This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Norton Blocking Instrusion Attempts, Help Needed

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Peace of mind required please!!

Computer is behaving as normal, however Norton started flagging up on Friday that I was getting intrusion attempts, example "Category: Intrusion Prevention
Date & Time,Risk,Activity,Status,Recommended Action,Risk Name,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description
27/02/2011 11:16,High,An intrusion attempt by 46.252.131.22 was blocked.,Blocked,No Action Required,HTTP Phoenix Toolkit Download Request ,"46.252.131.22, 80",tygradred.vv.cc/in.php?a=QQkFBg0MAwAFAgYAEkcJBQYNDAMCAQQHDQ==,"92.41.239.185, 49204",46.252.131.22,"TCP, www-http"

I have been getting these from various IP's on a regular basis since.


Ran Malwarebyte last night which found and deleted 1 trojan, see below log

Internet Explorer 8.0.6001.19019

27/02/2011 10:26:40
mbam-log-2011-02-27 (10-26-40).txt

Scan type: Quick scan
Objects scanned: 154956
Time elapsed: 6 minute(s), 5 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\tracy griffiths\local settings\temporary internet files\udRemove.exe (Trojan.Agent) -> Quarantined and deleted successfully.


I have been online for 3 hours now and haven't had one flag up, which seems like it has done the job, however I am now getting these two flagging up every couple of minutes or so. What are these? They didn't seem to appear before.
Category: Firewall - Activities
Date & Time,Risk,Activity,Status,Recommended Action,Category
28/02/2011 13:19,Info,"Rule \"Default Block Microsoft Windows 2000 SMB\" blocked (92.53.10.64, Port (445) ). Inbound TCP connection. ",Detected,No Action Required,Firewall - Activities

Category: Firewall - Activities
Date & Time,Risk,Activity,Status,Recommended Action,Category
28/02/2011 12:57,Info,"Unused port blocking has blocked communications. Inbound TCP connection from 85.114.133.45, local service Port (25) .",Detected,No Action Required,Firewall - Activities


Log run by Hitman Pro:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:32:29, on 28/02/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19019)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Users\Tracy Griffiths\AppData\Roaming\Smilebox\SmileboxTray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Users\TRACYG~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\3\3Connect\Wilog.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Tracy Griffiths\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D25KCV79\index[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ig
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…p;m=aspire_5735
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…p;m=aspire_5735
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.search.yahoo.com/search?fr=mcafee&p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\IPS\IPSBHO.DLL
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\coIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [VIP Organizer] "C:\Program Files\VIP Quality Software\VIP Organizer\VIP Organizer.exe"
O4 - HKCU\..\Run: [SmileboxTray] "C:\Users\Tracy Griffiths\AppData\Roaming\Smilebox\SmileboxTray.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Update Agent.lnk = ?
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-31-0.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/bejeweled…ploader_v10.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{19A28066-AE7D-4FBB-814D-8AB0A35B2786}: NameServer = 217.171.132.1 217.171.135.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{19A28066-AE7D-4FBB-814D-8AB0A35B2786}: NameServer = 217.171.132.1 217.171.135.1
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: BecHelperService - Unknown owner - C:\Program Files\3\3Connect\BecHelperService.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1ca0a35c714e39d) (gupdate1ca0a35c714e39d) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

–
End of file - 11608 bytes


Any help much appreciated, thanks!
Hello ikandi84 and welcome to WhatTheTech. Please follow these guidelines while we work on your PC:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Any underlined text in my posts indicates a clickable link.
  • If you have any questions at all, please stop and ask before proceeding.
🖼Click to load external image (Posted Image) Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.scr
DDS.com
DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
🖼Click to load external image (Posted Image) Download GMER Rootkit Scanner from here to your desktop.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If you have trouble running GEMR:
  • Make sure that your security software is disabled
  • Uncheck the box next to "Files" this time also
  • If you still can't run it, try in the Safe Mode
Please include the following in your next post:
  • DDS.txt and Attach.txt logs
  • GMER log
Ok, thanks so much for your help!!!! :)

DDS log:


DDS (Ver_10-12-12.02) - NTFSx86
Run by [removed] at 19:58:36.11 on 01/03/2011
Internet Explorer: 8.0.6001.19019
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.44.1033.18.3000.1543 [GMT 0:00]

AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\3\3Connect\BecHelperService.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Program Files\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Users\Tracy Griffiths\AppData\Roaming\Smilebox\SmileboxTray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\TRACYG~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\3\3Connect\Wilog.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Tracy Griffiths\Desktop\dds.com
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uSearch Bar = Preserve
uStart Page = hxxp://www.google.co.uk/ig
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=0809&s;=2&o;=vb32&d;=1208&m;=aspire_5735
mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=0809&s;=2&o;=vb32&d;=1208&m;=aspire_5735
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p;=%s
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\18.5.0.125\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\18.5.0.125\ips\IPSBHO.DLL
BHO: ShowBarObj Class: {83a2f9b1-01a2-4aa5-87d1-45b6b8505e96} - c:\program files\acer\empowering technology\edatasecurity\x86\ActiveToolBand.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\program files\acer\empowering technology\edatasecurity\x86\eDStoolbar.dll
TB: &Google;: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\18.5.0.125\coIEPlg.dll
uRun: [VIP Organizer] "c:\program files\vip quality software\vip organizer\VIP Organizer.exe"
uRun: [SmileboxTray] "c:\users\tracy griffiths\appdata\roaming\smilebox\SmileboxTray.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [BkupTray] "c:\program files\newtech infosystems\nti backup now 5\BkupTray.exe"
mRun: [ArcadeDeluxeAgent] "c:\program files\acer arcade deluxe\acer arcade deluxe\ArcadeDeluxeAgent.exe"
mRun: [CLMLServer] "c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\CLMLSvc.exe"
mRun: [PlayMovie] "c:\program files\acer arcade deluxe\playmovie\PMVService.exe"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Skytel] Skytel.exe
mRun: [LManager] c:\progra~1\launch~1\LManager.exe
mRun: [eDataSecurity Loader] c:\program files\acer\empowering technology\edatasecurity\x86\eDSloader.exe
mRun: [ePower_DMC] c:\program files\acer\empowering technology\epower\ePower_DMC.exe
mRun: [eRecoveryService]
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\users\tracyg~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\update~1.lnk - c:\program files\3\3connect\AutoUpdateSrv.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://www.shockwave.com/content/bejeweled2/sis/popcaploader_v10.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {19A28066-AE7D-4FBB-814D-8AB0A35B2786} = 217.171.132.1 217.171.135.1
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL

============= SERVICES / DRIVERS ===============

R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [2010-10-3 59240]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nis\1205000.07d\SymDS.sys [2011-1-13 340016]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1205000.07d\SymEFA.sys [2011-1-13 652336]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_18.5.0.125\definitions\bashdefs\20110225.002\BHDrvx86.sys [2011-2-25 800376]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_18.5.0.125\definitions\ipsdefs\20110228.002\IDSvix86.sys [2011-3-1 353912]
R1 RapportCerberus_23945;RapportCerberus_23945;c:\programdata\trusteer\rapport\store\exts\rapportcerberus\23945\RapportCerberus_23945.sys [2011-2-28 55224]
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2010-10-3 169320]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nis\1205000.07d\Ironx86.sys [2011-1-13 136312]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\nis\1205000.07d\symtdiv.sys [2011-1-13 330360]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\acer arcade deluxe\playmovie\000.fcl [2008-5-15 61424]
R2 BecHelperService;BecHelperService;c:\program files\3\3connect\BecHelperService.exe [2010-9-2 1737464]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 CLHNService;CLHNService;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\CLHNService.exe [2008-5-15 81504]
R2 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2008-5-15 24576]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
R2 NIS;Norton Internet Security;c:\program files\norton internet security\engine\18.5.0.125\ccSvcHst.exe [2011-1-13 130000]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-7 50424]
R2 NTIPPKernel;NTIPPKernel;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\NTIPPKernel.sys [2008-5-15 122368]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-4 131072]
R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2010-10-3 767208]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-7-21 102448]
R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2008-11-17 3668480]
S2 gupdate1ca0a35c714e39d;Google Update Service (gupdate1ca0a35c714e39d);c:\program files\google\update\GoogleUpdate.exe [2009-7-21 133104]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-1-21 179712]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-9-11 36608]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-4-22 30192]

=============== Created Last 30 ================

2011-02-28 09:46:03 2048 —-a-w- c:\windows\system32\winrsmgr.dll
2011-02-27 11:36:49 16968 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-02-27 11:36:17 ——– d—–w- c:\progra~2\Hitman Pro
2011-02-27 10:16:11 ——– d—–w- c:\users\tracyg~1\appdata\roaming\Malwarebytes
2011-02-27 10:15:47 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-27 10:15:46 ——– d—–w- c:\progra~2\Malwarebytes
2011-02-27 10:15:43 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-02-27 10:15:42 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-02-27 09:56:14 ——– d—–w- c:\users\tracyg~1\appdata\local\Symantec
2011-02-27 08:28:22 ——– d—–w- c:\users\tracyg~1\appdata\roaming\Tific
2011-02-19 12:50:41 ——– d—–w- c:\users\tracyg~1\appdata\local\Smilebox
2011-02-19 12:49:52 ——– d—–w- c:\users\tracyg~1\appdata\roaming\Smilebox
2011-02-08 21:24:11 2039808 —-a-w- c:\windows\system32\win32k.sys
2011-02-08 21:24:03 3602320 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-02-08 21:24:03 1205080 —-a-w- c:\windows\system32\ntdll.dll
2011-02-08 21:24:02 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-02-06 08:47:59 ——– d—–w- c:\windows\system32\x64

==================== Find3M ====================

2011-01-20 16:08:16 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08:06 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08:06 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08:06 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08:06 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07:58 37376 —-a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07:42 258048 —-a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07:16 586240 —-a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06:38 2873344 —-a-w- c:\windows\system32\mf.dll
2011-01-20 16:06:35 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04:54 98816 —-a-w- c:\windows\system32\mfps.dll
2011-01-20 16:04:54 209920 —-a-w- c:\windows\system32\mfplat.dll
2011-01-20 14:28:38 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27:50 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26:30 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25:25 847360 —-a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24:32 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-01-20 14:24:26 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15:10 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14:39 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14:03 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14:03 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12:46 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11:34 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47:51 683008 —-a-w- c:\windows\system32\d2d1.dll
2011-01-20 13:44:05 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-01-20 13:44:03 797184 —-a-w- c:\windows\system32\FntCache.dll
2011-01-08 08:47:50 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-01-08 06:28:49 292352 —-a-w- c:\windows\system32\atmfd.dll
2010-12-28 15:55:03 413696 —-a-w- c:\windows\system32\odbc32.dll
2010-12-18 06:27:04 916480 —-a-w- c:\windows\system32\wininet.dll
2010-12-18 06:22:41 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-12-18 06:22:27 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2010-12-18 06:22:11 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-12-18 06:22:11 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-12-18 05:25:26 385024 —-a-w- c:\windows\system32\html.iec
2010-12-18 04:48:39 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2010-12-18 04:47:11 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2010-12-14 14:49:23 1169408 —-a-w- c:\windows\system32\sdclt.exe

============= FINISH: 19:59:05.00 ===============


Attached is the attach dds file.



GMER log:

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-03-01 22:37:06
Windows 6.0.6002 Service Pack 2
Running: n4pxqeox.exe; Driver: C:\Users\TRACYG~1\AppData\Local\Temp\fglyapoc.sys


—- System - GMER 1.0.15 —-

SSDT 8C9465B0 ZwAlertResumeThread
SSDT 8C946690 ZwAlertThread
SSDT 8C946F80 ZwAllocateVirtualMemory
SSDT 8C33E2A8 ZwAlpcConnectPort
SSDT 8D1823D8 ZwAssignProcessToJobObject
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwCreateFile [0x96B21996]
SSDT 8D182E20 ZwCreateMutant
SSDT 8D1FFC40 ZwCreateSymbolicLinkObject
SSDT 8CF82870 ZwCreateThread
SSDT 8D1824B8 ZwDebugActiveProcess
SSDT \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\23945\RapportCerberus_23945.sys ZwDeleteFile [0x96B4C9F8]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteKey [0x96B2536C]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteValueKey [0x96B2539E]
SSDT 8CF825B8 ZwDuplicateObject
SSDT 8C946DC0 ZwFreeVirtualMemory
SSDT 8D182F10 ZwImpersonateAnonymousToken
SSDT 8D182FD0 ZwImpersonateThread
SSDT 8C33E210 ZwLoadDriver
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwLoadKey [0x96B25500]
SSDT 8C946CC0 ZwMapViewOfSection
SSDT 8D182B00 ZwOpenEvent
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwOpenFile [0x96B21A5A]
SSDT 8CF82758 ZwOpenProcess
SSDT 8CF824F8 ZwOpenProcessToken
SSDT 8D182940 ZwOpenSection
SSDT 8CF82688 ZwOpenThread
SSDT 8D1822E8 ZwProtectVirtualMemory
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwQueryValueKey [0x96B25476]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwRenameKey [0x96B253E0]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwReplaceKey [0x96B25412]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwRestoreKey [0x96B25444]
SSDT 8C946770 ZwResumeThread
SSDT 8C946A10 ZwSetContextThread
SSDT \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\23945\RapportCerberus_23945.sys ZwSetInformationFile [0x96B4CA6C]
SSDT 8C946AF0 ZwSetInformationProcess
SSDT 8D1827F8 ZwSetSystemInformation
SSDT \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\23945\RapportCerberus_23945.sys ZwSetValueKey [0x96B4D878]
SSDT 8D182A20 ZwSuspendProcess
SSDT 8C946850 ZwSuspendThread
SSDT 8CF82950 ZwTerminateProcess
SSDT 8C946930 ZwTerminateThread
SSDT 8C946BE0 ZwUnmapViewOfSection
SSDT 8C946EB0 ZwWriteVirtualMemory
SSDT 8D1FFF70 ZwCreateThreadEx

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!KeSetEvent + 11D 85AED8A0 8 Bytes [B0, 65, 94, 8C, 90, 66, 94, …]
.text ntkrnlpa.exe!KeSetEvent + 131 85AED8B4 4 Bytes [80, 6F, 94, 8C] {SUB BYTE [EDI-0x6c], 0x8c}
.text ntkrnlpa.exe!KeSetEvent + 13D 85AED8C0 4 Bytes [A8, E2, 33, 8C]
.text ntkrnlpa.exe!KeSetEvent + 191 85AED914 4 Bytes [D8, 23, 18, 8D]
.text ntkrnlpa.exe!KeSetEvent + 1D9 85AED95C 4 Bytes [96, 19, B2, 96]
.text …
PAGE ntkrnlpa.exe!FsRtlCancellableWaitForMultipleObjects + 2AE 85C1F355 7 Bytes JMP 90131E98
C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl entry point in "" section [0xB8C2741C]
.clc C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl unknown last code section [0xB8C28000, 0x1000, 0xE0000020]
? C:\Users\TRACYG~1\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Windows\Explorer.EXE[584] SHELL32.dll!SHGetFolderPathAndSubDirW + 81C5 7641B37C 4 Bytes [00, 26, 00, 10] {ADD [ESI], AH; ADD [EAX], DL}
.text C:\Windows\Explorer.EXE[584] SHELL32.dll!ShellExecuteExW + 18B7 7644DA0C 4 Bytes [10, 1B, 00, 10] {ADC [EBX], BL; ADD [EAX], DL}
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[612] ntdll.dll!KiUserApcDispatcher 775F5B48 5 Bytes JMP 004397C0 C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (RapportService/Trusteer Ltd.)
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[612] WS2_32.dll!getaddrinfo 7610418A 5 Bytes JMP 71670022
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[612] WS2_32.dll!gethostbyname 761162D4 5 Bytes JMP 716E0022
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1172] ntdll.dll!KiUserApcDispatcher 775F5B48 5 Bytes JMP 00414C10 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (RapportMgmtService/Trusteer Ltd.)
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1172] USER32.dll!InSendMessageEx + 3B1 76F6E6B0 6 Bytes JMP 716E001E
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1172] WS2_32.dll!getaddrinfo 7610418A 5 Bytes JMP 71640022
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1172] WS2_32.dll!gethostbyname 761162D4 5 Bytes JMP 71670022
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] ntdll.dll!LdrLoadDll + 1 775B93A9 5 Bytes [22, 00, 67, 71, C3]
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] ntdll.dll!KiUserApcDispatcher 775F5B48 5 Bytes JMP 02E77420 c:\program files\trusteer\rapport\bin\rooksdol.dll (Rooks/Dolomite/Trusteer Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] kernel32.dll!SetUnhandledExceptionFilter 7770A84F 6 Bytes PUSH 71580022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] USER32.dll!DdeInitializeW 76F67921 6 Bytes PUSH 71520022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] USER32.dll!RegisterClassExW 76F6DA30 6 Bytes PUSH 716E0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] USER32.dll!RegisterClassA 76F6DF42 6 Bytes PUSH 71610022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] USER32.dll!RegisterClassW 76F6E1AB 6 Bytes PUSH 715E0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] USER32.dll!CreateWindowExW 76F71305 5 Bytes JMP 708ADB6C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] USER32.dll!TranslateMessage 76F801AD 6 Bytes PUSH 714C0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] USER32.dll!DialogBoxParamW 76F910B0 5 Bytes JMP 707D5501 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] USER32.dll!DialogBoxIndirectParamW 76F92EF5 5 Bytes JMP 709A502F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] USER32.dll!GetClipboardData 76FA715A 6 Bytes PUSH 714F0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] USER32.dll!DialogBoxParamA 76FA8152 5 Bytes JMP 709A4FCC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] USER32.dll!DialogBoxIndirectParamA 76FA847D 5 Bytes JMP 709A5092 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] USER32.dll!MessageBoxIndirectA 76FBD4D9 5 Bytes JMP 709A4F61 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] USER32.dll!MessageBoxIndirectW 76FBD5D3 5 Bytes JMP 709A4EF6 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] USER32.dll!MessageBoxExA 76FBD639 5 Bytes JMP 709A4E94 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] USER32.dll!MessageBoxExW 76FBD65D 5 Bytes JMP 709A4E32 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] GDI32.dll!BitBlt 773B70A6 6 Bytes PUSH 715B0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] ole32.dll!CoCreateInstance 761A9F3E 5 Bytes JMP 71640022
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] ole32.dll!CoCreateInstanceEx 761A9F81 5 Bytes JMP 71550022
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WS2_32.dll!connect 761040D9 5 Bytes JMP 70650022
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WS2_32.dll!getaddrinfo 7610418A 5 Bytes JMP 70610022
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!InternetCloseHandle 75C49088 6 Bytes PUSH 71340022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!InternetQueryDataAvailable 75C4BF83 6 Bytes PUSH 70750022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!HttpAddRequestHeadersA 75C4CF4E 6 Bytes PUSH 71490022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!HttpOpenRequestA 75C4D508 6 Bytes PUSH 71460022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!InternetConnectA 75C4DEAE 6 Bytes PUSH 71310022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!InternetConnectW 75C4F862 6 Bytes PUSH 712E0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!HttpSendRequestW 75C4FABE 6 Bytes PUSH 71370022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!HttpOpenRequestW 75C4FBFB 6 Bytes PUSH 71430022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!InternetOpenA 75C5D690 6 Bytes PUSH 71250022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!InternetOpenW 75C5DB09 6 Bytes PUSH 71220022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!InternetSetStatusCallback 75C5DCC8 6 Bytes PUSH 706F0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!HttpSendRequestA 75C5EE89 6 Bytes PUSH 71400022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!InternetReadFileExA 75C63381 6 Bytes PUSH 70720022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!InternetGetCookieExA 75C64BD0 6 Bytes PUSH 71280022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!InternetWriteFile 75CA608E 6 Bytes PUSH 706C0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!HttpSendRequestExA 75CBA666 6 Bytes PUSH 713D0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!HttpSendRequestExW 75CBA6BF 6 Bytes PUSH 713A0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[4184] WININET.dll!InternetGetCookieA 75CBBD44 6 Bytes PUSH 712B0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] ntdll.dll!LdrLoadDll + 1 775B93A9 5 Bytes [22, 00, 67, 71, C3]
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] ntdll.dll!KiUserApcDispatcher 775F5B48 5 Bytes JMP 024F7420 c:\program files\trusteer\rapport\bin\rooksdol.dll (Rooks/Dolomite/Trusteer Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] kernel32.dll!SetUnhandledExceptionFilter 7770A84F 6 Bytes PUSH 71580022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!CreateDialogParamW 76F672A2 5 Bytes JMP 708ADEF8 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!DdeInitializeW 76F67921 6 Bytes PUSH 71520022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!GetAsyncKeyState 76F6863C 5 Bytes JMP 707C8F37 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!SetWindowsHookExW 76F687AD 5 Bytes JMP 708A9B15 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!CallNextHookEx 76F68E3B 5 Bytes JMP 7089D16D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!UnhookWindowsHookEx 76F698DB 5 Bytes JMP 70814666 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!EnableWindow 76F6CD8B 5 Bytes JMP 708ADD85 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!RegisterClassExW 76F6DA30 6 Bytes PUSH 716E0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!RegisterClassA 76F6DF42 6 Bytes PUSH 71610022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!RegisterClassW 76F6E1AB 6 Bytes PUSH 715E0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!CreateWindowExW 76F71305 5 Bytes JMP 708ADB6C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!GetKeyState 76F78CB1 5 Bytes JMP 708AD333 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!TranslateMessage 76F801AD 6 Bytes PUSH 714C0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!IsDialogMessageW 76F80745 5 Bytes JMP 707D5A13 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!CreateDialogParamA 76F817AA 5 Bytes JMP 709A5CB4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!IsDialogMessage 76F81847 5 Bytes JMP 709A5550 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!CreateDialogIndirectParamA 76F826F1 5 Bytes JMP 709A5CEB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!CreateDialogIndirectParamW 76F89A62 5 Bytes JMP 709A5D22 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!SetKeyboardState 76F90987 5 Bytes JMP 709A58BF C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!DialogBoxParamW 76F910B0 5 Bytes JMP 707D5501 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!DialogBoxIndirectParamW 76F92EF5 5 Bytes JMP 709A502F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!SendInput 76F92F75 5 Bytes JMP 709A647B C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!EndDialog 76F9326E 5 Bytes JMP 707D7EBA C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!SetCursorPos 76FA6FB2 5 Bytes JMP 709A64CF C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!GetClipboardData 76FA715A 6 Bytes PUSH 714F0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!DialogBoxParamA 76FA8152 5 Bytes JMP 709A4FCC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!DialogBoxIndirectParamA 76FA847D 5 Bytes JMP 709A5092 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!MessageBoxIndirectA 76FBD4D9 5 Bytes JMP 709A4F61 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!MessageBoxIndirectW 76FBD5D3 5 Bytes JMP 709A4EF6 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!MessageBoxExA 76FBD639 5 Bytes JMP 709A4E94 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!MessageBoxExW 76FBD65D 5 Bytes JMP 709A4E32 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] USER32.dll!keybd_event 76FBD972 5 Bytes JMP 709A67FF C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] GDI32.dll!BitBlt 773B70A6 6 Bytes PUSH 715B0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] SHELL32.dll!SHRestricted + D95 764689A8 4 Bytes [4D, 30, 8D, 65]
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] SHELL32.dll!SHRestricted + D9D 764689B0 8 Bytes [57, 2F, 8D, 65, 9C, 5B, 8C, …]
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] ole32.dll!OleLoadFromStream 76171E80 5 Bytes JMP 709A53B0 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] ole32.dll!CoCreateInstance 761A9F3E 5 Bytes JMP 708ADBC8 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] ole32.dll!CoCreateInstanceEx 761A9F81 5 Bytes JMP 71550022
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WS2_32.dll!connect 761040D9 5 Bytes JMP 70650022
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WS2_32.dll!getaddrinfo 7610418A 5 Bytes JMP 70610022
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!InternetCloseHandle 75C49088 6 Bytes PUSH 71340022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!InternetQueryDataAvailable 75C4BF83 6 Bytes PUSH 70750022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!HttpAddRequestHeadersA 75C4CF4E 6 Bytes PUSH 71490022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!HttpOpenRequestA 75C4D508 6 Bytes PUSH 71460022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!InternetConnectA 75C4DEAE 6 Bytes PUSH 71310022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!InternetConnectW 75C4F862 6 Bytes PUSH 712E0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!HttpSendRequestW 75C4FABE 6 Bytes PUSH 71370022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!HttpOpenRequestW 75C4FBFB 6 Bytes PUSH 71430022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!InternetOpenA 75C5D690 6 Bytes PUSH 71250022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!InternetOpenW 75C5DB09 6 Bytes PUSH 71220022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!InternetSetStatusCallback 75C5DCC8 6 Bytes PUSH 706F0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!HttpSendRequestA 75C5EE89 6 Bytes PUSH 71400022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!InternetReadFileExA 75C63381 6 Bytes PUSH 70720022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!InternetGetCookieExA 75C64BD0 6 Bytes PUSH 71280022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!InternetWriteFile 75CA608E 6 Bytes PUSH 706C0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!HttpSendRequestExA 75CBA666 6 Bytes PUSH 713D0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!HttpSendRequestExW 75CBA6BF 6 Bytes PUSH 713A0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5292] WININET.dll!InternetGetCookieA 75CBBD44 6 Bytes PUSH 712B0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] ntdll.dll!LdrLoadDll + 1 775B93A9 5 Bytes [22, 00, 67, 71, C3]
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] ntdll.dll!KiUserApcDispatcher 775F5B48 5 Bytes JMP 02647420 c:\program files\trusteer\rapport\bin\rooksdol.dll (Rooks/Dolomite/Trusteer Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] kernel32.dll!SetUnhandledExceptionFilter 7770A84F 6 Bytes PUSH 71580022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!CreateDialogParamW 76F672A2 5 Bytes JMP 708ADEF8 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!DdeInitializeW 76F67921 6 Bytes PUSH 71520022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!GetAsyncKeyState 76F6863C 5 Bytes JMP 707C8F37 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!SetWindowsHookExW 76F687AD 5 Bytes JMP 708A9B15 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!CallNextHookEx 76F68E3B 5 Bytes JMP 7089D16D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!UnhookWindowsHookEx 76F698DB 5 Bytes JMP 70814666 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!EnableWindow 76F6CD8B 5 Bytes JMP 708ADD85 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!RegisterClassExW 76F6DA30 6 Bytes PUSH 716E0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!RegisterClassA 76F6DF42 6 Bytes PUSH 71610022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!RegisterClassW 76F6E1AB 6 Bytes PUSH 715E0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!CreateWindowExW 76F71305 5 Bytes JMP 708ADB6C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!GetKeyState 76F78CB1 5 Bytes JMP 708AD333 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!TranslateMessage 76F801AD 6 Bytes PUSH 714C0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!IsDialogMessageW 76F80745 5 Bytes JMP 707D5A13 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!CreateDialogParamA 76F817AA 5 Bytes JMP 709A5CB4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!IsDialogMessage 76F81847 5 Bytes JMP 709A5550 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!CreateDialogIndirectParamA 76F826F1 5 Bytes JMP 709A5CEB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!CreateDialogIndirectParamW 76F89A62 5 Bytes JMP 709A5D22 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!SetKeyboardState 76F90987 5 Bytes JMP 709A58BF C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!DialogBoxParamW 76F910B0 5 Bytes JMP 707D5501 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!DialogBoxIndirectParamW 76F92EF5 5 Bytes JMP 709A502F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!SendInput 76F92F75 5 Bytes JMP 709A647B C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!EndDialog 76F9326E 5 Bytes JMP 707D7EBA C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!SetCursorPos 76FA6FB2 5 Bytes JMP 709A64CF C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!GetClipboardData 76FA715A 6 Bytes PUSH 714F0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!DialogBoxParamA 76FA8152 5 Bytes JMP 709A4FCC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!DialogBoxIndirectParamA 76FA847D 5 Bytes JMP 709A5092 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!MessageBoxIndirectA 76FBD4D9 5 Bytes JMP 709A4F61 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!MessageBoxIndirectW 76FBD5D3 5 Bytes JMP 709A4EF6 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!MessageBoxExA 76FBD639 5 Bytes JMP 709A4E94 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!MessageBoxExW 76FBD65D 5 Bytes JMP 709A4E32 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] USER32.dll!keybd_event 76FBD972 5 Bytes JMP 709A67FF C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] GDI32.dll!BitBlt 773B70A6 6 Bytes PUSH 715B0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] SHELL32.dll!SHAppBarMessage + 22B 7644BA5C 4 Bytes [4D, 30, 8D, 65]
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] SHELL32.dll!SHAppBarMessage + 233 7644BA64 4 Bytes [57, 2F, 8D, 65]
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] SHELL32.dll!SHAppBarMessage + 25B 7644BA8C 4 Bytes [4D, 30, 8D, 65]
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] SHELL32.dll!SHAppBarMessage + 263 7644BA94 4 Bytes [57, 2F, 8D, 65]
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] SHELL32.dll!SHAppBarMessage + 3B7 7644BBE8 4 Bytes [4D, 30, 8D, 65]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] SHELL32.dll!SHRestricted + BC5 764687D8 4 Bytes [4D, 30, 8D, 65]
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] SHELL32.dll!SHRestricted + BCD 764687E0 4 Bytes [57, 2F, 8D, 65]
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] SHELL32.dll!SHRestricted + D1D 76468930 4 Bytes [4D, 30, 8D, 65]
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] SHELL32.dll!SHRestricted + D25 76468938 4 Bytes [57, 2F, 8D, 65]
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] SHELL32.dll!SHRestricted + D95 764689A8 4 Bytes [4D, 30, 8D, 65]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] ole32.dll!OleLoadFromStream 76171E80 5 Bytes JMP 709A53B0 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] ole32.dll!CoCreateInstance 761A9F3E 5 Bytes JMP 708ADBC8 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] ole32.dll!CoCreateInstanceEx 761A9F81 5 Bytes JMP 71550022
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WS2_32.dll!connect 761040D9 5 Bytes JMP 70650022
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WS2_32.dll!getaddrinfo 7610418A 5 Bytes JMP 70610022
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!InternetCloseHandle 75C49088 6 Bytes PUSH 71340022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!InternetQueryDataAvailable 75C4BF83 6 Bytes PUSH 70750022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!HttpAddRequestHeadersA 75C4CF4E 6 Bytes PUSH 71490022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!HttpOpenRequestA 75C4D508 6 Bytes PUSH 71460022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!InternetConnectA 75C4DEAE 6 Bytes PUSH 71310022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!InternetConnectW 75C4F862 6 Bytes PUSH 712E0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!HttpSendRequestW 75C4FABE 6 Bytes PUSH 71370022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!HttpOpenRequestW 75C4FBFB 6 Bytes PUSH 71430022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!InternetOpenA 75C5D690 6 Bytes PUSH 71250022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!InternetOpenW 75C5DB09 6 Bytes PUSH 71220022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!InternetSetStatusCallback 75C5DCC8 6 Bytes PUSH 706F0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!HttpSendRequestA 75C5EE89 6 Bytes PUSH 71400022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!InternetReadFileExA 75C63381 6 Bytes PUSH 70720022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!InternetGetCookieExA 75C64BD0 6 Bytes PUSH 71280022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!InternetWriteFile 75CA608E 6 Bytes PUSH 706C0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!HttpSendRequestExA 75CBA666 6 Bytes PUSH 713D0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!HttpSendRequestExW 75CBA6BF 6 Bytes PUSH 713A0022; RET
.text C:\Program Files\Internet Explorer\iexplore.exe[5784] WININET.dll!InternetGetCookieA 75CBBD44 6 Bytes PUSH 712B0022; RET
.text C:\Program Files\Microsoft Office\Office12\EXCEL.EXE[6084] kernel32.dll!SetUnhandledExceptionFilter 7770A84F 5 Bytes JMP 5FC154C1 C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)
.text C:\Program Files\Microsoft Office\Office12\EXCEL.EXE[6084] ole32.dll!OleLoadFromStream 76171E80 5 Bytes JMP 606CD62A C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\Udp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\RawIp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)



Thanks again for the help :)

Attachments:

ikandi84:

🖼Click to load external image (Posted Image) Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • If you have trouble, stop and post back. Do not try to repeatedly run comboFix!
  • When finished, it will produce a report for you.
.
Please include the following in your next post:
  • ComboFix log
Combofix Log: :blush: :)

ComboFix 11-03-02.01 - Tracy Griffiths 02/03/2011 19:49:40.1.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.44.1033.18.3000.1724 [GMT 0:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Tracy Griffiths\AppData\Roaming\.#
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Temp\log.txt

.
((((((((((((((((((((((((( Files Created from 2011-02-02 to 2011-03-02 )))))))))))))))))))))))))))))))
.

2011-03-02 19:58 . 2011-03-02 19:58 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-02-28 09:46 . 2009-10-09 21:56 2048 —-a-w- c:\windows\system32\winrsmgr.dll
2011-02-27 11:36 . 2011-02-28 13:29 16968 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-02-27 11:36 . 2011-02-27 11:36 ——– d—–w- c:\programdata\Hitman Pro
2011-02-27 10:16 . 2011-02-27 10:16 ——– d—–w- c:\users\Tracy Griffiths\AppData\Roaming\Malwarebytes
2011-02-27 10:15 . 2010-12-20 18:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-27 10:15 . 2011-02-27 10:15 ——– d—–w- c:\programdata\Malwarebytes
2011-02-27 10:15 . 2010-12-20 18:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-02-27 10:15 . 2011-02-27 10:15 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-02-27 09:56 . 2011-02-27 09:56 ——– d—–w- c:\users\Tracy Griffiths\AppData\Local\Symantec
2011-02-27 08:28 . 2011-02-27 08:28 ——– d—–w- c:\users\Tracy Griffiths\AppData\Roaming\Tific
2011-02-19 12:50 . 2011-02-19 12:58 ——– d—–w- c:\users\Tracy Griffiths\AppData\Local\Smilebox
2011-02-19 12:49 . 2011-02-20 17:10 ——– d—–w- c:\users\Tracy Griffiths\AppData\Roaming\Smilebox
2011-02-08 21:24 . 2010-12-31 13:57 2039808 —-a-w- c:\windows\system32\win32k.sys
2011-02-08 21:24 . 2010-10-15 14:08 3602320 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-02-08 21:24 . 2010-10-15 13:48 1205080 —-a-w- c:\windows\system32\ntdll.dll
2011-02-08 21:24 . 2010-10-15 14:08 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-02-06 08:47 . 2011-02-06 08:47 ——– d—–w- c:\windows\system32\x64

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-13 19:25 . 2010-07-21 17:23 126512 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-12-28 15:55 . 2011-01-13 18:35 413696 —-a-w- c:\windows\system32\odbc32.dll
2010-12-14 14:49 . 2011-01-13 18:35 1169408 —-a-w- c:\windows\system32\sdclt.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-05-15 01:05 121392 —-a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmileboxTray"="c:\users\Tracy Griffiths\AppData\Roaming\Smilebox\SmileboxTray.exe" [2011-01-22 312640]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1049896]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-07 34040]
"ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2008-04-10 147456]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-04-10 167936]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2008-04-18 167936]
"RtHDVCpl"="RtHDVCpl.exe" [2008-06-13 6183456]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-09-10 809480]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-05-15 526896]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-06-11 409600]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-07-01 30192]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 1164584]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]

c:\users\Tracy Griffiths\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Update Agent.lnk - c:\program files\3\3Connect\AutoUpdateSrv.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001

R2 gupdate1ca0a35c714e39d;Google Update Service (gupdate1ca0a35c714e39d);c:\program files\Google\Update\GoogleUpdate.exe [2009-07-21 133104]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-04 131072]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-07-01 30192]
S0 RapportKELL;RapportKELL;c:\windows\System32\Drivers\RapportKELL.sys [2010-10-03 59240]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1205000.07D\SYMDS.SYS [2010-10-21 340016]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1205000.07D\SYMEFA.SYS [2010-11-18 652336]
S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\BASHDefs\20110225.002\BHDrvx86.sys [2011-02-25 800376]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\IPSDefs\20110302.001\IDSvix86.sys [2010-11-11 353912]
S1 RapportCerberus_23945;RapportCerberus_23945;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\23945\RapportCerberus_23945.sys [2011-02-28 55224]
S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [2010-10-03 169320]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1205000.07D\Ironx86.SYS [2010-11-16 136312]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\NIS\1205000.07D\SYMTDIV.SYS [2010-12-01 330360]
S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-04-18 61424]
S2 BecHelperService;BecHelperService;c:\program files\3\3Connect\BecHelperService.exe [2010-01-28 1737464]
S2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
S2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-17 81504]
S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
S2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe [2010-11-24 130000]
S2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-07 50424]
S2 NTIPPKernel;NTIPPKernel;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-01-17 122368]
S2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [2010-10-03 767208]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-07-21 102448]
S3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2011-03-02 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-22 18:59]

2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-21 19:01]

2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-21 19:01]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/ig
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=0809&s;=2&o;=vb32&d;=1208&m;=aspire_5735
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p;=%s
TCP: {19A28066-AE7D-4FBB-814D-8AB0A35B2786} = 217.171.132.1 217.171.135.1
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-VIP Organizer - c:\program files\VIP Quality Software\VIP Organizer\VIP Organizer.exe
HKLM-Run-eRecoveryService - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-02 19:59
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\18.5.0.125\diMaster.dll\" /prefetch:1"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-03-02 20:01:29
ComboFix-quarantined-files.txt 2011-03-02 20:01

Pre-Run: 31,139,946,496 bytes free
Post-Run: 31,517,081,600 bytes free

- - End Of File - - 9581E438B0C64338541F283EB5559F66
ikandi84:

How is your computer running now? Please do this next:

🖼Click to load external image (Posted Image) Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.

Java™ 6 Update 17 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now. An update should begin; follow the prompts. If it does not, let me know.

Once the install is complete…

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
    • Trace and Log Files
  • Click OK on Delete Temporary Files Window
Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
🖼Click to load external image (Posted Image) You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM
  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Uncheck any entries from C:\System Volume Information or C:\Qoobox
  • Make sure that everything else is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

🖼Click to load external image (Posted Image) Please run ESET Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Please include the following in your next post:
  • MBAM log
  • ESET log
Again, computer is still running as normal, so no problems there.

Unfortunately wasn't able to carry out this section (see below) as there was no option to click "show results" once the scan had been completed. After clicking the OK button the log instantly appeared. Followed everything else as requested.

"•When the scan is complete, click OK, then Show Results to view the results.
•Uncheck any entries from C:\System Volume Information or C:\Qoobox
•Make sure that everything else is checked, and click Remove Selected."



MBAM log:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5946

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19019

03/03/2011 20:43:56
mbam-log-2011-03-03 (20-43-56).txt

Scan type: Quick scan
Objects scanned: 153477
Time elapsed: 7 minute(s), 32 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


ESET log

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6425
# api_version=3.0.2
# EOSSerial=6dd2c550a1123444a915bd341d4a0caf
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-03-03 10:29:16
# local_time=2011-03-03 10:29:16 (+0000, GMT Standard Time)
# country="United Kingdom"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=3588 16777214 85 82 996176 9210590 0 0
# compatibility_mode=5892 16776574 100 100 26017834 136718398 0 0
# compatibility_mode=8192 67108863 100 0 3812 3812 0 0
# scanned=160873
# found=0
# cleaned=0
# scan_time=5731

Thanks :)
ikandi84:

Your logs look good. Now I have another updatate and some very important cleanup for you to take care of:

🖼Click to load external image (Posted Image) Your Adobe reader needs to be updated. Please visit Adobe's site and grab the newest version. Be sure to watch for and uncheck any boxes offering to install other software.

🖼Click to load external image (Posted Image) Uninstall ComboFix
  • Press the Windows key + R on your keyboard or click Start -> Run. Copy and past the following text into the run box that opens and press OK:
    Combofix /Uninstall
🖼Click to load external image (Posted Image)

🖼Click to load external image (Posted Image) Delete the following tools along with any other logs you saved from our work:
  • DDS
  • GMER
  • Rootkit Unhooker
  • MBRCheck
🖼Click to load external image (Posted Image) Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
🖼Click to load external image (Posted Image) Finally, I'd like to make a couple of suggestions to help you stay clean in the future:
  • Restart any anti-malware programs that we disabled while we were cleaning your machine.
  • Keep your antivirus application and MBAM current and updated. Scan with them at least weekly.
  • Please carefully review the information in the Security - Best Practices and Prevention forum located HERE
Please post once more so I know you are all set and I can close this thread. Good luck and stay safe!
Completed all the above, so it looks like its all done and dusted. Phew!!! I can relax now. I must say a big thank you for all your help with this, I can't emphasise enough how much it is appreciated :D :D :D Thanks Again!!! ikandi84

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI