This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] DNSChanger.as, Mcafee finds it but can not delete the .dll

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

C:\WINDOWS\system32\kaziduwo.dll is one of the files mcafee finds but cannot delete. computer is running horribly slow, redirects webpages. MBAM wont run at all. Mcafee pops up every 2 seconds with the virus detection but cant delete the files. sometimes programs like minitab wont open at all.

again mbam wont open so i dont have that log file but here are the DDS adn the gmer logs.

GMER log

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-09 22:25:26
Windows 5.1.2600 Service Pack 3
Running: pls5rq81.exe; Driver: C:\DOCUME~1\pcarrill\LOCALS~1\Temp\awliapog.sys

GMER
—- System - GMER 1.0.15 —-

SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateKey [0xF743BE52]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xF741CCDE]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xF741CED0]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteKey [0xF743C640]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteValueKey [0xF743C8F4]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwOpenKey [0xF743AB44]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xF743CD60]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwSetValueKey [0xF743C112]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xF741C984]

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0x9AA4322F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x9AA43285]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0x9AA43243]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x9AA4329B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0x9AA4326F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!ZwYieldExecution 80515A6A 7 Bytes JMP 9AA43273 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtCreateFile 8057C328 5 Bytes JMP 9AA43233 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 8057DEF1 5 Bytes JMP 9AA4329F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtMapViewOfSection 8057E369 7 Bytes JMP 9AA43289 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 80581889 7 Bytes JMP 9AA43247 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? C:\WINDOWS\system32\drivers\atapi.sys The process cannot access the file because it is being used by another process.

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 036E0FEF
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 036E0076
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 036E0065
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 036E0054
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 036E0F97
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 036E001E
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 036E0F55
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 036E009D
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 036E00DD
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 036E0F44
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 036E00F8
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 036E0039
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 036E0FDE
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 036E0F66
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 036E0FB2
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 036E0FC3
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 036E00C2
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 036D0FC3
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 036D0F7C
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 036D000A
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 036D0FD4
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 036D0F8D
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 036D0FE5
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 036D0FA8
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [8D, 8B]
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 036D002F
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 036C0FA6
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!system 77C293C7 5 Bytes JMP 036C0FB7
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 036C0FE3
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!_open 77C2F566 5 Bytes JMP 036C0000
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 036C0FC8
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 036C001D
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] WS2_32.dll!socket 71AB4211 5 Bytes JMP 036A0FEF
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 036B0000
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 036B0FE5
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 036B0011
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 036B0022
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 015A0FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 015A0F66
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 015A0F81
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 015A005B
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 015A004A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 015A0FC3
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 015A0F38
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 015A0F55
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 015A0F16
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 015A00AF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 015A00CA
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 015A0FB2
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 015A0FDE
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 015A0080
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 015A002F
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 015A000A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 015A0F27
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01590FDE
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01590F97
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0159002F
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01590FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01590FA8
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0159000A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01590FC3
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [79, 89] {JNS 0xffffffffffffff8b}
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0159004A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01580FB9
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!system 77C293C7 5 Bytes JMP 01580044
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01580029
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01580FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01580FD4
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01580018
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] WS2_32.dll!socket 71AB4211 5 Bytes JMP 0156000A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 01570FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 01570014
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 01570025
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 01570040
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01080000
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01080F96
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0108008B
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0108007A
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01080FBD
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0108004E
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 010800BC
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01080F74
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01080F3E
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 010800D7
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 010800E8
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0108005F
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01080011
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01080F85
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0108003D
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0108002C
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01080F59
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01070FCA
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01070F8D
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0107001B
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0107000A
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01070F9E
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01070FEF
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01070FAF
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [27, 89]
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01070036
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01060FCF
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!system 77C293C7 5 Bytes JMP 0106005A
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0106002E
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01060000
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0106003F
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0106001D
.text C:\WINDOWS\system32\svchost.exe[920] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FF0FE5
.text C:\WINDOWS\system32\svchost.exe[920] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 01050FEF
.text C:\WINDOWS\system32\svchost.exe[920] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 01050000
.text C:\WINDOWS\system32\svchost.exe[920] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 01050011
.text C:\WINDOWS\system32\svchost.exe[920] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 0105002C
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FD000A
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FD0F72
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FD0071
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FD0054
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FD0043
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FD0FA8
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FD0F35
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FD0F50
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FD00C7
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FD0F24
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FD0F13
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FD0F97
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FD0FEF
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FD0F61
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FD0FB9
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FD0FDE
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FD0098
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00070036
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00070F79
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00070FEF
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00070025
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00070F94
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0007000A
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00070FA5
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [27, 88]
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00070FC0
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00060FBE
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!system 77C293C7 5 Bytes JMP 00060049
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0006001D
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00060FEF
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0006002E
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00060000
.text C:\WINDOWS\system32\services.exe[996] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00040000
.text C:\WINDOWS\system32\services.exe[996] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00050000
.text C:\WINDOWS\system32\services.exe[996] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00050011
.text C:\WINDOWS\system32\services.exe[996] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00050FD1
.text C:\WINDOWS\system32\services.exe[996] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00050022
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 016D0000
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 016D0F79
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 016D0F8A
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 016D0058
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 016D0F9B
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 016D0FCA
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 016D0F37
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 016D0F48
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 016D00AB
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 016D0F1C
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 016D00C6
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 016D0047
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 016D001B
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 016D007F
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 016D0FDB
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 016D002C
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 016D009A
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 016C002C
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 016C0FA8
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 016C001B
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 016C0FE5
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 016C0FB9
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 016C0000
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 016C0051
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 016C0FCA
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 016B003D
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!system 77C293C7 5 Bytes JMP 016B002C
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 016B0FC6
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_open 77C2F566 5 Bytes JMP 016B0000
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 016B001B
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 016B0FE3
.text C:\WINDOWS\system32\lsass.exe[1008] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01690FE5
.text C:\WINDOWS\system32\lsass.exe[1008] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 016A0FEF
.text C:\WINDOWS\system32\lsass.exe[1008] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 016A000A
.text C:\WINDOWS\system32\lsass.exe[1008] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 016A0025
.text C:\WINDOWS\system32\lsass.exe[1008] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 016A0FD4
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0109000A
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01090F61
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01090F7C
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0109004A
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01090F8D
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01090FB9
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01090F35
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01090F46
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01090098
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01090F09
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01090EE4
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01090FA8
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0109001B
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01090071
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01090FD4
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01090FEF
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01090F24
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01080FC0
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01080F8A
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01080011
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01080000
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01080047
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01080FE5
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 01080036
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01080FAF
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01070FA6
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!system 77C293C7 5 Bytes JMP 01070FB7
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01070FE3
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01070000
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01070FC8
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0107001D
.text C:\WINDOWS\system32\svchost.exe[1188] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01050FE5
.text C:\WINDOWS\system32\svchost.exe[1188] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 01060000
.text C:\WINDOWS\system32\svchost.exe[1188] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 01060FEF
.text C:\WINDOWS\system32\svchost.exe[1188] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 01060025
.text C:\WINDOWS\system32\svchost.exe[1188] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 01060036
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 011B0000
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 011B0F66
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 011B005B
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 011B004A
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 011B0F8D
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 011B0F9E
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 011B0087
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 011B0F4B
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 011B00C7
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 011B00A2
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 011B00D8
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 011B002F
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 011B0FE5
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 011B0076
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 011B0FAF
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 011B0FD4
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 011B0F24
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0112002F
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01120F83
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01120FD4
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01120FEF
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01120F9E
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01120000
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 01120040
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01120FC3
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01110FA8
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!system 77C293C7 5 Bytes JMP 01110033
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01110018
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01110FEF
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01110FC3
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01110FDE
.text C:\WINDOWS\system32\svchost.exe[1264] WS2_32.dll!socket 71AB4211 5 Bytes JMP 010F0FE5
.text C:\WINDOWS\system32\svchost.exe[1264] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 01100000
.text C:\WINDOWS\system32\svchost.exe[1264] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 0110001B
.text C:\WINDOWS\system32\svchost.exe[1264] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 01100036
.text C:\WINDOWS\system32\svchost.exe[1264] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 01100FEF
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02C20FEF
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02C20062
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02C2003D
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02C20F63
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02C2002C
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02C20FAF
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02C20F2B
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02C2007D
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02C20EEB
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02C2008E
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02C2009F
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02C20F94
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02C20FD4
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02C20F52
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02C2001B
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02C2000A
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02C20F1A
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01DD002C
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01DD0062
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01DD0FDB
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01DD0011
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01DD0051
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01DD0000
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01DD0FAF
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [FD, 89]
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01DD0FCA
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01DC0F8B
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!system 77C293C7 5 Bytes JMP 01DC0F9C
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01DC0FC8
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01DC0000
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01DC0FB7
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01DC0FE3
.text C:\WINDOWS\System32\svchost.exe[1312] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01DA0FE5
.text C:\WINDOWS\System32\svchost.exe[1312] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 01DB0000
.text C:\WINDOWS\System32\svchost.exe[1312] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 01DB0FE5
.text C:\WINDOWS\System32\svchost.exe[1312] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 01DB0011
.text C:\WINDOWS\System32\svchost.exe[1312] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 01DB0022
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E00FE5
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E00F4B
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E00036
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E00F5C
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E00F79
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E00025
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E00F0E
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E00F1F
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E00067
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E00ECE
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00E00078
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00E00F9E
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00E0000A
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00E00F3A
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00E00FB9
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00E00FD4
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00E00EE9
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00DF0F9E
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00DF0F68
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00DF0FB9
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00DF0FCA
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00DF0025
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00DF0FEF
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00DF0F83
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [FF, 88]
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00DF000A
.text C:\WINDOWS\system32\svchost.exe[1392] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00F6000A
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00DE0F8B
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!system 77C293C7 5 Bytes JMP 00DE0FA6
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00DE0FD2
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00DE0000
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00DE0FB7
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00DE0FE3
.text C:\WINDOWS\system32\svchost.exe[1392] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00DC0FEF
.text C:\WINDOWS\system32\svchost.exe[1392] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00DD0000
.text C:\WINDOWS\system32\svchost.exe[1392] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00DD0FEF
.text C:\WINDOWS\system32\svchost.exe[1392] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00DD0FCA
.text C:\WINDOWS\system32\svchost.exe[1392] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00DD0FB9
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F20FEF
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F2008C
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F2007B
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F20FA1
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F20FBC
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F20FCD
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F20F5F
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F200A7
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F20F29
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F20F44
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F200DD
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F2005E
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F2000A
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F20F7C
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F2002F
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F20FDE
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F200B8
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00F10FEF
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00F1006C
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00F10040
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00F10025
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00F10FB9
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00F10000
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00F10FD4
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [11, 89]
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00F1005B
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00F00FAB
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!system 77C293C7 5 Bytes JMP 00F00FBC
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00F00FCD
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00F00FEF
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00F00022
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00F00FDE
.text C:\WINDOWS\system32\svchost.exe[1524] WS2_32.dll!socket 71AB4211 5 Bytes JMP 001B0000
.text C:\WINDOWS\system32\svchost.exe[1524] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00EF0000
.text C:\WINDOWS\system32\svchost.exe[1524] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00EF0011
.text C:\WINDOWS\system32\svchost.exe[1524] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00EF0022
.text C:\WINDOWS\system32\svchost.exe[1524] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00EF0FD1
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F80FEF
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F800A1
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F80086
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F80069
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F80058
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F8002C
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F80F7E
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F80F8F
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F80F48
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F800E1
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F80F37
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F8003D
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F80FDE
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F800BC
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F8001B
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F8000A
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F80F59
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00EA0025
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00EA005B
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00EA0014
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00EA0FDE
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00EA0040
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00EA0FEF
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00EA0F9E
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [0A, 89]
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00EA0FAF
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E90FCA
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E90055
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E90029
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E90000
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E9003A
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E90FEF
.text C:\WINDOWS\system32\svchost.exe[1956] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00E70000
.text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00E80000
.text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00E80FEF
.text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00E80FD4
.text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00E80025
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01360FE5
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01360049
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01360038
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01360F5E
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0136001B
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01360F94
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01360089
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0136006E
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01360F01
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01360F1C
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01360EF0
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01360F79
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01360FD4
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreatePipe 7C81D83F 1 Byte [E9]
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01360F43
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01360FA5
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01360000
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 0136009A
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01350040
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01350087
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01350025
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0135000A
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01350076
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01350FEF
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01350FCA
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [55, 89]
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0135005B
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00FF0F92
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!system 77C293C7 5 Bytes JMP 00FF001D
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00FF0FC8
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00FF0000
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00FF0FB7
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00FF0FE3
.text C:\WINDOWS\System32\svchost.exe[3528] WS2_32.dll!socket 71AB4211 5 Bytes JMP 001A0000
.text C:\WINDOWS\System32\svchost.exe[3528] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 001B0000
.text C:\WINDOWS\System32\svchost.exe[3528] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 001B0011
.text C:\WINDOWS\System32\svchost.exe[3528] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 001B0022
.text C:\WINDOWS\System32\svchost.exe[3528] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 001B0FD1
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02A80FEF
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02A8004D
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02A80F58
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02A80F69
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02A80F86
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02A80FA8
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02A80F36
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02A80F47
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02A80EF6
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02A80F97
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02A80FD4
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02A80068
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02A8000A
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02A80FB9
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02A80099
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02A70FE5
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 02A70FAF
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 02A70036
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 02A7001B
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02A70FC0
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 02A7000A
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 02A70062
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02A70047
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02A6005A
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!system 77C293C7 5 Bytes JMP 02A60049
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02A60FD9
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02A60000
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02A60038
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02A6001D
.text C:\WINDOWS\Explorer.EXE[3836] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 02A50FEF
.text C:\WINDOWS\Explorer.EXE[3836] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 02A50FCA
.text C:\WINDOWS\Explorer.EXE[3836] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 02A50FB9
.text C:\WINDOWS\Explorer.EXE[3836] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 02A50014
.text C:\WINDOWS\Explorer.EXE[3836] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02A40FE5

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\Explorer.EXE [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Classes\CLSID\{6CB39D60-4086-B7F8-381D8F903EAF6AF0}\{AFC2635D-FADA-3E20-D0B5B6B6E250D71B}\{28C204A2-D9FA-6C6E-1B551E281BAD6C81}
Reg HKLM\SOFTWARE\Classes\CLSID\{6CB39D60-4086-B7F8-381D8F903EAF6AF0}\{AFC2635D-FADA-3E20-D0B5B6B6E250D71B}\{28C204A2-D9FA-6C6E-1B551E281BAD6C81}@{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1 0x01 0x00 0x01 0x00 …
Reg HKLM\SOFTWARE\Classes\CLSID\{A1146105-B145-D547-791CC80E83BF21B6}\{DC78455E-4161-0768-1856DB98A0FFD8AF}\{619B65F9-9B50-CD99-3F29A63495E25D6C}
Reg HKLM\SOFTWARE\Classes\CLSID\{A1146105-B145-D547-791CC80E83BF21B6}\{DC78455E-4161-0768-1856DB98A0FFD8AF}\{619B65F9-9B50-CD99-3F29A63495E25D6C}@RA4KGUJC6T6LBNJRIDQ63C2L6C1 0x01 0x00 0x01 0x00 …

—- EOF - GMER 1.0.15 —-


DDS log


DDS (Ver_09-12-01.01) - NTFSx86 NETWORK
Run by [removed] at 6:28:29.32 on Wed 02/10/2010
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3536.2827 [GMT -7:00]

AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\pcarrill\Desktop\dds.pif

============== Pseudo HJT Report ===============

uWindow Title = Windows Internet Explorer provided by Mosaic
uStart Page = hxxp://employee.mosaicco.com/
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_11\bin\ssv.dll
BHO: ADC PlugIn: {77dc0baa-3235-4ba9-8be8-aa9eb678fa02} - c:\program files\adc32.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptcl.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
uRun: [ISUSPM] "c:\documents and settings\all users\application data\macrovision\flexnet connect\6\ISUSPM.exe" -scheduler
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\UdaterUI.exe" /StartedFromRunKey
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Sfopikoq] rundll32.exe "c:\windows\ohivukov.dll",Startup
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [milepihew] Rundll32.exe "c:\windows\system32\pokitiwi.dll",a
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [Communicator] "c:\program files\microsoft office communicator\Communicator.exe"
mPolicies-explorer: NoWelcomeScreen = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_11\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
Trusted Zone: buy-is2010.com
Trusted Zone: cargill.com\hrdirect
Trusted Zone: cargill.com\smaccess.ds
Trusted Zone: is-soft-download.com
Trusted Zone: is-software-download.com
Trusted Zone: is10-soft-download.com
Trusted Zone: mosaicco.com\alsharepoint
Trusted Zone: mosaicco.com\it
Trusted Zone: mosaicco.com\mgts
Trusted Zone: mosaicco.com\ps1.pmo
Trusted Zone: mosaicco.com\sites.project
Trusted Zone: mosaicco.com\wdsharepoint
Trusted Zone: mosaicco.com\webmail
Trusted Zone: mosaicco.com\www.pmo
Trusted Zone: wdwebprd2
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
Trusted Zone: buy-is2010.com
Trusted Zone: cargill.com\hrdirect
Trusted Zone: cargill.com\smaccess.ds
Trusted Zone: mosaicco.com\alsharepoint
Trusted Zone: mosaicco.com\it
Trusted Zone: mosaicco.com\mgts
Trusted Zone: mosaicco.com\ps1.pmo
Trusted Zone: mosaicco.com\sites.project
Trusted Zone: mosaicco.com\wdsharepoint
Trusted Zone: mosaicco.com\webmail
Trusted Zone: mosaicco.com\www.pmo
Trusted Zone: wdwebprd2
DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} - hxxps://vpn2.mosaicco.com/vdesk/terminal/urxvpn.cab#version=6031,2009,1010,313
DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} - hxxps://vpn2.mosaicco.com/vdesk/terminal/f5tunsrv.cab#version=6031,2009,1010,310
DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} - hxxps://vpn2.mosaicco.com/vdesk/terminal/InstallerControl.cab#version=6031,2009,1010,0312
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1243366726630
DPF: {6C275925-A1ED-4DD2-9CEE-9823F5FDAA10} - hxxps://vpn1.mosaicco.com/vdesk/terminal/urTermProxy.cab#version=6020,2007,1001,2136
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1243366697098
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} - hxxps://vpn2.mosaicco.com/vdesk/terminal/urxshost.cab#version=6031,2009,1010,308
DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} - hxxps://vpn2.mosaicco.com/vdesk/terminal/urxhost.cab#version=6031,2009,1010,304
Handler: saphtmlp - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\sapgui\SAPHTMLP.DLL
Handler: sapr3 - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\sapgui\SAPHTMLP.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\tusugemo.dll kaziduwo.dll c:\windows\system32\pokitiwi.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: penedahet - {7d7e192b-e486-4107-a9c0-ec81e981a533} - c:\windows\system32\tusugemo.dll
SSODL: vajazozoh - {76c938f6-8593-41a0-ac23-5fa8d8ddf15f} - c:\windows\system32\pokitiwi.dll
STS: mujuzedij: {7d7e192b-e486-4107-a9c0-ec81e981a533} - c:\windows\system32\tusugemo.dll
STS: tokatiluy: {76c938f6-8593-41a0-ac23-5fa8d8ddf15f} - c:\windows\system32\pokitiwi.dll
LSA: Notification Packages = scecli deqmabFi.dll jivobumo.dll
Hosts: 216.203.33.144 vpn1.mosaicco.com #ADDED BY F5 NETWORKS SSL TUNNEL - ORIGINAL RECORD#
Hosts: [removed] vpn1 #ADDED BY F5 NETWORKS SSL TUNNEL - ORIGINAL RECORD#
================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\pcarrill\applic~1\mozilla\firefox\profiles\xia7xztq.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://mail.live.com/default.aspx?wa=wsignin1.0
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - prefs.js: network.proxy.type - 2
FF - plugin: c:\documents and settings\pcarrill\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\pcarrill\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJPI150_11.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPOJI610.dll
FF - HiddenExtension: XULRunner: {70660533-012F-4BC3-A5DA-BA8C628D8037} - c:\documents and settings\pcarrill\local settings\application data\{70660533-012F-4BC3-A5DA-BA8C628D8037}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-2-1 207792]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [2008-12-31 244368]
R3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\drivers\covpndrv.sys [2009-10-9 33920]
S1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2009-1-27 31848]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\spyware doctor\bdt\BDTUpdateService.exe [2010-2-1 112592]
S2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2008-9-25 103744]
S2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2009-1-27 144704]
S2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2009-1-27 54608]
S3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2009-11-16 108160]
S3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [2008-12-31 32808]
S3 f5ipfw;F5 Networks StoneWall Filter;c:\windows\system32\drivers\urfltw2k.sys [2009-12-2 10752]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2009-11-16 110080]
S3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2008-9-25 73512]
S3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2008-9-25 34408]
S3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2008-9-25 177864]
S3 OracleOraHome81ClientCache;OracleOraHome81ClientCache;c:\oracle\ora81\bin\onrsd.exe –> c:\oracle\ora81\bin\ONRSD.EXE [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2010-2-1 359624]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2010-2-1 1141712]

=============== Created Last 30 ================

2010-02-08 13:37:25 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-08 13:37:24 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-08 13:37:24 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-07 17:21:04 0 —-a-w- c:\windows\Yfezuqol.bin
2010-02-07 17:21:02 120 —-a-w- c:\windows\Twefoboxebod.dat
2010-02-07 13:13:03 0 d—–w- c:\program files\schtml
2010-02-07 13:08:35 962560 —-a-w- c:\program files\adc32.dll
2010-02-07 13:08:33 56 —-a-w- c:\program files\wp4.dat
2010-02-07 13:08:33 4 —-a-w- c:\program files\wp3.dat
2010-02-07 13:08:33 36 —-a-w- c:\program files\skynet.dat
2010-02-07 13:08:25 0 d—–w- c:\program files\Your PC Protector
2010-02-02 18:56:16 0 —-a-w- c:\windows\system32\29358.exe
2010-02-02 18:36:15 0 —-a-w- c:\windows\system32\11478.exe
2010-02-02 18:16:14 0 —-a-w- c:\windows\system32\15724.exe
2010-02-02 17:56:13 0 —-a-w- c:\windows\system32\19169.exe
2010-02-02 04:31:07 767952 —-a-w- c:\windows\BDTSupport.dll
2010-02-02 04:31:06 882 —-a-w- c:\windows\RegSDImport.xml
2010-02-02 04:31:06 879 —-a-w- c:\windows\RegISSImport.xml
2010-02-02 04:31:06 165840 —-a-w- c:\windows\PCTBDRes.dll
2010-02-02 04:31:06 1652688 —-a-w- c:\windows\PCTBDCore.dll
2010-02-02 04:31:06 1640400 —-a-w- c:\windows\PCTBDCore.dll.old
2010-02-02 04:31:06 149456 —-a-w- c:\windows\SGDetectionTool.dll
2010-02-02 04:31:06 131 —-a-w- c:\windows\IDB.zip
2010-02-02 04:31:06 1152444 —-a-w- c:\windows\UDB.zip
2010-02-02 04:29:09 7387 —-a-w- c:\windows\system32\drivers\pctgntdi.cat
2010-02-02 04:29:09 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-02-02 04:29:07 7412 —-a-w- c:\windows\system32\drivers\PCTAppEvent.cat
2010-02-02 04:29:07 7383 —-a-w- c:\windows\system32\drivers\pctcore.cat
2010-02-02 04:29:07 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2010-02-02 04:29:06 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-02-02 04:29:00 7383 —-a-w- c:\windows\system32\drivers\pctplsg.cat
2010-02-02 04:29:00 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2010-02-02 04:28:46 0 d—–w- c:\program files\Spyware Doctor
2010-02-02 04:28:46 0 d—–w- c:\program files\common files\PC Tools
2010-02-02 04:28:46 0 d—–w- c:\docume~1\pcarrill\applic~1\PC Tools
2010-02-02 04:28:46 0 d—–w- c:\docume~1\alluse~1\applic~1\PC Tools
2010-02-02 04:01:35 0 —-a-w- c:\windows\system32\26500.exe
2010-02-02 03:41:34 0 —-a-w- c:\windows\system32\6334.exe
2010-02-02 03:21:34 0 —-a-w- c:\windows\system32\18467.exe
2010-02-02 03:01:33 0 —-a-w- c:\windows\system32\41.exe
2010-01-26 16:00:34 0 d—–w- c:\docume~1\pcarrill\applic~1\Macrovision
2010-01-25 20:15:02 0 d—–w- c:\windows\system32\E177E04D548C4006A465EEB92D3DE021
2010-01-25 20:14:56 65 —-a-w- c:\windows\minitab.ini
2010-01-25 20:14:05 0 d—–w- c:\program files\Minitab 15
2010-01-21 21:04:40 0 d—–w- c:\windows\system32\rc
2010-01-21 20:42:38 0 d—–w- c:\docume~1\pcarrill\applic~1\Malwarebytes
2010-01-21 19:07:21 0 d—–w- c:\program files\Microsoft Visual Studio 8
2010-01-21 18:59:57 79872 -c—-w- c:\windows\system32\dllcache\raschap.dll
2010-01-21 18:59:57 66560 -c–a-w- c:\windows\system32\dllcache\tdc.ocx
2010-01-21 18:59:57 149504 -c—-w- c:\windows\system32\dllcache\rastls.dll
2010-01-21 18:59:55 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-21 18:59:54 270336 -c—-w- c:\windows\system32\dllcache\oakley.dll
2010-01-21 04:57:21 0 d—–w- c:\program files\uTorrent
2010-01-21 04:57:14 0 d—–w- c:\docume~1\pcarrill\applic~1\uTorrent
2010-01-20 23:58:10 0 d—–w- c:\program files\True Sword 5
2010-01-20 21:52:11 0 d—–w- c:\program files\RADO Removal Tool[1]
2010-01-14 05:50:17 79040 —ha-w- c:\windows\system32\mlfcache.dat

==================== Find3M ====================

2010-02-07 13:08:54 9 —-a-w- c:\program files\nuar.old
2010-01-26 15:57:47 2725698 —ha-w- c:\docume~1\pcarrill\applic~1\logs.dat
2010-01-10 02:55:10 21928 —-a-w- c:\windows\fonts\Princess_Sparkle_Font_by_darnfancylettuce.ttf
2010-01-10 02:52:17 7808 —-a-w- c:\windows\fonts\meow_font_by_pinktooney7.ttf
2009-12-27 04:07:48 126148 —-a-w- c:\windows\fonts\Sony_Sketch_Bold_205.ttf
2009-12-16 04:58:38 50772 —-a-w- c:\windows\fonts\sunshineinmysoul.ttf
2009-12-06 16:09:14 17680 —-a-w- c:\windows\fonts\heyyyy.ttf
2009-11-16 20:49:08 402006 —-a-w- c:\windows\system32\ScreenSaverMosaic.scr
1601-01-01 00:03:28 93696 –sha-w- c:\windows\system32\duzurosa.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\fivajubu.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\fivefoda.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\fodituva.dll
1601-01-01 00:03:28 93696 –sha-w- c:\windows\system32\gedoneno.dll
1601-01-01 00:03:52 53760 –sha-w- c:\windows\system32\jivobumo.dll
1601-01-01 00:03:52 53760 –sha-w- c:\windows\system32\kaziduwo.dll
1601-01-01 00:03:28 94208 –sha-w- c:\windows\system32\kiwatehu.dll
1601-01-01 00:03:28 93184 –sha-w- c:\windows\system32\lemutuja.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\nepihene.dll
1601-01-01 00:03:28 93696 –sha-w- c:\windows\system32\pokitiwi.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\pubonepo.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\selulisa.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\telariva.dll
1601-01-01 00:03:28 42496 –sha-w- c:\windows\system32\tesegigo.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\tifunalo.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\wopeneda.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\yehuruma.dll

============= FINISH: 6:30:09.85 ===============

thank you very much for you help.
Hi,

Please do the following:


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Thank you for your help! and sorry for the late reply, i was out of town for the holiday weekend and didnt bring this laptop since its not running properly. here is my combo fix log. it says i had that AV running, but i tried shutting it off and could not, when i brought up task manager it didnt show anything running and i had closed everything in the tray. so i just ran it.

ComboFix 10-02-12.01 - pcarrill 02/16/2010 6:44.1.2 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3536.3089 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\pcarrill\Application Data\logs.dat
c:\program files\nuar.old
c:\program files\wp3.dat
c:\program files\wp4.dat
c:\program files\Your PC Protector
c:\program files\Your PC Protector\Your PC Protector.exe
c:\recycler\S-1-5-21-1708537768-287218729-725345543-500
c:\recycler\S-1-5-21-2003686897-4092239950-2276124122-500
c:\recycler\S-1-5-21-307633987-10451574-3902780685-1019
c:\recycler\S-1-5-21-3279475894-938237408-3930678521-500
c:\recycler\S-1-5-21-4096751349-44545729-2002333330-500
c:\recycler\S-1-5-21-940662028-1292608343-4271632739-500
c:\recycler\S-1-5-21-993081177-2700597510-2887598414-500
c:\windows\ohivukov.dll
c:\windows\system32\11478.exe
c:\windows\system32\15724.exe
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\26500.exe
c:\windows\system32\29358.exe
c:\windows\system32\41.exe
c:\windows\system32\6334.exe
c:\windows\system32\jivobumo.dll
c:\windows\system32\kaziduwo.dll
c:\windows\system32\spool\prtprocs\w32x86\000071e8.tmp
c:\windows\system32\tesegigo.dll
c:\windows\system32\tifunalo.dll
c:\windows\system32\tomuzipu.dll
c:\windows\system32\waremilo.dll
c:\windows\system32\zoroviro.dll
c:\windows\Tasks\xynvufcd.job

—– BITS: Possible infected sites —–

hxxp://cbsmsprd1.mna.corp.mosaicco.com:8540
hxxp://nasccmprd1.mna.corp.mosaicco.com:8540
.
((((((((((((((((((((((((( Files Created from 2010-01-16 to 2010-02-16 )))))))))))))))))))))))))))))))
.

2010-02-10 18:48 . 2001-08-18 05:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2010-02-10 18:48 . 2008-04-14 12:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2010-02-10 18:48 . 2008-04-14 07:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-02-10 13:57 . 2010-01-07 23:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-10 13:57 . 2010-01-07 23:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-10 13:46 . 2010-02-10 13:46 ——– d—–w- c:\program files\ERUNT
2010-02-08 13:37 . 2010-02-11 03:25 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-07 17:21 . 2010-02-16 13:30 0 —-a-w- c:\windows\Yfezuqol.bin
2010-02-07 17:21 . 2010-02-16 13:30 120 —-a-w- c:\windows\Twefoboxebod.dat
2010-02-07 17:20 . 2010-02-07 17:20 ——– d—–w- c:\documents and settings\pcarrill\Local Settings\Application Data\{70660533-012F-4BC3-A5DA-BA8C628D8037}
2010-02-07 13:13 . 2010-02-07 13:41 ——– d—–w- c:\program files\schtml
2010-02-07 13:08 . 2010-02-07 13:08 36 —-a-w- c:\program files\skynet.dat
2010-02-02 04:37 . 2010-02-02 04:37 ——– d—–w- c:\documents and settings\pcarrill\Local Settings\Application Data\Threat Expert
2010-02-02 04:31 . 2010-01-21 23:21 767952 —-a-w- c:\windows\BDTSupport.dll
2010-02-02 04:31 . 2010-01-21 23:21 165840 —-a-w- c:\windows\PCTBDRes.dll
2010-02-02 04:31 . 2010-01-21 23:21 149456 —-a-w- c:\windows\SGDetectionTool.dll
2010-02-02 04:31 . 2010-01-21 23:21 1652688 —-a-w- c:\windows\PCTBDCore.dll
2010-02-02 04:31 . 2009-10-28 08:36 1152444 —-a-w- c:\windows\UDB.zip
2010-02-02 04:31 . 2008-11-26 19:08 131 —-a-w- c:\windows\IDB.zip
2010-02-02 04:29 . 2009-10-30 18:11 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-02-02 04:29 . 2009-11-09 18:20 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2010-02-02 04:29 . 2009-10-06 23:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-02-02 04:29 . 2009-09-03 16:45 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2010-02-02 04:28 . 2010-02-10 04:31 ——– d—–w- c:\program files\Spyware Doctor
2010-02-02 04:28 . 2010-02-02 04:31 ——– d—–w- c:\program files\Common Files\PC Tools
2010-02-02 04:28 . 2010-02-02 04:28 ——– d—–w- c:\documents and settings\pcarrill\Application Data\PC Tools
2010-02-02 04:28 . 2010-02-02 04:28 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2010-02-02 04:28 . 2010-02-16 13:53 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-01 15:25 . 2010-02-10 20:59 ——– d—–w- c:\documents and settings\pcarrill\Local Settings\Application Data\Deployment
2010-01-26 16:00 . 2010-01-26 16:00 ——– d—–w- c:\documents and settings\pcarrill\Application Data\Macrovision
2010-01-25 20:15 . 2010-01-25 20:15 ——– d—–w- c:\windows\system32\E177E04D548C4006A465EEB92D3DE021
2010-01-25 20:14 . 2010-01-25 20:14 ——– d—–w- c:\program files\Minitab 15
2010-01-25 20:14 . 2010-01-25 20:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Macrovision
2010-01-21 21:04 . 2010-01-21 21:05 ——– d—–w- c:\windows\system32\rc
2010-01-21 20:42 . 2010-01-21 20:42 ——– d—–w- c:\documents and settings\pcarrill\Application Data\Malwarebytes
2010-01-21 19:14 . 2010-01-21 19:22 ——– d—–w- c:\program files\Microsoft Works
2010-01-21 19:07 . 2010-01-21 19:19 ——– d—–w- c:\program files\Microsoft Visual Studio 8
2010-01-21 19:06 . 2010-01-21 22:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-21 18:59 . 2009-10-12 13:38 149504 -c—-w- c:\windows\system32\dllcache\rastls.dll
2010-01-21 18:59 . 2009-10-12 13:38 79872 -c—-w- c:\windows\system32\dllcache\raschap.dll
2010-01-21 18:59 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-21 18:59 . 2009-10-13 10:30 270336 -c—-w- c:\windows\system32\dllcache\oakley.dll
2010-01-21 04:57 . 2010-01-21 04:57 ——– d—–w- c:\program files\uTorrent
2010-01-21 04:57 . 2010-02-12 05:15 ——– d—–w- c:\documents and settings\pcarrill\Application Data\uTorrent
2010-01-20 23:58 . 2010-02-02 20:36 ——– d—–w- c:\program files\True Sword 5
2010-01-20 21:52 . 2010-02-02 20:36 ——– d—–w- c:\program files\RADO Removal Tool[1]

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-11 22:36 . 2009-12-03 00:59 ——– d—–w- c:\program files\Pixel Mine
2010-02-10 21:16 . 2008-05-13 13:02 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-01-25 22:23 . 2006-02-19 01:30 ——– d-sh–r- c:\program files\Windows Update
2010-01-21 22:53 . 2009-12-02 22:20 ——– d—–w- c:\program files\Common Files\ArchestrA
2010-01-21 20:36 . 2009-12-07 01:25 107728 —-a-w- c:\documents and settings\pcarrill\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-21 03:11 . 2009-12-08 03:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-20 18:09 . 2007-10-16 17:49 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-14 15:27 . 2009-12-07 04:05 ——– d—–w- c:\documents and settings\pcarrill\Application Data\Apple Computer
2010-01-14 05:50 . 2010-01-14 05:50 79040 —ha-w- c:\windows\system32\mlfcache.dat
2010-01-09 16:20 . 2010-01-09 16:20 ——– d—–w- c:\documents and settings\pcarrill\Application Data\ArchestrA
2010-01-05 23:14 . 2010-01-05 23:14 ——– d—–w- c:\program files\Free M4a to MP3 Converter
2010-01-04 01:08 . 2009-11-19 20:19 ——– d—–w- c:\documents and settings\pcarrill\Application Data\ICAClient
2009-12-31 19:38 . 2009-12-31 19:37 ——– d—–w- c:\program files\iTunes
2009-12-31 19:38 . 2009-12-31 19:37 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-31 19:37 . 2009-12-31 19:37 ——– d—–w- c:\program files\iPod
2009-12-31 19:37 . 2009-12-07 04:03 ——– d—–w- c:\program files\Common Files\Apple
2009-12-31 19:35 . 2009-12-07 04:04 ——– d—–w- c:\program files\QuickTime
2009-12-26 18:41 . 2009-12-26 18:41 ——– d—–w- c:\program files\Xvid
2009-12-26 18:37 . 2009-12-26 18:37 ——– d—–w- c:\documents and settings\pcarrill\Application Data\Media Player Classic
2009-12-06 00:07 . 2009-12-06 00:07 164 —-a-w- c:\windows\install.dat
2009-12-03 00:27 . 2009-12-03 00:27 0 —-a-w- c:\windows\nsreg.dat
2009-12-02 19:06 . 2009-12-02 19:06 71504 —-a-w- c:\documents and settings\nquintel\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
1601-01-01 00:03 . 1601-01-01 00:03 93696 –sha-w- c:\windows\system32\duzurosa.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 –sha-w- c:\windows\system32\fivajubu.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 –sha-w- c:\windows\system32\fivefoda.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 –sha-w- c:\windows\system32\fodituva.dll
1601-01-01 00:03 . 1601-01-01 00:03 93696 –sha-w- c:\windows\system32\gedoneno.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 –sha-w- c:\windows\system32\jomotewa.dll
1601-01-01 00:03 . 1601-01-01 00:03 94208 –sha-w- c:\windows\system32\kiwatehu.dll
1601-01-01 00:03 . 1601-01-01 00:03 93184 –sha-w- c:\windows\system32\lemutuja.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 –sha-w- c:\windows\system32\nepihene.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 –sha-w- c:\windows\system32\pubonepo.dll
1601-01-01 00:03 . 1601-01-01 00:03 66560 –sha-w- c:\windows\system32\sagopise.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 –sha-w- c:\windows\system32\selulisa.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 –sha-w- c:\windows\system32\telariva.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 –sha-w- c:\windows\system32\wopeneda.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 –sha-w- c:\windows\system32\yehuruma.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\documents and settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-03-29 222128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2009-01-28 111952]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2009-02-26 136512]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-09 150040]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-09 141848]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-05-22 442467]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2008-05-20 466944]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-10-02 200704]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-06-02 2220032]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="c:\program files\Microsoft Office Communicator\Communicator.exe" [2007-12-05 3900936]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli deqmabFi.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Snagit 9.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Snagit 9.lnk
backup=c:\windows\pss\Snagit 9.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMMUNICATOR]
2007-12-05 22:30 3900936 —-a-w- c:\program files\Microsoft Office Communicator\communicator.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 23:33 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\pcarrill\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\pcarrill\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2/1/2010 9:29 PM 207792]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [2/1/2010 9:31 PM 112592]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [11/16/2009 10:49 AM 108160]
R3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [12/31/2008 7:11 AM 32808]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [12/31/2008 7:11 AM 244368]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [11/16/2009 10:49 AM 110080]
R3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\drivers\covpndrv.sys [10/9/2009 8:15 PM 33920]
S3 f5ipfw;F5 Networks StoneWall Filter;c:\windows\system32\drivers\urfltw2k.sys [12/2/2009 8:08 PM 10752]
S3 OracleOraHome81ClientCache;OracleOraHome81ClientCache;c:\oracle\ora81\BIN\ONRSD.EXE –> c:\oracle\ora81\BIN\ONRSD.EXE [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2/1/2010 9:28 PM 359624]
.
Contents of the 'Scheduled Tasks' folder

2010-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1599442949-3460341375-2447778116-15330Core.job
- c:\documents and settings\pcarrill\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-13 00:23]

2010-02-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1599442949-3460341375-2447778116-15330UA.job
- c:\documents and settings\pcarrill\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-13 00:23]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://employee.mosaicco.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
Trusted Zone: buy-is2010.com
Trusted Zone: cargill.com\hrdirect
Trusted Zone: cargill.com\smaccess.ds
Trusted Zone: is-soft-download.com
Trusted Zone: is-software-download.com
Trusted Zone: is10-soft-download.com
Trusted Zone: mosaicco.com\alsharepoint
Trusted Zone: mosaicco.com\it
Trusted Zone: mosaicco.com\mgts
Trusted Zone: mosaicco.com\ps1.pmo
Trusted Zone: mosaicco.com\sites.project
Trusted Zone: mosaicco.com\wdsharepoint
Trusted Zone: mosaicco.com\webmail
Trusted Zone: mosaicco.com\www.pmo
Trusted Zone: wdwebprd2
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
Trusted Zone: buy-is2010.com
Trusted Zone: cargill.com\hrdirect
Trusted Zone: cargill.com\smaccess.ds
Trusted Zone: mosaicco.com\alsharepoint
Trusted Zone: mosaicco.com\it
Trusted Zone: mosaicco.com\mgts
Trusted Zone: mosaicco.com\ps1.pmo
Trusted Zone: mosaicco.com\sites.project
Trusted Zone: mosaicco.com\wdsharepoint
Trusted Zone: mosaicco.com\webmail
Trusted Zone: mosaicco.com\www.pmo
Trusted Zone: wdwebprd2
FF - ProfilePath - c:\documents and settings\pcarrill\Application Data\Mozilla\Firefox\Profiles\xia7xztq.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://mail.live.com/default.aspx?wa=wsignin1.0
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - prefs.js: network.proxy.type - 2
FF - plugin: c:\documents and settings\pcarrill\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\pcarrill\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJPI150_11.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPOJI610.dll
FF - HiddenExtension: XULRunner: {70660533-012F-4BC3-A5DA-BA8C628D8037} - c:\documents and settings\pcarrill\Local Settings\Application Data\{70660533-012F-4BC3-A5DA-BA8C628D8037}
.
- - - - ORPHANS REMOVED - - - -

BHO-{424fa445-9856-47ae-b280-8941ca227d72} - fasububi.dll
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
HKLM-Run-Sfopikoq - c:\windows\ohivukov.dll
HKLM-Run-Malwarebytes Anti-Malware (reboot) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe
HKLM-Run-milepihew - c:\windows\system32\zoroviro.dll
HKLM-Run-hizihinigi - jivobumo.dll
SharedTaskScheduler-{7d7e192b-e486-4107-a9c0-ec81e981a533} - c:\windows\system32\tusugemo.dll
SharedTaskScheduler-{b0d44a43-985e-44d0-b6eb-62f8ce9c6704} - c:\windows\system32\zoroviro.dll
SSODL-penedahet-{7d7e192b-e486-4107-a9c0-ec81e981a533} - c:\windows\system32\tusugemo.dll
SSODL-yoziroluv-{b0d44a43-985e-44d0-b6eb-62f8ce9c6704} - c:\windows\system32\zoroviro.dll
MSConfigStartUp-Malwarebytes Anti-Malware (reboot) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe
MSConfigStartUp-uTorrent - c:\documents and settings\pcarrill\My Documents\Downloads\utorrent(2).exe
AddRemove-Adobe Acrobat Connect Add-in - c:\documents and settings\pcarrill\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectaddin.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-16 07:07
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\KIX32.EXE:WDCTXPRD2.2 237568 bytes executable
c:\windows\KIX32.EXE:WDCTXPRD2.3 237568 bytes executable

scan completed successfully
hidden files: 2

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6CB39D60-4086-B7F8-381D8F903EAF6AF0}\{AFC2635D-FADA-3E20-D0B5B6B6E250D71B}\{28C204A2-D9FA-6C6E-1B551E281BAD6C81}*]
"{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1"=hex:01,00,01,00,0c,00,00,00,c2,16,95,
a4,d8,26,d6,26,1c,3e,21,49,43,31,6b,fd,21,d1,f9,0e,da,d8,c9,6d,56,c2,45,ad,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A1146105-B145-D547-791CC80E83BF21B6}\{DC78455E-4161-0768-1856DB98A0FFD8AF}\{619B65F9-9B50-CD99-3F29A63495E25D6C}*]
"RA4KGUJC6T6LBNJRIDQ63C2L6C1"=hex:01,00,01,00,00,00,00,00,f7,8a,3d,85,55,45,07,
82,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(936)
c:\program files\Bonjour\mdnsNSP.dll

- - - - - - - > 'lsass.exe'(992)
c:\windows\deqmabFi.dll
c:\program files\Bonjour\mdnsNSP.dll

- - - - - - - > 'explorer.exe'(3620)
c:\windows\system32\ieframe.dll
c:\windows\deqmabFi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\idt\dellxpm09b_6017v022\wdm\stacsv.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Common Files\ArchestrA\aaLogger.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe
c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\PIPC\BIN\pilogsrv.exe
c:\program files\PIPC\BIN\pinetmgr.exe
c:\windows\system32\rc\winvnc4.exe
c:\windows\system32\CCM\CcmExec.exe
c:\program files\PIPC\BIN\pimsgss.exe
c:\program files\McAfee\VirusScan Enterprise\MCUPDATE.EXE
c:\windows\system32\rundll32.exe
c:\program files\McAfee\Common Framework\McTray.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\HidFind.exe
c:\program files\DellTPad\Apntex.exe
c:\windows\SoftwareDistribution\Download\72187e1a9593df853aa7db379edb1348\update\update.exe
.
**************************************************************************
.
Completion time: 2010-02-16 07:24:42 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-16 14:24

Pre-Run: 18,691,878,912 bytes free
Post-Run: 18,559,819,776 bytes free

- - End Of File - - 2A83C3A3C2313062DCF4BF52291355AB


again thanks for your help!!
Dipablo,

CatByte is unavailable for a few days so I'm going to see if I can help you get cleaned up.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Killall::
    
    Collect::
    c:\windows\Yfezuqol.bin
    c:\windows\Twefoboxebod.dat
    c:\program files\skynet.dat
    c:\windows\system32\duzurosa.dll
    c:\windows\system32\fivajubu.dll
    c:\windows\system32\fivefoda.dll
    c:\windows\system32\fodituva.dll
    c:\windows\system32\gedoneno.dll
    c:\windows\system32\jomotewa.dll
    c:\windows\system32\kiwatehu.dll
    c:\windows\system32\lemutuja.dll
    c:\windows\system32\nepihene.dll
    c:\windows\system32\pubonepo.dll
    c:\windows\system32\sagopise.dll
    c:\windows\system32\selulisa.dll
    c:\windows\system32\telariva.dll
    c:\windows\system32\wopeneda.dll
    c:\windows\system32\yehuruma.dll
    
    DDS::
    FF - HiddenExtension: XULRunner: {70660533-012F-4BC3-A5DA-BA8C628D8037} - c:\documents and settings\pcarrill\Local Settings\Application Data\{70660533-012F-4BC3-A5DA-BA8C628D8037}
    
    RegNull::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A1146105-B145-D547-791CC80E83BF21B6}\{DC78455E-4161-0768-1856DB98A0FFD8AF}\{619B65F9-9B50-CD99-3F29A63495E25D6C}*]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6CB39D60-4086-B7F8-381D8F903EAF6AF0}\{AFC2635D-FADA-3E20-D0B5B6B6E250D71B}\{28C204A2-D9FA-6C6E-1B551E281BAD6C81}*]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
thanks tomk!!! i really appreciate your help on this.

again it will not let me disable mcafee, i do have administrative rights to the laptop but when i go to disable the scanners the disable button is grayed out and will not let me disable it. also combofix is not able to install recovery console and when i go to microsoft i can not find it to download.

here is the combofix log:

ComboFix 10-02-12.01 - pcarrill 02/16/2010 13:19:43.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3536.2507 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\pcarrill\Desktop\CFScript.txt
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

file zipped: c:\program files\skynet.dat
file zipped: c:\windows\system32\jomotewa.dll
file zipped: c:\windows\system32\sagopise.dll
file zipped: c:\windows\system32\selulisa.dll
file zipped: c:\windows\Twefoboxebod.dat
file zipped: c:\windows\Yfezuqol.bin
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\skynet.dat
c:\windows\system32\jomotewa.dll
c:\windows\system32\sagopise.dll
c:\windows\system32\selulisa.dll
c:\windows\Twefoboxebod.dat
c:\windows\Yfezuqol.bin

—– BITS: Possible infected sites —–

hxxp://cbsmsprd1.mna.corp.mosaicco.com:8540
.
((((((((((((((((((((((((( Files Created from 2010-01-16 to 2010-02-16 )))))))))))))))))))))))))))))))
.

2010-02-16 14:19 . 2010-01-05 10:00 459264 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2010-02-16 14:19 . 2010-01-05 10:00 268288 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2010-02-16 14:19 . 2010-01-05 10:00 380928 -c—-w- c:\windows\system32\dllcache\ieapfltr.dll
2010-02-16 14:19 . 2010-01-05 10:00 52224 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-02-16 14:19 . 2010-01-05 10:00 63488 -c—-w- c:\windows\system32\dllcache\icardie.dll
2010-02-16 14:19 . 2009-12-31 15:33 13824 -c—-w- c:\windows\system32\dllcache\ieudinit.exe
2010-02-16 14:19 . 2009-06-29 08:33 2452872 -c—-w- c:\windows\system32\dllcache\ieapfltr.dat
2010-02-16 14:19 . 2010-01-05 10:00 6067200 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2010-02-10 18:48 . 2001-08-18 05:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2010-02-10 18:48 . 2008-04-14 12:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2010-02-10 18:48 . 2008-04-14 07:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-02-10 13:57 . 2010-01-07 23:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-10 13:57 . 2010-01-07 23:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-10 13:46 . 2010-02-10 13:46 ——– d—–w- c:\program files\ERUNT
2010-02-08 13:37 . 2010-02-11 03:25 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-07 13:13 . 2010-02-07 13:41 ——– d—–w- c:\program files\schtml
2010-02-02 04:37 . 2010-02-02 04:37 ——– d—–w- c:\documents and settings\pcarrill\Local Settings\Application Data\Threat Expert
2010-02-02 04:31 . 2010-01-21 23:21 767952 —-a-w- c:\windows\BDTSupport.dll
2010-02-02 04:31 . 2010-01-21 23:21 165840 —-a-w- c:\windows\PCTBDRes.dll
2010-02-02 04:31 . 2010-01-21 23:21 149456 —-a-w- c:\windows\SGDetectionTool.dll
2010-02-02 04:31 . 2010-01-21 23:21 1652688 —-a-w- c:\windows\PCTBDCore.dll
2010-02-02 04:31 . 2009-10-28 08:36 1152444 —-a-w- c:\windows\UDB.zip
2010-02-02 04:31 . 2008-11-26 19:08 131 —-a-w- c:\windows\IDB.zip
2010-02-02 04:29 . 2009-10-30 18:11 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-02-02 04:29 . 2009-11-09 18:20 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2010-02-02 04:29 . 2009-10-06 23:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-02-02 04:29 . 2009-09-03 16:45 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2010-02-02 04:28 . 2010-02-10 04:31 ——– d—–w- c:\program files\Spyware Doctor
2010-02-02 04:28 . 2010-02-02 04:31 ——– d—–w- c:\program files\Common Files\PC Tools
2010-02-02 04:28 . 2010-02-02 04:28 ——– d—–w- c:\documents and settings\pcarrill\Application Data\PC Tools
2010-02-02 04:28 . 2010-02-02 04:28 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2010-02-02 04:28 . 2010-02-16 20:27 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-01 15:25 . 2010-02-10 20:59 ——– d—–w- c:\documents and settings\pcarrill\Local Settings\Application Data\Deployment
2010-01-26 16:00 . 2010-01-26 16:00 ——– d—–w- c:\documents and settings\pcarrill\Application Data\Macrovision
2010-01-25 20:15 . 2010-01-25 20:15 ——– d—–w- c:\windows\system32\E177E04D548C4006A465EEB92D3DE021
2010-01-25 20:14 . 2010-01-25 20:14 ——– d—–w- c:\program files\Minitab 15
2010-01-25 20:14 . 2010-01-25 20:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Macrovision
2010-01-21 21:04 . 2010-01-21 21:05 ——– d—–w- c:\windows\system32\rc
2010-01-21 20:42 . 2010-01-21 20:42 ——– d—–w- c:\documents and settings\pcarrill\Application Data\Malwarebytes
2010-01-21 19:14 . 2010-01-21 19:22 ——– d—–w- c:\program files\Microsoft Works
2010-01-21 19:07 . 2010-01-21 19:19 ——– d—–w- c:\program files\Microsoft Visual Studio 8
2010-01-21 19:06 . 2010-01-21 22:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-21 18:59 . 2009-10-12 13:38 149504 -c—-w- c:\windows\system32\dllcache\rastls.dll
2010-01-21 18:59 . 2009-10-12 13:38 79872 -c—-w- c:\windows\system32\dllcache\raschap.dll
2010-01-21 18:59 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-21 18:59 . 2009-10-13 10:30 270336 -c—-w- c:\windows\system32\dllcache\oakley.dll
2010-01-21 04:57 . 2010-01-21 04:57 ——– d—–w- c:\program files\uTorrent
2010-01-21 04:57 . 2010-02-12 05:15 ——– d—–w- c:\documents and settings\pcarrill\Application Data\uTorrent
2010-01-20 23:58 . 2010-02-02 20:36 ——– d—–w- c:\program files\True Sword 5
2010-01-20 21:52 . 2010-02-02 20:36 ——– d—–w- c:\program files\RADO Removal Tool[1]

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-11 22:36 . 2009-12-03 00:59 ——– d—–w- c:\program files\Pixel Mine
2010-02-10 21:16 . 2008-05-13 13:02 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-01-25 22:23 . 2006-02-19 01:30 ——– d-sh–r- c:\program files\Windows Update
2010-01-21 22:53 . 2009-12-02 22:20 ——– d—–w- c:\program files\Common Files\ArchestrA
2010-01-21 20:36 . 2009-12-07 01:25 107728 —-a-w- c:\documents and settings\pcarrill\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-21 03:11 . 2009-12-08 03:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-20 18:09 . 2007-10-16 17:49 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-14 15:27 . 2009-12-07 04:05 ——– d—–w- c:\documents and settings\pcarrill\Application Data\Apple Computer
2010-01-14 05:50 . 2010-01-14 05:50 79040 —ha-w- c:\windows\system32\mlfcache.dat
2010-01-09 16:20 . 2010-01-09 16:20 ——– d—–w- c:\documents and settings\pcarrill\Application Data\ArchestrA
2010-01-05 23:14 . 2010-01-05 23:14 ——– d—–w- c:\program files\Free M4a to MP3 Converter
2010-01-05 10:00 . 2006-02-28 12:00 832512 —-a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2006-02-28 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2006-02-28 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-01-04 01:08 . 2009-11-19 20:19 ——– d—–w- c:\documents and settings\pcarrill\Application Data\ICAClient
2009-12-31 19:38 . 2009-12-31 19:37 ——– d—–w- c:\program files\iTunes
2009-12-31 19:38 . 2009-12-31 19:37 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-31 19:37 . 2009-12-31 19:37 ——– d—–w- c:\program files\iPod
2009-12-31 19:37 . 2009-12-07 04:03 ——– d—–w- c:\program files\Common Files\Apple
2009-12-31 19:35 . 2009-12-07 04:04 ——– d—–w- c:\program files\QuickTime
2009-12-31 19:27 . 2009-12-31 19:27 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-12-26 18:41 . 2009-12-26 18:41 ——– d—–w- c:\program files\Xvid
2009-12-26 18:37 . 2009-12-26 18:37 ——– d—–w- c:\documents and settings\pcarrill\Application Data\Media Player Classic
2009-12-06 00:07 . 2009-12-06 00:07 164 —-a-w- c:\windows\install.dat
2009-12-04 17:03 . 2009-12-04 17:03 251376 —-a-w- c:\documents and settings\pcarrill\Application Data\Mozilla\plugins\npgoogletalk.dll
2009-12-03 00:31 . 2009-12-03 00:31 1925024 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2009-12-03 00:27 . 2009-12-03 00:27 0 —-a-w- c:\windows\nsreg.dat
2009-12-02 19:06 . 2009-12-02 19:06 71504 —-a-w- c:\documents and settings\nquintel\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-21 15:51 . 2006-02-28 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-02-16_15.12.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-16 20:25 . 2010-02-16 20:25 16384 c:\windows\temp\Perflib_Perfdata_e40.dat
+ 2007-05-06 21:20 . 2007-05-07 03:20 69166 c:\windows\system32\spool\drivers\w32x86\3\CnxD0202.dat
+ 2006-02-28 12:00 . 2010-02-16 16:06 79644 c:\windows\system32\perfc009.dat
- 2006-02-28 12:00 . 2010-02-16 14:10 79644 c:\windows\system32\perfc009.dat
+ 2007-08-14 01:54 . 2010-01-05 10:00 52224 c:\windows\system32\msfeedsbs.dll
+ 2007-08-14 01:36 . 2010-01-05 10:00 63488 c:\windows\system32\icardie.dll
- 2007-10-16 18:56 . 2010-02-16 14:03 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-10-16 18:56 . 2010-02-16 20:19 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-02-16 16:01 . 2010-02-16 20:19 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2007-06-28 18:00 . 2007-06-28 18:00 2652 c:\windows\system32\spool\drivers\w32x86\3\CnPX_12A.DAT
+ 2006-02-28 12:00 . 2010-01-05 10:00 233472 c:\windows\system32\webcheck.dll
+ 2006-02-28 12:00 . 2010-01-05 10:00 105984 c:\windows\system32\url.dll
- 2006-02-28 12:00 . 2007-08-14 01:44 105984 c:\windows\system32\url.dll
+ 2007-05-16 21:20 . 2007-05-17 03:20 249856 c:\windows\system32\spool\drivers\w32x86\3\CnxIpc2.DLL
+ 2006-02-28 12:00 . 2010-02-16 16:06 463574 c:\windows\system32\perfh009.dat
- 2006-02-28 12:00 . 2010-02-16 14:10 463574 c:\windows\system32\perfh009.dat
+ 2007-08-14 01:54 . 2010-01-05 10:00 459264 c:\windows\system32\msfeeds.dll
+ 2007-08-14 01:34 . 2010-01-05 10:00 268288 c:\windows\system32\iertutil.dll
+ 2007-07-11 19:27 . 2010-01-05 10:00 380928 c:\windows\system32\ieapfltr.dll
+ 2006-02-28 12:00 . 2010-01-05 10:00 124928 c:\windows\system32\advpack.dll
+ 2006-02-28 12:00 . 2010-01-05 10:00 1168384 c:\windows\system32\urlmon.dll
+ 2007-06-28 18:00 . 2007-06-28 18:00 2984448 c:\windows\system32\spool\drivers\w32x86\3\Cnp60MUI_D5BCC.DLL
+ 2007-06-28 18:00 . 2007-06-28 18:00 1519616 c:\windows\system32\spool\drivers\w32x86\3\Cnp60M_D5BCC.DLL
+ 2007-06-28 18:00 . 2007-06-28 18:00 2658304 c:\windows\system32\spool\drivers\w32x86\3\Cnp60409_D5BCC.DLL
+ 2006-02-28 12:00 . 2010-01-05 22:30 3599360 c:\windows\system32\mshtml.dll
+ 2007-08-14 01:54 . 2010-01-05 10:00 6067200 c:\windows\system32\ieframe.dll
+ 2007-02-12 23:10 . 2009-06-29 08:33 2452872 c:\windows\system32\ieapfltr.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\documents and settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-03-29 222128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2009-01-28 111952]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2009-02-26 136512]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-09 150040]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-09 141848]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-05-22 442467]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2008-05-20 466944]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-10-02 200704]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-06-02 2220032]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="c:\program files\Microsoft Office Communicator\Communicator.exe" [2007-12-05 3900936]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli deqmabFi.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Snagit 9.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Snagit 9.lnk
backup=c:\windows\pss\Snagit 9.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMMUNICATOR]
2007-12-05 22:30 3900936 —-a-w- c:\program files\Microsoft Office Communicator\communicator.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 23:33 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\pcarrill\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\pcarrill\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2/1/2010 9:29 PM 207792]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [2/1/2010 9:31 PM 112592]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [11/16/2009 10:49 AM 108160]
R3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [12/31/2008 7:11 AM 32808]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [12/31/2008 7:11 AM 244368]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [11/16/2009 10:49 AM 110080]
R3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\drivers\covpndrv.sys [10/9/2009 8:15 PM 33920]
S3 f5ipfw;F5 Networks StoneWall Filter;c:\windows\system32\drivers\urfltw2k.sys [12/2/2009 8:08 PM 10752]
S3 OracleOraHome81ClientCache;OracleOraHome81ClientCache;c:\oracle\ora81\BIN\ONRSD.EXE –> c:\oracle\ora81\BIN\ONRSD.EXE [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2/1/2010 9:28 PM 359624]
.
Contents of the 'Scheduled Tasks' folder

2010-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1599442949-3460341375-2447778116-15330Core.job
- c:\documents and settings\pcarrill\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-13 00:23]

2010-02-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1599442949-3460341375-2447778116-15330UA.job
- c:\documents and settings\pcarrill\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-13 00:23]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://employee.mosaicco.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: cargill.com\hrdirect
Trusted Zone: cargill.com\smaccess.ds
Trusted Zone: mosaicco.com\alsharepoint
Trusted Zone: mosaicco.com\it
Trusted Zone: mosaicco.com\mgts
Trusted Zone: mosaicco.com\ps1.pmo
Trusted Zone: mosaicco.com\sites.project
Trusted Zone: mosaicco.com\wdsharepoint
Trusted Zone: mosaicco.com\webmail
Trusted Zone: mosaicco.com\www.pmo
Trusted Zone: wdwebprd2
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
Trusted Zone: buy-is2010.com
Trusted Zone: cargill.com\hrdirect
Trusted Zone: cargill.com\smaccess.ds
Trusted Zone: mosaicco.com\alsharepoint
Trusted Zone: mosaicco.com\it
Trusted Zone: mosaicco.com\mgts
Trusted Zone: mosaicco.com\ps1.pmo
Trusted Zone: mosaicco.com\sites.project
Trusted Zone: mosaicco.com\wdsharepoint
Trusted Zone: mosaicco.com\webmail
Trusted Zone: mosaicco.com\www.pmo
Trusted Zone: wdwebprd2
FF - ProfilePath - c:\documents and settings\pcarrill\Application Data\Mozilla\Firefox\Profiles\xia7xztq.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://mail.live.com/default.aspx?wa=wsignin1.0
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - prefs.js: network.proxy.type - 2
FF - plugin: c:\documents and settings\pcarrill\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\pcarrill\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJPI150_11.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-16 14:52
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\KIX32.EXE:WDCTXPRD2.2 237568 bytes executable
c:\windows\KIX32.EXE:WDCTXPRD2.3 237568 bytes executable

scan completed successfully
hidden files: 2

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(940)
c:\program files\Bonjour\mdnsNSP.dll

- - - - - - - > 'lsass.exe'(996)
c:\windows\deqmabFi.dll
c:\windows\system32\WININET.dll
c:\program files\Bonjour\mdnsNSP.dll

- - - - - - - > 'explorer.exe'(2068)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\deqmabFi.dll
c:\program files\Bonjour\mdnsNSP.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\idt\dellxpm09b_6017v022\wdm\stacsv.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Common Files\ArchestrA\aaLogger.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe
c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\PIPC\BIN\pilogsrv.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\PIPC\BIN\pinetmgr.exe
c:\windows\system32\rc\winvnc4.exe
c:\windows\system32\CCM\CcmExec.exe
c:\program files\PIPC\BIN\pimsgss.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\McAfee\Common Framework\McTray.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\HidFind.exe
c:\program files\DellTPad\Apntex.exe
.
**************************************************************************
.
Completion time: 2010-02-16 14:55:25 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-16 21:55
ComboFix2.txt 2010-02-16 15:15
ComboFix3.txt 2010-02-16 14:24

Pre-Run: 18,708,246,528 bytes free
Post-Run: 18,663,047,168 bytes free

- - End Of File - - 752C90557369D470FB0F17CFA501C75D
The files we collected to look at didn't get submitted.

Please open this link HERE in a new window.

In the box marked Link to topic where this file was requested: please paste in the following text
http://forums.whatthetech.com/add_reply_f27_to110171.html

Click the Browse button and navigate to C:\Qoobox\Quarantine

There should be a zip file there called [4]-Submit_2010-2-16_13:19:43.zip
Select this file and click Open
In the Largest box please put
File Requested By Tomk

Failed Submit::

Finally click SendFile

Please return here and let me know when that file has been uploaded.
Dipablo,

Thank you.

Yep. A little trojan Vundo and some downloaders. :angry:

Do you recognize this company: mosaicco? Looks to be maybe a fertilizer company?

Your Java is out of date and you have other old versions still on your computer, those old versions are now a security vulnerability:

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer - Version 6 update 18

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).
yes mosaic is my company, i use this laptop to vpn into the network and check emails and do various work. Java is done. ill run gooredfix tomorrow and post he log. Thank you so much for all your help, it is much appreciated
Hey Tomk, sorry for the delay….here is the gooredfix log GooredFix by jpshortstuff (08.01.10.1) Log created at 06:49 on 18/02/2010 (gcdishc1) Firefox version 3.5.7 (en-US) ========== GooredScan ========== ========== GooredLog ========== C:\Program Files\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} [02:06 07/12/2009] {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} [04:22 17/02/2010] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [04:21 17/02/2010] -=E.O.F=-
Dipablo,


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Tomk, Here is the log ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Thursday, February 18, 2010 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Thursday, February 18, 2010 20:25:51 Records in database: 3553601 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ U:\ W:\ Scan statistics: Objects scanned: 148398 Threats found: 8 Infected objects found: 9 Suspicious objects found: 0 Scan duration: 05:39:12 File name / Threat / Threats count C:\WINDOWS\system32\rc\winvnc4.exe/C:\WINDOWS\system32\rc\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\waremilo.dll.vir Infected: Trojan.Win32.Migotrup.nol 1 C:\System Volume Information\_restore{037BD92A-8E2E-4D1B-8D33-3573A2A30216}\RP72\A0045812.dll Infected: Packed.Win32.Tdss.c 1 C:\System Volume Information\_restore{037BD92A-8E2E-4D1B-8D33-3573A2A30216}\RP72\A0045813.dll Infected: Trojan.Win32.TDSS.awat 1 C:\System Volume Information\_restore{037BD92A-8E2E-4D1B-8D33-3573A2A30216}\RP72\A0045814.dll Infected: Trojan.Win32.TDSS.awbd 1 C:\System Volume Information\_restore{037BD92A-8E2E-4D1B-8D33-3573A2A30216}\RP72\A0045817.dll Infected: Trojan.Win32.TDSS.away 1 C:\WINDOWS\deqmabFi.dll Infected: Trojan-Downloader.Win32.Mufanom.hry 1 C:\WINDOWS\system32\rc\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 1 C:\WINDOWS\system32\rc\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1 Selected area has been scanned.
Dipablo,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\WINDOWS\deqmabFi.dll
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then please let me know how things are running now.
tomk,

the computer is running much better!! starts up a million times faster now. it SEEMS to be running good.

here is the comobfix log from this last scan:
ComboFix 10-02-18.07 - pcarrill 02/18/2010 23:41:56.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3536.2312 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\pcarrill\Desktop\CFScript.txt
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
* Resident AV is active


FILE ::
"c:\windows\deqmabFi.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

—– BITS: Possible infected sites —–

hxxp://cbsmsprd1.mna.corp.mosaicco.com:8540
.
((((((((((((((((((((((((( Files Created from 2010-01-19 to 2010-02-19 )))))))))))))))))))))))))))))))
.

2010-02-17 04:22 . 2010-02-17 04:21 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-16 14:19 . 2010-01-05 10:00 459264 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2010-02-16 14:19 . 2010-01-05 10:00 268288 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2010-02-16 14:19 . 2010-01-05 10:00 380928 -c—-w- c:\windows\system32\dllcache\ieapfltr.dll
2010-02-16 14:19 . 2010-01-05 10:00 52224 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-02-16 14:19 . 2010-01-05 10:00 63488 -c—-w- c:\windows\system32\dllcache\icardie.dll
2010-02-16 14:19 . 2009-12-31 15:33 13824 -c—-w- c:\windows\system32\dllcache\ieudinit.exe
2010-02-16 14:19 . 2009-06-29 08:33 2452872 -c—-w- c:\windows\system32\dllcache\ieapfltr.dat
2010-02-16 14:19 . 2010-01-05 10:00 6067200 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2010-02-10 18:48 . 2001-08-18 05:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2010-02-10 18:48 . 2008-04-14 12:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2010-02-10 18:48 . 2008-04-14 07:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-02-10 13:57 . 2010-01-07 23:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-10 13:57 . 2010-01-07 23:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-10 13:46 . 2010-02-10 13:46 ——– d—–w- c:\program files\ERUNT
2010-02-08 13:37 . 2010-02-11 03:25 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-07 13:13 . 2010-02-18 21:01 ——– d—–w- c:\program files\schtml
2010-02-02 04:37 . 2010-02-02 04:37 ——– d—–w- c:\documents and settings\pcarrill\Local Settings\Application Data\Threat Expert
2010-02-02 04:31 . 2010-01-21 23:21 767952 —-a-w- c:\windows\BDTSupport.dll
2010-02-02 04:31 . 2010-01-21 23:21 165840 —-a-w- c:\windows\PCTBDRes.dll
2010-02-02 04:31 . 2010-01-21 23:21 149456 —-a-w- c:\windows\SGDetectionTool.dll
2010-02-02 04:31 . 2010-01-21 23:21 1652688 —-a-w- c:\windows\PCTBDCore.dll
2010-02-02 04:31 . 2009-10-28 08:36 1152444 —-a-w- c:\windows\UDB.zip
2010-02-02 04:31 . 2008-11-26 19:08 131 —-a-w- c:\windows\IDB.zip
2010-02-02 04:29 . 2009-10-30 18:11 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-02-02 04:29 . 2009-11-09 18:20 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2010-02-02 04:29 . 2009-10-06 23:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-02-02 04:29 . 2009-09-03 16:45 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2010-02-02 04:28 . 2010-02-10 04:31 ——– d—–w- c:\program files\Spyware Doctor
2010-02-02 04:28 . 2010-02-02 04:31 ——– d—–w- c:\program files\Common Files\PC Tools
2010-02-02 04:28 . 2010-02-02 04:28 ——– d—–w- c:\documents and settings\pcarrill\Application Data\PC Tools
2010-02-02 04:28 . 2010-02-02 04:28 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2010-02-02 04:28 . 2010-02-19 06:47 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-01 15:25 . 2010-02-17 19:06 ——– d—–w- c:\documents and settings\pcarrill\Local Settings\Application Data\Deployment
2010-01-26 16:00 . 2010-01-26 16:00 ——– d—–w- c:\documents and settings\pcarrill\Application Data\Macrovision
2010-01-25 20:15 . 2010-01-25 20:15 ——– d—–w- c:\windows\system32\E177E04D548C4006A465EEB92D3DE021
2010-01-25 20:14 . 2010-01-25 20:14 ——– d—–w- c:\program files\Minitab 15
2010-01-25 20:14 . 2010-01-25 20:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Macrovision
2010-01-21 21:04 . 2010-01-21 21:05 ——– d—–w- c:\windows\system32\rc
2010-01-21 20:42 . 2010-01-21 20:42 ——– d—–w- c:\documents and settings\pcarrill\Application Data\Malwarebytes
2010-01-21 19:14 . 2010-01-21 19:22 ——– d—–w- c:\program files\Microsoft Works
2010-01-21 19:07 . 2010-01-21 19:19 ——– d—–w- c:\program files\Microsoft Visual Studio 8
2010-01-21 19:06 . 2010-01-21 22:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-21 18:59 . 2009-10-12 13:38 149504 -c—-w- c:\windows\system32\dllcache\rastls.dll
2010-01-21 18:59 . 2009-10-12 13:38 79872 -c—-w- c:\windows\system32\dllcache\raschap.dll
2010-01-21 18:59 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-21 18:59 . 2009-10-13 10:30 270336 -c—-w- c:\windows\system32\dllcache\oakley.dll
2010-01-21 04:57 . 2010-01-21 04:57 ——– d—–w- c:\program files\uTorrent
2010-01-21 04:57 . 2010-02-19 01:24 ——– d—–w- c:\documents and settings\pcarrill\Application Data\uTorrent
2010-01-20 23:58 . 2010-02-02 20:36 ——– d—–w- c:\program files\True Sword 5
2010-01-20 21:52 . 2010-02-02 20:36 ——– d—–w- c:\program files\RADO Removal Tool[1]

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-17 04:22 . 2008-05-13 12:11 ——– d—–w- c:\program files\Common Files\Java
2010-02-17 04:21 . 2008-05-13 12:11 ——– d—–w- c:\program files\Java
2010-02-11 22:36 . 2009-12-03 00:59 ——– d—–w- c:\program files\Pixel Mine
2010-02-10 21:16 . 2008-05-13 13:02 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-01-25 22:23 . 2006-02-19 01:30 ——– d-sh–r- c:\program files\Windows Update
2010-01-21 22:53 . 2009-12-02 22:20 ——– d—–w- c:\program files\Common Files\ArchestrA
2010-01-21 20:36 . 2009-12-07 01:25 107728 —-a-w- c:\documents and settings\pcarrill\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-21 03:11 . 2009-12-08 03:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-20 18:09 . 2007-10-16 17:49 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-14 15:27 . 2009-12-07 04:05 ——– d—–w- c:\documents and settings\pcarrill\Application Data\Apple Computer
2010-01-14 05:50 . 2010-01-14 05:50 79040 —ha-w- c:\windows\system32\mlfcache.dat
2010-01-09 16:20 . 2010-01-09 16:20 ——– d—–w- c:\documents and settings\pcarrill\Application Data\ArchestrA
2010-01-05 23:14 . 2010-01-05 23:14 ——– d—–w- c:\program files\Free M4a to MP3 Converter
2010-01-05 10:00 . 2006-02-28 12:00 832512 ——w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2006-02-28 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2006-02-28 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-01-04 01:08 . 2009-11-19 20:19 ——– d—–w- c:\documents and settings\pcarrill\Application Data\ICAClient
2009-12-31 19:38 . 2009-12-31 19:37 ——– d—–w- c:\program files\iTunes
2009-12-31 19:38 . 2009-12-31 19:37 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-31 19:37 . 2009-12-31 19:37 ——– d—–w- c:\program files\iPod
2009-12-31 19:37 . 2009-12-07 04:03 ——– d—–w- c:\program files\Common Files\Apple
2009-12-31 19:35 . 2009-12-07 04:04 ——– d—–w- c:\program files\QuickTime
2009-12-26 18:41 . 2009-12-26 18:41 ——– d—–w- c:\program files\Xvid
2009-12-26 18:37 . 2009-12-26 18:37 ——– d—–w- c:\documents and settings\pcarrill\Application Data\Media Player Classic
2009-12-06 00:07 . 2009-12-06 00:07 164 —-a-w- c:\windows\install.dat
2009-12-03 00:27 . 2009-12-03 00:27 0 —-a-w- c:\windows\nsreg.dat
2009-12-02 19:06 . 2009-12-02 19:06 71504 —-a-w- c:\documents and settings\nquintel\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-21 15:51 . 2006-02-28 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\documents and settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-03-29 222128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2009-01-28 111952]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2009-02-26 136512]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-09 150040]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-09 141848]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-05-22 442467]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2008-05-20 466944]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-10-02 200704]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-06-02 2220032]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="c:\program files\Microsoft Office Communicator\Communicator.exe" [2007-12-05 3900936]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Snagit 9.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Snagit 9.lnk
backup=c:\windows\pss\Snagit 9.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMMUNICATOR]
2007-12-05 22:30 3900936 —-a-w- c:\program files\Microsoft Office Communicator\communicator.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 23:33 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\pcarrill\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\pcarrill\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2/1/2010 9:29 PM 207792]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [2/1/2010 9:31 PM 112592]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [11/16/2009 10:49 AM 108160]
R3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [12/31/2008 7:11 AM 32808]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [12/31/2008 7:11 AM 244368]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [11/16/2009 10:49 AM 110080]
R3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\drivers\covpndrv.sys [10/9/2009 8:15 PM 33920]
S3 f5ipfw;F5 Networks StoneWall Filter;c:\windows\system32\drivers\urfltw2k.sys [12/2/2009 8:08 PM 10752]
S3 OracleOraHome81ClientCache;OracleOraHome81ClientCache;c:\oracle\ora81\BIN\ONRSD.EXE –> c:\oracle\ora81\BIN\ONRSD.EXE [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2/1/2010 9:28 PM 359624]
.
Contents of the 'Scheduled Tasks' folder

2010-02-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1599442949-3460341375-2447778116-15330Core.job
- c:\documents and settings\pcarrill\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-13 00:23]

2010-02-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1599442949-3460341375-2447778116-15330UA.job
- c:\documents and settings\pcarrill\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-13 00:23]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://employee.mosaicco.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: cargill.com\hrdirect
Trusted Zone: cargill.com\smaccess.ds
Trusted Zone: mosaicco.com\alsharepoint
Trusted Zone: mosaicco.com\it
Trusted Zone: mosaicco.com\mgts
Trusted Zone: mosaicco.com\ps1.pmo
Trusted Zone: mosaicco.com\sites.project
Trusted Zone: mosaicco.com\wdsharepoint
Trusted Zone: mosaicco.com\webmail
Trusted Zone: mosaicco.com\www.pmo
Trusted Zone: wdwebprd2
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
Trusted Zone: buy-is2010.com
Trusted Zone: cargill.com\hrdirect
Trusted Zone: cargill.com\smaccess.ds
Trusted Zone: mosaicco.com\alsharepoint
Trusted Zone: mosaicco.com\it
Trusted Zone: mosaicco.com\mgts
Trusted Zone: mosaicco.com\ps1.pmo
Trusted Zone: mosaicco.com\sites.project
Trusted Zone: mosaicco.com\wdsharepoint
Trusted Zone: mosaicco.com\webmail
Trusted Zone: mosaicco.com\www.pmo
Trusted Zone: wdwebprd2
FF - ProfilePath - c:\documents and settings\pcarrill\Application Data\Mozilla\Firefox\Profiles\xia7xztq.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://mail.live.com/default.aspx?wa=wsignin1.0
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - prefs.js: network.proxy.type - 2
FF - plugin: c:\documents and settings\pcarrill\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\pcarrill\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-18 23:59
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\KIX32.EXE:WDCTXPRD2.2 237568 bytes executable
c:\windows\KIX32.EXE:WDCTXPRD2.3 237568 bytes executable

scan completed successfully
hidden files: 2

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2532)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\idt\dellxpm09b_6017v022\wdm\stacsv.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Common Files\ArchestrA\aaLogger.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe
c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\PIPC\BIN\pilogsrv.exe
c:\program files\PIPC\BIN\pinetmgr.exe
c:\windows\system32\rc\winvnc4.exe
c:\windows\system32\CCM\CcmExec.exe
c:\program files\PIPC\BIN\pimsgss.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\McAfee\Common Framework\McTray.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\HidFind.exe
c:\program files\DellTPad\Apntex.exe
c:\program files\McAfee\Common Framework\McScript_InUse.exe
.
**************************************************************************
.
Completion time: 2010-02-19 00:03:26 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-19 07:03
ComboFix2.txt 2010-02-16 21:55
ComboFix3.txt 2010-02-16 15:15
ComboFix4.txt 2010-02-16 14:24

Pre-Run: 18,242,453,504 bytes free
Post-Run: 18,354,749,440 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=AlwaysOff /fastdetect

- - End Of File - - A815C7F546254B995F380DD5CC2B4BD5


THANKS!!!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI