:12 190464 —-a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27 . 2009-11-18 01:12 634880 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27 . 2009-11-18 01:12 37888 —-a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27 . 2009-11-18 01:12 793088 —-a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27 . 2009-11-18 01:12 1064448 —-a-w- c:\windows\system32\DWrite.dll
2009-09-24 22:54 . 2009-11-18 01:12 258048 —-a-w- c:\windows\system32\winspool.drv
2009-09-24 22:54 . 2009-11-18 01:12 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54 . 2009-11-18 01:12 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-16 15:22 . 2008-09-15 20:09 79816 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 15:22 . 2008-09-15 20:09 40552 —-a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 15:22 . 2008-09-15 20:09 35272 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 15:22 . 2008-06-27 11:08 214664 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 15:22 . 2008-09-15 20:05 34248 —-a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-14 09:29 . 2009-10-15 15:29 144896 —-a-w- c:\windows\system32\drivers\srv2.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-12-08_01.31.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-02-09 14:44 . 2009-12-09 16:46 63774 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-12-09 16:46 63206 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2007-06-23 22:05 . 2009-12-08 00:58 10030 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3195504165-2291815495-2145060001-1000_UserData.bin
+ 2007-06-23 22:05 . 2009-12-09 16:46 10030 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3195504165-2291815495-2145060001-1000_UserData.bin
+ 2007-06-23 22:02 . 2009-12-09 16:46 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2007-06-23 22:02 . 2009-12-08 00:59 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-06-23 22:02 . 2009-12-09 16:46 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-06-23 22:02 . 2009-12-08 00:59 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-06-23 22:02 . 2009-12-09 16:46 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-06-23 22:02 . 2009-12-08 00:59 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-04-24 23:14 . 2009-12-07 23:03 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-04-24 23:14 . 2009-12-09 16:11 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-04-24 23:14 . 2009-12-07 23:03 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-04-24 23:14 . 2009-12-09 16:11 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-04-24 23:14 . 2009-12-09 16:11 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-04-24 23:14 . 2009-12-07 23:03 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-08-07 22:38 . 2009-12-08 00:57 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-08-07 22:38 . 2009-12-09 16:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-08-07 22:38 . 2009-12-09 16:11 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-08-07 22:38 . 2009-12-08 00:57 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-08-07 22:38 . 2009-12-08 00:57 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-08-07 22:38 . 2009-12-09 16:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-09 16:44 . 2009-12-09 16:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-12-08 00:57 . 2009-12-08 00:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-12-08 00:57 . 2009-12-08 00:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-12-09 16:44 . 2009-12-09 16:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-10-16 20:10 . 2009-12-09 21:11 245760 c:\windows\System32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat
- 2009-10-16 20:10 . 2009-12-07 21:53 245760 c:\windows\System32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat
- 2006-11-02 10:22 . 2009-11-30 20:49 7077888 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 10:22 . 2009-12-09 16:43 7077888 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-05-30 15:18 . 2009-12-09 16:24 220754854 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe -scheduler" [X]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"Google Update"="c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-07-01 133104]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe -hide" [X]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe -atboottime" [X]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2006-11-20 155648]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 4874240]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-11-15 1121016]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-07-31 271672]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-07-25 29744]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 92704]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-25 44136]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
VirtualExpander.lnk - c:\users\Owner\AppData\Local\Sony Corporation\VirtualExpander\VirtualExpander.exe [2007-11-23 474808]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-4-9 972064]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2006-10-3 54776]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Connections.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Connections.lnk
backup=c:\windows\pss\HP Connections.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
2006-11-24 00:53 1480296 —-a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):7c,18,01,12,24,e4,c9,01

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [15/09/2008 02:10 p.m. 93320]
R3 hcw18bda;Hauppauge WinTV 418 Driver;c:\windows\System32\drivers\hcw18bda.sys [19/03/2009 09:50 p.m. 391168]
S2 gupdate1c9df196c3e980b;Servicio de actualización de Google (gupdate1c9df196c3e980b);c:\program files\Google\Update\GoogleUpdate.exe [27/05/2009 04:21 p.m. 133104]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [20/06/2008 09:30 a.m. 21504]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [20/10/2009 05:04 p.m. 54632]
S3 fsssvc;Servicio de Windows Live Protección infantil;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 09:48 p.m. 704864]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [03/12/2007 01:27 p.m. 29744]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\mip2e4bu.default\
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1591.6512\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Owner\AppData\Local\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\users\Owner\AppData\Local\Yahoo!\BrowserPlus\2.4.17\Plugins\npybrowserplus_2.4.17.dll
FF - plugin: c:\users\Owner\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-09 17:50
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(4512)
c:\progra~1\mcafee\SITEAD~1\saHook.dll
.
Completion time: 2009-12-09 17:53:07
ComboFix-quarantined-files.txt 2009-12-09 23:53
ComboFix2.txt 2009-12-09 16:40
ComboFix3.txt 2009-12-08 01:35

Pre-Run: 398,496,952,320 bytes free
Post-Run: 398,542,761,984 bytes free

- - End Of File - - CF95F3A43884458E2993A7326BF77F9B
lamar,

I'm not sure. :blush:

I'm not finding anything serious. We cleaned up a little adware and then just dusted out some of the dross hanging around.

At this point, I think you will be better served by the tech team. They know much more about the inner workings of the OS than I do. I suggest that you post in the Windows forum. When you do post, please provide a link there back to this thread so that they will have access to your logs.

Meanwhile, as far as malware is concerned, Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /Uninstall in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.

Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI