This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Nasty infection - not sure if you can help this time

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Something nasty infected my computer today. I'm getting all kinds of bogus pop up antivirus software alerts - attention spyware alert - Windows Security Center pops up - IE pops up attempting to go to porn sites, etc. I'm posting this from another computer - got on here looking for your instructions on how to proceed. However I cannot get anywhere on the internet on the infected computer using either IE or Firefox. I get messages saying Firefox is offline or IE cannot display the page. So I can't run through the steps for downloading - posting logs - etc. Is there anything else I can do to try to eradicate this? Thank-you very much - you've been very helpful to me with a problem in the past - maybe you can help with this.
Hi,

Do you have any method of transferring tools/logs to/from the infected computer, i.e. via a USB stick?

If not, please try restarting your computer and tapping F8, then hitting Safe Mode With Networking, and see if that allows you to go onto the Internet.

If either of the above allow you to obtain and run tools, please run DDS and GMER as in the "Are You Infected" topic. Otherwise, let me know and we'll try some other things.

Thanks.
Thanks so much. Yes, I could transfer some things via a USB drive but I'm concerned about infecting my other computer - wouldn't that be likely if I'm transferring stuff back and forth with a USB drive? I'll check and see if I can boot up in safe mode and get on the internet.
You can take precautions, such as disabling autoruns on the clean computer, and scanning the drive before getting everything off of it. However, by all means take the Safe Mode option if you prefer. Using Safe Mode on the infected computer when transferring tools onto it should also prevent Malware from trying to jump to it, although of course its not a 100% guarantee.
I've made some progress. When I booted up in safe mode I just tried running a McAfee scan and that found something and quarantined it. I can now boot up normally and I'm no longer getting all the pop ups though I get two RunDLL errors when it boots up. One says error loading C:\users\USERNAME\appdata/local/syrxtaz.dll The specified module could not be found. The other one is the same except it's avuqoralosupuka.dll. Not sure if these are related to the infection or ??? Do you think I should go ahead and run through your full diagnostic routine? I know you say that just because your symptoms are gone doesn't mean your infection is really gone.
Yes, please run the two diagnostic tools if you can. Those two error messages are indeed related to the infection, and they indicate that McAfee only removed the files, and didn't remove any references to those files. Since McAfee didn't perform a complete removal of your infection(s), its entirely possible that there are more on there.
Okay - here's my Malware log, gmer log, dds.txt. At the top of the attach.txt it says:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT Am I supposed to post this or zip and attach it or don't you need it?


Malwarebytes' Anti-Malware 1.44
Database version: 3510
Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

2/24/2010 8:56:30 PM
mbam-log-2010-02-24 (20-55-45).txt

Scan type: Quick Scan
Objects scanned: 102000
Time elapsed: 4 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mbomo (Trojan.Agent.U) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cginajelehefonu (Trojan.Agent.U) -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

———————————————————————————————————————————————————————————————-

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-24 21:32:59
Windows 6.0.6001 Service Pack 1
Running: nktgmqfc.exe; Driver: C:\Users\MACGIB~1\AppData\Local\Temp\pwryauod.sys


—- System - GMER 1.0.15 —-

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0x9059479E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0x90594738]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0x9059474C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x905947DC]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0x9059481F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0x90594710]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0x90594724]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0x905947B2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0x90594847]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0x90594833]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0x9059478A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0x90594776]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0x9059480B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x905947F2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0x905947C8]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateUserProcess [0x90594762]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwYieldExecution 8226D1C0 5 Bytes JMP 905947CC \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 8240717C 5 Bytes JMP 90594823 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateUserProcess 8240EDD5 5 Bytes JMP 90594766 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 82428F8A 5 Bytes JMP 9059480F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 824481D8 5 Bytes JMP 90594728 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 82457B14 5 Bytes JMP 90594714 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 8246A74E 7 Bytes JMP 905947E0 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 8246ADA5 5 Bytes JMP 905947F6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 8246CFB6 5 Bytes JMP 905947A2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 8247A674 5 Bytes JMP 9059477A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 8247C8CE 7 Bytes JMP 905947B6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRestoreKey 8249B452 5 Bytes JMP 90594837 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplaceKey 8249C49E 5 Bytes JMP 9059484B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 824DA1AF 5 Bytes JMP 9059473C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 824DA1FA 7 Bytes JMP 90594750 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 824DACB7 5 Bytes JMP 9059478E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8F410000, 0x263A88, 0xE8000020]

—- User code sections - GMER 1.0.15 —-

.text C:\Windows\system32\services.exe[700] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 008F0F22
.text C:\Windows\system32\services.exe[700] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 008F0F33
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 008F0F07
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 008F0094
.text C:\Windows\system32\services.exe[700] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 008F0F70
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 008F0FCA
.text C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 008F0F81
.text C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 008F0036
.text C:\Windows\system32\services.exe[700] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 008F0F55
.text C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 008F0F9E
.text C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 008F0FAF
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 008F0F44
.text C:\Windows\system32\services.exe[700] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 008F0EF6
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 008F0000
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 008F0FEF
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 008F001B
.text C:\Windows\system32\services.exe[700] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 008F0083
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 002C0FB9
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 002C0051
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 002C0000
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 002C0FD4
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 002C0080
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 002C0FEF
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 002C0025
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 002C0040
.text C:\Windows\system32\services.exe[700] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 00900033
.text C:\Windows\system32\services.exe[700] msvcrt.dll!system 77258B63 5 Bytes JMP 00900022
.text C:\Windows\system32\services.exe[700] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 00900000
.text C:\Windows\system32\services.exe[700] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 00900FE3
.text C:\Windows\system32\services.exe[700] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 00900011
.text C:\Windows\system32\services.exe[700] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 00900FD2
.text C:\Windows\system32\services.exe[700] WS2_32.dll!socket 769736D1 5 Bytes JMP 002D0FEF
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 00C600C9
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 00C600AE
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 00C60F5E
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 00C600F5
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 00C60093
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 00C6001B
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryExW 76E530C3 3 Bytes JMP 00C60FB9
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryExW + 4 76E530C7 1 Byte [89]
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 00C60051
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 00C60F94
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 00C60076
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 00C60040
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 00C60F83
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 00C60F43
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 00C60FE5
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 00C60000
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 00C60FCA
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 00C600E4
.text C:\Windows\system32\lsass.exe[712] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 008B0FA8
.text C:\Windows\system32\lsass.exe[712] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 008B002F
.text C:\Windows\system32\lsass.exe[712] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 008B0FEF
.text C:\Windows\system32\lsass.exe[712] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 008B004A
.text C:\Windows\system32\lsass.exe[712] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 008B005B
.text C:\Windows\system32\lsass.exe[712] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 008B0FC3
.text C:\Windows\system32\lsass.exe[712] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 008B0FDE
.text C:\Windows\system32\lsass.exe[712] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 008B0014
.text C:\Windows\system32\lsass.exe[712] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 00CB0FBC
.text C:\Windows\system32\lsass.exe[712] msvcrt.dll!system 77258B63 5 Bytes JMP 00CB0047
.text C:\Windows\system32\lsass.exe[712] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 00CB0FCD
.text C:\Windows\system32\lsass.exe[712] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 00CB0FEF
.text C:\Windows\system32\lsass.exe[712] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 00CB002C
.text C:\Windows\system32\lsass.exe[712] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 00CB0FDE
.text C:\Windows\system32\lsass.exe[712] WS2_32.dll!socket 769736D1 5 Bytes JMP 008C0FEF
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 002F00D3
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 002F00B8
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 002F0F72
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 002F0109
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 002F0F8D
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 002F0036
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 002F0FA8
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 002F0051
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 002F008C
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 002F0FB9
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 002F0FCA
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 002F009D
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 002F0F57
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 002F0FE5
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 002F0000
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 002F001B
.text C:\Windows\system32\svchost.exe[920] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 002F00F8
.text C:\Windows\system32\svchost.exe[920] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 00300FB0
.text C:\Windows\system32\svchost.exe[920] msvcrt.dll!system 77258B63 5 Bytes JMP 00300FC1
.text C:\Windows\system32\svchost.exe[920] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 0030001D
.text C:\Windows\system32\svchost.exe[920] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 00300000
.text C:\Windows\system32\svchost.exe[920] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 00300FD2
.text C:\Windows\system32\svchost.exe[920] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 00300FE3
.text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 001C0051
.text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 001C0FB9
.text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 001C0000
.text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 001C0040
.text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 001C0F94
.text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 001C0FD4
.text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 001C0FE5
.text C:\Windows\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 001C001B
.text C:\Windows\system32\svchost.exe[920] WS2_32.dll!socket 769736D1 5 Bytes JMP 002E0FE5
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 002900A7
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 00290F61
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 002900EE
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 002900DD
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 00290F94
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 00290036
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 00290FA5
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 00290058
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 00290F83
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 00290FB6
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 00290047
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 00290F72
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 00290F3C
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 00290011
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 00290000
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 00290FDB
.text C:\Windows\system32\svchost.exe[988] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 002900C2
.text C:\Windows\system32\svchost.exe[988] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 002A0FD2
.text C:\Windows\system32\svchost.exe[988] msvcrt.dll!system 77258B63 5 Bytes JMP 002A0FE3
.text C:\Windows\system32\svchost.exe[988] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 002A0038
.text C:\Windows\system32\svchost.exe[988] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 002A0000
.text C:\Windows\system32\svchost.exe[988] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 002A0049
.text C:\Windows\system32\svchost.exe[988] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 002A001D
.text C:\Windows\system32\svchost.exe[988] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 001B0FCD
.text C:\Windows\system32\svchost.exe[988] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 001B0FDE
.text C:\Windows\system32\svchost.exe[988] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 001B0FEF
.text C:\Windows\system32\svchost.exe[988] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 001B0065
.text C:\Windows\system32\svchost.exe[988] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 001B0FB2
.text C:\Windows\system32\svchost.exe[988] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 001B002F
.text C:\Windows\system32\svchost.exe[988] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 001B000A
.text C:\Windows\system32\svchost.exe[988] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 001B004A
.text C:\Windows\system32\svchost.exe[988] WS2_32.dll!socket 769736D1 5 Bytes JMP 00200FEF
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 009100AE
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 00910F72
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 009100DA
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 00910F43
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 00910093
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 00910036
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 00910FAF
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 0091006C
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 00910F9E
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 00910FC0
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 00910051
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 00910F8D
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 009100FF
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 0091001B
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 0091000A
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 00910FDB
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 009100BF
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 0092005A
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!system 77258B63 5 Bytes JMP 00920049
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 0092001D
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 00920FE3
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 0092002E
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 0092000C
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 00730047
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 00730FAF
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 00730FE5
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 00730036
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 00730062
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 0073000A
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 00730FD4
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 0073001B
.text C:\Windows\System32\svchost.exe[1172] WS2_32.dll!socket 769736D1 5 Bytes JMP 007A0000
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 018B00B5
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 018B0F79
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 018B0F40
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 018B00E1
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 018B0F94
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 018B0025
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 018B0078
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 018B0051
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 018B0089
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 018B0FAF
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 018B0036
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 018B00A4
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 018B0F25
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 018B0FDE
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 018B0FEF
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 018B0014
.text C:\Windows\System32\svchost.exe[1208] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 018B00C6
.text C:\Windows\System32\svchost.exe[1208] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 01900027
.text C:\Windows\System32\svchost.exe[1208] msvcrt.dll!system 77258B63 5 Bytes JMP 01900F9C
.text C:\Windows\System32\svchost.exe[1208] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 01900FC8
.text C:\Windows\System32\svchost.exe[1208] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 01900000
.text C:\Windows\System32\svchost.exe[1208] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 01900FAD
.text C:\Windows\System32\svchost.exe[1208] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 01900FE3
.text C:\Windows\System32\svchost.exe[1208] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 01810047
.text C:\Windows\System32\svchost.exe[1208] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 01810FB9
.text C:\Windows\System32\svchost.exe[1208] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 01810FEF
.text C:\Windows\System32\svchost.exe[1208] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 01810036
.text C:\Windows\System32\svchost.exe[1208] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 01810F8A
.text C:\Windows\System32\svchost.exe[1208] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 01810FD4
.text C:\Windows\System32\svchost.exe[1208] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 0181000A
.text C:\Windows\System32\svchost.exe[1208] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 01810025
.text C:\Windows\System32\svchost.exe[1208] WS2_32.dll!socket 769736D1 5 Bytes JMP 018A0FEF
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 014B00D0
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 014B00B5
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 014B00F5
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 014B0F54
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 014B0093
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 014B002F
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 014B0076
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 014B005B
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 014B00A4
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 014B0FB9
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 014B004A
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 014B0F8A
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 014B0106
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 014B0FDE
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 014B0FEF
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 014B0014
.text C:\Windows\system32\svchost.exe[1224] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 014B0F6F
.text C:\Windows\system32\svchost.exe[1224] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 01590066
.text C:\Windows\system32\svchost.exe[1224] msvcrt.dll!system 77258B63 5 Bytes JMP 01590FE5
.text C:\Windows\system32\svchost.exe[1224] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 0159003A
.text C:\Windows\system32\svchost.exe[1224] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 01590000
.text C:\Windows\system32\svchost.exe[1224] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 01590055
.text C:\Windows\system32\svchost.exe[1224] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 01590029
.text C:\Windows\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 01350040
.text C:\Windows\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 0135002F
.text C:\Windows\system32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 01350FEF
.text C:\Windows\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 01350FA8
.text C:\Windows\system32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 0135005B
.text C:\Windows\system32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 0135000A
.text C:\Windows\system32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 01350FDE
.text C:\Windows\system32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 01350FC3
.text C:\Windows\system32\svchost.exe[1224] WS2_32.dll!socket 769736D1 5 Bytes JMP 01420000
.text C:\Windows\system32\svchost.exe[1224] WININET.dll!InternetOpenA 769B0A4D 5 Bytes JMP 029C0FEF
.text C:\Windows\system32\svchost.exe[1224] WININET.dll!InternetOpenUrlA 769B2713 5 Bytes JMP 029C0FD4
.text C:\Windows\system32\svchost.exe[1224] WININET.dll!InternetOpenW 769B30C8 5 Bytes JMP 029C000A
.text C:\Windows\system32\svchost.exe[1224] WININET.dll!InternetOpenUrlW 76A084F1 5 Bytes JMP 029C0025
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 00D7006E
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 00D7005D
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 00D70EEB
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 00D70F06
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 00D70F4D
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 00D70FA8
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 00D70027
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 00D70F83
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 00D70042
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 00D70F68
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 00D7000A
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 00D70F32
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 00D70093
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 00D70FD4
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 00D70FEF
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 00D70FB9
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 00D70F17
.text C:\Windows\system32\svchost.exe[1376] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 00D80F7C
.text C:\Windows\system32\svchost.exe[1376] msvcrt.dll!system 77258B63 5 Bytes JMP 00D80011
.text C:\Windows\system32\svchost.exe[1376] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 00D80FAB
.text C:\Windows\system32\svchost.exe[1376] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 00D80FEF
.text C:\Windows\system32\svchost.exe[1376] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 00D80000
.text C:\Windows\system32\svchost.exe[1376] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 00D80FC6
.text C:\Windows\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 00D60F72
.text C:\Windows\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 00D60F94
.text C:\Windows\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 00D60FEF
.text C:\Windows\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 00D60F83
.text C:\Windows\system32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 00D60F61
.text C:\Windows\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 00D60FCA
.text C:\Windows\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 00D6000A
.text C:\Windows\system32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 00D60FB9
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 00B500A2
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 00B50F52
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 00B50F01
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 00B50F1C
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 00B50058
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 00B5002C
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 00B50F8A
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 00B50FB6
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 00B5007D
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 00B50FA5
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 00B50047
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 00B50F63
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 00B500B3
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 00B5001B
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 00B5000A
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 00B50FE5
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 00B50F37
.text C:\Windows\system32\svchost.exe[1460] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 00BA0053
.text C:\Windows\system32\svchost.exe[1460] msvcrt.dll!system 77258B63 5 Bytes JMP 00BA0FC8
.text C:\Windows\system32\svchost.exe[1460] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 00BA0027
.text C:\Windows\system32\svchost.exe[1460] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 00BA000C
.text C:\Windows\system32\svchost.exe[1460] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 00BA0038
.text C:\Windows\system32\svchost.exe[1460] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 00BA0FE3
.text C:\Windows\system32\svchost.exe[1460] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 0019004D
.text C:\Windows\system32\svchost.exe[1460] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 00190FA1
.text C:\Windows\system32\svchost.exe[1460] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 00190FEF
.text C:\Windows\system32\svchost.exe[1460] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 00190028
.text C:\Windows\system32\svchost.exe[1460] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 0019005E
.text C:\Windows\system32\svchost.exe[1460] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 00190FC3
.text C:\Windows\system32\svchost.exe[1460] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 00190FD4
.text C:\Windows\system32\svchost.exe[1460] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 00190FB2
.text C:\Windows\system32\svchost.exe[1460] WS2_32.dll!socket 769736D1 5 Bytes JMP 00980FEF
.text C:\Windows\system32\svchost.exe[1460] WinInet.dll!InternetOpenA 769B0A4D 5 Bytes JMP 009D0FE5
.text C:\Windows\system32\svchost.exe[1460] WinInet.dll!InternetOpenUrlA 769B2713 5 Bytes JMP 009D0FD4
.text C:\Windows\system32\svchost.exe[1460] WinInet.dll!InternetOpenW 769B30C8 5 Bytes JMP 009D0000
.text C:\Windows\system32\svchost.exe[1460] WinInet.dll!InternetOpenUrlW 76A084F1 5 Bytes JMP 009D0FB9
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 009C0064
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 009C0F1E
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 009C0EF9
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 009C0086
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 009C0F65
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 009C0FC0
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 009C003D
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 009C0F9B
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 009C0F4A
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 009C0F8A
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 009C002C
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 009C0F2F
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 009C0EDE
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 009C000A
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 009C0FEF
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 009C001B
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 009C0075
.text C:\Windows\system32\svchost.exe[1588] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 00A90FA5
.text C:\Windows\system32\svchost.exe[1588] msvcrt.dll!system 77258B63 5 Bytes JMP 00A9003A
.text C:\Windows\system32\svchost.exe[1588] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 00A90FD4
.text C:\Windows\system32\svchost.exe[1588] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 00A90000
.text C:\Windows\system32\svchost.exe[1588] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 00A90029
.text C:\Windows\system32\svchost.exe[1588] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 00A90FEF
.text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 00950040
.text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 00950014
.text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 00950FE5
.text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 00950025
.text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 00950051
.text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 00950FC3
.text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 00950FD4
.text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 00950FA8
.text C:\Windows\system32\svchost.exe[1588] WS2_32.dll!socket 769736D1 5 Bytes JMP 009B0000
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 00A000C2
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 00A000A7
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 00A000D3
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 00A00F46
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 00A00071
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 00A00FD4
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 00A00F97
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 00A00FC3
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 00A0008C
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 00A00FA8
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 00A00040
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 00A00F7C
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 00A00F21
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 00A0001B
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 00A0000A
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 00A00FE5
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 00A00F57
.text C:\Windows\system32\svchost.exe[1864] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 00A10FA6
.text C:\Windows\system32\svchost.exe[1864] msvcrt.dll!system 77258B63 5 Bytes JMP 00A10031
.text C:\Windows\system32\svchost.exe[1864] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 00A10FD2
.text C:\Windows\system32\svchost.exe[1864] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 00A10FEF
.text C:\Windows\system32\svchost.exe[1864] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 00A10FC1
.text C:\Windows\system32\svchost.exe[1864] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 00A1000C
.text C:\Windows\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 00990F94
.text C:\Windows\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 0099001B
.text C:\Windows\system32\svchost.exe[1864] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 00990FEF
.text C:\Windows\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 00990036
.text C:\Windows\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 00990051
.text C:\Windows\system32\svchost.exe[1864] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 00990FCA
.text C:\Windows\system32\svchost.exe[1864] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 00990000
.text C:\Windows\system32\svchost.exe[1864] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 00990FAF
.text C:\Windows\system32\svchost.exe[1864] WS2_32.dll!socket 769736D1 5 Bytes JMP 009B0FEF
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1912] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 0041C1B0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1912] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 0041C130 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 00240F5C
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 002400A2
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 002400E9
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 002400CE
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 00240076
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 0024002F
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 00240F9C
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 0024005B
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 00240087
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 00240FB9
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 00240040
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 00240F81
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 00240F37
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 00240FE5
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 00240000
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 00240FD4
.text C:\Windows\System32\svchost.exe[2228] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 002400BD
.text C:\Windows\System32\svchost.exe[2228] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 006D0F89
.text C:\Windows\System32\svchost.exe[2228] msvcrt.dll!system 77258B63 5 Bytes JMP 006D0FA4
.text C:\Windows\System32\svchost.exe[2228] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 006D0FC6
.text C:\Windows\System32\svchost.exe[2228] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 006D0000
.text C:\Windows\System32\svchost.exe[2228] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 006D0FB5
.text C:\Windows\System32\svchost.exe[2228] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 006D0FE3
.text C:\Windows\System32\svchost.exe[2228] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 00090FB2
.text C:\Windows\System32\svchost.exe[2228] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 00090FC3
.text C:\Windows\System32\svchost.exe[2228] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 00090FEF
.text C:\Windows\System32\svchost.exe[2228] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 0009004A
.text C:\Windows\System32\svchost.exe[2228] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 0009006F
.text C:\Windows\System32\svchost.exe[2228] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 0009001B
.text C:\Windows\System32\svchost.exe[2228] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 0009000A
.text C:\Windows\System32\svchost.exe[2228] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 00090FD4
.text C:\Windows\System32\svchost.exe[2228] WS2_32.dll!socket 769736D1 5 Bytes JMP 000A0FEF
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 00820F39
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 0082007F
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 008200BF
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 0082009A
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 00820064
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 00820047
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 00820F8A
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 00820FB6
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 00820F6F
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 00820FA5
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 00820FD1
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 00820F54
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 00820F0D
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 0082001B
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 0082000A
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 00820036
.text C:\Windows\System32\svchost.exe[2256] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 00820F1E
.text C:\Windows\System32\svchost.exe[2256] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 0083004E
.text C:\Windows\System32\svchost.exe[2256] msvcrt.dll!system 77258B63 5 Bytes JMP 00830FC3
.text C:\Windows\System32\svchost.exe[2256] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 00830029
.text C:\Windows\System32\svchost.exe[2256] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 00830FEF
.text C:\Windows\System32\svchost.exe[2256] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 00830FD4
.text C:\Windows\System32\svchost.exe[2256] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 0083000C
.text C:\Windows\System32\svchost.exe[2256] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 001A0F72
.text C:\Windows\System32\svchost.exe[2256] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 001A0F9E
.text C:\Windows\System32\svchost.exe[2256] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 001A000A
.text C:\Windows\System32\svchost.exe[2256] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 001A0F83
.text C:\Windows\System32\svchost.exe[2256] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 001A0F61
.text C:\Windows\System32\svchost.exe[2256] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 001A0FD4
.text C:\Windows\System32\svchost.exe[2256] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 001A0FEF
.text C:\Windows\System32\svchost.exe[2256] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 001A0FB9
.text C:\Windows\System32\svchost.exe[2256] WS2_32.dll!socket 769736D1 5 Bytes JMP 00810FEF
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 00190F41
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 00190091
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 00190F26
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 001900C7
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 0019004A
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 00190FAF
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 00190F72
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 00190F94
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 0019005B
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 00190F83
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 0019001B
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 00190076
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 001900D8
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 00190000
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 00190FE5
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 00190FCA
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 001900A2
.text C:\Windows\system32\svchost.exe[2312] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 001A0FC0
.text C:\Windows\system32\svchost.exe[2312] msvcrt.dll!system 77258B63 5 Bytes JMP 001A0055
.text C:\Windows\system32\svchost.exe[2312] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 001A0FEF
.text C:\Windows\system32\svchost.exe[2312] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 001A0000
.text C:\Windows\system32\svchost.exe[2312] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 001A0044
.text C:\Windows\system32\svchost.exe[2312] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 001A001D
.text C:\Windows\system32\svchost.exe[2312] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 000B0098
.text C:\Windows\system32\svchost.exe[2312] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 000B0062
.text C:\Windows\system32\svchost.exe[2312] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 000B000A
.text C:\Windows\system32\svchost.exe[2312] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 000B007D
.text C:\Windows\system32\svchost.exe[2312] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 000B0FD1
.text C:\Windows\system32\svchost.exe[2312] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 000B0036
.text C:\Windows\system32\svchost.exe[2312] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 000B0025
.text C:\Windows\system32\svchost.exe[2312] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 000B0051
.text C:\Windows\system32\svchost.exe[2312] WS2_32.dll!socket 769736D1 5 Bytes JMP 00170FEF
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 00EE00A2
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 00EE0F66
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 00EE00CE
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 00EE00BD
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 00EE005B
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 00EE0FC3
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 00EE0F77
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 00EE0025
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 00EE006C
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 00EE0040
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 00EE0FA8
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 00EE0087
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 00EE0F1C
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 00EE0014
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 00EE0FEF
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 00EE0FDE
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 00EE0F41
.text C:\Windows\system32\svchost.exe[2392] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 010B0FA1
.text C:\Windows\system32\svchost.exe[2392] msvcrt.dll!system 77258B63 5 Bytes JMP 010B0FB2
.text C:\Windows\system32\svchost.exe[2392] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 010B0FD7
.text C:\Windows\system32\svchost.exe[2392] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 010B0000
.text C:\Windows\system32\svchost.exe[2392] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 010B0022
.text C:\Windows\system32\svchost.exe[2392] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 010B0011
.text C:\Windows\system32\svchost.exe[2392] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 00EC0062
.text C:\Windows\system32\svchost.exe[2392] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 00EC0036
.text C:\Windows\system32\svchost.exe[2392] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 00EC000A
.text C:\Windows\system32\svchost.exe[2392] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 00EC0047
.text C:\Windows\system32\svchost.exe[2392] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 00EC0FA5
.text C:\Windows\system32\svchost.exe[2392] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 00EC001B
.text C:\Windows\system32\svchost.exe[2392] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 00EC0FE5
.text C:\Windows\system32\svchost.exe[2392] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 00EC0FCA
.text C:\Windows\system32\svchost.exe[2392] WS2_32.dll!socket 769736D1 5 Bytes JMP 00ED000A
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 0006005E
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 00060F18
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 00060080
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 00060EE9
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 00060F55
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 0006000A
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 00060F70
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 0006002F
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 00060F44
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 00060F8D
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 00060FA8
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 00060F29
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 00060ECE
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 00060FDE
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 00060FEF
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 00060FB9
.text C:\Windows\System32\svchost.exe[2576] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 0006006F
.text C:\Windows\System32\svchost.exe[2576] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 00070F7A
.text C:\Windows\System32\svchost.exe[2576] msvcrt.dll!system 77258B63 5 Bytes JMP 00070F8B
.text C:\Windows\System32\svchost.exe[2576] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 00070FC1
.text C:\Windows\System32\svchost.exe[2576] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 00070FEF
.text C:\Windows\System32\svchost.exe[2576] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 00070FA6
.text C:\Windows\System32\svchost.exe[2576] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 00070FDE
.text C:\Windows\System32\svchost.exe[2576] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 00050FAC
.text C:\Windows\System32\svchost.exe[2576] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 0005003D
.text C:\Windows\System32\svchost.exe[2576] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 00050FEF
.text C:\Windows\System32\svchost.exe[2576] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 0005004E
.text C:\Windows\System32\svchost.exe[2576] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 00050F9B
.text C:\Windows\System32\svchost.exe[2576] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 0005001B
.text C:\Windows\System32\svchost.exe[2576] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 00050000
.text C:\Windows\System32\svchost.exe[2576] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 0005002C
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 0001009A
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 0001007F
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 00010F25
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 000100C6
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 00010064
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 00010FCA
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 00010F8A
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 00010036
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 00010F79
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 00010047
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 00010FAF
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 00010F54
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 000100E1
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 0001001B
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 00010000
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 00010FDB
.text C:\Windows\Explorer.EXE[2932] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 000100B5
.text C:\Windows\Explorer.EXE[2932] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 00050054
.text C:\Windows\Explorer.EXE[2932] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 00050FC3
.text C:\Windows\Explorer.EXE[2932] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 00050FEF
.text C:\Windows\Explorer.EXE[2932] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 00050FB2
.text C:\Windows\Explorer.EXE[2932] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 00050F8D
.text C:\Windows\Explorer.EXE[2932] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 0005001B
.text C:\Windows\Explorer.EXE[2932] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 0005000A
.text C:\Windows\Explorer.EXE[2932] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 00050FD4
.text C:\Windows\Explorer.EXE[2932] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 00060F8B
.text C:\Windows\Explorer.EXE[2932] msvcrt.dll!system 77258B63 5 Bytes JMP 00060FA6
.text C:\Windows\Explorer.EXE[2932] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 0006000C
.text C:\Windows\Explorer.EXE[2932] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 00060FEF
.text C:\Windows\Explorer.EXE[2932] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 00060FC1
.text C:\Windows\Explorer.EXE[2932] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 00060FD2
.text C:\Windows\Explorer.EXE[2932] WS2_32.dll!socket 769736D1 5 Bytes JMP 03190000
.text C:\Windows\Explorer.EXE[2932] WININET.dll!InternetOpenA 769B0A4D 5 Bytes JMP 031B0000
.text C:\Windows\Explorer.EXE[2932] WININET.dll!InternetOpenUrlA 769B2713 5 Bytes JMP 031B001B
.text C:\Windows\Explorer.EXE[2932] WININET.dll!InternetOpenW 769B30C8 5 Bytes JMP 031B0FE5
.text C:\Windows\Explorer.EXE[2932] WININET.dll!InternetOpenUrlW 76A084F1 5 Bytes JMP 031B0036
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 019800E1
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 019800D0
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 01980F65
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 01980F76
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 01980089
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 01980FE5
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 01980FAF
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 01980051
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 019800A4
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 0198006C
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 01980FCA
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 019800BF
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 01980F54
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 0198001B
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 0198000A
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 0198002C
.text C:\Windows\system32\svchost.exe[2940] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 019800F2
.text C:\Windows\system32\svchost.exe[2940] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 01B40FD4
.text C:\Windows\system32\svchost.exe[2940] msvcrt.dll!system 77258B63 5 Bytes JMP 01B4005F
.text C:\Windows\system32\svchost.exe[2940] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 01B40FE5
.text C:\Windows\system32\svchost.exe[2940] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 01B4000C
.text C:\Windows\system32\svchost.exe[2940] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 01B4003A
.text C:\Windows\system32\svchost.exe[2940] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 01B4001D
.text C:\Windows\system32\svchost.exe[2940] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 01920F9E
.text C:\Windows\system32\svchost.exe[2940] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 01920025
.text C:\Windows\system32\svchost.exe[2940] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 01920FEF
.text C:\Windows\system32\svchost.exe[2940] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 01920040
.text C:\Windows\system32\svchost.exe[2940] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 01920051
.text C:\Windows\system32\svchost.exe[2940] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 01920FD4
.text C:\Windows\system32\svchost.exe[2940] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 0192000A
.text C:\Windows\system32\svchost.exe[2940] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 01920FB9
.text C:\Windows\system32\svchost.exe[2940] WS2_32.dll!socket 769736D1 5 Bytes JMP 0197000A
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!GetStartupInfoW 76E31929 5 Bytes JMP 00010F41
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!GetStartupInfoA 76E319C9 5 Bytes JMP 00010F5C
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!CreateProcessW 76E31C01 5 Bytes JMP 00010F0B
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!CreateProcessA 76E31C36 5 Bytes JMP 000100A2
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!VirtualProtect 76E31DD1 5 Bytes JMP 00010F77
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!CreateNamedPipeW 76E35C44 5 Bytes JMP 00010FC3
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!LoadLibraryExW 76E530C3 5 Bytes JMP 00010051
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!LoadLibraryW 76E5361F 5 Bytes JMP 00010040
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!VirtualProtectEx 76E58D7E 5 Bytes JMP 00010076
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!LoadLibraryExA 76E59469 5 Bytes JMP 00010F9E
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!LoadLibraryA 76E59491 5 Bytes JMP 0001002F
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!CreatePipe 76E60284 5 Bytes JMP 00010087
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!GetProcAddress 76E7B8B6 5 Bytes JMP 000100C7
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!CreateFileW 76E7CC4E 5 Bytes JMP 00010FD4
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!CreateFileA 76E7CF71 5 Bytes JMP 00010FEF
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!CreateNamedPipeA 76EC430E 5 Bytes JMP 0001000A
.text C:\Windows\system32\wuauclt.exe[3192] kernel32.dll!WinExec 76EC54FF 5 Bytes JMP 00010F30
.text C:\Windows\system32\wuauclt.exe[3192] msvcrt.dll!_wsystem 77258A47 5 Bytes JMP 000A0FA6
.text C:\Windows\system32\wuauclt.exe[3192] msvcrt.dll!system 77258B63 5 Bytes JMP 000A0FB7
.text C:\Windows\system32\wuauclt.exe[3192] msvcrt.dll!_creat 7725C6F1 5 Bytes JMP 000A0FE3
.text C:\Windows\system32\wuauclt.exe[3192] msvcrt.dll!_open 7725DA7E 5 Bytes JMP 000A000C
.text C:\Windows\system32\wuauclt.exe[3192] msvcrt.dll!_wcreat 7725DC9E 5 Bytes JMP 000A0FC8
.text C:\Windows\system32\wuauclt.exe[3192] msvcrt.dll!_wopen 7725DE79 5 Bytes JMP 000A001D
.text C:\Windows\system32\wuauclt.exe[3192] ADVAPI32.dll!RegCreateKeyExA 75D1B5E7 5 Bytes JMP 000B0F83
.text C:\Windows\system32\wuauclt.exe[3192] ADVAPI32.dll!RegCreateKeyA 75D1B8AE 5 Bytes JMP 000B0025
.text C:\Windows\system32\wuauclt.exe[3192] ADVAPI32.dll!RegOpenKeyA 75D20BF5 5 Bytes JMP 000B0FEF
.text C:\Windows\system32\wuauclt.exe[3192] ADVAPI32.dll!RegCreateKeyW 75D2B83D 5 Bytes JMP 000B0F9E
.text C:\Windows\system32\wuauclt.exe[3192] ADVAPI32.dll!RegCreateKeyExW 75D2BCE1 5 Bytes JMP 000B0F72
.text C:\Windows\system32\wuauclt.exe[3192] ADVAPI32.dll!RegOpenKeyExA 75D2D4E8 5 Bytes JMP 000B000A
.text C:\Windows\system32\wuauclt.exe[3192] ADVAPI32.dll!RegOpenKeyW 75D33CB0 5 Bytes JMP 000B0FDE
.text C:\Windows\system32\wuauclt.exe[3192] ADVAPI32.dll!RegOpenKeyExW 75D3F09D 5 Bytes JMP 000B0FB9
.text C:\Windows\system32\wuauclt.exe[3192] WS2_32.dll!socket 769736D1 5 Bytes JMP 00180FE5

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[668] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [001D2F20] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[668] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [001D2CF0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[668] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [001D2C90] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[668] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [001D2CC0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Skype\Phone\Skype.exe[1032] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [030D2F20] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Skype\Phone\Skype.exe[1032] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [030D2CF0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Skype\Phone\Skype.exe[1032] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [030D2C90] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Skype\Phone\Skype.exe[1032] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [030D2CC0] C:\Windows\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [743488B4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [743898A5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7434B9D4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7433FB47] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74347A79] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [7433EA65] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [7437B17D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7434BC9A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [7434074E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [743406B5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [743371B3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [743CD848] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [74367379] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [7433E109] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [7433697E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [743369A9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2932] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74342465] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54
c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

—- EOF - GMER 1.0.15 —-


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 21:39:47.21 on Wed 02/24/2010
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Business 6.0.6001.1.1252.1.1033.18.3325.2172 [GMT -6:00]

SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\AERTSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k HPService
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Users\MACGIBBON\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\WD\WD Anywhere Backup\MemeoBackup.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Windows\system32\NOTEPAD.EXE
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\MACGIBBON\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.comcast.net/a/
uWindow Title = Internet Explorer provided by Dell
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\2.0.301.7164\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
uRun: [googletalk] c:\users\macgibbon\appdata\roaming\google\google talk\googletalk.exe /autostart
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [Mbomo] rundll32.exe "c:\users\macgibbon\appdata\local\SYRXTAz.dll",Startup
uRun: [Cginajelehefonu] rundll32.exe "c:\users\macgibbon\appdata\local\avuqoralosupuka.dll",Startup
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [ownvijjg] c:\users\macgibbon\appdata\local\nbwmjp\ekvjsftav.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe"
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [BrStsWnd] c:\program files\brownie\BrstsWnd.exe Autorun
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [WD Drive Manager] c:\program files\western digital\wd drive manager\WDBtnMgrUI.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [WD Anywhere Backup] c:\program files\wd\wd anywhere backup\MemeoLauncher2.exe –silent
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide
StartupFolder: c:\users\macgib~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\webshots.lnk - c:\program files\webshots\Launcher.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~1\office12\ONBttnIE.dll
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {49232000-16E4-426C-A231-62846947304B} - hxxps://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\users\macgib~1\appdata\roaming\mozilla\firefox\profiles\pomp1wq8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/a/
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npoji610.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-5 77824]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-4-29 176128]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\wd\wd anywhere backup\MemeoBackgroundService.exe [2009-4-17 25824]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\western digital\wd drive manager\WDBtnMgrSvc.exe [2008-7-24 102400]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-5-6 30192]

=============== Created Last 30 ================

2010-02-24 21:34 500,136,621 a——- c:\windows\MEMORY.DMP
2010-02-24 20:47 –d—– c:\users\macgib~1\appdata\roaming\Malwarebytes
2010-02-24 20:47 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-24 20:47 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-02-24 20:47 –d—– c:\programdata\Malwarebytes
2010-02-24 20:47 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-02-24 20:47 –d—– c:\progra~2\Malwarebytes
2010-02-23 19:53 2,048 a——- c:\windows\system32\tzres.dll
2010-02-23 19:52 523,776 a——- c:\windows\system32\RMActivate_isv.exe
2010-02-23 19:52 511,488 a——- c:\windows\system32\RMActivate.exe
2010-02-23 19:52 472,576 a——- c:\windows\system32\secproc_isv.dll
2010-02-23 19:52 472,064 a——- c:\windows\system32\secproc.dll
2010-02-23 19:52 347,136 a——- c:\windows\system32\RMActivate_ssp.exe
2010-02-23 19:52 346,624 a——- c:\windows\system32\RMActivate_ssp_isv.exe
2010-02-23 19:52 329,216 a——- c:\windows\system32\msdrm.dll
2010-02-23 19:52 151,040 a——- c:\windows\system32\secproc_ssp_isv.dll
2010-02-23 19:52 151,040 a——- c:\windows\system32\secproc_ssp.dll
2010-02-22 21:42 –d—– c:\users\macgib~1\appdata\roaming\AVG8
2010-02-10 21:15 –d—– c:\users\macgibbon\Tracing
2010-02-10 21:11 82,696 a——- c:\windows\system32\lmdimon8.dll
2010-02-10 21:10 –d—– c:\programdata\Applications
2010-02-10 21:10 –d—– c:\progra~2\Applications
2010-02-08 20:23 –d—– c:\program files\Microsoft CAPICOM 2.1.0.2
2010-02-06 19:00 0 a——- c:\windows\system32\drivers\lvuvc.hs
2010-02-06 18:58 6,756,632 a——- c:\windows\system32\drivers\lvuvc.sys
2010-02-06 18:58 539,160 a——- c:\windows\system32\LVUI2RC.dll
2010-02-06 18:58 539,160 a——- c:\windows\system32\LVUI2.dll
2010-02-06 18:58 416,280 a——- c:\windows\system32\lvcodec2.dll
2010-02-06 18:58 266,828 a——- c:\windows\system32\drivers\LVAFT.cfg
2010-02-06 18:57 266,008 a——- c:\windows\system32\drivers\lvrs.sys
2010-02-06 18:57 199,192 a——- c:\windows\system32\lvci12101110.dll
2010-02-06 18:57 82,289 a——- c:\windows\system32\lvcoinst.ini
2010-02-06 18:57 34,068 a——- c:\windows\system32\Repository.reg

==================== Find3M ====================

2010-02-06 18:58 51,200 a——- c:\windows\inf\infpub.dat
2010-02-06 18:58 143,360 a——- c:\windows\inf\infstrng.dat
2010-02-06 18:58 86,016 a——- c:\windows\inf\infstor.dat
2010-01-25 19:55 56 a—h— c:\programdata\ezsidmv.dat
2010-01-25 19:55 56 a—h— c:\progra~2\ezsidmv.dat
2009-12-28 06:35 11,776 a——- c:\windows\system32\tsbyuv.dll
2009-12-28 06:35 1,314,816 a——- c:\windows\system32\quartz.dll
2009-12-28 06:32 22,528 a——- c:\windows\system32\msyuv.dll
2009-12-28 06:32 123,904 a——- c:\windows\system32\msvfw32.dll
2009-12-28 06:32 31,744 a——- c:\windows\system32\msvidc32.dll
2009-12-28 06:32 13,312 a——- c:\windows\system32\msrle32.dll
2009-12-28 06:31 82,944 a——- c:\windows\system32\mciavi32.dll
2009-12-28 06:31 50,176 a——- c:\windows\system32\iyuv_32.dll
2009-12-28 06:28 91,136 a——- c:\windows\system32\avifil32.dll
2009-12-28 06:28 65,024 a——- c:\windows\system32\avicap32.dll
2009-12-20 08:47 147,616 a——- c:\windows\hpoins21.dat
2009-12-18 07:05 833,024 a——- c:\windows\system32\wininet.dll
2009-12-18 07:01 78,336 a——- c:\windows\system32\ieencode.dll
2009-12-18 04:14 26,624 a——- c:\windows\system32\ieUnatt.exe
2009-12-08 14:52 3,597,912 a——- c:\windows\system32\ntkrnlpa.exe
2009-12-08 14:52 3,546,200 a——- c:\windows\system32\ntoskrnl.exe
2008-11-13 03:33 174 a–sh— c:\program files\desktop.ini
2008-11-13 03:23 665,600 a——- c:\windows\inf\drvindex.dat
2006-11-02 06:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 06:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 06:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 06:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 03:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 03:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 03:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 03:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2008-05-06 11:24 8,192 a–sh— c:\windows\users\default\NTUSER.DAT

============= FINISH: 21:40:56.57 ===============
Just attach it as it is, no need to .zip it.

Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2
Link 3

[external image: Posted Image]

[external image: Posted Image]

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on Combo-Fix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Here is the Combo-Fix log

ComboFix 10-02-25.02 - MACGIBBON 02/25/2010 21:17:51.1.2 - x86
Microsoft® Windows Vista™ Business 6.0.6001.1.1252.1.1033.18.3325.2048 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-243088818-3472766843-1735871867-500
c:\$recycle.bin\S-1-5-21-2826133206-2312993737-4083541239-500
c:\$recycle.bin\S-1-5-21-918056312-2952985149-2686913973-500
c:\users\MACGIBBON\AppData\Local\{984C81B2-EF23-4D0F-AB77-4B967AC8EF31}
c:\users\MACGIBBON\AppData\Local\{984C81B2-EF23-4D0F-AB77-4B967AC8EF31}\chrome.manifest
c:\users\MACGIBBON\AppData\Local\{984C81B2-EF23-4D0F-AB77-4B967AC8EF31}\chrome\content\_cfg.js
c:\users\MACGIBBON\AppData\Local\{984C81B2-EF23-4D0F-AB77-4B967AC8EF31}\chrome\content\overlay.xul
c:\users\MACGIBBON\AppData\Local\{984C81B2-EF23-4D0F-AB77-4B967AC8EF31}\install.rdf
c:\users\MACGIBBON\AppData\Local\Microsoft\Windows\Temporary Internet Files\PMHB8C4.tmp
c:\windows\system32\AutoRun.inf
c:\windows\TEMP\logishrd\LVPrcInj01.dll

.
((((((((((((((((((((((((( Files Created from 2010-01-26 to 2010-02-26 )))))))))))))))))))))))))))))))
.

2010-02-26 03:22 . 2010-02-26 03:22 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-02-25 02:47 . 2010-02-25 02:47 ——– d—–w- c:\users\MACGIBBON\AppData\Roaming\Malwarebytes
2010-02-25 02:47 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-25 02:47 . 2010-02-25 02:47 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-25 02:47 . 2010-02-25 02:47 ——– d—–w- c:\programdata\Malwarebytes
2010-02-25 02:47 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-25 02:41 . 2010-02-25 02:41 ——– d—–w- c:\program files\ERUNT
2010-02-24 01:53 . 2010-01-23 09:44 2048 —-a-w- c:\windows\system32\tzres.dll
2010-02-24 01:52 . 2010-01-25 12:48 472576 —-a-w- c:\windows\system32\secproc_isv.dll
2010-02-24 01:52 . 2010-01-25 12:48 472064 —-a-w- c:\windows\system32\secproc.dll
2010-02-24 01:52 . 2010-01-25 08:35 346624 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-02-24 01:52 . 2010-01-25 08:35 523776 —-a-w- c:\windows\system32\RMActivate_isv.exe
2010-02-24 01:52 . 2010-01-25 08:34 511488 —-a-w- c:\windows\system32\RMActivate.exe
2010-02-24 01:52 . 2010-01-25 08:34 347136 —-a-w- c:\windows\system32\RMActivate_ssp.exe
2010-02-24 01:52 . 2010-01-25 12:48 151040 —-a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-02-24 01:52 . 2010-01-25 12:48 151040 —-a-w- c:\windows\system32\secproc_ssp.dll
2010-02-24 01:52 . 2010-01-25 12:45 329216 —-a-w- c:\windows\system32\msdrm.dll
2010-02-23 03:42 . 2010-02-23 03:42 ——– d—–w- c:\users\MACGIBBON\AppData\Roaming\AVG8
2010-02-22 14:48 . 2010-02-23 13:09 ——– d—–w- c:\users\MACGIBBON\AppData\Local\nbwmjp
2010-02-11 03:15 . 2010-02-11 14:56 ——– d—–w- c:\users\MACGIBBON\Tracing
2010-02-11 03:11 . 2009-12-10 15:24 82696 —-a-w- c:\windows\system32\lmdimon8.dll
2010-02-11 03:11 . 2009-12-10 15:24 82168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\lmdippr8.dll
2010-02-11 03:10 . 2010-02-11 03:10 ——– d—–w- c:\programdata\Applications
2010-02-09 02:23 . 2010-02-09 02:23 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-02-07 00:58 . 2010-02-07 00:58 ——– d—–w- c:\users\MACGIBBON\AppData\Roaming\Leadertech
2010-02-07 00:58 . 2009-10-07 08:49 6756632 —-a-w- c:\windows\system32\drivers\lvuvc.sys
2010-02-07 00:58 . 2009-10-07 08:48 539160 —-a-w- c:\windows\system32\LVUI2RC.dll
2010-02-07 00:58 . 2009-10-07 08:48 539160 —-a-w- c:\windows\system32\LVUI2.dll
2010-02-07 00:58 . 2009-10-07 08:43 416280 —-a-w- c:\windows\system32\lvcodec2.dll
2010-02-07 00:57 . 2009-10-07 08:47 266008 —-a-w- c:\windows\system32\drivers\lvrs.sys
2010-02-07 00:57 . 2009-10-07 08:43 199192 —-a-w- c:\windows\system32\lvci12101110.dll
2010-02-07 00:57 . 2009-10-07 08:24 34068 —-a-w- c:\windows\system32\Repository.reg

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-26 03:25 . 2010-01-26 01:52 ——– d—–w- c:\users\MACGIBBON\AppData\Roaming\Skype
2010-02-26 03:23 . 2010-02-07 01:00 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2010-02-26 03:09 . 2010-01-26 01:55 ——– d—–w- c:\users\MACGIBBON\AppData\Roaming\skypePM
2010-02-24 02:01 . 2008-05-10 20:45 59464 —-a-w- c:\users\MACGIBBON\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-23 12:41 . 2008-11-18 01:22 7728 —-a-w- c:\users\MACGIBBON\AppData\Local\d3d9caps.dat
2010-02-19 11:48 . 2008-05-11 01:09 ——– d—–w- c:\program files\McAfee
2010-02-10 09:18 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-02-07 00:57 . 2008-11-17 03:10 ——– d—–w- c:\program files\Common Files\Logishrd
2010-02-07 00:55 . 2008-11-17 13:02 ——– d—–w- c:\programdata\LogiShrd
2010-02-07 00:55 . 2008-05-12 02:06 ——– d—–w- c:\program files\Logitech
2010-01-29 04:17 . 2009-09-10 13:31 ——– d—–w- c:\program files\Safari
2010-01-29 04:14 . 2010-01-29 04:14 79144 —-a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2010-01-26 01:55 . 2010-01-26 01:55 56 —ha-w- c:\programdata\ezsidmv.dat
2010-01-26 01:51 . 2010-01-26 01:51 ——– d—–r- c:\program files\Skype
2010-01-26 01:51 . 2010-01-26 01:51 ——– d—–w- c:\program files\Common Files\Skype
2010-01-26 01:51 . 2010-01-26 01:51 ——– d—–w- c:\programdata\Skype
2009-12-28 12:35 . 2010-02-09 22:33 11776 —-a-w- c:\windows\system32\tsbyuv.dll
2009-12-28 12:35 . 2010-02-09 22:33 1314816 —-a-w- c:\windows\system32\quartz.dll
2009-12-28 12:32 . 2010-02-09 22:33 22528 —-a-w- c:\windows\system32\msyuv.dll
2009-12-28 12:32 . 2010-02-09 22:33 31744 —-a-w- c:\windows\system32\msvidc32.dll
2009-12-28 12:32 . 2010-02-09 22:33 123904 —-a-w- c:\windows\system32\msvfw32.dll
2009-12-28 12:32 . 2010-02-09 22:33 13312 —-a-w- c:\windows\system32\msrle32.dll
2009-12-28 12:31 . 2010-02-09 22:33 82944 —-a-w- c:\windows\system32\mciavi32.dll
2009-12-28 12:31 . 2010-02-09 22:33 50176 —-a-w- c:\windows\system32\iyuv_32.dll
2009-12-28 12:28 . 2010-02-09 22:33 65024 —-a-w- c:\windows\system32\avicap32.dll
2009-12-28 12:28 . 2010-02-09 22:33 91136 —-a-w- c:\windows\system32\avifil32.dll
2009-12-20 14:47 . 2008-09-26 03:42 147616 —-a-w- c:\windows\hpoins21.dat
2009-12-18 13:05 . 2010-01-22 17:25 833024 —-a-w- c:\windows\system32\wininet.dll
2009-12-18 13:01 . 2010-01-22 17:25 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-12-18 10:14 . 2010-01-22 17:25 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-12-11 12:07 . 2010-02-09 22:33 301568 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-11 12:07 . 2010-02-09 22:33 98304 —-a-w- c:\windows\system32\drivers\srvnet.sys
2009-12-08 20:52 . 2010-02-09 22:33 897624 —-a-w- c:\windows\system32\drivers\tcpip.sys
2009-12-08 20:52 . 2010-02-09 22:33 3597912 —-a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-08 20:52 . 2010-02-09 22:33 3546200 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-04 16:12 . 2010-02-09 22:33 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-12-04 16:12 . 2010-02-09 22:33 105472 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-28 22:50 . 2009-11-28 22:50 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-05-06 17:24 . 2008-05-06 17:15 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"googletalk"="c:\users\MACGIBBON\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 124200]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-11-28 30192]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"BrStsWnd"="c:\program files\Brownie\BrstsWnd.exe" [2007-08-01 815104]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-07-24 450560]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"WD Anywhere Backup"="c:\program files\WD\WD Anywhere Backup\MemeoLauncher2.exe" [2009-04-17 197856]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]

c:\users\MACGIBBON\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2008-5-10 157008]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-11-16 805392]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-05-06 09:59 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfehidk.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"FirewallOverride"=dword:00000001

R2 AERTFilters;Andrea RT Filters Service;c:\windows\System32\AERTSrv.exe [12/5/2007 5:17 AM 77824]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [4/29/2009 1:07 AM 176128]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\WD\WD Anywhere Backup\MemeoBackgroundService.exe [4/17/2009 11:51 AM 25824]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [7/24/2008 2:22 PM 102400]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [5/6/2008 3:56 AM 30192]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
.
Contents of the 'Scheduled Tasks' folder

2010-02-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-22 17:22]

2010-02-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-22 17:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.comcast.net/a/
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\MACGIBBON\AppData\Roaming\Mozilla\Firefox\Profiles\pomp1wq8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/a/
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Mbomo - c:\users\MACGIBBON\AppData\Local\SYRXTAz.dll
HKCU-Run-Cginajelehefonu - c:\users\MACGIBBON\AppData\Local\avuqoralosupuka.dll
HKCU-Run-ownvijjg - c:\users\MACGIBBON\AppData\Local\nbwmjp\ekvjsftav.exe
SafeBoot-mfehidk
SafeBoot-mferkdk
SafeBoot-mfetdik
SafeBoot-mfetdik.sys



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-25 21:24
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-243088818-3472766843-1735871867-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\bmp*]
"0"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00,
00,1a,00,ee,bb,fe,23,00,00,10,00,d0,9a,d3,fd,8f,23,af,46,ad,b4,6c,85,48,03,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff

[HKEY_USERS\S-1-5-21-243088818-3472766843-1735871867-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*bmp*]
@Class="Shell"

[HKEY_USERS\S-1-5-21-243088818-3472766843-1735871867-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*bmp*\OpenWithList]
@Class="Shell"
"a"="hpqscnvw.exe"
"MRUList"="a"

[HKEY_USERS\S-1-5-21-243088818-3472766843-1735871867-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.*bmp*]
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
"0"=hex:61,00,70,00,61,00,72,00,74,00,6d,00,65,00,6e,00,74,00,2e,00,62,6d,70,
00,00,00,7a,00,36,00,00,00,00,00,00,00,00,00,00,00,61,00,70,00,61,00,72,00,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(6680)
c:\program files\Logitech\SetPoint\lgscroll.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\atieclxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\windows\system32\WUDFHost.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\RtHDVCpl.exe
c:\program files\Webshots\Webshots.scr
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\WD\WD Anywhere Backup\MemeoBackup.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2010-02-25 21:29:49 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-26 03:29

Pre-Run: 375,634,329,600 bytes free
Post-Run: 375,913,193,472 bytes free

- - End Of File - - 4DF65C64D2FB3043A31875F67FE8CB03
Hi,

Looking better, let's press on with the cleaning.


1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

Folder::
c:\users\MACGIBBON\AppData\Local\nbwmjp

DDS::
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = 

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

5. After reboot, (in case it asks to reboot), please post ComboFix.txt in your next reply.


Eset online scannner

You can use either Internet Explorer or Mozilla FireFox for this scan.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.
Let me know how things are running now.
Uh-oh I just picked up with your latest instructions and started running the Combo-Fix again. However I had turned my antivirus back on after running it the last time so it was still on when I started the Combo-Fix. I noticed the McAfee popped up and said something about detecting something while the Combo-Fix was running. Which made me think about the fact I probably was supposed to shut that off again. So Combo-Fix is running through the stages but maybe something isn't working right because of the antivirus being on. If it gets done before I hear back I will post the log and wait to do anything further until I hear back.
Here is the ComboFix log - note that I botched this a bit by not shutting the McAfee down before I started it. I am on hold waiting to hear if I should proceed with the next stop or not - in light of that error in the process.

ComboFix 10-02-26.01 - MACGIBBON 02/26/2010 19:46:16.2.2 - x86
Microsoft® Windows Vista™ Business 6.0.6001.1.1252.1.1033.18.3325.2066 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\users\MACGIBBON\Desktop\CFScript.txt
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\MACGIBBON\AppData\Local\nbwmjp
c:\windows\TEMP\logishrd\LVPrcInj01.dll

.
((((((((((((((((((((((((( Files Created from 2010-01-27 to 2010-02-27 )))))))))))))))))))))))))))))))
.

2010-02-27 01:50 . 2010-02-27 01:50 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-02-27 01:50 . 2010-02-27 01:50 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-02-25 02:47 . 2010-02-25 02:47 ——– d—–w- c:\users\MACGIBBON\AppData\Roaming\Malwarebytes
2010-02-25 02:47 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-25 02:47 . 2010-02-25 02:47 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-25 02:47 . 2010-02-25 02:47 ——– d—–w- c:\programdata\Malwarebytes
2010-02-25 02:47 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-25 02:41 . 2010-02-25 02:41 ——– d—–w- c:\program files\ERUNT
2010-02-24 01:53 . 2010-01-23 09:44 2048 —-a-w- c:\windows\system32\tzres.dll
2010-02-24 01:52 . 2010-01-25 12:48 472576 —-a-w- c:\windows\system32\secproc_isv.dll
2010-02-24 01:52 . 2010-01-25 12:48 472064 —-a-w- c:\windows\system32\secproc.dll
2010-02-24 01:52 . 2010-01-25 08:35 346624 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-02-24 01:52 . 2010-01-25 08:35 523776 —-a-w- c:\windows\system32\RMActivate_isv.exe
2010-02-24 01:52 . 2010-01-25 08:34 511488 —-a-w- c:\windows\system32\RMActivate.exe
2010-02-24 01:52 . 2010-01-25 08:34 347136 —-a-w- c:\windows\system32\RMActivate_ssp.exe
2010-02-24 01:52 . 2010-01-25 12:48 151040 —-a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-02-24 01:52 . 2010-01-25 12:48 151040 —-a-w- c:\windows\system32\secproc_ssp.dll
2010-02-24 01:52 . 2010-01-25 12:45 329216 —-a-w- c:\windows\system32\msdrm.dll
2010-02-23 03:42 . 2010-02-23 03:42 ——– d—–w- c:\users\MACGIBBON\AppData\Roaming\AVG8
2010-02-11 03:15 . 2010-02-11 14:56 ——– d—–w- c:\users\MACGIBBON\Tracing
2010-02-11 03:11 . 2009-12-10 15:24 82696 —-a-w- c:\windows\system32\lmdimon8.dll
2010-02-11 03:11 . 2009-12-10 15:24 82168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\lmdippr8.dll
2010-02-11 03:10 . 2010-02-11 03:10 ——– d—–w- c:\programdata\Applications
2010-02-09 02:23 . 2010-02-09 02:23 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-02-07 00:58 . 2010-02-07 00:58 ——– d—–w- c:\users\MACGIBBON\AppData\Roaming\Leadertech
2010-02-07 00:58 . 2009-10-07 08:49 6756632 —-a-w- c:\windows\system32\drivers\lvuvc.sys
2010-02-07 00:58 . 2009-10-07 08:48 539160 —-a-w- c:\windows\system32\LVUI2RC.dll
2010-02-07 00:58 . 2009-10-07 08:48 539160 —-a-w- c:\windows\system32\LVUI2.dll
2010-02-07 00:58 . 2009-10-07 08:43 416280 —-a-w- c:\windows\system32\lvcodec2.dll
2010-02-07 00:57 . 2009-10-07 08:47 266008 —-a-w- c:\windows\system32\drivers\lvrs.sys
2010-02-07 00:57 . 2009-10-07 08:43 199192 —-a-w- c:\windows\system32\lvci12101110.dll
2010-02-07 00:57 . 2009-10-07 08:24 34068 —-a-w- c:\windows\system32\Repository.reg

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-27 01:52 . 2010-01-26 01:52 ——– d—–w- c:\users\MACGIBBON\AppData\Roaming\Skype
2010-02-27 01:51 . 2010-02-07 01:00 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2010-02-27 01:34 . 2010-01-26 01:55 ——– d—–w- c:\users\MACGIBBON\AppData\Roaming\skypePM
2010-02-26 03:36 . 2008-11-18 01:22 7728 —-a-w- c:\users\MACGIBBON\AppData\Local\d3d9caps.dat
2010-02-24 02:01 . 2008-05-10 20:45 59464 —-a-w- c:\users\MACGIBBON\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-19 11:48 . 2008-05-11 01:09 ——– d—–w- c:\program files\McAfee
2010-02-10 09:18 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-02-07 00:57 . 2008-11-17 03:10 ——– d—–w- c:\program files\Common Files\Logishrd
2010-02-07 00:55 . 2008-11-17 13:02 ——– d—–w- c:\programdata\LogiShrd
2010-02-07 00:55 . 2008-05-12 02:06 ——– d—–w- c:\program files\Logitech
2010-01-29 04:17 . 2009-09-10 13:31 ——– d—–w- c:\program files\Safari
2010-01-29 04:14 . 2010-01-29 04:14 79144 —-a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2010-01-26 01:55 . 2010-01-26 01:55 56 —ha-w- c:\programdata\ezsidmv.dat
2010-01-26 01:51 . 2010-01-26 01:51 ——– d—–r- c:\program files\Skype
2010-01-26 01:51 . 2010-01-26 01:51 ——– d—–w- c:\program files\Common Files\Skype
2010-01-26 01:51 . 2010-01-26 01:51 ——– d—–w- c:\programdata\Skype
2009-12-28 12:35 . 2010-02-09 22:33 11776 —-a-w- c:\windows\system32\tsbyuv.dll
2009-12-28 12:35 . 2010-02-09 22:33 1314816 —-a-w- c:\windows\system32\quartz.dll
2009-12-28 12:32 . 2010-02-09 22:33 22528 —-a-w- c:\windows\system32\msyuv.dll
2009-12-28 12:32 . 2010-02-09 22:33 31744 —-a-w- c:\windows\system32\msvidc32.dll
2009-12-28 12:32 . 2010-02-09 22:33 123904 —-a-w- c:\windows\system32\msvfw32.dll
2009-12-28 12:32 . 2010-02-09 22:33 13312 —-a-w- c:\windows\system32\msrle32.dll
2009-12-28 12:31 . 2010-02-09 22:33 82944 —-a-w- c:\windows\system32\mciavi32.dll
2009-12-28 12:31 . 2010-02-09 22:33 50176 —-a-w- c:\windows\system32\iyuv_32.dll
2009-12-28 12:28 . 2010-02-09 22:33 65024 —-a-w- c:\windows\system32\avicap32.dll
2009-12-28 12:28 . 2010-02-09 22:33 91136 —-a-w- c:\windows\system32\avifil32.dll
2009-12-20 14:47 . 2008-09-26 03:42 147616 —-a-w- c:\windows\hpoins21.dat
2009-12-18 13:05 . 2010-01-22 17:25 833024 —-a-w- c:\windows\system32\wininet.dll
2009-12-18 13:01 . 2010-01-22 17:25 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-12-18 10:14 . 2010-01-22 17:25 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-12-11 12:07 . 2010-02-09 22:33 301568 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-11 12:07 . 2010-02-09 22:33 98304 —-a-w- c:\windows\system32\drivers\srvnet.sys
2009-12-08 20:52 . 2010-02-09 22:33 897624 —-a-w- c:\windows\system32\drivers\tcpip.sys
2009-12-08 20:52 . 2010-02-09 22:33 3597912 —-a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-08 20:52 . 2010-02-09 22:33 3546200 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-04 16:12 . 2010-02-09 22:33 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-12-04 16:12 . 2010-02-09 22:33 105472 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-28 22:50 . 2009-11-28 22:50 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-05-06 17:24 . 2008-05-06 17:15 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"googletalk"="c:\users\MACGIBBON\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 124200]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-11-28 30192]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"BrStsWnd"="c:\program files\Brownie\BrstsWnd.exe" [2007-08-01 815104]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-07-24 450560]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"WD Anywhere Backup"="c:\program files\WD\WD Anywhere Backup\MemeoLauncher2.exe" [2009-04-17 197856]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]

c:\users\MACGIBBON\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2008-5-10 157008]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-11-16 805392]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-05-06 09:59 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfehidk.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"FirewallOverride"=dword:00000001

R2 AERTFilters;Andrea RT Filters Service;c:\windows\System32\AERTSrv.exe [12/5/2007 5:17 AM 77824]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [4/29/2009 1:07 AM 176128]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\WD\WD Anywhere Backup\MemeoBackgroundService.exe [4/17/2009 11:51 AM 25824]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [5/6/2008 3:56 AM 30192]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
.
Contents of the 'Scheduled Tasks' folder

2010-02-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-22 17:22]

2010-02-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-22 17:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.comcast.net/a/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\MACGIBBON\AppData\Roaming\Mozilla\Firefox\Profiles\pomp1wq8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/a/
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-26 19:52
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-243088818-3472766843-1735871867-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\bmp*]
"0"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00,
00,1a,00,ee,bb,fe,23,00,00,10,00,d0,9a,d3,fd,8f,23,af,46,ad,b4,6c,85,48,03,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff

[HKEY_USERS\S-1-5-21-243088818-3472766843-1735871867-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*bmp*]
@Class="Shell"

[HKEY_USERS\S-1-5-21-243088818-3472766843-1735871867-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*bmp*\OpenWithList]
@Class="Shell"
"a"="hpqscnvw.exe"
"MRUList"="a"

[HKEY_USERS\S-1-5-21-243088818-3472766843-1735871867-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.*bmp*]
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
"0"=hex:61,00,70,00,61,00,72,00,74,00,6d,00,65,00,6e,00,74,00,2e,00,62,6d,70,
00,00,00,7a,00,36,00,00,00,00,00,00,00,00,00,00,00,61,00,70,00,61,00,72,00,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(7740)
c:\program files\Logitech\SetPoint\lgscroll.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\atieclxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
c:\windows\system32\WUDFHost.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\RtHDVCpl.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
c:\program files\Webshots\Webshots.scr
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2010-02-26 19:58:22 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-27 01:58
ComboFix2.txt 2010-02-26 03:29

Pre-Run: 374,881,792,000 bytes free
Post-Run: 374,633,881,600 bytes free

- - End Of File - - 41B9BC6CAE4388F8B822FC875AE121FE

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI